PoC Archive PoC Archive

tag

Unauthenticated

WordPress Divi Ajax Filter LFI (CVE-2026-11613)
CVE-2026-11613 web Unverified
CVE-2026-11613webCRITICAL 9.8Unverified2026-09-05WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CVE-2026-82970webCRITICAL 10Unverified2026-09-03Kestra Authentication Bypass to RCE (CVE-2026-49869)
CVE-2026-49869, CVE-2026-53576 web Unverified
CVE-2026-49869, CVE-2026-53576webCRITICAL 10Unverified2026-09-03Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078) KEV RW EPSS 100%
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD) network Unverified
CVE-2023-35078networkCRITICAL 9.8Unverified2026-08-09Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457) KEV RW EPSS 100%
CVE-2025-22457 network Unpatched
CVE-2025-22457networkCRITICAL 9Unpatched2026-08-09GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205) KEV RW EPSS 100%
CVE-2021-22205 (chains CVE-2021-22204 in ExifTool) web Patched
CVE-2021-22205webCRITICAL 10Patched2026-08-09CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378) KEV RW EPSS 95%
CVE-2024-51378 web Patched
CVE-2024-51378webCRITICAL 10Patched2026-08-09Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier) binary Unverified
NotCVE-2026-0010binaryHIGHUnverified2026-08-01Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
CVE-2026-65694 (VulnCheck advisory) web Patched
CVE-2026-65694webHIGH 7.5Patched2026-07-31IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198) KEV EPSS 35%
CVE-2026-9198 web Patched
CVE-2026-9198webCRITICAL 9.8Patched2026-07-31Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432) KEV EPSS 100%
CVE-2025-32432 web Patched
CVE-2025-32432webCRITICAL 10Patched2026-07-31Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066) EPSS 28%
CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) web Patched
CVE-2026-66066webCRITICAL 9.5Patched2026-07-27Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522) KEV EPSS 85%
CVE-2026-50522 web Patched
CVE-2026-50522webCRITICAL 9.8Patched2026-07-27Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
CVE-2026-57830 web Patched
CVE-2026-57830webCRITICAL 9.1Patched2026-07-27Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CVE-2026-56291webCRITICAL 9.8Unverified2026-07-27Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7) web Patched
CVE-2026-53753webCRITICAL 9.8Patched2026-07-27Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
CVE-2026-54350 (GHSA-8qv3-p479-cj62) web Patched
CVE-2026-54350webCRITICAL 10Patched2026-07-27Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
CVE-2026-49230 web Patched
CVE-2026-49230webCRITICAL 9.1Patched2026-07-27wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CVE-2026-63030webCRITICAL 9.1Patched2026-07-19SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558) KEV EPSS 12%
CVE-2026-48558 web Patched
CVE-2026-48558webCRITICAL 10Patched2026-07-19Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230) KEV EPSS 88%
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW) network Patched
CVE-2026-20230networkCRITICAL 8.6Patched2026-07-19Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282) KEV EPSS 42%
CVE-2026-48282 (Adobe APSB26-68) web Patched
CVE-2026-48282webCRITICAL 10Patched2026-07-19SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409) KEV RW EPSS 84%
CVE-2026-15409 (SNWLID-2026-0008) network Patched
CVE-2026-15409networkCRITICAL 10Patched2026-07-15Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8) web Patched
CVE-2026-56271webCRITICAL 9.8Patched2026-07-12Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg) web Patched
CVE-2026-56260webCRITICAL 9.1Patched2026-07-12ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950) KEV EPSS 85%
CVE-2023-38950 web Patched
CVE-2023-38950webHIGH 7.5Patched2026-07-11Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208) KEV EPSS 89%
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc) web Patched
CVE-2026-42208webCRITICAL 9.8Patched2026-07-11Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4) web Patched
CVE-2026-20896webCRITICAL 9.8Patched2026-07-11D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258) KEV EPSS 80%
CVE-2022-26258 network Unverified
CVE-2022-26258networkCRITICAL 9.8Unverified2026-07-11XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
network Unpatched
—networkCRITICALUnpatched2026-07-08XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893) KEV EPSS 100%
