02 Telemetry
FEED: ACQUIRING
03 Severity mix
WINDOW: T-30D
04 Latest published
FEED: ACQUIRING
01 Search consoleIDX: 382,272
The CVE corpus, on scope in milliseconds.
382,272 records · updated every 15 minutes
02 Telemetry
FEED: LIVETotal CVEs382,272
New today55
Known-exploited (KEV)1,675
Sync lag26 MIN
03 Severity mix
WINDOW: T-30D
CRITICAL 15%HIGH 45%MEDIUM 37%LOW 3%NONE 0%
04 Latest published
LAST 15 / 15-MIN SYNCCVE IDCVSSSeverityKEVSummaryVendor / ProductPublished
CVE-2026-199436.4Medium—6.4MediumGutenverse <= 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attributejegstudio gutenverse – wordpress blocks, page builder & site editor30 MIN AGO CVE-2026-142806.6Medium—6.6MediumEvents Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keysnetweblogic events manager – calendar, bookings, tickets, and more!30 MIN AGO CVE-2026-170896.1Medium—6.1MediumEvents Manager <= 7.4.0.1 - Reflected Cross-Site Scripting via 'header_format' Parameternetweblogic events manager – calendar, bookings, tickets, and more!30 MIN AGO CVE-2026-760636.4Medium—6.4MediumFundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameterroxnor fundengine – donation and crowdfunding platform31 MIN AGO CVE-2026-198928.8High—8.8HighInfusedWoo Pro <= 5.1.18 - Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosureinfused addons infusedwoo pro31 MIN AGO CVE-2026-759304.3Medium—4.3MediumFundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' Parameterroxnor fundengine – donation and crowdfunding platform31 MIN AGO CVE-2026-750196.4Medium—6.4MediumCozy Blocks <= 2.2.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via cozyHoverEffect Block Attributecozythemes cozy blocks – page builder for gutenberg editor & fse with 700+ patterns, 58 blocks & templates1 HR AGO CVE-2025-98786.4Medium—6.4MediumPassword Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scriptingbuildwps ppwp – password protect pages1 HR AGO CVE-2026-759824.4Medium—4.4MediumLearnPress <= 4.4.4 - Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameterthimpress learnpress – wordpress lms plugin for create and sell online courses1 HR AGO CVE-2026-106275.3Medium—5.3MediumEvents Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parametersnetweblogic events manager – calendar, bookings, tickets, and more!1 HR AGO CVE-2026-786858.6High—8.6HighLe-yan|Medical Practice Management System - Remote Code Executionle-yan medical practice management system1 HR AGO CVE-2026-786839.4Critical—9.4CriticalNLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserializationnltk nltk2 HR AGO CVE-2026-786828.7High—8.7HighNLTK before 3.10.3 SSRF Protection Bypass via Proxynltk nltk2 HR AGO CVE-2026-786818.7High—8.7HighNLTK before 3.10.3 Entity Expansion DoS via ElementTreenltk nltk2 HR AGO CVE-2026-786808.5High—8.5HighNLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binarynltk nltk2 HR AGO 05 Recently added to KEV
SRC: CISAKEVCVE-2026-21962oracle corporation oracle http server, oracle weblogic server proxy plug-inAdded 2026-08-24