| medium |
CVE-2026-15602 — The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQ… |
vulnerability |
nvd |
CVE-2026-15602 |
|
2026-08-16 |
| medium |
CVE-2026-15441 — The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and… |
vulnerability |
nvd |
CVE-2026-15441 |
phishing |
2026-08-16 |
| medium |
CVE-2026-15066 — The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Ext… |
vulnerability |
nvd |
CVE-2026-15066 |
|
2026-08-16 |
| medium |
CVE-2026-15009 — The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin… |
vulnerability |
nvd |
CVE-2026-15009 |
|
2026-08-16 |
| high |
CVE-2026-15002 — The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Sc… |
vulnerability |
nvd |
CVE-2026-15002 |
|
2026-08-16 |
| critical |
CVE-2026-14524 — The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insuf… |
vulnerability |
nvd |
CVE-2026-14524 |
rce |
2026-08-16 |
| high |
CVE-2026-14498 — The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to… |
vulnerability |
nvd |
CVE-2026-14498 |
rce |
2026-08-16 |
| medium |
CVE-2026-13358 — The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress… |
vulnerability |
nvd |
CVE-2026-13358 |
|
2026-08-16 |
| medium |
CVE-2026-13167 — The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin fo… |
vulnerability |
nvd |
CVE-2026-13167 |
|
2026-08-16 |
| medium |
CVE-2026-12905 — The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to,… |
vulnerability |
nvd |
CVE-2026-12905 |
|
2026-08-16 |
| medium |
CVE-2026-12477 — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Store… |
vulnerability |
nvd |
CVE-2026-12477 |
|
2026-08-16 |
| medium |
CVE-2026-11780 — The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to… |
vulnerability |
nvd |
CVE-2026-11780, CVE-2026-15963 |
|
2026-08-16 |
| medium |
CVE-2025-10005 — The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vul… |
vulnerability |
nvd |
CVE-2025-10005 |
|
2026-08-16 |
| medium |
CVE-2026-2487 — The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin s… |
vulnerability |
nvd |
CVE-2026-2487 |
|
2026-08-16 |
| medium |
CVE-2026-19930 — A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the… |
vulnerability |
nvd |
CVE-2026-19930 |
botnet |
2026-08-16 |
| medium |
CVE-2026-19929 — A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplat… |
vulnerability |
nvd |
CVE-2026-19929 |
|
2026-08-16 |
| medium |
CVE-2026-19928 — A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of th… |
vulnerability |
nvd |
CVE-2026-19928 |
|
2026-08-16 |
| medium |
CVE-2026-19927 — A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of t… |
vulnerability |
nvd |
CVE-2026-19927 |
|
2026-08-16 |
| high |
CVE-2026-19926 — A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected el… |
vulnerability |
nvd |
CVE-2026-19926 |
|
2026-08-16 |
| medium |
CVE-2026-19925 — A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some… |
vulnerability |
nvd |
CVE-2026-19925 |
|
2026-08-16 |
| critical |
CVE-2026-19924 — A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability… |
vulnerability |
nvd |
CVE-2026-19924 |
|
2026-08-16 |
| medium |
CVE-2026-19923 — A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown… |
vulnerability |
nvd |
CVE-2026-19923 |
|
2026-08-16 |
| low |
CVE-2026-19922 — A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this is… |
vulnerability |
nvd |
CVE-2026-19922 |
|
2026-08-16 |
| medium |
CVE-2026-19921 — A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnera… |
vulnerability |
nvd |
CVE-2026-19921 |
|
2026-08-16 |
| medium |
CVE-2026-19920 — A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown f… |
vulnerability |
nvd |
CVE-2026-19920 |
|
2026-08-16 |
| high |
CVE-2026-19919 — A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown funct… |
vulnerability |
nvd |
CVE-2026-19919 |
|
2026-08-16 |
| medium |
CVE-2026-19918 — A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects th… |
vulnerability |
nvd |
CVE-2026-19918 |
|
2026-08-16 |
| medium |
New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies |
threat-intel |
otx |
CVE-2016-6277, CVE-2007-3010, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583 | 91.92.40.118 |
edge devices, cve-2007-3010, iot exploitation, cve-2022-37055, cve-2025-55583, cve-2020-10987, mirai variant, cve-2025-10123, cve-2021-46422, cve-2024-29269, cve-2018-14558, cve-2019-14931, ddos attacks, linux botnet, evooo1bot, cve-2016-6277, socks proxy, encrypted c2, mirai, botnet |
2026-08-14 |
| medium |
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged |
threat-intel |
otx |
CVE-2017-7269, CVE-2021-3156, CVE-2021-4034, CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-43503 | ff662b60f6a142f9…, 9c9976adbb1f4cda… |
cve-2026-43500, hiveserver2 exploitation, apache hadoop targeting, cve-2026-43284, vshell, cve-2017-7269, suo5, shadowpad, cve-2021-3156, autonomous attack operations, thailand ministry finance, cve-2021-4034, cve-2026-31431, hermes ai agent, cve-2026-43503, government espionage, hades, hades implant, yolo mode, botnet |
2026-07-23 |
| high |
Global Webmail Espionage |
threat-intel |
otx |
CVE-2025-66376 |
cyberespionage, laundry bear, cve-2025-66376, zimbra, russian threat actor, zero-click phishing, javascript injection, void blizzard, cl-sta-1114, zeroday, phishing, botnet |
2026-07-23 |
| medium |
Exploitation in the Wild of wp2shell |
threat-intel |
otx |
CVE-2026-63030, CVE-2026-60137 |
plugin upload, cmsmap, cve-2026-63030, cve-2026-60137, wordpress, pre-authentication, rce, batch api exploitation, webshell, sql injection |
2026-07-23 |
| high |
JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models |
threat-intel |
otx |
CVE-2025-3248 | ea7822eac6cecef7… |
jadepuffer, ai infrastructure, cve-2025-3248, autonomous threat, langflow, container escape, encforge, machine learning, ransomware, phishing |
2026-07-21 |