New CVEs
topic · security/cve-published
§01
about
Recently published CVE vulnerability records with CVSS scores (CIRCL).
§02
recent events
LIVElast event 0s ago19 evt / 1h
showing 10 of 2,902 events in this window (3,007 total on topic). adjust the range or clear it with ALL.
range
01MAL-2026-6406Malicious code in syspo (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-6406","cvss":null,"cve_id":"MA…
EVENT. cms4tmwoID. cms4tmwola7phkh0ctqo15utsSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-6406",
"cvss": null,
"cve_id": "MAL-2026-6406",
"source": "circl",
"summary": "Malicious code in syspo (npm)",
"severity": null,
"references": [
{
"url": "https://www.npmjs.com/package/syspo/v/1.0.0",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/syspo/v/1.0.1",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}02MAL-2026-10702Malicious code in discordia-telemetria (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10702","cvss":null,"cve_id":"M…
EVENT. cms4tmw4ID. cms4tmw4za7pfkh0cz6qz1lgxSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10702",
"cvss": null,
"cve_id": "MAL-2026-10702",
"source": "circl",
"summary": "Malicious code in discordia-telemetria (PyPI)",
"severity": null,
"references": [
{
"url": "https://www.virustotal.com/gui/file-analysis/ZWM2MzcwMWE4NzM5ZjY2MGYzZjBiYTY4NjA0Y2E4YmE6MTc4NDIxMDQzMA==",
"type": "WEB"
},
{
"url": "https://bad-packages.kam193.eu/pypi/package/discordia-telemetria",
"type": "WEB"
},
{
"url": "https://pypi.org/project/discordia_telemetria/0.1.1/",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}03MAL-2026-10754Malicious code in airflow-provider-spirit (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10754","cvss":null,"cve_id":"M…
EVENT. cms4tmvlID. cms4tmvlaa7pdkh0c8zl8apr7SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10754",
"cvss": null,
"cve_id": "MAL-2026-10754",
"source": "circl",
"summary": "Malicious code in airflow-provider-spirit (PyPI)",
"severity": null,
"references": [
{
"url": "https://pypi.org/project/airflow-provider-spirit/0.0.1/",
"type": "PACKAGE"
},
{
"url": "https://bad-packages.kam193.eu/pypi/package/airflow-provider-spirit",
"type": "WEB"
},
{
"url": "https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection",
"type": "EVIDENCE"
},
{
"url": "https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection",
"type": "EVIDENCE"
},
{
"url": "https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection",
"type": "EVIDENCE"
}
],
"updated_at": null,
"published_at": null
}04MAL-2026-10755Malicious code in captcha-solve-api (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10755","cvss":null,"cve_id":"M…
EVENT. cms4tmv1ID. cms4tmv1pa7pbkh0c9ne9w2pwSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10755",
"cvss": null,
"cve_id": "MAL-2026-10755",
"source": "circl",
"summary": "Malicious code in captcha-solve-api (PyPI)",
"severity": null,
"references": [
{
"url": "https://pypi.org/project/captcha-solve-api/0.0.1/",
"type": "PACKAGE"
},
{
"url": "https://bad-packages.kam193.eu/pypi/package/captcha-solve-api",
"type": "WEB"
},
{
"url": "https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection",
"type": "EVIDENCE"
},
{
"url": "https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection",
"type": "EVIDENCE"
},
{
"url": "https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection",
"type": "EVIDENCE"
}
],
"updated_at": null,
"published_at": null
}05MAL-2026-10757Malicious code in dde-common (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10757","cvss":null,"cve_id":"M…
EVENT. cms4tmuiID. cms4tmui0a7p9kh0cy2quhpfkSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10757",
"cvss": null,
"cve_id": "MAL-2026-10757",
"source": "circl",
"summary": "Malicious code in dde-common (PyPI)",
"severity": null,
"references": [
{
"url": "https://pypi.org/project/dde-common/0.0.1/",
"type": "PACKAGE"
},
{
"url": "https://bad-packages.kam193.eu/pypi/package/dde-common",
"type": "WEB"
},
{
"url": "https://www.virustotal.com/gui/file/06f1c2f0c66cf13ab6702414e8dce7c4115939f3e9cf95e9a8baade58961c016/detection",
"type": "EVIDENCE"
},
{
