boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 2, 2026 · all times UTC← 2026-09-01 · archive

Security Box Score — September 2, 2026

CISA adds 7 to KEV; 322 CVEs published, led by Jenkins Project (33).

322 CVEs published September 2, 2026: 23 critical, 113 high, 155 medium, 25 low; 0 in the KEV catalog at press time; 4 with a public exploit reference; 6 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 297 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published79935535——
KEV catalog size1694

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2270 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux03961418197464211230.17.8.00160
google262190276850977877760.37.5.0026+26 ▲
microsoft11900145128445615287281.57.8.0044+1 ▲
red hat206474026830335200.06.6.0028+16 ▲
apple0316598516578882.56.5.00290
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse33151781000.07.8.0039+3 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco11952445260561313.77.5.0044+11 ▲
ubiquiti059362210335.19.1.00490
palo alto networks0371321121325.44.7.00200
netgear03200275000.04.3.00250
fortinet0307814128620.07.0.00500
f572461431414.28.7.0057+7 ▲
vmware019410327210.58.3.00400
sonicwall216484019425.07.8.0027+2 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache1508103217174133320.47.5.0049+1 ▲
mozilla342217376580900.08.1.0029+34 ▲
drupal2694119658411.15.7.0024+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+3 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm06191482861778610.27.6.00300
adobe06065030024791930.57.8.00210
progress2631439100611.68.1.0037+2 ▲
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.00320
zohocorp1113620000.08.8.0144+1 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link045151398300.08.5.01570
rockwell automation174253160000.08.6.0029+17 ▲
siemens03722483000.07.3.00160
synology02736153000.05.6.00250
schneider electric4131840000.08.2.0032+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
mitsubishi electric050410000.07.2.00520
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1318413102645210.57.3.0021+13 ▲
spring017011598515000.06.5.00240
sourcecodester0169009277000.05.5.00290
nvidia3016420115290000.07.8.0026+30 ▲
splunk0128647705110.86.5.00250
elastic35122025943100.06.5.0029+35 ▲
itsourcecode0116003284000.02.1.00270
openclaw01110583914000.07.0.00260

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-34486.986299.97.5
CVE-2026-63077.877199.79.8
CVE-2026-60004.867899.79.8
CVE-2026-72898.823299.610.0
CVE-2026-18556.401698.58.2
CVE-2026-64638.312098.18.9
CVE-2026-71362.251497.89.1
CVE-2026-73570.205397.38.9
CVE-2026-64849.164196.89.3
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.8232KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1645
oracle890
microsoft462
google428
ibm390
red hat239
apache165
splunk110
adobe94
mozilla94
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
berriai4
oracle4
solarwinds4
sonicwall4
Most-affected ecosystems
EcosystemAdvisories
Maven64
Packagist32
PyPI15
npm15
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-18556N-able0
CVE-2026-20349Cisco0
CVE-2026-34486Apache Software Foundation0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171750
CVE-2021-27102n/a2021-11-171750
CVE-2021-27101n/a2021-11-171750
CVE-2021-27103n/a2021-11-171750
CVE-2021-21017Adobe2021-11-171750
CVE-2021-28550Adobe2021-11-171750
CVE-2021-42013Apache Software Foundation2021-11-171750
CVE-2021-41773Apache Software Foundation2021-11-171750
CVE-2021-30858Apple2021-11-171750
CVE-2021-30860Apple2021-11-171750

Transactions

ADDED TO KEV — CVE-2026-48710 (Kludex starlette). Remediation due September 16, 2026.

ADDED TO KEV — CVE-2026-49869 (kestra-io kestra). Remediation due September 5, 2026.

ADDED TO KEV — CVE-2026-59822 (BerriAI litellm). Remediation due September 16, 2026.

ADDED TO KEV — CVE-2026-82329 (jfrog artifactory). Remediation due September 5, 2026.

ADDED TO KEV — CVE-2026-83548 (SonicWall SMA1000). Remediation due September 5, 2026.

ADDED TO KEV — CVE-2026-83549 (SonicWall SMA1000). Remediation due September 5, 2026.

ADDED TO KEV — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Remediation due September 5, 2026.

EXPLOIT PUBLISHED — gitpython-developers GitPython: 6 CVEs (CVE-2026-76221, CVE-2026-76222, CVE-2026-78675, CVE-2026-78676, CVE-2026-78677, CVE-2026-78678). Public exploit references added.

EXPLOIT PUBLISHED — traefik: 3 CVEs (CVE-2026-48020, CVE-2026-48491, CVE-2026-53622). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-16253 (Unknown Total Upkeep). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25550 (Seagull Software, LLC. BarTender 2010). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25551 (Seagull Software, LLC. BarTender 2021). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42264 (axios). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42579 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 8). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62384 (nltk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82641 (Keploy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82669 (klaussilveira GitList). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82679 (diem-project diem). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82691 (D-Link DNS-320L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82696 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82701 (code-projects Online Shopping System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82803 (armink struct2json). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82810 (extension.vn 2FA Authenticator Extension). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82817 (dibo-software diboot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82834 (Doccano Open Source Annotation Tools for Machine Learning Practitioners). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82876 (Phison Electronics Corporation PS3111-S11 Controller Firmware). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82909 (QuantumNous new-api). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-83744 (invoiceninja Invoice Ninja). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84288 (NousResearch hermes-agent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84289 (NousResearch hermes-agent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Public exploit reference added.

REJECTED — CVE-2026-39909 (ggml-org llama.cpp). Record withdrawn by the CNA.

RESCORED — Spring Cloud Function: 4 CVEs (CVE-2026-59297, CVE-2026-59298, CVE-2026-59299, CVE-2026-59300). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-20579 (AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics ). CVSS 3.4 → 6 (NVD).

RESCORED — CVE-2026-16821 (IBM AIX). CVSS 7 → 7.8 (NVD).

RESCORED — CVE-2026-18504 (fastify). CVSS 5.4 → 5.3 (NVD).

RESCORED — CVE-2026-19478 (GitLab). CVSS 9.4 → 9.1 (NVD).

