{"schema_version":1,"title":"Unknown vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 69 vulnerabilities in Unknown: 13 in the last 7 days and 51 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-98148, was published on 25 September 2026.","url":"https://junglewise.ai/threats/vendors/unknown","json_url":"https://junglewise.ai/threats/vendors/unknown.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/unknown","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":69,"critical":5,"exploited":0,"last_7_days":13,"last_30_days":20,"last_90_days":51,"last_365_days":58},"latest":[{"cve":"CVE-2026-98148","slug":"cve-2026-98148-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel drm/gud rotation validation missing","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:46.363+00:00","url":"https://junglewise.ai/threats/cve-2026-98148-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-98139","slug":"cve-2026-98139-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel NTFS cluster free counting logic error","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:45.383+00:00","url":"https://junglewise.ai/threats/cve-2026-98139-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-98093","slug":"cve-2026-98093-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel fsl_micfil clock enable/disable imbalance","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:39.023+00:00","url":"https://junglewise.ai/threats/cve-2026-98093-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-98024","slug":"cve-2026-98024-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel s390/ism memory corruption in error handling","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:30.997+00:00","url":"https://junglewise.ai/threats/cve-2026-98024-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-98020","slug":"cve-2026-98020-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel pds_core race condition in cmd_regs BAR access during reset","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:30.48+00:00","url":"https://junglewise.ai/threats/cve-2026-98020-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-97922","slug":"cve-2026-97922-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel memory leak in tracing histogram variable references","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:19.287+00:00","url":"https://junglewise.ai/threats/cve-2026-97922-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-97913","slug":"cve-2026-97913-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel Ethos-U NPU driver command stream validation","severity":"info","exploited":false,"published_at":"2026-09-25T11:17:18.28+00:00","url":"https://junglewise.ai/threats/cve-2026-97913-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-84283","epss":0.0011,"slug":"cve-2026-84283-secure-folder-1-2-stores-files-selected-for-its-password","title":"Secure Folder plaintext vault files in shared storage","severity":"info","exploited":false,"published_at":"2026-09-25T00:16:57.57+00:00","url":"https://junglewise.ai/threats/cve-2026-84283-secure-folder-1-2-stores-files-selected-for-its-password"},{"cve":"CVE-2026-93808","epss":0.0017,"slug":"cve-2026-93808-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel ALSA USB audio caiaq buffer over-read","severity":"info","exploited":false,"published_at":"2026-09-24T17:17:13.797+00:00","url":"https://junglewise.ai/threats/cve-2026-93808-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-93257","epss":0.0019,"slug":"cve-2026-93257-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel block layer metadata integrity logic flaw","severity":"info","exploited":false,"published_at":"2026-09-24T16:17:22.31+00:00","url":"https://junglewise.ai/threats/cve-2026-93257-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-93254","epss":0.0021,"slug":"cve-2026-93254-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel arm64 interrupt handling logic fix","severity":"info","exploited":false,"published_at":"2026-09-24T16:17:21.807+00:00","url":"https://junglewise.ai/threats/cve-2026-93254-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-93234","epss":0.0021,"slug":"cve-2026-93234-in-the-linux-kernel-the-following-vulnerability-has-been-resolved","title":"Linux kernel DRM GUD driver out-of-bounds read in TV mode