Skip to content
THREATWIRE

Index

Search

Search the public record. Drafts and scheduled notes are not included.

Critical

news

Visual Composer LFI is CVE-2026-12227

Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.

Published 54m ago

High

news

The PostgreSQL fuzzystrmatch bug needs a database login

CVE-2026-15742 can run code as the PostgreSQL operating-system user. The vendor score is 8.8 and the vector requires a database account. Fixed builds shipped on 13 August 2026. A public PoC path exists. CISA has not listed it.

Published 1h ago

High

research

The Roundcube SQL injection is not in the CISA catalog

CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.

Published 1h ago

Critical

research

Reading the Next.js ImageResponse advisory

CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.

Published 3h ago

Critical

news

The Gotenberg public PoC is not a confirmed RCE

CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.

Published 3h ago

research

How ThreatWire records a vulnerability

The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.

Published 31h ago

CriticalPoC Available

CVE-2026-94545

Satori SVG injection affecting Next.js ImageResponse

RCE

Published 6d ago

CriticalPoC Available

CVE-2026-12227

Visual Composer unauthenticated local file inclusion

Other

Published 11d ago

HighPoC Available

CVE-2026-15742

PostgreSQL fuzzystrmatch integer wraparound

RCE

Published 13 Aug 2026

HighPoC Available

CVE-2026-48842

Roundcube virtuser_query SQL injection

SQLi

Published 25 May 2026

CriticalPoC Available

CVE-2026-40281

Gotenberg ExifTool argument injection

Other

Published 6 May 2026