RESCORED — CVE-2026-24184 (NVIDIA Cumulus Linux GA). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2026-47606 (NVIDIA Triton Inference Server). CVSS 6.5 → 9.1 (NVD).

RESCORED — CVE-2026-47864 (Spring Integration). CVSS 6.4 → 9.8 (NVD).

RESCORED — CVE-2026-47875 (Spring Batch). CVSS 5.6 → 9.8 (NVD).

RESCORED — CVE-2026-47877 (Spring Security). CVSS 8.2 → 6.1 (NVD).

RESCORED — CVE-2026-49096 (Elastic Kibana). CVSS 4.3 → 3.5 (NVD).

RESCORED — CVE-2026-59277 (Spring Security). CVSS 3.7 → 5.3 (NVD).

RESCORED — CVE-2026-66376 (jfrog artifactory). CVSS 4.2 → 5.4 (NVD).

RESCORED — CVE-2026-71474 (Red Hat Advanced Cluster Management for Kubernetes 2.11). CVSS 6.5 → 7.1 (NVD).

RESCORED — CVE-2026-71475 (Red Hat Advanced Cluster Management for Kubernetes 2.13). CVSS 5 → 6.8 (NVD).

RESCORED — CVE-2026-7680 (jsbroks COCO Annotator). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-78607 (Elasticsearch). CVSS 5.4 → 7.1 (NVD).

PATCH SHIPPED — Red Hat Advanced Cluster Management for Kubernetes 2.17: 6 CVEs (CVE-2026-66780, CVE-2026-66782, CVE-2026-66783, CVE-2026-66785, CVE-2026-66787, CVE-2026-66788). Fix versions published.

PATCH SHIPPED — CVE-2023-50224 (TP-Link TL-WR841N). Fixed in TL-WR841N V11_211209.

PATCH SHIPPED — CVE-2026-82641 (Keploy). Fixed in Keploy 3.6.26.

ENRICHED — Linux: 12 CVEs (CVE-2024-27010, CVE-2024-58095, CVE-2025-22104, CVE-2025-38203, CVE-2025-38237, CVE-2026-64049, CVE-2026-64052, CVE-2026-64054, CVE-2026-64059, CVE-2026-64060, CVE-2026-64062, CVE-2026-64063). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

322 CVEs published. 25 box scores, 297 table rows — nothing truncated.

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access M…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0144   71.4     —
AFFECTED
  Product                            Versions     Fixed
  ManageEngine Password Manager Pro  unspecified  —
  ManageEngine PAM360                unspecified  —
  ManageEngine Access Manager Plus   unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Sep 2   Published (CNA: Zohocorp)
CWE-89 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Received
bdthemes SigmaForms Pro – AI Generated Forms — SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.4     —
AFFECTED
  Product                              Versions     Fixed
  SigmaForms Pro – AI Generated Forms  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 2   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   R  C  H  H  H    7.6   .0068   49.8     —
AFFECTED
  Product  Versions  Fixed
  WeOS     5.24 –    —
TIMELINE
  Apr 24  Reserved by CNA
  Sep 2   Published (CNA: mitre)
CWE-78 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
dplugins DevKit Pro — DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0065   48.5     —
AFFECTED
  Product     Versions     Fixed
  DevKit Pro  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Sep 2   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
The Libreswan Project libreswan — FIPS mode assertion failure via malicious CERT payload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0056   44.2     —
AFFECTED
  Product    Versions  Fixed
  libreswan  3.0 –     5.3.2
TIMELINE
  Jul 7   Reserved by CNA
  Sep 2   Published (CNA: libreswan)
CWE-252, CWE-617 · CNA: libreswan · CVSS v3.1 · 2 references · NVD status: Received
JoomUnited WP File Download — WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0052   42.0     —
AFFECTED
  Product           Versions     Fixed
  WP File Download  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Sep 2   Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
nasa-jpl ION-DTN — ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnv
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0048   39.4     —
AFFECTED
  Product  Versions     Fixed
  ION-DTN  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · CVSS v4.0 · 7 references · NVD status: Received
coollabsio coolify — Coolify before 4.2.0 Remote Code Execution via Environment Variable Key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0045   37.8     —
AFFECTED
  Product  Versions     Fixed
  coolify  unspecified  4.2.0
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
n/a Piwigo — Piwigo Image Derivative i.php path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.1     —
AFFECTED
  Product  Versions  Fixed
  Piwigo   16.0 –    —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Eclipse Foundation Eclipse Ditto — In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over H…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   L    5.3   .0040   32.8     —
AFFECTED
  Product        Versions  Fixed
  Eclipse Ditto  3.9.0 –   —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: eclipse)
CWE-674, CWE-918 · CNA: eclipse · CVSS v4.0 · 2 references · NVD status: Received
Unknown User Frontend — WP User Frontend < 4.3.11 - Subscriber+ PHP Object Injection via Frontend Post Edit Form
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0039   31.6     —
AFFECTED
  Product        Versions     Fixed
  User Frontend  unspecified  —
TIMELINE
  Aug 6   Reserved by CNA
  Sep 2   Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
facefusion before 3.7.0 Path Traversal via Job Identifier
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   H   N    8.7   .0037   30.5     —
AFFECTED
  Product     Versions     Fixed
  facefusion  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0037   29.7     —
AFFECTED
  Product                Versions     Fixed
  Team Password Manager  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-640 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
OpenAtomFoundation pikiwidb — Pika Unauthenticated Replication Access via Internal Protobuf Port
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   L   L    8.8   .0035   28.3     —
AFFECTED
  Product   Versions     Fixed
  pikiwidb  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
APITable through 1.13.0-beta.1 Missing Authentication on the Internal Organization Load or Search Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0035   27.6     —
AFFECTED
  Product   Versions     Fixed
  apitable  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
MythicalLTD FeatherPanel — FeatherPanel before 1.3.7.10 Privilege Escalation via Subuser Permission Update
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0032   24.4     —
AFFECTED
  Product       Versions     Fixed
  FeatherPanel  unspecified  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
wpmudev Broken Link Checker — Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0030   22.6     —
AFFECTED
  Product              Versions     Fixed
  Broken Link Checker  unspecified  —
TIMELINE
  Aug 17  Reserved by CNA
  Sep 2   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 13 references · NVD status: Deferred
melograno Booking for Appointments and Events Calendar – Amelia — Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0029   21.2     —
AFFECTED
  Product                                                Versions  Fixed
  Booking for Appointments and Events Calendar – Amelia  8.0 –     —
TIMELINE
  May 20  Reserved by CNA
  Sep 2   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6   .0029   21.0     —
AFFECTED
  Product  Versions  Fixed
  Baserow  2.3.3 –   —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 2   Published (CNA: Fluid Attacks)
CWE-89 · CNA: Fluid Attacks · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  L  L    8.6   .0028   20.6     —
AFFECTED
  Product  Versions     Fixed
  MinKNOW  unspecified  —
TIMELINE
  May 17  Reserved by CNA
  Sep 2   Published (CNA: mitre)
CWE-306 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   N   N   N   H    7.1   .0027   19.3     —
AFFECTED
  Product        Versions     Fixed
  PX4-Autopilot  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-787 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   L    2.1   .0027   18.9     —
AFFECTED
  Product   Versions  Fixed
  CowAgent  2.1.0 –   —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulDB)
CWE-404 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
zhayujie CowAgent Bash Tool bash.py denial of service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   L    2.1   .0027   18.9     —
AFFECTED
  Product   Versions  Fixed
  CowAgent  2.1.0 –   —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulDB)
