boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, October 7, 2026 · all times UTC← 2026-10-06 · archive

Security Box Score — October 7, 2026

330 CVEs published, led by Cisco (36).

330 CVEs published October 7, 2026: 47 critical, 110 high, 149 medium, 9 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 15 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 305 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published273352725——
KEV catalog size1734

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3426 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux2106415532269073711560.17.8.0018+22 ▲
google2913122380119713681378090.37.5.0026+253 ▲
microsoft122913203199969417290311.17.8.0047+3 ▲
red hat809795439447556200.06.5.0034+37 ▲
apple056467166317148991.66.5.00190
suse053827162000.07.5.0036-9 ▼
canonical2521612195000.07.8.0022+2 ▲
freebsd04823673000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco36218698563160177.88.4.0046+25 ▲
ubiquiti065362810334.69.1.00500
palo alto networks0461426151324.34.7.00220
fortinet142121017330819.07.2.0040+1 ▲
netgear03400277000.04.3.00270
f502671441527.78.7.0050-7 ▼
ivanti0246162025520.88.8.01520
sonicwall4238105019417.47.8.0050-1 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache118825169373260213320.27.5.0057+109 ▲
mozilla2381123170870900.08.8.0031-32 ▼
gitlab21068246311532.85.3.0035+2 ▲
drupal094119668411.15.7.0027-26 ▼
github225212110000.07.4.0052-1 ▼
docker3151950000.07.6.0018+3 ▲
wordpress0614103350.08.7.03920
eclipse022000000.09.3.00500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle0290558116605631012840.17.8.00360
ibm24104719549334118610.17.5.0037-46 ▼
adobe08308236437592150.67.5.0036-3 ▼
progress7731643131611.48.0.0045+5 ▲
zohocorp04262970000.08.3.0117-5 ▼
solarwinds0261853010415.49.1.00670
veeam62571170100.08.5.0036+6 ▲
atlassian11028001300.07.8.0043+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link07422281212300.08.5.0164-6 ▼
siemens052633103000.07.3.0026-1 ▼
synology046510256000.05.6.00320
rockwell automation04353260000.08.6.0029-18 ▼
advantech02021710000.08.6.0071-2 ▼
schneider electric01821150000.08.5.0044-4 ▼
hitachi energy0122460000.07.0.0025-4 ▼
abb0111640000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell224004217915722210.37.2.0027-33 ▼
nvidia230325207710000.07.8.0019-28 ▼
sourcecodester1725400149105000.05.5.0041-9 ▼
openclaw022341148421000.07.1.00310
hewlett packard enterprise (hpe)382043992649110.57.3.0042-48 ▼
mongodb1170699605100.07.1.0037-9 ▼
spring017013608314000.06.5.00330
itsourcecode141670042125000.02.1.0033-8 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.929699.810.0
CVE-2026-87902.461298.88.1
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.510.0
CVE-2026-85102.075594.49.8
CVE-2026-12269.069994.08.8
CVE-2026-77692.065693.67.5
CVE-2026-17176.049792.07.7
CVE-2026-12268.047391.68.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9296KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8200410.0.0325
CVE-2026-10548410.0.0213
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
CVE-2026-7570310.0.0125
CVE-2026-7572110.0.0125
CVE-2026-8441210.0.0125
Most disclosures (vendor)
VendorCVEs
linux2137
microsoft1005
google915
oracle634
ibm358
apache304
red hat301
apple247
adobe221
dell174
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet8
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven131
NuGet30
Packagist25
npm25
PyPI19
Go12
crates.io10
RubyGems4
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-88779NetScaler0
CVE-2026-93952Arista Networks0
CVE-2026-102489Zammad GmbH1
CVE-2026-102490Zammad GmbH1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171785
CVE-2021-27102n/a2021-11-171785
CVE-2021-27101n/a2021-11-171785
CVE-2021-27103n/a2021-11-171785
CVE-2021-21017Adobe2021-11-171785
CVE-2021-28550Adobe2021-11-171785
CVE-2021-42013Apache Software Foundation2021-11-171785
CVE-2021-41773Apache Software Foundation2021-11-171785
CVE-2021-30858Apple2021-11-171785
CVE-2021-30860Apple2021-11-171785

Transactions

EXPLOIT PUBLISHED — x-stream xstream: 23 CVEs (CVE-2020-26217, CVE-2020-26258, CVE-2020-26259, CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351, CVE-2021-39140, CVE-2021-39141, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154). Public exploit references added.

EXPLOIT PUBLISHED — jpadilla pyjwt: 5 CVEs (CVE-2026-101917, CVE-2026-101918, CVE-2026-102265, CVE-2026-102266, CVE-2026-102268). Public exploit references added.

EXPLOIT PUBLISHED — docling-project docling: 3 CVEs (CVE-2026-105742, CVE-2026-105744, CVE-2026-105748). Public exploit references added.

EXPLOIT PUBLISHED — Red Hat Enterprise Linux 10: 3 CVEs (CVE-2026-55653, CVE-2026-90462, CVE-2026-90996). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2014-0050. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2015-6420. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2016-1000027. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2017-16138 (HackerOne mime node module). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2018-20852. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-16935. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-5010 (Python). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-9740. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-9947. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-9948. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-15250 (junit-team junit4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-8492. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-9054 (ZyXEL NAS326). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-29425 (Apache Software Foundation Apache Commons IO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-0235 (node-fetch/node-fetch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-2596 (node-fetch/node-fetch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-42003. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-42004. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-22894. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-50572. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-1102 (jberet). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-14611 (Gladinet CentreStack and TrioFox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-25249 (Fortinet FortiSwitchManager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104973 (makeplane plane). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-10520 (ivanti Sentry). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105226 (osCommerce2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105232 (kishor-23 food-waste-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105245 (sgl-project sglang). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105254 (itsourcecode Online Admission System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105286 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105290 (feelec-yishu feelcrm-os). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105329 (TallCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105385 (onetwothreeneth HospitalManagementSystem). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105389 (feelec-yishu feelcrm-os). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105468 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105472 (girishsaraf Online-Appointment-Booking-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105571 (PickMall Lilishop). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105611 (chillzhuang SpringBlade). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105705 (SourceCodester Drug Recommendation System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-106214 (Google Chrome). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-21589 (Atlassian Bamboo Data Center). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48558 (SimpleHelp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55255 (langflow-ai langflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-69147 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77226 (Camunda 7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81914 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86843 (Apache Software Foundation Apache Airflow Teradata provider). Public exploit reference added.

REJECTED — CVE-2026-39768 (CleanTalk Inc Security & Malware scan by CleanTalk). Record withdrawn by the CNA.

RESCORED — x-stream xstream: 15 CVEs (CVE-2020-26217, CVE-2020-26258, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351, CVE-2021-29505, CVE-2021-39139, CVE-2021-39140). CVSS rescored — before/after on each CVE page.

RESCORED — docling-project docling: 5 CVEs (CVE-2026-105742, CVE-2026-105744, CVE-2026-105745, CVE-2026-105746, CVE-2026-105750). CVSS rescored — before/after on each CVE page.

