๐Ÿ” CVE Alert

Real-Time CVE Alerts & Vulnerability Tracker

Search enriched vulnerability intelligence โ€” EPSS exploitability scores, CVSS severity, CISA KEV status โ€” and get instant alerts to Slack, Telegram, Discord or Google Chat.

โšก Immediate or digest alerts ๐ŸŽฏ Filter by ecosystem, severity, EPSS ๐Ÿ”‘ CISA KEV tracking ๐Ÿ†“ Free forever

282,649 results

CVE-2026-87915HIGH 7.2

Popup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter

The Popup Maker โ€“ Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses sanitization applied on output is insufficient in this context because HTML entities within allowed attribute values survive normalization intact and are later evaluated by the jQuery(link.attr('href')) sink in wp-admin/js/common.js when a contextual help tab anchor is clicked.

EPSS
0.0%
danieliser / popup maker โ€“ boost sales, conversions, optins, subscribers with the ultimate wp popup builderSep 18, 2026
CVE-2026-15797MEDIUM 6.4

Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_title

The Popup Maker โ€“ Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.

EPSS
0.0%
danieliser / popup maker โ€“ boost sales, conversions, optins, subscribers with the ultimate wp popup builderSep 18, 2026
CVE-2026-90884MEDIUM 5.4

WP Recipe Maker <= 10.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

EPSS
0.0%
brechtvds / wp recipe makerSep 18, 2026
CVE-2026-18405HIGH 7.2

Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content

The Jeg Kit for Elementor โ€“ Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.2.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the targeted post also renders a legitimate Jeg Kit Countdown widget, which causes the countdown frontend script to be enqueued and to initialize on any matching DOM element โ€” including forged widget markup stored in comments.

EPSS
0.0%
jegtheme / jeg kit for elementor โ€“ powerful addons for elementor, widgets & templates for wordpressSep 18, 2026
CVE-2026-21822MEDIUM 6.3

A path traversal vulnerability has been identified in HCL AppScan 360ยฐ (CVE-2026-21822).

HCLSoftware AppScan 360ยฐ was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification within the application's directory scope.

EPSS
0.0%
hcl software / hcl appscan 360ยฐSep 18, 2026
CVE-2026-40539HIGH 7.1

No title available

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40538LOW 3.7

No title available

An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to read limited files via brute-force attacks.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40535MEDIUM 6.5

No title available

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40533MEDIUM 5.3

No title available

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-85410HIGH 8.1

Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter

The Master Addons for Elementor โ€“ Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to modify the title and metadata of arbitrary WordPress posts or permanently delete arbitrary WordPress posts by supplying an attacker-controlled popup_id. The required nonce is emitted on the edit-jltma_popup admin screen, which is accessible to Contributors because the jltma_popup custom post type is registered with capability_type='post'.

EPSS
0.0%
pixarlabs / master addons for elementor โ€“ elementor addons, widgets, mega menu builder, popup builder, widget builder & template kitsSep 18, 2026
CVE-2026-83561HIGH 7.2

Complianz GDPR/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex

The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie/script blocker enabled.

EPSS
0.0%
complianz / complianz gdpr/ccpa cookie consent bannerSep 18, 2026
CVE-2025-13533MEDIUM 4.4

CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Assignment Engine Fields

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment data. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the CJT block edit screen in the admin dashboard.

EPSS
0.0%
wipeoutmedia / css & javascript toolboxSep 18, 2026
CVE-2026-40537MEDIUM 4.3

No title available

A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40536MEDIUM 4.3

No title available

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40534MEDIUM 5.4

No title available

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40532MEDIUM 6.5

No title available

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40531MEDIUM 4.3

No title available

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct limited denial-of-service attacks.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-4036MEDIUM 6.5

No title available

An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-40530HIGH 8.0

No title available

An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.

EPSS
0.0%
synology / diskstation manager (dsm)Sep 18, 2026
CVE-2026-56595LOW 3.1

HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.

EPSS
0.0%
hcl software / hcl bigfix service managementSep 18, 2026

Never miss a critical vulnerability

Set up free alerts in 60 seconds. Filter by ecosystem, CVSS score or EPSS โ€” get notified to Slack, Telegram, Discord or Google Chat the moment a new CVE matches.

Set Up Free Alerts โ†’ Create Free Account

Slack ยท Telegram ยท Discord ยท Google Chat