Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-73320XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint | Evidence Sep 8, 2026Published Sep 8, 2026 | 5.1ModerateMedium | 0.3%Low | — | XenForoXenForo | 1 |
| Sep 8, 2026 |
| CVE-2026-73310XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri Bypass | Evidence Sep 8, 2026Published Sep 8, 2026 | 8.2HighHigh | 0.4%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73319XenForo < 2.3.13 XSS via Dynamic Redirect Handler | Evidence Sep 8, 2026Published Sep 8, 2026 | 5.1ModerateMedium | 0.3%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-73309XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint | Evidence Sep 8, 2026Published Sep 8, 2026 | 9.1HighCritical | 0.5%Low | — | XenForoXenForo | 1 | Sep 8, 2026 |
|---|
| CVE-2026-52307An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute... | Evidence Sep 8, 2026Published Sep 8, 2026 | 5.4ModerateMedium | 0.3%Low | — | n/an/a | 1 | Sep 8, 2026 |
|---|
| CVE-2026-78837A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted... | Evidence Sep 8, 2026Published Sep 8, 2026 | 7.5HighHigh | 0.3%Low | — | n/an/a | 1 | Sep 8, 2026 |
|---|
| CVE-2026-0001Mali GPU Kernel Driver allows access to already freed memory | Evidence Sep 8, 2026Published Sep 8, 2026 | 4.4ModerateMedium | 0.2%Low | — | Arm LtdBifrost GPU Kernel Driver, Valhall GPU Kernel Driver, Arm 5th Gen GPU Architecture Kernel Driver | 1 | Sep 8, 2026 |
|---|
| CVE-2026-78838A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary... | Evidence Sep 8, 2026Published Sep 8, 2026 | 6.5ModerateMedium | 0.4%Low | — | n/an/a | 1 | Sep 8, 2026 |
|---|
| CVE-2026-52774Reflected XSS via Unescaped id Parameter in Bazar Widget HTML Attributes in YesWiki | Evidence Sep 8, 2026Published Sep 4, 2026 | 6.1ModerateMedium | 0.5%Low | — | YesWikiyeswiki | 1 | Sep 8, 2026 |
|---|
| CVE-2022-4140Welcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access | Evidence Sep 8, 2026Published Jan 2, 2023 | 7.5HighHigh | 2.9%Low | — | UnknownWelcart e-Commerce | 1 | Sep 8, 2026 |
|---|
| CVE-2026-72744Nuxt before 4.5.1 Information Disclosure via Chrome DevTools | Evidence Sep 8, 2026Published Aug 11, 2026 | 6.9ModerateMedium | 0.1%Low | — | nuxtnuxt | 1 | Sep 8, 2026 |
|---|
| CVE-2026-8069PredatorSense V3: Local Privilege Escalation (LPE) vulnerability | Evidence Sep 8, 2026Published May 8, 2026 | 8.5HighHigh | 0.1%Low | — | AcerPredatorSense V3 | 1 | Sep 8, 2026 |
|---|
| CVE-2026-57811WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability | Evidence Sep 8, 2026Published Jul 13, 2026 | 10.0HighCritical | 0.6%Low | — | RealtynaRealtyna Organic IDX plugin | 1 | Sep 8, 2026 |
|---|
| CVE-2026-75650Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) | Evidence Sep 8, 2026Published Sep 7, 2026 | 10.0HighCritical | 2.1%Low | KEV | AdobeAdobe Commerce, Adobe Commerce B2B, Magento Open Source | 3 | Sep 8, 2026 |
|---|
| CVE-2025-47981SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | Evidence Sep 8, 2026Published Jul 8, 2025 | 9.8HighCritical | 32.6%Moderate | — | MicrosoftWindows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | 1 | Sep 8, 2026 |
|---|
| CVE-2023-52356Libtiff: segment fault in libtiff in tiffreadrgbatileext() leading to denial of service | Evidence Sep 7, 2026Published Jan 25, 2024 | 7.5HighHigh | 2.2%Low | — | Red HatRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.3, Red Hat Discovery 2, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 | 1 | Sep 7, 2026 |
|---|
| CVE-2026-77262MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of CVE-2026-27825) | Evidence Sep 7, 2026Published Sep 22, 2026 | 8.6HighHigh | —Not available | — | soopersetmcp-atlassian | 1 | Sep 7, 2026 |
|---|
