CVE Intelligence Dashboard

Last updated: Sep 05, 2026 at 09:05:23 PM Pacific

Exploitable This Week

High-severity CVEs with known proof-of-concept exploits available

About This Section

This table shows CVEs that have publicly available proof-of-concept (POC) exploits, cross-referenced with severity scores from CISA. These vulnerabilities represent the highest risk as attackers can readily exploit them. Priority should be given to Critical and High severity items with Network attack vectors. GitHub links point to POC repositories, while Ref links provide additional technical details.

Total with POC

170190

Critical Severity

1246

High Severity

2

Network Exploitable

2

Showing 50 of 170190
CVE ID Product Description Score Severity Attack Vector POC Links
CVE-2026-8018 Chrome Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote... 8.1 HIGH NETWORK [Ref1] [Ref2]
CVE-2026-8083 Pharmacy Sales and Inventory System A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an... 7.3 HIGH NETWORK [Ref1]
CVE-2026-84937 Video Player for YouTube The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape us... N/A Unknown N/A [Ref1]
CVE-2026-84936 EmbedPress The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-... N/A Unknown N/A [Ref1]
CVE-2026-84935 HT Menu The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check... N/A Unknown N/A [Ref1]
CVE-2026-84934 JCH Optimize The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its aut... N/A Unknown N/A [Ref1]
CVE-2026-84930 CatFolders Document Gallery %26 PDF Library The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly valida... N/A Unknown N/A [Ref1]
CVE-2026-84931 Joli Table Of Contents The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode att... N/A Unknown N/A [Ref1]
CVE-2026-84899 VikWidgetsLoader The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute b... N/A Unknown N/A [Ref1]
CVE-2026-84926 EmbedPress The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Googl... N/A Unknown N/A [Ref1]
CVE-2026-84927 EmbedPress The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on o... N/A Unknown N/A [Ref1]
CVE-2026-84901 Eventin The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its ... N/A Unknown N/A [Ref1]
CVE-2026-84225 Kirki The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collabora... N/A Unknown N/A [Ref1]
CVE-2026-84043 ePayco Payment Gateway for WooCommerce The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify th... N/A Unknown N/A [Ref1]
CVE-2026-84745 The Events Calendar The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the use... N/A Unknown N/A [Ref1]
CVE-2026-84896 King Addons for Elementor The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-styl... N/A Unknown N/A [Ref1]
CVE-2026-84045 E-cab Taxi Booking Manager for Woocommerce The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a cli... N/A Unknown N/A [Ref1]
CVE-2026-84021 Bold Page Builder The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before out... N/A Unknown N/A [Ref1]
CVE-2026-84044 Restaurant Menu and Food Ordering The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal p... N/A Unknown N/A [Ref1]
CVE-2026-84898 Eventin The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before ... N/A Unknown N/A [Ref1]
CVE-2026-84221 Kirki The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it ... N/A Unknown N/A [Ref1]
CVE-2026-84022 Bold Page Builder The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode a... N/A Unknown N/A [Ref1]
CVE-2026-82923 AI Website Builder (GitHub build) The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n... N/A Unknown N/A [Ref1]
CVE-2026-83543 Greenshift The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching... N/A Unknown N/A [Ref1]
CVE-2026-83544 Greenshift The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute ... N/A Unknown N/A [Ref1]
CVE-2026-82846 Masteriyo LMS The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings b... N/A Unknown N/A [Ref1]
CVE-2026-81423 Accept Stripe Payments The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL befor... N/A Unknown N/A [Ref1]
CVE-2026-82304 Music Store The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using ... N/A Unknown N/A [Ref1]
CVE-2026-8212 gdal A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the functio... N/A Unknown N/A [Ref1] [Ref2]
CVE-2026-81424 Accept Stripe Payments The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled ... N/A Unknown N/A [Ref1]
CVE-2026-81348 My Private Site The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to... N/A Unknown N/A [Ref1]
CVE-2026-81404 IPGP Visitors Origin The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before r... N/A Unknown N/A [Ref1]
CVE-2026-8022 Chrome Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attac... N/A Unknown N/A [Ref1] [Ref2]
CVE-2026-80346 StarRocks StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every ... N/A Unknown N/A [Ref1]
CVE-2026-80348 TarsWeb TarsWeb enforces its per-application roles by calling AuthService from individual controller methods... N/A Unknown N/A [Ref1]
CVE-2026-80347 mcp-fetch mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround a... N/A Unknown N/A [Ref1]
CVE-2026-80223 ash_graphql Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber ... N/A Unknown N/A [Ref1]
CVE-2026-80227 ash_sql Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with t... N/A Unknown N/A [Ref1]
CVE-2026-80349 TarsWeb TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header... N/A Unknown N/A [Ref1]
CVE-2026-80427 bestzip bestzip builds the argument list for the system zip utility without separating options from operands... N/A Unknown N/A [Ref1]
CVE-2026-80205 nltk NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.fin... N/A Unknown N/A [Ref1] [Ref2]
CVE-2026-8021 Chrome Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinc... N/A Unknown N/A [Ref1]
CVE-2026-80214 librenms LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated... N/A Unknown N/A [Ref1]
CVE-2026-80202 kimai Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), wh... N/A Unknown N/A [Ref1]
CVE-2026-80206 nltk NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgre... N/A Unknown N/A [Ref1]
CVE-2026-80199 kimai Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthe... N/A Unknown N/A [Ref1]
CVE-2026-80196 kimai Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remai... N/A Unknown N/A [Ref1]
CVE-2026-80197 kimai Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add a... N/A Unknown N/A [Ref1]
CVE-2026-8020 Chrome Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacke... N/A Unknown N/A [Ref1]
CVE-2026-80195 kimai Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team upd... N/A Unknown N/A [Ref1]