Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-52832Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container | Evidence Sep 2, 2026Published Sep 2, 2026 | 4.9ModerateMedium | 0.5%Low | — | nuclionuclio | 1 |
| Sep 2, 2026 |
| CVE-2026-51407Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803). | Evidence Sep 2, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 2, 2026 |
|---|
| CVE-2026-51406Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803). | Evidence Sep 2, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 2, 2026 |
|---|
| CVE-2026-51405Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803). | Evidence Sep 2, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 2, 2026 |
|---|
| CVE-2026-51404Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803). | Evidence Sep 2, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 2, 2026 |
|---|
| CVE-2026-51403Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803). | Evidence Sep 2, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 2, 2026 |
|---|
| CVE-2026-51402Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803). | Evidence Sep 2, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 2, 2026 |
|---|
| CVE-2024-47179RSSHub's docker-test-cont.yml workflow is vulnerable to Artifact Poisoning which may lead to a full repository takeover. | Evidence Sep 2, 2026Published Sep 26, 2024 | 8.8HighHigh | 0.7%Low | — | DIYgodRSSHub | 1 | Sep 2, 2026 |
|---|
| CVE-2024-4254Secrets Exfiltration in gradio-app/gradio | Evidence Sep 2, 2026Published Jun 4, 2024 | 7.1HighHigh | 0.5%Low | — | gradio-appgradio-app/gradio | 1 | Sep 2, 2026 |
|---|
| CVE-2026-84361Composer: Perforce source URL permits P4PORT rsh: command execution | Evidence Sep 2, 2026Published Sep 1, 2026 | 7.7HighHigh | 0.4%Low | — | composercomposer | 1 | Sep 2, 2026 |
|---|
| CVE-2024-4253Command Injection in gradio-app/gradio | Evidence Sep 2, 2026Published Jun 4, 2024 | 9.1HighCritical | 1.7%Low | — | gradio-appgradio-app/gradio | 1 | Sep 2, 2026 |
|---|
| CVE-2026-68525Apache Tomcat: Redirect after FORM auth may bypass method specific constraints | Evidence Sep 2, 2026Published Aug 25, 2026 | 9.1HighCritical | 0.6%Low | — | Apache Software FoundationApache Tomcat | 1 | Sep 2, 2026 |
|---|
| CVE-2026-16639Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 | Evidence Sep 2, 2026Published Aug 25, 2026 | 9.8HighCritical | 0.3%Low | — | DrupalInternationalization Single Sign-On | 1 | Sep 2, 2026 |
|---|
| CVE-2026-9586Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB | Evidence Sep 2, 2026Published Jul 17, 2026 | 9.3HighCritical | 11.8%Moderate | KEV | SangomaSwitchvox SMB Edition | 1 | Sep 2, 2026 |
|---|
| CVE-2026-83549Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the... | Evidence Sep 2, 2026Published Sep 1, 2026 | 7.8HighHigh | 8.5%Low | KEV | SonicWallSMA1000 | 1 | Sep 8, 2026 |
|---|
| CVE-2026-83548A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote... | Evidence Sep 2, 2026Published Sep 1, 2026 | 10.0HighCritical | 4.7%Low | KEV | SonicWallSMA1000 | 2 | Sep 3, 2026 |
|---|
| CVE-2026-41456Bludit CMS Reflected XSS via Search Plugin | Evidence Sep 2, 2026Published Apr 21, 2026 | 5.1ModerateMedium | 1.9%Low | — | bluditbludit | 1 | Sep 3, 2026 |
|---|
| CVE-2025-70336A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or... | Evidence Sep 2, 2026Published Jan 28, 2026 | 4.8ModerateMedium | 0.4%Low | — | n/an/a | 2 | Sep 3, 2026 |
|---|
| CVE-2025-68137EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop | Evidence Sep 2, 2026Published Jan 21, 2026 | 8.3HighHigh | 1.1%Low | — | EVeresteverest-core | 1 | Sep 3, 2026 |
|---|
| CVE-2026-75604Next.js: Unauthenticated Remote Code Execution on windows-hosted servers | Evidence Sep 1, 2026Published Sep 1, 2026 | 9.0HighCritical | 2.5%Low | — | vercelnext.js | 4 | Sep 1, 2026 |
