Threat Log

723advisories read
487affect you
236checked and dismissed
As of

Updated every 6 hours
Subscribe via RSS
7 of 487 entries
  1. For the record Wordfence

    GiveWP – Donation Plugin and Fundraising Platform

    CVE-2026-66690

    Affects you if you run the GiveWP donation plugin in a version up to and including 4.16.5 on your WordPress site.

    An attacker can place malicious code in donation forms without logging in. The code executes whenever someone accesses the affected page. The plugin is widely used, so the likelihood that this vulnerability is being actively sought out is high.

    Update GiveWP to version 4.16.5.1.

    Affected
    GiveWP – Donation Plugin and Fundraising Platform
    Fixed in
    4.16.5.1
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  2. For the record Wordfence

    Rank Math SEO

    CVE-2026-66702

    Affects you if you run Rank Math SEO in versions up to and including 1.0.274.1.

    A stored cross-site scripting vulnerability that can be triggered without authentication. An attacker can deposit scripts that execute whenever someone accesses an affected page. Rank Math SEO is very widely used, which is why this entry is here even though it is not listed in the KEV catalog of actively exploited vulnerabilities.

    Update to version 1.0.275.

    Affected
    Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
    Fixed in
    1.0.275
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  3. For the record Wordfence

    Meta for WooCommerce

    CVE-2026-66707

    Affects you if you run Meta for WooCommerce in a version up to and including 3.7.5.

    An attacker can exploit a stored cross-site scripting vulnerability without logging in. The malicious script stays on the server and runs in the browser of every visitor who loads the affected page. This allows session takeover, hijacking of administrator accounts, or using the site for phishing.

    Update to version 3.7.6.

    Affected
    Meta for WooCommerce
    Fixed in
    3.7.6
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 5.2
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  4. For the record Wordfence

    Meta pixel for WordPress

    CVE-2026-66705

    Affects you if you run Meta pixel for WordPress in a version up to and including 5.2.1.

    A stranger can trigger a stored cross-site scripting vulnerability without logging in. The plugin is widely installed, so the likelihood of someone trying is high.

    Update to version 5.2.2.

    Affected
    Meta pixel for WordPress
    Fixed in
    5.2.2
    CVSS
    7.1
    source audit@patchstack.com
    Login required
    no
    Likely to be exploited
    0.15 %
    percentile 4.4
    Type
    CWE-79
    Actively exploited
    not on the KEV list
    Published
    2026-07-31

    Sources: NVD · EPSS · Wordfence
    Includes data from the CVE Program, © MITRE Corporation.

  5. Act now Added manually Exploited in the wild

    WordPress Core (wp2shell)

    CVE-2026-63030 and 1 more

    Affects you if you run WordPress 6.9 or 7.0 and the REST API is reachable from outside. Out of the box, it is.

    A route confusion in the REST API batch endpoint. On its own it would be a blemish. Combined with the SQL injection in CVE-2026-60137 it turns into access to your database, with no account, no password, from the outside, and subsequently code execution on the server.

    Both flaws sit in the core, not in a plugin. That means every installation that has not been updated is affected, regardless of which extensions you use.

    Update to 6.9.5 or 7.0.2. The same update closes both holes. If your installation has not been updated since July 17, do not assume nothing happened. Go and look.

    Affected
    WordPress Core (wp2shell)
    CVSS
    9.8
    source contact@wpscan.com
    Login required
    no
    Likely to be exploited
    95.60 %
    percentile 99.9
    Type
    CWE-436
    Actively exploited
    KEV since 2026-07-21
    Published
    2026-07-17

    Sources: Sicherheitshinweis · Hersteller · NVD · EPSS · CISA KEV

  6. For the record Debian Security

    python-httplib2

    CVE-2026-59939

    Affects you if you run Python applications on the server that use httplib2. The situation report itself is among them.

    httplib2 decompresses incoming HTTP responses without a size limit. A remote server can send a tiny compressed response that expands to an arbitrary size in memory and kills the process with a memory error. That is enough to take the service down.

    The issue is fixed in version 0.32.0.

    Update python-httplib2 to 0.32.0.

    Affected
    python-httplib2
    CVSS
    7.5
    source security-advisories@github.com
    Login required
    no
    Likely to be exploited
    0.41 %
    percentile 34.1
    Type
    CWE-409
    Actively exploited
    not on the KEV list
    Published
    2026-07-08

    Sources: NVD · EPSS · Debian DSA

  7. For the record Debian Security

    libheif

    CVE-2025-68431 and 11 more

    Affects you if your servers process HEIF or AVIF images, for example through ImageMagick or WordPress uploads.

    A buffer over-read when decoding HEIF files with crafted overlay data. An attacker can prepare an image that makes the library read past the end of a memory region and crash. The classic path to code execution via an uploaded file is conceivable, even though the source only describes the crash here.

