synced 1 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

404,030 records · updated every 15 minutes

02 Telemetry

Total CVEs404,030
New today335
Known-exploited (KEV)1,739
Sync lag85 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1036854.3Medium—4.3MediumWordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.4 - Broken Access Control vulnerabilityvillatheme ald – dropshipping and fulfillment for aliexpress and woocommerce1 HR AGO
CVE-2026-1086045.8Medium—5.8MediumTabularis through 0.27.0 Read-Only Bypass via MCP run_query SELECT Classificationtabularisdb tabularis1 HR AGO
CVE-2026-1086034.8Medium—4.8Mediumslide-maker through 5.8.0 Path Traversal via generate_images_openai.pyaddsumtech slide-maker1 HR AGO
CVE-2026-1086025.3Medium—5.3MediumHelicone through v2025.08.21-1 SSRF via Jawn Webhook Sender DNS Resolutionhelicone helicone1 HR AGO
CVE-2026-273507.2High—7.2HighWordPress Builderius plugin <= 1.4-beta - Server Side Request Forgery (SSRF) vulnerabilitybuilderius.io builderius1 HR AGO
CVE-2026-978536.9Medium—6.9MediumUnbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoSericmj decimal1 HR AGO
CVE-2026-664805.3Medium—5.3MediumWordPress YITH WooCommerce Product Add-Ons plugin <= 4.34.0 - Sensitive Data Exposure vulnerabilityyith yith woocommerce product add-ons1 HR AGO
CVE-2026-577427.1High—7.1HighWordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerabilitythemerex group kids planet1 HR AGO
CVE-2026-1074345.4Medium—5.4MediumWordPress MicroPayments plugin <= 3.2.9 - Bypass Vulnerability vulnerabilityvideowhisper micropayments1 HR AGO
CVE-2026-1074205.3Medium—5.3MediumWordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin <= 1.7.2 - Bypass Vulnerability vulnerabilitynarinder singh pay with metamask for woocommerce – cryptocurrency payment gateway1 HR AGO
CVE-2026-817979.8Critical—9.8CriticalWordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - PHP Object Injection vulnerabilitythemerex buzz stone | magazine & viral blog wordpress theme1 HR AGO
CVE-2026-785359.8Critical—9.8CriticalWordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerabilitythemerex photolia1 HR AGO
CVE-2026-785347.1High—7.1HighWordPress Educavo theme <= 3.4.2 - Cross Site Scripting (XSS) vulnerabilitykeen it solutions educavo1 HR AGO
CVE-2026-785339.8Critical—9.8CriticalWordPress Qwery theme <= 3.6.1 - PHP Object Injection vulnerabilityancorathemes qwery1 HR AGO
CVE-2026-785327.1High—7.1HighWordPress LMS theme <= 8.3 - Cross Site Scripting (XSS) vulnerabilitydesignthemes lms1 HR AGO

05 Recently added to KEV

KEVCVE-2023-22894Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that containAdded 2026-10-08
KEVCVE-2021-3199Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.Added 2026-10-08
KEVCVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related toAdded 2026-10-08
KEVCVE-2015-5477named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.Added 2026-10-08
KEVCVE-2015-3306The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.Added 2026-10-08
KEVCVE-2026-88779netscaler adc netscaler gatewayAdded 2026-10-04