Evan
6 credited records · 6 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-67615No exploit | openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invokerapereo foundation · openequella · CWE-184 | High8.7 | — | 0.5% | Sep 22, 2026 |
34Monitor | CVE-2026-94109No exploit | openEQUELLA < 2026.1.0 Authenticated Stored SSTI via FreemarkerPortletRendereropenequella · openequella · CWE-1336 | High8.6 | — | 0.8% | Sep 20, 2026 |
21Monitor | CVE-2026-11984No exploit | Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameterspacetime · ad inserter – ad manager & adsense ads · CWE-862 | Medium5.3 | — | 0.3% | Sep 16, 2026 |
20Monitor | CVE-2026-65053No exploit | Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Namehorde · imp · CWE-79 | Medium5.1 | — | 0.4% | Aug 24, 2026 |
28Monitor | CVE-2026-58451No exploit | Horde IMP < 7.0.1 Path Traversal via Compose.php img srchorde · imp · CWE-22 | High7.1 | — | 0.6% | Jul 1, 2026 |
35Monitor | CVE-2026-25857Proof of concept | Tenda G300-F Command Injection via formSetWanDiagtenda · g300-f firmware · CWE-78 | High8.6 | — | 2.9% | Feb 7, 2026 |
- CVE-2026-6761534Monitor
openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invoker
HighCVSS 8.7No exploitEPSS 1%apereo foundation · openequellaSep 22, 2026
- CVE-2026-9410934Monitor
openEQUELLA < 2026.1.0 Authenticated Stored SSTI via FreemarkerPortletRenderer
HighCVSS 8.6No exploitEPSS 1%openequella · openequellaSep 20, 2026
- CVE-2026-1198421Monitor
Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Footer Code Disclosure via 'ai-debug-code' Parameter
MediumCVSS 5.3No exploitEPSS 0%spacetime · ad inserter – ad manager & adsense adsSep 16, 2026
- CVE-2026-6505320Monitor
Horde IMP before 7.2.0 Stored Cross-Site Scripting via AppleDouble Viewer Part Name
MediumCVSS 5.1No exploitEPSS 0%horde · impAug 24, 2026
- CVE-2026-5845128Monitor
Horde IMP < 7.0.1 Path Traversal via Compose.php img src
HighCVSS 7.1No exploitEPSS 1%horde · impJul 1, 2026
- CVE-2026-2585735Monitor
Tenda G300-F Command Injection via formSetWanDiag
HighCVSS 8.6Proof of conceptEPSS 3%tenda · g300-f firmwareFeb 7, 2026