boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, September 3, 2026 · all times UTC← 2026-09-02 · archive

Security Box Score — September 3, 2026

346 CVEs published, led by Linux (32).

346 CVEs published September 3, 2026: 40 critical, 172 high, 108 medium, 10 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 16 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 321 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published114535881——
KEV catalog size1694

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2273 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux323993420200766911230.17.8.0016+32 ▲
google382202279856977887760.37.5.0026+38 ▲
microsoft91908149128845615287281.57.8.0044-7 ▼
red hat276534027130735200.06.6.0028+17 ▲
apple0316598516578882.56.5.00290
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse937521101000.07.5.0039+9 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco11952445260561313.77.5.0042+11 ▲
ubiquiti059362210335.19.1.00490
palo alto networks0371321121325.44.7.00200
netgear03200275000.04.3.00250
fortinet0307814128620.07.0.00500
f572461431414.28.7.0047+7 ▲
vmware019410327210.58.3.00400
sonicwall216484019425.07.8.0033+2 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache1508103217174133320.47.5.0049-4 ▼
mozilla342218079620900.08.1.0029+34 ▲
drupal2694119658411.15.7.0023+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+3 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm66251482871828610.27.5.0030+6 ▲
adobe26085030224791930.57.8.0021-5 ▼
progress2631439100611.68.1.0036+2 ▲
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.00320
zohocorp1113620000.08.8.0144+1 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link348151698300.08.5.0157+3 ▲
rockwell automation184353260000.08.6.0027+18 ▲
siemens13822583000.07.3.0016+1 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric4131840000.08.2.0032+4 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1919013103695210.57.3.0021+16 ▲
spring017011598515000.06.5.00240
sourcecodester0169009277000.05.5.00290
nvidia3016420115290000.07.8.0028+30 ▲
elastic42129028983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250
itsourcecode5121003586000.02.1.0027+5 ▲
openclaw01110583914000.07.0.00260

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-63077.877199.79.8
CVE-2026-60004.867899.79.8
CVE-2026-72898.823299.610.0
CVE-2026-73570.323898.28.9
CVE-2026-64638.312098.18.9
CVE-2026-71362.251497.89.1
CVE-2026-64849.164196.89.3
CVE-2026-48376.139296.35.4
CVE-2026-15733.135496.29.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.8232KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1672
oracle890
microsoft470
google438
ibm396
red hat236
apache164
splunk110
adobe96
mozilla93
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
fortinet6
google6
ivanti5
berriai4
oracle4
solarwinds4
sonicwall4
Most-affected ecosystems
EcosystemAdvisories
Maven62
Packagist32
npm14
PyPI11
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-20349Cisco0
CVE-2026-63077JetBrains0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-64849mlflow1
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171751
CVE-2021-27102n/a2021-11-171751
CVE-2021-27101n/a2021-11-171751
CVE-2021-27103n/a2021-11-171751
CVE-2021-21017Adobe2021-11-171751
CVE-2021-28550Adobe2021-11-171751
CVE-2021-42013Apache Software Foundation2021-11-171751
CVE-2021-41773Apache Software Foundation2021-11-171751
CVE-2021-30858Apple2021-11-171751
CVE-2021-30860Apple2021-11-171751

Transactions

EXPLOIT PUBLISHED — gitpython-developers GitPython: 14 CVEs (CVE-2026-67322, CVE-2026-67323, CVE-2026-67324, CVE-2026-67325, CVE-2026-73619, CVE-2026-73620, CVE-2026-73621, CVE-2026-73622, CVE-2026-73623, CVE-2026-73625, CVE-2026-76217, CVE-2026-76218, CVE-2026-76219, CVE-2026-76220). Public exploit references added.

EXPLOIT PUBLISHED — FlowiseAI Flowise: 6 CVEs (CVE-2026-73483, CVE-2026-73484, CVE-2026-73485, CVE-2026-73486, CVE-2026-73487, CVE-2026-73488). Public exploit references added.

EXPLOIT PUBLISHED — axios: 3 CVEs (CVE-2026-44492, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-10522 (Unknown MemberHero). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-14216 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-19722 (Unknown WPvivid — Backup, Migration & Staging). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62911 (Microsoft Exchange Server 2016 Cumulative Update 23). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63293 (Canonical LXD). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66401 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66418 (tugcantopaloglu openclaw-dashboard). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66421 (tugcantopaloglu openclaw-dashboard). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67291 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75134 (SEOWriting). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77790 (Unknown RegistrationMagic). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-83613 (xmldom). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84110 (Releasit COD Form & Upsells). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84127 (Mozilla Firefox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84287 (NousResearch hermes-agent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84423 (Casdoor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84427 (zhayujie CowAgent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84437 (OpenCart). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84441 (Piwigo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84832 (SEPPmail AG SEPPmail Secure Email Gateway (SEG)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84833 (ntegrals openbrowser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84839 (tsi-coop tsi-dpdp-cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84856 (rowboatlabs rowboat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84857 (sigoden aichat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Public exploit reference added.

DUE DATE PASSED — CVE-2026-64849 (mlflow). CISA remediation deadline was September 2, 2026; still in catalog.

REJECTED — CVE-2026-19582 (Red Hat Migration Toolkit for Containers). Record withdrawn by the CNA.

REJECTED — CVE-2026-76848 (typeorm). Record withdrawn by the CNA.

RESCORED — Mozilla Firefox: 4 CVEs (CVE-2026-84136, CVE-2026-84137, CVE-2026-84138, CVE-2026-84139). CVSS rescored — before/after on each CVE page.

RESCORED — simular-ai Agent-S: 3 CVEs (CVE-2026-84885, CVE-2026-84886, CVE-2026-84887). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD).

RESCORED — CVE-2026-11835 (Caliptra Core ROM). CVSS 5.6 → 5.7 (NVD).

RESCORED — CVE-2026-64631 (Veeam ONE). CVSS 8.5 → 8.6 (NVD).

RESCORED — CVE-2026-72680 (Elastic Kibana). CVSS 6.5 → 5.4 (NVD).

RESCORED — CVE-2026-72681 (Elastic Kibana). CVSS 6.5 → 8.8 (NVD).

RESCORED — CVE-2026-7326 (Progress Software Corporation MarkLogic Server). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2026-84888 (RightNow-AI OpenFang). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — Red Hat Hardened Images: 3 CVEs (CVE-2026-78408, CVE-2026-78409, CVE-2026-78410). Fix versions published.

PATCH SHIPPED — CVE-2026-16493 (Red Hat Satellite 6.17 for RHEL 9). Fixed in Red Hat Satellite 6.17 for RHEL 9 1:2.16.19-1.el9sat.

PATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755.

PATCH SHIPPED — CVE-2026-82451 (getformwork Formwork). Fixed in Formwork 2.3.11.

ENRICHED — Linux: 43 CVEs (CVE-2026-64064, CVE-2026-64065, CVE-2026-64070, CVE-2026-64071, CVE-2026-64072, CVE-2026-64075, CVE-2026-64079, CVE-2026-64083, CVE-2026-64085, CVE-2026-64087, CVE-2026-64301, CVE-2026-64302, CVE-2026-64305, CVE-2026-64306, CVE-2026-64314, CVE-2026-64316, CVE-2026-64331, CVE-2026-64332, CVE-2026-64334, CVE-2026-64335, CVE-2026-64336, CVE-2026-64337, CVE-2026-64338, CVE-2026-64339, CVE-2026-64340, CVE-2026-64341, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64345, CVE-2026-64346, CVE-2026-64347, CVE-2026-64348, CVE-2026-64349, CVE-2026-64350, CVE-2026-64351, CVE-2026-64352, CVE-2026-64353, CVE-2026-64429, CVE-2026-64433, CVE-2026-64446, CVE-2026-64451, CVE-2026-64453). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

