Hinoki vulnerability directory
Vulnerabilities observed in recent attacks.
Every square is a vulnerability observed by honeypots, placed on its highest-activity day in the last 30 reporting days. Explore the public record and the software it affects.
View activity data
Each CVE's highest daily unique-IP count in the last 30 reporting days, plotted by observation date.
264,678CVEs indexed and searchable
Recently published · Showing 10 of 264,678
CVE-2026-92603Sep 16, 2026ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageControllerOpenContiNew, ContiNew Admin—UnscoredCVE-2026-61593Sep 16, 2026djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE sessiondjust, djust—UnscoredCVE-2026-92626Sep 16, 2026Control iD iDSecure Unauthenticated Denial of ServiceControl iD, iDSecure On-Premises—UnscoredCVE-2026-70416Sep 16, 2026CVE-2026-70416Dell Technologies, ObjectScale—UnscoredCVE-2026-92627Sep 16, 2026Heap Use-After-Free in H5T__conv_f_fThe HDF Group, HDF5—UnscoredCVE-2025-43936Sep 16, 2026CVE-2025-43936Dell Technologies, ObjectScale—UnscoredCVE-2026-82410Sep 16, 2026Pocketbase: Unhandled panic in worker goroutinesPocketBase, PocketBase—UnscoredCVE-2026-79651Sep 16, 2026Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale cachingUnknown vendor, Unknown product—UnscoredCVE-2026-74909Sep 16, 2026Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segmentsRed Hat, Red Hat build of Keycloak—UnscoredCVE-2026-18212Sep 16, 2026Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib stateRed Hat, Red Hat build of Keycloak—UnscoredFeatured
Unauthenticated privilege-15 account creation via path validation bypass
Privilege escalation in the Cisco IOS XE Software web UI allows remote attackers to create privilege-15 local accounts without authentication. Improper path validation lets crafted requests bypass Nginx filtering and reach a privileged WSMA SOAP endpoint without authentication. The HTTP or HTTPS server feature must be enabled; the resulting account grants full administrative control of the device.
Daily unique IPs observed over 30 days
View daily counts
| Reporting day | Unique IPs |
|---|---|
| Aug 17, 2026 | Unavailable |
| Aug 18, 2026 | Unavailable |
| Aug 19, 2026 | 263 |
| Aug 20, 2026 | 274 |
| Aug 21, 2026 | 230 |
| Aug 22, 2026 | 204 |
| Aug 23, 2026 | 218 |
| Aug 24, 2026 | 260 |
| Aug 25, 2026 | 268 |
| Aug 26, 2026 | 270 |
| Aug 27, 2026 | 286 |
| Aug 28, 2026 | 257 |
| Aug 29, 2026 | 326 |
| Aug 30, 2026 | 269 |
| Aug 31, 2026 | 270 |
| Sep 1, 2026 | 275 |
| Sep 2, 2026 | Unavailable |
| Sep 3, 2026 | Unavailable |
| Sep 4, 2026 | Unavailable |
| Sep 5, 2026 | Unavailable |
| Sep 6, 2026 | Unavailable |
| Sep 7, 2026 | Unavailable |
| Sep 8, 2026 | Unavailable |
| Sep 9, 2026 | Unavailable |
| Sep 10, 2026 | Unavailable |
| Sep 11, 2026 | Unavailable |
| Sep 12, 2026 | Unavailable |
| Sep 13, 2026 | Unavailable |
| Sep 14, 2026 | 522 |
| Sep 15, 2026 | 523 |
Shadowserver KEV observations through Sep 15, 2026. Gaps indicate unavailable data.
Observed
Attack activity on the latest reporting day
Shadowserver observations through Sep 15, 2026. Counts describe the reporting day shown on each card.
Rising
Largest increases in observed activity
Compare the 7-day average of daily unique IPs with the preceding, separate 30-day average. A comparison requires complete history and a positive baseline.
No increases can be ranked for this window. A CVE needs complete history and activity above its baseline.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo