cbcvebase.
← Exploited This Week

Exploited This Week — Jun 08–Jun 15, 2026

7 KEV · 28 newly weaponized · 8 EPSS surges

Patch now — added to CISA KEV

CVE-2026-42271
BerriAI LiteLLM Command Injection Vulnerability
CISA KEV (added 2026-06-08, due 2026-06-22) · CVSS 8.8 HIGH · EPSS 0.61 (98th pct)

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST…

Nuclei templateblogs_hackernews, vulncheck
CVE-2026-10520
Ivanti Sentry OS Command Injection Vulnerability
CISA KEV (added 2026-06-11, due 2026-06-14) · CVSS 10 CRITICAL · EPSS 0.43 (98th pct)

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, blogs_rapid7, vulncheck
CVE-2026-7473
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
CISA KEV (added 2026-06-09, due 2026-06-23) · CVSS 5.8 MEDIUM · EPSS 0.27 (97th pct)

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly…

blogs_hackernews, vuldb, vulncheck
CVE-2026-35273
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-06-12, due 2026-06-15) · 🦠 ransomware · CVSS 9.8 CRITICAL · EPSS 0.20 (96th pct)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows…

blogs_bleepingcomputer, blogs_hackernews, blogs_mandiant, blogs_rapid7 +1
CVE-2026-50751
Check Point Security Gateway Improper Authentication Vulnerability
CISA KEV (added 2026-06-08, due 2026-06-11) · 🦠 ransomware · CVSS 9.3 CRITICAL · EPSS 0.14 (94th pct)

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without…

blogs_bleepingcomputer, blogs_hackernews, blogs_rapid7, vuldb +1
CVE-2026-11645
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
CISA KEV (added 2026-06-09, due 2026-06-23) · CVSS 8.8 HIGH · EPSS 0.06 (91th pct)

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck
CVE-2026-20245
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
CISA KEV (added 2026-06-09, due 2026-06-23) · CVSS 7.8 HIGH · EPSS 0.00 (58th pct)

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated…

blogs_bleepingcomputer, blogs_hackernews, vuldb, vulncheck

Newly weaponized — exploit code appeared

CVE-2026-41679
Paperclip AI RCE using a chain of six API calls
CVSS 10 CRITICAL · EPSS 0.66 (99th pct)

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip…

Metasploit module
CVE-2026-3300
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all…
CVSS 9.8 CRITICAL · EPSS 0.35 (97th pct)

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating…

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, blogs_wiz, vulncheck
CVE-2026-41492
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
CVSS 9.8 CRITICAL · EPSS 0.27 (97th pct)

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security…

Nuclei templatevuldb
CVE-2025-13339
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and…
CVSS 7.5 HIGH · EPSS 0.30 (97th pct)

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the…

Nuclei templateblogs_wiz
CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
CVSS 10 CRITICAL · EPSS 0.24 (96th pct)

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, vulncheck
CVE-2026-5073
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to…
CVSS 7.5 HIGH · EPSS 0.24 (96th pct)

The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the…

Nuclei templatevuldb, vulncheck
CVE-2026-26190
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise in…
CVSS 9.8 CRITICAL · EPSS 0.15 (95th pct)

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable…

Nuclei templateblogs_wiz
CVE-2026-3018
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter…
CVSS 7.5 HIGH · EPSS 0.18 (95th pct)

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter and lack of…

Nuclei templatevulncheck
CVE-2025-25296
Label Studio allows Cross-Site Scripting (XSS) via GET request to /projects/upload-example endpoint
CVSS 6.1 MEDIUM · EPSS 0.24 (96th pct)

Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's /projects/upload-example endpoint allows injection of arbitrary HTML through a GET request with an appropriately crafted label_config query…

Nuclei template
CVE-2026-10523
Ivanti Sentry OS Command Injection Vulnerability
CVSS 9.9 CRITICAL · EPSS 0.09 (93th pct)

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Nuclei templateblogs_bleepingcomputer, blogs_hackernews, blogs_rapid7

+15 more lower-signal CVEs gained public exploit code this week.

EPSS surges — exploitation risk jumped

CVE-2022-1711
Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.
CVSS 7.5 HIGH · EPSS 0.83 (99th pct) · ↑ EPSS 0.35→0.83 (+0.48) over 7d

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

Nuclei template
CVE-2022-42118
Liferay Portal and Liferay DXP Vulnerable to XSS via the Portal Search Module
CVSS 6.1 MEDIUM · EPSS 0.52 (98th pct) · ↑ EPSS 0.13→0.52 (+0.39) over 7d

A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject…

Nuclei template
CVE-2004-2466
Easy Chat Server 3.1 - Remote Stack Buffer Overflow (SEH)
CVSS 5 MEDIUM · EPSS 0.78 (99th pct) · ↑ EPSS 0.45→0.78 (+0.33) over 7d

chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.

ExploitDB PoCMetasploit module
CVE-2020-36730
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the…
CVSS 9.3 CRITICAL · EPSS 0.70 (99th pct) · ↑ EPSS 0.46→0.70 (+0.24) over 7d

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This…

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2021-28549
Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability…
CVSS 7.8 HIGH · EPSS 0.28 (97th pct) · ↑ EPSS 0.06→0.28 (+0.22) over 7d

Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve…

blogs_qualys
CVE-2016-7976
Ghostscript vulnerabilities
CVSS 8.8 HIGH · EPSS 0.68 (99th pct) · ↑ EPSS 0.47→0.68 (+0.21) over 7d

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

🔧 no public PoC or detection rule linked yet — detection gap
CVE-2012-10056
PHP Volunteer Management System v1
CVSS 8.7 HIGH · EPSS 0.58 (98th pct) · ↑ EPSS 0.37→0.58 (+0.21) over 7d

PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file…

Metasploit module
CVE-2011-5172
Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio…
CVSS 9.3 CRITICAL · EPSS 0.51 (98th pct) · ↑ EPSS 0.30→0.51 (+0.20) over 7d

Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute arbitrary code via a long string in the string element field in a frame xml file.

ExploitDB PoC

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.