Threat Log

487advisories read
177affect you
310checked and dismissed
As of

Updated every 6 hours
7 of 177 entries
  1. This week Wordfence

    PickPlugins Question Answer

    CVE-2026-10207

    Affects you if you use the PickPlugins Question Answer plugin and the user profile page is reachable from outside.

    A SQL injection via a GET parameter that can be reached without login. An attacker can append additional queries to the database and extract sensitive data. The flaw sits in the user profile output, which is reachable out of the box.

    Exploitation requires no account and no login. Anyone who knows the profile page can manipulate the query.

    Update the plugin to a version after 1.2.73 once the vendor releases a fix. Until then, disable the plugin or block the user profile page for external access.

    Affected
    PickPlugins Question Answer
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 22.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. This week Wordfence

    Premium Packages – Sell Digital Products Securely

    CVE-2026-12800

    Affects you if you run the Premium Packages – Sell Digital Products Securely plugin in version 6.2.0 or earlier and the REST API is reachable from outside.

    An SQL injection via a public REST endpoint of the plugin. An attacker can manipulate database queries without authentication and extract sensitive data from the database.

    The vulnerability is in the coupon endpoint, where user input is passed into a SQL query without proper sanitization. The plugin is common on WordPress installations that sell digital products.

    Update to the latest version of the plugin. If no updated version is available, disable the plugin until a fix is released.

    Affected
    Premium Packages – Sell Digital Products Securely
    Fixed in
    7.0.0
    CVSS
    7.5
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.30 %
    percentile 22.7
    Type
    CWE-89
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. This week Wordfence

    PDFDraft

    CVE-2026-12124

    Affects you if you run the PDFDraft plugin in version 1.1.0 or older and have PDF templates containing customer data, invoices, or order data stored in them.

    A missing capability check on the function that serves PDF templates. Anyone who knows or guesses a template name can download the associated file without logging in. Templates may contain names, invoice, and order data of your customers.

    The flaw is not hard to exploit, but it requires someone to guess or know a template identifier. That lowers the likelihood, but it does not reduce the damage.

    Update to the latest version of the plugin. If that is not possible, disable the plugin until an update is available.

    Affected
    PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
    Fixed in
    1.1.1
    CVSS
    5.3
    source security@wordfence.com
    Login required
    no
    Likely to be exploited
    0.21 %
    percentile 11.2
    Type
    CWE-862
    Actively exploited
    not on the KEV list
    Published
    2026-07-27

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Debian Security

    Exim

    CVE-2026-66140 and 1 more

    Affects you if your server runs Exim as its mail server and it sends mail.

    A mishandling of queue-name arguments allows access to files outside the spool directory. An attacker can use this to gain elevated privileges. The attack requires the mail server to be actively processing messages.

    The source does not name a specific version with the fix. Update Exim to the newest release your distribution provides.

    Affected
    exim4
    CVSS
    8.4
    source cve@mitre.org
    Login required
    no
    Likely to be exploited
    0.27 %
    percentile 19.4
    Type
    CWE-24
    Actively exploited
    not on the KEV list
    Published
    2026-07-24

    Sources: NVD · EPSS · Debian DSA

  5. This week Ubuntu Security

    tar

    CVE-2026-5704

    Affects you if you use tar to receive and extract archives from outside and rely on a pre-extraction check.

    A flaw in tar that allows hidden files with arbitrary content to be placed inside an archive. A pre-extraction check does not see these files. An attacker can thus introduce files onto the system unnoticed if they feed you a crafted archive.

    This vulnerability is not on the KEV catalog of actively exploited flaws. It is rated CVSS 5.0 because an attacker first has to trick you into processing their archive. On its own, that is not a direct system compromise. In an environment that automatically accepts backups, it weighs heavier.

    The source does not name a fixed version. Check incoming archives with a tool that fully lists the contents before you point tar at them.

    Affected
    tar
    CVSS
    5.0
    source secalert@redhat.com
    Login required
    yes, user account
    Likely to be exploited
    0.37 %
    percentile 30.2
    Type
    CWE-434
    Actively exploited
    not on the KEV list
    Published
    2026-07-22

    Sources: NVD · EPSS · Ubuntu USN

  6. Act now Added manually Exploited in the wild

    WordPress Core (wp2shell)

    CVE-2026-63030 and 1 more

    Affects you if you run WordPress 6.9 or 7.0 and the REST API is reachable from outside. Out of the box, it is.

    A route confusion in the REST API batch endpoint. On its own it would be a blemish. Combined with the SQL injection in CVE-2026-60137 it turns into access to your database, with no account, no password, from the outside, and subsequently code execution on the server.

    Both flaws sit in the core, not in a plugin. That means every installation that has not been updated is affected, regardless of which extensions you use.