RESCORED — BUSINESS NOTEBOOK PCS BIOS; BUSINESS DESKTOP PCS BIOS; RETAIL POINT-OF-SALE SYSTEMS BIOS; WORKSTATIONS BIOS: 4 CVEs (CVE-2021-39297, CVE-2021-39299, CVE-2021-39300, CVE-2021-39301). CVSS rescored — before/after on each CVE page.

RESCORED — jpadilla pyjwt: 4 CVEs (CVE-2026-101917, CVE-2026-101918, CVE-2026-102266, CVE-2026-102267). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2018-14647 (The Python Project Python). CVSS 5.3 → 7.5 (NVD).

RESCORED — CVE-2019-16056. CVSS 5.3 → 7.5 (NVD).

RESCORED — CVE-2019-18348. CVSS 5.4 → 6.1 (NVD).

RESCORED — CVE-2019-20907. CVSS 5.5 → 7.5 (NVD).

RESCORED — CVE-2019-5010 (Python). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2019-9636. CVSS 5.3 → 9.8 (NVD).

RESCORED — CVE-2019-9740. CVSS 6.5 → 6.1 (NVD).

RESCORED — CVE-2019-9947. CVSS 5.4 → 6.1 (NVD).

RESCORED — CVE-2020-10735 (python). CVSS 6.2 → 7.5 (NVD).

RESCORED — CVE-2020-15250 (junit-team junit4). CVSS 4.4 → 5.5 (NVD).

RESCORED — CVE-2021-29425 (Apache Software Foundation Apache Commons IO). CVSS 6.5 → 4.8 (NVD).

RESCORED — CVE-2021-36342 (Dell CPG BIOS). CVSS 7.5 → 6.4 (NVD).

RESCORED — CVE-2021-36343 (Dell CPG BIOS). CVSS 7.5 → 6.4 (NVD).

RESCORED — CVE-2021-39298 (AMD 2nd Gen EPYC). CVSS 6.5 → 8.8 (NVD).

RESCORED — CVE-2022-0235 (node-fetch/node-fetch). CVSS 8.8 → 6.1 (NVD).

RESCORED — CVE-2023-22894. CVSS 9.8 → 4.9 (NVD).

RESCORED — CVE-2023-43086 (Dell Command Configure (DCC)). CVSS 7.3 → 7.8 (NVD).

RESCORED — CVE-2025-21043 (Samsung Mobile Devices). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2025-32151 (Themekraft BuddyForms). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2025-5154 (PhonePe App). CVSS 4.6 → 1.8 (NVD).

RESCORED — CVE-2025-9000 (Mechrevo Control Center GX V2). CVSS 7.3 → 6.4 (NVD).

RESCORED — CVE-2025-9016 (Mechrevo Control Center GX V2). CVSS 7.3 → 6.4 (NVD).

RESCORED — CVE-2026-10542 (Mattermost). CVSS 5 → 4.3 (NVD).

RESCORED — CVE-2026-12985 (Mattermost). CVSS 6.8 → 9.3 (NVD).

RESCORED — CVE-2026-18074 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.2 → 7.5 (NVD).

RESCORED — CVE-2026-18095 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.5 → 8.8 (NVD).

RESCORED — CVE-2026-18114 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-18123 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 7.6 → 7.5 (NVD).

RESCORED — CVE-2026-18131 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 8.2 → 6.1 (NVD).

RESCORED — CVE-2026-18133 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift). CVSS 5.4 → 6.5 (NVD).

RESCORED — CVE-2026-62874 (Microsoft Azure Billing). CVSS 10 → 9.8 (NVD).

RESCORED — CVE-2026-78446 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 7.5 (NVD).

RESCORED — CVE-2026-78501 (Microsoft 365 Copilot's Business Chat). CVSS 7.4 → 8.6 (NVD).

RESCORED — CVE-2026-90996 (Red Hat Enterprise Linux 10). CVSS 4 → 5.5 (NVD).

PATCH SHIPPED — CVE-2026-105326 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.4.19-4.3.hum1.

PATCH SHIPPED — CVE-2026-42708 (AF themes WP Post Author). Fixed in WP Post Author 4.0.1.

PATCH SHIPPED — CVE-2026-57737 (Averta LTD Shortcodes and extra features for Phlox theme). Fixed in Shortcodes and extra features for Phlox theme 2.17.24.

PATCH SHIPPED — CVE-2026-85234 (Red Hat Enterprise Linux 8). Fixed in Red Hat Enterprise Linux 8 0:5.2-28.el8_10.

ENRICHED — Google Chrome: 3 CVEs (CVE-2026-106237, CVE-2026-106324, CVE-2026-106326). Received CVSS/CPE analysis.

ENRICHED — Linux: 3 CVEs (CVE-2026-63986, CVE-2026-63990, CVE-2026-63991). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

330 CVEs published. 25 box scores, 305 table rows — nothing truncated.

IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0079   54.9     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 10  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   53.7     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0068   50.8     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-440 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
LMCache Unauthenticated RCE in multiprocess mode via pickle deserialization
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   50.5     —
AFFECTED
  Product  Versions  Fixed
  LMCache  0.3.9 –   —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 7   Published (CNA: JFROG)
CWE-306, CWE-502 · CNA: JFROG · CVSS v3.1 · 4 references · NVD status: Deferred
ASUSTOR Inc. ADM — An HTTP header injection vulnerability was found in the ADM
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    9.2   .0065   49.7     —
AFFECTED
  Product  Versions  Fixed
  ADM      5.0.0 –   —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 7   Published (CNA: ASUSTOR1)
CWE-113 · CNA: ASUSTOR1 · CVSS v4.0 · 1 reference · NVD status: Deferred
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0064   49.0     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-22 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0061   47.5     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  H  H  H    8.5   .0058   46.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0058   46.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-94 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  L    4.3   .0047   38.6     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-400 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0046   37.8     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-200 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
Apache YuniKorn: Admission control bypass via workload UPDATE operation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   H   P   N   L   N    2.0   .0045   37.2     —
AFFECTED
  Product          Versions     Fixed
  Apache YuniKorn  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Oct 7   Published (CNA: apache)
CWE-863 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Deferred
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0045   36.8     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-22 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0043   35.8     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-693 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0043   35.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-502 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
Manacle Technologies Multi-tenant ERP System — Unsafe Deserialization Vulnerability in Manacle Technologies ERP System
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0042   34.6     —
AFFECTED
  Product                  Versions   Fixed
  Multi-tenant ERP System  version –  —
TIMELINE
  Oct 7   Reserved by CNA
  Oct 7   Published (CNA: CERT-In)
CWE-502 · CNA: CERT-In · CVSS v4.0 · 1 reference · NVD status: Deferred
Sarah Giles Dynamic User Directory — WordPress Dynamic User Directory plugin <= 2.4 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  N  L    7.6   .0038   30.2     —
AFFECTED
  Product                 Versions     Fixed
  Dynamic User Directory  unspecified  —
TIMELINE
  Apr 29  Reserved by CNA
  Oct 7   Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
SERVIT Software Solutions affiliate-toolkit — WordPress affiliate-toolkit plugin <= 3.9.1 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  H  N  L    7.6   .0038   30.2     —
AFFECTED
  Product            Versions     Fixed
  affiliate-toolkit  unspecified  —
TIMELINE
  Apr 29  Reserved by CNA
  Oct 7   Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
IBM Langflow OSS — Langflow OSS is affected by multiple vulnerabilities
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  H  L    7.6   .0038   30.1     —
AFFECTED
  Product       Versions  Fixed
  Langflow OSS  1.0.0 –   —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 7   Published (CNA: ibm)
CWE-639 · CNA: ibm · CVSS v3.1 · 1 reference · NVD status: Analyzed
Unknown String locator — String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0037   29.3     —
AFFECTED
  Product         Versions     Fixed
  String locator  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 7   Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
Flexera FlexNet Publisher — FlexNet Publisher lmadmin SOAP Authentication Bypass Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0037   29.0     —
AFFECTED
  Product            Versions     Fixed
  FlexNet Publisher  unspecified  —
TIMELINE
  Aug 11  Reserved by CNA
  Oct 7   Published (CNA: flexera)
CWE-288 · CNA: flexera · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Veeam Backup and Replication — This vulnerability in Veeam Backup & Replication allows an authenticated Cloud Connect tenant to read arbit…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    8.3   .0037   28.8     —
AFFECTED
  Product                 Versions  Fixed
  Backup and Replication  12 –      —
TIMELINE
  Jun 28  Reserved by CNA
  Oct 7   Published (CNA: hackerone)
CWE-22 · CNA: hackerone · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Unknown WP Coder — WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   28.8     —
AFFECTED
  Product   Versions  Fixed
  WP Coder  4.0 –     —
TIMELINE
  Oct 2   Reserved by CNA
  Oct 7   Published (CNA: WPScan)
CWE-94 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.3.1 - Unauthenticated Stored Cross-Site Scripting via Registration Metadata
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0037   28.4     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Sep 28  Reserved by CNA
  Oct 7   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
Apache YuniKorn: Admission control bypass via system label forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   N   L   N    4.8   .0037   28.3     —
AFFECTED
  Product          Versions     Fixed
  Apache YuniKorn  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 7   Published (CNA: apache)
CWE-290 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2025-643939.427.7VeeamBackup and ReplicationCWE-502This vulnerability in Veeam Backup & Replication allows a Backup Viewer to ex…
CVE-2025-643924.825.1VeeamBackup Enterprise ManagerCWE-79This vulnerability in Veeam Backup Enterprise Manager allows an attacker to e…
CVE-2026-835407.725.0wolfSSLwolfSSHCWE-287wolfSSHd on Windows race condition leading to logon token reused across conne…
CVE-2026-837425.324.1wolfSSL Inc.wolfSSHCWE-121wstrncat() unsigned integer underflow leads to an off-by-one null write in wo…
CVE-2026-1071039.323.6Manacle TechnologiesMulti-tenant ERP SystemCWE-89SQL Injection Vulnerability in Manacle Technologies ERP System
CVE-2026-149119.322.8ASUSRouterCWE-79Improper Neutralization of Input During Web Page Generation (“Cross-site Scri…
CVE-2026-158948.821.6zephyrprojectzephyrCWE-121Bluetooth Mesh solicitation PDU stack buffer overflow via oversized advertise…
CVE-2026-848976.920.9wolfSSL Inc.wolfSSHCWE-372wolfSSH server accepts server-to-client DH group exchange messages from an un…
CVE-2026-930266.120.7VeeamBackup and ReplicationCWE-862This vulnerability in Veeam Backup & Replication allows a Backup Viewer to mo…
CVE-2026-1024788.720.3Octopus DeployOctopus ServerCWE-1289In affected versions of Octopus Server, an authenticated user with permission…
CVE-2026-274345.320.1sc Internet VivooWP RentalsCWE-862WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability
CVE-2026-57037.119.9Satel IberiaSenNet Datalogger Serie 200CWE-35Path Traversal in Satel Iberia SenNet Datalogger Serie 200
CVE-2026-1064718.118.6Red HatRed Hat Satellite 6CWE-863Candlepin: candlepin: broken object-level authorization via verifyauthorizati…
CVE-2026-1027829.318.5ordasoft.comOrdaSoft Simple Membership extension for JoomlaCWE-89Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft S…
CVE-2026-815356.318.4wolfSSL Inc.wolfSSHCWE-862wolfSSH SSH client accepts unsolicited forwarded-tcpip channel opens without …
CVE-2026-1030754.316.1WPMU DEVHustleCWE-862WordPress Hustle plugin <= 7.8.14.2 - Broken Access Control vulnerability
CVE-2026-593469.316.0VMwareVMware WorkstationCWE-190VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability
CVE-2026-1071029.315.7Manacle TechnologiesMulti-tenant ERP SystemCWE-345Account Takeover Vulnerability in Manacle Technologies ERP System
CVE-2026-782432.115.1Apache Software FoundationApache YuniKornCWE-248Apache YuniKorn: LDAP Group provider panics on lowercase attribute name
CVE-2026-894177.214.6daanvandenberghOMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.CWE-79OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. <= 6.3.10 - Unauthent…
CVE-2026-1058765.314.5WP ChillModula Image GalleryCWE-862WordPress Modula Image Gallery plugin <= 3.0.11 - Sensitive Data Exposure vul…
CVE-2026-1027816.913.8ordasoft.comTouch Slider extension for JoomlaCWE-284Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSof…
CVE-2026-1046526.813.3UnknownEnvira GalleryCWE-79Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID
CVE-2026-1046536.813.3UnknownEnvira GalleryCWE-79Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions
CVE-2026-1038705.013.0Red HatRed Hat Satellite 6CWE-22Pulp-rpm: distribution tree publish creates directories from .treeinfo ids
CVE-2026-877828.812.9UnknownKoinonia LinkCWE-269Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
CVE-2026-868165.312.9UnknownWPCafeCWE-200WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API
CVE-2026-1046676.812.7UnknownAnimated Number CountersCWE-89Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order
CVE-2026-1049536.812.7UnknownMPGCWE-89MPG < 4.2.3 - Editor+ SQLi via Project Import
CVE-2026-1038686.512.4Red HatRed Hat Ansible Automation Platform 2CWE-488Pulp-container: registry credentials are reused across remotes in a worker
CVE-2026-1038696.512.4Red HatRed Hat Ansible Automation Platform 2CWE-488Pulp-ansible: bearer tokens are reused across remotes in a worker
CVE-2026-972946.512.0David LingrenMedia LIbrary AssistantCWE-79WordPress Media LIbrary Assistant plugin <= 3.41 - Cross Site Scripting (XSS)…
CVE-2026-1043916.512.0ExpressTechQuiz And Survey MasterCWE-79WordPress Quiz And Survey Master plugin <= 11.2.7 - Cross Site Scripting (XSS…
CVE-2026-1043936.512.0weDevsHappy Addons for ElementorCWE-79WordPress Happy Addons for Elementor plugin <= 3.50.0 - Cross Site Scripting …
CVE-2026-1058846.512.0WP MediaRocket Lazy LoadCWE-79WordPress Rocket Lazy Load plugin <= 2.4.0 - Cross Site Scripting (XSS) vulne…
CVE-2026-965306.511.3UnknownOptimoleCWE-200Optimole 4.0.0 - 4.2.14 - Subscriber+ Sensitive Data Disclosure via Dashboard…
CVE-2026-1043904.310.6ArrayticsBookticsCWE-862WordPress Booktics plugin <= 1.0.27 - Broken Access Control vulnerability
CVE-2026-191868.110.6zephyrprojectzephyrCWE-191Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds re…
CVE-2026-1058716.510.5BdThemesElement Pack Elementor AddonsCWE-79WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scriptin…
CVE-2026-1058736.510.5BdThemesElement Pack Elementor AddonsCWE-79WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scriptin…
CVE-2026-1058756.510.5BdThemesPrime Slider – Addons For ElementorCWE-79WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Sc…
CVE-2026-1034169.310.2Eclipse FoundationEclipse ThreadX - NetX DuoCWE-787Out-of-bounds write via the TLS 1.3 handshake message cache in NetX Duo in Ec…
CVE-2026-165288.49.9ASUSRouterCWE-532Insertion of Sensitive Information into Log File in certain ASUS router model…
CVE-2026-593478.19.9VMwareVMware WorkstationCWE-121VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability
CVE-2026-977209.18.5Apache Software FoundationApache ImpalaCWE-303Apache Impala: Impala Executor Webserver Auth Bypass
CVE-2026-904666.58.5Apache Software FoundationApache ImpalaCWE-23Apache Impala: Path traversal executes JARs outside trusted paths
CVE-2026-1053225.38.3UnknownMagee ShortcodesCWE-472Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form
CVE-2026-193869.38.1ASUSRouterCWE-121A stack-based buffer overflow in the ASUS router modules allows an authentica…
CVE-2026-822118.27.6UnknownNexi XPay BuildCWE-862Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key D…
CVE-2026-936845.47.6Apache Software FoundationApache ImpalaCWE-79Apache Impala: Stored XSS in Impala query plans
CVE-2026-973544.16.8UnknownPowerPress Podcasting plugin by BlubrryCWE-918PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects
CVE-2026-973314.36.6UnknownUser Private FilesCWE-200User Private Files < 2.1.9 - Subscriber+ User Email Address Disclosure via dp…
CVE-2026-1046782.75.6UnknownCP Media PlayerCWE-284CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update
CVE-2026-1053167.15.1UnknownMagee ShortcodesCWE-79Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_s…
CVE-2026-868335.44.8UnknownMetFormCWE-74MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via F…
CVE-2026-165169.03.6wolfSSL Inc.wolfSSHCWE-345wolfSSH ECDSA host key curve not validated against negotiated algorithm
CVE-2026-879717.13.3UnknownIf-So Dynamic ContentCWE-79If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter
CVE-2026-1033786.53.3UnknownGeliver Akıllı Kargo PazaryeriCWE-200Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclo…
CVE-2026-1033235.92.6UnknownIntegration for Epos Now and WooCommerceCWE-862Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Act…
CVE-2026-1036814.32.4UnknownFrontend DashboardCWE-284Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via …
CVE-2026-1040494.32.4UnknownAcademy LMSCWE-639Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Top…
CVE-2026-1040504.32.4UnknownAcademy LMSCWE-639Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via ren…
CVE-2026-1046514.32.4UnknownYaad Sarig Payment Gateway For WCCWE-639Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Paym…