| CVE-2026-11991Automated exploit for CVE-2026-11991, an authorization bypass in FlowForms WordPress plugin allowing Contributor+ users to publish any draft form via... | Evidence Sep 7, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 14, 2026 |
|---|
| CVE-2026-86043Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix CVE-2026-50197) | Evidence Sep 7, 2026Published Sep 16, 2026 | 7.5HighHigh | 0.5%Low | — | zalandoskipper | 1 | Sep 7, 2026 |
|---|
| CVE-2026-19843389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor | Evidence Sep 7, 2026Published Sep 7, 2026 | 8.4HighHigh | 0.5%Low | — | Red HatRed Hat Directory Server 11.7 E4S for RHEL 8, Red Hat Directory Server 11.9 for RHEL 8, Red Hat Directory Server 12.2 E4S for RHEL 9, Red Hat Directory Server 12.4 E4S for RHEL 9, Red Hat Directory Server 12.6 EUS for RHEL 9, Red Hat Directory Server 12.8 for RHEL 9, Red Hat Directory Server 13.0 EUS for RHEL 10, Red Hat Directory Server 13.2 for RHEL 10, Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 | 1 | Sep 7, 2026 |
|---|
| CVE-2026-47172Quest Bot: Untrusted pull request code can be built and deployed by privileged workflow_run deployment. | Evidence Sep 7, 2026Published Jun 11, 2026 | 9.5HighCritical | 0.3%Low | — | duck-organizationquest-bot | 1 | Sep 7, 2026 |
|---|
| CVE-2026-33234AutoGPT: SendEmailBlock's IP blocklist bypass allows SSRF via user-controlled SMTP server | Evidence Sep 7, 2026Published May 19, 2026 | 5.0ModerateMedium | 0.3%Low | — | Significant-GravitasAutoGPT | 1 | Sep 7, 2026 |
|---|
| CVE-2026-28576In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no... | Evidence Sep 7, 2026Published Jun 17, 2026 | 10.0HighCritical | 0.1%Low | — | AndroidAndroid | 2 | Sep 7, 2026 |
|---|
| CVE-2026-71981Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | Evidence Sep 7, 2026Published Sep 1, 2026 | 8.7HighHigh | 0.6%Low | — | cypht-orgcypht | 1 | Sep 7, 2026 |
|---|
| CVE-2026-86218pre-authentication remote code execution | Evidence Sep 7, 2026Published Sep 6, 2026 | 10.0HighCritical | 7.5%Low | KEV | N-ableN-central | 3 | Sep 8, 2026 |
|---|
| CVE-2026-13184RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX | Evidence Sep 7, 2026Published Jul 22, 2026 | 7.5HighHigh | 0.2%Low | — | Progress SoftwareTelerik UI for ASP.NET AJAX | 1 | Sep 7, 2026 |
|---|
| CVE-2026-13183RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX | Evidence Sep 7, 2026Published Jul 22, 2026 | 7.5HighHigh | 0.3%Low | — | Progress SoftwareTelerik UI for ASP.NET AJAX | 1 | Sep 7, 2026 |
|---|
| CVE-2026-13182RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX | Evidence Sep 7, 2026Published Jul 22, 2026 | 7.5HighHigh | 0.3%Low | — | Progress SoftwareTelerik UI for ASP.NET AJAX | 1 | Sep 7, 2026 |
|---|
| CVE-2026-13181RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX | Evidence Sep 7, 2026Published Jul 22, 2026 | 8.1HighHigh | 0.5%Low | — | Progress SoftwareTelerik UI for ASP.NET AJAX | 2 | Sep 7, 2026 |
|---|
| CVE-2026-81780WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability | Evidence Sep 7, 2026Published Aug 31, 2026 | 10.0HighCritical | 0.3%Low | — | hashthemesHash Form | 1 | Sep 7, 2026 |
|---|
| CVE-2026-45131CloudPirates Open Source Helm Charts: GitHub Actions pull_request_target workflow allows secret exfiltration via fork pull requests | Evidence Sep 7, 2026Published Jun 1, 2026 | 10.0HighCritical | 0.3%Low | — | CloudPirates-iohelm-charts | 1 | Sep 7, 2026 |
|---|
| CVE-2026-42031CKAN: Unauthenticated SQL Injection and Authorization Bypass in datastore_search_sql | Evidence Sep 7, 2026Published May 13, 2026 | 8.3HighHigh | 1.8%Low | — | ckanckan | 1 | Sep 7, 2026 |
|---|
