Hinoki vulnerability directory
Vulnerabilities observed in recent attacks.
Every square is a vulnerability observed by honeypots, placed on its highest-activity day in the last 30 reporting days. Explore the public record and the software it affects.
View activity data
Each CVE's highest daily unique-IP count in the last 30 reporting days, plotted by observation date.
265,053CVEs indexed and searchable
Recently published · Showing 10 of 265,053
CVE-2026-89058Sep 18, 2026Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard configRed Hat, RESTEasy—UnscoredCVE-2026-89059Sep 18, 2026Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)Red Hat, RESTEasy—UnscoredCVE-2024-38639Sep 18, 2026QTSUnknown vendor, Unknown product—UnscoredCVE-2024-27123Sep 18, 2026QcalAgentLinn Products Limited, QcalAgent—UnscoredCVE-2026-92561Sep 18, 2026Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Parameterwpdevelop, Booking Calendar—UnscoredCVE-2026-89330Sep 18, 2026Reflected XSS via unescaped unique parameterReviewX Team, EmbedPress6.1MediumCVE-2026-89278Sep 18, 2026API key disclosure via reversible frontend encodingJExtensions Store, GPTranslate7.5HighCVE-2026-84909Sep 18, 2026Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode AttributeSmash Balloon, Custom Twitter Feeds—UnscoredCVE-2026-12106Sep 18, 2026Auto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of <img> TagsAli Irani, Auto Upload Images—UnscoredCVE-2026-92619Sep 18, 2026Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameterwpdevelop, Booking Calendar—UnscoredFeatured
Unauthenticated administrator takeover via unchecked password reset
Authentication bypass in SmarterTools SmarterMail before 100.0.9511 allows remote attackers to reset a system administrator password. The anonymous force-reset-password endpoint trusts IsSysAdmin and writes NewPassword without authenticating the caller or validating OldPassword. Knowledge or guessing of an administrator username is the only gate, after which the reset credential grants full application administration and command execution as SYSTEM or root.
Daily unique IPs observed over 30 days
View daily counts
| Reporting day | Unique IPs |
|---|---|
| Aug 22, 2026 | Unavailable |
| Aug 23, 2026 | Unavailable |
| Aug 24, 2026 | 1 |
| Aug 25, 2026 | 17 |
| Aug 26, 2026 | 11 |
| Aug 27, 2026 | Unavailable |
| Aug 28, 2026 | 14 |
| Aug 29, 2026 | Unavailable |
| Aug 30, 2026 | Unavailable |
| Aug 31, 2026 | 14 |
| Sep 1, 2026 | Unavailable |
| Sep 2, 2026 | Unavailable |
| Sep 3, 2026 | 2,148 |
| Sep 4, 2026 | Unavailable |
| Sep 5, 2026 | Unavailable |
| Sep 6, 2026 | Unavailable |
| Sep 7, 2026 | Unavailable |
| Sep 8, 2026 | Unavailable |
| Sep 9, 2026 | Unavailable |
| Sep 10, 2026 | Unavailable |
| Sep 11, 2026 | 1 |
| Sep 12, 2026 | Unavailable |
| Sep 13, 2026 | Unavailable |
| Sep 14, 2026 | Unavailable |
| Sep 15, 2026 | 1 |
| Sep 16, 2026 | Unavailable |
| Sep 17, 2026 | Unavailable |
| Sep 18, 2026 | Unavailable |
| Sep 19, 2026 | Unavailable |
| Sep 20, 2026 | Unavailable |
Shadowserver KEV observations through Sep 20, 2026. Gaps indicate unavailable data.
Observed
Attack activity on the latest reporting day
Shadowserver observations through Sep 20, 2026. Counts describe the reporting day shown on each card.
Rising
Largest increases in observed activity
Compare the 7-day average of daily unique IPs with the preceding, separate 30-day average. A comparison requires complete history and a positive baseline.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo