Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Threat Lab
CVE-2026-33267 – Header Injection / Internal Metadata Spoofing – Apache Traffic Server 9.2.0–9.2….

CVE-2026-33267 is an Improper Input Validation vulnerability in Apache Traffic Server (ATS) in which untrusted @ headers in HTTP requests can be used to spoof ATS internal metadata, affecting versions 9.2.0 through 9.2.14 and 10.1.0 through 10.1.3. The flaw carries a perfect CVSS 3.1 score of 10.0 (Critical) and is exploitable remotely by unauthenticated attackers with no user interaction required. Apache has released fixed versions 9.2.15 and 10.1.4 and recommends immediate upgrade.

Created Date
Source IONIX Threat Lab
CVE-2026-57834 – HTTP Request Smuggling – Apache Traffic Server 8.0.0–10.1.3

CVE-2026-57834 is a critical HTTP request smuggling vulnerability in Apache Traffic Server (ATS) caused by improper handling of malformed chunked message bodies (CWE-444: Inconsistent Interpretation of HTTP Requests). It affects ATS versions 8.0.0 through 10.1.3 and carries a CVSS v3.1 base score of 10.0 (Critical), requiring no authentication and no user interaction to exploit over the network.

Created Date
Source IONIX Threat Lab
CVE-2026-22068 – Access Control Bypass via Unanchored Regex – Apache Traffic Server 9.0.x–9.2.14,…

CVE-2026-22068 is a high-severity Regular Expression without Anchors (CWE-777) vulnerability in Apache Traffic Server (ATS), a widely deployed internet-facing reverse proxy and caching server. Improperly anchored regular expressions in ATS's URL-mapping rules can be matched by specially crafted malicious domain names, allowing an unauthenticated remote attacker to bypass access controls and reach backend resources that should be restricted. The vulnerability carries a CVSS v3.1 score of 8.2 (High) and affects the 9.x and 10.x release branches.

Created Date
Source IONIX Threat Lab
CVE-2026-58150 – HTTP/2 Request Smuggling – Apache Traffic Server 8.0.0–10.1.3

CVE-2026-58150 is a critical HTTP/2 request smuggling vulnerability in Apache Traffic Server (ATS), rated CVSS 10.0 (Critical). The flaw arises because ATS does not reject Transfer-Encoding headers in HTTP/2 requests — violating the HTTP/2 specification — which enables H2.TE-based downgrade request smuggling attacks against downstream backend servers. The vulnerability is remotely exploitable with no authentication, no user interaction, and low attack complexity, and its scope-changed CVSS rating reflects that exploitation can extend beyond ATS itself to the backend infrastructure it proxies.

Created Date
Source IONIX Threat Lab
CVE-2026-41920 – Improper Access Control (SNI/Host Header Policy Bypass) – Apache Traffic Server …

CVE-2026-41920 is a critical Improper Access Control vulnerability (CWE-284) in Apache Traffic Server, caused by the failure to properly enforce SNI (Server Name Indication) to Host header matching policies. It affects all deployments running versions 9.0.0 through 9.1.14 and 10.0.0 through 10.1.3, and carries a CVSS v3.1 score of 9.3 (Critical). The flaw requires no authentication and no user interaction, and is exploitable over the network from any remote attacker.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-65879 – Unauthenticated Mail Relay (Hardcoded Secret) – SP Page Builder for Joomla 1.0.0 th

CVE-2026-65879 is a critical (CVSS 9.8) use of hard-coded credentials vulnerability in the SP Page Builder extension for Joomla (vendor: JoomShaper). A secret string embedded identically in every shipped copy of the extension protects the recipient address used by contact-form addons. Because the secret is present in the distributed source, an unauthenticated attacker can forge a valid signature and abuse the site as an open mail relay, spoofing the "mail from" address on forms.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51077 – SQL Injection – DedeCMS 5.7.118

CVE-2026-51077 is an SQL injection vulnerability (CWE-89) in DedeCMS version 5.7.118. A remote attacker can inject arbitrary SQL through the sqlquery parameter of the sys_sql_query.php component, allowing extraction of sensitive information from the backing database. The issue carries a CVSS v3.1 base score of 7.5 (HIGH) with a network attack vector.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-14924 – Unauthenticated Post/Page Creation & Overwrite (Missing Authorization) – Tablesome

