Skip to main content
CVE Database

Vulnerability intelligencewith CVSS, EPSS & KEV

High-priority CVEs enriched with CVSS v3, EPSS exploit probabilities, CISA KEV status, Nuclei templates, and correlation with live IOC feeds. Updated every 6 hours from NVD, CISA, CERT-FR, MSRC, and GHSA.

0
CISA KEV

Known exploited in this sample

9
Critical severity

CVSS severity = CRITICAL

0
Actively exploited

SSVC exploitation = active

CVE intelligence facts

How we prioritize and what these pages are — and are not — for.

Prioritization signals
CVSS severity, EPSS probability, CISA KEV status, SSVC exploitation state, Nuclei templates, and exploit references.
Primary sources
NVD, CISA, CERT-FR, Microsoft Security Response Center, GitHub Security Advisories, and public exploit metadata.
Best fit
Patch prioritization, SBOM triage, exposed-service review, incident response, and vulnerability intelligence briefings.
Limitations
A CVE page indicates public vulnerability risk. Confirm asset exposure, compensating controls, and vendor patch availability before remediation decisions.

Recent high-priority vulnerabilities

Crawlable advisories with enough severity or exploitation signal to deserve a stable public page.

Recently added to KEVFull search
HIGHCVSS 7.1

CVE-2026-108913

Code Execution via Untrusted Theme Files in Omarchy

omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an untrusted Git repository.

2026-10-11

HIGHCVSS 7.5

CVE-2026-108905

pH7Builder before 18.6.0 Hard-Coded API Key Bypass via Host Header

pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields.

2026-10-11

HIGHCVSS 8.1

CVE-2026-108902

pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service.

2026-10-11

HIGHCVSS 8.2

CVE-2026-108865

AmoyLab Unla through 0.10.0 OAuth2 Authentication Bypass via /authorize

AmoyLab Unla through 0.10.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid access tokens because the OAuth2 server never authenticates a resource owner. Attackers can register a client, request a code from /authorize, and exchange it at /token to access OAuth2-protected MCP prefixes, proxied upstream APIs and injected credentials.

2026-10-11

HIGHCVSS 7.5

CVE-2026-108863

Katanemo Plano through 0.4.37 Missing Authentication on Envoy Admin Interface

Katanemo Plano through 0.4.37 contains a missing authentication vulnerability that allows unauthenticated network attackers to access the Envoy admin interface, which is bound to all host interfaces on port 9901. Attackers can request the /config_dump endpoint to read configured LLM provider API keys in plaintext from the WASM filter configuration.

2026-10-11

CRITICALCVSS 9.1

CVE-2026-108860

BotSharp through 5.2.0 Authentication Bypass via Hard-Coded JWT Signing Key

BotSharp through 5.2.0 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to forge bearer tokens using the hard-coded Jwt:Key in WebStarter appsettings.json. Attackers can sign tokens with the committed HMAC secret and fixed botsharp issuer and audience to impersonate any known user, including administrators, on Authorize-protected API routes.

2026-10-11

HIGHCVSS 7.5

CVE-2026-108859

mcp-go through 1.2.1 Denial of Service via Unbounded POST Body Buffering

mcp-go through 1.2.1 contains a denial of service vulnerability in StreamableHTTPServer.ServeHTTP that allows remote unauthenticated attackers to exhaust memory by sending oversized POST bodies. Attackers can send arbitrarily large or many concurrent POST requests, read fully via io.ReadAll before validation, to degrade or OOM-kill the server process.

2026-10-11

HIGHCVSS 8.1

CVE-2026-108853

UnicomAI Wanwu before 0.6.3 IDOR via DELETE /v1/appspace/app

UnicomAI Wanwu before 0.6.3 contains an insecure direct object reference vulnerability that allows authenticated low-privileged users to delete other tenants' agent or RAG applications by supplying their appId. Attackers can send requests to DELETE /v1/appspace/app with guessed sequential assistant IDs to permanently delete victims' applications, workflows, conversations, and associated data.

2026-10-11

HIGHCVSS 7.6

CVE-2026-108760

LlamaFarm through 0.0.34 Unauthenticated API Exposed on All Interfaces

LlamaFarm through 0.0.34 contains an insecure default configuration that binds its unauthenticated FastAPI server to 0.0.0.0 on port 14345, while the lf CLI silently discards HOST overrides. Network-adjacent attackers can call the project and dataset management API to read stored provider API keys, modify projects, trigger ingestion, and irreversibly delete projects.

2026-10-11

HIGHCVSS 8.2

CVE-2026-108758

Easy!Appointments through 1.6.0 Authorization Bypass via booking/register Endpoint

Easy!Appointments through 1.6.0 contains an authorization bypass vulnerability in Booking::register() that allows unauthenticated attackers to modify any appointment by supplying an appointment id without its hash. Attackers can enumerate sequential appointment ids with a self-asserted manage_mode flag to rewrite appointment details, rebind them to attacker-controlled customers, and obtain management hashes for rescheduling or cancellation.

2026-10-11

CRITICALCVSS 9.4

CVE-2026-108753

Agnaistic agnai through 1.0.555 Hard-Coded Credentials in self-host Docker Compose

Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability in self-host.docker-compose.yml, which sets a fixed admin password and public JWT secret. Unauthenticated attackers can log in as admin or sign their own JWT with admin: true to impersonate users, reset passwords, and change server configuration.

2026-10-11

HIGHCVSS 8.8

CVE-2026-108746

Vearch 3.5.2 through 3.5.9 Incorrect Authorization via Role.HasPermissionForResources

Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.

2026-10-11

HIGHCVSS 7

CVE-2026-108744

pbi-cli 3.10.1 through 3.12.0 OS Command Injection via Desktop Sync

pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when reopening projects. Attackers can lure victims into opening a Power BI project from a space-free path containing & to run commands with victim privileges during report write or reload.

2026-10-11

HIGHCVSS 8.3

CVE-2026-108740

GoatCounter through 2.7.0 Privilege Escalation via /user/pref Mass Assignment

GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify protected account fields via form-encoded requests. Attackers with read-only access can POST user.access[all]=* and user.email_verified=true to /user/pref, bypassing readonly tags to gain superuser or admin access.

2026-10-11

HIGHCVSS 7.5

CVE-2026-108739

OpenAgents Workspace through launcher-v1.0.17 Unauthenticated Credential Exposure via /v1/workspaces

OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all workspaces via GET /v1/workspaces. Attackers can read the unmasked browserfabric_api_key in each workspace's settings map, along with workspace ids, slugs, creator emails and member lists.

2026-10-11

HIGHCVSS 8.1

CVE-2026-108718

Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered clients without user consent. Attackers can register a client with the long_lived_access_token scope and lure a user to an authorization link, obtaining a non-expiring API token with the user's full permissions.

2026-10-11

HIGHCVSS 7.5

CVE-2026-108714

MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because Application.mcpWebSocket installs Ktor WebSockets without a maxFrameSize limit. Attackers can send small frame headers declaring payloads near 2 GiB over one or a few connections, forcing huge heap allocations and causing denial of service.

2026-10-11

CRITICALCVSS 10

CVE-2026-108576

A vulnerability was found in TOZED X300 up to 6.01.3. This vulnerability affects the function process_ping of the component IPPingDiagnostics Handler. The manipulation of the argument Host results in os command injection. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

2026-10-11

HIGHCVSS 7.3

CVE-2026-108571

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-96227

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).

2026-10-11

HIGHCVSS 7.1EPSS 0.2 %

CVE-2026-91829

The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89302

The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89299

The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89297

The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

2026-10-11

HIGHCVSS 8.6EPSS 0.3 %

CVE-2026-89287

The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89285

The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.1 %

CVE-2026-89283

The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89234

The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89232

The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89214

The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89213

The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-89195

The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.

2026-10-11

HIGHCVSS 8.6EPSS 0.2 %

CVE-2026-88930

The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-88905

The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-88903

The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated attackers to publish arbitrary posts containing malicious JavaScript on any site where its API key has never been configured.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-88827

The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.

2026-10-11

HIGHCVSS 8.8EPSS 0.1 %

CVE-2026-88826

The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-87764

The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before outputting it back, allowing unauthenticated users to store arbitrary web scripts that will execute in the session of any member who later views that conversation.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-87762

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.

2026-10-11

HIGHCVSS 8EPSS 0.2 %

CVE-2026-87761

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline script block on every front-end page, allowing any authenticated user, such as a subscriber, to perform Stored Cross-Site Scripting attacks against every visitor, including administrators.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-87760

The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-86798

The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators.

2026-10-11

CRITICALCVSS 9.1EPSS 0.1 %

CVE-2026-86717

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.

2026-10-11

CRITICALCVSS 9.1EPSS 0.1 %

CVE-2026-86706

The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable.

2026-10-11

HIGHCVSS 7.2EPSS 0.1 %

CVE-2026-85126

The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.

2026-10-11

CRITICALCVSS 9.1EPSS 0.1 %

CVE-2026-85121

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to create and overwrite arbitrary WordPress options with request data, which can take the site offline and deactivate all of its Insurify WordPress plugin through 1.0.

2026-10-11

CRITICALCVSS 9.8EPSS 0.1 %

CVE-2026-85118

The AI Content Generator Marketing WordPress plugin through 1.0.0 does not enforce a nonce or capability check on some of its AJAX actions, allowing unauthenticated users to update and delete arbitrary WordPress options, which can be used to gain administrator access to the site.

2026-10-11

CRITICALCVSS 9.8EPSS 0.1 %

CVE-2026-84737

The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.

2026-10-11

CRITICALCVSS 9.8EPSS 0.1 %

CVE-2026-84734

The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.

2026-10-11

HIGHCVSS 8.8EPSS 0.2 %

CVE-2026-84261

The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.

2026-10-11

Indexable CVE pages

Stable canonical URLs for high-priority advisories — page 1 of 183.

CVE-2026-102388CVE-2026-103071CVE-2026-103305CVE-2026-103694CVE-2026-103695CVE-2026-104028CVE-2026-104398CVE-2026-104680CVE-2026-105885CVE-2026-105889CVE-2026-105892CVE-2026-106029CVE-2026-106608CVE-2026-106609CVE-2026-106610CVE-2026-108161CVE-2026-108522CVE-2026-108540CVE-2026-108546CVE-2026-108548CVE-2026-108549CVE-2026-108550CVE-2026-108551CVE-2026-108553CVE-2026-108571CVE-2026-108576CVE-2026-108598CVE-2026-108623CVE-2026-108628CVE-2026-108657CVE-2026-108693CVE-2026-108695CVE-2026-108707CVE-2026-108708CVE-2026-108714CVE-2026-108718CVE-2026-108739CVE-2026-108740CVE-2026-108744CVE-2026-108746CVE-2026-108753CVE-2026-108758CVE-2026-108760CVE-2026-108853CVE-2026-108859CVE-2026-108860CVE-2026-108863CVE-2026-108865CVE-2026-108902CVE-2026-108905CVE-2026-108913CVE-2026-14854CVE-2026-27350CVE-2026-39800CVE-2026-40800CVE-2026-42630CVE-2026-42696CVE-2026-42697CVE-2026-42709CVE-2026-57742CVE-2026-57806CVE-2026-62034CVE-2026-62043CVE-2026-62044CVE-2026-62116CVE-2026-62118CVE-2026-81420CVE-2026-81649CVE-2026-81797CVE-2026-84251CVE-2026-84252CVE-2026-84253CVE-2026-84254CVE-2026-84258CVE-2026-84259CVE-2026-84260CVE-2026-84261CVE-2026-84734CVE-2026-84737CVE-2026-85118CVE-2026-85121CVE-2026-85126CVE-2026-86706CVE-2026-86717CVE-2026-86798CVE-2026-87760CVE-2026-87761CVE-2026-87762CVE-2026-87764CVE-2026-88826CVE-2026-88827CVE-2026-88903CVE-2026-88905CVE-2026-88930CVE-2026-89195CVE-2026-89213CVE-2026-89214CVE-2026-89232CVE-2026-89234CVE-2026-89283CVE-2026-89285CVE-2026-89287CVE-2026-89297CVE-2026-89299CVE-2026-89302CVE-2026-91829CVE-2026-94160CVE-2026-94676CVE-2026-96227CVE-2026-96341CVE-2026-97263CVE-2026-97264CVE-2018-13379CVE-2019-0708CVE-2019-11510CVE-2019-19781CVE-2020-5902CVE-2021-1498CVE-2021-21985CVE-2021-22005CVE-2021-26084CVE-2021-26086CVE-2021-35464CVE-2021-40438CVE-2021-44228CVE-2022-26134CVE-2022-29464CVE-2023-0669CVE-2023-1389CVE-2023-1671CVE-2023-22518CVE-2023-27350CVE-2023-32315CVE-2023-35078CVE-2023-35082CVE-2023-44487CVE-2023-4966CVE-2024-21887CVE-2024-21893CVE-2024-23897CVE-2024-3400CVE-2024-7593CVE-2025-53770CVE-2022-22954CVE-2020-14882CVE-2024-3273CVE-2019-16920CVE-2022-44877CVE-2025-49704CVE-2024-34102

Looking for a specific CVE?

Search by CVE ID, keyword, product, or vendor — or wire the catalog into your stack with a free API key.