Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-57707 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. | 9.3 | 0.29% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57706 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6. | 7.1 | 0.18% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57705 | Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5. | 7.5 | 0.25% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57702 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2. | 9.3 | 0.29% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57700 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6. | 10.0 | 0.37% | 2026-06-25 | 2026-06-29 |
| CVE-2026-57698 | Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12. | 6.5 | 0.25% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57697 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6. | 7.5 | 0.33% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57695 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0. | 7.1 | 0.18% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57694 | Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13. | 6.5 | 0.24% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57693 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ad Inserter: from n/a through <= 2.8.11. | 6.5 | 0.22% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57692 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2. | 9.8 | 0.29% | 2026-07-01 | 2026-07-01 |
| CVE-2026-57691 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89. | 5.8 | 0.20% | 2026-07-13 | 2026-07-13 |
| CVE-2026-57690 | Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions. | 4.3 | 0.10% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57689 | Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions. | 4.3 | 0.22% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57688 | Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions. | 8.2 | 0.24% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57687 | Contributor SQL Injection in Custom Field Template <= 2.7.8 versions. | 8.5 | 0.22% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57686 | Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions. | 7.1 | 0.19% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57685 | Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions. | 4.3 | 0.25% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57684 | Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions. | 6.5 | 0.17% | 2026-07-02 | 2026-07-02 |
| CVE-2026-57683 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | 9.3 | 0.25% | 2026-07-02 | 2026-07-02 |