|---|
| CVE-2026-13753Certain HP DeskJet All in One – Potential Information Disclosure | Evidence Sep 1, 2026Published Jul 6, 2026 | 7.5HighHigh | 0.5%Low | — | HP IncHP DeskJet 2820 AIO Printer, HP DeskJet 2823 AIO Printer, HP DeskJet 2822 AIO Printer, HP DeskJet 2829 AIO Printer, HP DeskJet 2821 AIO Printer, HP DeskJet 2820 All-in-One Printer, HP DeskJet 2828 AIO Printer, HP DeskJet 2810 Printer, HP DeskJet 2820e AIO Printer, HP DeskJet 2842e All-in-One, HP DeskJet 2821e All-in-One, HP DeskJet 2810e AIO Printer, HP DeskJet 2821e AIO Printer, HP DeskJet 2823e AIO Printer, HP DeskJet 2822e AIO Printer, HP DeskJet 2842e All-in-One Printer, HP DeskJet 2827e All-in-One Printer, HP DeskJet 2825e All-in-One Printer, HP DJ 4227e NA OOVWhite Printer, HP DeskJet 2842e AIO Printer, HP DeskJet 2855e AIO Printer, HP DeskJet 2852e All-in-One Printer, HP DeskJet Ink Advantage 2875 Printer, HP DeskJet Ink Advantage 2874 Printer, HP DeskJet Ink Advantage 2876 Printer, HP DeskJet Ink Advantage 2878 Printer, HP DeskJet Ink Advantage 2875 All-in-One, HP DeskJet Ink Advantage 2879 Printer, HP DeskJet Ink Advantage 2877 Printer, HP DeskJet Ink Advantage Ultra 4925, HP DeskJet Ink Advantage Ultra 4927, HP DeskJet Ink Advantage 4928 All-in-One Printer, HP DeskJet Ink Advantage Ultra 4926, HP DeskJet Ink Advantage Ultra 4977, HP DeskJet Ink Advantage Ultra 4929, HP DeskJet Ink Advantage 4929 All-in-One Printer, HP DeskJet Ink Advantage Ultra 4928, HP DeskJet Ink Advantage 4978 All-in-One Printer, HP DeskJet Ink Advantage Ultra 4975, HP DeskJet Ink Advantage Ultra 4976 | 1 | Sep 1, 2026 |
|---|
| CVE-2026-82221WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability | Evidence Sep 1, 2026Published Aug 31, 2026 | 7.1HighHigh | 0.1%Low | — | MetagaussRegistrationMagic | 1 | Sep 1, 2026 |
|---|
| CVE-2026-51788An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py... | Evidence Sep 1, 2026Published Sep 1, 2026 | 7.5HighHigh | 0.5%Low | — | n/an/a | 1 | Sep 1, 2026 |
|---|
| CVE-2024-39700Remote Code Execution (RCE) vulnerability in jupyterlab extension template update-integration-tests GitHub Action | Evidence Sep 1, 2026Published Jul 16, 2024 | 9.9HighCritical | 1.0%Low | — | jupyterlabextension-template | 1 | Sep 1, 2026 |
|---|
| CVE-2026-75855ArcadeDB before 26.8.1 Path Traversal via create/drop database | Evidence Sep 1, 2026Published Aug 18, 2026 | 8.4HighHigh | 0.4%Low | — | ArcadeDataarcadedb | 1 | Sep 1, 2026 |
|---|
| CVE-2025-11142The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited... | Evidence Sep 1, 2026Published Feb 10, 2026 | 8.8HighHigh | 0.5%Low | — | Axis Communications ABAXIS OS | 1 | Sep 1, 2026 |
|---|
| CVE-2026-36130Proof-of-concept demonstrating a vulnerability that disables Microsoft Defender (MsMpEng.exe) by locking a folder and rebooting, with screenshots showing... | Evidence Sep 1, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 8, 2026 |
|---|
| CVE-2026-31321Proof-of-concept demonstrating methods to disable or bypass Windows Defender by hiding, locking, or protecting its folders, enabling persistence after reboot. | Evidence Sep 1, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 8, 2026 |
|---|
| CVE-2026-27475SPIP < 4.4.9 Insecure Deserialization | Evidence Sep 1, 2026Published Feb 19, 2026 | 9.2HighCritical | 0.8%Low | — | SPIPSPIP | 1 | Sep 1, 2026 |
|---|
| CVE-2026-27474SPIP < 4.4.9 Cross-Site Scripting in Private Area (Incomplete Fix) | Evidence Sep 1, 2026Published Feb 19, 2026 | 4.8ModerateMedium | 0.3%Low | — | SPIPSPIP | 1 | Sep 1, 2026 |
|---|
| CVE-2026-27472SPIP < 4.4.9 Blind Server-Side Request Forgery via Syndicated Sites | Evidence Sep 1, 2026Published Feb 19, 2026 | 5.3ModerateMedium | 0.3%Low | — | SPIPSPIP | 1 | Sep 1, 2026 |
|---|
