Index
Search
Search the public record. Drafts and scheduled notes are not included.
HighNo PoC
CVE-2026-83540
wolfSSHd on Windows reuses logon token across connections
Auth bypass
Published 2d ago
MediumNo PoC
CVE-2026-84897
wolfSSH server accepts server-only DH group exchange messages from clients
DoS
Published 2d ago
High
research
The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 3d ago
CriticalNo PoC
CVE-2026-10747
IBM MQ pre-auth heap overflow in protocol message processing
RCE
Published 18 Sept 2026
HighPoC Available
CVE-2026-48842
Roundcube virtuser_query SQL injection
SQLi
Published 25 May 2026