CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
2,430 results Clear all
CVE-2026-24891 7.5 HIGH EPSS 0.00
openITCOCKPIT <=5.3.1 - Deserialization
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads without enforcing class restrictions or validating data origin. While the intended deployment assumes only trusted internal components enqueue Gearman jobs, this trust boundary is not enforced in application code. In environments where the Gearman service or worker is exposed to untrusted systems, an attacker may submit crafted serialized payloads to trigger PHP Object Injection in the worker process. This vulnerability is exploitable when Gearman listens on non-local interfaces, network access to TCP/4730 is unrestricted, or untrusted systems can enqueue jobs. Default, correctly hardened deployments may not be immediately exploitable, but the unsafe sink remains present in code regardless of deployment configuration. Enforcing this trust boundary in code would significantly reduce risk and prevent exploitation in misconfigured environments. This issue has been fixed in version 5.4.0.
CWE-502 Feb 20, 2026
CVE-2026-22384 8.8 HIGH EPSS 0.00
Applay - Shortcodes <=3.7 - Deserialization
Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.
CWE-502 Feb 20, 2026
CVE-2026-22354 8.8 HIGH EPSS 0.00
Woocommerce Category Banner Management <=2.5.1 - Deserialization
Deserialization of Untrusted Data vulnerability in Dotstore Woocommerce Category Banner Management banner-management-for-woocommerce allows Object Injection.This issue affects Woocommerce Category Banner Management: from n/a through <= 2.5.1.
CWE-502 Feb 20, 2026
CVE-2026-22346 8.8 HIGH EPSS 0.00
Slider Responsive Slideshow <=1.5.4 - Deserialization
Deserialization of Untrusted Data vulnerability in A WP Life Slider Responsive Slideshow – Image slider, Gallery slideshow slider-responsive-slideshow allows Object Injection.This issue affects Slider Responsive Slideshow – Image slider, Gallery slideshow: from n/a through <= 1.5.4.
CWE-502 Feb 20, 2026
CVE-2026-22345 8.8 HIGH EPSS 0.00
A WP Life Image Gallery <=1.6.0 - Deserialization
Deserialization of Untrusted Data vulnerability in A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery new-image-gallery allows Object Injection.This issue affects Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery: from n/a through <= 1.6.0.
CWE-502 Feb 20, 2026
CVE-2025-69405 9.8 CRITICAL EPSS 0.00
Lorem Ipsum | Books & Media Store <=1.2.6 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.6.
CWE-502 Feb 20, 2026
CVE-2025-69404 9.8 CRITICAL EPSS 0.00
ThemeREX Extreme Store <=1.5.7 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.7.
CWE-502 Feb 20, 2026
CVE-2025-69382 9.8 CRITICAL EPSS 0.00
Themesflat Elementor <=1.0.1 - Deserialization
Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.
CWE-502 Feb 20, 2026
CVE-2025-69372 9.8 CRITICAL EPSS 0.00
AncoraThemes SevenHills <=1.6.2 - Deserialization
Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a through <= 1.6.2.
CWE-502 Feb 20, 2026
CVE-2025-69371 9.8 CRITICAL EPSS 0.00
AncoraThemes KindlyCare <=1.6.1 - Deserialization
Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a through <= 1.6.1.
CWE-502 Feb 20, 2026
CVE-2025-69370 9.8 CRITICAL EPSS 0.00
ThemeGoods Capella <=2.5.5 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <= 2.5.5.
CWE-502 Feb 20, 2026
CVE-2025-69329 9.8 CRITICAL EPSS 0.00
Jthemes Prestige <1.4.1 - Deserialization
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < 1.4.1.
CWE-502 Feb 20, 2026
CVE-2025-69328 8.8 HIGH EPSS 0.00
Booking and Rental Manager <=2.5.9 - Deserialization
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.
CWE-502 Feb 20, 2026
CVE-2025-69301 9.8 CRITICAL EPSS 0.00
ThemeGoods PhotoMe <=5.6.11 - Deserialization
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.
CWE-502 Feb 20, 2026
CVE-2025-69294 8.8 HIGH EPSS 0.00
PeakShops <=1.5.9 - Deserialization
Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5.9.
CWE-502 Feb 20, 2026
CVE-2025-68853 8.8 HIGH EPSS 0.00
Kleor Contact Manager <=9.1.1 - Deserialization
Deserialization of Untrusted Data vulnerability in Kleor Contact Manager contact-manager allows Object Injection.This issue affects Contact Manager: from n/a through <= 9.1.1.
CWE-502 Feb 20, 2026
CVE-2025-68541 9.8 CRITICAL EPSS 0.00
BoldThemes Ippsum <=1.2.0 - Deserialization
Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects Ippsum: from n/a through <= 1.2.0.
CWE-502 Feb 20, 2026
CVE-2025-68531 8.8 HIGH EPSS 0.00
ModelTheme Addons <1.5.6 - Deserialization
Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injection.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6.
CWE-502 Feb 20, 2026
CVE-2025-68526 8.8 HIGH EPSS 0.00
Modal Popup Box <=1.6.1 - Deserialization
Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1.
CWE-502 Feb 20, 2026
CVE-2025-67997 9.8 CRITICAL EPSS 0.00
BoldThemes Travelicious <1.6.7 - Deserialization
Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7.
CWE-502 Feb 20, 2026