CVE-2025-24893 web Patched
CVE-2025-24893webCRITICAL 9.8Patched2026-07-06WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CVE-2025-39401webCRITICAL 10Unverified2026-07-06WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CVE-2025-6440webCRITICAL 9.8Unverified2026-07-06Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CVE-2025-29009webCRITICAL 10Patched2026-07-06WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CVE-2025-12057webCRITICAL 9.8Unverified2026-07-06Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315) EPSS 33%
CVE-2025-13315 network Unpatched
CVE-2025-13315networkCRITICAL 9.8Unpatched2026-07-06TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CVE-2025-12539webCRITICAL 10Patched2026-07-06StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CVE-2025-7441webCRITICAL 9.8Unpatched2026-07-06StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CVE-2025-48148webCRITICAL 9.8Unverified2026-07-06Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389) EPSS 76%
CVE-2025-6389 web Unverified
CVE-2025-6389webCRITICAL 9.8Unverified2026-07-06Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334 web Unverified
CVE-2025-4334webCRITICAL 9.8Unverified2026-07-06Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CVE-2025-53580webCRITICAL 9.8Patched2026-07-06Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CVE-2025-6758webCRITICAL 9.8Unverified2026-07-06React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953) KEV EPSS 94%
CVE-2025-11953 network Patched
CVE-2025-11953networkCRITICAL 9.8Patched2026-07-06Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CVE-2025-49132webCRITICAL 10Patched2026-07-06Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294) EPSS 78%
CVE-2025-2294 web Unverified
CVE-2025-2294webCRITICAL 9.8Unverified2026-07-06KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CVE-2025-12674webCRITICAL 9.8Unverified2026-07-06JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440 web Unverified
CVE-2025-14440webCRITICAL 9.8Unverified2026-07-06GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CVE-2025-22777webCRITICAL 9.8Patched2026-07-06Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 web Patched
CVE-2025-13342webCRITICAL 9.8Patched2026-07-06FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819) KEV EPSS 88%
CVE-2025-57819 web Patched
CVE-2025-57819webCRITICAL 9.8Patched2026-07-06Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CVE-2025-14156webCRITICAL 9.8Unverified2026-07-06Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CVE-2025-49071webCRITICAL 9.8Unverified2026-07-06Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528) EPSS 87%
CVE-2025-59528 web Patched
CVE-2025-59528webCRITICAL 10Patched2026-07-06camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
CVE-2026-33453 web Unverified
CVE-2026-33453webCRITICAL 9.8Unverified2026-07-06"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354 web Unpatched
CVE-2025-65354webCRITICAL 9.8Unpatched2026-07-06ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474) EPSS 25%
CVE-2026-34474 network Unverified
CVE-2026-34474networkHIGHUnverified2026-07-05ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472 network Unverified
CVE-2026-34472networkCRITICALUnverified2026-07-05ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473 network Unverified
CVE-2026-34473networkHIGHUnverified2026-07-05ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
CVE-2026-25807 network Patched
CVE-2026-25807networkCRITICALPatched2026-07-05XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
CVE-2026-33137 web Patched
CVE-2026-33137webCRITICAL 9.3Patched2026-07-05Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912 web Patched
CVE-2026-39912webCRITICAL 9.1Patched2026-07-05WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357) EPSS 33%
CVE-2026-1357 web Unverified
CVE-2026-1357webCRITICALUnverified2026-07-05WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105 web Unverified
CVE-2026-49105webHIGH 8.1Unverified2026-07-05WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
CVE-2026-40791 web Patched
CVE-2026-40791webHIGH 7.2Patched2026-07-05WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379 web Patched
CVE-2026-6379webCRITICAL 8.6Patched2026-07-05WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085 web Unverified
CVE-2026-49085webHIGH 8.1Unverified2026-07-05WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
