cbcvebase.
← Exploited This Week

Exploited This Week — Jun 01–Jun 08, 2026

5 KEV · 18 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2024-21182
Oracle WebLogic Server Unspecified Vulnerability
CISA KEV (added 2026-06-01, due 2026-06-04) · CVSS 7.5 HIGH · EPSS 0.90 (100th pct)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

blogs_bleepingcomputer, blogs_hackernews, vulncheck
CVE-2022-0492
Linux Kernel Improper Authentication Vulnerability
CISA KEV (added 2026-06-02, due 2026-06-05) · CVSS 7.8 HIGH · EPSS 0.28 (97th pct)

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges…

Metasploit moduleelastic_rules ruleblogs_bleepingcomputer, blogs_hackernews, blogs_securelist, blogs_sentinelone +2
CVE-2026-28318
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
CISA KEV (added 2026-06-05, due 2026-06-19) · CVSS 7.5 HIGH · EPSS 0.07 (91th pct)

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-45247
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-06-03, due 2026-06-06) · CVSS 9.8 CRITICAL · EPSS 0.06 (91th pct)

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the…

blogs_hackernews, vuldb, vulncheck
CVE-2025-48595
Android Framework Integer Overflow Vulnerability
CISA KEV (added 2026-06-02, due 2026-06-05) · CVSS 8.4 HIGH · EPSS 0.01 (68th pct)

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-42208
BerriAI LiteLLM SQL Injection Vulnerability
CISA KEV (added 2026-05-08, due 2026-05-11) · CVSS 9.8 CRITICAL · EPSS 0.57 (98th pct)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_talos +2
CVE-2026-0257
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
CISA KEV (added 2026-05-29, due 2026-06-01) · CVSS 9.1 CRITICAL · EPSS 0.53 (98th pct)

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW…

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, blogs_rapid7 +3
CVE-2026-29059
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs.
CVSS 7.5 HIGH · EPSS 0.23 (96th pct)

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint…

Nuclei templateblogs_checkpoint, blogs_hackernews
CVE-2026-42589
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
CVSS 9.8 CRITICAL · EPSS 0.09 (93th pct)

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No…

Nuclei templatevuldb
CVE-2025-13773
tychesoftwares print_invoice_\&_delivery_notes_for_woocommerce Improper Control of Generation of Code ('Code Injection')
CVSS 9.8 CRITICAL · EPSS 0.09 (93th pct)

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing…

Nuclei templateblogs_wiz, vulncheck
CVE-2025-49001
DataEase is an open source business intelligence and data visualization tool.
CVSS 9.8 CRITICAL · EPSS 0.07 (92th pct)

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been…

Nuclei templateblogs_greynoiseio
CVE-2026-42647
Vulnerability
CVSS 9.3 CRITICAL

WordPress Plugin: joomsport-sports-league-results-management: CVE-2026-42647: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Required Action: Apply remediations or mitigations per vendor instructions…

Nuclei templatevulncheck
CVE-2026-45397
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
CVSS 5.3 MEDIUM · EPSS 0.01 (78th pct)

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticated HTTP client. No Authorization header…

Nuclei templatevuldb
CVE-2026-7798
The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin…
CVSS 5.4 MEDIUM · EPSS 0.01 (76th pct)

The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the…

Nuclei templatevuldb
CVE-2026-48710
starlette: Starlette: Security restriction bypass via malformed HTTP Host header
CVSS 6.5 MEDIUM · EPSS 0.00 (58th pct)

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while…

Nuclei templatevuldb

+5 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2017-7397
BackBox OS - Denial of Service
CVSS 7.5 HIGH · EPSS 0.51 (98th pct) · ↑ EPSS 0.20→0.51 (+0.31) over 7d

BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables…

ExploitDB PoC
CVE-2018-7846
Schneider Electric Modicon Controllers
CVSS 9.8 CRITICAL · EPSS 0.63 (98th pct) · ↑ EPSS 0.34→0.63 (+0.30) over 7d

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute…

blogs_talos
CVE-2022-28508
MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php
CVSS 6.1 MEDIUM · EPSS 0.29 (97th pct) · ↑ EPSS 0.01→0.29 (+0.28) over 7d

An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field.

Nuclei template
CVE-2011-5162
GOM Player 2.1.33.5071 - '.asx' File Unicode Stack Buffer Overflow
CVSS 9.3 CRITICAL · EPSS 0.51 (98th pct) · ↑ EPSS 0.26→0.51 (+0.24) over 7d

Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-0707 regression.

ExploitDB PoC
CVE-2011-5002
Final Draft 8 - Multiple Stack Buffer Overflows (Metasploit)
CVSS 10 CRITICAL · EPSS 0.34 (97th pct) · ↑ EPSS 0.10→0.34 (+0.24) over 7d

Multiple stack-based buffer overflows in Final Draft 8 before 8.02 allow remote attackers to execute arbitrary code via a .fdx or .fdxt file with long (1) Word, (2) Transition, (3) Location, (4) Extension, (5) SceneIntro, (6) TimeOfDay…

ExploitDB PoC
CVE-2012-3259
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute…
CVSS 10 CRITICAL · EPSS 0.46 (98th pct) · ↑ EPSS 0.24→0.46 (+0.22) over 7d

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.

suricata rule
CVE-2013-2574
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and…
CVSS 7.5 HIGH · EPSS 0.53 (98th pct) · ↑ EPSS 0.31→0.53 (+0.22) over 7d

An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.

ExploitDB PoC
CVE-2019-11634
Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability
CISA KEV (added 2021-11-03, due 2022-05-03) · 🦠 ransomware · CVSS 9.8 CRITICAL · EPSS 0.52 (98th pct) · ↑ EPSS 0.31→0.52 (+0.22) over 7d

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

blogs_qualys, vulncheck

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.