Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-91106HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 9.3HighCritical | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 |
| Sep 21, 2026 |
| CVE-2026-91105HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 8.6HighHigh | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91104HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 9.3HighCritical | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91103HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 5.1ModerateMedium | 0.3%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91102HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 8.4HighHigh | 0.2%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91101HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 5.1ModerateMedium | 0.3%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91100HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 6.8ModerateMedium | 0.2%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91099HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 5.1ModerateMedium | 0.3%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91098HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 8.6HighHigh | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91097HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 7.0HighHigh | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-93528Technical analysis, proof of concept, and responsible disclosure timeline for CVE-2026-93528, an unauthenticated order data disclosure in NP Quote Request... | Evidence Sep 21, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 21, 2026 |
|---|
| CVE-2026-43786This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may... | Evidence Sep 21, 2026Published Sep 14, 2026 | 7.8HighHigh | 0.2%Low | — | ApplemacOS | 1 | Sep 21, 2026 |
|---|
| CVE-2026-77078multer vulnerable to Denial of Service via crafted multipart field names | Evidence Sep 21, 2026Published Aug 28, 2026 | 7.5HighHigh | 0.3%Low | — | multermulter | 1 | Sep 21, 2026 |
|---|
| CVE-2026-28618In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional... | Evidence Sep 21, 2026Published Sep 8, 2026 | 8.8HighHigh | 0.3%Low | — | GoogleAndroid | 1 | Sep 21, 2026 |
|---|
| CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | Evidence Sep 21, 2026Published Aug 20, 2026 | 9.3HighCritical | 5.7%Low | — | TP-Link Systems Inc., TP-Link Systems IncER7212PC v2, ER605 v2, ER7206 v2, ER7406 v1, ER707-M2 v1, ER7412-M2 v1, ER8411 v1, ER706W v1, v1, ER706W-4G v2, ER706WP-4G v1, ER703WP-4G-Outdoor v1, DR3220v-4G v1, DR3650v v1, DR3650v-4G v1, ER603WP-4G-Outdoor v1, DR3150 v1, ER701-5G-Outdoor v1, ER605W v2 | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94128BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where | Evidence Sep 21, 2026Published Sep 21, 2026 | 8.5HighHigh | —Not available | — | BioStarVIVID LED DJ | 1 | Sep 21, 2026 |
|---|
| CVE-2026-84568A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An... | Evidence Sep 21, 2026Published Sep 14, 2026 | 7.8HighHigh | 0.2%Low | — | ApplemacOS | 1 | Sep 21, 2026 |
|---|
| CVE-2025-6327WordPress King Addons for Elementor plugin <= 51.1.36 - Arbitrary File Upload vulnerability | Evidence Sep 21, 2026Published Nov 6, 2025 | 10.0HighCritical | 0.5%Low | — | KingAddons.comKing Addons for Elementor | 1 | Sep 21, 2026 |
|---|
| CVE-2025-6325WordPress King Addons for Elementor plugin <= 51.1.36 - Privilege Escalation vulnerability | Evidence Sep 21, 2026Published Nov 6, 2025 | 9.8HighCritical | 0.4%Low | — | KingAddons.comKing Addons for Elementor | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94097PoC for CVE-2026-94095, a traceroute command injection in Netcore NBR200V2 firmware via ubus JSON-RPC, enabling root RCE for authorized testing. | Evidence Sep 21, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94095Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection | Evidence Sep 21, 2026Published Sep 20, 2026 | 8.6HighHigh | —Not available | — | NetcoreNBR200V2 | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94096Netcore NBR200V2 LAN IP Configuration network_tools command injection | Evidence Sep 21, 2026Published Sep 20, 2026 | 8.6HighHigh | —Not available | — | NetcoreNBR200V2 | 1 | Sep 21, 2026 |
|---|
| CVE-2026-90817An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious... | Evidence Sep 21, 2026Published Sep 20, 2026 | 9.8HighCritical | —Not available | — | Vanderbilt UniversityREDCap | 2 | Sep 21, 2026 |
|---|
| CVE-2026-94129BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where | Evidence Sep 21, 2026Published Sep 21, 2026 | 8.5HighHigh | —Not available | — | BioStarVALKYRIE AURORA | 1 | Sep 21, 2026 |
|---|
| CVE-2023-20593An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. | Evidence Sep 21, 2026Published Jul 24, 2023 | 5.5ModerateMedium | 5.2%Low | — | AMDRyzen™ 3000 Series Desktop Processors “Matisse” AM4, AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics “Renoir” AM4, 3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT, Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3, Ryzen™ 5000 Series Mobile processors with Radeon™ Graphics “Lucienne”, Ryzen™ 4000 Series Mobile processors with Radeon™ Graphics “Renoir”, Ryzen™ 7020 Series processors “Mendocino” FT6, 2nd Gen AMD EPYC™ Processors | 1 | Sep 21, 2026 |
