Loading vulnerability catalog
Threat intelligence
Public CVEs with current exploit evidence, risk signals and related defensive or research tooling.
Exploits RSS| CVE and title | Evidence / dates | CVSS | EPSS | KEV | Vendor / product | Exploits | Updated |
|---|---|---|---|---|---|---|---|
| CVE-2026-1769Stored XSS on Xerox CentreWare Web 7.0.6 | Evidence Sep 23, 2026Published Feb 6, 2026 | 5.4ModerateMedium | 0.2%Low | — | XeroxCentreWare | 1 |
| Sep 23, 2026 |
| CVE-2026-67279SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS | Evidence Sep 23, 2026Published Sep 5, 2026 | 6.9ModerateMedium | 0.4%Low | — | MikrotikRouterOS | 1 | Sep 23, 2026 |
|---|
| CVE-2026-90847EFM ipTIME C200E System Setup iux_set.cgi os command injection | Evidence Sep 23, 2026Published Sep 15, 2026 | 8.5HighHigh | 2.2%Low | — | EFMipTIME C200E | 1 | Sep 23, 2026 |
|---|
| CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameter | Evidence Sep 23, 2026Published Mar 24, 2026 | 8.7HighHigh | 3.5%Low | — | ZabbixZabbix | 1 | Sep 23, 2026 |
|---|
| CVE-2026-87902An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme... | Evidence Sep 22, 2026Published Sep 22, 2026 | 8.1HighHigh | —Not available | — | WordPressWordPress | 9 | Sep 22, 2026 |
|---|
| CVE-2026-48519Langflow: Unauthenticated RCE in Shareable Playgrounds | Evidence Sep 22, 2026Published Jun 23, 2026 | 9.6HighCritical | 0.8%Low | — | langflow-ailangflow | 1 | Sep 22, 2026 |
|---|
| CVE-2026-84388A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4... | Evidence Sep 22, 2026Published Sep 22, 2026 | 9.1HighCritical | —Not available | — | FortinetFortiPAM Chrome Extension | 1 | Sep 22, 2026 |
|---|
| CVE-2026-18322Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator | Evidence Sep 22, 2026Published Aug 5, 2026 | 8.8HighHigh | 0.3%Low | — | supsysticcomSmart Popup by Supsystic | 1 | Sep 22, 2026 |
|---|
| CVE-2026-93485WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability | Evidence Sep 22, 2026Published Sep 18, 2026 | 7.1HighHigh | 0.2%Low | — | AutomatticWordPress | 1 | Sep 22, 2026 |
|---|
| CVE-2026-51773This project describes detailed information about the CVE-2026-51772 vulnerability. | Evidence Sep 22, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 22, 2026 |
|---|
| CVE-2026-51772This project describes detailed information about the CVE-2026-51772 vulnerability. | Evidence Sep 22, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 22, 2026 |
|---|
| CVE-2026-68376sctp: fix auth_hmacs array size in struct sctp_cookie | Evidence Sep 22, 2026Published Aug 10, 2026 | 8.1HighHigh | 0.5%Low | — | LinuxLinux | 1 | Sep 22, 2026 |
|---|
| CVE-2026-93674Python proof-of-concept exploit for CVE-2026-93674, an authenticated blind command injection in Langflow, enabling remote shell command execution via... | Evidence Sep 22, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 22, 2026 |
|---|
| CVE-2026-19658Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter | Evidence Sep 22, 2026Published Sep 22, 2026 | 9.8HighCritical | —Not available | — | LiquidWebGive Tributes | 1 | Sep 22, 2026 |
|---|
| CVE-2026-13355Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter | Evidence Sep 22, 2026Published Sep 22, 2026 | 9.8HighCritical | —Not available | — | Meta BoxMeta Box Frontend Submission | 1 | Sep 22, 2026 |
|---|
| CVE-2026-61628nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition | Evidence Sep 22, 2026Published Sep 21, 2026 | 8.1HighHigh | —Not available | — | lucasdillmannnginx-ignition | 1 | Sep 22, 2026 |
|---|
| CVE-2026-93680Proof-of-concept exploit for CVE-2026-93680 demonstrating MCP SSE authentication bypass and data exfiltration via tool invocation. | Evidence Sep 22, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 22, 2026 |
|---|
| CVE-2026-94127BIG-IP APM OAuth vulnerability | Evidence Sep 22, 2026Published Sep 22, 2026 | 9.3HighCritical | —Not available | KEV | F5BIG-IP | 1 | Sep 23, 2026 |
|---|
| CVE-2026-93616Directory Traversal and File upload allows execution of arbitrary script on the Management Server | Evidence Sep 22, 2026Published Sep 22, 2026 | 9.8HighCritical | —Not available | KEV | checkpointQuantum Security Management | 2 | Sep 22, 2026 |
|---|
| CVE-2026-91106HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 9.3HighCritical | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91105HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 8.6HighHigh | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91104HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 9.3HighCritical | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91103HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 5.1ModerateMedium | 0.3%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91102HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 8.4HighHigh | 0.2%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 2 | Sep 21, 2026 |
|---|
| CVE-2026-91101HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 5.1ModerateMedium | 0.3%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91100HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 6.8ModerateMedium | 0.2%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91099HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 5.1ModerateMedium | 0.3%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91098HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 8.6HighHigh | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 1 | Sep 21, 2026 |
