The
Reassessment
Feed.

All ↑ Upgraded ↓ Downgraded = Unchanged
Sort
All reassessments
showing 1–20 of 1,895
2026-09-13
CVE-2026-85188
Assessment for CVE-2026-85188
CVE-2026-85188 has no public record — cannot assess what does not exist.
? = IGNORE
2026-09-13
CVE-2023-20867
CWE-287
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and int
Vendor says LOW but a nation-state APT weaponized this for silent fleet-wide VM compromise since 2021
LOW 3.9 ↑ HIGH
EPSS 0.14 KEV
2026-09-13
CVE-2026-78159
CWE-94
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the par
Unauthenticated RCE gated behind comment moderation — real but not frictionless
CRITICAL 9.8 ↓ HIGH
EPSS 0.01
2026-09-13
CVE-2026-78006
CWE-502
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_
Unauthenticated RCE via comment injection on 800K WordPress sites; public PoC, patch now.
CRITICAL 9.8 = CRITICAL
EPSS 0.01
2026-09-12
CVE-2026-42016
CWE-863
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the to
KEV-listed supply-chain escalation: low-priv token to Artifactory admin, actively exploited in the wild
HIGH 8.1 ↑ CRITICAL
EPSS 0.00 KEV
2026-09-12
CVE-2026-89094
CWE-1336
Forgejo before 16.0.4
Any authenticated user turns a template repo into full RCE on your code forge — supply-chain game over.
CRITICAL 9.9 = CRITICAL
EPSS 0.01
2026-09-12
CVE-2026-87859
CWE-117
morgan is an HTTP request logger middleware for Node.js.
Log-field confusion in a logging middleware — no code exec, no newlines, just shifted columns.
MEDIUM 5.3 ↓ LOW
EPSS 0.00
2026-09-12
CVE-2026-87776
CWE-401
compression is a Node.js and Express compression middleware.
Unauthenticated memory-leak DoS in Express compression middleware, capped at availability impact.
HIGH 7.5 ↓ MEDIUM
2026-09-12
CVE-2026-87719
CWE-502
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that
Duo Chat gate shrinks the blast radius, but stolen Elasticsearch creds can pivot deep.
CRITICAL 9.9 ↓ HIGH
2026-09-12
CVE-2026-87123
CWE-248
hbs is an Express view engine wrapper for Handlebars.
Single-version DoS in a view engine helper path; process managers absorb the impact.
MEDIUM 5.9 ↓ LOW
EPSS 0.00
2026-09-12
CVE-2026-85706
CWE-22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 th
Unauthenticated file read on your CI/CD brain. Patch now or lose your secrets.
CRITICAL 10.0 = CRITICAL
KEV
2026-09-12
CVE-2026-84869
CWE-269
A condition in the ScreenConnect client may
KEV-listed RMM client flaw with worm-like propagation — patch or lose the fleet
CRITICAL 9.9 = CRITICAL
EPSS 0.00 KEV
2026-09-12
CVE-2026-80462
CWE-306
A vulnerability in the Chef Automate API gateway and identity validation path may
Unauthenticated gateway bypass on your fleet's command-and-control plane — narrow version window is the only saving grace.
CRITICAL 10.0 = CRITICAL
2026-09-12
CVE-2026-73324
CWE-125
VLC media player copies an RTSP response line into a fixed buffer without guaranteeing termination and then treats that buffer as a C string
Client-side heap leak via legacy RTSP protocol — no code execution, no patch yet, low real-world exposure.
MEDIUM 6.5 = MEDIUM
EPSS 0.00
2026-09-12
CVE-2026-56711
CWE-190
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result.
Client-side media player heap overflow with no PoC, no exploitation, and workstation-only blast radius.
HIGH 8.8 ↓ MEDIUM
EPSS 0.00
2026-09-12
CVE-2026-51990
CWE-88
Sogou Input Method sgbiz: Protocol Handler Argument Injection Leading to RCE via Unsandboxed Chromium 80
One-click RCE in Sogou IME actively exploited by China-linked APT to deploy GRAYRABBIT backdoor
? = HIGH
2026-09-10
CVE-2025-14733
CWE-787
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may
Unauthenticated RCE on 117K+ internet-facing firewalls, actively exploited in ransomware campaigns.
CRITICAL 9.8 = CRITICAL
EPSS 0.27 KEV
2026-09-10
CVE-2026-88038
CWE-74
cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options
Cookie attribute injection needs an app anti-pattern most codebases dont have
MEDIUM 4.8 ↓ LOW
2026-09-10
CVE-2026-82533
CWE-807
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API
Localhost-only AI client lib with 15K downloads — real bug, inflated blast radius.
CRITICAL 9.6 ↓ MEDIUM
EPSS 0.00
2026-09-10
CVE-2025-20701
CWE-863
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privilege
Consumer BT peripheral flaw with proximity-only attack — not patchable by your infra team.
HIGH 8.8 ↓ MEDIUM
EPSS 0.08