Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-86999PoC — path traversal via malicious device sync in the Supernote Obsidian plugin (GHSA-3gx3-r874-5pp4, CVE-2026-86999, CVSS 5.6). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— |
| 1 |
| Sep 10, 2026 |
| CVE-2026-86998PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87001PoC — path traversal via unsanitized LLM-derived domain field in OpenLore (GHSA-5j8x-q7q6-58j5, CVE-2026-87001, CVSS 4.7). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87002PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87005PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87009PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87003PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87000PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87007PoC — SSRF via JS-rendering tier bypass of the URL safety filter in crw (GHSA-5jp3-339h-vxqw, CVE-2026-87007, CVSS 7.5). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87004PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc-6vc7-xrfh, CVE-2026-87004, CVSS 8.1). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-87008PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1). | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 10, 2026 |
|---|
| CVE-2026-86060SSH session privilege manipulation via a crafted username in Mikrotik RouterOS | Evidence Sep 10, 2026Published Sep 5, 2026 | 9.2HighCritical | 1.1%Low | KEV | MikrotikRouterOS | 2 | Sep 16, 2026 |
|---|
| CVE-2026-0303Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File | Evidence Sep 10, 2026Published Sep 10, 2026 | 2.4LowLow | 0.1%Low | — | Palo Alto NetworksCheckov by Prisma Cloud | 1 | Sep 10, 2026 |
|---|
| CVE-2026-27604FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions | Evidence Sep 10, 2026Published Jun 23, 2026 | 10.0HighCritical | 0.5%Low | — | FOSSBillingFOSSBilling | 1 | Sep 10, 2026 |
|---|
| CVE-2026-42613Grav: Privilege Escalation via Missing Server-Side Validation of groups/access | Evidence Sep 10, 2026Published May 11, 2026 | 9.4HighCritical | 0.9%Low | — | getgravgrav | 1 | Sep 10, 2026 |
|---|
| CVE-2019-18394A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP... | Evidence Sep 10, 2026Published Oct 24, 2019 | 9.8HighCritical | 32.3%Moderate | — | n/an/a | 1 | Sep 10, 2026 |
|---|
| CVE-2026-77578Python proof-of-concept exploiting CVE-2026-77578, an authenticated path traversal in Xibo CMS that reads arbitrary local files via crafted XML template... | Evidence Sep 10, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 17, 2026 |
|---|
| CVE-2026-72815go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header | Evidence Sep 10, 2026Published Aug 14, 2026 | 6.9ModerateMedium | 0.4%Low | — | go-chichi | 1 | Sep 10, 2026 |
|---|
| CVE-2026-76578Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci | Evidence Sep 10, 2026Published Sep 7, 2026 | 9.8HighCritical | 0.5%Low | — | Red HatRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 | 1 | Sep 10, 2026 |
|---|
| CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn | Evidence Sep 10, 2026Published Sep 7, 2026 | 7.5HighHigh | 0.4%Low | — | Red HatRed Hat Directory Server 11.7 E4S for RHEL 8, Red Hat Directory Server 11.9 for RHEL 8, Red Hat Directory Server 12.2 E4S for RHEL 9, Red Hat Directory Server 12.4 E4S for RHEL 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 6 | 1 | Sep 10, 2026 |
|---|
| CVE-2026-79387SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including... | Evidence Sep 9, 2026Published Sep 9, 2026 | 4.3ModerateMedium | 0.2%Low | — | n/an/a | 1 | Sep 9, 2026 |
|---|
| CVE-2026-51376An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache | Evidence Sep 9, 2026Published Aug 28, 2026 | 6.5ModerateMedium | 0.3%Low | — | n/an/a | 1 | Sep 9, 2026 |
|---|
| CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | Evidence Sep 9, 2026Published Sep 9, 2026 | 9.9HighCritical | 1.0%Low | — | WebProscPanel | 3 | Sep 9, 2026 |
|---|
| CVE-2021-32675DoS vulnerability in Redis | Evidence Sep 9, 2026Published Oct 4, 2021 | 7.5HighHigh | 16.9%Moderate | — | redisredis | 1 | Sep 9, 2026 |
|---|
| CVE-2026-74586sctp: clear new_transport when removing a peer | Evidence Sep 9, 2026Published Aug 22, 2026 | 9.8HighCritical | 0.5%Low | — | LinuxLinux | 1 | Sep 9, 2026 |
|---|
| CVE-2026-79303kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and... | Evidence Sep 9, 2026Published Sep 15, 2026 | 9.9HighCritical | 0.2%Low | — | n/an/a | 1 | Sep 9, 2026 |
|---|
| CVE-2026-62201OpenClaw < 2026.6.6 Network Policy Bypass via exec-server | Evidence Sep 9, 2026Published Jul 17, 2026 | 4.9ModerateMedium | 0.4%Low | — | OpenClawOpenClaw | 1 | Sep 9, 2026 |
