LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Ollyo

3 CVEs published in the last four months. Exploited flaws first.

Critical2
High1
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-48908exploited9.8criticalsp page builderA vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately r77d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-48908exploited9.8criticalsp page builderA vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately r77d ago
CVE-2026-578309.1criticalhelix ultimateJoomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla54d ago
CVE-2026-490497.5highhelix3The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitra68d ago

Filter the full tracker by Ollyo