CVE-2026-14924 is a Missing Authorization (CWE-862) vulnerability in the Tablesome Table WordPress plugin for versions before 1.1.31. One of the plugin's AJAX actions performs no authentication, capability, or nonce checks, allowing unauthenticated attackers to create new published posts and overwrite arbitrary existing posts and pages. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-14545 – Authentication Bypass / Account Takeover – TrueBooker WordPress Plugin (before 1…

CVE-2026-14545 is a critical authentication bypass and account takeover vulnerability in the TrueBooker – Appointment Booking and Scheduler System WordPress plugin affecting all versions before 1.2.4. The flaw allows an unauthenticated remote attacker to reset the password of any WordPress account — including site administrators — by exploiting a front-end account handler that performs no account ownership validation, leading to full site takeover. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-65880 – Unauthenticated RCE via Signature Field – Balbooa Forms for Joomla (all versions…

CVE-2026-65880 is a critical unauthenticated remote code execution vulnerability in Balbooa Forms, a form-builder extension for the Joomla CMS developed by balbooa.com. The flaw resides in insecure form processing logic that is triggered when a form includes the signature field type, enabling a fully unauthenticated remote attacker to execute arbitrary code on the underlying server. The vulnerability carries a maximum CVSS 4.0 score of 10.0, with no complexity, no required privileges, no user interaction, and full impact on confidentiality, integrity, and availability of both the affected system and its surrounding…

Created Date
Source IONIX Threat Lab
CVE-2026-65702 – Arbitrary File Write via Path Traversal – Vanna AI (vanna-ai) through v2.0.2

CVE-2026-65702 is a path traversal vulnerability (CWE-22) in Vanna (vanna-ai) through version 2.0.2, affecting the FileSystemConversationStore persistence integration. Unauthenticated remote attackers can supply path traversal sequences in the conversation_id parameter of the unauthenticated chat API endpoints to write attacker-controlled JSON files to arbitrary filesystem locations or read files outside the intended base directory. The vulnerability carries a CVSS v3.1 score of 8.6 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-12255 – Authentication Bypass – MainWP Child WordPress Plugin before 6.1.2

CVE-2026-12255 is a high-severity authentication bypass vulnerability (CWE-287: Improper Authentication) in the MainWP Child WordPress plugin, affecting all versions before 6.1.2. The flaw allows an unauthenticated remote attacker to obtain a fully valid authenticated session — including administrator-level access — by exploiting a missing identity verification step in the plugin's site-registration request handler. With over 700,000 active installations, the potential exposure across internet-facing WordPress sites is significant.

Created Date
Source IONIX Threat Lab
CVE-2026-12493 – Payment Verification Bypass – Clover Payment Gateway by Zaytech for WooCommerce …

CVE-2026-12493 is a high-severity unauthenticated payment verification bypass affecting the Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin in all versions before 1.3.6. The flaw allows any unauthenticated attacker to mark arbitrary WooCommerce orders as paid by replaying a legitimately-approved payment reference — without paying the correct amount. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-13152 – Unauthenticated Privilege Escalation / Admin Takeover – Custom Fields Account Re…

CVE-2026-13152 is a high-severity unauthenticated privilege escalation vulnerability in the Custom Fields Account Registration For WooCommerce WordPress plugin, affecting all versions before 1.4. By exploiting insufficient validation in how custom registration fields are saved to user metadata, an unauthenticated attacker can register an account and assign themselves the WordPress administrator role, resulting in full site takeover. The IONIX research team is tracking potentially affected assets and recommends immediate patching.

Created Date
Source IONIX Threat Lab
CVE-2026-59538 – Unauthenticated SQL Injection – GamiPress WordPress Plugin ≤ 7.9.7

CVE-2026-59538 is a critical unauthenticated blind SQL injection vulnerability affecting the GamiPress WordPress plugin in all versions up to and including 7.9.7. With a CVSS v3.1 base score of 9.3, the flaw allows any remote, unauthenticated attacker to interact directly with the underlying WordPress database, enabling mass extraction of sensitive data from over 10,000 active installations.