346 CVEs published. 25 box scores, 321 table rows — nothing truncated.

ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0164   74.7     —
AFFECTED
  Product  Versions  Fixed
  CRMEB    6.0 –     —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
SEPPmail AG Secure Email Gateway — OS command injection in privileged configuration handling
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0107   62.5     —
AFFECTED
  Product               Versions     Fixed
  Secure Email Gateway  unspecified  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: NCSC.ch)
CWE-78, CWE-269 · CNA: NCSC.ch · CVSS v4.0 · 1 reference · NVD status: Deferred
SEPPmail AG SEPPmail Secure Email Gateway (SEG) — Unsafe deserialization in the REST interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0061   46.9     —
AFFECTED
  Product                              Versions     Fixed
  SEPPmail Secure Email Gateway (SEG)  unspecified  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Public exploit reference published
  Sep 3   Published (CNA: NCSC.ch)
CWE-78, CWE-502 · CNA: NCSC.ch · CVSS v4.0 · 2 references · NVD status: Deferred
TOTOLINK CP450 cstecgi.cgi buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0058   45.4     —
AFFECTED
  Product  Versions  Fixed
  CP450    4.1.0 –   —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumption
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   L    2.1   .0052   42.3     —
AFFECTED
  Product      Versions  Fixed
  agent-squad  1.1.0 –   —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 3   Published (CNA: VulDB)
CWE-400, CWE-404 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
OCS Inventory NG Ocsreports — Multiple vulnerabilities in Ocsreports for OCS Inventory NG
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .0049   40.1     —
AFFECTED
  Product     Versions  Fixed
  Ocsreports  2.12.6 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 3   Published (CNA: INCIBE)
CWE-434 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
SEPPmail AG SEPPmail Secure Email Gateway (SEG) — Mandatory MFA bypass before enrollment
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0045   37.6     —
AFFECTED
  Product                              Versions     Fixed
  SEPPmail Secure Email Gateway (SEG)  unspecified  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: NCSC.ch)
CWE-287, CWE-306 · CNA: NCSC.ch · CVSS v4.0 · 1 reference · NVD status: Deferred
zlib 1.3.1.2 through 1.3.2 Heap Buffer Overflow via gz_vacate
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   H   H    8.3   .0044   37.0     —
AFFECTED
  Product  Versions   Fixed
  zlib     1.3.1.2 –  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulnCheck)
CWE-787 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
FreeRDP before 3.31.0 Information Disclosure via uninitialized heap memory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0039   32.1     —
AFFECTED
  Product  Versions  Fixed
  FreeRDP  3.0.0 –   3.31.0
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulnCheck)
CWE-908 · CNA: VulnCheck · CVSS v4.0 · 7 references · NVD status: Received
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerabili…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  N    6.5   .0038   31.1     —
AFFECTED
  Product                    Versions     Fixed
  PowerProtect Data Manager  unspecified  —
TIMELINE
  Aug 16  Reserved by CNA
  Sep 3   Published (CNA: dell)
CWE-863 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
langgenius dify Splash Layout splash.tsx router.replace cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0037   29.8     —
AFFECTED
  Product  Versions  Fixed
  dify     1.13.0 –  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
HKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic error
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   N   L   N    2.9   .0036   28.5     —
AFFECTED
  Product    Versions                                    Fixed
  AI-Trader  d03ff6c056b32ced735adf7c19ed8175adb1c8df –  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulDB)
CWE-840 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Hitachi Energy RTU500 series CMU firmware — RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0035   28.0     —
AFFECTED
  Product                     Versions  Fixed
  RTU500 series CMU firmware  12.7.1 –  —
TIMELINE
  Jul 27  Reserved by CNA
  Sep 3   Published (CNA: Hitachi Energy)
