PoC Archive PoC Archive

Proof-of-concept research filed under the web category.

Entries

438

in web

CISA KEV

64

exploited in the wild

Ransomware

20

known campaign use

Unpatched

160

no vendor fix

Critical

250

57% of listed

438 entries

Severity

Exploitation signals

Patch status

Date range

→
Sort

438 result(s)

WEB LIST 438 shown · 438 indexed
PoC titleSeverity
WordPress Divi Ajax Filter LFI (CVE-2026-11613)
CVE-2026-11613 web Unverified
CRITICAL 9.8
PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078)
CVE-2026-81578, CVE-2026-82078 web Unverified
CRITICAL 9.8
WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CRITICAL 10
React Router Session Path Traversal (CVE-2025-61686)
CVE-2025-61686 web Unverified
CRITICAL 9.1
Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
CVE-2026-75604 web Unverified
CRITICAL 9
Kestra Authentication Bypass to RCE (CVE-2026-49869)
CVE-2026-49869, CVE-2026-53576 web Unverified
CRITICAL 10
PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 / GHSA-x692-q9x7-8c3f web Unverified
CRITICAL 9.8
nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 web Patched
CRITICAL 9.8
Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web Patched
CRITICAL 10
WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
HIGH 8.9
TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077) KEV EPSS 88%
CVE-2026-63077 web Patched
CRITICAL 9.8
Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882) KEV RW EPSS 100%
CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025) web Patched
CRITICAL 9.8
GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CRITICAL 10
Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004) KEV EPSS 85%
CVE-2026-60004 web Patched
HIGH 8.8
CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CRITICAL 10
Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory) web Patched
HIGH 7.5
IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198) KEV EPSS 35%
CVE-2026-9198 web Patched
CRITICAL 9.8
Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432) KEV EPSS 100%
CVE-2025-32432 web Patched
CRITICAL 10
Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988) EPSS 15%
CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459) web Patched
CRITICAL 9.8
Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723) EPSS 16%
CVE-2026-16723 web Unpatched
CRITICAL 9
Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066) EPSS 28%
CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) web Patched
CRITICAL 9.5
MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports & Sharing Groups (CVE-2026-56423)
CVE-2026-56423 web Patched
HIGH 8.8
Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522) KEV EPSS 85%
CVE-2026-50522 web Patched
CRITICAL 9.8
Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
CVE-2026-57830 web Patched
CRITICAL 9.1
Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CRITICAL 9.8
GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News) web Unverified
CRITICAL
Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7) web Patched
CRITICAL 9.8
Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
CVE-2026-54350 (GHSA-8qv3-p479-cj62) web Patched
CRITICAL 10
Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
CVE-2026-49230 web Patched
CRITICAL 9.1
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CRITICAL 9.1
SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CRITICAL 10
LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
CVE-2026-58116 web Patched
CRITICAL 9.8
Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255) KEV
CVE-2026-55255 (GHSA-qrpv-q767-xqq2) web Patched
HIGH 8.4
Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CRITICAL 10
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CRITICAL 9.8
Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CRITICAL 9.1
ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
HIGH 7.5
Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CRITICAL 9.8
Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CRITICAL 9.8
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296) KEV EPSS 72%
CVE-2021-25296 web Patched
HIGH 8.8
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297) KEV EPSS 57%
CVE-2021-25297 web Patched
HIGH 8.8
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298) KEV EPSS 75%
CVE-2021-25298 web Patched
HIGH 8.8
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CRITICAL 9.8
Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4) web Patched
CRITICAL 9.8
XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893) KEV EPSS 100%
CVE-2025-24893 web Patched
CRITICAL 9.8
WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170 web Unpatched
CRITICAL 9.8
WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390 web Patched
CRITICAL 10
WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CRITICAL 10
WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901 web Patched
CRITICAL 9.8
WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
CVE-2025-5947 web Unverified
CRITICAL 9.8
WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CRITICAL 9.8
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CRITICAL 9.8
Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812) KEV EPSS 93%
CVE-2025-47812 web Patched
CRITICAL 10
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CRITICAL 10
WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CRITICAL 9.8
TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CRITICAL 10
ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888 web Unverified
CRITICAL 9.8
ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
CVE-2025-34282 web Patched
CRITICAL 9.1
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CRITICAL 9.8
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CRITICAL 9.8
Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243 web Unpatched
CRITICAL 10
Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389) EPSS 76%
CVE-2025-6389 web Unverified
CRITICAL 9.8
SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001) KEV RW EPSS 86%
CVE-2025-52691 web Patched
CRITICAL 10
Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334 web Unverified
CRITICAL 9.8
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CRITICAL 9.8
SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324) KEV RW EPSS 100%
CVE-2025-31324 web Patched
CRITICAL 10
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CRITICAL 9.8
Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113) KEV EPSS 99%
CVE-2025-49113 web Patched
CRITICAL 9.9
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209 web Unpatched
CRITICAL 9.8
Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CRITICAL 9.8
React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182) KEV RW EPSS 100%
CVE-2025-55182 web Patched
CRITICAL 10
Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CRITICAL 10
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
CVE-2025-61922 web Patched
CRITICAL 9.1
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391 web Patched
CRITICAL 9.8
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147 web Unverified
CRITICAL 9.8
pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
CVE-2025-13780 web Unverified
CRITICAL 9.1
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945) EPSS 54%
CVE-2025-2945 web Patched
CRITICAL 9.9
Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757) KEV EPSS 88%
CVE-2025-61757 web Unpatched
CRITICAL 9.8
Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934) EPSS 25%
CVE-2025-6934 web Unverified
CRITICAL 9.8
Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 web Patched
CRITICAL 9
Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CRITICAL 9.8
Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 web Patched
CRITICAL 9.8
Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966) EPSS 34%
CVE-2026-27966 (GHSA-3645-fxcv-hqr4) web Patched
CRITICAL 9.8
Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294) EPSS 78%
CVE-2025-2294 web Unverified
CRITICAL 9.8
KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CRITICAL 9.8
JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440 web Unverified
CRITICAL 9.8
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916) EPSS 84%
CVE-2025-47916 web Patched
CRITICAL 10
Hoverfly Middleware Command Injection to RCE (CVE-2025-54123) EPSS 11%
CVE-2025-54123 web Patched
CRITICAL 9.8
Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115) EPSS 19%
CVE-2025-41115 web Patched
CRITICAL 10
Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611) KEV EPSS 53%
CVE-2025-14611 web Unverified
CRITICAL 9.8
GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CRITICAL 9.8
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 web Patched
CRITICAL 9.8
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819) KEV EPSS 88%
CVE-2025-57819 web Patched
CRITICAL 9.8
Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CRITICAL 9.8
Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CRITICAL 9.8
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434) EPSS 50%
CVE-2025-58434 web Patched
CRITICAL 9.8
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528) EPSS 87%
CVE-2025-59528 web Patched
CRITICAL 10
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459) EPSS 19%
CVE-2025-64459 web Patched
CRITICAL 9.1
DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002) EPSS 47%
CVE-2025-49002 web Patched
CRITICAL 9.8
CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309) KEV EPSS 95%
CVE-2025-54309 web Patched
CRITICAL 9
Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
CVE-2025-14700 web Unverified
CRITICAL 9.9
Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595 web Unverified
CRITICAL 9.8
camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
CVE-2026-33453 web Unverified
CRITICAL 9.8
Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)
CVE-2025-23048 web Patched
CRITICAL 9.1
Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
CVE-2026-27172 web Patched
CRITICAL 9.8
AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597 web Unverified
CRITICAL 9.8
AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CRITICAL 9.8
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236) KEV EPSS 95%
CVE-2025-54236 web Patched
CRITICAL 9.1
Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253) KEV EPSS 88%
