🔒 Security Intelligence Dashboard

Updated: 2026-08-02 (UTC)
NVD CVEs (today)
3
CISA KEV (added)
0
GH Advisories
4
JVN Items
0
News Articles
20
NVD CVEs — 本日公開 (3 件)
CVE-2026-13339 7.5 HIGH
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensiti
CVE-2026-18352 7.5 HIGH
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensi
CVE-2026-8457 9.8 CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's
CISA Known Exploited Vulnerabilities — 本日追加 (0 件 / 累計 1656 件)

本日の新規追加なし

GitHub Security Advisories — 本日公開 (4 件)
GHSA-qwc9-q2f8-q72q CRITICAL
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all...
GHSA-mxw9-rxrv-85f3 HIGH
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions...
GHSA-2cff-wc4f-2m48 HIGH
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up...
GHSA-fw84-2m38-54m7 UNKNOWN
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
JVN / JPCERT·CC — 最新情報

本日の新着なし

Security News