| CVE-2026-52924sctp: purge outqueue on stale COOKIE-ECHO handling | Evidence Sep 7, 2026Published Jun 24, 2026 | 9.8HighCritical | 0.4%Low | — | LinuxLinux | 1 | Sep 7, 2026 |
|---|
| CVE-2026-44246nnU-Net: Agentic workflow injection in .github/workflows/issue-triage.yml of MIC-DKFZ/nnUNet | Evidence Sep 7, 2026Published May 12, 2026 | 7.2HighHigh | 0.2%Low | — | MIC-DKFZnnUNet | 2 | Sep 7, 2026 |
|---|
| CVE-2026-42298Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev | Evidence Sep 7, 2026Published May 8, 2026 | 10.0HighCritical | 0.5%Low | — | gitroomhqpostiz-app | 1 | Sep 7, 2026 |
|---|
| CVE-2026-41249CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure pull_request_target Configuration | Evidence Sep 7, 2026Published Jun 4, 2026 | 8.2HighHigh | 0.4%Low | — | coreshopCoreShop | 1 | Sep 7, 2026 |
|---|
| CVE-2026-41414Skim: Arbitrary code execution via pull_request_target fork checkout in pr.yml | Evidence Sep 7, 2026Published Apr 24, 2026 | 7.4HighHigh | 0.3%Low | — | skim-rsskim | 1 | Sep 7, 2026 |
|---|
| CVE-2026-42559RMCP: DNS rebinding vulnerability in rmcp Streamable HTTP server transport | Evidence Sep 7, 2026Published May 14, 2026 | 8.8HighHigh | 0.2%Low | — | modelcontextprotocolrust-sdk | 1 | Sep 7, 2026 |
|---|
| CVE-2026-78850Proof-of-concept demonstrating an authenticated blind SSRF in Matomo's SiteContentDetector, allowing internal network reconnaissance and requests to... | Evidence Sep 6, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 13, 2026 |
|---|
| CVE-2026-19949All-in-One WP Migration and Backup <= 7.109 - Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution | Evidence Sep 6, 2026Published Aug 25, 2026 | 8.8HighHigh | 0.5%Low | — | servmaskAll-in-One WP Migration and Backup | 3 | Sep 6, 2026 |
|---|
| CVE-2026-67276SSH user impersonation possible in Mikrotik RouterOS | Evidence Sep 6, 2026Published Sep 5, 2026 | 9.2HighCritical | 0.2%Low | — | MikrotikRouterOS | 4 | Sep 6, 2026 |
|---|
| CVE-2026-78851Technical advisory detailing an authenticated path traversal vulnerability in Grav CMS's Twig media_directory() function, enabling arbitrary directory... | Evidence Sep 6, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 13, 2026 |
|---|
| CVE-2026-64705A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7,... | Evidence Sep 6, 2026Published Aug 25, 2026 | 5.5ModerateMedium | 0.1%Low | — | AppleiOS and iPadOS, macOS | 1 | Sep 6, 2026 |
|---|
| CVE-2026-78938Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.... | Evidence Sep 6, 2026Published Aug 25, 2026 | 8.8HighHigh | 0.4%Low | — | GoogleChrome | 1 | Sep 6, 2026 |
|---|
| CVE-2026-28956A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma... | Evidence Sep 6, 2026Published May 11, 2026 | 6.5ModerateMedium | 0.5%Low | — | AppleiOS and iPadOS, macOS, tvOS, visionOS, watchOS | 1 | Sep 6, 2026 |
|---|
| CVE-2021-3030Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in... | Evidence Sep 6, 2026Published Sep 17, 2026 | 6.1ModerateMedium | 0.3%Low | — | n/an/a | 1 | Sep 6, 2026 |
|---|
| CVE-2026-84645In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files... | Evidence Sep 5, 2026Published Sep 2, 2026 | 8.8HighHigh | 0.7%Low | — | Jenkins ProjectJenkins | 1 | Sep 5, 2026 |
|---|
| CVE-2026-3326XStore < 9.7.3 - Unauthenticated SQLi | Evidence Sep 5, 2026Published Jun 10, 2026 | 8.6HighHigh | 1.9%Low | — | UnknownXstore | 1 | Sep 5, 2026 |
|---|
| CVE-2026-7873Code Injection Vulnerability in Code Validation Endpoint | Evidence Sep 5, 2026Published Jun 30, 2026 | 9.9HighCritical | 0.5%Low | — | IBMLangflow OSS | 1 | Sep 5, 2026 |
|---|
| CVE-2026-39382dbt has a Command Injection in Reusable Workflow via Unsanitized comment-body Output | Evidence Sep 5, 2026Published Apr 7, 2026 | 9.3HighCritical | 0.4%Low | — | dbt-labsdbt-core | 1 | Sep 5, 2026 |
|---|