CVE 列表 – 发现高风险与在野利用漏洞

聚合 NVD、CVE 及多源情报,深度解析 RCE 等高危风险。系统集成 CVSS 与 EPSS 模型,动态追踪 Exploit 资源与 PoC 公开状态,研判可利用性。结合官方补丁与修复方案,优化漏洞管理优先级,缩短响应周期,保障资产安全。

分配机构(CNA / 来源):[email protected] 移除此筛选

显示 1211401222 条结果
CVE 描述 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-49770 Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49769 Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49768 Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49766 Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. 9.9 0.51% 2026-06-15 2026-06-17
CVE-2026-49765 Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49764 Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. 9.8 0.40% 2026-06-15 2026-06-17
CVE-2026-49763 Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. 9.8 0.38% 2026-06-15 2026-07-08
CVE-2026-49109 Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49106 Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49105 Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. 9.8 0.48% 2026-06-15 2026-06-17
CVE-2026-49104 Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. 9.8 0.48% 2026-06-15 2026-06-17
CVE-2026-49085 Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. 9.8 0.48% 2026-06-15 2026-06-17
CVE-2026-49067 Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions. 9.3 0.30% 2026-06-15 2026-06-17
CVE-2026-48886 Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. 9.3 0.28% 2026-06-15 2026-06-17
CVE-2026-48881 Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. 9.1 0.28% 2026-06-15 2026-06-17
CVE-2026-48836 Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. 10.0 0.57% 2026-06-15 2026-06-17
CVE-2026-45439 Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions. 9.3 0.29% 2026-06-15 2026-06-17
CVE-2026-42665 Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. 9.3 0.28% 2026-06-15 2026-06-17
CVE-2026-42639 Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. 9.3 0.28% 2026-06-15 2026-06-17
CVE-2026-42386 Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions. 9.3 0.28% 2026-06-15 2026-06-17
cvelogic Threat Intelligence