Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2024-57552CVE-2024-57551, CVE-2024-57552, CVE-2024-57553 advisories by Aman Bahiniya | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
| CVE-2024-57551CVE-2024-57551, CVE-2024-57552, CVE-2024-57553 advisories by Aman Bahiniya |
|---|
| Evidence Sep 4, 2026Published — |
—Not availableNot available |
| —Not available |
| — |
| —— |
| 1 |
| Sep 4, 2026 |
| CVE-2020-6950Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. | Evidence Sep 4, 2026Published Jun 2, 2021 | 6.5ModerateMedium | 10.1%Moderate | — | n/an/a | 1 | Sep 4, 2026 |
|---|
| CVE-2026-19516CVE-2026-19516 CVE Record | Evidence Sep 4, 2026Published Aug 11, 2026 | 9.1HighCritical | 0.2%Low | — | GrafanaGrafana MCP Server, mcp-grafana | 1 | Sep 4, 2026 |
|---|
| CVE-2026-84696Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands | Evidence Sep 4, 2026Published Sep 2, 2026 | 9.3HighCritical | 0.1%Low | — | Phison Electronics CorporationPS3111-S11 Controller Firmware | 1 | Sep 4, 2026 |
|---|
| CVE-2026-82876Phison PS3111-S11 Controller Firmware Signature Verification Bypass | Evidence Sep 4, 2026Published Aug 31, 2026 | 9.3HighCritical | 0.1%Low | — | Phison Electronics CorporationPS3111-S11 Controller Firmware | 1 | Sep 4, 2026 |
|---|
| CVE-2025-34158Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides... | Evidence Sep 4, 2026Published Aug 21, 2025 | 8.5HighHigh | 0.6%Low | — | PlexMedia Server | 1 | Sep 4, 2026 |
|---|
| CVE-2026-10134Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows | Evidence Sep 4, 2026Published Jun 30, 2026 | 10.0HighCritical | 0.6%Low | — | IBMLangflow OSS | 1 | Sep 4, 2026 |
|---|
| CVE-2025-54415dag-factory's CI/CD Workflow Allows for Repository Takeover and Secret Exfiltration | Evidence Sep 4, 2026Published Jul 26, 2025 | 9.1HighCritical | 0.6%Low | — | astronomerdag-factory | 1 | Sep 4, 2026 |
|---|
| CVE-2025-52467pgai secrets exfiltration via pull_request_target | Evidence Sep 4, 2026Published Jun 19, 2025 | 9.1HighCritical | 0.4%Low | — | timescalepgai | 1 | Sep 4, 2026 |
|---|
| CVE-2025-53546Folo allows secrets exfiltration via pull_request_target | Evidence Sep 4, 2026Published Jul 9, 2025 | 9.1HighCritical | 0.3%Low | — | RSSNextFolo | 1 | Sep 4, 2026 |
|---|
| CVE-2025-53104gluestack-ui Command Injection Vulnerability via discussion-to-slack GitHub Action Workflow | Evidence Sep 4, 2026Published Jul 1, 2025 | 9.1HighCritical | 1.2%Low | — | gluestackgluestack-ui | 1 | Sep 4, 2026 |
|---|
| CVE-2025-47928Spotipy repo vulnerable to secrets exfiltration via pull_request_target | Evidence Sep 4, 2026Published May 15, 2025 | 9.1HighCritical | 0.6%Low | — | spotipy-devspotipy | 1 | Sep 4, 2026 |
|---|
| CVE-2026-70648CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-70647CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61602CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61601CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61600CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61587CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61585CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61584CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61583CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61582CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2026-61578CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,... | Evidence Sep 4, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 4, 2026 |
|---|
| CVE-2024-42370Litestar repository vulnerable to Environment Variable injection in docs-preview.yml workflow | Evidence Sep 4, 2026Published Aug 9, 2024 | 8.3HighHigh | 0.7%Low | — | litestar-orglitestar | 1 | Sep 4, 2026 |
|---|
| CVE-2026-56718AJCloud AJY IPC Firmware Path Traversal via jdbhttpd | Evidence Sep 4, 2026Published Aug 30, 2026 | 8.7HighHigh | 0.6%Low | — | AJCloudAJY IPC Firmware | 1 | Sep 4, 2026 |
|---|
| CVE-2026-31787xen/privcmd: fix double free via VMA splitting | Evidence Sep 4, 2026Published Apr 30, 2026 | 7.8HighHigh | 0.2%Low | — | LinuxLinux | 1 | Sep 4, 2026 |
|---|
| CVE-2026-65643Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. | Evidence Sep 3, 2026Published Sep 1, 2026 | 8.7HighHigh | 0.9%Low | — | WebProscPanel | 1 | Sep 3, 2026 |
|---|
| CVE-2026-51585rt26cx21x64.sys exploit (Realtek PCIe GbE/2.5GbE/5GbE family) | Evidence Sep 3, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 3, 2026 |
|---|