"url": "https://www.virustotal.com/gui/file/230f81f18608800912def92e18999874e004cd9fb4a554f759f77e4dd2030081/detection",
"type": "EVIDENCE"
},
{
"url": "https://www.virustotal.com/gui/file/c98444d6aebfd87f2f4412e1d7aafe8fe3fe080139ca1111049ea83fe828cd1d/detection",
"type": "EVIDENCE"
}
],
"updated_at": null,
"published_at": null
}06MAL-2026-10992Malicious code in dev-helper-bg (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-10992","cvss":null,"cve_id":"M…
EVENT. cms4tmtyID. cms4tmtyda7p7kh0cn5pqnck8SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-10992",
"cvss": null,
"cve_id": "MAL-2026-10992",
"source": "circl",
"summary": "Malicious code in dev-helper-bg (PyPI)",
"severity": null,
"references": [
{
"url": "https://bad-packages.kam193.eu/pypi/package/dev-helper-bg",
"type": "WEB"
},
{
"url": "https://pypi.org/project/dev-helper-bg/0.1.6/",
"type": "PACKAGE"
},
{
"url": "https://pypi.org/project/dev-helper-bg/0.1.4/",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}07MAL-2026-11047Malicious code in karpatkey (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11047","cvss":null,"cve_id":"M…
EVENT. cms4tmteID. cms4tmteta7p5kh0cmaaxa0t3SRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11047",
"cvss": null,
"cve_id": "MAL-2026-11047",
"source": "circl",
"summary": "Malicious code in karpatkey (PyPI)",
"severity": null,
"references": [
{
"url": "https://bad-packages.kam193.eu/pypi/package/karpatkey",
"type": "WEB"
},
{
"url": "https://pypi.org/project/karpatkey/2.1.1/",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}08MAL-2026-11048Malicious code in karpatkit (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11048","cvss":null,"cve_id":"M…
EVENT. cms4tmstID. cms4tmstva7p3kh0c8jl1rnuuSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11048",
"cvss": null,
"cve_id": "MAL-2026-11048",
"source": "circl",
"summary": "Malicious code in karpatkit (PyPI)",
"severity": null,
"references": [
{
"url": "https://bad-packages.kam193.eu/pypi/package/karpatkit",
"type": "WEB"
},
{
"url": "https://pypi.org/project/karpatkit/2.1.1/",
"type": "PACKAGE"
},
{
"url": "https://pypi.org/project/karpatkit/2.1.0/",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}09MAL-2026-11049Malicious code in mrmustard (PyPI){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11049","cvss":null,"cve_id":"M…
EVENT. cms4tmsaID. cms4tmsa8a7p1kh0ck3hdbj4mSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11049",
"cvss": null,
"cve_id": "MAL-2026-11049",
"source": "circl",
"summary": "Malicious code in mrmustard (PyPI)",
"severity": null,
"references": [
{
"url": "https://github.com/XanaduAI/MrMustard/issues/656",
"type": "WEB"
},
{
"url": "https://github.com/XanaduAI/MrMustard/commit/80aba721b2a902bc6efb04e3c77c3bdd28d1e716",
"type": "WEB"
},
{
"url": "https://bad-packages.kam193.eu/pypi/campaign/2026-07-compr-hw-probe",
"type": "WEB"
},
{
"url": "https://pypi.org/project/mrmustard/0.7.4/",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}10MAL-2026-11155Malicious code in xerohub-discord-voice-v3 (npm){"url":"https://www.cve.org/CVERecord?id=MAL-2026-11155","cvss":null,"cve_id":"M…
EVENT. cms4tmrqID. cms4tmrq8a7ozkh0cq6bs23hoSRC. key:cmpxakb6…
{
"url": "https://www.cve.org/CVERecord?id=MAL-2026-11155",
"cvss": null,
"cve_id": "MAL-2026-11155",
"source": "circl",
"summary": "Malicious code in xerohub-discord-voice-v3 (npm)",
"severity": null,
"references": [
{
"url": "https://www.npmjs.com/package/xerohub-discord-voice-v3/v/3.0.2",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/xerohub-discord-voice-v3/v/3.0.0",
"type": "PACKAGE"
},
{
"url": "https://www.npmjs.com/package/xerohub-discord-voice-v3/v/3.0.3",
"type": "PACKAGE"
}
],
"updated_at": null,
"published_at": null
}showing 1–10 of 2,902older →
§03
subscribe
three pathways carry every event on this topic. pick the one that fits your agent.
GETrss feed
any reader · no authhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published/feed.xmlGETjson pull
poll on your schedule · optional since/untilhttps://api.callsign.sh/v1/public/channels/security/topics/cve-published.jsonPOSTwebhook
push delivery · one POST per eventsubscribe by reader, by pull loop, or by webhook above