Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.
CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile
CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 09:16Z
CRIT
CVE-2026-39620 — Site: Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.
CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile
CWECWE 352TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-08
2026-04-08 09:16Z
CRIT
CVE-2026-39619 — Site: Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.
CVSSv3.1 9.6 (CRITICAL) · EPSS 5th percentile
CWECWE 352TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-08
2026-04-08 09:16Z
CRIT
CVE-2026-39617 — Site: Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
CVSSv3.1 8.5 (HIGH) · EPSS 10th percentile
CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-08
2026-04-08 09:16Z
HIGH
CVE-2026-39486 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through <= 5.1.8.
CVSSv3.1 8.5 (HIGH) · EPSS 11th percentile
CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-08
2026-04-08 09:16Z
HIGH
CVE-2026-39475 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.1.
CVSSv3.1 8.5 (HIGH) · EPSS 10th percentile
CWECWE 89TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-08
2026-04-08 09:16Z
CRIT
CVE-2026-33088 — Sixapart Movable_type: contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary
Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.
CVSSv3.1 9.8 (CRITICAL) · EPSS 27th percentile
CWECWE 89VNDMovableVNDSixapartTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 09:16Z
CRIT
CVE-2026-25776 — Movable: contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl
Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 94VNDMovableTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 09:00Z
HIGH
Financial cyberthreats in 2025 and the outlook for 2026
Kaspersky Securelist·securelist.com
Kaspersky's 2025 financial threat report documents a significant shift in attacker tactics away from traditional PC banking malware toward credential theft via infostealers, mobile banking malware, and highly targeted phishing campaigns. Over 1 million banking accounts from the world's 100 largest banks were compromised and published on dark web resources, with 74% of stolen payment cards remaining valid months or years after theft. Phishing campaigns now heavily target e-commerce, digital services, and gaming platforms with region-specific social engineering, while infostealers surged 59% globally and fuel a thriving dark web economy in stolen credentials, payment data, and identity profiles.
The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a user-supplied URL as a CSS file, extracts URLs from its content, and downloads those files to a publicly accessible directory without validating the file type. This
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDDsgvoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 06:16Z
HIGH
CVE-2026-24913 — SQL: Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be obtained or altered by a user who can log in to the product.
CVSSv3.1 8.8 (HIGH)
CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 05:16Z
CRIT
CVE-2026-4003 — Users: The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via
The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the userspn_ajax_nopriv_server() function within the 'userspn_form_save' case. The conditional only blocks unauthenticated users when the user_id is empty, but when a non-empty user_id is supplied, execution bypasses this check entirely and proceeds to update arbitrary
CVSSv3.1 9.8 (CRITICAL)
CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 02:16Z
HIGH
CVE-2026-3499 — Product: The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin
The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type, ajax_adt_clear_custom_attributes_product_meta_keys, ajax_update_file_url_to_lower_case, ajax_use_legacy_filters_and_rules, and ajax_fix_duplicate_feed functions. This makes it possible for unauthenticate
CVSSv3.1 8.8 (HIGH)
CWECWE 352TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 02:16Z
CRIT
CVE-2026-3296 — Everest: The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms
CVSSv3.1 9.8 (CRITICAL)
CWECWE 502VNDEverestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 02:16Z
HIGH
CVE-2026-33810 — Golang Go: When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
CVSSv3.1 8.2 (HIGH)
CWECWE 1289CWECWE 295TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-08
2026-04-08 02:16Z
CRIT
CVE-2026-27143 — Arithmetic: As a result, the compiler would allow for invalid indexing to occur at runtime
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
CVSSv3.1 9.8 (CRITICAL)
VNDArithmeticTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 02:16Z
HIGH
CVE-2026-27140 — SWIG: file names containing 'cgo' and well-crafted payloads could lead to code smuggling and
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVSSv3.1 8.8 (HIGH)
VNDSwigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 01:16Z
HIGH
CVE-2026-4788 — Ibm Tivoli_netcool\/impact: Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that
IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
CVSSv3.1 8.8 (HIGH)
CWECWE 502VNDIbmVNDLangflowTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 01:16Z
CRIT
CVE-2026-1346 — Ibm Security_verify_access: Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 250VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-08
2026-04-08 00:16Z
HIGH
CVE-2026-1342 — Ibm Security_verify_access: Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
CVSSv3.1 8.5 (HIGH)
CWECWE 829VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-07
2026-04-07 23:15Z
INFO
v9.0.0-rc2
BloodHound releases·github.com
BloodHound v9.0.0-rc2 released with bug fixes and feature additions including query space handling, user-agent parsing correction, DAWGS dependency bump, and new Azure ingestion support for AZContributor on management groups, resource groups, and subscriptions.
SRFApplicationVNDSpecter OpsTYPToolSTGRecon
35
Edit Score
2026-04-07
2026-04-07 22:16Z
CRIT
CVE-2026-39847 — Emmett: From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__
Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbitrary files outside the assets directory. This vulnerability is fixed in 2.8.1.
CVSSv3.1 9.1 (CRITICAL)