New CVE disclosures with patch-priority intelligence (weekly)
Weekly intelligence over newly disclosed CVEs: every CVE published by NIST NVD in the trailing 7 complete days (2026-09-18 → 2026-09-25 for this snapshot), joined with the FIRST EPSS daily 30-day exploitation-probability scores and scored for remediation triage. Each row carries the CVSS base score and severity (v3.1 preferred, then v3.0, then v2.0), exploitability metrics (attack vector / complexity / privileges required / user interaction), a remote-no-auth flag, the record's CWE ids mapped to one of 13 deterministic exploit categories, a 400-char plain-English summary, reference count, EPSS score + percentile + score date, and a documented 0-100 priority_score (45% CVSS + 35% EPSS percentile + 20% remote-exploitability bonus) ranked as disclosure_rank with p1–p4 priority tiers. Columns: ISO week, as-of date, CVE id / NVD URL / published / last-modified timestamps, summary, reference count, CVSS version/score/severity, the four exploitability metrics, remote-no-auth flag, CWE ids, exploit category, EPSS score/percentile/missing flag/score date, priority score/tier/rank, row hash. Primary key: (week, cve_id). Cadence: weekly. Nullability: cvss_* null when unrecorded; exploitability metrics null for v2-only records without a v3 vector; epss null with epss_missing=1 for CVEs absent from the EPSS feed. Caveats: ~2.5k CVEs/week — priority_score is a triage heuristic, not quantified risk; CWE coverage is incomplete; vendor/product columns were dropped (CPE configurations cover <2% of weekly disclosures). Agent-curated by intel-4 (2026-09-25): collection = keyless NVD API + EPSS CSV; transformation = dedupe + CVSS selection + CWE categorization + EPSS join + priority scoring. NVD content is public domain; EPSS is free of charge with no stated redistribution license — commercial_use = unclear. Sample use: order by disclosure_rank for this week's patch-priority list, or filter exploit_category = 'command-injection' and remote_no_auth = true for the internet-exposed RCE set.
Les titres et les descriptions proviennent des sources de données, en anglais.
- Lignes
- 2 520
- Colonnes
- 27
- Cadence de la source
- Hebdomadaire
- Dernière actualisation
- 25 sept. 2026
- Thème
- technology
| Colonne | Type | Description |
|---|---|---|
| week | string | ISO week of the trailing-7-day window (2026-W39). (unit: ISO week) |
| as_of | string | Fixed as-of date of the run; the window covers the 7 complete days ending this date. Fixed per run for hash stability. (unit: date) |
| fetched_at | string | As-of stamp of the fetch, pinned to the fixed 7-day window end (not wall-clock time) so same-window re-runs are byte-identical. ISO-8601 UTC. (unit: date-time) |
| cve_id | string | Canonical CVE id (CVE-YYYY-NNNNN). Primary key together with week. |
| cve_url | string | Canonical NVD detail URL for the CVE. (unit: url) |
| published_at | string | NVD publication timestamp (UTC). (unit: datetime) |
| last_modified_at | string | NVD last-modified timestamp (UTC). (unit: datetime) |
| description_short | string | First English NVD description, whitespace-normalized, emails redacted, truncated to 400 chars. |
| ref_count | integer | Number of reference URLs on the NVD record. (unit: count) |
| cvss_version | string | CVSS version selected for the row: 3.1 preferred, then 3.0, then 2.0; null when the record carries no CVSS. (unit: version) |
| cvss_score | float | CVSS base score (0.0–10.0) of the selected version. (unit: score) |
| cvss_severity | string | CVSS base severity of the selected version (NONE/LOW/MEDIUM/HIGH/CRITICAL); null when unrecorded. |
| attack_vector | string | CVSS attack vector (NETWORK/ADJACENT/LOCAL/PHYSICAL; v2 accessVector equivalents); null when absent. |
| attack_complexity | string | CVSS attack/access complexity; null when absent. |
| privileges_required | string | CVSS v3 privileges required; always null for v2-only records. |
| user_interaction | string | CVSS v3 user interaction; always null for v2-only records. |