|---|
| CVE-2026-49881In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local... | Evidence Sep 9, 2026Published Sep 8, 2026 | 7.8HighHigh | 0.1%Low | — | GoogleAndroid | 2 | Sep 9, 2026 |
|---|
| CVE-2026-72243selinux: check connect-related permissions on TCP Fast Open | Evidence Sep 9, 2026Published Aug 15, 2026 | 8.4HighHigh | 0.2%Low | — | LinuxLinux | 1 | Sep 9, 2026 |
|---|
| CVE-2026-83991Windows Cloud Files Mini Filter Driver Tampering Vulnerability | Evidence Sep 9, 2026Published Sep 8, 2026 | 5.5ModerateMedium | 0.3%Low | — | MicrosoftWindows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | 2 | Sep 9, 2026 |
|---|
| CVE-2026-30225OliveTin: RestartAction always runs actions as guest | Evidence Sep 9, 2026Published Mar 6, 2026 | 5.3ModerateMedium | 0.4%Low | — | OliveTinOliveTin | 1 | Sep 9, 2026 |
|---|
| CVE-2026-59313Server Sent Event stream corruption in Spring MVC functional web framework | Evidence Sep 9, 2026Published Aug 27, 2026 | 9.8HighCritical | 0.4%Low | — | SpringSpring Framework | 1 | Sep 9, 2026 |
|---|
| CVE-2026-55634Pimcore: Remote Code Execution via DataObject Class-Definition Field Name | Evidence Sep 9, 2026Published Aug 28, 2026 | 9.9HighCritical | 0.4%Low | — | pimcorepimcore | 1 | Sep 9, 2026 |
|---|
| CVE-2026-19089Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload | Evidence Sep 9, 2026Published Aug 10, 2026 | 9.8HighCritical | 0.5%Low | — | UnknownProduct Input Fields for WooCommerce | 1 | Sep 9, 2026 |
|---|
| CVE-2026-87491Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML... | Evidence Sep 9, 2026Published Sep 9, 2026 | 8.8HighHigh | 1.0%Low | KEV | GoogleChrome | 1 | Sep 13, 2026 |
|---|
| CVE-2022-2869libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who... | Evidence Sep 8, 2026Published Aug 17, 2022 | 5.5ModerateMedium | 0.3%Low | — | n/alibtiff | 1 | Sep 8, 2026 |
|---|
| CVE-2026-29782OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2 | Evidence Sep 8, 2026Published Apr 2, 2026 | 7.2HighHigh | 0.6%Low | — | devcode-itopenstamanager | 1 | Sep 8, 2026 |
|---|
| CVE-2026-69451Windows Management Instrumentation Elevation of Privilege Vulnerability | Evidence Sep 8, 2026Published Sep 8, 2026 | 7.1HighHigh | 0.7%Low | — | MicrosoftWindows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | 1 | Sep 8, 2026 |
|---|
| CVE-2026-84118Use-after-free in the JavaScript: GC component | Evidence Sep 8, 2026Published Sep 1, 2026 | 5.4ModerateMedium | 0.2%Low | — | MozillaFirefox, Thunderbird | 1 | Sep 8, 2026 |
|---|
| CVE-2026-77276CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online | Evidence Sep 8, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73318XenForo < 2.3.13 Missing Authorization via force-agreement Controller | Evidence Sep 8, 2026Published Sep 8, 2026 | 5.1ModerateMedium | 0.3%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73317XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher | Evidence Sep 8, 2026Published Sep 8, 2026 | 5.1ModerateMedium | 0.3%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73316XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider | Evidence Sep 8, 2026Published Sep 8, 2026 | 8.7HighHigh | 0.2%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73315XenForo < 2.3.13 SSRF via PayPal REST Webhook Handler | Evidence Sep 8, 2026Published Sep 8, 2026 | 7.7HighHigh | 0.3%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73314XenForo < 2.3.13 Signature Verification Bypass via PayPal REST Webhook | Evidence Sep 8, 2026Published Sep 8, 2026 | 8.7HighHigh | 0.5%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73313XenForo < 2.3.13 MFA Bypass via Passkey TFA Provider | Evidence Sep 8, 2026Published Sep 8, 2026 | 7.6HighHigh | 0.4%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-74239XenForo < 2.3.13 Path Traversal via Style Archive Importer on Windows | Evidence Sep 8, 2026Published Sep 8, 2026 | 8.6HighHigh | 0.7%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73312XenForo < 2.3.13 Refresh Token Replay via Expired Access Token | Evidence Sep 8, 2026Published Sep 8, 2026 | 9.1HighCritical | 0.4%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73321XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode Parser | Evidence Sep 8, 2026Published Sep 8, 2026 | 7.1HighHigh | 0.4%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73311XenForo < 2.3.13 OAuth2 Authorization Code Reuse | Evidence Sep 8, 2026Published Sep 8, 2026 | 9.1HighCritical | 0.4%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|