CVE-2025-54253 web Unverified
CRITICAL 10
ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486) EPSS 68%
CVE-2025-13486 web Unverified
CRITICAL 9.8
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354 web Unpatched
CRITICAL 9.8
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470 web Patched
HIGH 8.8
ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
CVE-2026-28286 web Unverified
CRITICAL
YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937 web Unverified
HIGH 7.2
YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
CVE-2026-44595 / GHSA-p2rj-mrmc-9w29 web Patched
MEDIUM 4.3
YAMCS Missing Rate Limiting on Authentication Endpoint (CVE-2026-44596)
CVE-2026-44596 / GHSA-w5r6-mcgq-7pq4 web Patched
MEDIUM 5.3
XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
CVE-2026-33137 web Patched
CRITICAL 9.3
Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912 web Patched
CRITICAL 9.1
WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357) EPSS 33%
CVE-2026-1357 web Unverified
CRITICAL
WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105 web Unverified
HIGH 8.1
WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
CVE-2026-40791 web Patched
HIGH 7.2
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379 web Patched
CRITICAL 8.6
WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085 web Unverified
HIGH 8.1
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 web Unverified
HIGH 8.8
WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806 web Patched
CRITICAL 9.8
WordPress User Language Switch Plugin SSRF — CVE-2026-0745
CVE-2026-0745 (GHSA-m38c-5p3m-p7gm) web Unverified
MEDIUM
WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417 web Unverified
CRITICAL 9.8
WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740 EPSS 63%
CVE-2026-0740 web Unverified
HIGH
WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
CVE-2026-4106 web Unverified
HIGH
WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
CVE-2026-39676 web Unverified
MEDIUM
WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
HIGH
WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844) EPSS 28%
CVE-2026-3844 web Unverified
CRITICAL
WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
CVE-2026-0594 web Unverified
MEDIUM
WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
CVE-2026-3629 web Unverified
CRITICAL
WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359 web Unverified
CRITICAL
WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
HIGH 8.1
WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CRITICAL 9.8
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807 web Unverified
INFO
Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
CVE-2026-44403 web Patched
HIGH
WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp web Patched
HIGH
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555 web Unverified
CRITICAL 9.8
WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)
CVE-2026-27778 web Patched
MEDIUM
Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
CVE-2026-24126 web Patched
HIGH 6.5
WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
CVE-2026-43700 web Unverified
HIGH
WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)
CVE-2026-20643 web Unverified
MEDIUM
WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)
CVE-2026-43735 web Unverified
HIGH
VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
CVE-2026-5615 web Patched
HIGH 8.5
Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748 web Unverified
HIGH 7.2
Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
CVE-2026-37064 web Unverified
MEDIUM
Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
CVE-2026-37066 web Unverified
HIGH
Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
CVE-2026-37067 web Unverified
MEDIUM
Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068 web Unverified
CRITICAL
Veno File Manager Arbitrary File Deletion (CVE-2026-37065)
CVE-2026-37065 web Unverified
HIGH
Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
CVE-2026-37069 web Unverified
LOW
Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072 web Unverified
CRITICAL
Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
CVE-2026-37073 web Unverified
MEDIUM
Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
CVE-2026-37070 web Unverified
MEDIUM
Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
CVE-2026-37071 web Unverified
HIGH
Vendure GraphQL Admin API Authentication Timing Attack / User Enumeration (CVE-2026-25050)
CVE-2026-25050 web Patched
MEDIUM
Vaultwarden Organization Collection Permissions Bypass & Cipher Enumeration (CVE-2026-26012)
CVE-2026-26012 (GHSA-h265-g7rm-h337) web Patched
MEDIUM 6.5
User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CRITICAL 9.8
User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492) EPSS 24%
CVE-2026-1492 web Unverified
CRITICAL 9.8
User Registration & Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)
CVE-2026-6145 web Unverified
MEDIUM 5.3
UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795 web Unverified
CRITICAL
Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
CVE-2026-35037 web Patched
HIGH
TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
CVE-2026-27621 (GHSA-xfvg-8v67-j7wp) web Patched
MEDIUM
Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
CVE-2026-33712 web Patched
HIGH
Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
CVE-2026-7671 web Unverified
MEDIUM
Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
CVE-2026-41901 web Patched
CRITICAL
The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CRITICAL 9.3
Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)
CVE-2026-22804 (GHSA-m3cv-5hgp-hv35) web Patched
HIGH
TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)
CVE-2026-26903 web Patched
MEDIUM
Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx) web Patched
MEDIUM 4.9
Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886 web Patched
CRITICAL
Spring Security Lazy Header Writing Security Header Bypass (CVE-2026-22732)
CVE-2026-22732 web Patched
CRITICAL 9.1
Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738 web Patched
CRITICAL 9.8
Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251) EPSS 32%
CVE-2026-20251 web Unverified
HIGH 8.8
Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
CVE-2026-7465 web Unverified
CRITICAL 8.8
SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh) web Patched
CRITICAL 9.5
Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CRITICAL
SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
CVE-2026-0001 (tracked publicly as WT-2026-0001) web Patched
CRITICAL 9
SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423 KEV RW EPSS 88%
CVE-2026-24423 web Unverified
CRITICAL
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760) KEV RW EPSS 96%
CVE-2026-23760 web Patched
CRITICAL 9.3
Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
CVE-2026-34227 (GHSA-6fpf-248c-m7wm) web Unverified
HIGH
SimpleHelp OIDC Authentication Bypass (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CRITICAL 9.8
Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459 web Unverified
HIGH 7.5
Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912 web Patched
HIGH 7.5
Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
CVE-2026-23498 web Patched
HIGH
Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951
CVE-2026-30951 web Patched
HIGH
School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
CVE-2026-37750 web Unverified
MEDIUM 6.1
Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067 web Unverified
HIGH 8.1
samlify SAML AttributeValue XML Injection → Privilege Escalation (CVE-2026-46490)
CVE-2026-46490 / GHSA-34r5-q4jw-r36m web Patched
HIGH 8.8
Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)
CVE-2026-23499 web Patched
HIGH
Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)
CVE-2026-22849 (GHSA-8jcj-r5g2-qrpv) web Patched
HIGH
Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
CVE-2026-24136 web Patched
HIGH 7.5
Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
CVE-2026-29198 web Patched
CRITICAL
Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023 web Unpatched
CRITICAL
Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
CVE-2026-4802 web Unpatched
HIGH
Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
CVE-2026-27579 (GHSA-qh5m-p8jh-hx88) web Unverified
HIGH 7.4
rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179 web Patched
CRITICAL 9.8
Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)
CVE-2026-39324 / GHSA-33qg-7wpp-89cq web Patched
CRITICAL
ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
CVE-2026-41462 web Patched
CRITICAL 9.8
Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926 web Unverified
HIGH
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 (Huntr bounty e2e88a0f-a8f6-49c9-94c5-e98dc385f07a) web Patched
HIGH
PraisonAI API Server Missing Authentication (CVE-2026-44338) EPSS 29%
CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6rmh-7xcm-cpxj) web Patched
HIGH
Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
CVE-2026-40487 / GHSA-44wg-r34q-hvfx web Patched
HIGH 8.9
PolarLearn Forum Vote Count Manipulation (CVE-2026-25126)
CVE-2026-25126 web Patched
MEDIUM
PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
CVE-2026-44166 / [GHSA-pq7p-mc74-g65w](https://github.com/pocketbase/pocketbase/security/advisories/GHSA-pq7p-mc74-g65w) web Patched
MEDIUM 6.1
Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CRITICAL
phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
CVE-2026-42569 web Patched
CRITICAL
phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584
CVE-2026-55584 / GHSA-786w-p5pm-cvgh web Patched
HIGH 7.5
Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 web Unverified
HIGH 8.1
Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 web Patched
CRITICAL 9.9
pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 web Patched
HIGH
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239 web Unverified
CRITICAL
pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
CVE-2026-29000 web Patched
CRITICAL 9.8
OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876) EPSS 14%
CVE-2026-21876 web Patched
CRITICAL
oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)
CVE-2026-33331 (GHSA-7f6v-3gx7-27q8) web Patched
HIGH
