01 Search console
The CVE corpus, on scope in milliseconds.
403,725 records · updated every 15 minutes
02 Telemetry
Total CVEs403,725
New today30
Known-exploited (KEV)1,739
Sync lag59 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-893017.5High—rtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Missing Authorization to Unauthenticated Limited File Read/Disclosure and Limited File Deletion via Sideload via 'files[tmp_name]' Parameterrtcamp rtmedia for wordpress, buddypress and bbpress1 HR AGO
CVE-2026-976709.1Critical—Avada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Fieldthemefusion avada (fusion) builder1 HR AGO
CVE-2026-1040217.2High—Fastcache by Host.it <= 1.7.4 - Authenticated (Administrator+) Code Injection via .htaccess Directive Injection via 'cache_cookie_exclude' Settinghostspa fastcache by host.it1 HR AGO
CVE-2026-96966.4Medium—Download Manager <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_packages Shortcodecodename065 download manager1 HR AGO
CVE-2026-1047245.3Medium—FireBox <= 3.1.13 - Authenticated (Author+) SQL Injection via FireBox Form Display Conditionfireplugins firebox – woocommerce popup builder, exit intent popup, email optin & cart abandonment1 HR AGO
CVE-2026-1039986.1Medium—Form Maker by 10Web <= 1.15.48 - Reflected Cross-Site Scripting via 'inputs' Parameter Array Key10web form maker by 10web – mobile-friendly drag & drop contact form builder1 HR AGO
CVE-2026-1034245.4Medium—Anti-Spam by CleanTalk <= 6.88 - Unauthenticated Stored Cross-Site Scripting via Comment Content via ContactsEncoder Greedy Regexcleantalk anti-spam by cleantalk – spam protection without captcha1 HR AGO
CVE-2026-67235.3Medium—Appointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Tokencroixhaug simply schedule appointments1 HR AGO
CVE-2026-1047356.4Medium—RSS Aggregator by Feedzy <= 5.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title>themeisle rss aggregator by feedzy – feed to post, autoblogging, news & youtube video feeds aggregator1 HR AGO
CVE-2026-1039644.3Medium—Download Manager <= 3.3.71 - Authenticated (Subscriber+) Sensitive Information Exposure via Email Template Token Injection in 'first_name' Profile Field Token Injection into Suspension Emailcodename065 download manager1 HR AGO
CVE-2026-878696.1Medium—Filter Everything — WordPress & WooCommerce Filters <= 1.9.6 - Reflected Cross-Site Scripting via Elementor Posts Widget Pagination URLstepasyuk filter everything — wordpress & woocommerce filters1 HR AGO
CVE-2026-976306.4Medium—FV Flowplayer Video Player <= 7.5.54.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Unquoted popup Shortcode Attributefoliovision fv flowplayer video player1 HR AGO
CVE-2026-57275.4Medium—Hello Plus <= 1.7.7 - Authenticated (Contributor+) Missing Authorization to Template Activation via hello_plus_set_as_entire_siteelemntor hello plus1 HR AGO
CVE-2026-1024016.4Medium—Download Manager <= 3.3.71 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'regurl' Shortcode Attributecodename065 download manager1 HR AGO
CVE-2026-1013244.7Medium—Fluent Forms <= 6.2.14 - Reflected Cross-Site Scripting via '{get.*}' Editor SmartCode Parameterwpmanageninja fluent forms – customizable contact forms, survey, quiz, & conversational form builder1 HR AGO
05 Recently added to KEV
KEVCVE-2023-22894Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that containAdded 2026-10-08
KEVCVE-2021-3199Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.Added 2026-10-08
KEVCVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related toAdded 2026-10-08
KEVCVE-2015-5477named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.Added 2026-10-08
KEVCVE-2015-3306The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.Added 2026-10-08