CVE 清單 – 發現高風險與在野利用漏洞

聚合 NVD、CVE 及多源情資,深度解析 RCE 等高危風險。系統整合 CVSS 與 EPSS 模型,動態追蹤 Exploit 資源與 PoC 公開狀態,研判可利用性。結合官方修補與修復方案,優化漏洞管理優先級,縮短回應週期,保障資產安全。

指派機構(CNA / 來源):[email protected] 移除此篩選

顯示 8110016710 筆結果
CVE 描述 最高 CVSS EPSS % 公開時間 更新時間
CVE-2026-52704 Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8. 10.0 0.31% 2026-06-15 2026-06-17
CVE-2026-52703 Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. 9.6 0.34% 2026-06-15 2026-06-17
CVE-2026-52702 Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. 7.1 0.15% 2026-06-15 2026-06-17
CVE-2026-52700 Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. 8.5 0.35% 2026-06-15 2026-06-17
CVE-2026-52699 Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. 7.5 0.24% 2026-06-15 2026-06-17
CVE-2026-52698 Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2.3 versions. 7.4 0.22% 2026-06-17 2026-06-17
CVE-2026-52697 Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. 8.5 0.35% 2026-06-15 2026-06-17
CVE-2026-52696 Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. 7.5 0.24% 2026-06-17 2026-06-17
CVE-2026-52695 Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. 7.5 0.24% 2026-06-15 2026-06-17
CVE-2026-52694 Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. 7.5 0.24% 2026-06-15 2026-06-17
CVE-2026-52693 Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. 9.3 0.30% 2026-06-15 2026-06-17
CVE-2026-52692 Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. 7.5 0.24% 2026-06-15 2026-06-17
CVE-2026-49782 Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Elementor Website Builder: from n/a through 4.1.0. 5.4 0.14% 2026-06-02 2026-06-17
CVE-2026-49781 Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. 9.8 0.38% 2026-06-15 2026-06-17
CVE-2026-49780 Customer Privilege Escalation in Dokan <= 5.0.2 versions. 8.8 0.28% 2026-06-15 2026-06-17
CVE-2026-49778 Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions. 7.1 0.19% 2026-06-17 2026-06-17
CVE-2026-49777 Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4. 10.0 1.66% 2026-06-05 2026-06-17
CVE-2026-49776 Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. 9.3 0.29% 2026-06-15 2026-06-17
CVE-2026-49775 Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. 6.5 0.19% 2026-06-15 2026-06-17
CVE-2026-49774 Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. 9.9 0.28% 2026-06-16 2026-06-17
cvelogic Threat Intelligence