CVE-2026-100518Medium· 5.3▾ SunlitUnauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97308Medium· 4.8Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
CVE-2026-94174High· 7.6Administrator SQL Injection in Email Log <= 2.63 versions.
CVE-2026-94457Medium· 4.8Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
CVE-2026-39769High· 7.5Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39793High· 8.8Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-100261Medium· 5.4In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission