CVE Intelligence Dashboard

Last updated: Aug 01, 2026 at 03:04:40 AM Pacific

Exploitable This Week

High-severity CVEs with known proof-of-concept exploits available

About This Section

This table shows CVEs that have publicly available proof-of-concept (POC) exploits, cross-referenced with severity scores from CISA. These vulnerabilities represent the highest risk as attackers can readily exploit them. Priority should be given to Critical and High severity items with Network attack vectors. GitHub links point to POC repositories, while Ref links provide additional technical details.

Total with POC

50

Critical Severity

50

High Severity

0

Network Exploitable

50

CVE ID Product Description Score Severity Attack Vector POC Links
CVE-2026-2778 Thunderbird Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerab... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-25142 SandboxJS SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict _... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-2776 Thunderbird Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software.... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-34938 PraisonAI PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-4963 smolagents A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function eval... 10.0 CRITICAL NETWORK [Ref1] [Ref2]
CVE-2026-34208 SandboxJS SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-4370 Juju A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.... 10.0 CRITICAL NETWORK [Ref1]
CVE-2024-57521 n/a SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrar... 10.0 CRITICAL NETWORK [Ref1] [Ref2] [Ref3]
CVE-2025-67108 n/a eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resultin... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-67109 n/a Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-64721 Sandboxie Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating sys... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-26954 SandboxJS SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays conta... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-25520 SandboxJS SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-28505 Tautulli Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-39337 CRM ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication re... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-21962 Oracle HTTP Server%2C Oracle Weblogic Server Proxy Plug-in Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusi... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-22686 enclave Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, th... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-27597 enclave Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-60219 WooCommerce Designer Pro Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro ... 10.0 CRITICAL NETWORK -
CVE-2025-50002 Energia Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Uploa... 10.0 CRITICAL NETWORK -
CVE-2025-9962 P series (P07%2C P10%2C P12%2C P15) A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without... 10.0 CRITICAL NETWORK [Ref1] [Ref2]
CVE-2026-24054 kata-containers Kata Containers is an open source project focusing on a standard implementation of lightweight Virtu... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-64075 n/a A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-33478 AVideo WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnera... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-15586 OGP-Website OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a typ... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-10878 Fikir Odalari AdminPando A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 be... 10.0 CRITICAL NETWORK [Ref1]
CVE-2026-23830 SandboxJS SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnera... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-61937 Process Optimization The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code exe... 10.0 CRITICAL NETWORK [Ref1]
CVE-2024-58338 Flamingo XL Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to e... 10.0 CRITICAL NETWORK [Ref1] [Ref2]
CVE-2025-65108 md-to-pdf md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prio... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-63414 n/a A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated ... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-63216 n/a The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper J... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-63224 n/a The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JW... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-61481 n/a An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over ... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-59528 Flowise Flowise is a drag & drop user interface to build a customized large language model flow. In version ... 10.0 CRITICAL NETWORK [Ref1]
CVE-2025-58384 n/a In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code exe... 10.0 CRITICAL NETWORK -
CVE-2025-55182 react-server-dom-webpack A pre-authentication remote code execution vulnerability exists in React Server Components versions ... 10.0 CRITICAL NETWORK [Ref1] [Ref2] [Ref3]
CVE-2025-3450 Automation Runtime An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions b... 10.0 CRITICAL NETWORK -
CVE-2025-10363 Topal Finanzbuchhaltung Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Win... 10.0 CRITICAL NETWORK -
CVE-2025-10230 Red Hat Enterprise Linux 8 A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration pack... 10.0 CRITICAL NETWORK [Ref1] [Ref2]
CVE-2018-25118 GeoVision embedded IP devices GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injec... 10.0 CRITICAL NETWORK [Ref1] [Ref2] [Ref3] [Ref4]
CVE-2025-63601 n/a Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenti... 9.9 CRITICAL NETWORK [Ref1]
CVE-2026-39888 praisonaiagents PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.p... 9.9 CRITICAL NETWORK [Ref1]
CVE-2026-25763 openproject OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 1... 9.9 CRITICAL NETWORK [Ref1] [Ref2] [Ref3]
CVE-2026-34987 wasmtime Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime wi... 9.9 CRITICAL NETWORK [Ref1]
CVE-2026-34156 nocobase NocoBase is an AI-powered no-code/low-code platform for building business applications and enterpris... 9.9 CRITICAL NETWORK [Ref1]
CVE-2025-62645 assistant platform The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote auth... 9.9 CRITICAL NETWORK [Ref1]
CVE-2026-23696 Windmill EE (Enterprise Edition) Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the fo... 9.9 CRITICAL NETWORK [Ref1] [Ref2]
CVE-2025-49844 redis Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an... 9.9 CRITICAL NETWORK [Ref1]
CVE-2025-70830 n/a A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1... 9.9 CRITICAL NETWORK [Ref1] [Ref2]