Skip to content

standard

CVSS

CVSS is an industry-standard framework for scoring the severity of software security vulnerabilities on a 0-10 scale based on exploitability and impact.

Known aliases

  • Common Vulnerability Scoring System
  • CVSS 3.1
  • CVSS 4.0
  • CVSS score
  • CVSS scoring system
  • CVSS v3
  • CVSS v3.1
  • CVSSv3.1
  • CVSS v4
  • CVSS v4.0
  • CVSSv4.0

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

vm2's prefix allowlist let one approved module load its unapproved siblings

vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence58
security7 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
security4 publishers

Google traces most of 2026's exploitation growth to fast n-day weaponization

Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.

Perspective Coverage

4 publishers
Builder
Builder 33%
Operator
Operator 61%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+30
Incentives35
Confidence65
security4 publishers

OpenSSL patches a DTLS flaw that sends heap memory to unauthenticated peers

OpenSSL patched 14 flaws, led by CVE-2026-84782, a CVSS 8.2 DTLS handshake bug that lets an unauthenticated remote peer pull fragments of heap memory. Only software that speaks DTLS is exposed, so VPN, VoIP and IoT products go first in the patch queue.

Perspective Coverage

4 publishers
Builder
Builder 40%
Operator
Operator 54%
Investor
Investor 6%

Reality

Evidence74
Adoption40
Hype gap+25
Incentives30
Confidence70
build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
build1 publisher

Putting KEV and EPSS ahead of CVSS lifts a 6.5 finding above a 9.1

Ranking by KEV, then EPSS, then CVSS puts a 6.5 with 0.61 exploit odds ahead of a 9.1 at 0.02 in a Dev.to triage guide's worked example. The order is sound, though the backlog savings it promises rest on five hypothetical findings and CVE-wide statistics the post does not source.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence50
security3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60
security3 publishers

One clicked link creates an attacker admin on Elementor 4.3.0 and 4.3.1

Elementor 4.3.0 and 4.3.1 carry a CSRF flaw that lets an attacker turn one link, clicked by a logged-in admin, into a rogue administrator account. Version 4.3.2, released this week, closes the query-string bypass.

Perspective Coverage

3 publishers
Builder
Builder 38%
Operator
Operator 55%
Investor
Investor 7%

Reality

Evidence72
Adoption60
Hype gap+10
Incentives30
Confidence74
security5 publishers

Six 10.0s in the control plane, and nothing in your patch queue to show for it

Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.

Perspective Coverage

5 publishers
Builder
Builder 20%
Operator
Operator 65%
Investor
Investor 15%

Reality

Evidence62
Adoption
Insufficient
Hype gap+40
Incentives55
Confidence55
security5 publishers

Check Point patches two 9.8 VPN certificate flaws without naming what triggers them

Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.

Perspective Coverage

5 publishers
Builder
Builder 15%
Operator
Operator 74%
Investor
Investor 11%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence62

Earlier coverage

  1. Attackers are exploiting CVE-2026-93952 in VeloCloud Orchestrators that authenticate Edges by certificate

    Security · September 22, 2026 · 4 publishers

  2. SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure

    Security · September 24, 2026 · 1 publisher

  3. Eclypsium finds the month's exploited infrastructure flaws again in the management consoles

    Security · September 23, 2026 · 1 publisher

  4. An agent now picks the packages the person prompting it will never see

    Build · September 23, 2026 · 1 publisher

  5. Admin credentials are the only gate on D-Link's unfixed R95 command injection

    Security · September 23, 2026 · 1 publisher

  6. Unauthenticated requests to TCP/19009 run scripts on Check Point management servers

    Build · September 22, 2026 · 1 publisher

  7. Signed int arithmetic in libde265 shrinks a 4 GB plane allocation to 1,040 bytes before the fill

    Security · September 22, 2026 · 1 publisher

  8. Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server

    Build · September 22, 2026 · 1 publisher

  9. A banner-grabbing scanner flags patched OpenSSL 3.0.2 on RHEL 9 as potentially vulnerable

    Build · September 22, 2026 · 1 publisher

  10. Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000

    Build · September 21, 2026 · 1 publisher

  11. A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy

    Build · September 20, 2026 · 1 publisher

  12. A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem

    Build · September 19, 2026 · 1 publisher

  13. N-able's fourth hotfix is the one that closes the N-central code injection

    Build · September 19, 2026 · 1 publisher

  14. A crafted request to one Cisco ISE API endpoint reaches root without a credential

    Build · September 19, 2026 · 2 publishers

  15. GitLab's commits API returns arbitrary files to an unauthenticated caller at CVSS 10.0

    Build · September 19, 2026 · 1 publisher

  16. Hard-coded static key in SolarWinds Access Rights Manager hands unauthenticated attackers RCE

    Security · September 19, 2026 · 1 publisher

  17. A prohibited leading character in a RouterOS username rewrites the session's policy mask

    Build · September 16, 2026 · 1 publisher

  18. Operators rebuilding CISA's post-CVSS patch sort must merge KEV with Vulnrichment themselves

    Security · September 18, 2026 · 1 publisher

  19. WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme

    Security · September 18, 2026 · 1 publisher

  20. A crafted HTTP request runs commands as root on unpatched Cisco ISE nodes

    Build · September 18, 2026 · 1 publisher

  21. Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0

    Security · September 18, 2026 · 1 publisher

  22. A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API

    Build · September 17, 2026 · 1 publisher

  23. Delinea fixed two unauthenticated critical flaws in its credential vault 18 days before disclosing them

    Science · September 18, 2026 · 1 publisher

  24. CVE-2026-77179 let sandboxed agent code write anywhere the macOS host account could

    Security · September 17, 2026 · 1 publisher

  25. An empty string in Artifactory's default join keys mints a platform admin token

    Build · September 17, 2026 · 1 publisher

  26. Delinea's 2 September hotfixes all land inside the new SAML impersonation range

    Build · September 17, 2026 · 1 publisher

  27. A crafted DNSKEY overflows the heap in every Unbound release before 1.26.1

    Security · September 17, 2026 · 1 publisher

  28. Microsoft expects 58 of September's 973 CVEs to be exploited within 30 days

    Security · September 17, 2026 · 1 publisher

  29. CVE-2026-84869 lets an attacker run files inside a live ScreenConnect session

    Security · September 16, 2026 · 1 publisher

  30. Acronis bases its CVE-2026-87886 exploitation warning on one customer report

    Security · September 16, 2026 · 4 publishers

  31. One slash in a Host header moves the path Starlette's middleware checks

    Build · September 16, 2026 · 1 publisher

  32. Any Kestra API path ending in /configs skipped Basic Authentication

    Build · September 15, 2026 · 1 publisher

  33. CISA ties 40% of 2024's exploited flaws to a handful of long-known weakness classes

    Security · September 15, 2026 · 1 publisher

  34. Exploitation catalogues logged 495 of the 35,853 CVEs published in the first half of 2026

    Security · September 15, 2026 · 1 publisher

  35. Attackers have been pushing VBScript through live ScreenConnect sessions since August 20

    Security · September 14, 2026 · 1 publisher

  36. CVE-2026-89049 converts a port-forwarding permission into instance-role credentials

    Build · September 12, 2026 · 1 publisher

  37. Prompt injection embedded in malware turns an LLM scanner's refusal into a free pass

    Security · September 11, 2026 · 1 publisher

  38. A wiki that accepted GET as an edit gave read-only agents 18,000 writes

    Build · September 11, 2026 · 1 publisher

  39. Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year

    Security · September 10, 2026 · 1 publisher

  40. cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root

    Security · September 9, 2026 · 1 publisher