Exploitable This Week
High-severity CVEs with known proof-of-concept exploits available
About This Section
This table shows CVEs that have publicly available proof-of-concept (POC) exploits, cross-referenced with severity scores from CISA. These vulnerabilities represent the highest risk as attackers can readily exploit them. Priority should be given to Critical and High severity items with Network attack vectors. GitHub links point to POC repositories, while Ref links provide additional technical details.
Total with POC
170190
Critical Severity
1246
High Severity
2
Network Exploitable
2
Showing 50 of 170190
| CVE ID | Product | Description | Score | Severity | Attack Vector | POC Links |
|---|---|---|---|---|---|---|
| CVE-2026-8018 | Chrome | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote... | 8.1 | HIGH | NETWORK | [Ref1] [Ref2] |
| CVE-2026-8083 | Pharmacy Sales and Inventory System | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an... | 7.3 | HIGH | NETWORK | [Ref1] |
| CVE-2026-84937 | Video Player for YouTube | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape us... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84936 | EmbedPress | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84935 | HT Menu | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84934 | JCH Optimize | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its aut... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84930 | CatFolders Document Gallery %26 PDF Library | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly valida... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84931 | Joli Table Of Contents | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode att... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84899 | VikWidgetsLoader | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute b... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84926 | EmbedPress | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Googl... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84927 | EmbedPress | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on o... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84901 | Eventin | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84225 | Kirki | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collabora... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84043 | ePayco Payment Gateway for WooCommerce | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify th... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84745 | The Events Calendar | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the use... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84896 | King Addons for Elementor | The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-styl... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84045 | E-cab Taxi Booking Manager for Woocommerce | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a cli... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84021 | Bold Page Builder | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before out... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84044 | Restaurant Menu and Food Ordering | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal p... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84898 | Eventin | The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84221 | Kirki | The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84022 | Bold Page Builder | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode a... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-82923 | AI Website Builder (GitHub build) | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-83543 | Greenshift | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-83544 | Greenshift | The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-82846 | Masteriyo LMS | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings b... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81423 | Accept Stripe Payments | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL befor... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-82304 | Music Store | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-8212 | gdal | A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the functio... | N/A | Unknown | N/A | [Ref1] [Ref2] |
| CVE-2026-81424 | Accept Stripe Payments | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81348 | My Private Site | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81404 | IPGP Visitors Origin | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before r... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-8022 | Chrome | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attac... | N/A | Unknown | N/A | [Ref1] [Ref2] |
| CVE-2026-80346 | StarRocks | StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80348 | TarsWeb | TarsWeb enforces its per-application roles by calling AuthService from individual controller methods... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80347 | mcp-fetch | mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround a... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80223 | ash_graphql | Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80227 | ash_sql | Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with t... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80349 | TarsWeb | TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80427 | bestzip | bestzip builds the argument list for the system zip utility without separating options from operands... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80205 | nltk | NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.fin... | N/A | Unknown | N/A | [Ref1] [Ref2] |
| CVE-2026-8021 | Chrome | Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinc... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80214 | librenms | LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80202 | kimai | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), wh... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80206 | nltk | NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgre... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80199 | kimai | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthe... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80196 | kimai | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remai... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80197 | kimai | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add a... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-8020 | Chrome | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacke... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-80195 | kimai | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team upd... | N/A | Unknown | N/A | [Ref1] |