names","severity":"info","exploited":false,"published_at":"2026-09-24T16:17:19.007+00:00","url":"https://junglewise.ai/threats/cve-2026-93234-in-the-linux-kernel-the-following-vulnerability-has-been-resolved"},{"cve":"CVE-2026-93529","cvss":6.5,"epss":0.0021,"slug":"cve-2026-93529-contributor-broken-access-control-in-wsp-mcp-8211-ai-agents","title":"WSP MCP , AI Agents Connector broken access control in contributor role","severity":"medium","exploited":false,"published_at":"2026-09-23T19:19:45.717+00:00","url":"https://junglewise.ai/threats/cve-2026-93529-contributor-broken-access-control-in-wsp-mcp-8211-ai-agents"},{"cve":"CVE-2026-86707","cvss":9.8,"epss":0.005,"slug":"cve-2026-86707-wordpress-private-feed-key-authentication-bypass","title":"WordPress Private Feed Key authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-17T06:16:51.213+00:00","url":"https://junglewise.ai/threats/cve-2026-86707-wordpress-private-feed-key-authentication-bypass"},{"cve":"CVE-2026-53941","cvss":6.9,"epss":0.0052,"slug":"cve-2026-53941-inspektor-gadget-ldcache-parser-denial-of-service","title":"Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF","severity":"medium","exploited":false,"published_at":"2026-09-15T18:17:22.267+00:00","url":"https://junglewise.ai/threats/cve-2026-53941-inspektor-gadget-ldcache-parser-denial-of-service"},{"cve":"CVE-2026-77884","epss":0.0025,"slug":"cve-2026-77884-gallery-private-photo-vault-unauthenticated-http-file-exposure","title":"Gallery - Private Photo Vault unauthenticated HTTP file exposure","severity":"info","exploited":false,"published_at":"2026-09-14T19:17:44.7+00:00","url":"https://junglewise.ai/threats/cve-2026-77884-gallery-private-photo-vault-unauthenticated-http-file-exposure"},{"cve":"CVE-2026-81330","cvss":6.5,"epss":0.0009,"slug":"cve-2026-81330-c6-ear-camera-unencrypted-udp-video-transmission","title":"C6 ear camera unencrypted UDP video transmission","severity":"medium","exploited":false,"published_at":"2026-09-09T16:17:10.397+00:00","url":"https://junglewise.ai/threats/cve-2026-81330-c6-ear-camera-unencrypted-udp-video-transmission"},{"cve":"CVE-2026-81823","cvss":5.3,"epss":0.0038,"slug":"cve-2026-81823-pimboards-unauthorized-read-access-via-authentication-bypass","title":"PIMBoards unauthorized read access via authentication bypass","severity":"medium","exploited":false,"published_at":"2026-09-08T18:20:57.733+00:00","url":"https://junglewise.ai/threats/cve-2026-81823-pimboards-unauthorized-read-access-via-authentication-bypass"},{"cve":"CVE-2026-79572","cvss":7.5,"epss":0.0044,"slug":"cve-2026-79572-distribution-management-xxe-in-level-rule-module","title":"Distribution Management XXE in level-rule module","severity":"high","exploited":false,"published_at":"2026-09-08T16:18:14.9+00:00","url":"https://junglewise.ai/threats/cve-2026-79572-distribution-management-xxe-in-level-rule-module"},{"cve":"CVE-2026-82404","cvss":8.3,"epss":0.0068,"slug":"cve-2026-82404-toon-format-prototype-pollution-in-decoder","title":"TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __pro","severity":"high","exploited":false,"published_at":"2026-09-02T17:18:00.223+00:00","url":"https://junglewise.ai/threats/cve-2026-82404-toon-format-prototype-pollution-in-decoder"},{"cvss":6.9,"slug":"postgres-protocol-panic-on-malformed-hstore-value-98d63cdf","title":"postgres-protocol panic on malformed hstore value","severity":"medium","exploited":false,"published_at":"2026-08-24T19:47:49+00:00","url":"https://junglewise.ai/threats/postgres-protocol-panic-on-malformed-hstore-value-98d63cdf"},{"cve":"CVE-2026-74001","cvss":9.8,"epss":0.0061,"slug":"cve-2026-74001-user-registration-membership-pro-authentication-bypass","title":"User Registration & Membership Pro authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-20T12:16:36.94+00:00","url":"https://junglewise.ai/threats/cve-2026-74001-user-registration-membership-pro-authentication-bypass"},{"cve":"CVE-2026-16292","cvss":5.4,"epss":0.0013,"slug":"cve-2026-16292-frontend-file-manager-plugin-csrf-in-file-metadata-update","title":"Frontend File Manager Plugin CSRF in file metadata update","severity":"medium","exploited":false,"published_at":"2026-08-02T06:16:40.673+00:00","url":"https://junglewise.ai/threats/cve-2026-16292-frontend-file-manager-plugin-csrf-in-file-metadata-update"},{"cve":"CVE-2026-15262","cvss":6.8,"slug":"cve-2026-15262-admin-columns-for-acf-fields-stored-xss-in-admin-list-table","title":"Admin Columns for ACF Fields Stored XSS in admin list-table