Free CVE lookup

Look up a CVE

Search a CVE ID, or browse by product. Each report lists the affected version, the CVSS score, and a defensive self-check. No subscription and no exploit writeup. Search by CVE ID.

1088Tracked CVEs
30CVSS 10.0
320Critical (9.0+)
15CISA KEV
19Actively Exploited
388Public PoC
3This Week
Step 1

Search the CVE or product

Use lookup or product groups to find whether the advisory touches your CMS, plugin, server, package, or appliance.

Open CVE Lookup
Step 2

Run the defensive self-check

Check version, exposure, enabled modules, logs, users, files, and vendor patch notes. The guides avoid payloads and unauthorized testing.

See latest guides
Step 3

Confirm it with a free tool

Use the WordPress, cPanel, or NGINX check on a site you own. Ping7 does not sell a CVE watch list.

Open the free tools

Updated coverage

Latest covered CVEs

Newest Ping7 coverage from the current CVE feed. Open a card to check affected versions, exposure, patch status, and signs of compromise.

Latest CVE drops

The 24 newest of 1088 tracked reports, newest first. Open a card for the defensive self-check. Older entries stay on their own pages.

LATEST
2026-09-25 CVSS 9.8

CVE-2026-87902

WordPress core - template file inclusion review

CVE-2026-87902 was added to CISA KEV on 2026-09-25. Confirm the WordPress version against the vendor advisory, update core, and review theme files plus administrator accounts on sites you own.

WordPress CISA KEV Active Exploit
2026-09-25 CVSS 9.8

CVE-2026-65660

SharePoint - code injection review

CVE-2026-65660 was added to CISA KEV on 2026-09-25. Match the farm build to the Microsoft fix, restrict unneeded access, and review site-collection administrators and newly added solution files.

Microsoft SharePoint CISA KEV Active Exploit
2026-09-24 CVSS 9.8

CVE-2026-71362

Adobe Commerce and Magento - authorization review

CVE-2026-71362 was added to CISA KEV on 2026-09-24. Apply the Adobe fix, then review administrator roles, integration tokens, and unexpected order or configuration changes.

Adobe Commerce / Magento CISA KEV Active Exploit
2026-09-16 CVSS 8.8

CVE-2026-87886

Acronis Backup cPanel plugin - permission review

CVE-2026-87886 was added to CISA KEV on 2026-09-16. Update the Acronis cPanel/WHM plugin or Plesk extension, then review file permissions, WHM users, and backup jobs on servers you administer.

Acronis Backup CISA KEV Active Exploit
2026-09-11 CVSS 9.8

CVE-2026-85706

GitLab - commits API file access review

CVE-2026-85706 was added to CISA KEV on 2026-09-11. Upgrade the GitLab instance to the fixed release and review whether public projects exposed files that should have stayed private.

GitLab CISA KEV Active Exploit
2026-09-08 CVSS 9.8

CVE-2026-75650

Adobe Commerce and Magento - template input review

CVE-2026-75650 was added to CISA KEV on 2026-09-08. Patch the store, then review CMS and email templates plus administrator accounts for changes you did not make.

Adobe Commerce / Magento CISA KEV Active Exploit
2026-08-31 CVSS 9.4

CVE-2026-82078

PaperCut NG and MF - configuration review

CVE-2026-82078 was added to CISA KEV on 2026-08-31. PaperCut fixed it on 2026-08-27 in NG and MF 26.0.5, 25.0.13, and 24.1.10. Confirm the version on servers you own.

PaperCut NG/MF CISA KEV Active Exploit
2026-08-31 CVSS 8.8

CVE-2026-81578

PaperCut NG and MF - admin access review

CVE-2026-81578 was added to CISA KEV on 2026-08-31 and is fixed in the same PaperCut NG and MF releases as CVE-2026-82078: 26.0.5, 25.0.13, and 24.1.10.

PaperCut NG/MF CISA KEV Active Exploit
2026-08-04 CVSS 9.8

CVE-2026-34486

Apache Tomcat - version review

CVE-2026-34486 was added to CISA KEV on 2026-08-04. Apache says it affects only Tomcat 11.0.20, 10.1.53, and 9.0.116, fixed in 11.0.21, 10.1.54, and 9.0.117.

Apache Tomcat CISA KEV Active Exploit
2026-07-21 CVSS 9.8

CVE-2026-60137

WordPress core - SQL injection review

CVE-2026-60137 was added to CISA KEV on 2026-07-21. WordPress fixed it on 2026-07-17 in 7.0.2, 6.9.5, and 6.8.6. Confirm the core version, then review administrator accounts and unexpected PHP files on sites you own.

WordPress CISA KEV Active Exploit
2026-07-21 CVSS 9.8

CVE-2026-63030

WordPress core - REST route review

CVE-2026-63030 was added to CISA KEV on 2026-07-21 and is fixed in WordPress 7.0.2 and 6.9.5. WordPress says the 6.8 line is not affected by this one. Confirm the core version on sites you own.

