WP-SHELLSTORM
| CVE-2026-50746 suspected | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. | CVSS 10.0 |
| CVE-2026-48907 suspected | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | CVSS 9.8 KEV |
| CVE-2026-40138 suspected | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled | CVSS 8.1 |
| CVE-2026-6433 suspected | The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL query, and the result is passed to eval(), allowing unauthenticated users to execute arbitrary PHP code on the server. | CVSS 7.3 |
| CVE-2020-25213 suspected | WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. | KEV |
| CVE-2021-29441 suspected | — | |
| CVE-2025-12057 suspected | — | |
| CVE-2025-34085 suspected | — | |
| CVE-2025-7443 suspected | — | |
| CVE-2025-7852 suspected | — | |
| CVE-2026-0740 suspected | — | |
| CVE-2026-1969 suspected | — | |
| CVE-2026-3844 suspected | — |
| ip | 43.108.17.80 | — | 2026-07-13 |
| ip | 137.175.93.126 | — | 2026-07-13 |
| sha256 | 84f7e396a48913851a10cc78c5cc22a25634564abd0694465236d2f365e2bdee | — | 2026-07-13 |
| ip | 113.196.56.150 | — | 2026-07-13 |
| ip | 113.196.59.51 | — | 2026-07-13 |
| domain | xs.xxooonline.eu.cc | — | 2026-07-13 |