| remote_no_auth | string | True when the vector is NETWORK with no privileges and no user interaction; null when exploitability metrics are absent. (unit: boolean) |
| cwe_ids | string | Comma-joined CWE ids from the record's English weaknesses, sorted ascending; empty when unrecorded. |
| exploit_category | string | Coarse exploit category from the record's CWE ids by a deterministic first-match rule set (13 values + other). Closed enum, documented in the module docstring. |
| epss | float | EPSS 30-day exploitation probability (0–1) from the daily feed; null with epss_missing=1 when the CVE is absent. (unit: probability) |
| epss_percentile | float | EPSS percentile (0–1) among all scored CVEs; null with epss_missing=1 when the CVE is absent. (unit: percentile) |
| epss_missing | boolean | 1 when the CVE had no EPSS score (0 contribution to priority_score). (unit: boolean) |
| epss_score_date | string | Score date from the EPSS CSV header (daily vintage behind every score). (unit: datetime) |
| priority_score | float | Documented 0–100 remediation-triage heuristic: 45% normalized CVSS + 35% EPSS percentile + 20% remote-exploitability bonus. Not a quantified risk measure. (unit: score) |
| priority_tier | string | Priority bucket from priority_score: p1 (>=75), p2 (>=55), p3 (>=35), p4 (below). |
| disclosure_rank | integer | 1-based rank within the week by priority_score desc, then cvss_score desc (nulls last), then cve_id asc. (unit: rank) |
| row_hash | string | SHA-256 (16 hex chars) over the row's content fields; identical input yields an identical hash. (unit: hash) |
10 premières lignes d’exemple — un aperçu, pas le jeu de données complet.
| week | as_of | fetched_at | cve_id | cve_url | published_at | last_modified_at | description_short | ref_count | cvss_version | cvss_score | cvss_severity | attack_vector | attack_complexity | privileges_required | user_interaction | remote_no_auth | cwe_ids | exploit_category | epss | epss_percentile | epss_missing | epss_score_date | priority_score | priority_tier | disclosure_rank | row_hash |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-94097 | https://nvd.nist.gov/vuln/detail/CVE-2026-94097 | 2026-09-21T00:16:59Z | 2026-09-24T13:17:17Z | A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about… | 5 | 3.1 | 10 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-74,CWE-77 | command-injection | 0,036 | 0,89 | false | 2026-09-24T12:00:20Z | 96,17 | p1 | 1 | 0e36f15e968bc78b |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-74849 | https://nvd.nist.gov/vuln/detail/CVE-2026-74849 | 2026-09-22T12:17:14Z | 2026-09-23T04:17:44Z | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | 1 | 3.1 | 9,8 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-78 | command-injection | 0,046 | 0,913 | false | 2026-09-24T12:00:20Z | 96,06 | p1 | 2 | b162a3cb93c1a0e6 |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-95675 | https://nvd.nist.gov/vuln/detail/CVE-2026-95675 | 2026-09-22T14:17:22Z | 2026-09-22T20:25:55Z | D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the… | 3 | 3.1 | 9,8 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-78 | command-injection | 0,039 | 0,899 | false | 2026-09-24T12:00:20Z | 95,56 | p1 | 3 | 3961cc0bf0ae9ba7 |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-84434 | https://nvd.nist.gov/vuln/detail/CVE-2026-84434 | 2026-09-19T03:17:15Z | 2026-09-21T13:33:33Z | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without… | 2 | 3.1 | 9,8 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-434 | file-upload | 0,035 | 0,887 | false | 2026-09-24T12:00:20Z | 95,13 | p1 | 4 | 8af8e04359b0fc0a |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-43641 | https://nvd.nist.gov/vuln/detail/CVE-2026-43641 | 2026-09-22T18:17:14Z | 2026-09-23T16:16:43Z | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field,… | 4 | 3.1 | 9,8 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-78 | command-injection | 0,03 | 0,869 | false | 2026-09-24T12:00:20Z | 94,52 | p1 | 5 | a50c9d358f59d74b |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-93616 | https://nvd.nist.gov/vuln/detail/CVE-2026-93616 | 2026-09-22T13:17:11Z | 2026-09-23T16:38:38Z | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | 3 | 3.1 | 9,8 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-22 | path-traversal | 0,024 | 0,835 | false | 2026-09-24T12:00:20Z | 93,31 | p1 | 6 | 36d1e672d407d12c |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-94089 | https://nvd.nist.gov/vuln/detail/CVE-2026-94089 | 2026-09-20T21:16:55Z | 2026-09-22T16:18:16Z | A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | 6 | 3.1 | 10 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-119,CWE-121 | memory-corruption | 0,019 | 0,79 | false | 2026-09-24T12:00:20Z | 92,64 | p1 | 7 | 59fccced37c76b70 |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-80155 | https://nvd.nist.gov/vuln/detail/CVE-2026-80155 | 2026-09-22T16:18:01Z | 2026-09-24T20:17:31Z | Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows unauthenticated attackers to read sensitive configuration files and upload files to arbitrary filesystem locations, leading… | 6 | 3.1 | 10 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-22 | path-traversal | 0,016 | 0,744 | false | 2026-09-24T12:00:20Z | 91,04 | p1 | 8 | fa671ba0276aaa36 |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-94493 | https://nvd.nist.gov/vuln/detail/CVE-2026-94493 | 2026-09-22T01:16:56Z | 2026-09-24T23:19:22Z | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | 5 | 3.1 | 10 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-287,CWE-306 | access-control | 0,013 | 0,701 | false | 2026-09-24T12:00:20Z | 89,53 | p1 | 9 | 88854b681d37d938 |
| 2026-W39 | 2026-09-25 | 2026-09-25T00:00:00Z | CVE-2026-6721 | https://nvd.nist.gov/vuln/detail/CVE-2026-6721 | 2026-09-23T21:17:01Z | 2026-09-25T04:17:38Z | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation allows remote code execution with the privileges of the affected application. | 1 | 3.1 | 9,8 | CRITICAL | NETWORK | LOW | NONE | NONE | true | CWE-78 | command-injection | 0,014 | 0,722 | false | 2026-09-24T12:00:20Z | 89,37 | p1 | 10 | 7f24db566d896aaf |
Profilé le 25 sept. 2026 à partir de l’instantané 20260925T085206Z-cff1008e4bcf
Mesuré- Complétude
- 92,6 %
- Lignes
- 2 520
- Colonnes
- 27
- Colonnes incomplètes
- 10
| Colonne | Manquant | Distinctes | Plage | Distribution |
|---|---|---|---|---|
| weekvarchar | 0 % | 1 | — |
|
| as_ofvarchar | 0 % | 1 | — |
|
| fetched_atvarchar | 0 % | 1 | — |
|
| cve_idvarchar | 0 % | 2 383 | — |
|
| cve_urlvarchar | 0 % | 2 480 | — |
|
| published_atvarchar | 0 % | 834 | — |
|
| last_modified_atvarchar | 0 % | 474 | — |
|
| description_shortvarchar | 0 % | 2 765 | — |
|
| ref_countbigint | 0 % | 20 | 0 → 18médiane 3 | 43 hors du 1er–99e centile |
| cvss_versionvarchar | 20 % | 2 | — |
|
| cvss_scoredouble | 20 % | 61 | 2 → 10médiane 7,1 | 14 hors du 1er–99e centile |
| cvss_severityvarchar | 20 % | 4 | — |
|
| attack_vectorvarchar | 20 % | 4 | — |
|
| attack_complexityvarchar | 20 % | 2 | — |
|
| privileges_requiredvarchar | 20 % | 3 | — |
|
| user_interactionvarchar | 20 % | 2 | — |
|
| remote_no_authboolean | 20 % | 2 | — |
|
| cwe_idsvarchar | 0 % | 464 | — |
|
| exploit_categoryvarchar | 0 % | 13 | — |
|
| epssdouble | 20,4 % | 741 | 0,0006 → 0,0461médiane 0,0035 | 40 hors du 1er–99e centile |
| epss_percentiledouble | 20,4 % | 1 816 | 0,0001 → 0,9132médiane 0,2594 | 42 hors du 1er–99e centile |
| epss_missingboolean | 0 % | 2 | — |
|
| epss_score_datevarchar | 0 % | 1 | — |
|
| priority_scoredouble | 0 % | 1 535 | 0 → 96,17médiane 46,3 | 26 hors du 1er–99e centile |
| priority_tiervarchar | 0 % | 4 | — |
|
| disclosure_rankbigint | 0 % | 2 558 | 1 → 2 520médiane 1 261 | 52 hors du 1er–99e centile |
| row_hashvarchar | 0 % | 2 452 | — |
|
- Actuelle
20260925T085206Z-cff1008e4bcf · sha256 cff1008e4bcf…
2 520 lignes · premier instantané
Dirigez n’importe quel LLM vers le point d’accès des métadonnées — la documentation ci-dessus est aussi lisible par machine (JSON-LD + Croissant).
