offset
51 credited records · 51 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2026-101047No exploit | Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLsfleetdm · fleet · CWE-862 | Medium6.9 | — | 0.2% | 2 days ago |
34Monitor | CVE-2026-100856No exploit | AzuraCast before 0.23.6 Code Injection via Remote Relay Passwordazuracast · azuracast · CWE-94 | High8.7 | — | 0.4% | 3 days ago |
28Monitor | CVE-2026-100855No exploit | AzuraCast before 0.23.6 Missing Permission Check via /playazuracast · azuracast · CWE-862 | High7.1 | — | 0.2% | 3 days ago |
21Monitor | CVE-2026-100854No exploit | AzuraCast before 0.23.6 Metadata Injection via Liquidsoap APIazuracast · azuracast · CWE-862 | Medium5.3 | — | 0.2% | 3 days ago |
25Monitor | CVE-2026-100837No exploit | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matchingedgelesssys · contrast · CWE-1289 | Medium6.3 | — | 0.2% | 3 days ago |
28Monitor | CVE-2026-100629No exploit | Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCHcap-go · capgo.app · CWE-863 | High7.0 | — | 0.3% | 3 days ago |
21Monitor | CVE-2026-100626No exploit | capgo through 12.128.2 IDOR via PUT /app icon endpointcap-go · capgo.app · CWE-639 | Medium5.3 | — | 0.2% | 3 days ago |
40Plan | CVE-2026-92960No exploit | vm2 before 3.11.6 Process-wide State Exposure via os and dnspatriksimek · vm2 · CWE-200 | Critical10.0 | — | 0.5% | Sep 17, 2026 |
21Monitor | CVE-2026-90935No exploit | Froxlor before 2.3.7 Authorization Bypass via Mysqls.add APIfroxlor · froxlor · CWE-285 | Medium5.3 | — | 0.3% | Sep 14, 2026 |
25Monitor | CVE-2026-90535No exploit | Flowise before 3.1.4 Denial of Service via text-to-speech/abortflowiseai · flowise · CWE-862 | Medium6.3 | — | 0.5% | Sep 12, 2026 |
27Monitor | CVE-2026-86252No exploit | h3 before 1.15.9 SSE Event Injection via Carriage Returnh3js · h3 · CWE-74 | Medium6.9 | — | 0.4% | Sep 6, 2026 |
32Monitor | CVE-2026-86251No exploit | h3 before 1.15.9 Path Traversal via Double Decodingh3js · h3 · CWE-22 | High8.2 | — | 0.4% | Sep 6, 2026 |
34Monitor | CVE-2026-86250No exploit | h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookieh3js · h3 · CWE-400 | High8.7 | — | 0.5% | Sep 6, 2026 |
21Monitor | CVE-2026-86205No exploit | h3 before 2.0.1-rc.18 Open Redirect via redirectBack()h3js · h3 · CWE-601 | Medium5.3 | — | 0.3% | Sep 6, 2026 |
35Monitor | CVE-2026-82866No exploit | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetchpdfme · common · CWE-918 | High8.9 | — | 0.3% | Aug 31, 2026 |
8Monitor | CVE-2026-82865No exploit | pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Labelpdfme · schemas · CWE-79 | Low2.1 | — | 0.2% | Aug 31, 2026 |
28Monitor | CVE-2026-82864No exploit | pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bombpdfme · pdf-lib · CWE-409 | High7.1 | — | 0.4% | Aug 31, 2026 |
34Monitor | CVE-2026-79673No exploit | Ech0 before 4.4.3 Scope Bypass via profile:read Tokenlin-snow · ech0 · CWE-863 | High8.5 | — | 0.4% | Aug 25, 2026 |
28Monitor | CVE-2026-79672No exploit | Ech0 before 4.4.3 Authentication Bypass via Comment Panellin-snow · ech0 · CWE-862 | High7.0 | — | 0.3% | Aug 25, 2026 |
20Monitor | CVE-2026-79671No exploit | Ech0 before 4.4.3 SSRF via DNS Resolution Bypasslin-snow · ech0 · CWE-918 | Medium5.1 | — | 0.3% | Aug 25, 2026 |
19Monitor | CVE-2026-79670No exploit | Ech0 before 4.4.3 Stored XSS via SVG Uploadlin-snow · ech0 · CWE-434 | Medium4.8 | — | 0.3% | Aug 25, 2026 |
21Monitor | CVE-2026-79669No exploit | Ech0 before 4.4.3 Missing Authorization on System Logslin-snow · ech0 · CWE-862 | Medium5.3 | — | 0.2% | Aug 25, 2026 |
20Monitor | CVE-2026-8630No exploit | justhtml before 1.12.0 Mutation XSS via Raw Text Elementsemilstenstrom · justhtml · CWE-79 | Medium5.1 | — | 0.3% | Aug 23, 2026 |
