Skip to main content

WPFunnels WooCommerce Plugin Unauthenticated Log Injection Leads to Remote Code Execution (CVE-2026-14345)

Scope: WPFunnels Funnel Builder for WooCommerce Plugin Versions up to and Including 3.12.7

GitHub Enterprise Server Stored XSS via Markdown Rendering Allows Session Hijacking (CVE-2026-11962)

Scope: GitHub Enterprise Server Versions 3.10.0 to 3.10.10, 3.11.0 to 3.11.7, and 3.12.0 to 3.12.3

WinRAR RAR5 Heap Overflow Enables Remote Code Execution via Malicious Recovery Volume Files (CVE-2026-14191)

Scope: WinRAR, Command-line RAR, and UnRAR (All Versions Prior to 7.23) on Windows, macOS, Linux, An

Veeam Backup and Replication Remote Code Execution via Deserialization Allows Domain User Takeover (CVE-2026-44963)

Scope: Veeam Backup and Replication Version 12.x (All Builds up to and Including 12.3.2.4465) Joined

SimpleHelp RMM Authentication Bypass Under Active Exploitation Delivering TaskWeaver and Djinn Stealer (CVE-2026-48558)

Scope: SimpleHelp Remote Monitoring and Management (RMM) Versions 5.5.15 and Earlier, and 6.0 Pre-Re

EventON WordPress Plugin SQL Injection Exposes Database Contents (CVE-2026-9711)

Scope: EventON WordPress Plugin (Versions Affected, Exact Range Unspecified in Source Material)

Open VSX Registry Stored XSS Enables Supply Chain Attack Against VS Code, Cursor, and Windsurf (CVE-2026-13323)

Scope: Open VSX Registry Versions Prior to 1.0.2 (Affects VS Code, VSCodium, Cursor, Windsurf, and O

Subscribe to Advisories