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr) web Patched
CRITICAL 9.8
OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777 web Patched
CRITICAL
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766 EPSS 26%
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj) web Unverified
HIGH 8.8
OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418 web Patched
HIGH 8.8
OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)
CVE-2026-24415 (GHSA-jfgp-g7x7-j25j) web Patched
MEDIUM
OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
CVE-2026-24419 web Patched
HIGH
OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
CVE-2026-24417 web Patched
HIGH
OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
CVE-2026-24416 web Patched
HIGH
OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
CVE-2026-39842 / GHSA-7mqr-33rv-p3mp web Patched
CRITICAL 10
OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849 web Patched
CRITICAL 6.5
OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812) EPSS 17%
CVE-2026-22812 (GHSA-vxw4-wv6m-9hhh) web Patched
HIGH 8.8
OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439) EPSS 10%
CVE-2026-33439 web Patched
CRITICAL 9.8
Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)
CVE-2026-45401 web Patched
HIGH
OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web Unverified
CRITICAL 9.9
Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242 web Patched
CRITICAL
Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
CVE-2026-34200 (GHSA-6c5x-3h35-vvw2) web Patched
CRITICAL 9.6
nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
CVE-2026-40701 web Patched
MEDIUM 6.3
Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability) web Unverified
HIGH
nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift") web Unverified
CRITICAL
NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926 web Patched
HIGH
Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh) web Patched
INFO
NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
CVE-2026-3228 web Unverified
MEDIUM 6.4
Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)
CVE-2026-45156 web Patched
HIGH 8.1
Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
CVE-2026-33671 web Patched
HIGH
n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613 EPSS 78%
CVE-2026-21858, CVE-2025-68613 web Patched
CRITICAL 10
n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
CVE-2026-44789 / GHSA-c8xv-5998-g76h web Patched
CRITICAL 9.4
Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
CVE-2026-3304 web Patched
HIGH 8.7
MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
CVE-2026-0596 (GHSA-rvhj-8chj-8v3c) web Unverified
CRITICAL 9.6
MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483) EPSS 11%
CVE-2026-27483 web Patched
CRITICAL
MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220 web Patched
HIGH
midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306 web Unverified
CRITICAL 9.8
Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 web Patched
HIGH
Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345 web Unverified
CRITICAL
MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744) EPSS 45%
CVE-2026-23744 web Patched
CRITICAL
MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
CVE-2026-23520 web Patched
CRITICAL
mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CRITICAL 9.3
Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
CVE-2026-40897 web Patched
CRITICAL
Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484 web Unverified
HIGH 8.8
MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
CVE-2026-30849 web Patched
HIGH
MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281 web Patched
CRITICAL 9.2
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468 web Patched
CRITICAL 9.8
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102 web Patched
HIGH 8.8
LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217) EPSS 15%
CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29) web Patched
CRITICAL 8.8
LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
CVE-2026-35030 web Patched
CRITICAL 9.1
LiteLLM /config/update Broken Access Control (CVE-2026-35029) EPSS 26%
CVE-2026-35029 web Patched
HIGH 8.8
Lightspeed Classroom Management Weak Authentication / Device Takeover — CVE-2026-30368
CVE-2026-30368 web Unverified
HIGH
LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083 web Unverified
HIGH 8.8
LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741 web Patched
HIGH 8.8
Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770) KEV EPSS 63%
CVE-2026-0770 web Patched
CRITICAL
Langflow Remote Code Execution — CVE-2026-27966 EPSS 34%
CVE-2026-27966 web Patched
CRITICAL 9.8
Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
CVE-2026-42048 (GHSA-9whx-c884-c68q) web Patched
HIGH
Langflow Custom Component Remote Code Execution — CVE-2026-33017 KEV EPSS 96%
CVE-2026-33017 web Patched
CRITICAL
LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920 web Unverified
CRITICAL 9.8
Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)
CVE-2026-38526 web Unverified
CRITICAL
KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 web Unverified