|---|
| CVE-2026-88854Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 | Evidence Sep 20, 2026Published Sep 20, 2026 | 9.3HighCritical | —Not available | — | OrdaSoft.comOrdaSoft Joomla Gallery free extension for Joomla, OrdaSoft Joomla Gallery extension for Joomla | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86555Hardcoded Key Vulnerability in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 6.2ModerateMedium | 0.2%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86554Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 4.3ModerateMedium | 0.2%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86553A password reset vulnerability in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 8.8HighHigh | 0.4%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86552A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 5.4ModerateMedium | 0.3%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-28609In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no... | Evidence Sep 20, 2026Published Sep 8, 2026 | 8.8HighHigh | 0.3%Low | — | GoogleAndroid | 1 | Sep 20, 2026 |
|---|
| CVE-2023-43804Cookie HTTP header isn't stripped on cross-origin redirects | Evidence Sep 20, 2026Published Oct 4, 2023 | 8.1HighHigh | 1.2%Low | — | urllib3urllib3 | 1 | Sep 20, 2026 |
|---|
| CVE-2026-78306DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution | Evidence Sep 20, 2026Published Aug 24, 2026 | 8.5HighHigh | 0.1%Low | — | DJINeo, Neo 2, Flip, Air 3, Air 3S, Avata 2, Avata 360, Mavic 3, Mavic 3 Classic, Mavic 3 Pro, Mavic 4 Pro, Mini 2, Mini 3, Mini 3 Pro, Mini 4 Pro, Mini 5 Pro | 1 | Sep 20, 2026 |
|---|
| CVE-2026-71217Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion | Evidence Sep 20, 2026Published Aug 11, 2026 | 7.5HighHigh | 0.6%Low | — | Red HatRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7 | 1 | Sep 20, 2026 |
|---|
| CVE-2026-89274WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content | Evidence Sep 20, 2026Published Sep 19, 2026 | 9.1HighCritical | 0.4%Low | — | brechtvdsWP Recipe Maker | 2 | Sep 20, 2026 |
|---|
| CVE-2026-93958D-Link R95 DHMAPI ssi system os command injection | Evidence Sep 20, 2026Published Sep 20, 2026 | 8.5HighHigh | 2.2%Low | — | D-LinkR95 | 1 | Sep 20, 2026 |
|---|
| CVE-2026-78844Advisory documenting CVE-2026-78844, an uncontrolled resource consumption flaw in delight-nashorn-sandbox 0.5.5 where dynamic code evaluation bypasses... | Evidence Sep 20, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 20, 2026 |
|---|
| CVE-2026-34180Heap Buffer Over-read in ASN.1 Content Parsing | Evidence Sep 20, 2026Published Jun 9, 2026 | 7.5HighHigh | 1.0%Low | — | OpenSSLOpenSSL | 1 | Sep 20, 2026 |
|---|
| CVE-2024-31218Missing Authentication for Critical Function in Webhood backend | Evidence Sep 20, 2026Published Apr 5, 2024 | 9.8HighCritical | 0.7%Low | — | webhood-iowebhood | 1 | Sep 20, 2026 |
|---|
| CVE-2026-92229Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter | Evidence Sep 20, 2026Published Sep 19, 2026 | 9.1HighCritical | 0.4%Low | — | wpmudevForminator Forms – Contact Form, Payment Form & Custom Form Builder | 1 | Sep 20, 2026 |
|---|
| CVE-2026-84434Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field | Evidence Sep 20, 2026Published Sep 19, 2026 | 9.8HighCritical | 0.7%Low | — | Gravity FormsGravity Forms | 1 | Sep 20, 2026 |
|---|
| CVE-2026-81294WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability | Evidence Sep 20, 2026Published Sep 2, 2026 | 9.8HighCritical | 0.3%Low | — | Paul RyanAuthorizer | 1 | Sep 20, 2026 |
|---|
| CVE-2026-81648CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router | Evidence Sep 20, 2026Published Sep 13, 2026 | 10.0HighCritical | 0.3%Low | — | UnknownCryptoPayment Gateway | 1 | Sep 20, 2026 |
|---|
| CVE-2026-79752CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection | Evidence Sep 20, 2026Published Sep 17, 2026 | 9.2HighCritical | 0.5%Low | — | cakephpcakephp | 1 | Sep 20, 2026 |
|---|
| CVE-2026-77635CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver | Evidence Sep 20, 2026Published Aug 24, 2026 | 9.2HighCritical | 0.3%Low | — | cakephpcakephp, cakephp/database | 1 | Sep 20, 2026 |
|---|
| CVE-2026-65647Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | Evidence Sep 19, 2026Published Aug 26, 2026 | 8.7HighHigh | 0.5%Low | — | WebProsPlesk Migrator, Plesk Site Import | 1 | Sep 19, 2026 |
|---|
| CVE-2026-78159The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation | Evidence Sep 19, 2026Published Sep 12, 2026 | 9.8HighCritical | 0.8%Low | — | stellarwpThe Events Calendar | 1 | Sep 19, 2026 |
|---|
| CVE-2026-75816Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier | Evidence Sep 19, 2026Published Sep 6, 2026 | 9.8HighCritical | 0.5%Low | — | shabtiFrontend Admin by DynamiApps | 1 | Sep 19, 2026 |
|---|
| CVE-2026-19952Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag | Evidence Sep 19, 2026Published Sep 1, 2026 | 7.5HighHigh | 0.8%Low | — | shabtiFrontend Admin by DynamiApps | 1 | Sep 19, 2026 |
|---|
| CVE-2026-18937Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection | Evidence Sep 19, 2026Published Aug 19, 2026 | 9.0HighCritical | 0.4%Low | — | UnknownBroken Link Checker | 1 | Sep 19, 2026 |
|---|