AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0079 54.9 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 10 Reserved by CNA Oct 7 Published (CNA: ibm)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
330 CVEs published, led by Cisco (36).
330 CVEs published October 7, 2026: 47 critical, 110 high, 149 medium, 9 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 15 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 305 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 2733 | 52725 | — | — |
| KEV catalog size | 1734 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3426 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 210 | 6415 | 532 | 2690 | 737 | 1 | 15 | 6 | 0.1 | 7.8 | .0018 | +22 ▲ |
| 291 | 3122 | 380 | 1197 | 1368 | 137 | 80 | 9 | 0.3 | 7.5 | .0026 | +253 ▲ | |
| microsoft | 12 | 2913 | 203 | 1999 | 694 | 17 | 290 | 31 | 1.1 | 7.8 | .0047 | +3 ▲ |
| red hat | 80 | 979 | 54 | 394 | 475 | 56 | 2 | 0 | 0.0 | 6.5 | .0034 | +37 ▲ |
| apple | 0 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | 0 |
| suse | 0 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | -9 ▼ |
| canonical | 2 | 52 | 16 | 12 | 19 | 5 | 0 | 0 | 0.0 | 7.8 | .0022 | +2 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 36 | 218 | 69 | 85 | 63 | 1 | 60 | 17 | 7.8 | 8.4 | .0046 | +25 ▲ |
| ubiquiti | 0 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | 0 |
| palo alto networks | 0 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | 0 |
| fortinet | 1 | 42 | 12 | 10 | 17 | 3 | 30 | 8 | 19.0 | 7.2 | .0040 | +1 ▲ |
| netgear | 0 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | 0 |
| f5 | 0 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | -7 ▼ |
| ivanti | 0 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | 0 |
| sonicwall | 4 | 23 | 8 | 10 | 5 | 0 | 19 | 4 | 17.4 | 7.8 | .0050 | -1 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 118 | 825 | 169 | 373 | 260 | 21 | 33 | 2 | 0.2 | 7.5 | .0057 | +109 ▲ |
| mozilla | 2 | 381 | 123 | 170 | 87 | 0 | 9 | 0 | 0.0 | 8.8 | .0031 | -32 ▼ |
| gitlab | 2 | 106 | 8 | 24 | 63 | 11 | 5 | 3 | 2.8 | 5.3 | .0035 | +2 ▲ |
| drupal | 0 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | -26 ▼ |
| github | 2 | 25 | 2 | 12 | 11 | 0 | 0 | 0 | 0.0 | 7.4 | .0052 | -1 ▼ |
| docker | 3 | 15 | 1 | 9 | 5 | 0 | 0 | 0 | 0.0 | 7.6 | .0018 | +3 ▲ |
| wordpress | 0 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0392 | 0 |
| eclipse | 0 | 2 | 2 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.3 | .0050 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | 0 |
| ibm | 24 | 1047 | 195 | 493 | 341 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | -46 ▼ |
| adobe | 0 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | -3 ▼ |
| progress | 7 | 73 | 16 | 43 | 13 | 1 | 6 | 1 | 1.4 | 8.0 | .0045 | +5 ▲ |
| zohocorp | 0 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | -5 ▼ |
| solarwinds | 0 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | 0 |
| veeam | 6 | 25 | 7 | 11 | 7 | 0 | 1 | 0 | 0.0 | 8.5 | .0036 | +6 ▲ |
| atlassian | 1 | 10 | 2 | 8 | 0 | 0 | 13 | 0 | 0.0 | 7.8 | .0043 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | -6 ▼ |
| siemens | 0 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -1 ▼ |
| synology | 0 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | 0 |
| rockwell automation | 0 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | -18 ▼ |
| advantech | 0 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | -2 ▼ |
| schneider electric | 0 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | -4 ▼ |
| hitachi energy | 0 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0025 | -4 ▼ |
| abb | 0 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 22 | 400 | 42 | 179 | 157 | 22 | 2 | 1 | 0.3 | 7.2 | .0027 | -33 ▼ |
| nvidia | 2 | 303 | 25 | 207 | 71 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | -28 ▼ |
| sourcecodester | 17 | 254 | 0 | 0 | 149 | 105 | 0 | 0 | 0.0 | 5.5 | .0041 | -9 ▼ |
| openclaw | 0 | 223 | 4 | 114 | 84 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| hewlett packard enterprise (hpe) | 38 | 204 | 39 | 92 | 64 | 9 | 1 | 1 | 0.5 | 7.3 | .0042 | -48 ▼ |
| mongodb | 1 | 170 | 6 | 99 | 60 | 5 | 1 | 0 | 0.0 | 7.1 | .0037 | -9 ▼ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| itsourcecode | 14 | 167 | 0 | 0 | 42 | 125 | 0 | 0 | 0.0 | 2.1 | .0033 | -8 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9296 | 99.8 | 10.0 |
| CVE-2026-87902 | .4612 | 98.8 | 8.1 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.5 | 10.0 |
| CVE-2026-85102 | .0755 | 94.4 | 9.8 |
| CVE-2026-12269 | .0699 | 94.0 | 8.8 |
| CVE-2026-77692 | .0656 | 93.6 | 7.5 |
| CVE-2026-17176 | .0497 | 92.0 | 7.7 |
| CVE-2026-12268 | .0473 | 91.6 | 8.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9296 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-105484 | 10.0 | .0213 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 | |
| CVE-2026-75703 | 10.0 | .0125 | |
| CVE-2026-75721 | 10.0 | .0125 | |
| CVE-2026-84412 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2137 |
| microsoft | 1005 |
| 915 | |
| oracle | 634 |
| ibm | 358 |
| apache | 304 |
| red hat | 301 |
| apple | 247 |
| adobe | 221 |
| dell | 174 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 17 |
| apple | 9 |
| 9 | |
| fortinet | 8 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 131 |
| NuGet | 30 |
| Packagist | 25 |
| npm | 25 |
| PyPI | 19 |
| Go | 12 |
| crates.io | 10 |
| RubyGems | 4 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-88779 | NetScaler | 0 |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-102489 | Zammad GmbH | 1 |
| CVE-2026-102490 | Zammad GmbH | 1 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1785 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1785 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1785 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1785 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1785 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1785 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1785 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1785 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1785 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1785 |
EXPLOIT PUBLISHED — x-stream xstream: 23 CVEs (CVE-2020-26217, CVE-2020-26258, CVE-2020-26259, CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351, CVE-2021-39140, CVE-2021-39141, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154). Public exploit references added.
EXPLOIT PUBLISHED — jpadilla pyjwt: 5 CVEs (CVE-2026-101917, CVE-2026-101918, CVE-2026-102265, CVE-2026-102266, CVE-2026-102268). Public exploit references added.
EXPLOIT PUBLISHED — docling-project docling: 3 CVEs (CVE-2026-105742, CVE-2026-105744, CVE-2026-105748). Public exploit references added.
EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-55653, CVE-2026-90462, CVE-2026-90996). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2014-0050. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2015-6420. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2016-1000027. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2017-16138 (HackerOne mime node module). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2018-20852. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-16935. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-5010 (Python). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-9740. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-9947. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2019-9948. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2020-15250 (junit-team junit4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2020-8492. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2020-9054 (ZyXEL NAS326). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2021-29425 (Apache Software Foundation Apache Commons IO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-0235 (node-fetch/node-fetch). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-2596 (node-fetch/node-fetch). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-42003. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-42004. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-22894. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-50572. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-1102 (jberet). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-14611 (Gladinet CentreStack and TrioFox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-25249 (Fortinet FortiSwitchManager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104973 (makeplane plane). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-10520 (ivanti Sentry). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105226 (osCommerce2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105232 (kishor-23 food-waste-management-system). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105245 (sgl-project sglang). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105254 (itsourcecode Online Admission System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105286 (Totolink A3002MU). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105290 (feelec-yishu feelcrm-os). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105329 (TallCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105385 (onetwothreeneth HospitalManagementSystem). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105389 (feelec-yishu feelcrm-os). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105468 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105472 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105571 (PickMall Lilishop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105611 (chillzhuang SpringBlade). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105705 (SourceCodester Drug Recommendation System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-106214 (Google Chrome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48558 (SimpleHelp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55255 (langflow-ai langflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-69147 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77226 (Camunda 7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81914 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86843 (Apache Software Foundation Apache Airflow Teradata provider). Public exploit reference added.
REJECTED — CVE-2026-39768 (CleanTalk Inc Security & Malware scan by CleanTalk). Record withdrawn by the CNA.
RESCORED — x-stream xstream: 15 CVEs (CVE-2020-26217, CVE-2020-26258, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351, CVE-2021-29505, CVE-2021-39139, CVE-2021-39140). CVSS rescored — before/after on each CVE page.
RESCORED — docling-project docling: 5 CVEs (CVE-2026-105742, CVE-2026-105744, CVE-2026-105745, CVE-2026-105746, CVE-2026-105750). CVSS rescored — before/after on each CVE page.
RESCORED — BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS: 4 CVEs (CVE-2021-39297, CVE-2021-39299, CVE-2021-39300, CVE-2021-39301). CVSS rescored — before/after on each CVE page.
RESCORED — jpadilla pyjwt: 4 CVEs (CVE-2026-101917, CVE-2026-101918, CVE-2026-102266, CVE-2026-102267). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2018-14647 (The Python Project Python). CVSS 5.3 → 7.5 (NVD).
RESCORED — CVE-2019-16056. CVSS 5.3 → 7.5 (NVD).
RESCORED — CVE-2019-18348. CVSS 5.4 → 6.1 (NVD).
RESCORED — CVE-2019-20907. CVSS 5.5 → 7.5 (NVD).
RESCORED — CVE-2019-5010 (Python). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2019-9636. CVSS 5.3 → 9.8 (NVD).
RESCORED — CVE-2019-9740. CVSS 6.5 → 6.1 (NVD).
RESCORED — CVE-2019-9947. CVSS 5.4 → 6.1 (NVD).
RESCORED — CVE-2020-10735 (python). CVSS 6.2 → 7.5 (NVD).
RESCORED — CVE-2020-15250 (junit-team junit4). CVSS 4.4 → 5.5 (NVD).
RESCORED — CVE-2021-29425 (Apache Software Foundation Apache Commons IO). CVSS 6.5 → 4.8 (NVD).
RESCORED — CVE-2021-36342 (Dell CPG BIOS). CVSS 7.5 → 6.4 (NVD).
RESCORED — CVE-2021-36343 (Dell CPG BIOS). CVSS 7.5 → 6.4 (NVD).
RESCORED — CVE-2021-39298 (AMD 2nd Gen EPYC). CVSS 6.5 → 8.8 (NVD).
RESCORED — CVE-2022-0235 (node-fetch/node-fetch). CVSS 8.8 → 6.1 (NVD).
RESCORED — CVE-2023-22894. CVSS 9.8 → 4.9 (NVD).
RESCORED — CVE-2023-43086 (Dell Command Configure (DCC)). CVSS 7.3 → 7.8 (NVD).
RESCORED — CVE-2025-21043 (Samsung Mobile Devices). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2025-32151 (Themekraft BuddyForms). CVSS 7.5 → 8.8 (NVD).
RESCORED — CVE-2025-5154 (PhonePe App). CVSS 4.6 → 1.8 (NVD).
RESCORED — CVE-2025-9000 (Mechrevo Control Center GX V2). CVSS 7.3 → 6.4 (NVD).
RESCORED — CVE-2025-9016 (Mechrevo Control Center GX V2). CVSS 7.3 → 6.4 (NVD).
RESCORED — CVE-2026-10542 (Mattermost). CVSS 5 → 4.3 (NVD).
RESCORED — CVE-2026-12985 (Mattermost). CVSS 6.8 → 9.3 (NVD).
RESCORED — CVE-2026-18074 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.2 → 7.5 (NVD).
RESCORED — CVE-2026-18095 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.5 → 8.8 (NVD).
RESCORED — CVE-2026-18114 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2026-18123 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 7.6 → 7.5 (NVD).
RESCORED — CVE-2026-18131 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.2 → 6.1 (NVD).
RESCORED — CVE-2026-18133 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 5.4 → 6.5 (NVD).
RESCORED — CVE-2026-62874 (Microsoft Azure Billing). CVSS 10 → 9.8 (NVD).
RESCORED — CVE-2026-78446 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 7.5 (NVD).
RESCORED — CVE-2026-78501 (Microsoft 365 Copilot's Business Chat). CVSS 7.4 → 8.6 (NVD).
RESCORED — CVE-2026-90996 (Red Hat Enterprise Linux 10). CVSS 4 → 5.5 (NVD).
PATCH SHIPPED — CVE-2026-105326 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.4.19-4.3.hum1.
PATCH SHIPPED — CVE-2026-42708 (AF themes WP Post Author). Fixed in WP Post Author 4.0.1.
PATCH SHIPPED — CVE-2026-57737 (Averta LTD Shortcodes and extra features for Phlox theme). Fixed in Shortcodes and extra features for Phlox theme 2.17.24.
PATCH SHIPPED — CVE-2026-85234 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 0:5.2-28.el8_10.
ENRICHED — Google Chrome: 3 CVEs (CVE-2026-106237, CVE-2026-106324, CVE-2026-106326). Received CVSS/CPE analysis.
ENRICHED — Linux: 3 CVEs (CVE-2026-63986, CVE-2026-63990, CVE-2026-63991). Received CVSS/CPE analysis.
