Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 79541384-47A5-

Exploit for CVE-2025-6440_79541384-47A5-592D-A5A6-0CDB62D82608

🧨 CVE-2025-6440 – WooCommerce Designer Pro Unrestricted File Upload Unauthenticated Arbitrary File Upload via wcdpsavecanvasdesignajax WooCommerce...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 9DB3988A-A1AC-

Exploit for CVE-2026-23550_9DB3988A-A1AC-5A76-BAFF-A614766C18D9

🧨 CVE-2026-23550 – Modular Connector Admin Bypass Unauthenticated WordPress Admin Login via origin=mo Parameter Modular Connector Plugin ≤ 2.5.1 -...

N/A N/A GITHUBEXPLOIT
NONE 73ED47F7-340E-

CVEAlertor_73ED47F7-340E-59EF-9B82-23D94DC498E9

CVEAlertor Get an instant Telegram alert the moment a new CVE is published for software you actually run. You tell CVEAlertor which products are in...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 3A214513-27F6-

Exploit for Code Injection in Phpunit_Project Phpunit_3A214513-27F6-566A-A861-1A2241A825C8

CVE-2017-9841 — PHPUnit Remote Code Execution RCE PoC ⚠️ DISCLAIMER: This tool is intended solely for educational purposes and authorized security ...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 1DB33557-ED5A-

Exploit for Code Injection in Phpunit_Project Phpunit_1DB33557-ED5A-5DFC-8001-A087CD793210

CVE-2017-9841 — PHPUnit Remote Code Execution RCE PoC ⚠️ DISCLAIMER: This tool is intended solely for educational purposes and authorized security ...

N/A N/A GITHUBEXPLOIT
HIGH 8.1 58222AF9-E3B1-

Exploit for SQL Injection in Cmsmadesimple Cms_Made_Simple_58222AF9-E3B1-5F41-A4D5-DADB0DA5111F

poc-CVE-2019-9053 PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple = 2.2.9. Esta versão foi ada...

N/A N/A GITHUBEXPLOIT
NONE THN:86B1DB111A1...

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks_THN:86B1DB111A1F65CBDDBE47C21A621765

![Supply Chain Attacks](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_yyoUTLr71Ug2Ge0R7qFSnlGjB3TzlrQ-2NDR5jpPSBjivUSxhxRV1eCg5E6Af1...

N/A N/A THN
MEDIUM 6.4 CVE-2026-40985

Data Binding Vulnerability in Spring Web Flow with Unified EL Parser_CVE-2026-40985

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring...

Spring Spring Web Flow 4.0.0 CVE
NONE 73629CA5-6CDC-

claude-code-f002-poc_73629CA5-6CDC-5867-A16B-E46998DF46E8

F002: Supply Chain Attack via Non-Interactive Workspace Trust Bypass 🔴 CRITICAL — CVE Candidate Severity CRITICAL when chained with supply chain a...

N/A N/A GITHUBEXPLOIT
MEDIUM 4.7 CVE-2026-2827

Open User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification'_CVE-2026-2827

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions u...

100plugins Open User Map PRO CVE