Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-49268Apache Shiro: LDAP DN Injection in DefaultLdapRealm | Evidence Sep 15, 2026Published Jun 17, 2026 | 8.8HighHigh | 0.5%Low | — | Apache Software FoundationApache Shiro | 1 |
| Sep 15, 2026 |
| CVE-2026-65013Onlook tRPC Insecure Direct Object Reference via multiple procedures | Evidence Sep 15, 2026Published Jul 22, 2026 | 8.7HighHigh | 0.4%Low | — | onlookrepo | 1 | Sep 15, 2026 |
|---|
| CVE-2026-44351fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass | Evidence Sep 15, 2026Published May 13, 2026 | 9.1HighCritical | 0.2%Low | — | nearformfast-jwt | 1 | Sep 15, 2026 |
|---|
| CVE-2026-12944Incomplete Security Scanner Blocklist Enables Network-Based Code Execution | Evidence Sep 15, 2026Published Sep 14, 2026 | 9.6HighCritical | 0.2%Low | — | IBMLangflow OSS | 2 | Sep 15, 2026 |
|---|
| CVE-2026-17633Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling | Evidence Sep 15, 2026Published Aug 5, 2026 | 8.8HighHigh | 0.4%Low | — | IBMLangflow OSS | 1 | Sep 15, 2026 |
|---|
| CVE-2026-17632Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling | Evidence Sep 15, 2026Published Aug 5, 2026 | 8.8HighHigh | 0.7%Low | — | IBMLangflow OSS | 1 | Sep 15, 2026 |
|---|
| CVE-2026-82090Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native... | Evidence Sep 15, 2026Published Aug 28, 2026 | 9.2HighCritical | 0.3%Low | — | getpocketPocket | 1 | Sep 15, 2026 |
|---|
| CVE-2026-59550WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability | Evidence Sep 15, 2026Published Jul 27, 2026 | 9.3HighCritical | 0.2%Low | — | Strategy11 TeamAWP Classifieds | 1 | Sep 15, 2026 |
|---|
| CVE-2026-79551Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. | Evidence Sep 15, 2026Published Sep 15, 2026 | —Not availableNot available | 0.3%Low | — | n/an/a | 1 | Sep 15, 2026 |
|---|
| CVE-2022-41404An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via... | Evidence Sep 15, 2026Published Oct 11, 2022 | 7.5HighHigh | 1.4%Low | — | n/an/a | 1 | Sep 15, 2026 |
|---|
| CVE-2026-24733Apache Tomcat: Security constraint bypass with HTTP/0.9 | Evidence Sep 15, 2026Published Feb 17, 2026 | 6.5ModerateMedium | 0.5%Low | — | Apache Software FoundationApache Tomcat | 1 | Sep 15, 2026 |
|---|
| CVE-2026-25057Zip Slip in MarkUs config upload allowing RCE | Evidence Sep 15, 2026Published Feb 9, 2026 | 9.1HighCritical | 0.5%Low | — | MarkUsProjectMarkus | 1 | Sep 15, 2026 |
|---|
| CVE-2026-43783A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges. | Evidence Sep 15, 2026Published Sep 14, 2026 | 7.8HighHigh | 0.2%Low | — | ApplemacOS | 1 | Sep 15, 2026 |
|---|
| CVE-2026-69328Windows Storage Elevation of Privilege Vulnerability | Evidence Sep 15, 2026Published Sep 8, 2026 | 7.8HighHigh | 0.3%Low | — | MicrosoftWindows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | 1 | Sep 15, 2026 |
|---|
| CVE-2026-88899knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header | Evidence Sep 14, 2026Published Sep 10, 2026 | 9.3HighCritical | 0.4%Low | — | knowns-devknowns | 1 | Sep 14, 2026 |
|---|
| CVE-2026-86259OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | Evidence Sep 14, 2026Published Sep 6, 2026 | 9.0HighCritical | 0.3%Low | — | THU-MAICOpenMAIC | 1 | Sep 14, 2026 |
|---|
| CVE-2026-61797Proof of Concept for CVE-2026-61797, a time-based blind SQL injection in the GLPI PDF plugin, with sqlmap validation and detection guidance. | Evidence Sep 14, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 14, 2026 |
|---|
| CVE-2026-9794Keycloak: keycloak: information disclosure via saml ecp endpoint | Evidence Sep 14, 2026Published May 28, 2026 | 5.3ModerateMedium | 0.3%Low | — | Red HatRed Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.13, Red Hat build of Keycloak 26.6, Red Hat build of Keycloak 26.6.3 | 1 | Sep 14, 2026 |
|---|
| CVE-2025-4030PHPGurukul COVID19 Testing Management System search-report-result.php sql injection | Evidence Sep 14, 2026Published Apr 28, 2025 | 6.9ModerateMedium | 0.5%Low | — | PHPGurukulCOVID19 Testing Management System | 1 | Sep 14, 2026 |
|---|
| CVE-2025-4028PHPGurukul COVID19 Testing Management System profile.php sql injection | Evidence Sep 14, 2026Published Apr 28, 2025 | 6.9ModerateMedium | 0.5%Low | — | PHPGurukulCOVID19 Testing Management System | 1 | Sep 14, 2026 |
|---|
| CVE-2026-90782S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items() | Evidence Sep 14, 2026Published Sep 13, 2026 | 6.0ModerateMedium | 0.3%Low | — | SysterelS2OPC | 1 | Sep 14, 2026 |
|---|
| CVE-2026-87492Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the... | Evidence Sep 14, 2026Published Sep 9, 2026 | 9.6HighCritical | 0.3%Low | — | GoogleChrome | 1 | Sep 14, 2026 |
|---|
| CVE-2026-86283MISP UiBeta Collection View Bypasses Event ACL, Exposing Unauthorized Event Data | Evidence Sep 14, 2026Published Sep 6, 2026 | 7.1HighHigh | 0.2%Low | — | MISPMISP | 1 | Sep 14, 2026 |
|---|
| CVE-2026-76461Cisco Secure Email Gateway SQL Injection Vulnerability | Evidence Sep 14, 2026Published Sep 14, 2026 | 9.8HighCritical | 2.0%Low | KEV | CiscoCisco Secure Email | 3 | Sep 15, 2026 |
|---|
| CVE-2026-42536Apache HTTP Server: mod_xml2enc heap overflow | Evidence Sep 13, 2026Published Jun 8, 2026 | 7.5HighHigh | 1.0%Low | — | Apache Software FoundationApache HTTP Server | 1 | Sep 13, 2026 |
|---|
| CVE-2026-90781alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii_elem_id_parse() | Evidence Sep 13, 2026Published Sep 13, 2026 | 4.8ModerateMedium | 0.2%Low | — | ALSA Projectalsa-lib | 1 | Sep 13, 2026 |
|---|
| CVE-2026-20516In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution... | Evidence Sep 13, 2026Published Sep 7, 2026 | 5.5ModerateMedium | 0.1%Low | — | MediaTek, Inc.MediaTek chipset | 1 | Sep 13, 2026 |
|---|
| CVE-2026-65615JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)English fallback | Evidence Sep 13, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 13, 2026 |
|---|
| CVE-2026-65616Potential privilege escalation to JFrog administrator privileges | Evidence Sep 13, 2026Published Jul 27, 2026 | 8.8HighHigh | 0.2%Low | — | jfrogartifactory | 3 | Sep 13, 2026 |
|---|
| CVE-2026-77770miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator | Evidence Sep 13, 2026Published Sep 10, 2026 | 10.0HighCritical | 0.2%Low | — | UnknownminiOrange 2FA | 1 | Sep 13, 2026 |
|---|
| CVE-2025-14659D-Link DIR-860LB1/DIR-868LB1 DHCP command injection | Evidence Sep 13, 2026Published Dec 14, 2025 | 7.4HighHigh | 3.9%Low | — | D-LinkDIR-860LB1, DIR-868LB1 | 1 | Sep 13, 2026 |
|---|
| CVE-2026-71294Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions | Evidence Sep 13, 2026Published Aug 5, 2026 | 7.6HighHigh | 0.2%Low | — | CotontiCotonti | 1 | Sep 13, 2026 |
|---|
| CVE-2024-2044Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4 | Evidence Sep 13, 2026Published Mar 7, 2024 | 9.9HighCritical | 79.5%High | — | pgadmin.orgpgAdmin 4 | 1 | Sep 13, 2026 |
|---|