CRITICAL
Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206 web Unverified
CRITICAL 9.8
Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529
CVE-2026-1529 web Unverified
CRITICAL
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f web Patched
HIGH 8.4
Kan SSRF via Attachment Download Endpoint — CVE-2026-32255 EPSS 21%
CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg) web Patched
HIGH 8.6
JupyterHub Cross-Origin Form POST XSRF Bypass (CVE-2026-40864)
CVE-2026-40864 (GHSA-m68r-v472-jgq9) web Patched
MEDIUM
Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290 KEV EPSS 30%
CVE-2026-56290 web Patched
CRITICAL 9.8
Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627 web Patched
CRITICAL 9.5
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001) web Unpatched
CRITICAL 8.7
Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 web Patched
CRITICAL
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079 web Unverified
HIGH 7.5
Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435 EPSS 53%
CVE-2026-53435 (Jenkins SECURITY-3707) web Patched
HIGH 9.1
JeecgBoot mLogin Endpoint CAPTCHA Bypass Enabling Credential Brute Force (CVE-2026-8196)
CVE-2026-8196 web Unverified
HIGH
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
CVE-2026-54597 web Unverified
HIGH
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
CVE-2026-54596 web Unverified
HIGH
InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CRITICAL
Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104 web Unverified
HIGH 8.1
Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
HIGH 8.1
Immich Stored XSS to API Key Exfiltration and Account Hijacking (CVE-2026-35455)
CVE-2026-35455 web Patched
HIGH
Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
HIGH
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580 web Unverified
CRITICAL 9.8
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395 web Patched
CRITICAL 9.8
HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394 web Patched
HIGH 7.2
Handlebars AST Injection Remote Code Execution — CVE-2026-33937
CVE-2026-33937 web Patched
CRITICAL
Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512) EPSS 19%
CVE-2026-25512 web Patched
CRITICAL 9.4
Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 (GHSA-h22j-frrf-5vxq) web Patched
CRITICAL
Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
CVE-2026-4406 web Patched
MEDIUM 6.1
Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866 web Patched
CRITICAL 9.6
graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
CVE-2026-32247 (GHSA, getzep/graphiti) web Patched
HIGH 8.1
Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
CVE-2026-21721 web Patched
HIGH
Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 web Patched
CRITICAL 9.8
Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2) web Patched
HIGH 7.5
Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
CVE-2026-52813 web Patched
INFO
GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173 web Patched
HIGH
Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
CVE-2026-28699 web Patched
HIGH
Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
CVE-2026-27771 web Patched
CRITICAL
Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053
CVE-2026-29053 (GHSA-cgc2-rcrh-qr5x) web Patched
HIGH
Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980) EPSS 70%
CVE-2026-26980 web Patched
CRITICAL
FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CRITICAL 9.8
Friendly Functions for Welcart WordPress Plugin CSRF (CVE-2026-1208)
CVE-2026-1208 web Patched
MEDIUM 4.3
FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289 EPSS 31%
CVE-2026-28289 web Patched
CRITICAL 10
FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)
CVE-2026-46376 (GHSA-m55x-h47x-v3gx) web Patched
CRITICAL 9.1
FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646) web Patched
MEDIUM 6.9
FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277 web Patched
CRITICAL
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229 web Patched
CRITICAL 9.8
Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824 EPSS 36%
CVE-2026-30824 web Patched
CRITICAL 9.8
Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)) web Unverified
INFO
Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CRITICAL 9.8
Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300) EPSS 39%
CVE-2026-3300 web Unverified
CRITICAL
EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657 web Patched
MEDIUM
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7 web Patched
HIGH 7.5
EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
CVE-2026-33656 web Patched
CRITICAL
EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
CVE-2026-33657 web Patched
MEDIUM
EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534 web Patched
MEDIUM
ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 web Patched
MEDIUM 6.4
EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)
CVE-2026-22243 web Patched
CRITICAL
EcoOnline EHS Android App — Deep Link Validation Bypass to WebView Open Redirect (CVE-2026-26897)
CVE-2026-26897 web Patched
MEDIUM 6.3
Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018 web Patched
