Full Disclosure·2h agoSCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education#xss#stored-xss#h5pVulnerability 2 sources
GBHackers·1d ago criticalHackers Exploit Check Point 0-Day Flaw to Execute Code on Management Servers#check-point#cve-2026-93616#zero-day 15 sources in the wild 3 min
CISA Advisories·2d ago highSiemens Siveillance Control#siemens#siveillance-control#cve-2026-50093CVE-2026-50093 5 sources 4 min
Full Disclosure·4d ago high[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8)#ecava#integraxor#scadaExploit / PoC 3 sources
Infosecurity Magazine·10d ago highPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug#cve-2026-27540#file-upload#rce in the wild 2 min
SOCRadar·10d ago highCVE-2026-27540 WooCommerce Flaw Exploited#exploitation#file-upload#plugin in the wild1
BleepingComputer·11d ago highHackers target WordPress sites via third-party WooCommerce plugin#cve#file-upload#plugin in the wild 2 min2
GBHackers·11d ago highHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors#cve-2026-27540#file-upload#rce in the wild 4 min
Cyber Security News·11d ago highHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login#cve-2026-27540#file-upload#webshell in the wild 5 min
Wordfence·12d ago highAttackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin#exploitation#file-upload#plugin in the wild1
Sansec (Magento / e-commerce security)·17d ago highAmasty patches dozens of Magento extensions, 2 critical#adobe-commerce#amasty#e-commerce 10 min
SOCRadar·22d ago criticalElementor Pro RCE Flaw Under Active Attack#active-exploitation#elementor#elementor-pro in the wild
The Hacker News·Aug 20, 2026 highElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code#elementor-pro#file-upload#patchstack 3 min1
Patchstack·Aug 19, 2026 highCritical Unauthenticated File Upload to RCE in Elementor Pro Plugin#elementor-pro#file-upload#patchstack
Joomla Security Centre·Aug 17, 2026[20260810] - Core - Unrestricted uploads of SHTML files#cms#code-execution#cve-2026-73373CVE-2026-73373
Exploit-DB·Aug 17, 2026[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload#ecommerce#file-upload#pocExploit / PoC
Patchstack·Aug 12, 2026 highWhen a PNG Isn’t a PNG: WordPress Patches an Author-Level Imagick RCE#file-upload#imagemagick#imagickVulnerability