| CVE-2026-14662PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound | Evidence Sep 1, 2026Published Aug 13, 2026 | 8.8HighHigh | 0.5%Low | — | n/aPostgreSQL | 1 | Sep 1, 2026 |
|---|
| CVE-2026-82592D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow | Evidence Sep 1, 2026Published Aug 30, 2026 | 8.6HighHigh | 0.8%Low | — | D-LinkDIR-825M | 1 | Sep 1, 2026 |
|---|
| CVE-2026-0768Langflow code Code Injection Remote Code Execution Vulnerability | Evidence Sep 1, 2026Published Jan 23, 2026 | 9.8HighCritical | 7.8%Low | — | LangflowLangflow | 2 | Sep 1, 2026 |
|---|
| CVE-2026-19914Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter | Evidence Sep 1, 2026Published Sep 1, 2026 | 7.2HighHigh | 0.5%Low | — | uscnanbuWelcart e-Commerce | 1 | Sep 1, 2026 |
|---|
| CVE-2024-1540Command Injection in gradio-app/gradio via deploy+test-visual.yml workflow | Evidence Sep 1, 2026Published Mar 27, 2024 | 8.2HighHigh | 2.0%Low | — | gradio-appgradio-app/gradio | 1 | Sep 1, 2026 |
|---|
| CVE-2026-82329Potential authentication bypass leading to administrative access in Artifactory | Evidence Sep 1, 2026Published Aug 28, 2026 | 9.8HighCritical | 7.7%Low | KEV | jfrogartifactory | 8 | Sep 2, 2026 |
|---|
| CVE-2026-3843SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution | Evidence Sep 1, 2026Published Mar 10, 2026 | 9.3HighCritical | 0.8%Low | — | Nefteprodukttekhnika LLCBUK TS-G Gas Station Automation System | 1 | Sep 1, 2026 |
|---|
| CVE-2026-12183Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials | Evidence Sep 1, 2026Published Jun 13, 2026 | 9.3HighCritical | 0.4%Low | — | Nefteprodukttekhnika LLCBUK TS-G Gas Station Automation System | 1 | Sep 1, 2026 |
|---|
| CVE-2026-30252Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers... | Evidence Sep 1, 2026Published Apr 2, 2026 | 6.1ModerateMedium | 0.2%Low | — | n/an/a | 1 | Sep 1, 2026 |
|---|
| CVE-2026-30251A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to... | Evidence Sep 1, 2026Published Apr 2, 2026 | 6.1ModerateMedium | 0.2%Low | — | n/an/a | 1 | Sep 1, 2026 |
|---|
| CVE-2023-6572Command Injection in gradio-app/gradio | Evidence Sep 1, 2026Published Dec 14, 2023 | 8.1HighHigh | 1.7%Low | — | gradio-appgradio-app/gradio | 1 | Sep 1, 2026 |
|---|
| CVE-2025-69080WordPress Gecko theme <= 1.9.8 - Local File Inclusion vulnerability | Evidence Sep 1, 2026Published Jan 7, 2026 | 8.1HighHigh | 0.5%Low | — | JanStudioGecko | 1 | Sep 1, 2026 |
|---|
| CVE-2026-25544Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters | Evidence Sep 1, 2026Published Feb 6, 2026 | 9.8HighCritical | 0.8%Low | — | payloadcmspayload | 1 | Sep 2, 2026 |
|---|
| CVE-2025-50455SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The... | Evidence Sep 1, 2026Published Jul 27, 2026 | 9.1HighCritical | 1.0%Low | — | n/an/a | 1 | Sep 2, 2026 |
|---|
| CVE-2026-79483FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated... | Evidence Aug 31, 2026Published Aug 31, 2026 | 5.3ModerateMedium | 0.4%Low | — | n/an/a | 1 | Aug 31, 2026 |
|---|
| CVE-2026-75594Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling | Evidence Aug 31, 2026Published Aug 31, 2026 | 8.2HighHigh | 0.5%Low | — | getkirbykirby | 1 | Aug 31, 2026 |
|---|
| CVE-2023-26493Command Injection in Cocos Engine workflow | Evidence Aug 31, 2026Published Mar 27, 2023 | 8.8HighHigh | 2.9%Low | — | cocoscocos-engine | 1 | Aug 31, 2026 |
|---|
| CVE-2026-62735Windows HTTP.sys Elevation of Privilege Vulnerability | Evidence Aug 31, 2026Published Aug 11, 2026 | 7.8HighHigh | 0.5%Low | — | MicrosoftWindows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | 2 | Aug 31, 2026 |
|---|
| CVE-2026-76569Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | Evidence Aug 31, 2026Published Aug 20, 2026 | 5.3ModerateMedium | 0.3%Low | — | phoca.czPhoca Download extension for Joomla | 1 | Aug 31, 2026 |
|---|