columns","severity":"info","exploited":false,"published_at":"2026-08-01T07:16:31.373+00:00","url":"https://junglewise.ai/threats/cve-2026-15262-admin-columns-for-acf-fields-stored-xss-in-admin-list-table"},{"cve":"CVE-2026-14836","cvss":8.1,"slug":"cve-2026-14836-wordpress-login-signup-popup-account-takeover-via-rate-limit","title":"WordPress Login/Signup Popup account takeover via rate limit bypass","severity":"info","exploited":false,"published_at":"2026-08-01T07:16:30.827+00:00","url":"https://junglewise.ai/threats/cve-2026-14836-wordpress-login-signup-popup-account-takeover-via-rate-limit"}],"vendor":{"hub":true,"name":"Unknown","slug":"unknown","description":"A placeholder designation used when the specific vendor of a product has not been identified.","url":"https://junglewise.ai/threats/vendors/unknown"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":21},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":13}],"most_severe":[{"cve":"CVE-1999-0192","cvss":10,"slug":"cve-1999-0192-multiple-vendors-telnetd-buffer-overflow-in-tgetent-via-termcap","title":"Multiple Vendors telnetd buffer overflow in tgetent via TERMCAP","severity":"critical","exploited":false,"published_at":"1997-10-18T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0192-multiple-vendors-telnetd-buffer-overflow-in-tgetent-via-termcap"},{"cve":"CVE-1999-0082","cvss":10,"slug":"cve-1999-0082-ftpd-unauthorized-root-access-via-cwd-root-command","title":"ftpd unauthorized root access via CWD ~root command","severity":"critical","exploited":false,"published_at":"1988-11-11T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0082-ftpd-unauthorized-root-access-via-cwd-root-command"},{"cve":"CVE-2026-74001","cvss":9.8,"epss":0.0061,"slug":"cve-2026-74001-user-registration-membership-pro-authentication-bypass","title":"User Registration & Membership Pro authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-20T12:16:36.94+00:00","url":"https://junglewise.ai/threats/cve-2026-74001-user-registration-membership-pro-authentication-bypass"},{"cve":"CVE-2026-86707","cvss":9.8,"epss":0.005,"slug":"cve-2026-86707-wordpress-private-feed-key-authentication-bypass","title":"WordPress Private Feed Key authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-17T06:16:51.213+00:00","url":"https://junglewise.ai/threats/cve-2026-86707-wordpress-private-feed-key-authentication-bypass"},{"cve":"CVE-2026-49104","cvss":9.8,"slug":"cve-2026-49104-wordpress-integration-for-keap-infusionsoft-php-object-injection","title":"WordPress Integration for Keap/Infusionsoft PHP Object Injection","severity":"critical","exploited":false,"published_at":"2026-06-15T21:17:20.4+00:00","url":"https://junglewise.ai/threats/cve-2026-49104-wordpress-integration-for-keap-infusionsoft-php-object-injection"},{"cve":"CVE-2026-82404","cvss":8.3,"epss":0.0068,"slug":"cve-2026-82404-toon-format-prototype-pollution-in-decoder","title":"TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __pro","severity":"high","exploited":false,"published_at":"2026-09-02T17:18:00.223+00:00","url":"https://junglewise.ai/threats/cve-2026-82404-toon-format-prototype-pollution-in-decoder"},{"cve":"CVE-2026-79572","cvss":7.5,"epss":0.0044,"slug":"cve-2026-79572-distribution-management-xxe-in-level-rule-module","title":"Distribution Management XXE in level-rule module","severity":"high","exploited":false,"published_at":"2026-09-08T16:18:14.9+00:00","url":"https://junglewise.ai/threats/cve-2026-79572-distribution-management-xxe-in-level-rule-module"},{"cve":"CVE-1999-0041","cvss":7.5,"slug":"cve-1999-0041-natural-language-service-nls-buffer-overflow","title":"Natural Language Service (NLS) buffer overflow","severity":"high","exploited":false,"published_at":"1997-02-13T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0041-natural-language-service-nls-buffer-overflow"},{"cve":"CVE-1999-0180","cvss":7.5,"slug":"cve-1999-0180-unix-in-rshd-authentication-bypass-via-null-username","title":"UNIX in.rshd authentication bypass via NULL username","severity":"high","exploited":false,"published_at":"1997-01-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0180-unix-in-rshd-authentication-bypass-via-null-username"},{"cve":"CVE-2026-53941","cvss":6.9,"epss":0.0052,"slug":"cve-2026-53941-inspektor-gadget-ldcache-parser-denial-of-service","title":"Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF","severity":"medium","exploited":false,"published_at":"2026-09-15T18:17:22.267+00:00","url":"https://junglewise.ai/threats/cve-2026-53941-inspektor-gadget-ldcache-parser-denial-of-service"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[]}