How to read these box scores · glossary
330 CVEs published. 25 box scores, 305 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0079 54.9 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 10 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 53.7 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 18 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0068 50.8 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 18 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 50.5 —
AFFECTED Product Versions Fixed LMCache 0.3.9 – —
TIMELINE Oct 4 Reserved by CNA Oct 7 Published (CNA: JFROG)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 9.2 .0065 49.7 —
AFFECTED Product Versions Fixed ADM 5.0.0 – —
TIMELINE Oct 5 Reserved by CNA Oct 7 Published (CNA: ASUSTOR1)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0064 49.0 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 17 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0061 47.5 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 17 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N C H H H 8.5 .0058 46.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 17 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0058 46.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 17 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N L 4.3 .0047 38.6 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 18 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N N 7.7 .0046 37.8 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 18 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P H P N L N 2.0 .0045 37.2 —
AFFECTED Product Versions Fixed Apache YuniKorn unspecified —
TIMELINE Sep 16 Reserved by CNA Oct 7 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0045 36.8 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 24 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0043 35.8 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 24 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0043 35.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 17 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H N 9.3 .0042 34.6 —
AFFECTED Product Versions Fixed Multi-tenant ERP System version – —
TIMELINE Oct 7 Reserved by CNA Oct 7 Published (CNA: CERT-In)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H N L 7.6 .0038 30.2 —
AFFECTED Product Versions Fixed Dynamic User Directory unspecified —
TIMELINE Apr 29 Reserved by CNA Oct 7 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C H N L 7.6 .0038 30.2 —
AFFECTED Product Versions Fixed affiliate-toolkit unspecified —
TIMELINE Apr 29 Reserved by CNA Oct 7 Published (CNA: Patchstack)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L H L 7.6 .0038 30.1 —
AFFECTED Product Versions Fixed Langflow OSS 1.0.0 – —
TIMELINE Sep 18 Reserved by CNA Oct 7 Published (CNA: ibm)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0037 29.3 —
AFFECTED Product Versions Fixed String locator unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 7 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0037 29.0 —
AFFECTED Product Versions Fixed FlexNet Publisher unspecified —
TIMELINE Aug 11 Reserved by CNA Oct 7 Published (CNA: flexera)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 8.3 .0037 28.8 —
AFFECTED Product Versions Fixed Backup and Replication 12 – —
TIMELINE Jun 28 Reserved by CNA Oct 7 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0037 28.8 —
AFFECTED Product Versions Fixed WP Coder 4.0 – —
TIMELINE Oct 2 Reserved by CNA Oct 7 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0037 28.4 —
AFFECTED Product Versions Fixed Kirki – Freeform Page Builder, Website Builder & Customizer unspecified —
TIMELINE Sep 28 Reserved by CNA Oct 7 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P N L N 4.8 .0037 28.3 —
AFFECTED Product Versions Fixed Apache YuniKorn unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 7 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2025-64393 | 9.4 | 27.7 | Veeam | Backup and Replication | CWE-502 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to ex… |
| CVE-2025-64392 | 4.8 | 25.1 | Veeam | Backup Enterprise Manager | CWE-79 | This vulnerability in Veeam Backup Enterprise Manager allows an attacker to e… |
| CVE-2026-83540 | 7.7 | 25.0 | wolfSSL | wolfSSH | CWE-287 | wolfSSHd on Windows race condition leading to logon token reused across conne… |
| CVE-2026-83742 | 5.3 | 24.1 | wolfSSL Inc. | wolfSSH | CWE-121 | wstrncat() unsigned integer underflow leads to an off-by-one null write in wo… |
| CVE-2026-107103 | 9.3 | 23.6 | Manacle Technologies | Multi-tenant ERP System | CWE-89 | SQL Injection Vulnerability in Manacle Technologies ERP System |
| CVE-2026-14911 | 9.3 | 22.8 | ASUS | Router | CWE-79 | Improper Neutralization of Input During Web Page Generation (“Cross-site Scri… |
| CVE-2026-15894 | 8.8 | 21.6 | zephyrproject | zephyr | CWE-121 | Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertise… |
| CVE-2026-84897 | 6.9 | 20.9 | wolfSSL Inc. | wolfSSH | CWE-372 | wolfSSH server accepts server-to-client DH group exchange messages from an un… |
| CVE-2026-93026 | 6.1 | 20.7 | Veeam | Backup and Replication | CWE-862 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to mo… |
| CVE-2026-102478 | 8.7 | 20.3 | Octopus Deploy | Octopus Server | CWE-1289 | In affected versions of Octopus Server, an authenticated user with permission… |
| CVE-2026-27434 | 5.3 | 20.1 | sc Internet Vivoo | WP Rentals | CWE-862 | WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability |
| CVE-2026-5703 | 7.1 | 19.9 | Satel Iberia | SenNet Datalogger Serie 200 | CWE-35 | Path Traversal in Satel Iberia SenNet Datalogger Serie 200 |
| CVE-2026-106471 | 8.1 | 18.6 | Red Hat | Red Hat Satellite 6 | CWE-863 | Candlepin: candlepin: broken object-level authorization via verifyauthorizati… |
| CVE-2026-102782 | 9.3 | 18.5 | ordasoft.com | OrdaSoft Simple Membership extension for Joomla | CWE-89 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft S… |
| CVE-2026-81535 | 6.3 | 18.4 | wolfSSL Inc. | wolfSSH | CWE-862 | wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without … |
| CVE-2026-103075 | 4.3 | 16.1 | WPMU DEV | Hustle | CWE-862 | WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability |
| CVE-2026-59346 | 9.3 | 16.0 | VMware | VMware Workstation | CWE-190 | VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability |
| CVE-2026-107102 | 9.3 | 15.7 | Manacle Technologies | Multi-tenant ERP System | CWE-345 | Account Takeover Vulnerability in Manacle Technologies ERP System |
| CVE-2026-78243 | 2.1 | 15.1 | Apache Software Foundation | Apache YuniKorn | CWE-248 | Apache YuniKorn: LDAP Group provider panics on lowercase attribute name |
| CVE-2026-89417 | 7.2 | 14.6 | daanvandenbergh | OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. | CWE-79 | OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthent… |
| CVE-2026-105876 | 5.3 | 14.5 | WP Chill | Modula Image Gallery | CWE-862 | WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vul… |
| CVE-2026-102781 | 6.9 | 13.8 | ordasoft.com | Touch Slider extension for Joomla | CWE-284 | Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSof… |
| CVE-2026-104652 | 6.8 | 13.3 | Unknown | Envira Gallery | CWE-79 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID |
| CVE-2026-104653 | 6.8 | 13.3 | Unknown | Envira Gallery | CWE-79 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions |
| CVE-2026-103870 | 5.0 | 13.0 | Red Hat | Red Hat Satellite 6 | CWE-22 | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids |
| CVE-2026-87782 | 8.8 | 12.9 | Unknown | Koinonia Link | CWE-269 | Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator |
| CVE-2026-86816 | 5.3 | 12.9 | Unknown | WPCafe | CWE-200 | WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API |
| CVE-2026-104667 | 6.8 | 12.7 | Unknown | Animated Number Counters | CWE-89 | Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order |
| CVE-2026-104953 | 6.8 | 12.7 | Unknown | MPG | CWE-89 | MPG < 4.2.3 - Editor+ SQLi via Project Import |
| CVE-2026-103868 | 6.5 | 12.4 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-488 | Pulp-container: registry credentials are reused across remotes in a worker |
| CVE-2026-103869 | 6.5 | 12.4 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-488 | Pulp-ansible: bearer tokens are reused across remotes in a worker |
| CVE-2026-97294 | 6.5 | 12.0 | David Lingren | Media LIbrary Assistant | CWE-79 | WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS)… |
| CVE-2026-104391 | 6.5 | 12.0 | ExpressTech | Quiz And Survey Master | CWE-79 | WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS… |
| CVE-2026-104393 | 6.5 | 12.0 | weDevs | Happy Addons for Elementor | CWE-79 | WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting … |
| CVE-2026-105884 | 6.5 | 12.0 | WP Media | Rocket Lazy Load | CWE-79 | WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-96530 | 6.5 | 11.3 | Unknown | Optimole | CWE-200 | Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard… |
| CVE-2026-104390 | 4.3 | 10.6 | Arraytics | Booktics | CWE-862 | WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability |
| CVE-2026-19186 | 8.1 | 10.6 | zephyrproject | zephyr | CWE-191 | Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds re… |
| CVE-2026-105871 | 6.5 | 10.5 | BdThemes | Element Pack Elementor Addons | CWE-79 | WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scriptin… |
| CVE-2026-105873 | 6.5 | 10.5 | BdThemes | Element Pack Elementor Addons | CWE-79 | WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scriptin… |
| CVE-2026-105875 | 6.5 | 10.5 | BdThemes | Prime Slider – Addons For Elementor | CWE-79 | WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Sc… |
| CVE-2026-103416 | 9.3 | 10.2 | Eclipse Foundation | Eclipse ThreadX - NetX Duo | CWE-787 | Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Ec… |
| CVE-2026-16528 | 8.4 | 9.9 | ASUS | Router | CWE-532 | Insertion of Sensitive Information into Log File in certain ASUS router model… |
| CVE-2026-59347 | 8.1 | 9.9 | VMware | VMware Workstation | CWE-121 | VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability |
| CVE-2026-97720 | 9.1 | 8.5 | Apache Software Foundation | Apache Impala | CWE-303 | Apache Impala: Impala Executor Webserver Auth Bypass |
| CVE-2026-90466 | 6.5 | 8.5 | Apache Software Foundation | Apache Impala | CWE-23 | Apache Impala: Path traversal executes JARs outside trusted paths |
| CVE-2026-105322 | 5.3 | 8.3 | Unknown | Magee Shortcodes | CWE-472 | Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form |
| CVE-2026-19386 | 9.3 | 8.1 | ASUS | Router | CWE-121 | A stack-based buffer overflow in the ASUS router modules allows an authentica… |
| CVE-2026-82211 | 8.2 | 7.6 | Unknown | Nexi XPay Build | CWE-862 | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key D… |
| CVE-2026-93684 | 5.4 | 7.6 | Apache Software Foundation | Apache Impala | CWE-79 | Apache Impala: Stored XSS in Impala query plans |
| CVE-2026-97354 | 4.1 | 6.8 | Unknown | PowerPress Podcasting plugin by Blubrry | CWE-918 | PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects |
| CVE-2026-97331 | 4.3 | 6.6 | Unknown | User Private Files | CWE-200 | User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dp… |
| CVE-2026-104678 | 2.7 | 5.6 | Unknown | CP Media Player | CWE-284 | CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update |
| CVE-2026-105316 | 7.1 | 5.1 | Unknown | Magee Shortcodes | CWE-79 | Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_s… |
| CVE-2026-86833 | 5.4 | 4.8 | Unknown | MetForm | CWE-74 | MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via F… |
| CVE-2026-16516 | 9.0 | 3.6 | wolfSSL Inc. | wolfSSH | CWE-345 | wolfSSH ECDSA host key curve not validated against negotiated algorithm |
| CVE-2026-87971 | 7.1 | 3.3 | Unknown | If-So Dynamic Content | CWE-79 | If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter |
| CVE-2026-103378 | 6.5 | 3.3 | Unknown | Geliver Akıllı Kargo Pazaryeri | CWE-200 | Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclo… |
| CVE-2026-103323 | 5.9 | 2.6 | Unknown | Integration for Epos Now and WooCommerce | CWE-862 | Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Act… |
| CVE-2026-103681 | 4.3 | 2.4 | Unknown | Frontend Dashboard | CWE-284 | Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via … |
| CVE-2026-104049 | 4.3 | 2.4 | Unknown | Academy LMS | CWE-639 | Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Top… |
| CVE-2026-104050 | 4.3 | 2.4 | Unknown | Academy LMS | CWE-639 | Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via ren… |
| CVE-2026-104651 | 4.3 | 2.4 | Unknown | Yaad Sarig Payment Gateway For WC | CWE-639 | Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Paym… |
| CVE-2026-82212 | 7.5 | 2.3 | Unknown | Nexi XPay Build | CWE-345 | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notificatio… |
| CVE-2026-19396 | 7.7 | 2.1 | ASUS | Router | CWE-337 | A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT … |
| CVE-2025-64391 | 4.1 | 1.5 | Veeam | Agent for Windows | CWE-1386 | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileg… |
| CVE-2026-106061 | 5.5 | 1.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on craft… |
| CVE-2026-58068 | 6.8 | 0.8 | Veeam | Agent for Windows | CWE-862 | This vulnerability in Veeam Agent for Microsoft Windows allows any local user… |
| CVE-2026-107121 | 6.5 | 0.2 | Red Hat | Red Hat Build of Keycloak | CWE-319 | Keycloak-services: keycloak-services: smtp starttls plaintext credential and … |
| CVE-2025-70518 | 10.0 | — | n/a | n/a | CWE-77 | The management portal's diagnostic ping tool of Fanvil x7a firmware version 2… |
| CVE-2026-76482 | 10.0 | — | Cisco | Cisco License On-Prem | CWE-347 | Cisco License On-Prem Security Hardening Release |
| CVE-2026-102255 | 10.0 | — | SonicWall | SMA1000 | CWE-441 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work … |
| CVE-2025-70521 | 9.8 | — | n/a | n/a | CWE-77 | The management portal's diagnostic ping tool of Fanvil x7a firmware version 2… |
| CVE-2026-62252 | 9.8 | — | sipcapture | homer | CWE-798 | Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on… |
| CVE-2026-62253 | 9.8 | — | sipcapture | homer | CWE-306 | Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (D… |
| CVE-2026-76268 | 9.8 | — | Splunk | Splunk Enterprise | CWE-306 | Missing Authentication for Critical Function in the Patroni REST API in Splun… |
| CVE-2026-76455 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-284 | Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Acce… |
| CVE-2026-76465 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-590 | Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vuln… |
| CVE-2026-76471 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-122 | Cisco NX-OS Software NX-API Remote Code Execution Vulnerability |
| CVE-2026-76480 | 9.8 | — | Cisco | Cisco License On-Prem | CWE-306 | Cisco License On-Prem Security Hardening Release |