    Update to 6.9.5 or 7.0.2. The same update closes both holes. If your installation has not been updated since July 17, do not assume nothing happened. Go and look.

    Affected
    WordPress Core (wp2shell)
    CVSS
    9.8
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    95.60 %
    percentile 99.9
    Type
    CWE-436
    Actively exploited
    KEV since 2026-07-21
    Published
    2026-07-17

    Sources: Sicherheitshinweis · Hersteller · NVD · EPSS · CISA KEV

  7. For the record Debian Security

    libheif

    CVE-2025-68431 and 11 more

    Affects you if your servers process HEIF or AVIF images, for example through ImageMagick or WordPress uploads.

    A buffer over-read when decoding HEIF files with crafted overlay data. An attacker can prepare an image that makes the library read past the end of a memory region and crash. The classic path to code execution via an uploaded file is conceivable, even though the source only describes the crash here.

    Update libheif to version 1.21.0. If the update is not yet available for your system, avoid processing images with iovl overlay boxes until it is.

    Affected
    libheif
    CVSS
    6.5
    source security-advisories@github.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 21.1
    Type
    CWE-125, CWE-190
    Actively exploited
    not on the KEV list
    Published
    2025-12-29

    Sources: NVD · EPSS · Debian DSA

310 checked and dismissed, with reasons
  • 170 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 11 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 7 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 7 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 6 advisoriesBetreibt unter meinen Kunden niemand.
  • 6 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
  • 5 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • 3 advisoriesKein Java-Anwendungsserver im Bestand.
  • CVE-2026-5358CVE wurde rejected, NIS+ war nie in Linux enthalten, kein Trust-Boundary-Übertritt – betrifft niemanden.
  • CVE-2026-1933Samba wird in Georges Stack nicht betrieben und erfordert zudem authentifizierten Zugriff.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.
  • CVE-2026-43495Lokaler Bug im WWAN-Treiber, hardware-spezifisch und erfordert ein Konto oder manipuliertes Modem.
  • CVE-2025-37780Lokaler Bug im isofs-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71313Lokaler NULL-Pointer-Bug im PCI-Endpoint-Treiber, hardware-spezifisch und ohne Fernausnutzung.
  • CVE-2026-29167Apache HTTP Server ist nicht Teil des betriebenen Stacks; für Kunden mit Apache-Hostern relevant, aber nicht für Georges betreute Systeme.
  • CVE-2026-46316Diese Kernel-Lücke betrifft KVM auf ARM64, was auf Georges Debian/Ubuntu-Servern nicht vorkommt.
  • CVE-2026-9698cPanel/WHM wird von George nicht betrieben; betrifft nur Kunden, deren Hoster cPanel einsetzt, und ist als Hinweis ohne Handlungsbedarf für Georges Systeme.
  • CVE-2026-46331Lokale Rechteausweitung im Netzwerk-Subsystem des Kernels, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-0864Die Lücke im configparser-Modul von CPython erfordert Kontrolle über geschriebene Werte und ist für die Serverumgebung nicht praktisch ausnutzbar.
  • CVE-2026-52944Diese Kernel-Lücke betrifft ksmbd, den in-kernel SMB-Server, der auf Georges Webservern nicht betrieben wird.
  • CVE-2026-15308Die Lücke im HTML-Parser von CPython ermöglicht nur Denial of Service und erfordert, dass der Parser mit unkontrollierten Daten gefüttert wird, was auf Georges Servern nicht der Fall ist.
  • CVE-2026-13149Die Lücke betrifft Red Hat Ansible Automation Platform, die auf Georges Servern nicht betrieben wird.
  • CVE-2026-58216Samba wird in Georges Umgebung selten betrieben und die Schwachstelle erfordert einen authentifizierten Angreifer mit Denial-of-Service-Wirkung, daher kein Handlungsbedarf.
  • CVE-2026-68083Lokale Kernel-Schwachstelle in ksmbd (SMB-Server), nicht ohne Konto ausnutzbar und nicht aktiv ausgenutzt.
  • CVE-2026-68429Die Meldung betrifft eine Kernel-Race-Condition im DRM-Subsystem, die nur lokalen Zugriff und spezielle Hardware voraussetzt, daher für Georges Server ohne solche Grafikhardware nicht relevant.
  • CVE-2026-23239Lokale Race-Condition im Kernel ohne bekannte Ausnutzung und ohne Fernzugriff; setzt ein lokales Konto voraus, das auf Georges Systemen nicht vorhanden ist.
  • CVE-2025-38617Lokale Kernel-Lücke im packet-Subsystem, die ein Konto auf der Maschine voraussetzt und daher für Georges gehärtete Server nicht relevant ist.
  • CVE-2026-5435Die Lücke in GNU libc betrifft veraltete DNS-Funktionen, die auf Georges Servern nicht verwendet werden.