WordPress CISA KEV Active Exploit
2026-07-11 CVSS 7.5

CVE-2026-9282

W3 Total Cache - file read exposure risk

CVE-2026-9282 affects W3 Total Cache <= 2.9.4. Preserve logs, confirm the deployed version, review manual minify settings, cache files, sensitive file access, and web logs, and keep public access restricted until patching and integrity checks are complete.

W3 Total Cache
2026-07-11 CVSS 8.8

CVE-2026-1359

Genolve AI media plugin - settings authorization gap

CVE-2026-1359 affects Genolve AI image AI video generation vendor advisory. Preserve logs, confirm the deployed version, review plugin options, administrator changes, generated media, and access logs, and keep public access restricted until patching and integrity checks are complete.

Genolve AI image AI video generation
2026-07-11 CVSS 8.8

CVE-2025-6784

Code Engine - shortcode code execution risk

CVE-2025-6784 affects Code Engine <= 0.3.5. Preserve logs, confirm the deployed version, review shortcodes, post content, administrator edits, and plugin files, and keep public access restricted until patching and integrity checks are complete.

Code Engine
2026-07-11 CVSS 8.8

CVE-2026-15155

Essential Addons for Elementor - account takeover review

CVE-2026-15155 affects Essential Addons for Elementor <= 6.6.10. Preserve logs, confirm the deployed version, review login/register flows, email changes, reset activity, and admin sessions, and keep public access restricted until patching and integrity checks are complete.

Essential Addons for Elementor
2026-07-11 CVSS 7.5

CVE-2026-4661

WP CTA - SQL injection exposure risk

CVE-2026-4661 affects WP CTA - Sticky CTA Builder <= 1.7.4. Preserve logs, confirm the deployed version, review CTA forms, database errors, query logs, and lead data access, and keep public access restricted until patching and integrity checks are complete.

WP CTA - Sticky CTA Builder
2026-07-11 CVSS 8.1

CVE-2026-7655

SureCart - account takeover and role review

CVE-2026-7655 affects SureCart <= 4.2.3. Preserve logs, confirm the deployed version, review customer accounts, administrator users, orders, webhooks, and login history, and keep public access restricted until patching and integrity checks are complete.

SureCart
2026-07-11 CVSS 8.8

CVE-2026-14262

Simple JWT Login - authentication bypass review

CVE-2026-14262 affects Simple JWT Login <= 3.6.6. Preserve logs, confirm the deployed version, review JWT settings, REST login events, new sessions, and administrator roles, and keep public access restricted until patching and integrity checks are complete.

Simple JWT Login
2026-07-11 CVSS 7.5

CVE-2026-15335

Booking Package - booking-form SQL injection risk

CVE-2026-15335 affects Booking Package <= 1.7.20. Preserve logs, confirm the deployed version, review booking forms, database errors, customer records, and plugin logs, and keep public access restricted until patching and integrity checks are complete.

Booking Package
2026-07-11 CVSS 8.8

CVE-2026-2354

Swiss Toolkit For WP - file upload exposure risk

CVE-2026-2354 affects Swiss Toolkit For WP <= 1.4.2. Preserve logs, confirm the deployed version, review uploads, plugin extension files, executable files, and recent file changes, and keep public access restricted until patching and integrity checks are complete.

Swiss Toolkit For WP
2026-07-11 CVSS 8.8

CVE-2026-13353

WP Ultimate CSV Importer - import workflow code execution risk

CVE-2026-13353 affects WP Ultimate CSV Importer <= 8.0.1. Preserve logs, confirm the deployed version, review CSV imports, add-on installs, administrator activity, and modified files, and keep public access restricted until patching and integrity checks are complete.

WP Ultimate CSV Importer
2026-07-11 CVSS 7.5

CVE-2026-15338

LA-Studio Element Kit for Elementor - template file inclusion risk

CVE-2026-15338 affects LA-Studio Element Kit for Elementor <= 1.6.1. Preserve logs, confirm the deployed version, review Elementor templates, theme files, PHP errors, and page-builder edits, and keep public access restricted until patching and integrity checks are complete.

LA-Studio Element Kit for Elementor
2026-07-11 CVSS 8.8

CVE-2026-13756

WP Grid Builder - privilege escalation review

CVE-2026-13756 affects WP Grid Builder <= 2.3.3. Preserve logs, confirm the deployed version, review role changes, grid settings, user meta changes, and admin sessions, and keep public access restricted until patching and integrity checks are complete.

WP Grid Builder
2026-07-11 CVSS 7.2

CVE-2026-6939

CorvusPay WooCommerce Gateway - stored script review

CVE-2026-6939 affects CorvusPay WooCommerce Payment Gateway <= 2.7.4. Preserve logs, confirm the deployed version, review payment callbacks, order notes, checkout fields, and WooCommerce logs, and keep public access restricted until patching and integrity checks are complete.

CorvusPay WooCommerce Payment Gateway

Look up an older CVE or use the product directory below. This page no longer repeats the full catalog.