CVE-2026-39676 web Unverified
CVE-2026-39676webMEDIUMUnverified2026-07-05WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
CVE-2026-3180webHIGHUnverified2026-07-05WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844) EPSS 28%
CVE-2026-3844 web Unverified
CVE-2026-3844webCRITICALUnverified2026-07-05WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359 web Unverified
CVE-2026-3359webCRITICALUnverified2026-07-05WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CVE-2026-27542webCRITICAL 9.8Unverified2026-07-05Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
CVE-2026-37064 web Unverified
CVE-2026-37064webMEDIUMUnverified2026-07-05Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
CVE-2026-37067 web Unverified
CVE-2026-37067webMEDIUMUnverified2026-07-05Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
CVE-2026-37069 web Unverified
CVE-2026-37069webLOWUnverified2026-07-05Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072 web Unverified
CVE-2026-37072webCRITICALUnverified2026-07-05Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
CVE-2026-37073 web Unverified
CVE-2026-37073webMEDIUMUnverified2026-07-05User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CVE-2026-4882webCRITICAL 9.8Unverified2026-07-05User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492) EPSS 24%
CVE-2026-1492 web Unverified
CVE-2026-1492webCRITICAL 9.8Unverified2026-07-05UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795 web Unverified
CVE-2026-10795webCRITICALUnverified2026-07-05Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
CVE-2026-35037 web Patched
CVE-2026-35037webHIGHPatched2026-07-05Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
CVE-2026-36522 network Unverified
CVE-2026-36522networkCRITICAL 9.1Unverified2026-07-05Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
CVE-2026-33712 web Patched
CVE-2026-33712webHIGHPatched2026-07-05The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CVE-2026-49772webCRITICAL 9.3Patched2026-07-05Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738 web Patched
CVE-2026-22738webCRITICAL 9.8Patched2026-07-05Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
CVE-2026-42096 network Unverified
CVE-2026-42096networkCRITICALUnverified2026-07-05Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CVE-2026-1056webCRITICALUnverified2026-07-05SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
CVE-2026-0001 (tracked publicly as WT-2026-0001) web Patched
CVE-2026-0001webCRITICAL 9Patched2026-07-05SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423 KEV RW EPSS 88%
CVE-2026-24423 web Unverified
CVE-2026-24423webCRITICALUnverified2026-07-05Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912 web Patched
CVE-2026-11912webHIGH 7.5Patched2026-07-05School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
CVE-2026-37750 web Unverified
CVE-2026-37750webMEDIUM 6.1Unverified2026-07-05Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067 web Unverified
CVE-2026-9067webHIGH 8.1Unverified2026-07-05Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
CVE-2026-24136 web Patched
CVE-2026-24136webHIGH 7.5Patched2026-07-05Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
CVE-2026-29198 web Patched
CVE-2026-29198webCRITICALPatched2026-07-05Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023 web Unpatched
CVE-2026-39023webCRITICALUnpatched2026-07-05rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
CVE-2026-41179 web Patched
CVE-2026-41179webCRITICAL 9.8Patched2026-07-05ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
CVE-2026-41462 web Patched
CVE-2026-41462webCRITICAL 9.8Patched2026-07-05ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167 network Patched
CVE-2026-42167networkHIGH 8.1Patched2026-07-05Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926 web Unverified
CVE-2026-0926webHIGHUnverified2026-07-05Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
CVE-2026-32096 cloud Patched
CVE-2026-32096cloudCRITICAL 9.3Patched2026-07-05Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CVE-2026-4885webCRITICALUnverified2026-07-05phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
CVE-2026-42569 web Patched
CVE-2026-42569webCRITICALPatched2026-07-05Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr) web Patched
CVE-2026-26198webCRITICAL 9.8Patched2026-07-05OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777 web Patched
