PULSE
LIVE24signals / 24h
FEED
ransomkrybit reclama a chkck.com · Technologyransomqilin reclama a WellPerf · GB · Healthcareransomthegentlemen reclama a Sirl · PT · Not Foundransomthegentlemen reclama a Disney Family · US · Financial Servicesransomqilin reclama a Corporate 360 Business Solutions · CA · Professional Servicesransomqilin reclama a Assos Pharmaceuticals · TR · Healthcareransomqilin reclama a Cano Industrial · MX · Manufacturingransomqilin reclama a Triton Trading · PE · Financial Servicesransomqilin reclama a AppleOne Properties · PH · Not Foundransommoneymessage reclama a Indigo Energy · CA · Energyransomqilin reclama a Sunway Berhad · MY · Hospitality and Tourismransomkairos reclama a LR Reed · AU · Business Servicesransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Servicesransomkrybit reclama a chkck.com · Technologyransomqilin reclama a WellPerf · GB · Healthcareransomthegentlemen reclama a Sirl · PT · Not Foundransomthegentlemen reclama a Disney Family · US · Financial Servicesransomqilin reclama a Corporate 360 Business Solutions · CA · Professional Servicesransomqilin reclama a Assos Pharmaceuticals · TR · Healthcareransomqilin reclama a Cano Industrial · MX · Manufacturingransomqilin reclama a Triton Trading · PE · Financial Servicesransomqilin reclama a AppleOne Properties · PH · Not Foundransommoneymessage reclama a Indigo Energy · CA · Energyransomqilin reclama a Sunway Berhad · MY · Hospitality and Tourismransomkairos reclama a LR Reed · AU · Business Servicesransomnova reclama a VNSO · Not Foundransomblacknevas reclama a Zuni Shopping Center, Inc. · US · Consumer Services
CVE Watch352,162 in full archive

Vulnerabilities exploitable today

352,162in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,653
New KEV · 24H0
Exploit Today ≥ 701,590

Distribution · last window

  • Critical
    2,073
  • High
    6,924
  • Medium
    5,904
  • Low
    547
Filters

Window

Severity

Flags

Vulnerabilities352,081–352,120 · 352,162
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-648037.8 HIG
0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK3h
CVE-2026-658967.1 HIG
0Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to an arbitrary writable location outside user/pages/, including outside the Grav installation.3h
CVE-2026-654574.3 MED
0Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.3h
CVE-2026-658978.8 HIG
0Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions.3h
CVE-2026-654564.3 MED
0Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.3h
CVE-2026-150178.8 HIG
0The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.5h
CVE-2026-654559.1 CRI
0Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.3h
CVE-2023-20914
0.0%
0
CVE-2026-648077.8 HIG
0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration3h
CVE-2026-654548.5 HIG
0Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.3h
CVE-2026-62165
0Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61446. Reason: This candidate is a duplicate of CVE-2026-61446. Notes: All CVE users should reference CVE-2026-61446 instead of this candidate.8d
CVE-2026-654535.3 MED
0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.3h
CVE-2026-654525.3 MED
0Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.3h
CVE-2026-130096.5 MED
0The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required waic-nonce is emitted on the front-end whenever the [waic_form] or [aiwu-form] shortcode is rendered, enabling contributor-level users who can publish shortcodes to obtain a valid nonce and reach the vulnerable AJAX handler, which performs no capability check beyond nonce verification when the shortcodes are not already embedded in a page.5h
CVE-2026-58212
0Rejected reason: Further research determined the issue is not a vulnerability based on CNA Rule 4.1.12 The act of updating Product dependencies MUST NOT be determined to be a Vulnerability, regardless of whether the dependencies have Vulnerabilities.15d
CVE-2026-648088.4 HIG
0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling3h
CVE-2026-648098.4 HIG
0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter3h
CVE-2026-648104.3 MED
0In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking3h
CVE-2026-648117.8 HIG
0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration3h
CVE-2026-656088.8 HIG
0Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.3h
CVE-2023-20940
0.0%
0
CVE-2026-656076.5 MED
0SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the file without the IsSubPath or IsSensitivePath checks added in the earlier export-disclosure hardening (GHSA-6865-qjcf-286f). An authenticated attacker can send percent-encoded traversal sequences (e.g. /export/temp/%2e%2e/.../etc/passwd, where %2e%2e is decoded to '..') to read arbitrary files outside TempDir, including /etc/passwd, SSH keys (~/.ssh/*), and SiYuan workspace *.db and *.log files, bypassing the sensitive-file protection.3h
CVE-2026-658958.5 HIG
0Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.3h
CVE-2025-680815.9 MED
0Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.3h
CVE-2026-167458.8 HIG
0A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.4h
CVE-2026-576997.1 HIG
0Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.3h
CVE-2026-576967.1 HIG
0Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.3h
CVE-2026-576267.1 HIG
0Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.3h
CVE-2026-573846.5 MED
0Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.3h
CVE-2026-574287.1 HIG
0Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.3h
CVE-2026-574277.1 HIG
0Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.3h
CVE-2026-573977.1 HIG
0Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.3h
CVE-2026-65758
0The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.5h
CVE-2026-573747.1 HIG
0Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.3h
CVE-2025-47330
0.0%
0
CVE-2026-574256.5 MED
0Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.3h
CVE-2026-656059.6 CRI
0SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as <img> are skipped by that check, a payload like <img src=x onerror=...> is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Because the desktop renderer runs with nodeIntegration enabled, the injected script can reach require and escalate to arbitrary command execution.3h
CVE-2026-573736.5 MED
0Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.3h
CVE-2026-573707.1 HIG
0Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.3h
CVE-2026-655505.9 MED
0Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.3h