HIGH 8.8
Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
CVE-2026-34036 web Patched
MEDIUM
Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web Patched
CRITICAL
Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
CVE-2026-33033 web Patched
MEDIUM
Django GIS RasterField SQL Injection (CVE-2026-1207) EPSS 13%
CVE-2026-1207 web Patched
HIGH
Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
CVE-2026-5118 web Unverified
CRITICAL 9.8
diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)
CVE-2026-38934 web Unverified
HIGH 8.8
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11) web Unverified
CRITICAL
dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39) web Patched
CRITICAL
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668 web Patched
CRITICAL 3.1
DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
CVE-2026-48017 / GHSA-hv83-ggc4-v385 web Patched
HIGH 8.8
Dagster Database I/O Manager SQL Injection via Dynamic Partition Keys (CVE-2026-41490)
CVE-2026-41490 (GHSA-mjw2-v2hm-wj34) web Patched
HIGH
CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
CVE-2026-34975 web Patched
HIGH 8.5
Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp) web Patched
CRITICAL 10
Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517
CVE-2026-57517 web Patched
CRITICAL 9.8
Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257) EPSS 41%
CVE-2026-4257 web Unverified
CRITICAL
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749 web Unverified
CRITICAL 9.8
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631) EPSS 15%
CVE-2026-4631 (GHSA-m4gv-x78h-3427) web Patched
CRITICAL 9.8
Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
CVE-2026-33715 / GHSA-mxc9-9335-45mc web Unverified
HIGH 7.5
Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041 web Patched
HIGH 8.8
Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751) web Patched
CRITICAL
Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
CVE-2026-6815 web Unverified
HIGH
Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
CVE-2026-39949 web Patched
HIGH
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576 web Patched
HIGH 7.5
Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181) EPSS 15%
CVE-2026-8181 web Patched
CRITICAL 9.8
Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816 EPSS 15%
CVE-2026-31816 web Unverified
CRITICAL
Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551 web Patched
CRITICAL 9.8
Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
CVE-2026-5513 web Patched
HIGH 7.2
BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CRITICAL 9.8
BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
HIGH
Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
HIGH
BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515 web Unverified
CRITICAL 9.8
BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)
CVE-2026-41653 web Patched
CRITICAL
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415 web Patched
HIGH 3.1
Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279 web Unverified
CRITICAL
AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
CVE-2026-30950 (GHSA-q58p-v9r9-7gqj) web Patched
HIGH 7.1
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074) web Patched
CRITICAL 9.8
Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862
CVE-2026-30862 (GHSA-5hw4-whxv-6794) web Patched
CRITICAL 9.1
ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
CVE-2026-32731 web Patched
HIGH
Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486) KEV EPSS 99%
CVE-2026-34486 web Patched
CRITICAL
Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
CVE-2026-43515 web Patched
HIGH
Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
CVE-2026-29145 web Patched
CRITICAL 9.1
Apache Tomcat LoadBalancerDrainingValve — Cross-System Open Redirect / Session Fixation (CVE-2026-25854)
CVE-2026-25854 web Patched
MEDIUM 6.1
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
CVE-2026-23980 web Patched
MEDIUM 6.5
Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
CVE-2026-44825 web Patched
CRITICAL 9.8
Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)
CVE-2026-22444 web Patched
CRITICAL
Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
CVE-2026-39816 web Patched
CRITICAL
Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
CVE-2026-24072 web Patched
MEDIUM
Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006
CVE-2026-33006 web Patched
MEDIUM 4.8
Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
CVE-2026-33453 web Patched
CRITICAL 10
Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908 web Patched
CRITICAL 10
Apache Airflow AWS Auth Manager SAML Host Header Injection (CVE-2026-25604)
CVE-2026-25604 web Patched
HIGH
Apache ActiveMQ Jolokia addNetworkConnector Spring Bean RCE (CVE-2026-42588)
CVE-2026-42588 web Patched
HIGH 8.1
adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
CVE-2026-33980 web Patched
HIGH 8.8
Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
CVE-2026-8809 web Unverified
CRITICAL 9.8
AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CRITICAL 9.2
AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