CVE-2026-45777webCRITICALPatched2026-07-05OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
CVE-2026-41900 (GHSA-8h25-q488-4hxw) cloud Patched
CVE-2026-41900cloudHIGH 8.6Patched2026-07-05Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
CVE-2026-53519 (GHSA-5c25-7vpj-9mqh) web Patched
CVE-2026-53519webINFOPatched2026-07-05MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483) EPSS 11%
CVE-2026-27483 web Patched
CVE-2026-27483webCRITICALPatched2026-07-05MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356) EPSS 14%
CVE-2026-36356 network Unverified
CVE-2026-36356networkCRITICALUnverified2026-07-05mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825) EPSS 13%
CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4) web Patched
CVE-2026-27825webCRITICAL 9.3Patched2026-07-05MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281 web Patched
CVE-2026-42281webCRITICAL 9.2Patched2026-07-05Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770) KEV EPSS 63%
CVE-2026-0770 web Patched
CVE-2026-0770webCRITICALPatched2026-07-05Langflow Remote Code Execution — CVE-2026-27966 EPSS 34%
CVE-2026-27966 web Patched
CVE-2026-27966webCRITICAL 9.8Patched2026-07-05LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920 web Unverified
CVE-2026-0920webCRITICAL 9.8Unverified2026-07-05Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206 web Unverified
CVE-2026-8206webCRITICAL 9.8Unverified2026-07-05Kan SSRF via Attachment Download Endpoint — CVE-2026-32255 EPSS 21%
CVE-2026-32255 (GHSA-qrx8-9hc6-jvqg) web Patched
CVE-2026-32255webHIGH 8.6Patched2026-07-05Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627 web Patched
CVE-2026-21627webCRITICAL 9.5Patched2026-07-05JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
CVE-2026-49048 (Advisory ID JOOMCCK-2026-001) web Unpatched
CVE-2026-49048webCRITICAL 8.7Unpatched2026-07-05JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079 web Unverified
CVE-2026-49079webHIGH 7.5Unverified2026-07-05InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CVE-2026-23491webCRITICALPatched2026-07-05Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104 web Unverified
CVE-2026-49104webHIGH 8.1Unverified2026-07-05Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
CVE-2026-9691webHIGH 8.1Unpatched2026-07-05Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580 web Unverified
CVE-2026-10580webCRITICAL 9.8Unverified2026-07-05Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
CVE-2026-4406 web Patched
CVE-2026-4406webMEDIUM 6.1Patched2026-07-05Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 web Patched
CVE-2026-42589webCRITICAL 9.8Patched2026-07-05Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
CVE-2026-27771 web Patched
CVE-2026-27771webCRITICALPatched2026-07-05Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980) EPSS 70%
CVE-2026-26980 web Patched
CVE-2026-26980webCRITICALPatched2026-07-05FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895) EPSS 11%
CVE-2026-25895 web Patched
CVE-2026-25895webCRITICAL 9.8Patched2026-07-05FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646) web Patched
CVE-2026-53647webMEDIUM 6.9Patched2026-07-05FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808) KEV EPSS 93%
CVE-2026-39808 network Unverified
CVE-2026-39808networkCRITICAL 9.8Unverified2026-07-05Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089) KEV EPSS 76%
CVE-2026-25089 network Patched
CVE-2026-25089networkCRITICAL 9.8Patched2026-07-05Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824 EPSS 36%
CVE-2026-30824 web Patched
CVE-2026-30824webCRITICAL 9.8Patched2026-07-05Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)) web Unverified
CVE-2026-54337webINFOUnverified2026-07-05Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300) EPSS 39%
CVE-2026-3300 web Unverified
CVE-2026-3300webCRITICALUnverified2026-07-05EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657 web Patched
CVE-2026-1657webMEDIUMPatched2026-07-05Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7 web Patched
CVE-2026-40776 / Patchstack PSID 85de025d71e7webHIGH 7.5Patched2026-07-05Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018 web Patched
CVE-2026-9018webHIGH 8.8Patched2026-07-05Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
CVE-2026-5118 web Unverified