CWE-476 · CNA: Hitachi Energy · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Shizen Connect Inc. ShizenBox2 (edge-app) — Authorization bypass through user-controlled key issue exists in ShizenBox2 (edge-app). If exploited, an at…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   N    7.1   .0035   27.9     —
AFFECTED
  Product                Versions     Fixed
  ShizenBox2 (edge-app)  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Sep 3   Published (CNA: jpcert)
CWE-639 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulne…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  H  N    6.8   .0035   27.8     —
AFFECTED
  Product                    Versions     Fixed
  PowerProtect Data Manager  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Sep 3   Published (CNA: dell)
CWE-188 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) v…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  L  N  N    4.1   .0035   27.8     —
AFFECTED
  Product                    Versions     Fixed
  PowerProtect Data Manager  unspecified  —
TIMELINE
  Aug 16  Reserved by CNA
  Sep 3   Published (CNA: dell)
CWE-918 · CNA: dell · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
OCS Inventory NG Ocsreports — Multiple vulnerabilities in Ocsreports for OCS Inventory NG
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0034   26.3     —
AFFECTED
  Product     Versions  Fixed
  Ocsreports  2.12.6 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 3   Published (CNA: INCIBE)
CWE-918 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
OCS Inventory NG Ocsreports — Multiple vulnerabilities in Ocsreports for OCS Inventory NG
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6   .0033   25.6     —
AFFECTED
  Product     Versions  Fixed
  Ocsreports  2.12.6 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 3   Published (CNA: INCIBE)
CWE-89 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
OCS Inventory NG Ocsreports — Multiple vulnerabilities in Ocsreports for OCS Inventory NG
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6   .0033   25.6     —
AFFECTED
  Product     Versions  Fixed
  Ocsreports  2.12.6 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 3   Published (CNA: INCIBE)
CWE-89 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Shizen Connect Inc. ShizenBox2 (dev-conf) — An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with p…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   P   L   N   N   N   H   H   H    7.0   .0033   25.7     —
AFFECTED
  Product                Versions     Fixed
  ShizenBox2 (dev-conf)  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Sep 3   Published (CNA: jpcert)
CWE-1263 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
cheshire-cat-ai core — Cheshire Cat AI Memory Collection Endpoint Information Disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0032   24.3     —
AFFECTED
  Product  Versions  Fixed
  core     1.8.0 –   —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
FreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   N   L    5.3   .0030   22.3     —
AFFECTED
  Product  Versions  Fixed
  FreeRDP  3.0.0 –   3.31.0
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulnCheck)
CWE-125 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   N   L   N    2.0   .0027   18.8     —
AFFECTED
  Product  Versions  Fixed
  dify     1.13.0 –  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 3   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
ataurr GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor — GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0025   16.2     —
AFFECTED
  Product                                                                             Versions     Fixed
  GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor  unspecified  —
TIMELINE
  Feb 16  Reserved by CNA
  Sep 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Elegant Themes Divi — Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0025   16.2     —
AFFECTED
  Product  Versions     Fixed
  Divi     unspecified  —
TIMELINE
  Mar 9   Reserved by CNA
  Sep 3   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-807317.815.4LinuxLinux—net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header
CVE-2026-80744await13.2LinuxLinux—netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
CVE-2026-807528.411.2LinuxLinux—Input: psxpad-spi - set driver data before use
CVE-2026-807327.811.2LinuxLinux—ata: pata_sl82c105: fix bridge revision use-after-free