Ranked by severity

The highest-scoring reports in each bucket, limited to 24. Perfect scores (10.0) and zero-auth criticals get scanned within hours of disclosure.

🔴 CVSS 10.0 — Perfect score, drop everything

2026-07-02 CVSS 10.0

CVE-2026-57624

Blocksy Companion Pro - unauthenticated code execution risk

CVE-2026-57624 affects Blocksy Companion Pro <= 2.1.46. Site owners should patch or disable the component, preserve logs, review plugin files, admin users, and server-side error logs, and clear caches only after evidence is saved.

Blocksy Companion Pro
2026-06-30 CVSS 10.0

CVE-2026-48286

Adobe Campaign Classic - incorrect authorization code execution risk

CVE-2026-48286 affects Adobe Campaign Classic <= 7.4.3 build 9396. Operators should confirm whether the platform is reachable, patch to the fixed version, review operator roles, workflow logs, and campaign job activity, and rotate secrets if execution or workflow integrity is uncertain.

Adobe Campaign Classic Public PoC
2026-06-29 CVSS 10.0

CVE-2026-56290

Page Builder CK - unauthenticated file upload risk

CVE-2026-56290 affects the Page Builder CK Joomla extension. Joomla owners should patch the extension, restrict administrative access, preserve logs, and review uploaded files and extension state.

Page Builder CK
2026-06-26 CVSS 10.0

CVE-2026-53576

Kestra - authentication boundary risk

CVE-2026-53576 affects Kestra. Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public i... Patch the affected deployment and review workflow and admin logs.

Kestra
2026-06-26 CVSS 10.0

CVE-2026-54350

Budibase - authentication boundary risk

CVE-2026-54350 affects Budibase. Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with... Patch the affected deployment and review workflow and admin logs.

Budibase
2026-06-25 CVSS 10.0

CVE-2026-46752

Apache Kvrocks - security boundary risk

CVE-2026-46752 affects Apache Kvrocks. Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. Patch the affected deployment and review component presence.

Apache Kvrocks
2026-06-25 CVSS 10.0

CVE-2026-57700

Daan.Dev OMGF Pro - Unrestricted Upload of File with Dangerous Type vulnerability

CVE-2026-57700 affects Daan.Dev OMGF Pro vendor-fixed release. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.

Daan.Dev OMGF Pro
2026-06-24 CVSS 10.0

CVE-2026-12485

GeoVision GV-I/O Box 4E - DVRSearch stack overflow risk

CVE-2026-12485 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.

GeoVision GV-I/O Box 4E
2026-06-24 CVSS 10.0

CVE-2026-12846

GeoVision GV-I/O Box 4E - network configuration stack overflow risk

CVE-2026-12846 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.

GeoVision GV-I/O Box 4E
2026-06-24 CVSS 10.0

CVE-2026-12847

GeoVision GV-I/O Box 4E - gateway field stack overflow risk

CVE-2026-12847 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.

GeoVision GV-I/O Box 4E
2026-06-24 CVSS 10.0

CVE-2026-12848

GeoVision GV-I/O Box 4E - DNS field stack overflow risk

CVE-2026-12848 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.

GeoVision GV-I/O Box 4E
2026-06-19 CVSS 10.0

CVE-2026-48772

ProxySQL - MySQL frontend memory corruption risk

CVE-2026-48772 affects ProxySQL 2.0.0 through 3.0.8. Patch to 3.0.9 or newer, restrict exposed listeners, and review ProxySQL listeners, crashes, restarts, and frontend access.

ProxySQL
2026-06-19 CVSS 10.0

CVE-2026-48908

Joomla SP Page Builder - unauthenticated file upload

CVE-2026-48908 affects Joomla SP Page Builder vendor advisory. Check whether the extension is installed, remove abandoned copies, and review uploads, executable files, and public builder routes.

Joomla SP Page Builder Public PoC
2026-06-19 CVSS 10.0

CVE-2026-48939

Joomla iCagenda - file attachment upload risk

CVE-2026-48939 affects Joomla iCagenda vendor advisory. Check whether the extension is installed, remove abandoned copies, and review event attachments, uploads, and executable files.

Joomla iCagenda Public PoC
2026-06-18 CVSS 10.0

CVE-2026-49257

mcp-pinot - unauthenticated MCP server exposure

CVE-2026-49257 affects mcp-pinot through 3.0.1. Review Pinot credentials, MCP access logs, and table/config changes, then apply the vendor fix or remove the risky exposure until patched.

mcp-pinot Public PoC
2026-06-17 CVSS 10.0

CVE-2025-69129

WordPress and WooCommerce Scraper - unauthenticated arbitrary file upload

CVE-2025-69129 affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site through 1.0.7. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

WordPress & WooCommerce Scraper Plugin, Import Data from Any Site
2026-06-17 CVSS 10.0

CVE-2026-25470

ACPT Pro - remote code execution

CVE-2026-25470 affects ACPT Pro - Custom Post Types Plugin for WordPress through 2.0.47. Confirm the installed version, patch or disable the component, and review changed files, cron jobs, users, and web server logs before closing the incident.