CVE-2026-5118webCRITICAL 9.8Unverified2026-07-05dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39) web Patched
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39]webCRITICALPatched2026-07-05Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257) EPSS 41%
CVE-2026-4257 web Unverified
CVE-2026-4257webCRITICALUnverified2026-07-05CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749 web Unverified
CVE-2026-37749webCRITICAL 9.8Unverified2026-07-05Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
CVE-2026-33715 / GHSA-mxc9-9335-45mc web Unverified
CVE-2026-33715 / GHSA-mxc9-9335-45mcwebHIGH 7.5Unverified2026-07-05Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576 web Patched
CVE-2026-2576webHIGH 7.5Patched2026-07-05Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551 web Patched
CVE-2026-11551webCRITICAL 9.8Patched2026-07-05BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CVE-2026-6960webCRITICAL 9.8Unverified2026-07-05Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279 web Unverified
CVE-2026-6279webCRITICALUnverified2026-07-05Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486) KEV EPSS 99%
CVE-2026-34486 web Patched
CVE-2026-34486webCRITICALPatched2026-07-05Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
CVE-2026-33453 web Patched
CVE-2026-33453webCRITICAL 10Patched2026-07-05Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
CVE-2026-8809 web Unverified
CVE-2026-8809webCRITICAL 9.8Unverified2026-07-05AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
CVE-2026-1729 web Unverified
CVE-2026-1729webCRITICALUnverified2026-07-05Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248) KEV RW EPSS 100%
CVE-2025-3248 web Patched
CVE-2025-3248webCRITICAL 9.8Patched2026-07-03Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451) EPSS 16%
CVE-2026-8451 network Unverified
CVE-2026-8451networkHIGH 7.5Unverified2026-07-03Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247) KEV EPSS 28%
CVE-2026-45247 web Unverified
CVE-2026-45247webCRITICAL 9.3Unverified2026-07-01Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257) KEV RW EPSS 94%
CVE-2026-0257 web Unverified
CVE-2026-0257webHIGH 7.8Unverified2026-07-01SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CVE-2026-55200networkCRITICAL 9.8Patched2026-06-30GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061) KEV EPSS 98%
CVE-2026-24061 network Patched
CVE-2026-24061networkCRITICAL 9.8Patched2026-06-30GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 network Patched
CVE-2026-12485networkCRITICAL 10Patched2026-06-30Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253) KEV EPSS 97%
CVE-2026-20253 web Patched
CVE-2026-20253webCRITICALPatched2026-06-28Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751) KEV RW EPSS 84%
CVE-2026-50751 network Patched
CVE-2026-50751networkCRITICAL 9.3Patched2026-06-28Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089) EPSS 80%
CVE-2026-41089 network Patched
CVE-2026-41089networkCRITICAL 9.8Patched2026-06-04Drupal Core PostgreSQL SQL Injection (CVE-2026-9082) KEV EPSS 88%
CVE-2026-9082 / SA-CORE-2026-004 web Patched
CVE-2026-9082 / SA-CORE-2026-004webCRITICALPatched2026-05-30TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
N/A (vendor confirmed TOS4 is EOL; no fix planned) network Unpatched
N/AnetworkCRITICALUnpatched2026-05-18Chrome WebGPU Use-After-Free (CVE-2026-5281) KEV
CVE-2026-5281 web Unverified
CVE-2026-5281webHIGH 8.8Unverified2026-05-18ToolShell - SharePoint Unauthenticated RCE Chain KEV RW EPSS 100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web Patched
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706webCRITICALPatched2026-05-17React2Shell - Next.js RSC Unauthenticated RCE KEV RW EPSS 100%
CVE-2025-55182 web Patched
CVE-2025-55182webCRITICAL 10Patched2026-05-17Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400) KEV RW EPSS 100%
CVE-2024-3400 web Patched
CVE-2024-3400webCRITICAL 10Patched2026-05-17Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572 web Patched
CVE-2026-44572webLOW 3.1Patched2026-05-17Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578) EPSS 39%
CVE-2026-44578 web Patched
CVE-2026-44578webHIGH 8.6Patched2026-05-17Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 web Patched
CVE-2026-23870webHIGH 7.5Patched2026-05-17Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576 web Patched
