LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

Vulnerability Intelligence

Track trending vulnerabilities and active exploitation signals in real-time.

Last updated: April 14, 2026 at 06:14 AM
Total
2,864
critical
889
high
1,565
medium
339
low
33
KEV
18
POCs
925
Remote
2,522

Showing 50 of 2864 vulnerabilities

CVE-2026-40313CriticalNEWPraisonAI - Authentication Bypass
CVSS: 9.1Age: today
Click to expand
CVE-2026-40289CriticalNEWPraisonAI - Authentication Bypass & Remote Session Hijacking
CVSS: 9.1Age: today
Click to expand
CVE-2026-40288CriticalNEWPraisonAI - Command Injection
CVSS: 9.8Age: today
Click to expand
CVE-2026-40287HighNEWPraisonAI - Command Injection
CVSS: 8.4Age: today
Click to expand
CVE-2026-6264CriticalNEWTalend JobServer & Runtime - Remote Code Execution
CVSS: 9.8Age: today
Click to expand
CVE-2026-6227HighNEWBackWPup WordPress Plugin - Local File Inclusion
CVSS: 7.2Age: today
PoCRemote
Click to expand
CVE-2026-4365CriticalNEWLearnPress WordPress Plugin - Broken Access Control
CVSS: 9.1Age: today
Click to expand
CVE-2026-27681CriticalNEWSAP Business Planning and Consolidation & SAP Business Warehouse - SQL Injection
CVSS: 9.9Age: today
Click to expand
CVE-2026-22564CriticalNEWUniFi Play - Broken Access Control
CVSS: 9.8Age: today
Click to expand
CVE-2026-22563CriticalNEWUniFi Play - Command Injection
CVSS: 9.8Age: today
Click to expand
CVE-2026-22562CriticalNEWUniFi Play - Path Traversal & Remote Code Execution
CVSS: 9.8Age: today
Click to expand
CVE-2026-31280N/aNEWParani M10 Motorcycle Intercom - Denial of Service
CVSS: N/AAge: today
PoC
Click to expand
CVE-2026-6201MediumNEWCodeAstro Online Job Portal - Broken Access Control
CVSS: 5.4Age: today
PoCRemote
Click to expand
CVE-2026-31048N/aNEWPyro - Remote Code Execution
CVSS: N/AAge: today
PoC
Click to expand
CVE-2026-6200HighNEWTenda F456 - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-6199HighNEWTenda F456 - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-6197HighNEWTenda F456 - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-6198HighNEWTenda F456 - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-40044CriticalNEWPachno - Remote Code Execution
CVSS: 9.8Age: today
Click to expand
CVE-2026-40042CriticalNEWPachno - XML External Entity Injection
CVSS: 9.8Age: today
Click to expand
CVE-2026-40040HighNEWPachno - Unrestricted File Upload
CVSS: 8.8Age: today
Click to expand
CVE-2026-29955N/aNEWKubePlus - Command Injection
CVSS: N/AAge: today
PoC
Click to expand
CVE-2026-6194HighNEWTotolink A3002MU - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-6195CriticalNEWTotolink A7100RU - Command Injection
CVSS: 9.8Age: today
Click to expand
CVE-2026-6196HighNEWTenda F456 - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-32316HighNEWjq - Integer Overflow & Heap-based Buffer Overflow
CVSS: 8.2Age: today
Click to expand
CVE-2026-28291HighNEWsimple-git - Command Injection
CVSS: 8.1Age: today
Click to expand
CVE-2026-6184LowNEWcode-projects Simple Content Management System - Stored XSS
CVSS: 2.4Age: today
PoCRemote
Click to expand
CVE-2026-6186HighNEWUTT HiPER 1200GW - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-6183HighNEWcode-projects Simple Content Management System - SQL Injection
CVSS: 7.3Age: today
PoCRemote
Click to expand
CVE-2026-6182HighNEWcode-projects Simple Content Management System - SQL Injection
CVSS: 7.3Age: today
PoCRemote
Click to expand
CVE-2026-31282N/aNEWTotara LMS - Broken Access Control
CVSS: N/AAge: today
PoC
Click to expand
CVE-2026-31283N/aNEWTotara LMS - Denial of Service
CVSS: N/AAge: today
PoC
Click to expand
CVE-2026-33858HighNEWApache Airflow - Stored XSS
CVSS: 8.8Age: today
Click to expand
CVE-2026-31281N/aNEWTotara LMS - Stored XSS
CVSS: N/AAge: today
PoC
Click to expand
CVE-2026-29628MediumNEWtinyobjloader - Denial of Service
CVSS: 6.2Age: today
PoC
Click to expand
CVE-2026-1462HighNEWKeras - Insecure Deserialization
CVSS: 8.8Age: today
Click to expand
CVE-2026-35337HighNEWApache Storm - Insecure Deserialization
CVSS: 8.8Age: today
Click to expand
CVE-2026-6168HighNEWTOTOLINK A7000R - Buffer Overflow
CVSS: 8.8Age: today
Click to expand
CVE-2026-5936HighNEWGeneric Server - Server Side Request Forgery
CVSS: 8.5Age: today
Click to expand
CVE-2026-3830HighNEWProduct Filter for WooCommerce by WBW WordPress - SQL Injection
CVSS: 8.6Age: today
Click to expand
CVE-2026-5085CriticalNEWSolstice::Session - Authentication Bypass
CVSS: 9.1Age: today
Click to expand
CVE-2026-25205HighNEWSamsung Open Source Escargot - Buffer Overflow
CVSS: 8.1Age: 1 day
Click to expand
CVE-2026-25208HighNEWSamsung Open Source Escargot - Integer Overflow
CVSS: 8.1Age: 1 day
Click to expand
CVE-2026-6157HighNEWTotolink A800R - Buffer Overflow
CVSS: 8.8Age: 1 day
Click to expand
CVE-2026-6155CriticalNEWTotolink A7100RU - Command Injection
CVSS: 9.8Age: 1 day
Click to expand
CVE-2026-6156CriticalNEWTotolink A7100RU - Command Injection
CVSS: 9.8Age: 1 day
Click to expand
CVE-2026-6154CriticalNEWTotolink A7100RU - Command Injection
CVSS: 9.8Age: 1 day
Click to expand
CVE-2026-6139CriticalNEWTotolink A7100RU - Command Injection
CVSS: 9.8Age: 1 day
Click to expand
CVE-2026-6140CriticalNEWTotolink A7100RU - Command Injection
CVSS: 9.8Age: 1 day
Click to expand

Check Your Domain for Exposed Credentials

Use our free scanner to check if credentials associated with your domain have been exposed in recent leaks or breaches.

Scan Your Domain