Translucid Security

Threat Intelligence

  • Dashboard
  • News
  • CVEs
  • Exploits
  • Ransomware
  • OT / ICS
Translucid Security
ENPT-BR

NVD · CISA KEV · EPSS

CVE Tracker

NVD classification · CISA KEV exploitation · EPSS probability. Choose date or classification order below.

Updating results…

Last 30 days · Medium

Time range
Classification
Exploitation
Search CVEs
Sort order
CVE-2026-97652MediumCVSS 3.1 6.1EPSS 0.5%

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including, 14.16.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

8h ago
CVE-2026-17508MediumCVSS 4.0 5.3EPSS 0.4%

In Bouncy Castle for Java before 1.86, several password-based key derivation entry points ran the KDF with cost parameters taken from the untrusted input being processed, without bounding them, so a small input could dictate an arbitrary amount of work before any password or integrity check could reject it. The affected paths are the RFC 9579 PBMAC1 MAC calculator builders, which took the PBKDF2 iteration count and derived-key length straight out of PBMAC1Params (JcePBMac1CalculatorBuilder, and PKCS12PBEUtils.createPBMac1Calculator reached from PKCS12PfxPdu.isMacValid); the scrypt parallelization parameter p in the PKCS#8 and PKCS#12 cost guards, which bounded only the cost parameter N and the block size r even though the scratch buffer scales with r times p, so the configured memory ceiling could be evaded entirely; the raw JCA PBKDF2 provider (org.bouncycastle.jcajce.provider.symmetric.PBEPBKDF2); and the bcrypt round count read from an encrypted OpenSSH v1 private key's own kdfoptions. Each now bounds the parameter before deriving, in line with the caps already applied elsewhere in the tree, with the OpenSSH round count configurable through the new org.bouncycastle.openssh.max_rounds property. This completes the bounding begun in 1.85 for the PKCS#8 / PBES2 decryptors (CVE-2026-15055). This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

10h ago
CVE-2026-59659MediumCVSS 4.0 4.8EPSS 0.4%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomZonaGeo” parameter is affected – endpoint “/es/geozones/update/149979”.

8h ago
CVE-2026-59660MediumCVSS 4.0 4.8EPSS 0.4%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”.

8h ago
CVE-2026-59661MediumCVSS 4.0 4.8EPSS 0.4%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomRuta” parameter is affected – endpoint “/es/routes/update/693”.

8h ago
CVE-2026-95662MediumCVSS 4.0 4.8EPSS 0.4%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.

8h ago
CVE-2026-59672MediumCVSS 4.0 4.8EPSS 0.4%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomGrupoEmpresarial” parameter is affected – endpoint "/es/corporategroups/update/246”.

8h ago
CVE-2026-59673MediumCVSS 4.0 4.8EPSS 0.4%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTipoCli” parameter is affected – endpoint “/es/clientypes/update/109441”.

8h ago
CVE-2026-85492MediumCVSS 3.1 6.1EPSS 0.4%

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user visits a crafted URL. Exploitation requires the victim to hold the aioseo_manage_seo capability and to open the SEO Preview panel in the WordPress admin toolbar while visiting a page with a malicious payload embedded in the URL pathname.

8h ago
CVE-2026-104403MediumCVSS 3.1 5.3EPSS 0.3%

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.

8h ago
CVE-2026-104123MediumCVSS 4.0 5.5EPSS 0.3%

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

15h ago
CVE-2026-94405MediumCVSS 3.1 5.3EPSS 0.3%

Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.

8h ago
CVE-2026-59669MediumCVSS 4.0 4.8EPSS 0.3%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “name” parameter is affected – endpoint “/es/attachmenttypes/update/203336”

9h ago
CVE-2026-12951MediumCVSS 3.1 6.5EPSS 0.3%

The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up to and including 5.0.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query — the value is concatenated directly into an ORDER BY clause where esc_sql() (which only neutralizes characters needed to break out of quoted string literals) provides no protection. This makes it possible for authenticated attackers, with vendor-level access and above (users granted the 'edit_stores' capability), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

10h ago
CVE-2026-104120MediumCVSS 4.0 5.5EPSS 0.3%

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

15h ago
CVE-2026-59670MediumCVSS 4.0 4.8EPSS 0.3%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomListaValidacion” parameter is affected – endpoint “/es/validationslists/assignList/Employee/45659”.

9h ago
CVE-2026-59671MediumCVSS 4.0 4.8EPSS 0.3%

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The endpoint “/es/datatables/getemployeetypesdatatable” is affected.

9h ago
CVE-2026-97634MediumCVSS 3.1 6.5EPSS 0.3%

The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. A Contributor-level user can reach the vulnerable code path by supplying a post_id they authored, as the can_access_page() gate requires only post authorship rather than the edit_others_posts capability for post owners.

10h ago
CVE-2026-94180MediumCVSS 3.1 4.3EPSS 0.3%

Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26.

8h ago
CVE-2026-80464MediumCVSS 3.1 4.9EPSS 0.3%

Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.

9h ago
CVE-2026-94432MediumCVSS 3.1 5.3EPSS 0.3%

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through wp_ajax_nopriv_latepoint_route_call. The handler loads an OsInvoiceModel by a sequential integer 'invoice_id' with no access-key/UUID or ownership check (the sibling Stripe and Razorpay handlers require a 128-bit access-key UUID via OsInvoicesHelper::get_invoice_by_key), and then calls OsTransactionIntentHelper::create_or_update_transaction_intent() which persists a transaction intent tied to the target invoice's customer_id, order_id and charge_amount and regenerates its intent_key before the PayPal-configured guard is reached. This makes it possible for unauthenticated attackers to enumerate invoices belonging to arbitrary customers, create unauthorized transaction-intent rows linked to another customer's data, and overwrite the intent_key of any in-flight NEW-status transaction intent — invalidating the intent_key that legitimate Stripe/Razorpay flows are waiting on and breaking payment webhooks for those customers.

10h ago
CVE-2026-91020MediumCVSS 3.1 5.3EPSS 0.3%

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to submit an arbitrary or negative amount, bypassing the configured denominations and manipulating the order total to obtain products without paying.

11h ago
CVE-2026-13413MediumCVSS 3.1 5.3EPSS 0.2%

The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request so it is mistaken for a login request.

11h ago
CVE-2026-90987MediumCVSS 3.1 5.3EPSS 0.2%

The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.

11h ago
CVE-2026-90952MediumCVSS 3.1 5.3EPSS 0.2%

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.

11h ago

Showing 1–25 of 4830 CVEs

Page 1 of 194