ACPT Pro - Custom Post Types Plugin for WordPress Public PoC
2026-06-17 CVSS 10.0

CVE-2026-28587

Android MmsSmsProvider - permission check information disclosure

CVE-2026-28587 affects Android MmsSmsProvider permission handling. Managed fleets should apply the Android security bulletin update and review devices that process sensitive messaging data.

Android
2026-06-15 CVSS 10.0

CVE-2026-40772

GeekyBot - unauthenticated arbitrary file upload

CVE-2026-40772 affects GeekyBot through 1.2.2. WordPress sites should patch or disable the component, then review upload directories, new PHP files, and web access logs before closing the incident.

GeekyBot
2026-06-15 CVSS 10.0

CVE-2026-48836

Easy Invoice - unauthenticated remote code execution

CVE-2026-48836 affects Easy Invoice through 2.1.19. WordPress sites should patch or disable the component, then review changed files, cron jobs, users, and web server logs before closing the incident.

Easy Invoice
2026-06-15 CVSS 10.0

CVE-2026-52704

WooCommerce PDF Invoice Builder - remote code inclusion risk

CVE-2026-52704 affects WooCommerce PDF Invoice Builder through 2.0.8. Stores should disable or patch the plugin, review generated invoice files and templates, and check administrator activity before reopening payments.

WooCommerce PDF Invoice Builder
2026-06-12 CVSS 10.0

CVE-2026-47131

vm2 - sandbox escape via host TypeError exposure

CVE-2026-47131 affects vm2 before 3.11.4. Services that run untrusted JavaScript should upgrade, isolate sandbox workers, and review logs for unexpected outbound access or worker failures.

vm2 Public PoC
2026-06-12 CVSS 10.0

CVE-2026-47137

vm2 - NodeVM require guard bypass

CVE-2026-47137 affects vm2 before 3.11.4. Services that run untrusted JavaScript should upgrade, isolate sandbox workers, and review logs for unexpected outbound access or worker failures.

vm2 Public PoC
2026-06-12 CVSS 10.0

CVE-2026-47140

vm2 - dangerous builtin denylist gap

CVE-2026-47140 affects vm2 before 3.11.4. Services that run untrusted JavaScript should upgrade, isolate sandbox workers, and review logs for unexpected outbound access or worker failures.

vm2 Public PoC

🟠 Critical (CVSS 9.0–9.9) — Patch this week

2026-06-29 CVSS 9.9

CVE-2026-57331

Paid Videochat Turnkey Site - performer file deletion risk

CVE-2026-57331 affects Paid Videochat Turnkey Site <= 7.4.8. Site owners should patch the component, preserve logs, and review files and performer accounts before closing the issue.

Paid Videochat Turnkey Site
2026-06-28 CVSS 9.9

CVE-2026-58053

Gitea act_runner - Docker backend container hardening bypass

CVE-2026-58053 affects Gitea act_runner deployments that use the Docker backend through act 0.262.0. Owners should restrict who can run workflows, review Docker runner configuration, isolate runners from production hosts, and apply vendor hardening guidance.

Gitea act_runner Public PoC
2026-06-26 CVSS 9.9

CVE-2026-46386

OpenProject - security boundary risk

CVE-2026-46386 affects OpenProject Docker deployments that inherited an unsafe default application secret configuration. Patch the affected deployment and review workflow and admin logs.

OpenProject
2026-06-26 CVSS 9.9

CVE-2026-56027

Booster for WooCommerce - Customer Arbitrary File Upload

CVE-2026-56027 affects Booster for WooCommerce <= 8.0.1. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.

Booster for WooCommerce
2026-06-26 CVSS 9.9

CVE-2026-56058

Quform - Subscriber Arbitrary File Upload

CVE-2026-56058 affects Quform <= 2.23.0. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.

Quform
2026-06-26 CVSS 9.9

CVE-2026-56059

Travel Booking - Subscriber Arbitrary File Upload

CVE-2026-56059 affects Travel Booking <= 2.2.5. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.

Travel Booking
2026-06-25 CVSS 9.9

CVE-2026-54823

Widget Options - Contributor Remote Code Execution (remote code execution)

CVE-2026-54823 affects Widget Options <= 4.2.3. Site owners should patch the component, preserve logs, and review logs and users before closing the issue.

Widget Options
2026-06-24 CVSS 9.9

CVE-2026-55454

Appsmith - bundled Caddy admin API takeover risk

CVE-2026-55454 affects Appsmith before 2.1. Review Caddy configuration changes, SSRF exposure, and low-privilege user activity after upgrading.

Appsmith Public PoC
2026-06-23 CVSS 9.9

CVE-2026-56274

Flowise - Custom MCP Server command injection risk

CVE-2026-56274 affects Flowise before 3.1.2 through Custom MCP Server validation bypasses. Patch, restrict Flowise accounts and API keys, and review chatflow and MCP tool changes.

