CVE-2026-36453High· 7.4▾ TwilightRhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40532Medium· 6.5A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
CVE-2026-33217High· 7.1NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-25679High· 7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-19903Medium· 5.3A vulnerability has been found in SourceCodester Online Clothing Store 1.0
CVE-2026-11986Medium· 4.9A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities
CVE-2026-0650NoneOpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware