Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

915
CISA KEV
266
Exploits
574
Proof-of-Concept
4.2%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

19 Sep/26
CVE-2026-84434
CRITICAL

This vulnerability is an arbitrary file upload flaw arising from inconsistent validation logic within the Gravity Forms WordPress plugin. Specifically, the upload_file function processes files without re-validating extensions when uploaded via hidden file upload fields, allowing bypass of the extension validation pipeline. The affected component is the File Upload field feature configured with Visibility set to 'Hidden' in Gravity Forms versions up to and including 3.1.0.4.

CVSS 9.8
EPSS 3.9%
KEV Pred in 10d
Product Gravity Forms gravity
CVSS v3.1 CWE-434 PoC
15 Sep/26
CVE-2026-89026
CRITICAL

This vulnerability is an authentication bypass caused by a hard-coded HS256 JWT signing key embedded in the pbxapi index.php file of the Issabel Framework. The root cause is the use of a static, identical JWT secret across all installations, which compromises token integrity verification. The affected component is the JWT authentication mechanism within the Issabel Framework's pbxapi endpoint.

CVSS 9.8
EPSS 0.7%
KEV Pred in 6d
Product Issabel Foundation Issabel Framework issabel
CVSS v3.1 CVSS v4.0 CWE-321 PoC
12 Sep/26
CVE-2026-78159
CRITICAL

This vulnerability is a remote code execution flaw caused by insufficient validation of the widget 'classes' map in the The Events Calendar WordPress plugin. The root cause lies in the parse_array function within the Element_Classes component, where a plain-array payload can bypass the is_safe_widget_instance() object check. This improper input handling in the widget classes feature enables unauthorized code execution.

CVSS 9.8
EPSS 1.4%
KEV Pred in 3d
Product stellarwp The Events Calendar stellarwp
CVSS v3.1 CWE-94 PoC
12 Sep/26
CVE-2026-78006
CRITICAL

This vulnerability is a remote code execution flaw caused by unsafe deserialization within the is_safe_widget_instance function of the The Events Calendar WordPress plugin. The root cause lies in insufficient validation allowing bypass of protection mechanisms due to PHP magic methods triggering during pre-parse combined with forged wp_hash integrity attributes before unserialize() is invoked. The affected component is the plugin's widget rendering logic, specifically in versions up to and including 6.17.4.

CVSS 9.8
EPSS 1.5%
KEV Pred in 3d
Product stellarwp The Events Calendar stellarwp
CVSS v3.1 CWE-502 PoC
11 Sep/26
CVE-2026-89013
HIGH

This vulnerability is an authorization bypass affecting Dolibarr's document management components. The root cause lies in insufficient validation of the 'hashp' parameter within the document storage endpoints, specifically in htdocs/document.php and htdocs/viewimage.php. The application incorrectly allows bypassing token-based authorization checks when the 'hashp' parameter is set to a crafted value, enabling unauthorized access to protected resources.

CVSS 7.5
EPSS 1.6%
KEV Pred in 2d
Product Dolibarr dolibarr
CVSS v3.1 CVSS v4.0 CWE-863 PoC
09 Sep/26
CVE-2026-80099
HIGH

This vulnerability is an authentication bypass caused by improper validation in the wp-module-data component bundled within several Newfold WordPress plugins. The root cause lies in the authenticate() method hooked to the rest_authentication_errors filter, which performs an HMAC-style Bearer token comparison that fails when HiiveConnection::get_auth_token() returns false. This results in the secret salt collapsing to a constant hash, allowing attacker-controlled inputs to pass authentication checks.

CVSS 8.8
EPSS 2.9%
KEV Pred N/A
Product Newfold WP Plugin Web newfold
CVSS v3.1 CWE-287 PoC
02 Sep/26
CVE-2026-9055
CRITICAL

This is a privilege escalation flaw rooted in missing authorization checks on the customer update endpoint of the Amelia booking plugin for WordPress. The endpoint accepts an attacker-controlled 'type' parameter and uses it to assign the caller's role without verifying that the caller is entitled to that role. A second defect compounds it: passing 'externalId' as 0 makes the plugin provision a new WordPress user carrying the wpamelia-manager role instead of linking to an existing account.

CVSS 9.8
EPSS 0.5%
KEV Pred 70%
Product melograno Booking for Appointments and Events Calendar – Amelia melograno
CVSS v3.1 CWE-269 PoC
28 Aug/26
CVE-2026-76581
CRITICAL

The WPMU DEV Dashboard plugin builds its HMAC message by concatenating token, state, redirect and domain values without a separator, and the two sides of the SSO handshake disagree on which fields belong in that string. The unauthenticated wdpsso_step1 action signs and returns a concatenation of all four values, while wdpsso_step2 verifies a concatenation that omits the domain field. Because no delimiter separates the fields, the boundary between redirect and domain is ambiguous to the verifier.

CVSS 9.8
EPSS 0.4%
KEV Pred 81%
Product wpmudev WPMU DEV Dashboard wpmudev
CVSS v3.1 CWE-347 PoC
21 Aug/26
CVE-2026-76904
CRITICAL

This vulnerability is a SQL Injection flaw caused by improper sanitization of input parameters within the GeoTools Java library. Specifically, the PostGIS DataStore implementation's `jsonArrayContains` function constructs SQL queries by directly embedding the `<value>` parameter without escaping, affecting versions 30.5 and earlier up to 33.6 and 34.5. The root cause lies in unsafe query generation when handling String or JSON fields in PostGIS 12 or greater environments.

CVSS 9.8
EPSS 4.0%
KEV Pred 83%
Product geotools geotools
CVSS v3.1 CWE-89 PoC
21 Aug/26
CVE-2026-77806
CRITICAL

This vulnerability is a code injection flaw rooted in improper handling of user-supplied input within the SPIP content management system. Specifically, the analyse_resultat_skel function fails to sanitize the X-Spip-Filtre HTTP request header, allowing arbitrary code to be injected and executed. The flaw affects SPIP versions prior to 4.4.21 and involves the HTTP header processing mechanism.

CVSS 9.8
EPSS 4.5%
KEV Pred 83%
Product SPIP spip
CVSS v3.1 CWE-94 PoC
20 Aug/26
CVE-2026-77647
CRITICAL

This vulnerability is a remote code execution flaw caused by improper handling of PHP code blocks within SPIP versions prior to 4.4.20. The root cause lies in incorrect parsing and identification of '<?php' tags combined with var_export's faulty processing of strings containing the '<' character. This parsing error occurs in the code serialization component responsible for exporting PHP variables, leading to unsafe code injection opportunities.

CVSS 9.8
EPSS 2.3%
KEV Pred 84%
Product SPIP spip
CVSS v3.1 CWE-94 Exploit
20 Aug/26
CVE-2026-69836
CRITICAL

This vulnerability is a deserialization flaw in Microsoft Entra ID, where untrusted serialized data is processed insecurely. The root cause lies in improper validation and handling of serialized objects during deserialization, allowing malicious input to be interpreted as executable code. The affected component is the deserialization mechanism within Microsoft Entra ID's authentication or identity management services.

CVSS 10.0
EPSS 1.5%
KEV Pred 81%
Product Microsoft Entra microsoft
CVSS v3.1 CWE-502 PoC RANSOMWARE
13 Jul/26
CVE-2026-6875
CRITICAL

The ServiceNow AI Platform contains a code injection flaw in which attacker-supplied input reaches an evaluation context and is executed by the platform. The vendor describes the reachable conditions as circumstantial rather than universal, which matches the high attack complexity in the severity rating: the path exists but depends on instance state.

CVSS 9.5
EPSS 1.4%
KEV Pred 73%
Product ServiceNow AI Platform servicenow
CVSS v4.0 CWE-94 PoC
19 Jun/26
CVE-2026-7515
CRITICAL

This vulnerability is a Local File Inclusion (LFI) flaw in the BetterDocs Pro WordPress plugin, specifically affecting versions up to 3.8.0. The root cause lies in insufficient input validation of the `doc_style` parameter, which allows an attacker to manipulate file inclusion logic. The affected component is the file inclusion mechanism within the plugin that processes the `doc_style` parameter without proper sanitization, enabling arbitrary file inclusion on the server.

CVSS 9.8
EPSS 0.9%
KEV Pred 83%
Product BetterDocs Pro betterdocs
CVSS v3.1 CWE-98 PoC
19 Jun/26
CVE-2026-8713
CRITICAL

This vulnerability is an arbitrary file deletion flaw rooted in improper validation of file paths within the maybe_delete_files function of the Avada (Fusion) Builder plugin for WordPress. The issue arises from insufficient sanitization of user-supplied input, enabling path traversal attacks. The affected component is the Fusion_Form_DB_Privacy cleanup routine triggered during shutdown, which processes database entries related to form submissions.

CVSS 9.1
EPSS 2.7%
KEV Pred 81%
Product themefusion Avada (Fusion) Builder themefusion
CVSS v3.1 CWE-22 PoC
02 Jun/26
CVE-2026-8206
CRITICAL

This vulnerability is a privilege escalation flaw caused by improper validation in the password reset functionality of the Kirki – Freeform Page Builder plugin for WordPress. The root cause lies in the plugin accepting an arbitrary email address when a username is submitted during a password reset request. The affected component is the password reset handler within the plugin's form processing logic, which fails to verify that the email corresponds to the username provided.

CVSS 9.8
EPSS 0.8%
KEV Pred 71%
Product themeum Kirki – Freeform Page Builder, Website Builder & Customizer themeum
CVSS v3.1 CWE-269 PoC
30 May/26
CVE-2026-7465
HIGH

This vulnerability is a remote code execution flaw arising from improper handling of block registration and rendering in the Spectra Gutenberg Blocks plugin. The root cause is the ability for authenticated users with Contributor-level privileges or higher to register arbitrary block types prefixed with 'uagb-' and assign attacker-controlled render callbacks. During sequential block rendering, the plugin invokes these callbacks via call_user_func(), enabling execution of arbitrary PHP code on the server.

CVSS 8.8
EPSS 1.0%
KEV Pred 37%
Product brainstormforce Spectra Gutenberg Blocks – Website Builder for the Block Editor brainstormforce
CVSS v3.1 CWE-269 PoC
29 May/26
CVE-2026-8732
CRITICAL

This vulnerability is a privilege escalation flaw caused by improper access control in the WP Maps Pro WordPress plugin. The root cause lies in the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_, allowing unauthenticated access. The protection relies solely on a nonce embedded in the frontend JavaScript, which is publicly accessible, rendering the nonce check ineffective as an authentication barrier.

CVSS 9.8
EPSS 1.9%
KEV Pred 83%
Product flippercode WP Maps Pro flippercode
CVSS v3.1 CWE-306 PoC
24 Feb/21
CVE-2021-21974
HIGH

This vulnerability is a heap overflow caused by improper handling of network messages within the OpenSLP service in VMware ESXi. The flaw arises from insufficient bounds checking when processing requests received on UDP port 427, leading to memory corruption in the heap. The affected component is the OpenSLP daemon responsible for service location protocol operations in ESXi versions prior to specified patches.

CVSS 8.8
EPSS 45.1%
KEV Pred 65%
Product VMware ESXi vmware
CVSS v3.1 CWE-787 PoC RANSOMWARE