CVE-2026-30498 (reserved by MITRE) web Unverified
HIGH
AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
CVE-2026-1729 web Unverified
CRITICAL
@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)
CVE-2026-46391 (GHSA-4fg7-f244-3j49) web Unverified
HIGH
PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
None assigned as of 2026-07-03 web Unverified
CRITICAL
NodeBB ActivityPub attributedTo Local UID Spoof
None assigned as of 2026-07-03 web Unverified
HIGH
Next.js unstable_cache Object-Argument Cache-Key Collision
None assigned as of 2026-07-03 web Unverified
HIGH
MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue) web Unpatched
HIGH
Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248) KEV RW EPSS 100%
CVE-2025-3248 web Patched
CRITICAL 9.8
Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
None assigned as of 2026-07-03 web Unverified
CRITICAL
Gogs Admin User Edit CSRF to Git Hook RCE
None assigned as of 2026-07-03 web Unverified
CRITICAL
Flowise Custom MCP Environment Variable Case Bypass
None assigned as of 2026-07-03 web Unverified
HIGH
Firefox Smart Window Private URL Exfiltration
None assigned as of 2026-07-03 web Unverified
HIGH
Discourse Scoped API Key Pre-Route Authorization Bypass
None assigned as of 2026-07-03 web Unverified
HIGH
Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247) KEV EPSS 28%
CVE-2026-45247 web Unverified
CRITICAL 9.3
Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CRITICAL 10
PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257) KEV RW EPSS 94%
CVE-2026-0257 web Unverified
HIGH 7.8
Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645) KEV
CVE-2026-11645 web Unverified
HIGH 8.8
Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271) KEV EPSS 84%
CVE-2026-42271 web Patched
HIGH 8.7
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CRITICAL 10
Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CRITICAL
FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition
web Unpatched
CRITICAL 9.3
LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172) KEV EPSS 19%
CVE-2026-48172 web Unverified
HIGH
Drupal Core PostgreSQL SQL Injection (CVE-2026-9082) KEV EPSS 88%
CVE-2026-9082 / SA-CORE-2026-004 web Patched
CRITICAL
Chrome WebGPU Use-After-Free (CVE-2026-5281) KEV
CVE-2026-5281 web Unverified
HIGH 8.8
ToolShell - SharePoint Unauthenticated RCE Chain KEV RW EPSS 100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web Patched
CRITICAL
React2Shell - Next.js RSC Unauthenticated RCE KEV RW EPSS 100%
CVE-2025-55182 web Patched
CRITICAL 10
Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400) KEV RW EPSS 100%
CVE-2024-3400 web Patched
CRITICAL 10
Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572 web Patched
LOW 3.1
Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578) EPSS 39%
CVE-2026-44578 web Patched
HIGH 8.6
Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 web Patched
HIGH 7.5
Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576 web Patched
MEDIUM 5.4
Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
CVE-2026-44582 web Patched
LOW 3.7
Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
CVE-2026-44577 web Patched
MEDIUM 5.9
Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 web Patched
HIGH 7.5
Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574 web Patched
HIGH 8.1
Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
CVE-2026-44581 web Patched
MEDIUM 4.7
Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
CVE-2026-44579 web Patched
HIGH 7.5
Next.js beforeInteractive Script XSS (CVE-2026-44580)
CVE-2026-44580 web Patched
MEDIUM 6.1
Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575 web Patched
HIGH 7.5
Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CRITICAL 9.8
Confluence SSTI RCE - CVE-2023-22527 KEV RW EPSS 100%
CVE-2023-22527 web Patched
CRITICAL 10
Confluence Post-Auth RCE - CVE-2024-21683 EPSS 88%
CVE-2024-21683 web Unverified
HIGH 8.3
Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918 EPSS 50%
CVE-2026-23918 web Patched
CRITICAL
Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108) KEV EPSS 98%
CVE-2025-0108 web Patched
CRITICAL 9.1
Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762) KEV RW EPSS 84%
CVE-2024-21762 web Patched
CRITICAL 9.6
Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591) KEV RW EPSS 98%
CVE-2024-55591 (Fortinet FG-IR-24-535) web Unverified
CRITICAL 9.6
cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940) KEV RW EPSS 99%
CVE-2026-41940 web Patched
CRITICAL 10
Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777) KEV RW EPSS 100%
CVE-2025-5777 web Patched
CRITICAL 9.3
Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441) KEV EPSS 22%
CVE-2026-2441 web Unpatched
HIGH 8.8
Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927) EPSS 99%
CVE-2025-29927 web Patched
CRITICAL 9.1
Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897) KEV EPSS 71%
CVE-2026-42897 web Unverified
MEDIUM 5.3
NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945) EPSS 68%
CVE-2026-42945 web Unverified
CRITICAL 9.8
CVE-2026-27876: Grafana SQL Expressions Arbitrary File Write to RCE
Unverified