01 Search console
The CVE corpus, on scope in milliseconds.
404,030 records · updated every 15 minutes
02 Telemetry
Total CVEs404,030
New today335
Known-exploited (KEV)1,739
Sync lag85 MIN
03 Severity mix
04 Latest published
CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-1036854.3Medium—WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.4 - Broken Access Control vulnerabilityvillatheme ald – dropshipping and fulfillment for aliexpress and woocommerce1 HR AGO
CVE-2026-1086045.8Medium—Tabularis through 0.27.0 Read-Only Bypass via MCP run_query SELECT Classificationtabularisdb tabularis1 HR AGO
CVE-2026-1086034.8Medium—slide-maker through 5.8.0 Path Traversal via generate_images_openai.pyaddsumtech slide-maker1 HR AGO
CVE-2026-1086025.3Medium—Helicone through v2025.08.21-1 SSRF via Jawn Webhook Sender DNS Resolutionhelicone helicone1 HR AGO
CVE-2026-273507.2High—WordPress Builderius plugin <= 1.4-beta - Server Side Request Forgery (SSRF) vulnerabilitybuilderius.io builderius1 HR AGO
CVE-2026-978536.9Medium—Unbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoSericmj decimal1 HR AGO
CVE-2026-664805.3Medium—WordPress YITH WooCommerce Product Add-Ons plugin <= 4.34.0 - Sensitive Data Exposure vulnerabilityyith yith woocommerce product add-ons1 HR AGO
CVE-2026-577427.1High—WordPress Kids Planet theme <= 2.2.14.2 - Cross Site Scripting (XSS) vulnerabilitythemerex group kids planet1 HR AGO
CVE-2026-1074345.4Medium—WordPress MicroPayments plugin <= 3.2.9 - Bypass Vulnerability vulnerabilityvideowhisper micropayments1 HR AGO
CVE-2026-1074205.3Medium—WordPress Pay With MetaMask For WooCommerce – Cryptocurrency Payment Gateway plugin <= 1.7.2 - Bypass Vulnerability vulnerabilitynarinder singh pay with metamask for woocommerce – cryptocurrency payment gateway1 HR AGO
CVE-2026-817979.8Critical—WordPress Buzz Stone | Magazine & Viral Blog WordPress Theme theme <= 1.0.2 - PHP Object Injection vulnerabilitythemerex buzz stone | magazine & viral blog wordpress theme1 HR AGO
CVE-2026-785359.8Critical—WordPress Photolia theme <= 1.0.3 - PHP Object Injection vulnerabilitythemerex photolia1 HR AGO
CVE-2026-785347.1High—WordPress Educavo theme <= 3.4.2 - Cross Site Scripting (XSS) vulnerabilitykeen it solutions educavo1 HR AGO
CVE-2026-785339.8Critical—WordPress Qwery theme <= 3.6.1 - PHP Object Injection vulnerabilityancorathemes qwery1 HR AGO
CVE-2026-785327.1High—WordPress LMS theme <= 8.3 - Cross Site Scripting (XSS) vulnerabilitydesignthemes lms1 HR AGO
05 Recently added to KEV
KEVCVE-2023-22894Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that containAdded 2026-10-08
KEVCVE-2021-3199Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.Added 2026-10-08
KEVCVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related toAdded 2026-10-08
KEVCVE-2015-5477named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.Added 2026-10-08
KEVCVE-2015-3306The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.Added 2026-10-08