Created Date
Source IONIX Threat Lab
CVE-2026-59549 – Unauthenticated SQL Injection – rtMedia for WordPress, BuddyPress and bbPress ≤ …

CVE-2026-59549 is a critical unauthenticated SQL Injection vulnerability (CWE-89) in the rtMedia for WordPress, BuddyPress and bbPress plugin, developed by rtCamp, affecting all versions up to and including 4.7.10. With a CVSS v3.1 score of 9.3 (Critical), the flaw can be exploited remotely by any unauthenticated attacker to extract sensitive data — including credentials, personally identifiable information (PII), and API keys — directly from the underlying WordPress database. A patched version (4.7.11) has been released and immediate upgrade is strongly recommended.

Created Date
Source IONIX Threat Lab
CVE-2026-59550 – Unauthenticated SQL Injection – AWP Classifieds Plugin <= 4.4.7

CVE-2026-59550 is a critical unauthenticated SQL injection vulnerability in the AWP Classifieds WordPress plugin (also known as Another WordPress Classifieds Plugin), developed by Strategy11 Team, affecting all versions up to and including 4.4.7. With a CVSS v3.1 score of 9.3 (Critical), the flaw allows any unauthenticated remote attacker to inject arbitrary SQL commands and extract sensitive data from the underlying WordPress database. A patched release, version 4.4.8, is available and immediate upgrade is strongly recommended.

Created Date
Source IONIX Threat Lab
CVE-2026-16812 – Unauthenticated Remote Code Execution – Arista VeloCloud Orchestrator On-Prem

CVE-2026-16812 is a critical OS command injection vulnerability (CWE-78) in Arista VeloCloud Orchestrator (VCO) On-Prem, carrying the maximum CVSS v3.1 score of 10.0. The flaw exposes privileged internal functionality — intended to be accessible only from within the system — to unauthenticated remote attackers over the network, enabling full compromise of the orchestrator host and all SD-WAN infrastructure it manages. Arista has confirmed active exploitation in the wild and released patched versions for all affected on-prem branches.

Created Date
Source IONIX Threat Lab
CVE-2026-66473 – Authorization Bypass – Xendit Payment WordPress Plugin <= 7.1.0

CVE-2026-66473 is a high-severity Broken Access Control vulnerability (CWE-862: Missing Authorization) affecting the Xendit Payment WooCommerce plugin (woo-xendit-virtual-accounts) for WordPress in all versions up to and including 7.1.0. The flaw allows unauthenticated remote attackers to invoke privileged plugin functionality without any credentials or user interaction, carrying a CVSS v3.1 base score of 7.5 (High). As of the publication date (July 27, 2026), no patched version has been released.

Created Date
Source IONIX Threat Lab
CVE-2026-13161 – Unauthenticated SQL Injection – TrueBooker WordPress Plugin ≤ 1.2.2

CVE-2026-13161 is a high-severity unauthenticated SQL injection vulnerability in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, affecting all versions up to and including 1.2.2. Due to insufficient escaping of user-supplied input and improper SQL query preparation, unauthenticated remote attackers can inject arbitrary SQL commands via the alldata[truebooker_user] POST parameter to extract sensitive data from the WordPress database. The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-14516 – Unauthenticated SQL Injection – Bookly WordPress Plugin ≤ 27.5

CVE-2026-14516 is a high-severity, unauthenticated time-based SQL Injection vulnerability in the Online Scheduling and Appointment Booking System – Bookly plugin for WordPress, affecting all versions up to and including 27.5. The flaw stems from insufficient escaping of user-supplied input and lack of proper SQL query preparation in the staff_ids parameter, enabling unauthenticated remote attackers to extract sensitive data from the underlying WordPress database. With a CVSS v3.1 base score of 7.5 (HIGH) and no authentication or user interaction required, all internet-exposed WordPress sites running a vulnerable version of Bookly are…

