VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,982 CVE recordsPage 532 of 1333 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57527

zaproxy zap-extensions

Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing the malicious object to be deserialized within the ZAP JVM when the Desktop UI renders the ViewSt...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57325

Jellywp NanoMag

CVE-2026-57325 affects Jellywp NanoMag. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57322

weDevs weMail

CVE-2026-57322 affects weDevs weMail. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57321

icc0rz H5P

CVE-2026-57321 affects icc0rz H5P. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57319

RealMag777 FOX

CVE-2026-57319 affects RealMag777 FOX. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57314

SureCart

CVE-2026-57314 affects SureCart. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57312

wpeverest Everest Forms

CVE-2026-57312 affects wpeverest Everest Forms. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-56773

teableio teable

Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-56072

Xtemos WoodMart

CVE-2026-56072 affects Xtemos WoodMart. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-56070

ThemeHunk Advance Product Search

CVE-2026-56070 affects ThemeHunk Advance Product Search. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-56068

Crocoblock. Jetimpex Inc. JetEngine

CVE-2026-56068 affects Crocoblock. Jetimpex Inc. JetEngine. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-56067

Crocoblock. Jetimpex Inc. JetSmartFilters

CVE-2026-56067 affects Crocoblock. Jetimpex Inc. JetSmartFilters. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.