| CVE-2026-4813Code injection in the Lutece Core | Evidence Sep 3, 2026Published Sep 1, 2026 | 9.4HighCritical | 0.3%Low | — | LuteceLutece Core | 1 | Sep 3, 2026 |
|---|
| CVE-2026-78071Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 | Evidence Sep 3, 2026Published Aug 28, 2026 | 7.5HighHigh | 0.3%Low | — | digital-peak.comDP Calendar extension for Joomla | 1 | Sep 3, 2026 |
|---|
| CVE-2026-78070Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 | Evidence Sep 3, 2026Published Aug 28, 2026 | 6.9ModerateMedium | 0.3%Low | — | digital-peak.comDP Calendar extension for Joomla | 1 | Sep 3, 2026 |
|---|
| CVE-2025-32958Adept exposed the GITHUB_TOKEN in workflow run artifact | Evidence Sep 3, 2026Published Apr 21, 2025 | 9.8HighCritical | 0.6%Low | — | AdeptLanguageAdept | 1 | Sep 3, 2026 |
|---|
| CVE-2026-40976In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be... | Evidence Sep 3, 2026Published Apr 27, 2026 | 9.1HighCritical | 0.5%Low | — | SpringSpring Boot | 1 | Sep 3, 2026 |
|---|
| CVE-2026-80428ILIAS PHP Object Injection via Shibboleth Logout | Evidence Sep 3, 2026Published Aug 26, 2026 | 9.3HighCritical | 2.3%Low | — | ILIAS-eLearning e.V.ILIAS | 4 | Sep 12, 2026 |
|---|
| CVE-2026-47627NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of... | Evidence Sep 3, 2026Published Aug 18, 2026 | 9.8HighCritical | 0.5%Low | — | NVIDIATriton Inference Server | 1 | Sep 3, 2026 |
|---|
| CVE-2026-0769Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability | Evidence Sep 3, 2026Published Jan 23, 2026 | 9.8HighCritical | 40.7%Moderate | — | LangflowLangflow | 1 | Sep 3, 2026 |
|---|
| CVE-2025-15617Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials | Evidence Sep 3, 2026Published Mar 27, 2026 | 8.3HighHigh | 0.4%Low | — | WazuhWazuh (GitHub Actions) | 1 | Sep 3, 2026 |
|---|
| CVE-2025-10894Nx: nx/devkit: malicious versions of nx and plugins published to npm | Evidence Sep 3, 2026Published Sep 24, 2025 | 9.6HighCritical | 0.6%Low | — | Red HatMulticluster Global Hub, OpenShift Serverless, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2 | 1 | Sep 3, 2026 |
|---|
| CVE-2026-38577Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access. | Evidence Sep 3, 2026Published Aug 31, 2026 | 9.8HighCritical | 0.3%Low | — | n/an/a | 1 | Sep 3, 2026 |
|---|
| CVE-2026-65349An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe... | Evidence Sep 3, 2026Published Aug 17, 2026 | 6.6ModerateMedium | 0.1%Low | — | AppleiOS and iPadOS, macOS, tvOS, visionOS, watchOS | 1 | Sep 3, 2026 |
|---|
| CVE-2026-65343A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27,... | Evidence Sep 3, 2026Published Aug 17, 2026 | 7.5HighHigh | 0.4%Low | — | AppleiOS and iPadOS, macOS, tvOS, visionOS, watchOS | 3 | Sep 3, 2026 |
|---|
| CVE-2026-65330The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27,... | Evidence Sep 3, 2026Published Aug 17, 2026 | 6.5ModerateMedium | 0.3%Low | — | AppleiOS and iPadOS, macOS, tvOS, visionOS, watchOS | 2 | Sep 3, 2026 |
|---|
| CVE-2026-64788The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, watchOS 27.... | Evidence Sep 3, 2026Published Aug 17, 2026 | 5.4ModerateMedium | 0.2%Low | — | AppleiOS and iPadOS, macOS, visionOS, watchOS | 4 | Sep 3, 2026 |
|---|
| CVE-2026-63828apparmor: mediate the implicit connect of TCP fast open sendmsg | Evidence Sep 3, 2026Published Jul 19, 2026 | 8.4HighHigh | 0.2%Low | — | LinuxLinux | 1 | Sep 3, 2026 |
|---|
| CVE-2025-56522Proof-of-concept exploit for CVE-2025-56521 and CVE-2025-56522, demonstrating the vulnerability and providing exploitation details. | Evidence Sep 3, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 3, 2026 |
|---|
| CVE-2026-9335Improper Handling of HDF5 ExternalLinks in keras-team/keras | Evidence Sep 2, 2026Published Aug 2, 2026 | 6.5ModerateMedium | 0.6%Low | — | keras-teamkeras-team/keras | 1 | Sep 2, 2026 |
|---|
| CVE-2026-19490NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 | Evidence Sep 2, 2026Published Aug 19, 2026 | 9.3HighCritical | 5.6%Low | KEV | NetScalerADC, Gateway | 2 | Sep 9, 2026 |
|---|
| CVE-2026-9055Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' | Evidence Sep 2, 2026Published Sep 2, 2026 | 9.8HighCritical | 0.3%Low | — | melogranoBooking for Appointments and Events Calendar – Amelia | 1 | Sep 2, 2026 |
|---|
| CVE-2026-73296Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure | Evidence Sep 2, 2026Published Aug 12, 2026 | 9.4HighCritical | 2.9%Low | — | microsoftUFO | 1 | Sep 2, 2026 |
|---|