Flowise Public PoC
2026-06-17 CVSS 9.9

CVE-2024-52488

Grip theme - subscriber arbitrary file upload

CVE-2024-52488 affects Grip through 1.0.9. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Grip
2026-06-17 CVSS 9.9

CVE-2025-60218

PT Luxa Addons - subscriber arbitrary file upload

CVE-2025-60218 affects PT Luxa Addons through 1.2.2. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

PT Luxa Addons
2026-06-17 CVSS 9.9

CVE-2026-22327

Restaurt theme - subscriber arbitrary file upload

CVE-2026-22327 affects Restaurt through 1.0.4. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Restaurt
2026-06-17 CVSS 9.9

CVE-2026-25446

WishList Member X - subscriber arbitrary file upload

CVE-2026-25446 affects WishList Member X through 3.29.0. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

WishList Member X
2026-06-17 CVSS 9.9

CVE-2026-27041

Unlimited Elements for Elementor Premium - contributor arbitrary file upload

CVE-2026-27041 affects Unlimited Elements for Elementor (Premium) through 2.0.6. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Unlimited Elements for Elementor (Premium)
2026-06-17 CVSS 9.9

CVE-2026-39589

Webenvo theme - subscriber arbitrary file upload

CVE-2026-39589 affects Webenvo through 0.0.6. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Webenvo
2026-06-17 CVSS 9.9

CVE-2026-40746

Restaurant Zone theme - subscriber arbitrary file upload

CVE-2026-40746 affects Restaurant Zone through 0.7.8. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Restaurant Zone
2026-06-17 CVSS 9.9

CVE-2026-40747

Ecommerce Zone theme - subscriber arbitrary file upload

CVE-2026-40747 affects Ecommerce Zone through 0.9.7. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Ecommerce Zone
2026-06-17 CVSS 9.9

CVE-2026-40748

Kids Gift Shop theme - subscriber arbitrary file upload

CVE-2026-40748 affects Kids Gift Shop through 0.5.4. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Kids Gift Shop
2026-06-17 CVSS 9.9

CVE-2026-40749

Charity Zone theme - subscriber arbitrary file upload

CVE-2026-40749 affects Charity Zone through 1.1.1. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.

Charity Zone
2026-06-17 CVSS 9.9

CVE-2026-40783

Blocksy Companion Pro - contributor remote code execution

CVE-2026-40783 affects Blocksy Companion Pro through 2.1.37. Confirm the installed version, patch or disable the component, and review changed files, cron jobs, users, and web server logs before closing the incident.

Blocksy Companion Pro Public PoC
2026-06-17 CVSS 9.9

CVE-2026-46850

MySQL Shell for VS Code - June 2026 Oracle CPU critical issue

CVE-2026-46850 affects MySQL Shell for VS Code 2026.2.0+9.6.1. Database teams should patch developer tooling and review saved connection profiles and extension access.

MySQL Shell for VS Code
2026-06-16 CVSS 9.9

CVE-2026-40750

WordPress Kids Online Store theme - dangerous file upload

CVE-2026-40750 affects the WordPress Kids Online Store theme through 0.8.9. Site owners should patch or replace the theme, block script execution from uploads, and review recent files and admin users.

Kids Online Store theme
2026-06-16 CVSS 9.9

CVE-2026-49774

RD Station - Remote code execution

CVE-2026-49774 affects RD Station through 5.6.0. Confirm the installed version, patch or disable the plugin, and review changed files, cron jobs, users, and web server logs before closing the incident.

RD Station

🟡 High (CVSS 7.0–8.9) — Patch this month

2026-06-24 CVSS 8.9

CVE-2026-50189

Appsmith - bundled supervisord XML-RPC exposure

CVE-2026-50189 affects Appsmith before 2.1. Review supervisord exposure, administrator activity, container process history, and environment access.

Appsmith Public PoC
2026-06-23 CVSS 8.9

CVE-2026-44792

n8n - Source Control Pull SQL injection

CVE-2026-44792 affects n8n instances using PostgreSQL and Source Control. Patch and review connected repositories, admin pulls, and Data Table import activity.

n8n Public PoC
2026-08-31 CVSS 8.8

CVE-2026-81578

PaperCut NG and MF - admin access review

CVE-2026-81578 was added to CISA KEV on 2026-08-31 and is fixed in the same PaperCut NG and MF releases as CVE-2026-82078: 26.0.5, 25.0.13, and 24.1.10.

PaperCut NG/MF CISA KEV Active Exploit
2026-09-16 CVSS 8.8

CVE-2026-87886

Acronis Backup cPanel plugin - permission review

CVE-2026-87886 was added to CISA KEV on 2026-09-16. Update the Acronis cPanel/WHM plugin or Plesk extension, then review file permissions, WHM users, and backup jobs on servers you administer.

Acronis Backup CISA KEV Active Exploit
2026-07-11 CVSS 8.8

CVE-2026-1359

Genolve AI media plugin - settings authorization gap

CVE-2026-1359 affects Genolve AI image AI video generation vendor advisory. Preserve logs, confirm the deployed version, review plugin options, administrator changes, generated media, and access logs, and keep public access restricted until patching and integrity checks are complete.

