BlackTreeCVE IntelligenceTransparent operational contextNo replacement for CVSSEvidence changes automatically
Operational reassessment
Technical severity, tested against real-world signals
Compare published severity with exploitation, reachability, prerequisites and EPSS. Every result shows its evidence and limitations.
30-day operating picture
The action queues at a glance
3,428 changed classification. 1,770 still need a manual severity baseline.
Assessment feed
Newest reassessments
Method v1. CISA KEV, public exploit evidence, network reachability, authentication, EPSS and prerequisite depth are evaluated against the published technical severity.
CVE-2026-101169Octopus Deploy · Octopus Server
UnchangedInsecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process
Published severityHigh · 8.7→Operational priority:High, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-84154Dassault Systèmes · GEOVIA Geospatial Data Manager
UnchangedCode Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x
Published severityCritical · 9.9→Operational priority:Critical, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-86158Progress Software · Progress® Telerik® Fiddler® Everywhere
UnchangedMissing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere
Published severityHigh · 7.7→Operational priority:High, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-86157Progress Software · Progress® Telerik® Fiddler® Everywhere
Loweredsince 29 Sept 2026Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere
Published severityMedium · 5.6→Operational priority:Low, lowered one band.
- No CISA KEV confirmation is currently recorded.
- Exploitation requires an existing local or physical foothold with privileges.
CVE-2026-102293realjerrytang · tacomall
Unchangedrealjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServiceImpl.add improper authorization
Published severityMedium · 6.9→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
CVE-2026-102292coolbeans1212 · MateisHomePage-Website
Unchangedcoolbeans1212 MateisHomePage-Website users.php cross site scripting
Published severityMedium · 5.3→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102290CodeCanyon · Rocket LMS
UnchangedCodeCanyon Rocket LMS Student Profile Image Upload cross site scripting
Published severityMedium · 5.1→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102264mwasikz · robo-cafe-rms
Unchangedmwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting
Published severityMedium · 5.1→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102263mwasikz · robo-cafe-rms
Unchangedmwasikz robo-cafe-rms manage-food.php unrestricted upload
Published severityMedium · 5.1→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102261owen2345 · Camaleon CMS
Unchangedowen2345 Camaleon CMS Media Crop media_controller.rb crop authorization
Published severityMedium · 5.3→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102422Unknown · shell-quote
Unchangedshell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token
Published severityCritical · 9.2→Operational priority:Critical, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
CVE-2026-102249Unknown · REBUILD
UnchangedREBUILD file-editor-save authorization
Published severityMedium · 6.9→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
CVE-2026-97029Red Hat · Red Hat Enterprise Linux 10
UnchangedFlatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group
Published severityMedium · 5.7→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102414browserify · pbkdf2
Unchangedpbkdf2 rehashes long passwords on every iteration, enabling denial of service
Published severityMedium · 6.3→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
CVE-2026-102248Unknown · Rebuild
UnchangedRebuild Login Endpoint login improper authentication
Published severityMedium · 6.9→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
CVE-2026-97024Red Hat · Red Hat Enterprise Linux 10
UnchangedFlatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc
Published severityHigh · 7.1→Operational priority:High, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102247Unknown · FastAdmin
UnchangedFastAdmin Database Management database.php unnecessary privileges
Published severityHigh · 8.5→Operational priority:High, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102245MODSetter · SurfSense
UnchangedMODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication
Published severityMedium · 6.9→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
- The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
CVE-2026-102244MODSetter · SurfSense
UnchangedMODSetter SurfSense Document Export Feature editor_routes.py server-side request forgery
Published severityMedium · 5.3→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
CVE-2026-102243MODSetter · SurfSense
UnchangedMODSetter SurfSense MCP Connector Integration test command injection
Published severityMedium · 5.3→Operational priority:Medium, unchanged from published severity.
- No CISA KEV confirmation is currently recorded.
What this result means
This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.