rexpository
41 credited records · 41 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-100721Proof of concept | vm2 before 3.12.2 Authorization Bypass via Custom Resolverpatriksimek · vm2 · CWE-863 | Critical9.5 | — | 0.4% | 3 days ago |
27Monitor | CVE-2026-100723No exploit | vm2 before 3.12.2 Memory Disclosure via zlib Buffer Poolpatriksimek · vm2 · CWE-200 | Medium6.9 | — | 0.3% | 3 days ago |
35Monitor | CVE-2026-100722No exploit | vm2 before 3.12.2 Host Process Termination via Construct Trappatriksimek · vm2 · CWE-248 | High8.9 | — | 0.3% | 3 days ago |
34Monitor | CVE-2026-100664No exploit | Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusionnetty · netty · CWE-20 | High8.7 | — | 0.3% | 3 days ago |
34Monitor | CVE-2026-100663No exploit | Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3netty · netty · CWE-20 | High8.7 | — | 0.3% | 3 days ago |
33Monitor | CVE-2026-100653No exploit | vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagationvllm-project · vllm · CWE-348 | High8.3 | — | 0.3% | 3 days ago |
32Monitor | CVE-2026-100652No exploit | vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_idsvllm-project · vllm · CWE-20 | High8.2 | — | 0.3% | 3 days ago |
28Monitor | CVE-2026-100651No exploit | vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypassvllm-project · vllm · CWE-400 | High7.1 | — | 0.3% | 3 days ago |
34Monitor | CVE-2026-100640No exploit | SiYuan before v3.8.4 Clipboard Data Disclosure via IPCsiyuan-note · siyuan · CWE-200 | High8.6 | — | 0.2% | 3 days ago |
34Monitor | CVE-2026-100639No exploit | SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IALsiyuan-note · siyuan · CWE-79 | High8.6 | — | 0.5% | 3 days ago |
32Monitor | CVE-2026-100635No exploit | SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookiesiyuan-note · siyuan · CWE-319 | High8.2 | — | 0.3% | 3 days ago |
34Monitor | CVE-2026-100665No exploit | Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypassnetty · netty · CWE-295 | High8.7 | — | 0.3% | 4 days ago |
34Monitor | CVE-2026-100641No exploit | SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Contentsiyuan-note · siyuan · CWE-79 | High8.6 | — | 0.5% | 4 days ago |
21Monitor | CVE-2026-100634No exploit | SiYuan before v3.8.4 Missing Authorization via siyuan-send-windowssiyuan-note · siyuan · CWE-862 | Medium5.3 | — | 0.5% | 4 days ago |
30Monitor | CVE-2026-100598No exploit | OpenClaw before 2026.7.1 Approval Binding Logic Erroropenclaw · openclaw · CWE-346 | High7.5 | — | 0.1% | 4 days ago |
21Monitor | CVE-2026-100591No exploit | OpenClaw before 2026.7.1 Authentication Bypass via Active Memoryopenclaw · openclaw · CWE-862 | Medium5.3 | — | 0.2% | 4 days ago |
21Monitor | CVE-2026-100590No exploit | OpenClaw before 2026.7.1 Authorization Bypass via voice setopenclaw · openclaw · CWE-863 | Medium5.3 | — | 0.2% | 4 days ago |
21Monitor | CVE-2026-100592No exploit | OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreamingopenclaw · openclaw · CWE-862 | Medium5.3 | — | 0.2% | 4 days ago |
27Monitor | CVE-2026-100527No exploit | OpenClaw before 2026.8.2 Denial of Service via Browser Relayopenclaw · openclaw · CWE-400 | Medium6.9 | — | 0.3% | 4 days ago |
27Monitor | CVE-2026-93604No exploit | vm2 3.11.8 Sandbox Escape via crypto.setFipspatriksimek · vm2 · CWE-284 | Medium6.9 | — | 0.3% | Sep 18, 2026 |
33Monitor | CVE-2026-92958No exploit | vm2 before 3.11.7 Denylist Bypass via fs/promisespatriksimek · vm2 · CWE-269 | High8.4 | — | 0.4% | Sep 17, 2026 |
36Monitor | CVE-2026-92954No exploit | vm2 3.10.0 through 3.11.7 Denial of Service via Host Promisepatriksimek · vm2 · CWE-248 | Critical9.2 | — | 0.5% | Sep 17, 2026 |
37Monitor | CVE-2026-92953No exploit | vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArraypatriksimek · vm2 · CWE-913 | Critical9.3 | — | 0.5% | Sep 17, 2026 |
