Vulner_ability — Real-Time CVE Intelligence Feed
A live, enriched CVE feed: CVSS and EPSS scores, CISA KEV status, public exploits and PoCs, nuclei templates and affected products — prioritized by real-world exploitation signals.
Top prioritized CVEs. Data as of .
- CVE-2026-82592 — D-Link DIR-825M, published — CVSS 9.9, EPSS 0.8%, public PoC: A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition…
- CVE-2026-18577 — N-able N-central, published — EPSS 1.5%, CISA KEV: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
- CVE-2026-66012 — siyuan-note siyuan, published — CVSS 10, EPSS 0.4%, public PoC: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This…
- CVE-2026-56413 — StoneFly Storage Concentrator, published — CVSS 10, EPSS 3.1%: Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An…
- CVE-2026-56415 — Stonefly Storage Concentrator, published — CVSS 10, EPSS 3.1%: Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a…
- CVE-2026-65321 — laughingman7743 PyAthena, published — CVSS 9.8, EPSS 0.4%, public PoC: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes…
- CVE-2026-15511 — Comfast CF-WR631AX V3, published — CVSS 9.8, EPSS 2.7%: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This…
- CVE-2026-62292 — strukturag libheif, published — EPSS 0.5%, public PoC: libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised…
- CVE-2026-82971 — QVidium Opera11, published — CVSS 10, EPSS 1.9%: A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command…
- CVE-2026-18684 — GL.iNet GL-MT3000, published — CVSS 9.8, EPSS 2.0%: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is…
- CVE-2026-83524 — RedPort Optimizer wXa-203, published — CVSS 9.9, EPSS 1.7%: A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component…
- CVE-2026-86060 — Mikrotik RouterOS, published — EPSS 0.4%, public PoC: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation…
- CVE-2026-67277 — Mikrotik RouterOS, published — EPSS 0.4%, public PoC: RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the…
- CVE-2026-67281 — Mikrotik RouterOS, published — EPSS 0.5%, public PoC: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated…
- CVE-2026-56700 — Grav, published — CVSS 9.8, EPSS 1.7%: Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without…
Each CVE links to a full public page. Bulk/API access via the MCP server (Purple tier).
Threadlinqs Intelligence — Real-Time Threat Detection Platform
// threat_feed
$ sort --newest
Showing all threats