34Monitor | CVE-2026-74788No exploit | Scriban before 7.0.0 Denial of Service via string.pad_left/pad_rightscriban · scriban · CWE-770 | High8.7 | — | 0.5% | Aug 16, 2026 |
34Monitor | CVE-2026-74787No exploit | Scriban before 7.0.0 Uncontrolled Recursion via object.to_jsonscriban · scriban · CWE-674 | High8.7 | — | 0.5% | Aug 16, 2026 |
- CVE-2026-10104727Monitor
Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs
MediumCVSS 6.9No exploitEPSS 0%fleetdm · fleet2 days ago
- CVE-2026-10085634Monitor
AzuraCast before 0.23.6 Code Injection via Remote Relay Password
HighCVSS 8.7No exploitEPSS 0%azuracast · azuracast3 days ago
- CVE-2026-10085528Monitor
AzuraCast before 0.23.6 Missing Permission Check via /play
HighCVSS 7.1No exploitEPSS 0%azuracast · azuracast3 days ago
- CVE-2026-10085421Monitor
AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API
MediumCVSS 5.3No exploitEPSS 0%azuracast · azuracast3 days ago
- CVE-2026-10083725Monitor
Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
MediumCVSS 6.3No exploitEPSS 0%edgelesssys · contrast3 days ago
- CVE-2026-10062928Monitor
Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH
HighCVSS 7.0No exploitEPSS 0%cap-go · capgo.app3 days ago
- CVE-2026-10062621Monitor
capgo through 12.128.2 IDOR via PUT /app icon endpoint
MediumCVSS 5.3No exploitEPSS 0%cap-go · capgo.app3 days ago
- CVE-2026-9296040Plan
vm2 before 3.11.6 Process-wide State Exposure via os and dns
CriticalCVSS 10.0No exploitEPSS 0%patriksimek · vm2Sep 17, 2026
- CVE-2026-9093521Monitor
Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API
MediumCVSS 5.3No exploitEPSS 0%froxlor · froxlorSep 14, 2026
- CVE-2026-9053525Monitor
Flowise before 3.1.4 Denial of Service via text-to-speech/abort
MediumCVSS 6.3No exploitEPSS 0%flowiseai · flowiseSep 12, 2026
- CVE-2026-8625227Monitor
h3 before 1.15.9 SSE Event Injection via Carriage Return
MediumCVSS 6.9No exploitEPSS 0%h3js · h3Sep 6, 2026
- CVE-2026-8625132Monitor
h3 before 1.15.9 Path Traversal via Double Decoding
HighCVSS 8.2No exploitEPSS 0%h3js · h3Sep 6, 2026
- CVE-2026-8625034Monitor
h3 before 2.0.1-rc.18 Denial of Service via Unbounded Chunked Cookie
HighCVSS 8.7No exploitEPSS 0%h3js · h3Sep 6, 2026
- CVE-2026-8620521Monitor
h3 before 2.0.1-rc.18 Open Redirect via redirectBack()
MediumCVSS 5.3No exploitEPSS 0%h3js · h3Sep 6, 2026
- CVE-2026-8286635Monitor
@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch
HighCVSS 8.9No exploitEPSS 0%pdfme · commonAug 31, 2026
- CVE-2026-828658Monitor
pdfme schemas before 5.5.10 Cross-Site Scripting via i18n Label
LowCVSS 2.1No exploitEPSS 0%pdfme · schemasAug 31, 2026
- CVE-2026-8286428Monitor
pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb
HighCVSS 7.1No exploitEPSS 0%pdfme · pdf-libAug 31, 2026
- CVE-2026-7967334Monitor
Ech0 before 4.4.3 Scope Bypass via profile:read Token
HighCVSS 8.5No exploitEPSS 0%lin-snow · ech0Aug 25, 2026
- CVE-2026-7967228Monitor
Ech0 before 4.4.3 Authentication Bypass via Comment Panel
HighCVSS 7.0No exploitEPSS 0%lin-snow · ech0Aug 25, 2026
- CVE-2026-7967120Monitor
Ech0 before 4.4.3 SSRF via DNS Resolution Bypass
MediumCVSS 5.1No exploitEPSS 0%lin-snow · ech0Aug 25, 2026
- CVE-2026-7967019Monitor
Ech0 before 4.4.3 Stored XSS via SVG Upload
MediumCVSS 4.8No exploitEPSS 0%lin-snow · ech0Aug 25, 2026
- CVE-2026-7966921Monitor
Ech0 before 4.4.3 Missing Authorization on System Logs
MediumCVSS 5.3No exploitEPSS 0%lin-snow · ech0Aug 25, 2026
- CVE-2026-863020Monitor
justhtml before 1.12.0 Mutation XSS via Raw Text Elements
MediumCVSS 5.1No exploitEPSS 0%emilstenstrom · justhtmlAug 23, 2026
- CVE-2026-7478834Monitor
Scriban before 7.0.0 Denial of Service via string.pad_left/pad_right
HighCVSS 8.7No exploitEPSS 0%scriban · scribanAug 16, 2026
- CVE-2026-7478734Monitor
Scriban before 7.0.0 Uncontrolled Recursion via object.to_json
HighCVSS 8.7No exploitEPSS 0%scriban · scribanAug 16, 2026