CVE-2026-822127.52.3UnknownNexi XPay BuildCWE-345Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notificatio…
CVE-2026-193967.72.1ASUSRouterCWE-337A predictable seed in the pseudo-random number generator (PRNG) in the IFTTT …
CVE-2025-643914.11.5VeeamAgent for WindowsCWE-1386This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileg…
CVE-2026-1060615.51.0Red HatRed Hat Enterprise Linux 10CWE-125Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on craft…
CVE-2026-580686.80.8VeeamAgent for WindowsCWE-862This vulnerability in Veeam Agent for Microsoft Windows allows any local user…
CVE-2026-1071216.50.2Red HatRed Hat Build of KeycloakCWE-319Keycloak-services: keycloak-services: smtp starttls plaintext credential and …
CVE-2025-7051810.0—n/an/aCWE-77The management portal's diagnostic ping tool of Fanvil x7a firmware version 2…
CVE-2026-7648210.0—CiscoCisco License On-PremCWE-347Cisco License On-Prem Security Hardening Release
CVE-2026-10225510.0—SonicWallSMA1000CWE-441A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work …
CVE-2025-705219.8—n/an/aCWE-77The management portal's diagnostic ping tool of Fanvil x7a firmware version 2…
CVE-2026-622529.8—sipcapturehomerCWE-798Homer: Hardcoded Default Admin Password 'sipcapture' With No Forced Change on…
CVE-2026-622539.8—sipcapturehomerCWE-306Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (D…
CVE-2026-762689.8—SplunkSplunk EnterpriseCWE-306Missing Authentication for Critical Function in the Patroni REST API in Splun…
CVE-2026-764559.8—CiscoCisco NX-OS SoftwareCWE-284Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Acce…
CVE-2026-764659.8—CiscoCisco NX-OS SoftwareCWE-590Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vuln…
CVE-2026-764719.8—CiscoCisco NX-OS SoftwareCWE-122Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
CVE-2026-764809.8—CiscoCisco License On-PremCWE-306Cisco License On-Prem Security Hardening Release
CVE-2026-764859.8—CiscoCisco NX-OS SoftwareCWE-121Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execu…
CVE-2026-764869.8—CiscoCisco NX-OS SoftwareCWE-121Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execu…
CVE-2026-764989.8—CiscoCisco Application Policy Infrastructure Controller (APIC)CWE-284Cisco Application Policy Infrastructure Controller Hardening Release: October…
CVE-2026-764999.8—CiscoCisco Application Policy Infrastructure Controller (APIC)CWE-707Cisco Application Policy Infrastructure Controller Hardening Release: October…
CVE-2026-765009.8—CiscoCisco Application Policy Infrastructure Controller (APIC)CWE-664Cisco Application Policy Infrastructure Controller Hardening Release: October…
CVE-2026-765019.8—CiscoCisco NX-OS SoftwareCWE-121Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulne…
CVE-2026-956069.8—Liquid Web / StellarWPThe Events CalendarCWE-502WordPress The Events Calendar plugin <= 6.17.4 - PHP Object Injection vulnera…
CVE-2026-764649.6—CiscoCisco Campus Gateway SoftwareCWE-119Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities
CVE-2026-1072829.4—AsyncHttpClientasync-http-clientCWE-319AsyncHttpClient: Replay to a different host sends the original host request a…
CVE-2026-924149.3—Apache Software FoundationApache JackrabbitCWE-384Apache Jackrabbit: Pre-auth hijack of cached sessions via derivable WebDAV lo…
CVE-2026-956059.3—Passionate Programmer PeterWP Data AccessCWE-89WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability
CVE-2026-964089.3—Six Apart Ltd.Movable Type Cloud EditionCWE-94A code injection vulnerability exists in the upgrade script of Movable Type, …
CVE-2026-1072049.3—LMCacheLMCacheCWE-306LMCache through 0.5.5 Unauthenticated RCE via /run_script Endpoint
CVE-2026-1071839.2—ggml-orgllama.cppCWE-416llama.cpp before b11393 Use-After-Free via common_chat_peg_mapper chat_parser
CVE-2026-1071949.2—SungrowiSolarCloudCWE-288Sungrow iSolarCloud before 2026 allows authentication bypass and account take…
CVE-2025-705169.1—n/an/aCWE-306The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enfo…
CVE-2026-203289.1—CiscoCisco License On-PremCWE-862Cisco Smart Software Manager On-Prem Arbitrary Account Password Reset Vulnera…
CVE-2026-621769.1—MervinPraisonPraisonAICWE-94PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Gen…
CVE-2026-764549.1—CiscoCisco License On-PremCWE-23Cisco Smart Software Manager On-Prem Unauthenticated API Vulnerability
CVE-2026-764839.1—CiscoCisco License On-PremCWE-522Cisco License On-Prem Security Hardening Release
CVE-2026-1072029.1—jonssonyanh-uiCWE-77CVE-2026-107202
CVE-2026-764538.8—CiscoCisco NX-OS SoftwareCWE-707Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Neut…
CVE-2026-764598.8—CiscoCisco NX-OS SoftwareCWE-787Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds…
CVE-2026-764638.8—CiscoCisco Campus Gateway SoftwareCWE-284Cisco Meraki Security Hardening Release: October 2026 - Improper Access Contr…
CVE-2026-764708.8—CiscoCisco Campus Gateway SoftwareCWE-682Cisco Meraki Hardening Release - Incorrect Calculation Vulnerabilities
CVE-2026-764728.8—CiscoCisco Campus Gateway SoftwareCWE-74Cisco Meraki Security Hardening Release October 2026 - Improper Neutralizatio…
CVE-2026-764848.8—CiscoCisco License On-PremCWE-94Cisco License On-Prem Security Hardening Release
CVE-2026-955348.8—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-502WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-1036688.8—Six Apart Ltd.Movable Type Cloud EditionCWE-89An SQL Injection vulnerability exists in the Site Search function of Movable …
CVE-2026-1065588.8—backstagebackstageCWE-502Backstage: Improper validation of TechDocs MkDocs configuration
CVE-2026-1072058.8—LMCacheLMCacheCWE-306LMCache through 0.5.5 Missing Authentication in MP Coordinator Fleet Control API
CVE-2026-1072068.8—LMCacheLMCacheCWE-306LMCache through 0.5.5 Missing Authentication in MP HTTP Server Management API
CVE-2026-1072798.8—AsyncHttpClientasync-http-clientCWE-303AsyncHttpClient: Digest mutual authentication is switched off by a peer offer…
CVE-2026-977168.7—Absolute SecuritySecure AccessCWE-400Denial of Service in Absolute Secure Access
CVE-2026-1060598.7—gitaheadgitaheadCWE-78GitAhead through 2.7.1 on macOS Command Injection via Show in Finder AppleScript
CVE-2026-1072118.7—qax-osexcelizeCWE-129Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes…
CVE-2026-1072138.7—qax-osexcelizeCWE-476Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst p…
CVE-2026-1072318.7—AsyncHttpClientasync-http-clientCWE-319AsyncHttpClient: Digest challenge without a usable nonce downgrades to Basic …
CVE-2026-764568.6—CiscoCisco NX-OS SoftwareCWE-20Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Inpu…
CVE-2026-764578.6—CiscoCisco NX-OS SoftwareCWE-125Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds…
CVE-2026-764588.6—CiscoCisco NX-OS SoftwareCWE-703Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Hand…
CVE-2026-1071818.6—TelegramTelegram DesktopCWE-143Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via inte…