CWE-404 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
bookstackapp bookstack — BookStack before 26.05.4 Stored XSS via Drawing Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   N    9.3   .0026   16.9     —
AFFECTED
  Product    Versions     Fixed
  bookstack  unspecified  26.05.4
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
n/a gouguoa — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0025   15.8     —
AFFECTED
  Product  Versions  Fixed
  gouguoa  5.0 –     6.0.3
TIMELINE
  Sep 1   Reserved by CNA
  Sep 2   Published (CNA: VulDB)
CWE-913, CWE-915 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-846976.915.5axllentmailpitCWE-918Mailpit SSRF Deny List Bypass via Azure Metadata and IPv6 Prefix
CVE-2025-79636.49.0tymoteyEasy Waveform PlayerCWE-79Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-844372.08.8n/aOpenCartCWE-79OpenCart Autocomplete Workflow address.php cross site scripting
CVE-2026-844382.08.8n/aOpenCartCWE-79OpenCart Autocomplete Workflow edit.php cross site scripting
CVE-2026-142156.58.3UnknownBooking for Appointments and Events CalendarCWE-862Amelia < 2.4.9 - Unauthenticated Post-Booking Action Trigger
CVE-2026-197045.38.2UnknownCommentsCWE-89Comments – wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi
CVE-2026-128657.18.1UnknownPhoto Gallery by 10WebCWE-79Photo Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged Parameters
CVE-2026-829686.47.2Red HatRed Hat Build of KeycloakCWE-639Keycloak-services: keycloak-services: cross-session email verification proof …
CVE-2026-38516.46.8Elegant ThemesDiviCWE-79Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
CVE-2026-818078.86.8UnknownSimple Ajax ChatCWE-79Simple Ajax Chat < 20260827 - Unauthenticated Stored XSS via Chat Message Lin…
CVE-2026-777927.56.8UnknownRegistrationMagicCWE-79RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field
CVE-2026-847015.16.7nocobasenocobaseCWE-79NocoBase Rich Text Field Stored Cross-Site Scripting via API
CVE-2026-536834.36.6Red HatRed Hat Enterprise Linux 10—Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_passwor…
CVE-2026-844311.96.2AirAsiaMOVE AppCWE-22AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRe…
CVE-2026-844421.96.2MapQuestGet Directions AppCWE-22MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt…
CVE-2026-197196.85.9UnknownSocial Media Share Buttons & Social Sharing IconsCWE-79Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stor…
CVE-2026-197237.15.8UnknownSocial Media Share Buttons & Social Sharing IconsCWE-79Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Reflected XSS via…
CVE-2025-156636.85.8UnknownUltimate Before After Image Slider & GalleryCWE-79BEAF < 4.7.19 - Author+ Stored XSS via After Label
CVE-2025-156646.85.8UnknownUltimate Before After Image Slider & GalleryCWE-79BEAF < 4.7.19 - Author+ Stored XSS via Before Label
CVE-2026-38506.45.4Elegant ThemesDiviCWE-79Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
CVE-2026-817378.85.1UnknownFAQ Builder AYSCWE-79FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_i…
CVE-2026-777825.35.1UnknownRank Math SEOCWE-200Rank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content D…
CVE-2026-821824.15.1UnknownWPvivid — Backup, Migration & StagingCWE-89WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation
CVE-2026-846969.34.4Phison Electronics CorporationPS3111-S11 Controller FirmwareCWE-306Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique…
CVE-2026-821838.14.4UnknownOAuth Single Sign OnCWE-287OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Un…
CVE-2026-828837.14.4MarcusLogin With AjaxCWE-79WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulner…
CVE-2026-169665.34.4UnknownSolace ExtraCWE-200Solace Extra < 1.7.0 - Unauthenticated Draft/Private Site Builder Content Dis…
CVE-2026-192515.34.4UnknownUltimate MemberCWE-200Ultimate Member < 2.13.0 - Unauthenticated Unapproved Comment Disclosure via …
CVE-2026-169834.34.4UnknownGutentorCWE-200Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure vi…
CVE-2026-152325.34.2UnknownMotoPress Appointment BookingCWE-639Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Dele…
CVE-2026-749275.34.2UnknownMultiVendorXCWE-862MultiVendorX 5.0.13 - 5.0.14 - Unauthenticated Vendor PII and Payout Data Dis…
CVE-2026-125268.14.1UnknownAdvanced Custom Fields: ExtendedCWE-287Advanced Custom Fields: Extended < 0.9.2.7 - Unauthenticated Administrator Ac…
CVE-2026-781515.34.1UnknownFormLayerCWE-200FormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Su…
CVE-2026-811955.34.1UnknownMasterStudy LMS WordPress PluginCWE-200MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via …
CVE-2026-811975.34.1UnknownMasterStudy LMS WordPress PluginCWE-200MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosur…
CVE-2026-194537.13.8UnknownJetBackupCWE-269JetBackup 3.1.7.9 - 3.1.23.3 - Subscriber+ Privilege Escalation via Restore A…
CVE-2026-777644.33.8UnknownGamiPressCWE-639GamiPress < 7.9.9.6 - Subscriber+ Arbitrary User Points and Achievement Award…
CVE-2026-777833.73.8UnknownRank Math SEOCWE-639Rank Math SEO < 1.0.277 - Unauthenticated Non-Public Post Schema and Content …
CVE-2026-777842.73.8UnknownRank Math SEOCWE-639Rank Math SEO < 1.0.277 - Author+ Robots and Pillar Content Meta Update on No…
CVE-2026-815835.43.4UnknownTheme My LoginCWE-269Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creatio…
CVE-2026-804678.13.1UnknownAdvanced Custom Fields: ExtendedCWE-269Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privileg…
CVE-2026-814286.53.1UnknownWC VendorsCWE-639WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modifi…
CVE-2026-777884.93.1UnknownRank Math SEOCWE-639Rank Math SEO < 1.0.277 - Author+ Arbitrary Post and User Metadata Overwrite …
CVE-2026-811944.33.1UnknownMasterStudy LMS WordPress PluginCWE-639MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure…
CVE-2026-814274.33.1UnknownWC VendorsCWE-862WC Vendors < 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status Change
CVE-2026-811983.83.1UnknownMasterStudy LMS WordPress PluginCWE-639MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and T…
CVE-2026-777852.73.1UnknownRank Math SEOCWE-639Rank Math SEO < 1.0.277 - Author+ Non-Public Post Content Disclosure via Abil…
CVE-2026-777872.73.1UnknownRank Math SEOCWE-862Rank Math SEO < 1.0.277 - Author+ Term Metadata Update and Cross-Object Post …
CVE-2026-811962.73.1UnknownMasterStudy LMS WordPress PluginCWE-639MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR
CVE-2026-814264.31.7UnknownWC VendorsCWE-352WC Vendors < 2.7.2.1 - Order Shipment Status Change via CSRF
CVE-2026-814324.31.7UnknownJetStyleManager for GutenbergCWE-352JetStyleManager < 1.3.9 - Skin Deletion and Modification via CSRF
CVE-2026-796214.30.9UnknownCatalogXCWE-345CatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared Transient
CVE-2026-811995.30.7UnknownMasterStudy LMS WordPress PluginCWE-200MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via …
CVE-2026-435710.0—UnknownEmbed HTML5 GameCWE-434Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload
CVE-2026-770099.9—UnknownWatchMan-Site7CWE-94WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console
CVE-2025-93149.8—UnknownDeveloper ToolsCWE-434Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload
CVE-2026-191179.8—DelineaSecret Server (On-Prem)CWE-290Delinea Secret Server FIDO2 credential registration authentication bypass vul…
CVE-2026-202129.8—CiscoCisco NX-OS SoftwareCWE-1327Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction La…
CVE-2026-202749.8—CiscoCisco IOS XR SoftwareCWE-664Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-202799.8—CiscoCisco IOS XR SoftwareCWE-284Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-536119.8—AS203038looking-glassCWE-78Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGP…
CVE-2026-812949.8—Paul RyanAuthorizerCWE-266WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability
CVE-2026-536499.6—BishopFoxjoroCWE-306Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
CVE-2026-536709.3—vbpfprevailCWE-682PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB acc…
CVE-2026-536719.3—vbpfprevailCWE-682PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to p…
CVE-2026-812869.3—WC LoversWCFM MarketplaceCWE-89WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability
CVE-2026-786899.2—F5NGINX JavaScriptCWE-122NGINX ngx_http_js_module vulnerablility
CVE-2026-847959.2—craftcmscmsCWE-269Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance
CVE-2026-667869.1—Red HatRed Hat Advanced Cluster Management for Kubernetes 2.17CWE-94Submariner: submariner: ipsec.conf stanza injection via remote-supplied cable…
CVE-2026-734759.1—DrupalCommerce PayPalCWE-863Commerce PayPal - Moderately critical - Access bypass - SA-CONTRIB-2026-095
CVE-2026-829559.0—Eclipse FoundationEclipse aeriOSCWE-295In the current development version of Eclipse aeriOS, which has not yet had a…
CVE-2026-183298.8—F5NGINX JavaScriptCWE-636NGINX ngx_http_js_module vulnerability
CVE-2026-202758.8—CiscoCisco IOS XR SoftwareCWE-682Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-202788.8—CiscoCisco IOS XR SoftwareCWE-707Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-202808.8—CiscoCisco IOS XR SoftwareCWE-703Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-537068.8—vbpfprevailCWE-682PREVAIL: ALU32 pointer arithmetic accepted without is64 gate — verifier emits…
CVE-2026-812838.8—weDevsWP User FrontendCWE-502WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability
CVE-2026-817698.8—LiquidThemesBooking HubCWE-266WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability
CVE-2026-817728.8—Saturday DriveNinja Forms - Layout & StylesCWE-502WordPress Ninja Forms - Layout & Styles plugin <= 3.0.31 - PHP Object Injecti…
CVE-2026-846458.8—Jenkins ProjectJenkinsCWE-94In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marke…
CVE-2026-846478.8—Jenkins ProjectJenkinsCWE-502In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, …
CVE-2026-846488.8—Jenkins ProjectJenkinsCWE-79In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer …
CVE-2026-846498.8—Jenkins ProjectJenkinsCWE-352In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive)…
CVE-2026-846508.8—Jenkins ProjectJenkinsCWE-502In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields canno…
CVE-2026-846688.8—Jenkins ProjectJenkins SAML PluginCWE-284Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the …
CVE-2026-846698.8—Jenkins ProjectJenkins Allure PluginCWE-22A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier al…
CVE-2026-846708.8—Jenkins ProjectJenkins Performance PluginCWE-502Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict…
CVE-2026-846718.8—Jenkins ProjectJenkins File Parameter PluginCWE-22Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing …
CVE-2026-846728.8—Jenkins ProjectJenkins Microsoft Entra ID (previously Azure AD) PluginCWE-639Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 an…
CVE-2026-846738.8—Jenkins ProjectJenkins Customizable Header PluginCWE-79Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows ov…
CVE-2026-847648.8—NSquaredSimply Schedule AppointmentsCWE-352WordPress Simply Schedule Appointments plugin <= 1.6.12.23 - Cross Site Reque…
CVE-2026-847708.8—Kitae ParkMang Board WPCWE-352WordPress Mang Board WP plugin <= 2.3.8 - Cross Site Request Forgery (CSRF) v…
CVE-2026-668428.7—F5BIG-IPCWE-918BIG-IP and BIG-IQ Configuration utility vulnerability
CVE-2026-771808.7—F5NGINX Ingress ControllerCWE-76NGINX Ingress Controller vulnerability
CVE-2026-782228.7—F5NGINX JavaScriptCWE-476NGINX ngx_http_js_module vulnerability
CVE-2026-797568.7—nuclionuclioCWE-78Nuclio: Unauthenticated OS command injection via namespace header in list-all…
CVE-2026-799898.7—craftcmscmsCWE-285Arbitrary user password reset leading to administrator account takeover
CVE-2026-799908.7—craftcmscmsCWE-639GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site c…
CVE-2026-847968.7—craftcmscmsCWE-639Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass
CVE-2026-848018.7—craftcmscmsCWE-862Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers
CVE-2026-848518.7—Amazonion-cCWE-674Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
CVE-2026-202768.6—CiscoCisco IOS XR SoftwareCWE-691Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-663628.6—F5NGINX Gateway FabricCWE-76NGF vulnerability
CVE-2026-825248.6—unopimunopimCWE-434UnoPim File Upload RCE via TinyMCE Image Upload Endpoint
CVE-2026-844528.6—microsoftwinml-cliCWE-306Windows ML CLI: CORS misconfig enables localhost RCE
CVE-2026-848038.6—siyuan-notesiyuanCWE-79SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist
CVE-2026-457308.3—nuclionuclioCWE-862Nuclio: Missing authorization on project write paths allows any authenticated…
CVE-2026-824048.3—toon-formattoonCWE-1321TOON: Prototype pollution when decoding untrusted TOON input
CVE-2025-154858.2—UnknownAuto x LINECWE-862Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call
CVE-2026-202778.2—CiscoCisco IOS XR SoftwareCWE-693Cisco IOS XR Software Security Hardening Release: September 2026
CVE-2026-192198.1—Progress SoftwareTelerik UI for ASP.NET AJAXCWE-345DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-843818.1—pydantichttpx2CWE-319HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
CVE-2026-498328.0—DSpaceDSpaceCWE-94DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN
CVE-2026-528318.0—nuclionuclioCWE-78Nuclio: Unsanitized cron trigger event headers/body injected into CronJob she…
CVE-2026-528338.0—nuclionuclioCWE-94Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build…
CVE-2026-797558.0—nuclionuclioCWE-78Nuclio: Unauthenticated OS command injection via function namespace in docker…