| CVE-2026-76485 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-121 | Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execu… |
| CVE-2026-76486 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-121 | Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execu… |
| CVE-2026-76498 | 9.8 | — | Cisco | Cisco Application Policy Infrastructure Controller (APIC) | CWE-284 | Cisco Application Policy Infrastructure Controller Hardening Release: October… |
| CVE-2026-76499 | 9.8 | — | Cisco | Cisco Application Policy Infrastructure Controller (APIC) | CWE-707 | Cisco Application Policy Infrastructure Controller Hardening Release: October… |
| CVE-2026-76500 | 9.8 | — | Cisco | Cisco Application Policy Infrastructure Controller (APIC) | CWE-664 | Cisco Application Policy Infrastructure Controller Hardening Release: October… |
| CVE-2026-76501 | 9.8 | — | Cisco | Cisco NX-OS Software | CWE-121 | Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulne… |
| CVE-2026-95606 | 9.8 | — | Liquid Web / StellarWP | The Events Calendar | CWE-502 | WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnera… |
| CVE-2026-76464 | 9.6 | — | Cisco | Cisco Campus Gateway Software | CWE-119 | Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities |
| CVE-2026-107282 | 9.4 | — | AsyncHttpClient | async-http-client | CWE-319 | AsyncHttpClient: Replay to a different host sends the original host request a… |
| CVE-2026-92414 | 9.3 | — | Apache Software Foundation | Apache Jackrabbit | CWE-384 | Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lo… |
| CVE-2026-95605 | 9.3 | — | Passionate Programmer Peter | WP Data Access | CWE-89 | WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability |
| CVE-2026-96408 | 9.3 | — | Six Apart Ltd. | Movable Type Cloud Edition | CWE-94 | A code injection vulnerability exists in the upgrade script of Movable Type, … |
| CVE-2026-107204 | 9.3 | — | LMCache | LMCache | CWE-306 | LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint |
| CVE-2026-107183 | 9.2 | — | ggml-org | llama.cpp | CWE-416 | llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser |
| CVE-2026-107194 | 9.2 | — | Sungrow | iSolarCloud | CWE-288 | Sungrow iSolarCloud before 2026 allows authentication bypass and account take… |
| CVE-2025-70516 | 9.1 | — | n/a | n/a | CWE-306 | The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enfo… |
| CVE-2026-20328 | 9.1 | — | Cisco | Cisco License On-Prem | CWE-862 | Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnera… |
| CVE-2026-62176 | 9.1 | — | MervinPraison | PraisonAI | CWE-94 | PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Gen… |
| CVE-2026-76454 | 9.1 | — | Cisco | Cisco License On-Prem | CWE-23 | Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability |
| CVE-2026-76483 | 9.1 | — | Cisco | Cisco License On-Prem | CWE-522 | Cisco License On-Prem Security Hardening Release |
| CVE-2026-107202 | 9.1 | — | jonssonyan | h-ui | CWE-77 | CVE-2026-107202 |
| CVE-2026-76453 | 8.8 | — | Cisco | Cisco NX-OS Software | CWE-707 | Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Neut… |
| CVE-2026-76459 | 8.8 | — | Cisco | Cisco NX-OS Software | CWE-787 | Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds… |
| CVE-2026-76463 | 8.8 | — | Cisco | Cisco Campus Gateway Software | CWE-284 | Cisco Meraki Security Hardening Release: October 2026 - Improper Access Contr… |
| CVE-2026-76470 | 8.8 | — | Cisco | Cisco Campus Gateway Software | CWE-682 | Cisco Meraki Hardening Release - Incorrect Calculation Vulnerabilities |
| CVE-2026-76472 | 8.8 | — | Cisco | Cisco Campus Gateway Software | CWE-74 | Cisco Meraki Security Hardening Release October 2026 - Improper Neutralizatio… |
| CVE-2026-76484 | 8.8 | — | Cisco | Cisco License On-Prem | CWE-94 | Cisco License On-Prem Security Hardening Release |
| CVE-2026-95534 | 8.8 | — | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-502 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-103668 | 8.8 | — | Six Apart Ltd. | Movable Type Cloud Edition | CWE-89 | An SQL Injection vulnerability exists in the Site Search function of Movable … |
| CVE-2026-106558 | 8.8 | — | backstage | backstage | CWE-502 | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-107205 | 8.8 | — | LMCache | LMCache | CWE-306 | LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API |
| CVE-2026-107206 | 8.8 | — | LMCache | LMCache | CWE-306 | LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API |
| CVE-2026-107279 | 8.8 | — | AsyncHttpClient | async-http-client | CWE-303 | AsyncHttpClient: Digest mutual authentication is switched off by a peer offer… |
| CVE-2026-97716 | 8.7 | — | Absolute Security | Secure Access | CWE-400 | Denial of Service in Absolute Secure Access |
| CVE-2026-106059 | 8.7 | — | gitahead | gitahead | CWE-78 | GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript |
| CVE-2026-107211 | 8.7 | — | qax-os | excelize | CWE-129 | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes… |
| CVE-2026-107213 | 8.7 | — | qax-os | excelize | CWE-476 | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst p… |
| CVE-2026-107231 | 8.7 | — | AsyncHttpClient | async-http-client | CWE-319 | AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic … |
| CVE-2026-76456 | 8.6 | — | Cisco | Cisco NX-OS Software | CWE-20 | Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Inpu… |
| CVE-2026-76457 | 8.6 | — | Cisco | Cisco NX-OS Software | CWE-125 | Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds… |
| CVE-2026-76458 | 8.6 | — | Cisco | Cisco NX-OS Software | CWE-703 | Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Hand… |
| CVE-2026-107181 | 8.6 | — | Telegram | Telegram Desktop | CWE-143 | Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via inte… |
| CVE-2026-34499 | 8.5 | — | Johnson Controls | ADVMS | CWE-321 | Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS a… |
| CVE-2026-106057 | 8.5 | — | wummel | patool | CWE-78 | patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt |
| CVE-2026-77214 | 8.3 | — | libexpat | libexpat | CWE-125 | libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer |
| CVE-2026-76468 | 8.2 | — | Cisco | Cisco Campus Gateway Software | CWE-20 | Cisco Meraki Hardening Release - Input Validation Vulnerabilities |
| CVE-2026-97714 | 8.2 | — | Absolute Security | Secure Access | CWE-400 | Denial of service vulnerability in Secure Access |
| CVE-2026-46570 | 8.1 | — | n/a | n/a | CWE-122 | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_… |
| CVE-2026-62251 | 8.1 | — | sipcapture | homer | CWE-89 | Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/… |
| CVE-2026-105816 | 8.0 | — | HashiCorp | Vault | CWE-22 | Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Resto… |
| CVE-2026-102256 | 7.8 | — | SonicWall | SMA1000 | CWE-78 | Post-authentication Improper Neutralization of Special Elements used in an OS… |
| CVE-2026-76266 | 7.7 | — | Splunk | Splunk Enterprise | CWE-269 | Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise |
| CVE-2026-103435 | 7.7 | — | Anthropic | @anthropic-ai/claude-code | CWE-22 | Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code |
| CVE-2026-106056 | 7.7 | — | rundeck | rundeck | CWE-78 | Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting |
| CVE-2026-106058 | 7.7 | — | gitahead | gitahead | CWE-78 | GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames |
| CVE-2026-106510 | 7.7 | — | backstage | backstage | CWE-183 | Backstage: Remote code execution via crafted markdown_extensions in TechDocs … |
| CVE-2026-106556 | 7.7 | — | backstage | backstage | CWE-78 | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106557 | 7.7 | — | backstage | backstage | CWE-22 | Backstage: Improper input validation in TechDocs Markdown extension configura… |
| CVE-2026-42708 | 7.6 | — | AF themes | WP Post Author | CWE-89 | WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability |
| CVE-2026-42710 | 7.6 | — | 10Web | Slider by 10Web | CWE-89 | WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability |
| CVE-2026-42713 | 7.6 | — | Gopiplus | Post title marquee scroll | CWE-89 | WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability |
| CVE-2026-42714 | 7.6 | — | Piggly Dev | Pix por Piggly (para Woocommerce) | CWE-89 | WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection v… |
| CVE-2026-92543 | 7.6 | — | Docker | Docker Engine | CWE-295 | Docker Engine insecure-registry fallback via malicious DNS responses |
| CVE-2026-107162 | 7.6 | — | ExpressGateway | express-gateway | CWE-287 | Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass |
| CVE-2026-107281 | 7.6 | — | AsyncHttpClient | async-http-client | CWE-346 | AsyncHttpClient: Connection pool key omits the authenticated principal, so an… |
| CVE-2026-76467 | 7.5 | — | Cisco | Cisco Campus Gateway Software | CWE-664 | Cisco Meraki Software Hardening Release - Resource Lifetime Management Vulner… |
| CVE-2026-92531 | 7.5 | — | BugTracker.NET | BugTracker.NET | CWE-78 | Improper Neutralization of Special Elements used in an OS Command in BugTrack… |
| CVE-2026-92532 | 7.5 | — | BugTracker.NET | BugTracker.NET | CWE-434 | Unrestricted Upload of File with Dangerous Type in BugTracker.NET |
| CVE-2026-96335 | 7.5 | — | WPMU DEV | Forminator | CWE-862 | WordPress Forminator plugin <= 1.57.2 - Broken Access Control vulnerability |
| CVE-2026-107161 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows mali… |
| CVE-2026-107212 | 7.5 | — | qax-os | excelize | CWE-770 | Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows ite… |
| CVE-2026-107214 | 7.5 | — | qax-os | excelize | CWE-248 | Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks |
| CVE-2026-107215 | 7.5 | — | qax-os | excelize | CWE-789 | Excelize: extractPart allocates attacker-controlled, unbounded and negative-s… |
| CVE-2026-107216 | 7.5 | — | qax-os | excelize | CWE-674 | Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly… |
| CVE-2026-107217 | 7.5 | — | qax-os | excelize | CWE-129 | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinat… |
| CVE-2026-107219 | 7.5 | — | qax-os | excelize | CWE-400 | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107227 | 7.5 | — | AsyncHttpClient | async-http-client | CWE-400 | AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables… |
| CVE-2026-107232 | 7.5 | — | AsyncHttpClient | async-http-client | CWE-319 | AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects… |
| CVE-2026-46572 | 7.4 | — | n/a | n/a | CWE-122 | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail… |
| CVE-2026-76469 | 7.4 | — | Cisco | Cisco Campus Gateway Software | CWE-691 | Cisco Meraki Security Hardening Release: October 2026 Insufficient Control Fl… |
| CVE-2026-107177 | 7.4 | — | ExpressGateway | express-gateway | CWE-1394 | Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens |
| CVE-2026-107230 | 7.4 | — | AsyncHttpClient | async-http-client | CWE-346 | AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiat… |
| CVE-2026-106164 | 7.3 | — | Progress Software | Telerik Document Processing Libraries | CWE-835 | Infinite Loop in Telerik Document Processing XLS Import |
| CVE-2026-20362 | 7.2 | — | Cisco | Cisco Finesse | CWE-918 | Cisco Finesse Server-Side Request Forgery Vulnerability |
| CVE-2026-89322 | 7.2 | — | HashiCorp | Vault | CWE-178 | Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions |
| CVE-2026-102257 | 7.2 | — | SonicWall | SMA1000 | CWE-22 | A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (… |
| CVE-2026-42617 | 7.1 | — | n/a | n/a | CWE-122 | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() … |
| CVE-2026-42618 | 7.1 | — | n/a | n/a | CWE-122 | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress(… |
| CVE-2026-43976 | 7.1 | — | wger-project | wger | CWE-863 | wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views) |
| CVE-2026-46434 | 7.1 | — | wger-project | wger | CWE-269 | wger: Trainer Privilege Escalation - Improper Privilege Management |
| CVE-2026-92533 | 7.1 | — | BugTracker.NET | BugTracker.NET | CWE-24 | Path Traversal in BugTracker.NET |
| CVE-2026-94662 | 7.1 | — | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-79 | WordPress Unlimited Elements For Elementor plugin <= 2.0.19 - Cross Site Scri… |
| CVE-2026-94670 | 7.1 | — | Everest Forms | Everest Forms | CWE-79 | WordPress Everest Forms plugin <= 3.6.1 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-95595 | 7.1 | — | Fontsplugin | Disable and Remove Google Fonts | GDPR & DSGVO friendly | CWE-79 | WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2… |
| CVE-2026-97715 | 7.1 | — | Absolute Security | Secure Access | CWE-400 | Denial of Service in Absolute Secure Access |
| CVE-2026-105138 | 7.1 | — | obot-platform | obot | CWE-522 | Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API |
| CVE-2026-106560 | 7.1 | — | backstage | backstage | CWE-22 | Backstage: Improper repository path validation in a Scaffolder backend module |
| CVE-2026-107159 | 7.1 | — | miniupnp project | miniupnpd | CWE-369 | MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header |
| CVE-2026-107180 | 7.1 | — | MISP | MISP | CWE-287 | MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_req… |
| CVE-2026-107223 | 7.1 | — | qax-os | excelize | CWE-789 | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check an… |
| CVE-2026-107270 | 7.1 | — | gophish | gophish | CWE-639 | Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create E… |
| CVE-2026-92415 | 6.9 | — | Apache Software Foundation | Apache Jackrabbit | CWE-470 | Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on … |
| CVE-2026-92542 | 6.9 | — | Docker | Docker Engine | CWE-290 | Blind VXLAN injection into encrypted overlay networks from cluster peer |
| CVE-2026-104074 | 6.9 | — | coturn | coturn | CWE-908 | Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE |
| CVE-2026-107207 | 6.9 | — | LMCache | LMCache | CWE-306 | LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows … |
| CVE-2026-107271 | 6.9 | — | gophish | gophish | CWE-348 | Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing |
| CVE-2026-107280 | 6.9 | — | AsyncHttpClient | async-http-client | CWE-1275 | AsyncHttpClient: Cookie Domain attribute is not checked against the public su… |
| CVE-2026-107353 | 6.9 | — | ljharb | traverse | CWE-1321 | traverse: set() can write to built-in prototypes via an untrusted path |
| CVE-2026-107176 | 6.8 | — | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-250 | Cluster-samples-operator: role reads all secrets in openshift-config, not jus… |
| CVE-2026-107228 | 6.8 | — | AsyncHttpClient | async-http-client | CWE-287 | AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Heade… |
| CVE-2026-1403 | 6.5 | — | GitLab | GitLab | CWE-770 | Allocation of Resources Without Limits or Throttling in GitLab |
| CVE-2026-20321 | 6.5 | — | Cisco | Cisco Application Policy Infrastructure Controller (APIC) | CWE-544 | Cisco Application Policy Infrastructure Controller API Command Injection Vuln… |
