Recent Advisories

Severity ID Title Vendor Product Date Type
NONE SECURELIST:318E...

ToddyCat: your hidden email assistant. Part 2_SECURELIST:318E425764C1762E8EB0EB5B9B2F6150

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2026/06/19083452/toddycat-part-2-featured-image-990x400.jpg) ## Introduction...

N/A N/A SECURELIST
NONE HACKREAD:F9C96F...

WhatsApp Usernames Will Let You Chat Without Sharing Your Phone Number_HACKREAD:F9C96F0F0C00545F020EAD13425F60F7

WhatsApp is letting users reserve usernames before its 2026 launch, giving people a way to chat without sharing phone numbers. Here is how it works...

N/A N/A HACKREAD
NONE THN:B2122E08A29...

What the Numbers Say About FIFA 2026 Cyber Risk_THN:B2122E08A297EDF9158A122D018B4FAD

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEZt1Yxw3eiMzyzPpblDGru8JlEmw-Rr1Lgn8hG9YCvxeCNDpKOCyn5_Evvmc_lB9tKDpcmBLfH3a6mHGkZB...

N/A N/A THN
NONE H1:3831345

curl: CURLSHOPT_UNSHARE race can cause UAF in shared SSL session cache during HTTPS transfer_H1:3831345

## Summary `CURLSHOPT_UNSHARE` can free a shared SSL session cache while another thread is starting a normal HTTPS transfer with the same share ha...

N/A N/A HACKERONE
CRITICAL 10 THN:92496BE41BB...

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer_THN:92496BE41BBB472864D9FF3429DE96A7

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEid1CxvsX2dPrKoA1VzJ6PUhwrXxvSC4ehRmgyaRRCJlP_MFSeOxvwrT2ODJSbQx3E-7bBwBG4YpP3CQGLz...

N/A N/A THN
CRITICAL 9.8 CVE-2026-9711

EventON – WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter_CVE-2026-9711

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' paramet...

EventON EventON (Pro) - WordPress Virtual Event Calendar Plugin CVE
HIGH 7.2 CVE-2026-8141

Ajax Load More – Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field_CVE-2026-8141

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all...

Connekt Media Ajax Load More - Filters CVE
MEDIUM 5.1 CVE-2026-6954

Multiple vulnerabilities in Intermark IT’s WebControl CMS_CVE-2026-6954

Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or...

Intermark IT WebControl CMS CVE
MEDIUM 5.1 CVE-2026-6953

Multiple vulnerabilities in Intermark IT’s WebControl CMS_CVE-2026-6953

HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTM...

Intermark IT WebControl CMS CVE
HIGH 7.7 CVE-2026-13149

CVE-2026-13149_CVE-2026-13149

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of conse...

juliangruber brace-expansion CVE