Vulnerabilities exploitable today
372,212in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,703
New KEV · 24H0
Exploit Today ≥ 701,643
Distribution · last window
- Critical2,286
- High8,401
- Medium6,423
- Low627
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-785366.5 MED—
———Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.13hCVE-2026-812756.5 MED—
———Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.13hCVE-2026-817826.5 MED—
———Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.11hCVE-2026-817837.1 HIG—
———Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.13hCVE-2026-817848.1 HIG—
———Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.8hCVE-2026-817856.5 MED—
———Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.13hCVE-2026-817867.5 HIG—
———Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.13hCVE-2026-870124.3 MED—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the shared upcoming-event scheduler compared that value numerically. An authenticated user with the calendar permission could store a non-numeric alert_minutes value that raised an exception and aborted the instance-wide alert pass, suppressing all users' reminders while the event remained in the lookahead window. This issue is fixed in version 0.11.1.11hCVE-2026-817876.5 MED—
———Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.11hCVE-2026-817886.3 MED—
———Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.13hCVE-2026-870117.5 HIG—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and signing keys before validating a submitted logout token. Each request repeated uncached network fetches, and the signing-key lookup blocked the async event loop, so requests carrying invalid tokens could stall the single-worker instance and amplify traffic to the identity provider when ENABLE_OAUTH_BACKCHANNEL_LOGOUT was enabled. This issue is fixed in version 0.11.1.14hCVE-2026-795226.5 MED—
———An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.10hCVE-2026-795164.0 MED—
———An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.13hCVE-2026-817898.6 HIG—
———Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions.8hCVE-2026-795154.3 MED—
———An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.13hCVE-2026-817916.5 MED—
———Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.13hCVE-2026-817936.5 MED—
———Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.13hCVE-2026-817947.5 HIG—
———Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.11hCVE-2026-795146.5 MED—
———An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.13hCVE-2026-817957.1 HIG—
———Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.13hCVE-2026-817967.3 HIG—
———Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.8hCVE-2026-795136.5 MED—
———A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.13hCVE-2026-817997.5 HIG—
———Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.13hCVE-2026-818009.3 CRI—
———Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.13hCVE-2026-818018.1 HIG—
———Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.11hCVE-2026-818037.5 HIG—
———Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.13hCVE-2026-818047.5 HIG—
———Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.8hCVE-2026-79387——
———SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.13hCVE-2026-818058.1 HIG—
———Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.13hCVE-2026-718088.8 HIG—
———A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java).13hCVE-2026-848167.1 HIG—
———Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.13hCVE-2026-848197.1 HIG—
———Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.11hCVE-2026-848217.5 HIG—
———Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.13hCVE-2026-718035.4 MED—
———money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. When processing returns, the backend fails to filter or escape the goodsName parameter, directly concatenating it into the order log description; the frontend subsequently renders this content using v-html. An attacker with product creation privileges can inject a malicious JavaScript payload, causing unauthorized code execution when an administrator views the order logs.10hCVE-2026-853106.5 MED—
———import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.8hCVE-2026-88004——
———Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthenticated client to submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer. When the retry or buffering middleware reads the body before the reverse proxy clones the request, the attacker-controlled trailer value reaches a backend that merges trailers into the header namespace, bypassing the documented delete or reject behavior and potentially spoofing identity or forwarded routing data. This issue is fixed in 3.7.13.9hCVE-2026-880056.5 MED—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through this endpoint. This issue is fixed in version 0.9.0.9hCVE-2026-71802——
———A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the escaped entities using jQuery's `html().text()` method and subsequently injects the result into the DOM. An administrator or attacker capable of controlling the announcement content can exploit this vulnerability to execute arbitrary JavaScript code in the browsers of users viewing the affected pages "which may include the dashboard, activity feed, or login page, depending on the announcement's visibility settings.13hCVE-2026-880066.5 MED—
———Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session at their existing role through this endpoint. This issue is fixed in version 0.11.1.9hCVE-2026-88007——
———Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.9h