Genolve AI image AI video generation
2026-07-11 CVSS 8.8

CVE-2025-6784

Code Engine - shortcode code execution risk

CVE-2025-6784 affects Code Engine <= 0.3.5. Preserve logs, confirm the deployed version, review shortcodes, post content, administrator edits, and plugin files, and keep public access restricted until patching and integrity checks are complete.

Code Engine
2026-07-11 CVSS 8.8

CVE-2026-15155

Essential Addons for Elementor - account takeover review

CVE-2026-15155 affects Essential Addons for Elementor <= 6.6.10. Preserve logs, confirm the deployed version, review login/register flows, email changes, reset activity, and admin sessions, and keep public access restricted until patching and integrity checks are complete.

Essential Addons for Elementor
2026-07-11 CVSS 8.8

CVE-2026-14262

Simple JWT Login - authentication bypass review

CVE-2026-14262 affects Simple JWT Login <= 3.6.6. Preserve logs, confirm the deployed version, review JWT settings, REST login events, new sessions, and administrator roles, and keep public access restricted until patching and integrity checks are complete.

Simple JWT Login
2026-07-11 CVSS 8.8

CVE-2026-2354

Swiss Toolkit For WP - file upload exposure risk

CVE-2026-2354 affects Swiss Toolkit For WP <= 1.4.2. Preserve logs, confirm the deployed version, review uploads, plugin extension files, executable files, and recent file changes, and keep public access restricted until patching and integrity checks are complete.

Swiss Toolkit For WP
2026-07-11 CVSS 8.8

CVE-2026-13353

WP Ultimate CSV Importer - import workflow code execution risk

CVE-2026-13353 affects WP Ultimate CSV Importer <= 8.0.1. Preserve logs, confirm the deployed version, review CSV imports, add-on installs, administrator activity, and modified files, and keep public access restricted until patching and integrity checks are complete.

WP Ultimate CSV Importer
2026-07-11 CVSS 8.8

CVE-2026-13756

WP Grid Builder - privilege escalation review

CVE-2026-13756 affects WP Grid Builder <= 2.3.3. Preserve logs, confirm the deployed version, review role changes, grid settings, user meta changes, and admin sessions, and keep public access restricted until patching and integrity checks are complete.

WP Grid Builder
2026-06-29 CVSS 8.8

CVE-2026-40521

FrontAccounting - attachment upload path traversal

CVE-2026-40521 affects FrontAccounting before 2.4.20. Owners should patch supported deployments, remove unsupported public exposure, preserve logs, and review attachment uploads and web-root file changes.

FrontAccounting Public PoC
2026-06-26 CVSS 8.8

CVE-2025-68052

Eagle Booking - Unauthenticated Cross Site Request Forgery (CSRF)

CVE-2025-68052 affects Eagle Booking <= 1.3.4.3. Site owners should patch the component, preserve logs, and review users and access before closing the issue.

Eagle Booking
2026-06-26 CVSS 8.8

CVE-2026-56008

Fusion Builder - Contributor Privilege Escalation

CVE-2026-56008 affects Fusion Builder <= 3.15.4. Site owners should patch the component, preserve logs, and review users and access before closing the issue.

Fusion Builder
2026-06-26 CVSS 8.8

CVE-2026-56010

Abandoned Cart Pro for WooCommerce - Subscriber Privilege Escalation

CVE-2026-56010 affects Abandoned Cart Pro for WooCommerce <= 10.4.0. Site owners should patch the component, preserve logs, and review users and access before closing the issue.

Abandoned Cart Pro for WooCommerce
2026-06-26 CVSS 8.8

CVE-2026-56038

Frisbii Pay - Contributor Privilege Escalation

CVE-2026-56038 affects Frisbii Pay <= 1.8.2. Site owners should patch the component, preserve logs, and review users and access before closing the issue.

Frisbii Pay
2026-06-26 CVSS 8.8

CVE-2026-56055

RealHomes - Subscriber PHP Object Injection

CVE-2026-56055 affects RealHomes <= 4.5.3. Site owners should patch the component, preserve logs, and review logs and users before closing the issue.

RealHomes
2026-06-26 CVSS 8.8

CVE-2026-57518

Pagekit CMS - privilege escalation risk

CVE-2026-57518 affects Pagekit CMS. Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to mi... Patch the affected deployment and review web and app logs.

Pagekit CMS
2026-06-26 CVSS 8.8

CVE-2026-57659

Paid Memberships Pro - Add Member From Admin - Unauthenticated Cross Site Request Forgery (CSRF)

CVE-2026-57659 affects Paid Memberships Pro - Add Member From Admin <= 0.7.2. Site owners should patch the component, preserve logs, and review users and access before closing the issue.

Paid Memberships Pro - Add Member From Admin
2026-06-25 CVSS 8.8

CVE-2026-56053

EventPrime - Subscriber PHP Object Injection

CVE-2026-56053 affects EventPrime <= 4.3.4.1. Site owners should patch the component, preserve logs, and review logs and users before closing the issue.