CVE-2026-807377.811.2LinuxLinux—serial: amba-pl011: synchronize DMA teardown
CVE-2026-807547.811.2LinuxLinux—Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
CVE-2026-80733await11.2LinuxLinux—net: remove WARN_ON_ONCE() from sk_mc_loop()
CVE-2026-80742await11.2LinuxLinux—af_packet: Don't send zero-byte data in tpacket_snd().
CVE-2026-80743await11.2LinuxLinux—ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers
CVE-2026-80756await11.2LinuxLinux—selinux: do not cancel a policy conversion that never started
CVE-2026-80757await11.2LinuxLinux—selinux: reject a class permission count below its inherited common
CVE-2026-80728await11.0LinuxLinux—Revert "drm/amdgpu: fix aperture mapping leak"
CVE-2026-807357.310.7LinuxLinux—ovpn: ensure socket is owned by ovpn before deref sk_user_data
CVE-2026-80740await10.7LinuxLinux—drm/log: Fix infinite loop when scale is too large for display
CVE-2026-807269.310.6LinuxLinux—KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page
CVE-2026-80730await10.6LinuxLinux—ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
CVE-2026-807367.89.8LinuxLinux—thunderbolt: Fix bandwidth group reservation indexing
CVE-2026-807497.19.8LinuxLinux—drm/connector/hdmi: Fix out of bounds memory read
CVE-2026-80727await9.8LinuxLinux—x86/mce: Set up the polling timer before CMCI discovery
CVE-2026-80739await9.8LinuxLinux—net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock
CVE-2026-80755await9.8LinuxLinux—selinux: reject a permission value exceeding the class permission count
CVE-2026-807348.89.6LinuxLinux—btrfs: initialize inode mapping flags for cached inodes
CVE-2026-807458.49.6LinuxLinux—regulator: fp9931: Fix VPOS/VNEG voltage selector table
CVE-2026-807508.49.6LinuxLinux—pmdomain: mediatek: fix remaining %pOF after of_node_put()
CVE-2026-807538.49.6LinuxLinux—ovpn: run deferred work on a module-owned workqueue
CVE-2026-807487.89.6LinuxLinux—mmc: loongson2: Fix sg iteration in data reorder functions
CVE-2026-807387.39.6LinuxLinux—bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie
CVE-2026-807417.19.6LinuxLinux—drm/log: Fix out-of-bounds read on empty message length
CVE-2026-807478.08.6LinuxLinux—drm/amdkfd: Add bounds check for CRAT subtype length
CVE-2026-807517.88.6LinuxLinux—pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev()
CVE-2026-98524.68.6Hitachi EnergyMicroSCADA SYS600CWE-1236A CSV injection vulnerability exists in SYS600. Injected malicious formulas c…
CVE-2026-80729await8.6LinuxLinux—mm/huge_memory: initialise workingset state before folio split
CVE-2026-80746await8.6LinuxLinux—clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK
CVE-2026-736007.88.0DellPowerProtect Data ManagerCWE-121Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack …
CVE-2026-766428.56.0util-linuxutil-linuxCWE-390util-linux libmount Privilege Escalation via Failed Mount Helper
CVE-2021-384898.25.5Insyde SoftwareInsydeH2OCWE-256HDD Password Stored In Plaintext
CVE-2026-850925.24.7jtsylveLiMECWE-59LiME through 1.12.0 Arbitrary File Overwrite via Symlink Following
CVE-2021-436146.73.0Insyde SoftwareInsydeH2OCWE-120VariableEditSmm: Error checking of UEFI variables could cause buffer overflow…
CVE-2026-98538.52.2Hitachi EnergyMicroSCADA SYS600CWE-303A vulnerability exists in SYS600 which allows any user authenticated to the o…
CVE-2026-98548.52.2Hitachi EnergyMicroSCADA SYS600CWE-303A vulnerability exists in SYS600 RBAC mechanism where users having access to …
CVE-2021-436136.51.6Insyde SoftwareInsydeH2OCWE-732SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leadin…
CVE-2026-7035210.0—MicrosoftAzure AI Language AuthoringCWE-306Azure AI Language Elevation of Privilege Vulnerability
CVE-2026-8371110.0—MicrosoftEntraCWE-639Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVE-2026-8506110.0—maplibremaplibre-gl-jsCWE-79MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap …
CVE-2026-842389.8—YITHYITH Request a Quote for WooCommerce PremiumCWE-862WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Brok…
CVE-2026-847539.8—WPFunnelsMail MintCWE-502WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability
CVE-2026-848149.8—Bricksforge.BricksforgeCWE-266WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability
CVE-2026-848349.8—eyecixJobSearchCWE-502WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability
CVE-2026-850429.6—GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a …