CVE-2026-344998.5—Johnson ControlsADVMSCWE-321Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS a…
CVE-2026-1060578.5—wummelpatoolCWE-78patool before 4.0.6 OS Command Injection on Windows via shell_quote_nt
CVE-2026-772148.3—libexpatlibexpatCWE-125libexpat Heap Buffer Over-read in xmlparse.c via XML_ParseBuffer
CVE-2026-764688.2—CiscoCisco Campus Gateway SoftwareCWE-20Cisco Meraki Hardening Release - Input Validation Vulnerabilities
CVE-2026-977148.2—Absolute SecuritySecure AccessCWE-400Denial of service vulnerability in Secure Access
CVE-2026-465708.1—n/an/aCWE-122In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_…
CVE-2026-622518.1—sipcapturehomerCWE-89Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/…
CVE-2026-1058168.0—HashiCorpVaultCWE-22Vault Vulnerable to Arbitrary Code Execution via Plugin Catalog Entries Resto…
CVE-2026-1022567.8—SonicWallSMA1000CWE-78Post-authentication Improper Neutralization of Special Elements used in an OS…
CVE-2026-762667.7—SplunkSplunk EnterpriseCWE-269Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise
CVE-2026-1034357.7—Anthropic@anthropic-ai/claude-codeCWE-22Arbitrary File Write via Write-Time Symlink Following (TOCTOU) in Claude Code
CVE-2026-1060567.7—rundeckrundeckCWE-78Rundeck before 6.2.0 OS Command Injection via Windows Job Option Quoting
CVE-2026-1060587.7—gitaheadgitaheadCWE-78GitAhead through 2.7.1 OS Command Injection via Git Filter Filenames
CVE-2026-1065107.7—backstagebackstageCWE-183Backstage: Remote code execution via crafted markdown_extensions in TechDocs …
CVE-2026-1065567.7—backstagebackstageCWE-78Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization
CVE-2026-1065577.7—backstagebackstageCWE-22Backstage: Improper input validation in TechDocs Markdown extension configura…
CVE-2026-427087.6—AF themesWP Post AuthorCWE-89WordPress WP Post Author plugin <= 4.0.0 - SQL Injection vulnerability
CVE-2026-427107.6—10WebSlider by 10WebCWE-89WordPress Slider by 10Web plugin <= 1.2.63 - SQL Injection vulnerability
CVE-2026-427137.6—GopiplusPost title marquee scrollCWE-89WordPress Post title marquee scroll plugin <= 9.9 - SQL Injection vulnerability
CVE-2026-427147.6—Piggly DevPix por Piggly (para Woocommerce)CWE-89WordPress Pix por Piggly (para Woocommerce) plugin <= 2.1.2 - SQL Injection v…
CVE-2026-925437.6—DockerDocker EngineCWE-295Docker Engine insecure-registry fallback via malicious DNS responses
CVE-2026-1071627.6—ExpressGatewayexpress-gatewayCWE-287Express Gateway through 1.16.11 OAuth 2.0 Refresh Token Validation Bypass
CVE-2026-1072817.6—AsyncHttpClientasync-http-clientCWE-346AsyncHttpClient: Connection pool key omits the authenticated principal, so an…
CVE-2026-764677.5—CiscoCisco Campus Gateway SoftwareCWE-664Cisco Meraki Software Hardening Release - Resource Lifetime Management Vulner…
CVE-2026-925317.5—BugTracker.NETBugTracker.NETCWE-78Improper Neutralization of Special Elements used in an OS Command in BugTrack…
CVE-2026-925327.5—BugTracker.NETBugTracker.NETCWE-434Unrestricted Upload of File with Dangerous Type in BugTracker.NET
CVE-2026-963357.5—WPMU DEVForminatorCWE-862WordPress Forminator plugin <= 1.57.2 - Broken Access Control vulnerability
CVE-2026-1071617.5—Red HatRed Hat Enterprise Linux 10CWE-122Cyrus-sasl: heap buffer overflow in cyrus-sasl add_to_challenge() allows mali…
CVE-2026-1072127.5—qax-osexcelizeCWE-770Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows ite…
CVE-2026-1072147.5—qax-osexcelizeCWE-248Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks
CVE-2026-1072157.5—qax-osexcelizeCWE-789Excelize: extractPart allocates attacker-controlled, unbounded and negative-s…
CVE-2026-1072167.5—qax-osexcelizeCWE-674Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly…
CVE-2026-1072177.5—qax-osexcelizeCWE-129Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinat…
CVE-2026-1072197.5—qax-osexcelizeCWE-400Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile
CVE-2026-1072277.5—AsyncHttpClientasync-http-clientCWE-400AsyncHttpClient: Unbounded WebSocket permessage-deflate decompression enables…
CVE-2026-1072327.5—AsyncHttpClientasync-http-clientCWE-319AsyncHttpClient: Origin credentials sent in cleartext to a proxy that rejects…
CVE-2026-465727.4—n/an/aCWE-122In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail…
CVE-2026-764697.4—CiscoCisco Campus Gateway SoftwareCWE-691Cisco Meraki Security Hardening Release: October 2026 Insufficient Control Fl…
CVE-2026-1071777.4—ExpressGatewayexpress-gatewayCWE-1394Express Gateway through 1.16.11 Hardcoded Default cipherKey Exposes OAuth Tokens
CVE-2026-1072307.4—AsyncHttpClientasync-http-clientCWE-346AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiat…
CVE-2026-1061647.3—Progress SoftwareTelerik Document Processing LibrariesCWE-835Infinite Loop in Telerik Document Processing XLS Import
CVE-2026-203627.2—CiscoCisco FinesseCWE-918Cisco Finesse Server-Side Request Forgery Vulnerability
CVE-2026-893227.2—HashiCorpVaultCWE-178Vault ACL Policy Evaluation May Allow Bypass of Deny Restrictions
CVE-2026-1022577.2—SonicWallSMA1000CWE-22A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (…
CVE-2026-426177.1—n/an/aCWE-122In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() …
CVE-2026-426187.1—n/an/aCWE-122In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress(…
CVE-2026-439767.1—wger-projectwgerCWE-863wger: cross-tenant admin notes/contracts leak via gym=None bypass (5 views)
CVE-2026-464347.1—wger-projectwgerCWE-269wger: Trainer Privilege Escalation - Improper Privilege Management
CVE-2026-925337.1—BugTracker.NETBugTracker.NETCWE-24Path Traversal in BugTracker.NET
CVE-2026-946627.1—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-79WordPress Unlimited Elements For Elementor plugin <= 2.0.19 - Cross Site Scri…
CVE-2026-946707.1—Everest FormsEverest FormsCWE-79WordPress Everest Forms plugin <= 3.6.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-955957.1—FontspluginDisable and Remove Google Fonts | GDPR & DSGVO friendlyCWE-79WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2…
CVE-2026-977157.1—Absolute SecuritySecure AccessCWE-400Denial of Service in Absolute Secure Access
CVE-2026-1051387.1—obot-platformobotCWE-522Obot 0.12.0 before 0.26.2 Credential Exposure via MCP Catalog Entry API
CVE-2026-1065607.1—backstagebackstageCWE-22Backstage: Improper repository path validation in a Scaffolder backend module
CVE-2026-1071597.1—miniupnp projectminiupnpdCWE-369MiniUPnPd through 2.3.11 Divide-by-Zero DoS via SSDP M-SEARCH MX Header
CVE-2026-1071807.1—MISPMISPCWE-287MISP: Forced TOTP Enrolment Bypassed via Non-Browser Request Types on otp_req…
CVE-2026-1072237.1—qax-osexcelizeCWE-789Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check an…
CVE-2026-1072707.1—gophishgophishCWE-639Gophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create E…
CVE-2026-924156.9—Apache Software FoundationApache JackrabbitCWE-470Apache Jackrabbit: DavEx client runs Class.forName + (String)-constructor on …
CVE-2026-925426.9—DockerDocker EngineCWE-290Blind VXLAN injection into encrypted overlay networks from cluster peer
