synced 13 MIN AGO
01 Search console

The CVE corpus, on scope in milliseconds.

403,725 records · updated every 15 minutes

02 Telemetry

Total CVEs403,725
New today30
Known-exploited (KEV)1,739
Sync lag59 MIN

03 Severity mix

04 Latest published

CVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-893017.5High—7.5HighrtMedia for WordPress, BuddyPress and bbPress <= 4.7.13 - Missing Authorization to Unauthenticated Limited File Read/Disclosure and Limited File Deletion via Sideload via 'files[tmp_name]' Parameterrtcamp rtmedia for wordpress, buddypress and bbpress1 HR AGO
CVE-2026-976709.1Critical—9.1CriticalAvada (Fusion) Builder <= 7.16.1 - Unauthenticated Arbitrary WordPress Action Invocation via '{action_hook}' Dynamic-Data Token in Form Fieldthemefusion avada (fusion) builder1 HR AGO
CVE-2026-1040217.2High—7.2HighFastcache by Host.it <= 1.7.4 - Authenticated (Administrator+) Code Injection via .htaccess Directive Injection via 'cache_cookie_exclude' Settinghostspa fastcache by host.it1 HR AGO
CVE-2026-96966.4Medium—6.4MediumDownload Manager <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_packages Shortcodecodename065 download manager1 HR AGO
CVE-2026-1047245.3Medium—5.3MediumFireBox <= 3.1.13 - Authenticated (Author+) SQL Injection via FireBox Form Display Conditionfireplugins firebox – woocommerce popup builder, exit intent popup, email optin & cart abandonment1 HR AGO
CVE-2026-1039986.1Medium—6.1MediumForm Maker by 10Web <= 1.15.48 - Reflected Cross-Site Scripting via 'inputs' Parameter Array Key10web form maker by 10web – mobile-friendly drag & drop contact form builder1 HR AGO
CVE-2026-1034245.4Medium—5.4MediumAnti-Spam by CleanTalk <= 6.88 - Unauthenticated Stored Cross-Site Scripting via Comment Content via ContactsEncoder Greedy Regexcleantalk anti-spam by cleantalk – spam protection without captcha1 HR AGO
CVE-2026-67235.3Medium—5.3MediumAppointment Booking Calendar <= 1.6.11.11 - Incorrect Authorization to Unauthenticated Sensitive Field Modification via Appointment Public Tokencroixhaug simply schedule appointments1 HR AGO
CVE-2026-1047356.4Medium—6.4MediumRSS Aggregator by Feedzy <= 5.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title>themeisle rss aggregator by feedzy – feed to post, autoblogging, news & youtube video feeds aggregator1 HR AGO
CVE-2026-1039644.3Medium—4.3MediumDownload Manager <= 3.3.71 - Authenticated (Subscriber+) Sensitive Information Exposure via Email Template Token Injection in 'first_name' Profile Field Token Injection into Suspension Emailcodename065 download manager1 HR AGO
CVE-2026-878696.1Medium—6.1MediumFilter Everything — WordPress & WooCommerce Filters <= 1.9.6 - Reflected Cross-Site Scripting via Elementor Posts Widget Pagination URLstepasyuk filter everything — wordpress & woocommerce filters1 HR AGO
CVE-2026-976306.4Medium—6.4MediumFV Flowplayer Video Player <= 7.5.54.7212 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Unquoted popup Shortcode Attributefoliovision fv flowplayer video player1 HR AGO
CVE-2026-57275.4Medium—5.4MediumHello Plus <= 1.7.7 - Authenticated (Contributor+) Missing Authorization to Template Activation via hello_plus_set_as_entire_siteelemntor hello plus1 HR AGO
CVE-2026-1024016.4Medium—6.4MediumDownload Manager <= 3.3.71 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'regurl' Shortcode Attributecodename065 download manager1 HR AGO
CVE-2026-1013244.7Medium—4.7MediumFluent Forms <= 6.2.14 - Reflected Cross-Site Scripting via '{get.*}' Editor SmartCode Parameterwpmanageninja fluent forms – customizable contact forms, survey, quiz, & conversational form builder1 HR AGO

05 Recently added to KEV

KEVCVE-2023-22894Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that containAdded 2026-10-08
KEVCVE-2021-3199Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.Added 2026-10-08
KEVCVE-2016-3081Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related toAdded 2026-10-08
KEVCVE-2015-5477named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.Added 2026-10-08
KEVCVE-2015-3306The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.Added 2026-10-08
KEVCVE-2026-88779netscaler adc netscaler gatewayAdded 2026-10-04