PULSE
LIVE34signals / 24h
FEED
ransomplay reclama a Signature Services · Professional Servicesransomplay reclama a GCATS Investments · US · Financial Servicesransomplay reclama a Platinum Group · SG · Manufacturingransomlynx reclama a www.jerryleigh.com · US · Otherransomlynx reclama a www.talbotdes.org · GB · Otherransomgammax reclama a King International LLC · US · Otherransomqilin reclama a AmSpec · US · Energy & Utilitiesransomqilin reclama a ALIZE (alize-sud.fr) · FR · Professional Servicesransomqilin reclama a Jakle & Alexander · US · Not Foundransomqilin reclama a Akuur Law Firm · TR · Professional Servicesransomqilin reclama a J&T Bank and Trust · US · Financial Servicesransombravox reclama a MITC AG · CH · Otherransomakira reclama a Basic Grain Products · Agriculture and Food Productionransomakira reclama a Pharma Test Apparatebau AG · CH · Manufacturingransomplay reclama a Signature Services · Professional Servicesransomplay reclama a GCATS Investments · US · Financial Servicesransomplay reclama a Platinum Group · SG · Manufacturingransomlynx reclama a www.jerryleigh.com · US · Otherransomlynx reclama a www.talbotdes.org · GB · Otherransomgammax reclama a King International LLC · US · Otherransomqilin reclama a AmSpec · US · Energy & Utilitiesransomqilin reclama a ALIZE (alize-sud.fr) · FR · Professional Servicesransomqilin reclama a Jakle & Alexander · US · Not Foundransomqilin reclama a Akuur Law Firm · TR · Professional Servicesransomqilin reclama a J&T Bank and Trust · US · Financial Servicesransombravox reclama a MITC AG · CH · Otherransomakira reclama a Basic Grain Products · Agriculture and Food Productionransomakira reclama a Pharma Test Apparatebau AG · CH · Manufacturing
CVE Watch356,180 in full archive

Vulnerabilities exploitable today

356,180in current view

Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.

In KEV catalog1,661
New KEV · 24H0
Exploit Today ≥ 701,603

Distribution · last window

  • Critical
    2,780
  • High
    11,112
  • Medium
    7,370
  • Low
    694
Filters

Window

Severity

Flags

Vulnerabilities356,041–356,080 · 356,180
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-51349.8 CRI
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.6h
CVE-2026-649936.8 MED
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.6h
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.7h
CVE-2026-152464.3 MED
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.7h
CVE-2026-190445.3 MED
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.6h
CVE-2026-190455.3 MED
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.7h
CVE-2026-254036.5 MED
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.7h
CVE-2026-667057.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.6h
CVE-2026-667036.5 MED
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.7h
CVE-2026-280059.8 CRI
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.6h
CVE-2026-280827.1 HIG
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.7h
CVE-2026-281118.8 HIG
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.7h
CVE-2026-281399.8 CRI
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.6h
CVE-2026-667027.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.7h
CVE-2026-667015.3 MED
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.7h
CVE-2026-666995.3 MED
Custom role Broken Access Control in Dokan <= 5.0.10 versions.7h
CVE-2026-281407.5 HIG
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.7h
CVE-2026-281417.1 HIG
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.6h
CVE-2026-281437.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.7h
CVE-2026-281466.5 MED
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.7h
CVE-2026-281695.3 MED
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.6h
CVE-2026-281727.1 HIG
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.7h
CVE-2026-281777.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.6h
CVE-2026-281786.5 MED
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.7h
CVE-2026-281795.9 MED
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.7h
CVE-2026-281805.3 MED
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.6h
CVE-2026-281837.2 HIG
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.7h
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.7h
CVE-2026-324695.3 MED
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.6h
CVE-2026-325485.3 MED
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.7h
CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.37h
CVE-2026-34501
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.7h
CVE-2026-34502
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.7h
CVE-2026-539759.8 CRI
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.6h
CVE-2026-539769.1 CRI
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.6h
CVE-2026-544899.1 CRI
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.7h
CVE-2026-619596.5 MED
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.7h
CVE-2026-666964.3 MED
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.6h
CVE-2026-619617.1 HIG
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.6h
CVE-2026-619637.1 HIG
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.7h