Created Date
Source IONIX Threat Lab
CVE-2026-12800 – Unauthenticated SQL Injection – Premium Packages WordPress Plugin (≤ 6.2.0)

CVE-2026-12800 is a high-severity unauthenticated SQL injection vulnerability in the Premium Packages – Sell Digital Products Securely WordPress plugin (wpdm-premium-packages), affecting all versions up to and including 6.2.0. The flaw allows any unauthenticated remote attacker to inject arbitrary SQL via the plugin's coupon REST API endpoint and extract sensitive data from the WordPress database. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-12741 – Unauthenticated SQL Injection – WP Fast Total Search WordPress Plugin (≤ 1.80.280)

CVE-2026-12741 is a high-severity unauthenticated SQL injection vulnerability affecting the WP Fast Total Search – The Power of Indexed Search WordPress plugin (all versions up to and including 1.80.280), developed by Epsiloncool. Due to insufficient escaping of user-supplied input and improper SQL query preparation, unauthenticated remote attackers can append malicious SQL statements to existing queries and extract sensitive data from the underlying WordPress database. The vulnerability carries a CVSS v3.1 base score of 7.5 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-15014 – Authentication Bypass / Account Takeover – SMS Alert WordPress Plugin ≤ 3.9.7

CVE-2026-15014 is a critical authentication bypass vulnerability in the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery WordPress plugin (vendor: Cozy Vision Technologies Pvt. Ltd.), affecting all versions up to and including 3.9.7. The flaw allows completely unauthenticated remote attackers to authenticate as any existing WordPress user — including site administrators — by abusing a logic error in the plugin's OTP-based registration flow.

Created Date
Source IONIX Threat Lab
CVE-2026-64649 – SSRF in Server Actions – Next.js 14.1.1–15.5.20 and 16.0.0–16.2.10

CVE-2026-64649 is a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in Next.js Server Actions, rated 8.3 (High) under CVSS 4.0. When a Server Action forwards or redirects a request, an unauthenticated attacker who can control Host-associated headers can cause the server to send that outbound request to an attacker-controlled host. In some configurations, the vulnerability also leaks internal values that can weaken middleware and proxy-based authorization controls.

Created Date
Source IONIX Threat Lab
CVE-2026-9830 – Authentication Bypass – BookingPress Appointment Booking Pro WordPress Plugin bef…

CVE-2026-9830 is a high-severity authentication bypass vulnerability in the BookingPress Appointment Booking Pro WordPress plugin, affecting all versions prior to 5.7.3. The plugin fails to correctly invoke its REST API permission callback, leaving every route in one of its API namespaces accessible without authentication. With a CVSS v3.1 score of 8.2 (High), unauthenticated remote attackers can read sensitive customer booking data and modify other users' reservations without any credentials or user interaction.

Created Date
Source IONIX Threat Lab
CVE-2026-64642 – Authentication Bypass – Next.js 16.0.0–16.2.10

CVE-2026-64642 is a high-severity authentication bypass vulnerability in Next.js, the widely deployed React web framework maintained by Vercel. Affecting versions 16.0.0 through 16.2.10, the flaw allows unauthenticated remote attackers to craft requests that completely bypass middleware- and proxy-based authentication in applications using the App Router with Turbopack and a single configured i18n locale. The issue was disclosed and patched as part of Vercel's July 21, 2026 security release, with a CVSS 4.0 score of 8.3 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-64645 – SSRF / Open Redirect – Next.js 12.0.0–15.5.20 and 16.0.0–16.2.10

CVE-2026-64645 is a Server-Side Request Forgery (SSRF) and Open Redirect vulnerability in Next.js, the widely deployed React full-stack web framework maintained by Vercel. It affects versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, and carries a CVSS 4.0 score of 8.3 (High). When a rewrites() or redirects() configuration rule dynamically constructs an external destination hostname from attacker-controlled request input, the intended hostname suffix can be bypassed — enabling the Next.js server to be forced to proxy requests to any arbitrary host.

Created Date
Source IONIX Threat Lab
CVE-2026-63077 – Unauthenticated RCE via Agent Polling Protocol – JetBrains TeamCity before 2026….

