Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 B351E803-26D7-

Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft_B351E803-26D7-5CFC-8727-D423591F86F5

SMBGhost Scanner — CVE-2020-0796 SMBv3 vulnerability scanner SMBGhost. Detects vulnerable Windows hosts by sending a malformed SMBv3 negotiation pa...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.4 ED8AC01D-C112-

Exploit for SQL Injection in Ghost_ED8AC01D-C112-5F2F-86B2-002DDA813E82

CVE-2026-26980 — Ghost CMS Content API Blind SQL Injection Affected: Ghost 3.24.0 – 6.19.0 Fixed in: Ghost 6.19.1 Auth required: None — Content API...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 CVE-2026-57658

WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability_CVE-2026-57658

Administrator Arbitrary File Upload in TemplateSpare

Templatespare TemplateSpare n/a CVE
CRITICAL 9.3 CVE-2026-56070

WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability_CVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search

ThemeHunk Advance Product Search n/a CVE
CRITICAL 9.3 CVE-2026-56068

WordPress JetEngine plugin <= 3.8.10.2 - SQL Injection vulnerability_CVE-2026-56068

Unauthenticated SQL Injection in JetEngine

Crocoblock. Jetimpex Inc. JetEngine n/a CVE
CRITICAL 9.3 CVE-2026-56067

WordPress JetSmartFilters plugin <= 3.8.3 - SQL Injection vulnerability_CVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters

Crocoblock. Jetimpex Inc. JetSmartFilters n/a CVE
CRITICAL 9.3 CVE-2026-56062

WordPress Quotes llama plugin <= 3.1.5 - SQL Injection vulnerability_CVE-2026-56062

Unauthenticated SQL Injection in Quotes llama

oooorgle Quotes llama n/a CVE
CRITICAL 9.9 CVE-2026-56059

WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability_CVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking

PhysCode Travel Booking n/a CVE
CRITICAL 9.9 CVE-2026-56058

WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability_CVE-2026-56058

Subscriber Arbitrary File Upload in Quform

ThemeCatcher Quform n/a CVE
CRITICAL 9.8 CVE-2026-56057

WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vulnerability_CVE-2026-56057

Subscriber PHP Object Injection in Uncanny Automator Pro

Uncanny Owl Uncanny Automator Pro n/a CVE