CVE-2026-1040746.9—coturncoturnCWE-908Coturn 4.10.0 Uninitialized Stack Memory Disclosure via ERROR-CODE
CVE-2026-1072076.9—LMCacheLMCacheCWE-306LMCache through 0.5.5 Missing Authentication in Frontend Node Catalog Allows …
CVE-2026-1072716.9—gophishgophishCWE-348Gophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For Spoofing
CVE-2026-1072806.9—AsyncHttpClientasync-http-clientCWE-1275AsyncHttpClient: Cookie Domain attribute is not checked against the public su…
CVE-2026-1073536.9—ljharbtraverseCWE-1321traverse: set() can write to built-in prototypes via an untrusted path
CVE-2026-1071766.8—Red HatRed Hat OpenShift Container Platform 4CWE-250Cluster-samples-operator: role reads all secrets in openshift-config, not jus…
CVE-2026-1072286.8—AsyncHttpClientasync-http-clientCWE-287AsyncHttpClient CookieStore Silently Overrides Caller's Explicit Cookie Heade…
CVE-2026-14036.5—GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-203216.5—CiscoCisco Application Policy Infrastructure Controller (APIC)CWE-544Cisco Application Policy Infrastructure Controller API Command Injection Vuln…
CVE-2026-419586.5—visidatavisidataCWE-22A path traversal vulnerability exists in the unzip_http RemoteZipFile extract…
CVE-2026-464386.5—wger-projectwgerCWE-639wger: Cross-User Data Corruption via Missing Ownership Check on WorkoutLog.sl…
CVE-2026-621796.5—MervinPraisonpraisonai-platformCWE-862PraisonAI: Platform members can delete owner issue dependencies through membe…
CVE-2026-762656.5—SplunkSplunk EnterpriseCWE-284Improper Access Control through REST API Endpoints in Splunk Secure Gateway
CVE-2026-762696.5—SplunkSplunk EnterpriseCWE-639Improper Access Control in Search Job Retrieval through the REST API in Splun…
CVE-2026-762706.5—SplunkSplunk EnterpriseCWE-89Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splun…
CVE-2026-762716.5—SplunkSplunk EnterpriseCWE-407Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Sp…
CVE-2026-762746.5—SplunkSplunk EnterpriseCWE-918Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Spl…
CVE-2026-764886.5—CiscoCisco Application Policy Infrastructure Controller (APIC)CWE-264Cisco Application Policy Infrastructure Controller Authenticated Information …
CVE-2026-1072206.5—qax-osexcelizeCWE-125Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref
CVE-2026-1072216.5—qax-osexcelizeCWE-787Excelize: a row whose earlier cell has a higher column reference than its las…
CVE-2026-1072226.5—qax-osexcelizeCWE-129Excelize: GetConditionalFormats indexes conditional-formatting rule sub-eleme…
CVE-2026-1072246.5—qax-osexcelizeCWE-190Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader
CVE-2026-1072256.5—qax-osexcelizeCWE-20Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml
CVE-2026-1071746.4—Red HatOpenShift ServerlessCWE-61Source-to-image: source-to-image: security boundary bypass via absolute symbo…
CVE-2026-335866.3—OVHcloudOVHcloudCWE-290Authenticated SMTP Sender Address Forgery
CVE-2026-762806.3—SplunkSplunk EnterpriseCWE-732Incorrect Permission Assignment for App Key Value Store Collections in Splunk…
CVE-2026-1060646.3—Red HatRed Hat Enterprise Linux 10CWE-119Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions
CVE-2026-1060656.3—Red HatRed Hat Enterprise Linux 10CWE-119Gimp: gimp: heap buffer overflow in pcx export on oversized image dimensions
CVE-2026-1060666.3—Red HatRed Hat Enterprise Linux 10CWE-119Gimp: gimp: heap buffer overflow in raw data export on oversized image dimens…
CVE-2026-1060676.3—Red HatRed Hat Enterprise Linux 10CWE-119Gimp: gimp: heap buffer overflow in hot color filter on oversized image
CVE-2026-1065596.3—backstagebackstageCWE-22Backstage: Improper input validation in Confluence to Markdown scaffolder module
CVE-2026-1072696.3—gophishgophishCWE-208Gophish through 0.12.1 Username Enumeration via POST /login Timing Discrepancy
CVE-2026-1072766.3—MISPMISPCWE-362MISP Email OTP Race Condition Allows One-Time Password to Be Consumed by Mult…
CVE-2026-1073526.3—AWSAmazon AthenaCWE-424Missing authorization checks in Amazon Athena engine version 3 request handling
CVE-2026-1065796.2—ImageMagickImageMagickCWE-551ImageMagick: Policy Bypass when using coder as the domain.
CVE-2026-1071676.2—Red HatRed Hat Enterprise Linux 10CWE-416M17n-lib: heap use-after-free write in re_init_ic()
CVE-2026-1071686.2—Red HatRed Hat Enterprise Linux 10CWE-835M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()
CVE-2026-1071696.2—Red HatRed Hat Enterprise Linux 10CWE-476M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8
CVE-2025-705196.1—n/an/aCWE-79The device log component of Fanvil x7a firmware version 2.6.0.1182 does not p…
CVE-2026-941546.1—r3098Aurora HeatmapCWE-79Aurora Heatmap <= 1.7.2 - Unauthenticated Stored Cross-Site Scripting via 'ur…
CVE-2026-1022586.1—SonicWallSMA1000CWE-79Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been …
CVE-2026-1073636.1—OpenStackZaqarCWE-472In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the p…
CVE-2026-977176.0—Absolute SecuritySecure AccessCWE-400Denial of Service in Absolute Secure Access
CVE-2026-1058185.9—HashiCorpVaultCWE-345Vault PKI ACME Issues Certificate With Unvalidated SANs
CVE-2026-1065655.9—ImageMagickImageMagickCWE-400ImageMagick: Infinite Loop in bzip2 compressed images.
CVE-2026-1065675.9—ImageMagickImageMagickCWE-196ImageMagick: Infinite Loop in PSD decoder on 32-bit builds
CVE-2026-1065785.9—ImageMagickImageMagickCWE-590ImageMagick: Invalid Memory Free in MVG decoder
CVE-2026-1071515.9—Red HatRed Hat Satellite 6CWE-306Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenti…
CVE-2026-1072095.9—ImageMagickImageMagickCWE-415ImageMagick: Use-After-Free in RSVG decoder that is build without cairo support
CVE-2026-1072855.9—AsyncHttpClientasync-http-clientCWE-319AsyncHttpClient: WebSocket proxy credentials sent to the origin server over a…
CVE-2026-1073145.9—pgjdbcpgjdbcCWE-636pgjdbc does not enforce requireAuth when the value excludes every authenticat…
CVE-2026-200385.8—CiscoCisco NX-OS System Software in ACI ModeCWE-284Cisco Nexus 9000 Series Fabric Switches in ACI Mode Policy-Based Redirect End…
CVE-2026-201735.8—CiscoCisco NX-OS SoftwareCWE-770Cisco NX-OS Software Denial of Service Vulnerability
CVE-2026-425325.5—visidatavisidataCWE-22A path traversal vulnerability exists in the EmailSheet extract_parts functio…
CVE-2026-465715.5—n/an/aCWE-125In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name…
CVE-2026-885145.5—n/an/aCWE-200An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sens…
CVE-2026-1071665.5—n/aOpen5GSCWE-400Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation o…
CVE-2026-175385.4—latepointAppointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressCWE-639Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress …
CVE-2026-451615.4—wger-projectwgerCWE-352wger: trainer_login accepts GET - CSRF bypass enables forced session rebinding
CVE-2026-1058205.4—HashiCorpVault EnterpriseCWE-22Vault ACL Policy Cache Vulnerable to Cross-Namespace Policy Resolution
