Exploitable This Week
High-severity CVEs with known proof-of-concept exploits available
About This Section
This table shows CVEs that have publicly available proof-of-concept (POC) exploits, cross-referenced with severity scores from CISA. These vulnerabilities represent the highest risk as attackers can readily exploit them. Priority should be given to Critical and High severity items with Network attack vectors. GitHub links point to POC repositories, while Ref links provide additional technical details.
Total with POC
173,220
Critical Severity
1,130
High Severity
3
Network Exploitable
7
Showing 50 of 173220
| CVE ID | Product | Description | Score | Severity | Attack Vector | POC Links |
|---|---|---|---|---|---|---|
| CVE-2026-33994 | locutus | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starti... | 9.8 | CRITICAL | NETWORK | [Ref1] |
| CVE-2026-33890 | MyTube | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an... | 9.8 | CRITICAL | NETWORK | [Ref1] |
| CVE-2026-33937 | handlebars.js | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 thr... | 9.8 | CRITICAL | NETWORK | [Ref1] |
| CVE-2026-33768 | astro | Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads t... | 9.1 | CRITICAL | NETWORK | [Ref1] |
| CVE-2026-33767 | AVideo | WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like... | 8.8 | HIGH | NETWORK | [Ref1] |
| CVE-2026-33953 | LinkAce | LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requ... | 8.5 | HIGH | NETWORK | [Ref1] |
| CVE-2026-33723 | AVideo | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::... | 7.1 | HIGH | NETWORK | [Ref1] |
| CVE-2026-93988 | qloapps | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/aj... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-93308 | SMO OAM | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unkno... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-93454 | Aureus ERP | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML i... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-92541 | Import and export users and customers | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-92965 | TikTok | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting o... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-92540 | Import and export users and customers | The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce t... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-92422 | Meow Gallery | The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value befo... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-92423 | Meow Gallery | The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restric... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-91205 | Red Hat Enterprise Linux 9 | A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-92410 | Sign-up Sheets | The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that prot... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-90522 | Tourism-Management-System | A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b... | N/A | Unknown | N/A | [Ref1] [Ref2] |
| CVE-2026-87840 | Tripzzy | The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on it... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-87621 | Chrome | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-87839 | Tripzzy | The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-87067 | Forminator Forms | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-85017 | Unlimited Elements For Elementor | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability ch... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-87068 | Forminator Forms | The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforce... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84328 | Chrome | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacke... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-84223 | Kirki | The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uplo... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-82672 | mint | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in el... | N/A | Unknown | N/A | [Ref1] [Ref2] |
| CVE-2026-82842 | SAML Single Sign On | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81654 | Photo Gallery%2C Sliders%2C Proofing and Themes | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81652 | Photo Gallery%2C Sliders%2C Proofing and Themes | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the re... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81653 | Photo Gallery%2C Sliders%2C Proofing and Themes | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the us... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81650 | Photo Gallery%2C Sliders%2C Proofing and Themes | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-81651 | Photo Gallery%2C Sliders%2C Proofing and Themes | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the us... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-76757 | Gammu SMS Daemon | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-78030 | null | connect( $dsn );Note that DBD::Gofer forwards connect attributes to the server side, and DBI::ProxyServer checks only that a DSN starts with a driver prefix.">DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-76755 | Gammu SMS Daemon | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-51153 | n/a | Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handlers/task.py in QD 20220208 th... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-51152 | n/a | Server-side request forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250803. Fetche... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-71219 | Red Hat Enterprise Linux 9 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-38999 | n/a | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-38725 | n/a | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject ar... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-38332 | TinyEXIF | TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33981 | changedetection.io | changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` ... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33952 | FreeRDP | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalid... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33734 | FOSSBilling | FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33769 | astro | Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33727 | pi-hole | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33653 | Uploady | Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33675 | vikunja | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migratio... | N/A | Unknown | N/A | [Ref1] |
| CVE-2026-33621 | pinchtab | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Pinc... | N/A | Unknown | N/A | [Ref1] |