| CVE-2026-77771miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | Evidence Sep 12, 2026Published Sep 10, 2026 | 7.5HighHigh | 0.2%Low | — | UnknownminiOrange 2FA | 1 | Sep 12, 2026 |
|---|
| CVE-2026-80099Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret | Evidence Sep 12, 2026Published Sep 9, 2026 | 8.8HighHigh | 0.5%Low | — | NewfoldWP Plugin Web, WP Plugin Crazy Domains, WP Module Data, WP Plugin Hostgator, WP Plugin Bluehost | 1 | Sep 12, 2026 |
|---|
| CVE-2026-78006The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution | Evidence Sep 12, 2026Published Sep 12, 2026 | 9.8HighCritical | 0.8%Low | — | stellarwpThe Events Calendar | 1 | Sep 12, 2026 |
|---|
| CVE-2026-86547mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER | Evidence Sep 12, 2026Published Sep 9, 2026 | 6.9ModerateMedium | 0.1%Low | — | mrubycmrubyc | 1 | Sep 12, 2026 |
|---|
| CVE-2026-85706Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | Evidence Sep 12, 2026Published Sep 12, 2026 | 10.0HighCritical | 14.6%Moderate | KEV | GitLabGitLab | 15 | Sep 14, 2026 |
|---|
| CVE-2026-89013Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php | Evidence Sep 12, 2026Published Sep 11, 2026 | 8.7HighHigh | 0.4%Low | — | DolibarrDolibarr | 1 | Sep 12, 2026 |
|---|
| CVE-2026-89012Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter | Evidence Sep 12, 2026Published Sep 11, 2026 | 7.1HighHigh | 0.3%Low | — | DolibarrDolibarr | 1 | Sep 12, 2026 |
|---|
| CVE-2026-71510Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter | Evidence Sep 12, 2026Published Aug 24, 2026 | 7.1HighHigh | 0.2%Low | — | Dolibarrdolibarr | 1 | Sep 12, 2026 |
|---|
| CVE-2026-65540WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) vulnerability | Evidence Sep 11, 2026Published Jul 23, 2026 | 7.1HighHigh | 0.1%Low | — | Metin SaraçPopup for CF7 with Sweet Alert | 1 | Sep 11, 2026 |
|---|
| CVE-2026-19794WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting | Evidence Sep 11, 2026Published Aug 14, 2026 | 7.2HighHigh | 0.2%Low | — | gamerzWP-Stats | 1 | Sep 11, 2026 |
|---|
| CVE-2026-15253Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title | Evidence Sep 11, 2026Published Aug 19, 2026 | 6.8ModerateMedium | 0.3%Low | — | UnknownEasy Media Replace | 1 | Sep 11, 2026 |
|---|
| CVE-2026-33697CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys | Evidence Sep 11, 2026Published Mar 26, 2026 | 7.5HighHigh | 0.1%Low | — | ultravioletrscocos | 1 | Sep 11, 2026 |
|---|
| CVE-2024-30350Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability | Evidence Sep 11, 2026Published Apr 2, 2024 | 3.3LowLow | 0.5%Low | — | FoxitPDF Reader | 1 | Sep 11, 2026 |
|---|
| CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpoints | Evidence Sep 11, 2026Published Sep 4, 2026 | 8.7HighHigh | 0.2%Low | — | Openpanel-devopenpanel | 1 | Sep 11, 2026 |
|---|
| CVE-2026-15667Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter | Evidence Sep 11, 2026Published Sep 9, 2026 | 7.5HighHigh | 0.6%Low | — | arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | 1 | Sep 11, 2026 |
|---|
| CVE-2026-14962ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id | Evidence Sep 11, 2026Published Sep 9, 2026 | 8.6HighHigh | 0.3%Low | — | UnknownELEX WooCommerce Request a Quote | 1 | Sep 11, 2026 |
|---|
| CVE-2025-38502bpf: Fix oob access in cgroup local storage | Evidence Sep 11, 2026Published Aug 16, 2025 | 7.8HighHigh | 0.2%Low | — | LinuxLinux | 1 | Sep 11, 2026 |
|---|