Vulner_ability — Real-Time CVE Intelligence Feed

A live, enriched CVE feed: CVSS and EPSS scores, CISA KEV status, public exploits and PoCs, nuclei templates and affected products — prioritized by real-world exploitation signals.

Top prioritized CVEs. Data as of .

  • CVE-2026-82592D-Link DIR-825M, published — CVSS 9.9, EPSS 0.8%, public PoC: A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition…
  • CVE-2026-18577N-able N-central, published — EPSS 1.5%, CISA KEV: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
  • CVE-2026-66012siyuan-note siyuan, published — CVSS 10, EPSS 0.4%, public PoC: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This…
  • CVE-2026-56413StoneFly Storage Concentrator, published — CVSS 10, EPSS 3.1%: Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An…
  • CVE-2026-56415Stonefly Storage Concentrator, published — CVSS 10, EPSS 3.1%: Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a…
  • CVE-2026-65321laughingman7743 PyAthena, published — CVSS 9.8, EPSS 0.4%, public PoC: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes…
  • CVE-2026-15511Comfast CF-WR631AX V3, published — CVSS 9.8, EPSS 2.7%: A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This…
  • CVE-2026-62292strukturag libheif, published — EPSS 0.5%, public PoC: libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised…
  • CVE-2026-82971QVidium Opera11, published — CVSS 10, EPSS 1.9%: A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command…
  • CVE-2026-18684GL.iNet GL-MT3000, published — CVSS 9.8, EPSS 2.0%: A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is…
  • CVE-2026-83524RedPort Optimizer wXa-203, published — CVSS 9.9, EPSS 1.7%: A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component…
  • CVE-2026-86060Mikrotik RouterOS, published — EPSS 0.4%, public PoC: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation…
  • CVE-2026-67277Mikrotik RouterOS, published — EPSS 0.4%, public PoC: RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the…
  • CVE-2026-67281Mikrotik RouterOS, published — EPSS 0.5%, public PoC: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated…
  • CVE-2026-56700Grav, published — CVSS 9.8, EPSS 1.7%: Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without…

Each CVE links to a full public page. Bulk/API access via the MCP server (Purple tier).

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats