Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-65615JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)English fallback | Evidence Sep 13, 2026Published — | —Not availableNot available | —Not available | — |
| 1 |
| Sep 13, 2026 |
| CVE-2026-65616Potential privilege escalation to JFrog administrator privileges | Evidence Sep 13, 2026Published Jul 27, 2026 | 8.8HighHigh | 0.2%Low | — | jfrogartifactory | 3 | Sep 13, 2026 |
|---|
| CVE-2026-77770miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator | Evidence Sep 13, 2026Published Sep 10, 2026 | 10.0HighCritical | 0.2%Low | — | UnknownminiOrange 2FA | 1 | Sep 13, 2026 |
|---|
| CVE-2025-14659D-Link DIR-860LB1/DIR-868LB1 DHCP command injection | Evidence Sep 13, 2026Published Dec 14, 2025 | 7.4HighHigh | 3.9%Low | — | D-LinkDIR-860LB1, DIR-868LB1 | 1 | Sep 13, 2026 |
|---|
| CVE-2026-71294Cotonti CMS Comments Plugin PHP Object Injection via Unrestricted unserialize() in Create/Edit Actions | Evidence Sep 13, 2026Published Aug 5, 2026 | 7.6HighHigh | 0.2%Low | — | CotontiCotonti | 1 | Sep 13, 2026 |
|---|
| CVE-2024-2044Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4 | Evidence Sep 13, 2026Published Mar 7, 2024 | 9.9HighCritical | 79.5%High | — | pgadmin.orgpgAdmin 4 | 1 | Sep 13, 2026 |
|---|
| CVE-2026-77771miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | Evidence Sep 12, 2026Published Sep 10, 2026 | 7.5HighHigh | 0.2%Low | — | UnknownminiOrange 2FA | 1 | Sep 12, 2026 |
|---|
| CVE-2026-80099Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret | Evidence Sep 12, 2026Published Sep 9, 2026 | 8.8HighHigh | 0.5%Low | — | NewfoldWP Plugin Web, WP Plugin Crazy Domains, WP Module Data, WP Plugin Hostgator, WP Plugin Bluehost | 1 | Sep 12, 2026 |
|---|
| CVE-2026-78006The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution | Evidence Sep 12, 2026Published Sep 12, 2026 | 9.8HighCritical | 0.8%Low | — | stellarwpThe Events Calendar | 1 | Sep 12, 2026 |
|---|
| CVE-2026-86547mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER | Evidence Sep 12, 2026Published Sep 9, 2026 | 6.9ModerateMedium | 0.1%Low | — | mrubycmrubyc | 1 | Sep 12, 2026 |
|---|
| CVE-2026-85706Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | Evidence Sep 12, 2026Published Sep 12, 2026 | 10.0HighCritical | 14.6%Moderate | KEV | GitLabGitLab | 15 | Sep 14, 2026 |
|---|
| CVE-2026-89013Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php | Evidence Sep 12, 2026Published Sep 11, 2026 | 8.7HighHigh | 0.4%Low | — | DolibarrDolibarr | 1 | Sep 12, 2026 |
|---|
| CVE-2026-89012Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter | Evidence Sep 12, 2026Published Sep 11, 2026 | 7.1HighHigh | 0.3%Low | — | DolibarrDolibarr | 1 | Sep 12, 2026 |
|---|
| CVE-2026-71510Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter | Evidence Sep 12, 2026Published Aug 24, 2026 | 7.1HighHigh | 0.2%Low | — | Dolibarrdolibarr | 1 | Sep 12, 2026 |
|---|
| CVE-2026-65540WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) vulnerability | Evidence Sep 11, 2026Published Jul 23, 2026 | 7.1HighHigh | 0.1%Low | — | Metin SaraçPopup for CF7 with Sweet Alert | 1 | Sep 11, 2026 |
|---|
| CVE-2026-19794WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting | Evidence Sep 11, 2026Published Aug 14, 2026 | 7.2HighHigh | 0.2%Low | — | gamerzWP-Stats | 1 | Sep 11, 2026 |
|---|
| CVE-2026-15253Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title | Evidence Sep 11, 2026Published Aug 19, 2026 | 6.8ModerateMedium | 0.3%Low | — | UnknownEasy Media Replace | 1 | Sep 11, 2026 |
|---|
| CVE-2026-33697CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys | Evidence Sep 11, 2026Published Mar 26, 2026 | 7.5HighHigh | 0.1%Low | — | ultravioletrscocos | 1 | Sep 11, 2026 |
|---|
| CVE-2024-30350Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability | Evidence Sep 11, 2026Published Apr 2, 2024 | 3.3LowLow | 0.5%Low | — | FoxitPDF Reader | 1 | Sep 11, 2026 |
|---|
| CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpoints | Evidence Sep 11, 2026Published Sep 4, 2026 | 8.7HighHigh | 0.2%Low | — | Openpanel-devopenpanel | 1 | Sep 11, 2026 |
|---|
| CVE-2026-15667Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter | Evidence Sep 11, 2026Published Sep 9, 2026 | 7.5HighHigh | 0.6%Low | — | arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | 1 | Sep 11, 2026 |
|---|
| CVE-2026-14962ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id | Evidence Sep 11, 2026Published Sep 9, 2026 | 8.6HighHigh | 0.3%Low | — | UnknownELEX WooCommerce Request a Quote | 1 | Sep 11, 2026 |
|---|
| CVE-2025-38502bpf: Fix oob access in cgroup local storage | Evidence Sep 11, 2026Published Aug 16, 2025 | 7.8HighHigh | 0.2%Low | — | LinuxLinux | 1 | Sep 11, 2026 |
|---|
| CVE-2022-34303A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order... | Evidence Sep 11, 2026Published Aug 26, 2022 | 6.7ModerateMedium | 0.8%Low | — | n/an/a | 2 | Sep 11, 2026 |
|---|
| CVE-2022-34302A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections.... | Evidence Sep 11, 2026Published Aug 26, 2022 | 6.7ModerateMedium | 1.1%Low | — | n/an/a | 1 | Sep 11, 2026 |
|---|
| CVE-2022-34301A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot... | Evidence Sep 11, 2026Published Aug 26, 2022 | 6.7ModerateMedium | 1.0%Low | — | n/an/a | 2 | Sep 11, 2026 |
|---|
| CVE-2026-79294Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact... | Evidence Sep 11, 2026Published Sep 18, 2026 | 6.1ModerateMedium | 0.5%Low | — | n/an/a | 1 | Sep 11, 2026 |
|---|
| CVE-2026-25645Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function | Evidence Sep 11, 2026Published Mar 25, 2026 | 5.5ModerateMedium | 0.2%Low | — | psfrequests | 1 | Sep 11, 2026 |
|---|
| CVE-2026-81861CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU... | Evidence Sep 11, 2026Published Sep 11, 2026 | 5.9ModerateMedium | 0.4%Low | — | Schneider ElectricSCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R, SCADAPack 57x, SCADAPack 3xx, SCADAPack 32 | 1 | Sep 11, 2026 |
|---|
| CVE-2026-82583NextGen Healthcare Mirth Connect SQL Injection | Evidence Sep 11, 2026Published Sep 11, 2026 | 7.2HighHigh | 0.5%Low | — | NextGen HealthcareMirth Connect | 1 | Sep 11, 2026 |
|---|
| CVE-2026-82578NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference | Evidence Sep 11, 2026Published Sep 11, 2026 | 8.7HighHigh | 0.4%Low | — | NextGen HealthcareMirth Connect | 1 | Sep 11, 2026 |
|---|
| CVE-2026-78224NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference | Evidence Sep 11, 2026Published Sep 11, 2026 | 8.8HighHigh | 0.4%Low | — | NextGen HealthcareMirth Connect | 1 | Sep 11, 2026 |
|---|
| CVE-2026-88861Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization | Evidence Sep 11, 2026Published Sep 10, 2026 | 8.7HighHigh | 0.3%Low | — | Cap-gocapgo.app | 1 | Sep 11, 2026 |
|---|
| CVE-2026-22732Under Some Conditions Spring Security HTTP Headers Are not Written | Evidence Sep 11, 2026Published Mar 19, 2026 | 9.1HighCritical | 0.5%Low | — | VMwareSpring Security | 1 | Sep 11, 2026 |
|---|
| CVE-2026-79298An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the... | Evidence Sep 11, 2026Published Sep 16, 2026 | 8.4HighHigh | 0.2%Low | — | n/an/a | 2 | Sep 11, 2026 |
|---|
| CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to... | Evidence Sep 11, 2026Published Sep 8, 2026 | 9.3HighCritical | 0.3%Low | — | n/an/a | 1 | Sep 11, 2026 |
|---|
| CVE-2026-22706Strapi: Password Reset Does Not Revoke Existing Refresh Sessions | Evidence Sep 11, 2026Published May 14, 2026 | 2.1LowLow | 0.3%Low | — | strapistrapi, @strapi/admin, @strapi/plugin-users-permissions | 1 | Sep 11, 2026 |
|---|
| CVE-2022-29901Arbitrary Memory Disclosure through CPU Side-Channel Attacks (Retbleed) | Evidence Sep 11, 2026Published Jul 12, 2022 | 6.5ModerateMedium | 4.8%Low | — | IntelIntel Microprocessors | 1 | Sep 11, 2026 |
|---|
| CVE-2022-29900Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. | Evidence Sep 11, 2026Published Jul 12, 2022 | 6.5ModerateMedium | 3.8%Low | — | AMDAMD Processors | 1 | Sep 11, 2026 |
|---|
| CVE-2026-18351Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter | Evidence Sep 11, 2026Published Sep 10, 2026 | 9.8HighCritical | 0.8%Low | — | addonsorgDrag and Drop File Upload for Elementor Forms | 2 | Sep 11, 2026 |
|---|
| CVE-2026-51990An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component | Evidence Sep 11, 2026Published Sep 16, 2026 | 9.8HighCritical | 1.0%Low | — | n/an/a | 1 | Sep 11, 2026 |
|---|
| CVE-2026-42018Anonymous user token generation exposure in JFrog Artifactory | Evidence Sep 11, 2026Published Aug 12, 2026 | 7.5HighHigh | 11.0%Moderate | KEV | jfrogartifactory | 1 | Sep 13, 2026 |
|---|
| CVE-2026-15776Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a... | Evidence Sep 10, 2026Published Jul 14, 2026 | 8.8HighHigh | 0.5%Low | — | GoogleChrome | 1 | Sep 10, 2026 |
|---|
| CVE-2026-36392FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's... | Evidence Sep 10, 2026Published Sep 10, 2026 | 5.4ModerateMedium | 0.2%Low | — | n/an/a | 1 | Sep 10, 2026 |
|---|
| CVE-2026-78804The action responsible for setting the per-warehouse stock alert threshold (seuil_stock_alerte) accepts user-controlled input and later incorporates it into... | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-63643MagicMirror: ssrf calendar .js | Evidence Sep 10, 2026Published Aug 18, 2026 | 6.3ModerateMedium | 0.5%Low | — | MagicMirrorOrgMagicMirror | 1 | Sep 10, 2026 |
|---|
| CVE-2026-63642MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery | Evidence Sep 10, 2026Published Aug 18, 2026 | 6.3ModerateMedium | 0.5%Low | — | MagicMirrorOrgMagicMirror | 1 | Sep 10, 2026 |
|---|
| CVE-2026-85103Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding | Evidence Sep 10, 2026Published Sep 9, 2026 | 9.8HighCritical | 0.4%Low | — | checkpointQuantum Security Gateway, Quantum Security Management | 1 | Sep 10, 2026 |
|---|
| CVE-2026-85102Improper Certificate Validation in Quantum Security Gateway | Evidence Sep 10, 2026Published Sep 9, 2026 | 9.8HighCritical | 0.3%Low | KEV | checkpointQuantum Security Gateway | 1 | Sep 22, 2026 |
|---|
| CVE-2026-87006PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|