Threat Intelligence Feed

Aggregating 9509 articles from trusted cybersecurity sources

LATEST CVEs
HIGH · CVE-2026-16169 IBM DataPower Gateway 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service due to uncont MED · CVE-2026-14521 IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 throug HIGH · CVE-2026-106611 Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This MED · CVE-2026-106603 Authorization Bypass Through User-Controlled Key vulnerability in Groundhogg HollerBox holler-box allows Exploiting Inco MED · CVE-2026-106600 Missing Authorization vulnerability in Liquid Web / StellarWP GiveWP give allows Exploiting Incorrectly Configured Acces MED · CVE-2026-106596 Missing Authorization vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Exploiting MED · CVE-2026-105893 Authorization Bypass Through User-Controlled Key vulnerability in Liquid Web / StellarWP Event Tickets event-tickets all MED · CVE-2026-105891 Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly MED · CVE-2026-105890 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / Stell MED · CVE-2026-105888 Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly MED · CVE-2026-105887 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robosoft Robo Gall MED · CVE-2026-105886 Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Config MED · CVE-2026-105878 Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exp MED · CVE-2026-105079 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Mas MED · CVE-2026-105078 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Store Locator W HIGH · CVE-2026-105076 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Appsbd Vitepos vit MED · CVE-2026-103072 Missing Authorization vulnerability in VillaTheme VillaTheme Core villatheme-core allows Exploiting Incorrectly Configur MED · CVE-2026-103070 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel ShortPi CVE-2026-102784 Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait CVE-2026-102783 Joomla Extension - balbooa.com - Path Traversal in image preview Gridbox < 2.20.4.0 - Gridbox contains the same prefix-o CRIT · CVE-2026-92555 Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Tra HIGH · CVE-2026-19083 Authorization bypass through User-Controlled key vulnerability in AKIN Software Computer Import-Export Industry and Trad MED · CVE-2026-107587 Improper certificate validation in the webmail of Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unau HIGH · CVE-2026-107584 Progressive Robot hMailServer 6.0.0 through 6.3.5 fails open when applying DANE (RFC 7672) to outbound SMTP delivery. Th MED · CVE-2026-107583 Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 MED · CVE-2026-107582 Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6 MED · CVE-2026-107581 Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadr MED · CVE-2026-107580 Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 throu HIGH · CVE-2026-107579 Inefficient algorithmic complexity in the bounce and complaint processing of Progressive Robot hMailServer 6.3.4 and 6.3 MED · CVE-2026-107578 Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer HIGH · CVE-2026-107577 Inefficient algorithmic complexity and a non-terminating loop in the MIME processing of received messages in Progressive HIGH · CVE-2026-107576 Inefficient algorithmic complexity in the inbound DKIM and ARC signature verification of Progressive Robot hMailServer 6 MED · CVE-2026-107575 Inefficient algorithmic complexity in the SPF macro expansion of Progressive Robot hMailServer 6.3.4 and 6.3.5 allows a HIGH · CVE-2026-107574 Inefficient algorithmic complexity in the JSON reader of Progressive Robot hMailServer allows a remote unauthenticated a HIGH · CVE-2026-107573 Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a loca MED · CVE-2026-107572 Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an au CVE-2026-107570 heap OOB write in convert_file_from_to() via a crafted Content-Type header allows attacker to OOB write when email is us MED · CVE-2026-107275 @fastify/jwt is a JSON Web Token plugin for the Fastify web framework. In versions before 10.2.3, a time span passed to MED · CVE-2026-93509 The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is posit MED · CVE-2026-105190 The Easy Digital Downloads WordPress plugin before 3.7.1 does not consult the site's user registration setting before cr
6661 general 1094 advisories 752 research 675 vendor 327 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.