EventPrime
2026-06-25 CVSS 8.8

CVE-2026-9155

Rapid7 InsightConnect Sed Plugin - command execution risk in Linux workflow action

CVE-2026-9155 affects the Rapid7 InsightConnect Sed Plugin on Linux. Review workflow runs, connector permissions, input sources, generated artifacts, and runner logs before re-enabling affected automation.

Rapid7 InsightConnect Sed Plugin
2026-06-24 CVSS 8.8

CVE-2026-9772

Unraid - FileUpload command execution risk

CVE-2026-9772 affects Unraid web administration paths where authenticated access can reach command execution risk. Restrict admin access, patch, and review plugin, upload, and process activity.

Unraid Public PoC
2026-06-24 CVSS 8.8

CVE-2026-9773

Unraid - ToggleState command execution risk

CVE-2026-9773 affects Unraid web administration paths where authenticated access can reach command execution risk. Restrict admin access, patch, and review plugin, upload, and process activity.

Unraid Public PoC
2026-06-24 CVSS 8.8

CVE-2026-57280

Jenkins Script Security Plugin - sandbox constructor bypass

CVE-2026-57280 affects a Jenkins plugin covered by the 2026-06-24 advisory. Patch the plugin, review permissions, and preserve controller logs before cleanup.

Jenkins

Grouped by product

The 48 products with the most tracked reports, out of 724. Each row shows the three newest, then links to the self-check.

CISA KEV & actively exploited

19 tracked reports with confirmed real-world exploitation. Patch these before the rest of the catalog.

⚠️ CISA KEV
2026-09-25 CVSS 9.8

CVE-2026-87902

WordPress core - template file inclusion review

CVE-2026-87902 was added to CISA KEV on 2026-09-25. Confirm the WordPress version against the vendor advisory, update core, and review theme files plus administrator accounts on sites you own.

WordPress CISA KEV Active Exploit
⚠️ CISA KEV
2026-09-25 CVSS 9.8

CVE-2026-65660

SharePoint - code injection review

CVE-2026-65660 was added to CISA KEV on 2026-09-25. Match the farm build to the Microsoft fix, restrict unneeded access, and review site-collection administrators and newly added solution files.

Microsoft SharePoint CISA KEV Active Exploit
⚠️ CISA KEV
2026-09-24 CVSS 9.8

CVE-2026-71362

Adobe Commerce and Magento - authorization review

CVE-2026-71362 was added to CISA KEV on 2026-09-24. Apply the Adobe fix, then review administrator roles, integration tokens, and unexpected order or configuration changes.

Adobe Commerce / Magento CISA KEV Active Exploit
⚠️ CISA KEV
2026-09-16 CVSS 8.8

CVE-2026-87886

Acronis Backup cPanel plugin - permission review

CVE-2026-87886 was added to CISA KEV on 2026-09-16. Update the Acronis cPanel/WHM plugin or Plesk extension, then review file permissions, WHM users, and backup jobs on servers you administer.

Acronis Backup CISA KEV Active Exploit
⚠️ CISA KEV
2026-09-11 CVSS 9.8

CVE-2026-85706

GitLab - commits API file access review

CVE-2026-85706 was added to CISA KEV on 2026-09-11. Upgrade the GitLab instance to the fixed release and review whether public projects exposed files that should have stayed private.

GitLab CISA KEV Active Exploit
⚠️ CISA KEV
2026-09-08 CVSS 9.8

CVE-2026-75650

Adobe Commerce and Magento - template input review

CVE-2026-75650 was added to CISA KEV on 2026-09-08. Patch the store, then review CMS and email templates plus administrator accounts for changes you did not make.

Adobe Commerce / Magento CISA KEV Active Exploit
⚠️ CISA KEV
2026-08-31 CVSS 9.4

CVE-2026-82078

PaperCut NG and MF - configuration review

CVE-2026-82078 was added to CISA KEV on 2026-08-31. PaperCut fixed it on 2026-08-27 in NG and MF 26.0.5, 25.0.13, and 24.1.10. Confirm the version on servers you own.

PaperCut NG/MF CISA KEV Active Exploit
⚠️ CISA KEV
2026-08-31 CVSS 8.8

CVE-2026-81578

PaperCut NG and MF - admin access review

CVE-2026-81578 was added to CISA KEV on 2026-08-31 and is fixed in the same PaperCut NG and MF releases as CVE-2026-82078: 26.0.5, 25.0.13, and 24.1.10.

PaperCut NG/MF CISA KEV Active Exploit
⚠️ CISA KEV
2026-08-04 CVSS 9.8

CVE-2026-34486

Apache Tomcat - version review

CVE-2026-34486 was added to CISA KEV on 2026-08-04. Apache says it affects only Tomcat 11.0.20, 10.1.53, and 9.0.116, fixed in 11.0.21, 10.1.54, and 9.0.117.

