LIVE · cybersecurity feed
Live wire
vendor

Gvectors

14 CVEs published in the last four months. Exploited flaws first.

Critical1
High4
Medium8
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-221929.9criticalwpdiscuzVoltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticat176d ago
CVE-2026-222028.1highwpdiscuzwpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all com176d ago
CVE-2026-221938.1highwpdiscuzwpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string 176d ago
CVE-2026-221827.5highwpdiscuzwpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to 176d ago
CVE-2026-221997.5highwpdiscuzVoltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.176d ago
CVE-2026-222166.5mediumwpdiscuzwpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to sub176d ago
CVE-2026-221836.1mediumwpdiscuzwpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview function176d ago
CVE-2026-222095.5mediumwpdiscuzwpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administra176d ago
CVE-2026-222015.3mediumwpdiscuzwpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypa176d ago
CVE-2026-221915.2mediumwpdiscuzBeghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary 176d ago
CVE-2026-222034.9mediumwpdiscuzwpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertentl176d ago
CVE-2026-222104.4mediumwpdiscuzwpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious cod176d ago
CVE-2026-222154.3mediumwpdiscuzwpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that a176d ago
CVE-2026-222043.7lowwpdiscuzwpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail r176d ago

Filter the full tracker by Gvectors