| CVE-2026-41958 | 6.5 | — | visidata | visidata | CWE-22 | A path traversal vulnerability exists in the unzip_http RemoteZipFile extract… |
| CVE-2026-46438 | 6.5 | — | wger-project | wger | CWE-639 | wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.sl… |
| CVE-2026-62179 | 6.5 | — | MervinPraison | praisonai-platform | CWE-862 | PraisonAI: Platform members can delete owner issue dependencies through membe… |
| CVE-2026-76265 | 6.5 | — | Splunk | Splunk Enterprise | CWE-284 | Improper Access Control through REST API Endpoints in Splunk Secure Gateway |
| CVE-2026-76269 | 6.5 | — | Splunk | Splunk Enterprise | CWE-639 | Improper Access Control in Search Job Retrieval through the REST API in Splun… |
| CVE-2026-76270 | 6.5 | — | Splunk | Splunk Enterprise | CWE-89 | Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splun… |
| CVE-2026-76271 | 6.5 | — | Splunk | Splunk Enterprise | CWE-407 | Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Sp… |
| CVE-2026-76274 | 6.5 | — | Splunk | Splunk Enterprise | CWE-918 | Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Spl… |
| CVE-2026-76488 | 6.5 | — | Cisco | Cisco Application Policy Infrastructure Controller (APIC) | CWE-264 | Cisco Application Policy Infrastructure Controller Authenticated Information … |
| CVE-2026-107220 | 6.5 | — | qax-os | excelize | CWE-125 | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107221 | 6.5 | — | qax-os | excelize | CWE-787 | Excelize: a row whose earlier cell has a higher column reference than its las… |
| CVE-2026-107222 | 6.5 | — | qax-os | excelize | CWE-129 | Excelize: GetConditionalFormats indexes conditional-formatting rule sub-eleme… |
| CVE-2026-107224 | 6.5 | — | qax-os | excelize | CWE-190 | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
| CVE-2026-107225 | 6.5 | — | qax-os | excelize | CWE-20 | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107174 | 6.4 | — | Red Hat | OpenShift Serverless | CWE-61 | Source-to-image: source-to-image: security boundary bypass via absolute symbo… |
| CVE-2026-33586 | 6.3 | — | OVHcloud | OVHcloud | CWE-290 | Authenticated SMTP Sender Address Forgery |
| CVE-2026-76280 | 6.3 | — | Splunk | Splunk Enterprise | CWE-732 | Incorrect Permission Assignment for App Key Value Store Collections in Splunk… |
| CVE-2026-106064 | 6.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-119 | Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions |
| CVE-2026-106065 | 6.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-119 | Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions |
| CVE-2026-106066 | 6.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-119 | Gimp: gimp: heap buffer overflow in raw data export on oversized image dimens… |
| CVE-2026-106067 | 6.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-119 | Gimp: gimp: heap buffer overflow in hot color filter on oversized image |
| CVE-2026-106559 | 6.3 | — | backstage | backstage | CWE-22 | Backstage: Improper input validation in Confluence to Markdown scaffolder module |
| CVE-2026-107269 | 6.3 | — | gophish | gophish | CWE-208 | Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy |
| CVE-2026-107276 | 6.3 | — | MISP | MISP | CWE-362 | MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Mult… |
| CVE-2026-107352 | 6.3 | — | AWS | Amazon Athena | CWE-424 | Missing authorization checks in Amazon Athena engine version 3 request handling |
| CVE-2026-106579 | 6.2 | — | ImageMagick | ImageMagick | CWE-551 | ImageMagick: Policy Bypass when using coder as the domain. |
| CVE-2026-107167 | 6.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | M17n-lib: heap use-after-free write in re_init_ic() |
| CVE-2026-107168 | 6.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars() |
| CVE-2026-107169 | 6.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8 |
| CVE-2025-70519 | 6.1 | — | n/a | n/a | CWE-79 | The device log component of Fanvil x7a firmware version 2.6.0.1182 does not p… |
| CVE-2026-94154 | 6.1 | — | r3098 | Aurora Heatmap | CWE-79 | Aurora Heatmap <= 1.7.2 - Unauthenticated Stored Cross-Site Scripting via 'ur… |
| CVE-2026-102258 | 6.1 | — | SonicWall | SMA1000 | CWE-79 | Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been … |
| CVE-2026-107363 | 6.1 | — | OpenStack | Zaqar | CWE-472 | In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the p… |
| CVE-2026-97717 | 6.0 | — | Absolute Security | Secure Access | CWE-400 | Denial of Service in Absolute Secure Access |
| CVE-2026-105818 | 5.9 | — | HashiCorp | Vault | CWE-345 | Vault PKI ACME Issues Certificate With Unvalidated SANs |
| CVE-2026-106565 | 5.9 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Infinite Loop in bzip2 compressed images. |
| CVE-2026-106567 | 5.9 | — | ImageMagick | ImageMagick | CWE-196 | ImageMagick: Infinite Loop in PSD decoder on 32-bit builds |
| CVE-2026-106578 | 5.9 | — | ImageMagick | ImageMagick | CWE-590 | ImageMagick: Invalid Memory Free in MVG decoder |
| CVE-2026-107151 | 5.9 | — | Red Hat | Red Hat Satellite 6 | CWE-306 | Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenti… |
| CVE-2026-107209 | 5.9 | — | ImageMagick | ImageMagick | CWE-415 | ImageMagick: Use-After-Free in RSVG decoder that is build without cairo support |
| CVE-2026-107285 | 5.9 | — | AsyncHttpClient | async-http-client | CWE-319 | AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a… |
| CVE-2026-107314 | 5.9 | — | pgjdbc | pgjdbc | CWE-636 | pgjdbc does not enforce requireAuth when the value excludes every authenticat… |
| CVE-2026-20038 | 5.8 | — | Cisco | Cisco NX-OS System Software in ACI Mode | CWE-284 | Cisco Nexus 9000 Series Fabric Switches in ACI Mode Policy-Based Redirect End… |
| CVE-2026-20173 | 5.8 | — | Cisco | Cisco NX-OS Software | CWE-770 | Cisco NX-OS Software Denial of Service Vulnerability |
| CVE-2026-42532 | 5.5 | — | visidata | visidata | CWE-22 | A path traversal vulnerability exists in the EmailSheet extract_parts functio… |
| CVE-2026-46571 | 5.5 | — | n/a | n/a | CWE-125 | In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name… |
| CVE-2026-88514 | 5.5 | — | n/a | n/a | CWE-200 | An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sens… |
| CVE-2026-107166 | 5.5 | — | n/a | Open5GS | CWE-400 | Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation o… |
| CVE-2026-17538 | 5.4 | — | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | CWE-639 | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress … |
| CVE-2026-45161 | 5.4 | — | wger-project | wger | CWE-352 | wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding |
| CVE-2026-105820 | 5.4 | — | HashiCorp | Vault Enterprise | CWE-22 | Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution |
| CVE-2026-76286 | 5.3 | — | Splunk | Splunk MCP Server | CWE-918 | Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server |
| CVE-2026-105139 | 5.3 | — | obot-platform | obot | CWE-863 | Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and R… |
| CVE-2026-106563 | 5.3 | — | backstage | backstage | CWE-20 | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106564 | 5.3 | — | ImageMagick | ImageMagick | CWE-122 | ImageMagick: Heap Buffer Over-Write in EXR decoder |
| CVE-2026-106568 | 5.3 | — | ImageMagick | ImageMagick | CWE-835 | ImageMagick: Infinite Loop when reading a crafted XMP profile |
| CVE-2026-106569 | 5.3 | — | ImageMagick | ImageMagick | CWE-770 | ImageMagick: Denial of service in ASE decoder because of missing security checks |
