VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 57 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-18192

Vacron VIN-DS783E-E6

VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18191

Vacron VIN-DS783E-E6

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63234

Three Learning Koollab LMS

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63233

Three Learning Koollab LMS

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63232

Three Learning Koollab LMS

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to unserialize(), write a webshell to a publicly accessible location, and execute arbitrary code on the server.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-63231

Three Learning Koollab LMS

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to read the entire application database and obtain valid JWT tokens for account takeover.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63230

Three Learning Koollab LMS

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover, via the SCORM report endpoint.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63229

Three Learning Koollab LMS

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to read sensitive database contents, including personally identifiable information, credentials, and valid JWT tokens that may enable account takeover.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. Koollab LMS

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14300

miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they control and replaying it against the victim's email address. Exploitation requires the Profile Completion feature to be enabled and social login to be configured.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14234

WOLF

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administrator into writing arbitrary content, including a malicious script, into a post via a cross-site request, resulting in stored Cross-Site Scripting.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13690

UsersWP

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13423

Streamit

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-11974

wp-media-folder-addon

The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18072

nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no passw...

The CVSS severity warrants an early asset and exposure review.