curl "https://datazimuts.com/v1/datasets/nvd_disclosure_signals/nvd_weekly_cve_disclosures" | jq '{title, rows, columns_count, license}'import requests
ds = requests.get("https://datazimuts.com/v1/datasets/nvd_disclosure_signals/nvd_weekly_cve_disclosures").json()
print(ds["title"], ds["rows"], "rows")
# Sample rows for an LLM context window
for row in ds.get("sample_rows", [])[:5]:
print(row)Point d’accès API : https://datazimuts.com/v1/datasets/nvd_disclosure_signals/nvd_weekly_cve_disclosures
Astuce : récupérez /llms.txt pour le catalogue complet lisible par machine.
D’où viennent ces données et ce qui en a été fait. Le travail des autres apparaît sous forme de décomptes ; seuls les projets partagés sont nommés.
Citer cet instantané
Épinglé à l’instantané 20260925T085206Z-cff1008e4bcf et à son empreinte, pour que vos lecteurs obtiennent exactement les données utilisées.
NVD CVE disclosures + FIRST EPSS (agent-curated). (2026). New CVE disclosures with patch-priority intelligence (weekly) [Data set, snapshot 20260925T085206Z-cff1008e4bcf, sha256 cff1008e4bcf]. Datazimuts. Retrieved 2026-09-25, from https://datazimuts.com/fr/datasets/nvd_disclosure_signals/nvd_weekly_cve_disclosures?snapshot=20260925T085206Z-cff1008e4bcf
@misc{dz_nvd_disclosure_signals_nvd_weekly_cve_di_cff1008e,
title = {{New CVE disclosures with patch-priority intelligence (weekly)}},
author = {{NVD CVE disclosures + FIRST EPSS (agent-curated)}},
year = {2026},
publisher = {Datazimuts},
howpublished = {\url{https://datazimuts.com/fr/datasets/nvd_disclosure_signals/nvd_weekly_cve_disclosures?snapshot=20260925T085206Z-cff1008e4bcf}},
note = {Snapshot 20260925T085206Z-cff1008e4bcf, sha256 cff1008e4bcfed83a24416bfa537946728f629793ebf65a225d0e0826ea26faf; accessed 2026-09-25}
}Intégrer un tableau ou un graphique
Collez ce code dans n’importe quelle page. L’intégration est épinglée au même instantané, suit le thème clair ou sombre du lecteur et affiche toujours la source, la licence et un lien de retour.
<iframe src="https://datazimuts.com/embed/chart?dataset=nvd_disclosure_signals%2Fnvd_weekly_cve_disclosures&lang=fr&theme=auto&snapshot=20260925T085206Z-cff1008e4bcf&x=epss_score_date&y=ref_count&agg=avg" title="New CVE disclosures with patch-priority intelligence (weekly)" width="100%" height="380" style="border:0" loading="lazy"></iframe>
Posez une question sur ce jeu de données. Les réponses viennent uniquement de sa fiche, de son profil mesuré et de son historique, et citent les faits utilisés.