| CVE-2026-106572 | 5.3 | — | ImageMagick | ImageMagick | CWE-674 | ImageMagick: Stack Overflown CALS decoder due to missing depth check. |
| CVE-2026-106573 | 5.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Denial of service in MVG decoder |
| CVE-2026-106574 | 5.3 | — | ImageMagick | ImageMagick | CWE-122 | ImageMagick: Heap Buffer Over-Write in distributed pixel cache server will re… |
| CVE-2026-106575 | 5.3 | — | ImageMagick | ImageMagick | CWE-775 | ImageMagick: Unclosed file pointer in magick script |
| CVE-2026-106576 | 5.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Denial of service possible when parsing an XMP profile. |
| CVE-2026-106577 | 5.3 | — | ImageMagick | ImageMagick | CWE-94 | ImageMagick: Code Injection in the postscript coders |
| CVE-2026-107175 | 5.3 | — | MISP | MISP | CWE-284 | MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing G… |
| CVE-2026-107208 | 5.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Denial of service with crafted XMP profile |
| CVE-2026-107210 | 5.3 | — | ImageMagick | ImageMagick | CWE-409 | ImageMagick: Policy Bypass in MAT decoder when reading highly compressed data |
| CVE-2026-107218 | 5.3 | — | qax-os | excelize | CWE-129 | Excelize: RIGHT() on supplementary-plane text slices with a negative index an… |
| CVE-2026-107273 | 5.3 | — | gophish | gophish | CWE-918 | Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site |
| CVE-2026-107278 | 5.3 | — | MISP | MISP | CWE-20 | MISP Object Sync Drops Objects and Attributes When Description Is Empty |
| CVE-2026-107315 | 5.3 | — | pgjdbc | pgjdbc | CWE-226 | pgjdbc pads a value shorter than its declared length with bytes of earlier st… |
| CVE-2026-101886 | 5.1 | — | Cisco | Jabber for Android | CWE-22 | Cisco Jabber for Android Path Traversal via Shared Content URI |
| CVE-2026-106571 | 5.1 | — | ImageMagick | ImageMagick | CWE-190 | ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a … |
| CVE-2026-106561 | 5.0 | — | backstage | backstage | CWE-200 | Backstage: Sensitive information disclosure in Kubernetes resource queries |
| CVE-2026-76437 | 4.9 | — | Cisco | Cisco License On-Prem | CWE-78 | Cisco Smart Software Manager On-Prem Command Injection Vulnerability |
| CVE-2026-76452 | 4.9 | — | Cisco | Cisco License On-Prem | CWE-89 | Cisco Smart Software Manager On-Prem SQL Injection Vulnerability |
| CVE-2026-46437 | 4.8 | — | wger-project | wger | CWE-287 | wger: API credentials remain valid after logout/password change |
| CVE-2026-20032 | 4.4 | — | Cisco | Cisco NX-OS Software | CWE-653 | Cisco NX-OS Software Python Sandbox Escape Vulnerability |
| CVE-2026-76264 | 4.3 | — | Splunk | Splunk Enterprise | CWE-863 | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76267 | 4.3 | — | Splunk | Splunk Enterprise | CWE-117 | Log Injection through the REST API in Splunk App for Splunk O11y Cloud |
| CVE-2026-76272 | 4.3 | — | Splunk | Splunk Enterprise | CWE-862 | Missing Access Control through the REST API in Splunk Secure Gateway |
| CVE-2026-76273 | 4.3 | — | Splunk | Splunk Enterprise | CWE-20 | Improper Input Validation through the collect Command in Splunk Enterprise |
| CVE-2026-76275 | 4.3 | — | Splunk | Splunk Enterprise | CWE-285 | Improper Authorization in Search Job Listings through the REST API in Splunk … |
| CVE-2026-76276 | 4.3 | — | Splunk | Splunk Enterprise | CWE-1188 | Information Disclosure in the Discover Splunk Observability Cloud app through… |
| CVE-2026-76278 | 4.3 | — | Splunk | Splunk Enterprise | CWE-639 | Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise |
| CVE-2026-76279 | 4.3 | — | Splunk | Splunk Enterprise | CWE-20 | Improper Input Validation of Index Names through the collect Command in Splun… |
| CVE-2026-106562 | 4.3 | — | backstage | backstage | CWE-754 | Backstage: Incorrect authorization in search engine permission filtering |
| CVE-2026-106570 | 4.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick: Denial of service in distributed pixel cache server |
| CVE-2026-107313 | 4.2 | — | pgjdbc | pgjdbc | CWE-201 | pgjdbc stores bytes of earlier messages in place of a large value on GSS-encr… |
| CVE-2026-76277 | 4.1 | — | Splunk | Splunk Enterprise | CWE-20 | Improper Input Validation of Native Splunk Usernames through the REST API in … |
| CVE-2026-106566 | 4.0 | — | ImageMagick | ImageMagick | CWE-61 | ImageMagick: Policy Bypass in delegate symlink cleanup due to missing check |
| CVE-2026-106580 | 4.0 | — | ImageMagick | ImageMagick | CWE-284 | ImageMagick: Policy Bypass in CUT encoder |
| CVE-2026-107229 | 4.0 | — | AsyncHttpClient | async-http-client | CWE-384 | AsyncHttpClient: Incomplete origin checks in the default cookie store allow c… |
| CVE-2026-107283 | 3.7 | — | AsyncHttpClient | async-http-client | CWE-338 | AsyncHttpClient: Digest authentication cnonce generated with a non-cryptograp… |
| CVE-2026-107284 | 3.7 | — | AsyncHttpClient | async-http-client | CWE-345 | AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-A… |
| CVE-2026-107170 | 2.9 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | M17n-lib: null dereference in minput_open_im() after failed m17n_init() |
| CVE-2026-105140 | 2.3 | — | obot-platform | obot | CWE-362 | Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Re… |
| CVE-2026-107272 | 2.3 | — | gophish | gophish | CWE-79 | Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages |
| CVE-2026-107125 | 2.1 | — | XnView | Classic | CWE-119 | XnView Classic FLI File heap-based overflow |
| CVE-2025-70515 | await | — | n/a | n/a | — | The device log component of Fanvil x7a firmware version 2.6.0.1182 does not p… |
| CVE-2025-70517 | await | — | n/a | n/a | — | The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforc… |
| CVE-2025-70520 | await | — | n/a | n/a | — | The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enfo… |
| CVE-2025-70522 | await | — | n/a | n/a | — | The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforc… |
| CVE-2026-42616 | await | — | n/a | n/a | — | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat… |
| CVE-2026-46569 | await | — | n/a | n/a | — | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tai… |
| CVE-2026-56851 | await | — | golang.org/x/text | golang.org/x/text/secure/precis | — | Panic parsing crafted input in x/text/secure/precis in golang.org/x/text |
| CVE-2026-76281 | await | — | Splunk | Splunk Enterprise | CWE-284 | Improper Access Control in Splunk Enterprise |
| CVE-2026-76282 | await | — | Splunk | Splunk Enterprise | CWE-664 | Improper Control of a Resource Through its Lifetime in Splunk Enterprise |
| CVE-2026-76283 | await | — | Splunk | Splunk Enterprise | CWE-693 | Protection Mechanism Failure in Splunk Enterprise |
| CVE-2026-76284 | await | — | Splunk | Splunk Enterprise | CWE-707 | Improper Neutralization in Splunk Enterprise |
| CVE-2026-76285 | await | — | Splunk | Splunk Enterprise | CWE-710 | Improper Adherence to Coding Standards in Splunk Enterprise |
| CVE-2026-98373 | await | — | Linux | Linux | — | mm/hugetlb: preserve mremap address delta when skipping page tables |
| CVE-2026-98374 | await | — | Linux | Linux | — | tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() |
| CVE-2026-103371 | await | — | Apache Software Foundation | Apache Geode | — | Apache Geode: Management REST API: Insertion of Sensitive Information into Lo… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-10-07 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.