CVE-2026-846658.0—Jenkins ProjectJenkins SonarQube Scanner PluginCWE-79Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL scheme…
CVE-2026-784087.9—Red HatRed Hat Enterprise Linux 10CWE-775Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration aut…
CVE-2026-784107.8—Red HatRed Hat Enterprise Linux 10CWE-367Util-linux: util-linux: restricted bind mounts do not pin the source, allowin…
CVE-2026-786047.8—ElasticElastic AgentCWE-732Incorrect Permission Assignment for Critical Resource in Elastic Agent Leadin…
CVE-2026-848377.8—Red HatRed Hat Enterprise Linux 10CWE-78Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball…
CVE-2026-848387.8—Red HatRed Hat Enterprise Linux 10CWE-78Rpm: command injection in rpmuncompress via unescaped filenames passed to pop…
CVE-2023-205767.7—AMDAMD Ryzen™ 3000 Series Desktop ProcessorsCWE-345Insufficient Verification of Data Authenticity in AGESA™ may allow an attacke…
CVE-2024-79567.6—Rockwell AutomationDataMosaix™ Private CloudCWE-287Sensitive Data Exposure and Escalating Privileges Vulnerabilities in DataMosa…
CVE-2026-536357.6—openedxopenedx-platformCWE-862Open edX Platform: Insufficient Permission on set_course_mode_price()
CVE-2026-829587.6—Eclipse FoundationEclipse DittoCWE-74In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMap…
CVE-2026-186727.5—Progress SoftwareTelerik UI for ASP.NET AJAXCWE-22RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability …
CVE-2026-202817.5—CiscoCisco Session Initiation Protocol (SIP) SoftwareCWE-401Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone …
CVE-2026-771247.5—SonatypeNexus Repository 3CWE-184Nexus Repository 3 - Script Execution Disable Setting Not Enforced
CVE-2026-817747.5—DotstoreWooCommerce Product AttachmentCWE-497WordPress WooCommerce Product Attachment plugin <= 2.3.3 - Sensitive Data Exp…
CVE-2026-842927.5—fast-urifast-uriCWE-116fast-uri vulnerable to authority injection via an unvalidated port in serialize
CVE-2026-843827.5—pydantichttpx2CWE-409HTTPX2: Streaming response decompression does not bound peak memory (decompre…
CVE-2026-843947.5—fast-urifast-uriCWE-436fast-uri vulnerable to host confusion via an unclosed bracket in the URI auth…
CVE-2023-205777.4—AMD2nd Gen AMD EPYC™ ProcessorsCWE-121A heap overflow in SMM module may allow an attacker with access to a second v…
CVE-2026-846757.4—Jenkins ProjectJenkins TICS PluginCWE-78OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlie…
CVE-2026-180587.3—MotorolaSmart Connect ApplicationCWE-862The mobile Smart Connect dashboard UI was subject to manipulation by 3rd part…
CVE-2026-767597.3—DrupalScreenshotCWE-79Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102
CVE-2026-767827.3—DrupalScreenshotCWE-79Screenshot - Critical - Unsupported - SA-CONTRIB-2026-102
CVE-2026-785907.3—ElasticKibanaCWE-22Improper Limitation of a Pathname to a Restricted Directory in Kibana Leading…
CVE-2026-141997.1—GrafanaGrafana EnterpriseCWE-290Session takeover via Auth Proxy cache key collision
CVE-2026-492497.1—malach-itboruta-serverCWE-400Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsCo…
CVE-2026-771257.1—SonatypeNexus Repository 3CWE-863Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints
CVE-2026-797547.1—nuclionuclioCWE-77Nuclio: Kaniko build tempDir command injection
CVE-2026-799917.1—craftcmscmsCWE-89Authenticated SQL Injection via nested eager-loading criteria
CVE-2026-812887.1—WP SwingsUpsell Order Bump Offer for WooCommerceCWE-79WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Sit…
CVE-2026-812897.1—sonaarMP3 Audio Player for Music, Radio & Podcast by SonaarCWE-79WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1…
CVE-2026-817707.1—MapGeoInteractive Geo MapsCWE-79WordPress Interactive Geo Maps plugin <= 1.6.30 - Reflected Cross Site Script…
CVE-2026-817717.1—TrustedSiteTrustedSiteCWE-79WordPress TrustedSite plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability
CVE-2026-817757.1—EstatikEstatikCWE-79WordPress Estatik plugin <= 4.3.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-846677.1—Jenkins ProjectJenkins ThinBackup PluginCWE-22Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's b…
CVE-2026-847597.1—ElementorActivity LogCWE-352WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) v…
CVE-2026-847947.1—craftcmscmsCWE-862Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset
CVE-2026-847987.1—craftcmscmsCWE-862Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite
CVE-2026-848007.1—craftcmscmsCWE-862Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file
CVE-2026-848097.1—TencentAI-Infra-GuardCWE-693Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecode
CVE-2026-848107.1—claude-worldclaude-skill-antivirusCWE-693claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan
CVE-2026-848117.1—agentverusagentverus-scannerCWE-693agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecode
CVE-2026-784097.0—Red HatRed Hat Enterprise Linux 10CWE-59Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape vi…
CVE-2026-751356.9—Septeo IT SolutionsUpSignOnCWE-316UpSignOn < 7.19.0 Sensitive Key Retention in Memory
CVE-2026-751366.9—Septeo IT SolutionsUpSignOnCWE-522UpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVault
CVE-2026-751376.9—Septeo IT SolutionsUpSignOnCWE-316UpSignOn < 7.19.0 Sensitive Data Exposure in Process Memory after Lock
CVE-2026-848866.9—simular-aiAgent-SCWE-400simular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumption
CVE-2026-127046.8—GrafanaGrafana EnterpriseCWE-294SAML assertion replay via skipped InResponseTo validation
CVE-2026-554216.8—openedxopenedx-platformCWE-918Open edX Platform: SSRF in Studio Video Download Endpoint
CVE-2026-828846.8—UnknownAll in One SEOCWE-79All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block
CVE-2026-835476.8—UnknownXpro AddonsCWE-79Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Wi…
CVE-2026-108216.6—UnknownYoast SEO PremiumCWE-74Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection …
CVE-2026-26886.5—UnknownHIPAA FORMSCWE-863CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass
CVE-2026-194756.5—GrafanaPostgreSQL DatasourceCWE-400SQL Data Source Plugin: OOM DoS via $__timeGroup macro
CVE-2026-552216.5—malach-itboruta-serverCWE-532Boruta: OAuth credentials exposed in Boruta business logs
CVE-2026-785866.5—ElasticKibanaCWE-770Allocation of Resources Without Limits or Throttling in Kibana Leading to Den…
CVE-2026-785886.5—ElasticFilebeatCWE-770Allocation of Resources Without Limits or Throttling in Filebeat Leading to D…
CVE-2026-785996.5—ElasticKibanaCWE-22Stored Path Traversal in Kibana Leading to Unauthorized Deletion of Internal …
CVE-2026-822236.5—ArrayticsWP Event SOlutionCWE-862WordPress WP Event SOlution plugin <= 4.1.22 - Broken Access Control vulnerab…
CVE-2026-835626.5—WC LoversWCFM MarketplaceCWE-79WordPress WCFM Marketplace plugin <= 3.8.2 - Cross Site Scripting (XSS) vulne…