Apache Tomcat CISA KEV Active Exploit
⚠️ CISA KEV
2026-07-21 CVSS 9.8

CVE-2026-60137

WordPress core - SQL injection review

CVE-2026-60137 was added to CISA KEV on 2026-07-21. WordPress fixed it on 2026-07-17 in 7.0.2, 6.9.5, and 6.8.6. Confirm the core version, then review administrator accounts and unexpected PHP files on sites you own.

WordPress CISA KEV Active Exploit
⚠️ CISA KEV
2026-07-21 CVSS 9.8

CVE-2026-63030

WordPress core - REST route review

CVE-2026-63030 was added to CISA KEV on 2026-07-21 and is fixed in WordPress 7.0.2 and 6.9.5. WordPress says the 6.8 line is not affected by this one. Confirm the core version on sites you own.

WordPress CISA KEV Active Exploit
⚠️ CISA KEV
2026-06-15 CVSS 6.5

CVE-2026-20262

Cisco Catalyst SD-WAN Manager - authenticated arbitrary file write

CVE-2026-20262 affects Cisco Catalyst SD-WAN Manager web UI upload handling. The reported path requires valid low-privilege credentials but can create or overwrite files, so exposed management planes need patching and account review.

Cisco Catalyst SD-WAN Manager CISA KEV Active Exploit Public PoC
⚠️ ACTIVELY EXPLOITED
2026-06-14 CVSS 8.5

CVE-2026-54420

LiteSpeed cPanel Plugin - shared hosting privilege escalation risk

CVE-2026-54420 affects LiteSpeed cPanel user-end plugin deployments before 2.4.8, including bundled WHM Plugin deployments before the fixed 5.3.2.1 line. Shared hosts using CloudLinux/CageFS should patch and review cPanel logs because the vendor reported active exploitation.

LiteSpeed cPanel Plugin Active Exploit Public PoC
⚠️ CISA KEV
2026-06-11 CVSS 10.0

CVE-2026-10520

Ivanti Sentry - unauthenticated root-level command injection

CVE-2026-10520 affects Ivanti Sentry and was added to CISA KEV on 2026-06-11. Confirm version state, restrict management access, patch, and review appliance logs and unexpected accounts.

Ivanti Sentry CISA KEV Active Exploit
⚠️ ACTIVELY EXPLOITED
2026-06-08 CVSS 9.3

CVE-2026-50751

Check Point - deprecated IKEv1 VPN authentication bypass

CVE-2026-50751 affects Check Point Remote Access VPN and Mobile Access deployments that still accept deprecated IKEv1. Check Point reported exploitation in the wild; operators should patch, disable or restrict IKEv1, and review VPN logs from 2026-05-07 onward.

Check Point Remote Access VPN / Mobile Access Active Exploit
⚠️ ACTIVELY EXPLOITED
2026-06-05 CVSS 9.3

CVE-2026-45777

Open XDMoD - unauthenticated remote code execution

CVE-2026-45777 affects Open XDMoD 9.5.0 through 11.0.2. HPC portals should upgrade to 11.0.3 or newer, restrict web access, and review web-server process activity and application logs.

Open XDMoD Active Exploit
⚠️ ACTIVELY EXPLOITED
2026-06-02 CVSS 9.8

CVE-2026-8206

Kirki Page Builder — Unauthenticated Admin Account Takeover via Password Reset

Kirki 6.0.0–6.0.6 password reset endpoint sends reset link to attacker-supplied email instead of account owner. One unauthenticated request hijacks any admin. 500K+ installs, Wordfence blocking 222+ attacks/day.

WordPress Active Exploit Public PoC
⚠️ CISA KEV
2026-05-27 CVSS 9.3

CVE-2026-48027

Nx Console VS Code Extension — Supply Chain Attack (Actively Exploited)

Malicious Nx Console version 18.95.0 was published to VS Code Marketplace for ~18 minutes and OpenVSX for ~36 minutes on May 19, 2026. The compromised extension contained embedded malicious code (CWE-506) that executed at activation. Auto-update users may have installed it. CISA has added this to the Known Exploited Vulnerabilities catalog.

VS Code CISA KEV Active Exploit Public PoC
⚠️ CISA KEV
2026-04-28 CVSS 9.8

CVE-2026-41940

cPanel/WHM Pre-Auth CRLF Injection → Root Access

Pre-authentication CRLF injection in cPanel & WHM session handling leading to root access. 44,000 IPs compromised, 7,135 hit by .sorry ransomware. Persistent Mr_Rot13 Filemanager backdoor survives the patch. Second emergency TSR on May 8.

cPanel CISA KEV Active Exploit Public PoC

Same checks, no invoice

The desk is free. The tools next to it are free.

Ping7 keeps this page as the industry desk. Income comes from ads on the free tools, not from a CVE subscription.

Open all free tools →

Sources verified against NVD, CISA KEV, Shadowserver, Censys, F5, Rapid7, watchTowr, cPanel, WordPress plugin advisories, and FreePBX security advisories. Last updated 2026-09-25.