|---|
| CVE-2026-91097HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities | Evidence Sep 21, 2026Published Sep 16, 2026 | 7.0HighHigh | 0.7%Low | — | HP Inc.HP Linux Imaging and Printing Software (HPLIP) | 2 | Sep 21, 2026 |
|---|
| CVE-2026-93528NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quote Request Page | Evidence Sep 21, 2026Published Sep 23, 2026 | 3.7LowLow | —Not available | — | UnknownNP Quote Request for WooCommerce | 1 | Sep 21, 2026 |
|---|
| CVE-2026-43786This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may... | Evidence Sep 21, 2026Published Sep 14, 2026 | 7.8HighHigh | 0.2%Low | — | ApplemacOS | 1 | Sep 21, 2026 |
|---|
| CVE-2026-77078multer vulnerable to Denial of Service via crafted multipart field names | Evidence Sep 21, 2026Published Aug 28, 2026 | 7.5HighHigh | 0.3%Low | — | multermulter | 1 | Sep 21, 2026 |
|---|
| CVE-2026-28618In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional... | Evidence Sep 21, 2026Published Sep 8, 2026 | 8.8HighHigh | 0.3%Low | — | GoogleAndroid | 1 | Sep 21, 2026 |
|---|
| CVE-2026-19586Pre-Authentication OS Command Injection in Omada Gateways on OpenVPN Server in Omada Gateways | Evidence Sep 21, 2026Published Aug 20, 2026 | 9.3HighCritical | 5.7%Low | — | TP-Link Systems Inc., TP-Link Systems IncER7212PC v2, ER605 v2, ER7206 v2, ER7406 v1, ER707-M2 v1, ER7412-M2 v1, ER8411 v1, ER706W v1, v1, ER706W-4G v2, ER706WP-4G v1, ER703WP-4G-Outdoor v1, DR3220v-4G v1, DR3650v v1, DR3650v-4G v1, ER603WP-4G-Outdoor v1, DR3150 v1, ER701-5G-Outdoor v1, ER605W v2 | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94128BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where | Evidence Sep 21, 2026Published Sep 21, 2026 | 8.5HighHigh | 0.1%Low | — | BioStarVIVID LED DJ | 1 | Sep 21, 2026 |
|---|
| CVE-2026-84568A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An... | Evidence Sep 21, 2026Published Sep 14, 2026 | 7.8HighHigh | 0.2%Low | — | ApplemacOS | 1 | Sep 21, 2026 |
|---|
| CVE-2025-6327WordPress King Addons for Elementor plugin <= 51.1.36 - Arbitrary File Upload vulnerability | Evidence Sep 21, 2026Published Nov 6, 2025 | 10.0HighCritical | 0.5%Low | — | KingAddons.comKing Addons for Elementor | 1 | Sep 21, 2026 |
|---|
| CVE-2025-6325WordPress King Addons for Elementor plugin <= 51.1.36 - Privilege Escalation vulnerability | Evidence Sep 21, 2026Published Nov 6, 2025 | 9.8HighCritical | 0.4%Low | — | KingAddons.comKing Addons for Elementor | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94097PoC for CVE-2026-94095, a traceroute command injection in Netcore NBR200V2 firmware via ubus JSON-RPC, enabling root RCE for authorized testing. | Evidence Sep 21, 2026Published — | —Not availableNot available | —Not available | — | —— | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94095Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection | Evidence Sep 21, 2026Published Sep 20, 2026 | 8.6HighHigh | 1.7%Low | — | NetcoreNBR200V2 | 1 | Sep 21, 2026 |
|---|
| CVE-2026-94096Netcore NBR200V2 LAN IP Configuration network_tools command injection | Evidence Sep 21, 2026Published Sep 20, 2026 | 8.6HighHigh | 1.7%Low | — | NetcoreNBR200V2 | 1 | Sep 21, 2026 |
|---|
| CVE-2026-90817An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious... | Evidence Sep 21, 2026Published Sep 20, 2026 | 9.8HighCritical | 0.6%Low | — | Vanderbilt UniversityREDCap | 2 | Sep 21, 2026 |
|---|
| CVE-2026-94129BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where | Evidence Sep 21, 2026Published Sep 21, 2026 | 8.5HighHigh | 0.1%Low | — | BioStarVALKYRIE AURORA | 1 | Sep 21, 2026 |
|---|
| CVE-2023-20593An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. | Evidence Sep 21, 2026Published Jul 24, 2023 | 5.5ModerateMedium | 5.2%Low | — | AMDRyzen™ 3000 Series Desktop Processors “Matisse” AM4, AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics “Renoir” AM4, 3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT, Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3, Ryzen™ 5000 Series Mobile processors with Radeon™ Graphics “Lucienne”, Ryzen™ 4000 Series Mobile processors with Radeon™ Graphics “Renoir”, Ryzen™ 7020 Series processors “Mendocino” FT6, 2nd Gen AMD EPYC™ Processors | 1 | Sep 21, 2026 |
|---|
| CVE-2026-88854Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 | Evidence Sep 20, 2026Published Sep 20, 2026 | 9.3HighCritical | 0.3%Low | — | OrdaSoft.comOrdaSoft Joomla Gallery free extension for Joomla, OrdaSoft Joomla Gallery extension for Joomla | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86555Hardcoded Key Vulnerability in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 6.2ModerateMedium | 0.2%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86554Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 4.3ModerateMedium | 0.2%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86553A password reset vulnerability in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 8.8HighHigh | 0.4%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-86552A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP | Evidence Sep 20, 2026Published Sep 20, 2026 | 5.4ModerateMedium | 0.3%Low | — | ZTESmartLife | 1 | Sep 20, 2026 |
|---|
| CVE-2026-28609In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no... | Evidence Sep 20, 2026Published Sep 8, 2026 | 8.8HighHigh | 0.3%Low | — | GoogleAndroid | 1 | Sep 20, 2026 |
|---|