🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
Search: Time Range:
Sources: Clear All Filters
378,232+
CVEs Tracked
378,232
Exploit Intel
358,051
EPSS Scored
5,202
CISA KEV
2,698
Metasploit Modules
30,385
ExploitDB Entries
61
MITRE ATT&CK Maps
0
Actively Exploited
0
CISA KEV
0
PoC Available
0
Zero-Days
1
Recent Discoveries
0
Most Mentioned

CVE Severity Distribution (Last 30 Days)

Found 7 CVEs in the last 30 days.

CVE-2026-1340 CRITICAL CVSS: 9.8 EPSS: 86.2% VulnCheck KEV Weaponized Metasploit CWE-94 T1059
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Published: 2026-01-29
CVE-2026-13400 MEDIUM CVSS: 6.1 EPSS: 0.1% CWE-79 T1189
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments WordPress plugin before 1.6.12.4's wp_kses_post() filter, so a double-encoded payload survives intake and is reintroduced as an executable element at render time.
Published: 2026-07-27
CVE-2026-13407 MEDIUM CVSS: 5.4 EPSS: 0.2% RECENT DISCOVERY CWE-116
The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbitrary HTML into emails sent to the site administrator on form submission.
Published: 2026-09-16
CVE-2026-13402 MEDIUM CVSS: 5.3 EPSS: 0.3% CWE-200 T1005 T1083
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor templates linked from non-public navigation menu items.
Published: 2026-07-17
CVE-2026-13404 MEDIUM CVSS: 5.3 EPSS: 0.3% CWE-639
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated users to modify that metadata on any post, including private and draft posts.
Published: 2026-08-26
CVE-2026-13406 MEDIUM CVSS: 5.3 EPSS: 0.3% CWE-862 T1078
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to non-public taxonomies.
Published: 2026-08-26
CVE-2026-13401 UNKNOWN EPSS: 0.4%
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "<a ='c'>" or unbalanced quotes "<a b='''''''c'>" can trigger this condition.
Published: 2026-07-16