CVE-2026-63077 is a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, stemming from insecure deserialization of untrusted data (CWE-502) in the agent polling protocol. It affects all TeamCity On-Premises versions prior to 2026.1.3 and 2025.11.7, and carries a CVSS v3.1 base score of 9.8 (Critical). An unauthenticated remote attacker can exploit this flaw to execute arbitrary code on the TeamCity server with no credentials or user interaction required.

Created Date
Source IONIX Threat Lab
CVE-2025-15662 – Unauthenticated SSRF and Arbitrary File Read – Printcart Web to Print Product De…

CVE-2025-15662 is a high-severity vulnerability affecting the Printcart Web to Print Product Designer for WooCommerce WordPress plugin in all versions prior to 2.5.3. The flaw combines two unauthenticated attack vectors — an Arbitrary Local File Read and Server-Side Request Forgery (SSRF) — arising from the plugin's failure to validate user-supplied URLs before performing server-side fetch operations. With a CVSS v3.1 score of 8.6 (High) and no authentication requirement, internet-exposed WooCommerce stores running this plugin are at immediate risk of credential theft and internal network reconnaissance.

Created Date
Source IONIX Threat Lab
CVE-2026-59527 – Unauthenticated SQL Injection – MapSVG WordPress Plugin <= 8.14.0

CVE-2026-59527 is a critical unauthenticated SQL injection vulnerability in the MapSVG WordPress plugin (by RomanCode), affecting all versions up to and including 8.14.0. Classified as CWE-89 (Improper Neutralization of Special Elements in SQL Commands), it carries a CVSS v3.1 score of 9.3 and requires no credentials or user interaction to exploit. Organizations running the MapSVG plugin on internet-facing WordPress sites should treat this as a priority patching event.

Created Date
Source IONIX Threat Lab
CVE-2026-61511 – Unauthenticated Remote Code Execution via Eval Injection – vBulletin 5.x through…

CVE-2026-61511 is a critical eval injection vulnerability affecting vBulletin 5.x through 5.7.5 and 6.x through 6.2.1, rated CVSS 9.8 (Critical) under v3.1. The flaw resides in the vB5_Template_Runtime::runMaths() method and allows unauthenticated remote attackers to inject and execute arbitrary PHP code through a publicly accessible AJAX endpoint. No credentials, session token, or user interaction of any kind is required to exploit this vulnerability.

Created Date
Source IONIX Threat Lab
CVE-2026-65876 – Unauthenticated SQL Injection – SP Page Builder for Joomla (< 6.7.1)

CVE-2026-65876 is a critical, unauthenticated SQL injection vulnerability in SP Page Builder, a widely-deployed page-builder extension for Joomla developed by joomshaper.com. The flaw arises from improper validation of the catid parameter in the public-facing loadMoreArticles endpoint, allowing any anonymous attacker over the network to inject arbitrary SQL commands. The vulnerability carries a CVSS 4.0 score of 9.2 (Critical) and affects all SP Page Builder versions from 1.0.0 through 6.7.0.

Created Date
Source IONIX Threat Lab
CVE-2026-65766 – Unauthenticated SQL Injection – SP Page Builder for Joomla < 6.7.1

CVE-2026-65766 is a critical unauthenticated SQL injection vulnerability in SP Page Builder, a widely deployed page-building extension for Joomla developed by JoomShaper. The flaw exists in the Dynamic Content endpoint, where the direction order parameter is concatenated directly into a SQL ORDER BY clause without validation, enabling any unauthenticated remote attacker to extract the full contents of the Joomla database. This vulnerability was published on July 27, 2026 and carries a CVSS 4.0 score of 9.2 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-15810 – XSS Leading to Administrative Account Takeover – Google Cloud Looker (Self-Hoste…

CVE-2026-15810 is a reflected Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker affecting both Looker-hosted and self-hosted deployments. An unauthenticated attacker can craft a malicious URL that, when opened by a Looker administrator, executes arbitrary JavaScript in the administrator's session and results in full administrative account takeover. The vulnerability carries a CVSS v4.0 base score of 8.7 (HIGH) and was disclosed by Google on July 22, 2026.

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge