Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 1381-1400 of 18002 records
Threat Entry Updated 2026-06-17

CVE-2026-52704 - WooCommerce PDF Invoice Builder Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.

PLUGIN WooCommerce PDF Invoice Builder

CVE-2026-52704

CRITICAL CVSS 10.0 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-49111 - Masteriyo - LMS Plugin

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

PLUGIN Masteriyo - LMS

CVE-2026-49111

HIGH CVSS 8.8 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-49062 - Faust.Js Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

PLUGIN Faust.Js

CVE-2026-49062

HIGH CVSS 8.8 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-49064 - GetPaid Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

PLUGIN GetPaid

CVE-2026-49064

HIGH CVSS 7.5 2026-06-15
Threat Entry Updated 2026-06-17

CVE-2026-8935 - Wp Maps Pro Plugin

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing its map script, unconditionally creates an administrator account and returns a magic-login URL granting interactive admin access.

PLUGIN Wp Maps Pro

CVE-2026-8935

CRITICAL CVSS 9.8 2026-06-15
Scroll to top