216.73.216.54

Threat intelligence dashboard

Today's CVEs, attack reports, and CISA KEV — CVSS, EPSS, and MITRE context at a glance.

Attack reports – last 7 days · through Monday 27 July 2026 (26)

Vulnerabilities today (198)

Sorted by CVSS severity (highest first)

10.0 Critical

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and …

Attack vector
Network
Complexity
Low
Published
27/07/2026
9.9 Critical

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.8 Critical

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.8 Critical

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Attack vector
Network
Complexity
Low
Published
27/07/2026
9.8 Critical

A use-after-free (UAF) vulnerability was discovered in the core parsing component of SQLite 3.41. The flaw occurs because the program frees an …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.8 Critical

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.8 Critical

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.8 Critical

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.6 Critical

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary …

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.4 Critical

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges …

Published
27/07/2026
9.3 Critical

Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.

Attack vector
Network
Complexity
Low
Published
27/07/2026
9.3 Critical

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.3 Critical

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.3 Critical

Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026
9.3 Critical

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Attack vector
NETWORK
Complexity
LOW
Published
27/07/2026