CVE-2026-44576webMEDIUM 5.4Patched2026-05-17Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
CVE-2026-44582 web Patched
CVE-2026-44582webLOW 3.7Patched2026-05-17Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
CVE-2026-44577 web Patched
CVE-2026-44577webMEDIUM 5.9Patched2026-05-17Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 web Patched
CVE-2026-44573webHIGH 7.5Patched2026-05-17Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574 web Patched
CVE-2026-44574webHIGH 8.1Patched2026-05-17Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
CVE-2026-44581 web Patched
CVE-2026-44581webMEDIUM 4.7Patched2026-05-17Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
CVE-2026-44579 web Patched
CVE-2026-44579webHIGH 7.5Patched2026-05-17Next.js beforeInteractive Script XSS (CVE-2026-44580)
CVE-2026-44580 web Patched
CVE-2026-44580webMEDIUM 6.1Patched2026-05-17Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575 web Patched
CVE-2026-44575webHIGH 7.5Patched2026-05-17Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897) KEV RW EPSS 100%
CVE-2024-23897 web Patched
CVE-2024-23897webCRITICAL 9.8Patched2026-05-17Ivanti Connect Secure Pre-Auth RCE (Stack Overflow) KEV RW EPSS 100%
CVE-2025-0282 network Unverified
CVE-2025-0282networkCRITICAL 9Unverified2026-05-17IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE EPSS 100%
CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-05-17Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575) KEV EPSS 95%
CVE-2024-47575 network Unverified
CVE-2024-47575networkCRITICAL 9.8Unverified2026-05-17Fortinet FortiCloud SSO Authentication Bypass KEV EPSS 69%
CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647) network Unverified
CVE-2025-59718, CVE-2025-59719networkCRITICAL 9.8Unverified2026-05-17Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433 KEV EPSS 99%
CVE-2025-32433 network Patched
CVE-2025-32433networkCRITICAL 10Patched2026-05-17Confluence SSTI RCE - CVE-2023-22527 KEV RW EPSS 100%
CVE-2023-22527 web Patched
CVE-2023-22527webCRITICAL 10Patched2026-05-17Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918 EPSS 50%
CVE-2026-23918 web Patched
CVE-2026-23918webCRITICALPatched2026-05-17Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298) EPSS 81%
CVE-2025-21298 binary Patched
CVE-2025-21298binaryCRITICAL 9.8Patched2026-05-16VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079) KEV EPSS 22%
CVE-2024-37079 network Patched
CVE-2024-37079networkCRITICAL 9.8Patched2026-05-16Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108) KEV EPSS 98%
CVE-2025-0108 web Patched
CVE-2025-0108webCRITICAL 9.1Patched2026-05-16OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387) EPSS 100%
CVE-2024-6387 network Patched
CVE-2024-6387networkHIGH 8.1Patched2026-05-16Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762) KEV RW EPSS 84%
CVE-2024-21762 web Patched
CVE-2024-21762webCRITICAL 9.6Patched2026-05-16Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591) KEV RW EPSS 98%
CVE-2024-55591 (Fortinet FG-IR-24-535) web Unverified
CVE-2024-55591webCRITICAL 9.6Unverified2026-05-16cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940) KEV RW EPSS 99%
CVE-2026-41940 web Patched
CVE-2026-41940webCRITICAL 10Patched2026-05-16Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777) KEV RW EPSS 100%
CVE-2025-5777 web Patched
CVE-2025-5777webCRITICAL 9.3Patched2026-05-16Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441) KEV EPSS 22%
CVE-2026-2441 web Unpatched
CVE-2026-2441webHIGH 8.8Unpatched2026-05-16Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927) EPSS 99%
CVE-2025-29927 web Patched
CVE-2025-29927webCRITICAL 9.1Patched2026-05-15LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113) EPSS 83%
CVE-2024-49113 network Patched
CVE-2024-49113networkCRITICALPatched2026-05-15HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166) KEV EPSS 100%
CVE-2021-31166 network Patched
CVE-2021-31166networkCRITICAL 9.8Patched2026-05-15BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
CVE-2023-45866 network Patched
CVE-2023-45866networkHIGH 8.8Patched2026-05-15NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945) EPSS 68%
CVE-2026-42945 web Unverified
CVE-2026-42945webCRITICAL 9.8Unverified2026-05-14Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE EPSS 93%
CVE-2026-43500, CVE-2026-43284 binary Patched
CVE-2026-43500, CVE-2026-43284binaryCRITICAL 7.8Patched2026-05-14