CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
2,435 results Clear all
CVE-2026-27438 9.8 CRITICAL EPSS 0.00
ThemeREX Kingler <=1.7 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7.
CWE-502 Mar 05, 2026
CVE-2026-27437 9.8 CRITICAL EPSS 0.00
ThemeREX Tennis Club <=1.2.3 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through <= 1.2.3.
CWE-502 Mar 05, 2026
CVE-2026-27417 9.8 CRITICAL EPSS 0.00
SeventhQueen Sweet Date <4.0.1 - Deserialization
Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1.
CWE-502 Mar 05, 2026
CVE-2026-27379 8.8 HIGH EPSS 0.00
NextScripts social-networks-auto-poster <=4.4.7 - Deserialization
Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
CWE-502 Mar 05, 2026
CVE-2026-27369 8.1 HIGH EPSS 0.00
BoldThemes Celeste <=1.3.6 - Deserialization
Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through <= 1.3.6.
CWE-502 Mar 05, 2026
CVE-2026-27338 8.8 HIGH EPSS 0.00
AivahThemes Car Zone <=3.7 - Deserialization
Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7.
CWE-502 Mar 05, 2026
CVE-2026-27098 8.1 HIGH EPSS 0.00
axiomthemes Au Pair Agency <=1.2.2 - Deserialization
Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through <= 1.2.2.
CWE-502 Mar 05, 2026
CVE-2026-24385 7.5 HIGH EPSS 0.00
Podlove Web Player <=5.9.1 - Deserialization
Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1.
CWE-502 Mar 05, 2026
CVE-2026-23798 8.8 HIGH EPSS 0.00
blubrry PowerPress Podcasting <=11.15.10 - Deserialization
Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.
CWE-502 Mar 05, 2026
CVE-2026-22501 9.8 CRITICAL EPSS 0.00
Mounthood <=1.3.2 - Deserialization
Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2.
CWE-502 Mar 05, 2026
CVE-2026-22497 9.8 CRITICAL EPSS 0.00
AncoraThemes Jardi <=1.7.2 - Deserialization
Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2.
CWE-502 Mar 05, 2026
CVE-2026-22475 9.8 CRITICAL EPSS 0.00
axiomthemes Estate <=1.3.4 - Deserialization
Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4.
CWE-502 Mar 05, 2026
CVE-2026-22474 9.8 CRITICAL EPSS 0.00
ThemeREX Equestrian Centre <=1.5 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through <= 1.5.
CWE-502 Mar 05, 2026
CVE-2026-22473 8.8 HIGH EPSS 0.00
Dental Clinic <=3.7 - Deserialization
Deserialization of Untrusted Data vulnerability in designthemes Dental Clinic dental allows Object Injection.This issue affects Dental Clinic: from n/a through <= 3.7.
CWE-502 Mar 05, 2026
CVE-2026-22471 8.6 HIGH EPSS 0.00
Secudeal Payments for Ecommerce <=1.1 - Deserialization
Deserialization of Untrusted Data vulnerability in maximsecudeal Secudeal Payments for Ecommerce secudeal-payments-for-ecommerce allows Object Injection.This issue affects Secudeal Payments for Ecommerce: from n/a through <= 1.1.
CWE-502 Mar 05, 2026
CVE-2026-22454 9.8 CRITICAL EPSS 0.00
ThemeREX Solaris <=2.5 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5.
CWE-502 Mar 05, 2026
CVE-2026-22453 9.8 CRITICAL EPSS 0.00
ThemeREX Pets Club <=2.3 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3.
CWE-502 Mar 05, 2026
CVE-2026-22451 9.8 CRITICAL EPSS 0.00
AncoraThemes Handyman <=1.4 - Deserialization
Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through <= 1.4.
CWE-502 Mar 05, 2026
CVE-2026-22417 8.1 HIGH EPSS 0.00
ThemeGoods Grand Wedding <=3.1.0 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through <= 3.1.0.
CWE-502 Mar 05, 2026
CVE-2025-54001 9.8 CRITICAL EPSS 0.00
ThemeREX Classter <=2.5 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <= 2.5.
CWE-502 Mar 05, 2026