    Update libheif to version 1.21.0. If the update is not yet available for your system, avoid processing images with iovl overlay boxes until it is.

    Affected
    libheif
    CVSS
    6.5
    source security-advisories@github.com
    Login required
    no
    Likely to be exploited
    0.29 %
    percentile 21.3
    Type
    CWE-125, CWE-190
    Actively exploited
    not on the KEV list
    Published
    2025-12-29

    Sources: NVD · EPSS · Debian DSA

236 checked and dismissed, with reasons
  • 162 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
  • 9 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
  • 6 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
  • 2 advisoriesBetreibt unter meinen Kunden niemand.
  • 2 advisoriesKein Java-Anwendungsserver im Bestand.
  • 2 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
  • 1 advisoryNicht im Bestand.
  • 1 advisoryKeine Netzwerkgeraete dieser Hersteller im Bestand.
  • CVE-2026-1933Samba wird in Georges Stack nicht betrieben und erfordert zudem authentifizierten Zugriff.
  • CVE-2026-64561Lokale Rechteausweitung im KVM-Subsystem, setzt ein Konto auf der Maschine voraus und betrifft nur Virtualisierungsumgebungen, die George nicht betreibt.
  • CVE-2026-7444CSRF erfordert Benutzerinteraktion, nicht aktiv ausgenutzt und geringe Verbreitung; kein dringender Handlungsbedarf.
  • CVE-2025-38238Lokale Kernel-Schwachstelle in einem Fibre-Channel-Treiber, der auf den Servern nicht vorkommt; kein Handlungsbedarf.
  • CVE-2023-38709Betrifft Apache HTTP Server, den George nicht betreibt; für Kunden mit Apache-Hostern nur ein Hinweis, kein Handlungsbedarf für Georges Systeme.
  • CVE-2024-50047Lokale Kernel-Schwachstelle im CIFS-Treiber ohne KEV und ohne Fernzugriff, betrifft Georges Server nicht unmittelbar.
  • CVE-2020-24588Wi-Fi-Schwachstelle betrifft Arbeitsplatzgeräte, nicht die gehärteten Server; kein Handlungsbedarf.
  • CVE-2025-38554Lokale UAF im VMA-Management, erfordert lokales Konto und ist eine Race-Condition ohne praktische Fernausnutzung.
  • CVE-2024-58239Lokale Kernel-Schwachstelle im TLS-Subsystem ohne KEV und ohne Fernzugriff, keine unmittelbare Gefahr für die Server.
  • CVE-2025-39891Lokale Kernel-Schwachstelle im WLAN-Treiber, nicht auf Servern relevant.
  • CVE-2025-40110Lokale Kernel-Schwachstelle im DRM-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2025-40178Lokaler NULL-Pointer-Bug in PID-Namespaces, erfordert lokales Konto und hat keine Fernausnutzung.
  • CVE-2025-40214Lokale Kernel-Schwachstelle in AF_UNIX, setzt lokalen Zugriff voraus und ist nicht aktiv ausgenutzt.
  • CVE-2018-1000204Alter SCSI-ioctl-Bug, erfordert CAP_SYS_ADMIN und CAP_SYS_RAWIO, dritter Seite wird Relevanz bestritten.
  • CVE-2025-68767Lokaler Bug im hfsplus-Dateisystem, setzt ein Konto voraus und betrifft ein Dateisystem, das auf Georges Servern nicht vorkommt.
  • CVE-2025-71102Lokaler Bug im Shadow-Call-Stack-Debug-Code, nur bei aktiviertem CONFIG_DEBUG_STACK_USAGE relevant und ohne Fernausnutzung.
  • CVE-2025-71180Lokale Kernel-Schwachstelle im Counter-Subsystem ohne KEV und ohne Fernzugriff, keine Relevanz für die Server.
  • CVE-2025-71192Lokale Kernel-Schwachstelle im ALSA-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2025-71225Lokaler Bug im md-RAID-Treiber, setzt ein Konto voraus und betrifft Software-RAID, das George nicht einsetzt.
  • CVE-2026-23279Lokale Kernel-Schwachstelle im WLAN-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2026-23396Lokale Kernel-Schwachstelle im WLAN-Treiber ohne KEV und ohne Fernzugriff, keine Relevanz für die Server.
  • CVE-2026-31535Lokaler Bug im SMB-Client, erfordert ein Konto und betrifft SMB-Client-Funktionalität, die auf Georges Servern nicht aktiv ist.
  • CVE-2026-23234Lokale UAF im f2fs-Dateisystem, erfordert ein Konto und ein loop-Device, betrifft Georges Server nicht.
  • CVE-2026-43476Lokale Kernel-Schwachstelle im IIO-Treiber ohne KEV und ohne Fernzugriff, betrifft die Server nicht.
  • CVE-2026-32792Unbound wird in Georges Stack nicht betrieben und die Lücke betrifft nur DNSCrypt-Unterstützung.