CVE-2026-762865.3—SplunkSplunk MCP ServerCWE-918Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server
CVE-2026-1051395.3—obot-platformobotCWE-863Obot 0.26.0 before 0.26.2 Authorization Bypass via vMCP Profile Prompts and R…
CVE-2026-1065635.3—backstagebackstageCWE-20Backstage: Improper entity validation in deprecated Kubernetes services endpoint
CVE-2026-1065645.3—ImageMagickImageMagickCWE-122ImageMagick: Heap Buffer Over-Write in EXR decoder
CVE-2026-1065685.3—ImageMagickImageMagickCWE-835ImageMagick: Infinite Loop when reading a crafted XMP profile
CVE-2026-1065695.3—ImageMagickImageMagickCWE-770ImageMagick: Denial of service in ASE decoder because of missing security checks
CVE-2026-1065725.3—ImageMagickImageMagickCWE-674ImageMagick: Stack Overflown CALS decoder due to missing depth check.
CVE-2026-1065735.3—ImageMagickImageMagickCWE-400ImageMagick: Denial of service in MVG decoder
CVE-2026-1065745.3—ImageMagickImageMagickCWE-122ImageMagick: Heap Buffer Over-Write in distributed pixel cache server will re…
CVE-2026-1065755.3—ImageMagickImageMagickCWE-775ImageMagick: Unclosed file pointer in magick script
CVE-2026-1065765.3—ImageMagickImageMagickCWE-400ImageMagick: Denial of service possible when parsing an XMP profile.
CVE-2026-1065775.3—ImageMagickImageMagickCWE-94ImageMagick: Code Injection in the postscript coders
CVE-2026-1071755.3—MISPMISPCWE-284MISP Correlation Engine Fails to Refresh When Event Distribution or Sharing G…
CVE-2026-1072085.3—ImageMagickImageMagickCWE-400ImageMagick: Denial of service with crafted XMP profile
CVE-2026-1072105.3—ImageMagickImageMagickCWE-409ImageMagick: Policy Bypass in MAT decoder when reading highly compressed data
CVE-2026-1072185.3—qax-osexcelizeCWE-129Excelize: RIGHT() on supplementary-plane text slices with a negative index an…
CVE-2026-1072735.3—gophishgophishCWE-918Gophish 0.11.0 through 0.12.1 SSRF via POST /api/import/site
CVE-2026-1072785.3—MISPMISPCWE-20MISP Object Sync Drops Objects and Attributes When Description Is Empty
CVE-2026-1073155.3—pgjdbcpgjdbcCWE-226pgjdbc pads a value shorter than its declared length with bytes of earlier st…
CVE-2026-1018865.1—CiscoJabber for AndroidCWE-22Cisco Jabber for Android Path Traversal via Shared Content URI
CVE-2026-1065715.1—ImageMagickImageMagickCWE-190ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a …
CVE-2026-1065615.0—backstagebackstageCWE-200Backstage: Sensitive information disclosure in Kubernetes resource queries
CVE-2026-764374.9—CiscoCisco License On-PremCWE-78Cisco Smart Software Manager On-Prem Command Injection Vulnerability
CVE-2026-764524.9—CiscoCisco License On-PremCWE-89Cisco Smart Software Manager On-Prem SQL Injection Vulnerability
CVE-2026-464374.8—wger-projectwgerCWE-287wger: API credentials remain valid after logout/password change
CVE-2026-200324.4—CiscoCisco NX-OS SoftwareCWE-653Cisco NX-OS Software Python Sandbox Escape Vulnerability
CVE-2026-762644.3—SplunkSplunk EnterpriseCWE-863Improper Authorization through the REST API in Splunk Enterprise
CVE-2026-762674.3—SplunkSplunk EnterpriseCWE-117Log Injection through the REST API in Splunk App for Splunk O11y Cloud
CVE-2026-762724.3—SplunkSplunk EnterpriseCWE-862Missing Access Control through the REST API in Splunk Secure Gateway
CVE-2026-762734.3—SplunkSplunk EnterpriseCWE-20Improper Input Validation through the collect Command in Splunk Enterprise
CVE-2026-762754.3—SplunkSplunk EnterpriseCWE-285Improper Authorization in Search Job Listings through the REST API in Splunk …
CVE-2026-762764.3—SplunkSplunk EnterpriseCWE-1188Information Disclosure in the Discover Splunk Observability Cloud app through…
CVE-2026-762784.3—SplunkSplunk EnterpriseCWE-639Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise
CVE-2026-762794.3—SplunkSplunk EnterpriseCWE-20Improper Input Validation of Index Names through the collect Command in Splun…
CVE-2026-1065624.3—backstagebackstageCWE-754Backstage: Incorrect authorization in search engine permission filtering
CVE-2026-1065704.3—ImageMagickImageMagickCWE-400ImageMagick: Denial of service in distributed pixel cache server
CVE-2026-1073134.2—pgjdbcpgjdbcCWE-201pgjdbc stores bytes of earlier messages in place of a large value on GSS-encr…
CVE-2026-762774.1—SplunkSplunk EnterpriseCWE-20Improper Input Validation of Native Splunk Usernames through the REST API in …
CVE-2026-1065664.0—ImageMagickImageMagickCWE-61ImageMagick: Policy Bypass in delegate symlink cleanup due to missing check
CVE-2026-1065804.0—ImageMagickImageMagickCWE-284ImageMagick: Policy Bypass in CUT encoder
CVE-2026-1072294.0—AsyncHttpClientasync-http-clientCWE-384AsyncHttpClient: Incomplete origin checks in the default cookie store allow c…
CVE-2026-1072833.7—AsyncHttpClientasync-http-clientCWE-338AsyncHttpClient: Digest authentication cnonce generated with a non-cryptograp…
CVE-2026-1072843.7—AsyncHttpClientasync-http-clientCWE-345AsyncHttpClient: WebSocket handshake continues after a failed Sec-WebSocket-A…
CVE-2026-1071702.9—Red HatRed Hat Enterprise Linux 10CWE-476M17n-lib: null dereference in minput_open_im() after failed m17n_init()
CVE-2026-1051402.3—obot-platformobotCWE-362Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 Race Condition Restores Re…
CVE-2026-1072722.3—gophishgophishCWE-79Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages
CVE-2026-1071252.1—XnViewClassicCWE-119XnView Classic FLI File heap-based overflow
CVE-2025-70515await—n/an/a—The device log component of Fanvil x7a firmware version 2.6.0.1182 does not p…
CVE-2025-70517await—n/an/a—The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforc…
CVE-2025-70520await—n/an/a—The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enfo…
CVE-2025-70522await—n/an/a—The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforc…
CVE-2026-42616await—n/an/a—In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat…
CVE-2026-46569await—n/an/a—In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tai…
CVE-2026-56851await—golang.org/x/textgolang.org/x/text/secure/precis—Panic parsing crafted input in x/text/secure/precis in golang.org/x/text
CVE-2026-76281await—SplunkSplunk EnterpriseCWE-284Improper Access Control in Splunk Enterprise
CVE-2026-76282await—SplunkSplunk EnterpriseCWE-664Improper Control of a Resource Through its Lifetime in Splunk Enterprise
CVE-2026-76283await—SplunkSplunk EnterpriseCWE-693Protection Mechanism Failure in Splunk Enterprise
CVE-2026-76284await—SplunkSplunk EnterpriseCWE-707Improper Neutralization in Splunk Enterprise
CVE-2026-76285await—SplunkSplunk EnterpriseCWE-710Improper Adherence to Coding Standards in Splunk Enterprise
CVE-2026-98373await—LinuxLinux—mm/hugetlb: preserve mremap address delta when skipping page tables
CVE-2026-98374await—LinuxLinux—tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
CVE-2026-103371await—Apache Software FoundationApache Geode—Apache Geode: Management REST API: Insertion of Sensitive Information into Lo…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-10-07 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.