CVE-2026-843776.5—BerriAIlitellmCWE-918LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalida…
CVE-2026-847816.5—WP ChillGallery PhotoBlocksCWE-79WordPress Gallery PhotoBlocks plugin <= 1.3.4 - Cross Site Scripting (XSS) vu…
CVE-2026-536006.3—dignifiedquireasync-tarCWE-20async-tar PAX extension-header desync enables tar entry/content smuggling
CVE-2026-785916.3—ElasticKibanaCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-843766.3—withastroastroCWE-187Astro: Authorization bypass from missing path-segment boundary check when str…
CVE-2026-846516.3—Jenkins ProjectJenkinsCWE-284In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI e…
CVE-2026-850846.3—Samsung Open SourceTizenFXCWE-787Out-of-bounds write in TizenFX MediaBufferBase indexer setter due to missing …
CVE-2026-327736.1—Apache Software FoundationApache SparkCWE-80Apache Spark: XSS Vulnerability in Spark Web 3.5.4
CVE-2026-811606.1—DrupalSlick CarouselCWE-79Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026…
CVE-2026-812016.1—DrupalMonster MenusCWE-79Monster Menus - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-116
CVE-2026-771236.0—SonatypeNexus Repository 3CWE-201Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API
CVE-2024-37735.9—UnknownLiveJournal ShortcodeCWE-79LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode
CVE-2026-203545.9—CiscoCisco Secure EmailCWE-354Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
CVE-2026-203555.9—CiscoCisco Secure EmailCWE-345Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
CVE-2026-767555.9—DrupalGammu SMS DaemonCWE-119Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
CVE-2026-767565.9—DrupalGammu SMS DaemonCWE-119Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
CVE-2026-767575.9—DrupalGammu SMS DaemonCWE-119Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100
CVE-2026-767585.9—DrupalLink content parserCWE-20Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101
CVE-2026-843785.9—pydantichttpx2CWE-407HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
CVE-2026-843805.6—pydantichttpx2CWE-444HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-…
CVE-2026-142555.5—AutodeskShared ComponentsCWE-674IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products
CVE-2026-498315.5—DSpaceDSpaceCWE-22DSpace: Curation Task Reporter output path is not restricted to trusted direc…
CVE-2026-498335.5—DSpaceDSpaceCWE-22DSpace: Path Traversal possible in LDN message generation
CVE-2026-786015.5—ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Unauthorized Elasticsearch Index D…
CVE-2026-847725.5—WPMU DEVBroken Link CheckerCWE-918WordPress Broken Link Checker plugin <= 2.4.14 - Server Side Request Forgery …
CVE-2026-848395.5—tsi-cooptsi-dpdp-cmsCWE-287tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing au…
CVE-2026-848405.5—tsi-cooptsi-dpdp-cmsCWE-287tsi-coop tsi-dpdp-cms Bootstrap Setup Endpoint InterceptingFilter.java missin…
CVE-2026-848415.5—tsi-cooptsi-dpdp-cmsCWE-602tsi-coop tsi-dpdp-cms client-side enforcement of server-side security
CVE-2026-848565.5—rowboatlabsrowboatCWE-404rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of ser…
CVE-2026-848575.5—sigodenaichatCWE-400sigoden aichat API Endpoint serve.rs memory allocation
CVE-2026-28115.4—UnknownAjaxify CommentsCWE-113Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection
CVE-2026-81515.4—UnknownSimple Membership MailChimp IntegrationCWE-352Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF
CVE-2026-666525.4—ThemeGoodsGrand TourCWE-352WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulne…
CVE-2026-734765.4—DrupalExternal AuthenticationCWE-178External Authentication - Moderately critical - Access bypass - SA-CONTRIB-20…
CVE-2026-785985.4—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Unauthorized Cross-Space Exposur…
CVE-2026-786095.4—ElasticEck OperatorCWE-863Incorrect Authorization in Elastic Cloud on Kubernetes Leading to Unauthorize…
CVE-2026-811645.4—DrupalEntity PDFCWE-862Entity PDF - Moderately critical - Access bypass - SA-CONTRIB-2026-114
CVE-2026-842175.4—Mamunur RashidClassified ListingCWE-862WordPress Classified Listing plugin <= 6.1.1 - Broken Access Control vulnerab…
CVE-2026-846545.4—Jenkins ProjectJenkinsCWE-472In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, …
CVE-2026-846605.4—Jenkins ProjectJenkins Pipeline: Build Step PluginCWE-862A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67e…
CVE-2026-846615.4—Jenkins ProjectJenkins Pipeline: Build Step PluginCWE-862A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67e…
CVE-2026-846635.4—Jenkins ProjectJenkins Pipeline: Groovy Libraries PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy…
CVE-2026-846645.4—Jenkins ProjectJenkins GitLab PluginCWE-471Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab…
CVE-2026-846745.4—Jenkins ProjectJenkins XebiaLabs XL Deploy PluginCWE-862Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and ea…
CVE-2026-846775.4—Jenkins ProjectJenkins update-center2CWE-79Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided val…
CVE-2025-89455.3—UnknownWp Edit Password ProtectedCWE-863Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API
CVE-2025-154815.3—UnknownNotification Bar for WordPressCWE-306Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Dis…
CVE-2025-154895.3—UnknownPasssterCWE-863Passster < 4.2.24 - Password Protection Bypass
CVE-2025-154905.3—UnknownPasssterCWE-863Passster < 4.2.26 - Global Protection Bypass
CVE-2026-175635.3—UnknownUser FrontendCWE-862WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Ga…
CVE-2026-734745.3—DrupalEntity Share WebsubCWE-918Entity Share Websub - Moderately critical - Server-side request forgery (SSRF…
CVE-2026-734775.3—DrupalQuick TabsCWE-863Quick Tabs - Moderately critical - Access bypass - SA-CONTRIB-2026-099
CVE-2026-734785.3—DrupalDiffCWE-863Diff - Moderately critical - Access bypass - SA-CONTRIB-2026-096
CVE-2026-771215.3—SonatypeNexus Repository 3CWE-770Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields
CVE-2026-771225.3—SonatypeNexus Repository 3CWE-863Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repo…
CVE-2026-777935.3—UnknownRegistrationMagicCWE-602RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Pric…
CVE-2026-777945.3—UnknownRegistrationMagicCWE-472RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero…
CVE-2026-781535.3—UnknownRestrict User AccessCWE-863Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass vi…
CVE-2026-786025.3—ElasticElastic Maps ServerCWE-22Improper Limitation of a Pathname to a Restricted Directory in Elastic Maps S…
CVE-2026-811585.3—DrupalEntity APICWE-863Entity API - Moderately critical - Information disclosure - SA-CONTRIB-2026-113
CVE-2026-811625.3—DrupalDXPR Builder: The Best Editing (AI) Experience for DrupalCWE-201DXPR Builder: The AI Visual Page Builder for Drupal - Moderately critical - I…
CVE-2026-811655.3—DrupalBlazyCWE-863Blazy - Less critical - Access bypass - SA-CONTRIB-2026-104
CVE-2026-811665.3—DrupalDigital Signage FrameworkCWE-862Digital Signage Framework - Moderately critical - Access bypass - SA-CONTRIB-…
CVE-2026-812055.3—DrupalLDAP / Active Directory IntegrationCWE-90LDAP / Active Directory Integration - Moderately critical - Information Discl…
CVE-2026-812695.3—DrupalData fieldCWE-862Data field - Moderately critical - Information disclosure - SA-CONTRIB-2026-108
CVE-2026-825225.3—libjxllibjxlCWE-681libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Trunca…
CVE-2026-835335.3—UnknownWP Express CheckoutCWE-345WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process…
CVE-2026-843795.3—pydantichttpx2CWE-93HTTPX2: Multipart part header injection via unvalidated file Content-Type and…
CVE-2026-847605.3—WP SwingsUltimate Gift Cards For WooCommerceCWE-862WordPress Ultimate Gift Cards For WooCommerce plugin <= 3.2.9 - Broken Access…
CVE-2026-847715.3—PublishPressPublishPress PermissionsCWE-639WordPress PublishPress Permissions plugin <= 4.8.3 - Insecure Direct Object R…
CVE-2026-847755.3—Really Simple PluginsReally Simple SSLCWE-770WordPress Really Simple SSL plugin <= 9.8.0 - Denial of Service Attack vulner…
CVE-2026-847805.3—WPGMapsWP Go MapsCWE-770WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability
CVE-2026-847925.3—craftcmscmsCWE-862Craft CMS before 5.10.11 Broken Access Control via element-indexes
CVE-2026-847975.3—craftcmscmsCWE-862Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate
CVE-2026-847995.3—craftcmscmsCWE-285Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations
CVE-2026-848025.3—craftcmscmsCWE-862Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController
CVE-2026-848045.3—kimaikimaiCWE-284Kimai before 2.65.0 Authorization Bypass via Team Activity API
CVE-2026-848055.3—kimaikimaiCWE-862Kimai 2.61.0 before 2.63.0 Authentication Bypass via API
CVE-2026-848065.3—kimaikimaiCWE-732Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints
CVE-2026-848075.3—kimaikimaiCWE-266Kimai before 2.65.0 Authentication Bypass via Team Creation
CVE-2026-848085.3—kimaikimaiCWE-863Kimai before 2.65.0 Authorization Bypass via API Timesheet
CVE-2026-848355.3—DimaFreundRentsystCWE-862WordPress Rentsyst plugin <= 2.1.2 - Broken Access Control vulnerability
CVE-2026-848855.3—simular-aiAgent-SCWE-404simular-ai Agent-S CodeAgent code_agent.py denial of service
CVE-2026-848875.3—simular-aiAgent-SCWE-404simular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py…
CVE-2026-848885.3—RightNow-AIOpenFangCWE-789RightNow-AI OpenFang tool_runner.rs shell_exec memory allocation
CVE-2026-751345.1—SEOWritingSEOWritingCWE-79SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload
CVE-2026-528324.9—nuclionuclioCWE-22Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file …
CVE-2026-785944.9—ElasticApm ServerCWE-409Improper Handling of Highly Compressed Data in APM Server Leading to Persiste…
CVE-2026-189864.8—DrupalEntity BrowserCWE-79Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026…
CVE-2026-811674.8—DrupalAddress SuggestionCWE-79Address Suggestion - Moderately critical - Cross-site scripting - SA-CONTRIB-…
CVE-2026-815714.8—UnknownBraveCWE-74Brave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution v…
CVE-2026-847934.8—craftcmscmsCWE-79Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name
CVE-2026-536364.7—openedxopenedx-platformCWE-294Open edX LTI OAuth Replay Attack
CVE-2026-498304.4—DSpaceDSpaceCWE-20DSpace: ORE resource URI does not validate scheme for non-web resources
CVE-2026-785844.3—ElasticKibanaCWE-204Observable Response Discrepancy in Kibana Leading to Cross-Space Information …
CVE-2026-822934.3—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Unauthorized Resource Consumption
CVE-2026-846464.3—Jenkins ProjectJenkinsCWE-502In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appea…
CVE-2026-846554.3—Jenkins ProjectJenkinsCWE-116Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys w…
CVE-2026-846564.3—Jenkins ProjectJenkinsCWE-862A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earl…
CVE-2026-846584.3—Jenkins ProjectJenkins Script Security PluginCWE-200Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@Dat…
CVE-2026-846594.3—Jenkins ProjectJenkins Script Security PluginCWE-862Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enfor…
CVE-2026-846624.3—Jenkins ProjectJenkins LDAP PluginCWE-601Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a…
CVE-2026-846764.3—Jenkins ProjectJenkins Parameterized Remote Trigger PluginCWE-311Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens u…
CVE-2026-846574.2—Jenkins ProjectJenkinsCWE-862In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command …
CVE-2026-143263.8—UnknownTimeticsCWE-639Timetics <= 1.0.61 - Staff+ Cross-Staff Appointment Modification via IDOR
CVE-2026-811593.7—DrupalCommerce CyberSourceCWE-208Commerce CyberSource - Moderately critical - Insufficient input validation - …
CVE-2026-811683.7—DrupalCAPTCHA Protected PageCWE-288CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-20…
CVE-2025-156923.5—UnknownIcegram ExpressCWE-79Icegram Express < 5.8.6 - Admin+ Stored XSS
CVE-2026-196983.5—UnknownGutenKitCWE-74GutenKit < 2.5.1 - Contributor+ Stored CSS Injection
CVE-2026-786003.5—ElasticEck OperatorCWE-459Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cro…
CVE-2023-33603.3—UnknownWeaver Show PostsCWE-502Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection
CVE-2026-811613.3—DrupalContent Moderation NotificationsCWE-267Content Moderation Notifications - Moderately critical - Access bypass - SA-C…
CVE-2026-785873.1—ElasticFleet ServerCWE-863Incorrect Authorization in Fleet Server Leading to Denial of Service of Agent…
CVE-2026-630202.3—F5BIG-IPCWE-451BIG-IP Configuration utility vulnerability
CVE-2026-848332.1—ntegralsopenbrowserCWE-400ntegrals openbrowser Browser Agent Message Construction agent.ts resource con…
CVE-2026-848521.9—Reader ToolsPDF Reader AppCWE-22Reader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversal
CVE-2026-16647await—DrupalDisable Login PageCWE-288Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
CVE-2026-56855await—golang.org/x/cryptogolang.org/x/crypto/ssh—Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
CVE-2026-78662await—golang.org/x/cryptogolang.org/x/crypto/ssh—Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
CVE-2026-84652await—Jenkins ProjectJenkins—In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotat…
CVE-2026-84653await—Jenkins ProjectJenkins—Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (bo…
CVE-2026-84666await—Jenkins ProjectJenkins Job Configuration History Plugin—Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier all…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-02 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.