Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 441-460 of 1249 records
Threat Entry Updated 2026-01-22

CVE-2026-22584 - Uni2TS Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

PLUGIN Uni2TS

CVE-2026-22584

CRITICAL CVSS 9.8 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14741 - Acf Frontend Form Element Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenticated attackers to delete arbitrary posts, pages, products, taxonomy terms, and user accounts.

PLUGIN Acf Frontend Form Element

CVE-2025-14741

CRITICAL CVSS 9.1 2026-01-09
Threat Entry Updated 2026-01-13

CVE-2025-14736 - Frontend Admin By Dynamiapps Plugin

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display' functions. This makes it possible for unauthenticated attackers to register as administrators and gain complete control of the site, granted they can access a user registration form containing a Role field.

PLUGIN Frontend Admin By Dynamiapps

CVE-2025-14736

CRITICAL CVSS 9.8 2026-01-09
Threat Entry Updated 2026-02-18

CVE-2026-22234 - eCase Portal Plugin

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

PLUGIN eCase Portal

CVE-2026-22234

CRITICAL CVSS 9.3 2026-01-08
Threat Entry Updated 2026-01-08

CVE-2026-22034 - Snuffleupagus Plugin

Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual patching system. On deployments of Snuffleupagus prior to version 0.13.0 with the non-default upload validation feature enabled and configured to use one of the upstream validation scripts based on Vulcan Logic Disassembler (VLD) while the VLD extension is not available to the CLI SAPI, all files from multipart POST requests are evaluated as PHP code. The issue was fixed in version 0.13.0.

PLUGIN Snuffleupagus

CVE-2026-22034

CRITICAL CVSS 9.2 2026-01-08
Threat Entry Updated 2026-01-12

CVE-2026-21891 - ZimaOS Plugin

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known system service account. The application's login function fails to properly handle the password validation result for these users, effectively granting authenticated access to anyone who knows one of these common usernames and provides any password. As of time of publication, no…

PLUGIN ZimaOS

CVE-2026-21891

CRITICAL CVSS 9.4 2026-01-08
Threat Entry Updated 2026-02-23

CVE-2026-21876 - Coreruleset Plugin

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like `MULTIPART_PART_HEADERS`), the capture variables (`TX:0`, `TX:1`) get overwritten with each iteration. Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has…

PLUGIN Coreruleset

CVE-2026-21876

CRITICAL CVSS 9.3 2026-01-08
Threat Entry Updated 2026-01-20

CVE-2026-21881 - Kanboard Plugin

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse proxy. An attacker can impersonate any user, including administrators, by simply sending a spoofed HTTP header. This issue is fixed in version 1.2.49.

PLUGIN Kanboard

CVE-2026-21881

CRITICAL CVSS 9.1 2026-01-08
Threat Entry Updated 2026-01-20

CVE-2026-21877 - N8n Plugin

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Cloud instances. This issue is fixed in version 1.121.3. Administrators can reduce exposure by disabling the Git node and limiting access for untrusted users, but upgrading to the latest version is recommended.

PLUGIN N8n

CVE-2026-21877

CRITICAL CVSS 9.9 2026-01-08
Threat Entry Updated 2026-01-27

CVE-2026-21875 - Clipbucket V5 Plugin

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add comment section within a channel. When adding a comment within a channel, there is a POST request to the /actions/ajax.php endpoint. The obj_id parameter within the POST request to /actions/ajax.php is then used within the user_exists function of the upload/includes/classes/user.class. php file as the $id parameter. It is then used within the count function of the upload/includes/classes/db.class. php file. The $id parameter is concatenated into the…

PLUGIN Clipbucket V5

CVE-2026-21875

CRITICAL CVSS 9.8 2026-01-08
Threat Entry Updated 2026-01-16

CVE-2026-21858 - N8n Plugin

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.

PLUGIN N8n

CVE-2026-21858

CRITICAL CVSS 10.0 2026-01-08
Threat Entry Updated 2026-02-03

CVE-2026-21854 - Tarkov Data Manager Plugin

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpoint allows any unauthenticated user to gain full admin access to the Tarkov Data Manager admin panel by exploiting a JavaScript prototype property access vulnerability, combined with loose equality type coercion. A series of fix commits on 02 January 2025 fixed this and other vulnerabilities.

PLUGIN Tarkov Data Manager

CVE-2026-21854

CRITICAL CVSS 9.8 2026-01-07
Threat Entry Updated 2026-02-03

CVE-2026-21855 - Tarkov Data Manager Plugin

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scripting (XSS) vulnerability in the toast notification system allows any attacker to execute arbitrary JavaScript in the context of a victim's browser session by crafting a malicious URL. A series of fix commits on 02 January 2025 fixed this and other vulnerabilities.

PLUGIN Tarkov Data Manager

CVE-2026-21855

CRITICAL CVSS 9.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2026-22542 - QC 60/90/120 Plugin

An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service.

PLUGIN QC 60/90/120

CVE-2026-22542

CRITICAL CVSS 9.2 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2026-22540 - QC60/90/120 Plugin

The massive sending of ARP requests causes a denial of service on one board of the charger that allows control of the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

PLUGIN QC60/90/120

CVE-2026-22540

CRITICAL CVSS 9.2 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2026-0650 - Flagr Plugin

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.

PLUGIN Flagr

CVE-2026-0650

CRITICAL CVSS 9.3 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-15018 - Optional Email Plugin

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it possible for unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts.

PLUGIN Optional Email

CVE-2025-15018

CRITICAL CVSS 9.8 2026-01-07
Threat Entry Updated 2026-01-08

CVE-2025-30996 - Cted Upload Of File With Dangerous Type Vulnerability In Themify Themify Sidepane Theme

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects Themify Sidepane WordPress Theme: from n/a through 1.9.8; Themify Newsy: from n/a through 1.9.9; Themify Folo: from n/a through 1.9.6; Themify Edmin: from n/a through 2.0.0; Bloggie: from n/a through 2.0.8; Photobox: from n/a through 2.0.1; Wigi: from n/a through 2.0.1; Rezo: from n/a through 1.9.7;…

THEME Cted Upload Of File With Dangerous Type Vulnerability In Themify Themify Sidepane

CVE-2025-30996

CRITICAL CVSS 9.9 2026-01-06
Threat Entry Updated 2026-01-08

CVE-2025-15001 - Registration Password Plugin

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN Registration Password

CVE-2025-15001

CRITICAL CVSS 9.8 2026-01-06
Threat Entry Updated 2026-01-08

CVE-2025-14996 - As Password Field In Default Registration Form Plugin

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

PLUGIN As Password Field In Default Registration Form

CVE-2025-14996

CRITICAL CVSS 9.8 2026-01-06
Scroll to top