Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-48708

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination_CVE-2026-48708

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template engine uses a single shared t...

OliveTin OliveTin < 3000.13.0 CVE
HIGH 8.5 CVE-2026-48124

Cursor Desktop sandbox escape via Claude hook configuration_CVE-2026-48124

Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook c...

cursor cursor < 3.0.0 CVE
HIGH 8.6 CVE-2026-47825

Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations_CVE-2026-47825

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affe...

Spring Spring Cloud Gateway 3.1.0 CVE
HIGH 7.5 CVE-2026-47261

Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction_CVE-2026-47261

Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and Fil...

bytecodealliance wasmtime >= 37.0.0, < 44.0.2 CVE
HIGH 7.5 CVE-2026-45441

WordPress WpEvently plugin <= 5.3.3 - Other Vulnerability Type vulnerability_CVE-2026-45441

Unauthenticated Other Vulnerability Type in WpEvently

Magepeople inc. WpEvently n/a CVE
HIGH 7.1 CVE-2026-45437

WordPress Product Filter Widget for Elementor plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability_CVE-2026-45437

Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor

Bhavin Thummar Product Filter Widget for Elementor n/a CVE
HIGH 7.1 CVE-2026-42775

WordPress AutomatorWP plugin <= 5.7.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-42775

Unauthenticated Cross Site Scripting (XSS) in AutomatorWP

Ruben Garcia AutomatorWP n/a CVE
HIGH 8.1 CVE-2026-42687

WordPress EventPrime plugin <= 4.3.2.1 - PHP Object Injection vulnerability_CVE-2026-42687

Unauthenticated PHP Object Injection in EventPrime

EventPrime EventPrime n/a CVE
HIGH 7.1 CVE-2026-42686

WordPress EventPrime plugin <= 4.3.2.1 - Cross Site Scripting (XSS) vulnerability_CVE-2026-42686

Subscriber Cross Site Scripting (XSS) in EventPrime

EventPrime EventPrime n/a CVE
HIGH 7.5 CVE-2026-42668

WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.18.0 - Broken Authentication vulnerability_CVE-2026-42668

Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend

Omnisend Email Marketing for WooCommerce by Omnisend n/a CVE