35Monitor | CVE-2026-92952No exploit | vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypasspatriksimek · vm2 · CWE-669 | High8.9 | — | 0.5% | Sep 17, 2026 |
8Monitor | CVE-2026-86424No exploit | ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Raceimagemagick · imagemagick · CWE-59 | Low2.0 | — | 0.1% | Sep 7, 2026 |
- CVE-2026-10072138Monitor
vm2 before 3.12.2 Authorization Bypass via Custom Resolver
CriticalCVSS 9.5Proof of conceptEPSS 0%patriksimek · vm23 days ago
- CVE-2026-10072327Monitor
vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool
MediumCVSS 6.9No exploitEPSS 0%patriksimek · vm23 days ago
- CVE-2026-10072235Monitor
vm2 before 3.12.2 Host Process Termination via Construct Trap
HighCVSS 8.9No exploitEPSS 0%patriksimek · vm23 days ago
- CVE-2026-10066434Monitor
Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion
HighCVSS 8.7No exploitEPSS 0%netty · netty3 days ago
- CVE-2026-10066334Monitor
Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
HighCVSS 8.7No exploitEPSS 0%netty · netty3 days ago
- CVE-2026-10065333Monitor
vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation
HighCVSS 8.3No exploitEPSS 0%vllm-project · vllm3 days ago
- CVE-2026-10065232Monitor
vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids
HighCVSS 8.2No exploitEPSS 0%vllm-project · vllm3 days ago
- CVE-2026-10065128Monitor
vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass
HighCVSS 7.1No exploitEPSS 0%vllm-project · vllm3 days ago
- CVE-2026-10064034Monitor
SiYuan before v3.8.4 Clipboard Data Disclosure via IPC
HighCVSS 8.6No exploitEPSS 0%siyuan-note · siyuan3 days ago
- CVE-2026-10063934Monitor
SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL
HighCVSS 8.6No exploitEPSS 0%siyuan-note · siyuan3 days ago
- CVE-2026-10063532Monitor
SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie
HighCVSS 8.2No exploitEPSS 0%siyuan-note · siyuan3 days ago
- CVE-2026-10066534Monitor
Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
HighCVSS 8.7No exploitEPSS 0%netty · netty4 days ago
- CVE-2026-10064134Monitor
SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content
HighCVSS 8.6No exploitEPSS 1%siyuan-note · siyuan4 days ago
- CVE-2026-10063421Monitor
SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows
MediumCVSS 5.3No exploitEPSS 0%siyuan-note · siyuan4 days ago
- CVE-2026-10059830Monitor
OpenClaw before 2026.7.1 Approval Binding Logic Error
HighCVSS 7.5No exploitEPSS 0%openclaw · openclaw4 days ago
- CVE-2026-10059121Monitor
OpenClaw before 2026.7.1 Authentication Bypass via Active Memory
MediumCVSS 5.3No exploitEPSS 0%openclaw · openclaw4 days ago
- CVE-2026-10059021Monitor
OpenClaw before 2026.7.1 Authorization Bypass via voice set
MediumCVSS 5.3No exploitEPSS 0%openclaw · openclaw4 days ago
- CVE-2026-10059221Monitor
OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming
MediumCVSS 5.3No exploitEPSS 0%openclaw · openclaw4 days ago
- CVE-2026-10052727Monitor
OpenClaw before 2026.8.2 Denial of Service via Browser Relay
MediumCVSS 6.9No exploitEPSS 0%openclaw · openclaw4 days ago
- CVE-2026-9360427Monitor
vm2 3.11.8 Sandbox Escape via crypto.setFips
MediumCVSS 6.9No exploitEPSS 0%patriksimek · vm2Sep 18, 2026
- CVE-2026-9295833Monitor
vm2 before 3.11.7 Denylist Bypass via fs/promises
HighCVSS 8.4No exploitEPSS 0%patriksimek · vm2Sep 17, 2026
- CVE-2026-9295436Monitor
vm2 3.10.0 through 3.11.7 Denial of Service via Host Promise
CriticalCVSS 9.2No exploitEPSS 0%patriksimek · vm2Sep 17, 2026
- CVE-2026-9295337Monitor
vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray
CriticalCVSS 9.3No exploitEPSS 1%patriksimek · vm2Sep 17, 2026
- CVE-2026-9295235Monitor
vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass
HighCVSS 8.9No exploitEPSS 0%patriksimek · vm2Sep 17, 2026
- CVE-2026-864248Monitor
ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race
LowCVSS 2.0No exploitEPSS 0%imagemagick · imagemagickSep 7, 2026