CVE-2026-850479.6—GoogleChromeCWE-20Improper input validation in Transactions Platform in Google Chrome on on iOS…
CVE-2026-850509.6—GoogleChromeCWE-787Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.79…
CVE-2026-780699.5—j2commerce.comJ2Store extension for JoomlaCWE-862Joomla Extension - j2commerce.com - Missing authorization on Apps controller …
CVE-2026-821809.5—Eclipse FoundationEclipse ArrowheadCWE-290In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enable…
CVE-2026-852169.5—mispmispCWE-521MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
CVE-2026-780809.3—joodb.feenders.deJooDatabase Lite extension for JoomlaCWE-89Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase…
CVE-2026-800989.3—MicrosoftMicrosoft Copilot StudioCWE-347Copilot Studio Elevation of Privilege Vulnerability
CVE-2026-825269.3—SciPhi-AIR2RCWE-89R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint
CVE-2026-847689.3—e4jvikwpVikAppointments Services Booking CalendarCWE-89WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL In…
CVE-2026-848139.3—PaoloGeoDirectoryCWE-89WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability
CVE-2026-851549.3—WWBNAVideoCWE-269WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash
CVE-2026-851819.3—dianpingcatCWE-565CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
CVE-2026-851839.3—AvaigataipyCWE-1385Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS
CVE-2026-853919.3—Peppermint-LabpeppermintCWE-798Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compo…
CVE-2026-853949.3—mpdavispython-joseCWE-347python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as H…
CVE-2026-854249.3—themooscore-moosCWE-306MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subs…
CVE-2026-854259.3—moos-ivpmoos-ivpCWE-78MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS
CVE-2026-854269.3—moos-ivpmoos-ivpCWE-78MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names
CVE-2026-854289.3—themooscore-moosCWE-306MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write
CVE-2026-854339.3—themoosessential-moosCWE-862MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfig…
CVE-2026-854349.3—moos-ivpmoos-ivpCWE-345MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified…
CVE-2026-854359.3—moos-ivpmoos-ivpCWE-345MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
CVE-2026-854379.3—moos-ivpmoos-ivpCWE-787MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders
CVE-2026-854389.3—moos-ivpmoos-ivpCWE-190MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts
CVE-2026-854409.3—themooscore-moosCWE-787MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Neg…
CVE-2026-674029.2—WebProsConfigServer Security & FirewallCWE-552An insecure Apache configuration in ConfigServer Security & Firewall maps /us…
CVE-2026-761789.2—OCS Inventory NGOcsreportsCWE-79Multiple vulnerabilities in Ocsreports for OCS Inventory NG
CVE-2026-854279.2—themoosessential-moosCWE-494MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthen…
CVE-2026-584009.1—geonetworkcore-geonetworkCWE-94GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processo…
CVE-2026-629169.1—MicrosoftMicrosoft EntraCWE-288Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-805158.9—Eclipse FoundationEclipse ArrowheadCWE-647In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorizatio…
CVE-2026-851098.9—TendaHG10CWE-119Tenda HG10 Boa Web Server formLogin buffer overflow
CVE-2026-780648.8—j2commerce.comJ2Store extension for JoomlaCWE-639Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inher…
CVE-2026-804658.8—SiemensMendix SAML (Mendix 10 compatible)CWE-347A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (Al…
CVE-2026-847528.8—romethemeRTMKitCWE-502WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability
CVE-2026-850468.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote…
CVE-2026-850498.8—GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remo…
CVE-2026-850518.8—GoogleChromeCWE-843Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed…
CVE-2026-850538.8—GoogleChromeCWE-668Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.79…
CVE-2026-851998.8—Eclipse FoundationEclipse aeriOSCWE-22Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path trave…
CVE-2026-852368.8—mispmispCWE-352MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request
CVE-2026-854308.8—themoosessential-moosCWE-345MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republ…
CVE-2026-854328.8—themooscore-moosCWE-290MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity
CVE-2026-854558.8—themooscore-moosCWE-125MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet
CVE-2026-539248.7—1Hivegardens-v2CWE-284Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes
CVE-2026-574458.7—1Hivegardens-v2CWE-703Gardens v2: Approve-side dispute resolution drains active streaming escrow re…
CVE-2026-714048.7—SUSERancherCWE-639Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name…
CVE-2026-779998.7—j2commerce.comJ2Store extension for JoomlaCWE-472Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery l…
CVE-2026-825208.7—domainawareparsedmarcCWE-409parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments
CVE-2026-825278.7—SciPhi-AIR2RCWE-89R2R 3.6.6 SQL Injection via Retrieval Search Filter Key
CVE-2026-851558.7—WWBNAVideoCWE-89WWBN AVideo SQL Injection via get.json.php APIName channels
CVE-2026-851698.7—n8n-ion8nCWE-94n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak
CVE-2026-851748.7—siyuan-notesiyuanCWE-532SiYuan before v3.8.2 API Token Exposure via Log File
CVE-2026-851758.7—siyuan-notesiyuanCWE-552SiYuan before v3.8.2 TLS Private Key Disclosure via getFile
CVE-2026-851768.7—dbgatedbgateCWE-73DbGate through 7.2.6 Arbitrary File Read and Write via file:// jslid
CVE-2026-851808.7—ollamaollamaCWE-918Ollama 0.30.0 through 0.33.2 SSRF via Cross-Host Tensor Blob Redirect
CVE-2026-852128.7—crmebCRMEBCWE-862CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check
CVE-2026-853938.7—digitalbazaarforgeCWE-347node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestA…
CVE-2026-853968.7—rubyziprubyzipCWE-22rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directo…
CVE-2026-854298.7—moos-ivpmoos-ivpCWE-345MOOS-IvP through 24.8.1 uFldNodeComms Node Message Source Spoofing
CVE-2026-854318.7—themoosessential-moosCWE-345MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Inj…
CVE-2026-854368.7—themoosessential-moosCWE-191MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative U…
CVE-2026-854418.7—themooscore-moosCWE-195MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialize…
CVE-2026-854428.7—themooscore-moosCWE-789MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet A…
CVE-2026-854438.7—themooscore-moosCWE-400MOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of Service
CVE-2026-854448.7—moos-ivpmoos-ivpCWE-125MOOS-IvP through 24.8.1 Out-of-Bounds Read in isBraced, isQuoted and isChevroned
CVE-2026-854458.7—moos-ivpmoos-ivpCWE-789MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count
CVE-2026-854468.7—moos-ivpmoos-ivpCWE-407MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service
CVE-2026-854478.7—moos-ivpmoos-ivpCWE-770MOOS-IvP through 24.8.1 pRealm Unbounded REALMCAST_REQ Subscription Denial of…
CVE-2026-854488.7—moos-ivpmoos-ivpCWE-770MOOS-IvP through 24.8.1 uFldShoreBroker Unbounded Community State Retention
CVE-2026-854498.7—moos-ivpmoos-ivpCWE-770MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_R…
CVE-2026-854508.7—themooscore-moosCWE-770MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion
CVE-2026-854528.7—themoosui-moosCWE-787MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers
CVE-2026-632198.6—geonetworkcore-geonetworkCWE-862Unauthenticated file upload via missing authorization on formatter upload end…
CVE-2026-641998.6—measXDASYLabCWE-125Out Of Bounds Read outside the bounds of an allocated data structure when par…
CVE-2026-719638.6—NousResearchhermes-agentCWE-78Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection
CVE-2026-852238.6—D-LinkDNS-340LCWE-77D-Link DNS-340L CGI dropbox.cgi os command injection
CVE-2026-852378.6—mispmispCWE-307Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentica…
CVE-2026-853888.6—WorklenzworklenzCWE-89Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter
CVE-2026-641958.5—measXDASYLabCWE-787Out Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper vali…
CVE-2026-641968.5—measXDASYLabCWE-787Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper valid…
CVE-2026-641978.5—measXDASYLabCWE-787Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper valid…
CVE-2026-641988.5—measXDASYLabCWE-125Out Of Bounds Read in file handling when parsing a .DSB file in DASYLab
CVE-2026-642008.5—measXDASYLabCWE-125Out Of Bounds Read in during string conversionwhen parsing a .DSB file in DAS…
CVE-2026-658188.5—MicrosoftMicrosoft Power PlatformCWE-918Power Automate Elevation of Privilege Vulnerability
CVE-2026-673978.5—WebProsPleskCWE-22Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 a…
CVE-2026-698578.5—MicrosoftAzure Cosmos DBCWE-639Azure Cosmos DB Spoofing Vulnerability
CVE-2026-701788.5—MicrosoftMicrosoft FabricCWE-862Microsoft Fabric Elevation of Privilege Vulnerability
CVE-2026-850128.5—AWS@amazon-codecatalyst/blueprints.blueprintCWE-78OS command injection in the Amazon CodeCatalyst blueprints SDK
CVE-2026-852228.5—D-LinkDNS-340LCWE-77D-Link DNS-340L Add-On Center addon_center.cgi os command injection
CVE-2026-852248.5—D-LinkDNS-320 ShareCenterCWE-77D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection
CVE-2026-854398.5—moos-ivpmoos-ivpCWE-78MOOS-IvP through 24.8.1 alogsplit Command Injection via Input Pathname
CVE-2025-127378.4—WSO2WSO2 Open Banking AMCWE-78Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Produ…
CVE-2026-851798.4—HumanSignallabel-studioCWE-918Label Studio through 1.23.0 SSRF via Unvalidated Webhook URL
CVE-2026-847368.3—Eclipse FoundationEclipse aeriOSCWE-295In the current development version of Eclipse aeriOS, for which no official r…
CVE-2026-850488.3—GoogleChromeCWE-416Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed…
CVE-2026-851788.3—HeliconeheliconeCWE-639Helicone Cross-Tenant Provider Key Disclosure via Missing Organization Filter
CVE-2026-852118.3—HumanSignallabel-studioCWE-639Label Studio through 1.23.0 Cross-Organization Storage URI Resolution
CVE-2026-445068.2—medplummedplumCWE-200Medplum - Exposure of OAuth client secret via dynamic registration endpoint i…
CVE-2026-633768.2—BinaryMusetoml-nodeCWE-1321toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__…
CVE-2026-673988.2—WebProsWHMCSCWE-862Missing authorization vulnerability has been discovered in 2Checkout payment …
CVE-2026-847578.2—AresITWP CompressCWE-862WordPress WP Compress plugin <= 7.21.28 - Settings Change vulnerability
CVE-2026-849648.2—MongoDBC DriverCWE-415Heap corruption via OCSP request double free from crafted multi-URL certifica…
CVE-2026-785838.1—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Privilege Escalation
CVE-2026-823028.1—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modif…
CVE-2026-847798.1—Sheikh HeeraAgentimus – AI SEO, llms.txt &amp; MCP for AI AgentsCWE-862WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 -…
CVE-2026-839597.8—AdobeAdobe Substance 3D SamplerCWE-122Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
CVE-2026-181677.7—TP-Link Systems Inc.Archer AX55 v4CWE-121Stack-based buffer overflow in TP-Link Archer AX55 v4
CVE-2026-556587.7—1Hivegardens-v2CWE-862Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on canc…
CVE-2026-750337.7—SUSERancherCWE-639Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoo…
CVE-2026-851687.7—n8n-ion8nCWE-78n8n before 1.123.73 Remote Code Execution via Git Node
CVE-2026-851827.7—lenvevhrCWE-639vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change
CVE-2026-852217.6—mispmispCWE-295MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-…
CVE-2026-852387.6—mispmispCWE-384Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking
CVE-2026-60717.5—Rockwell AutomationArenaCWE-787Code Execution Vulnerability in Arena®
CVE-2026-88627.5—IBMNetezza SoftwareCWE-522Vulnerabilities exists in IBM Netezza Software
CVE-2026-336307.5—c-aresc-aresCWE-415c-ares : Use-after-free / double-free in c-ares query-completion handling, re…
CVE-2026-484867.5—signum-networksignum-nodeCWE-190Signum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary…
CVE-2026-774657.5—BinaryMusetoml-nodeCWE-674toml-node: Uncontrolled Recursion
CVE-2026-847767.5—malcareMalCare SecurityCWE-770WordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerab…
CVE-2026-847787.5—migrateguruMigrate Guru – Site Migration &amp; CloningCWE-770WordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of …
CVE-2026-848477.5—brightvesseldevQuick Event ManagerCWE-862WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerab…
CVE-2026-850457.5—GoogleChromeCWE-367Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote…
CVE-2026-851247.5—@fastify/http-proxy@fastify/http-proxyCWE-22@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments
CVE-2026-851507.5—Red HatRed Hat Enterprise Linux 10CWE-476Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_r…
CVE-2026-629067.4—MicrosoftMicrosoft Discovery StudioCWE-943Microsoft Discovery Studio Information Disclosure Vulnerability
CVE-2026-750347.4—SUSERancherCWE-294Rancher: SAML Assertion Replay
CVE-2026-847777.4—Really Simple PluginsReally Simple SSLCWE-288WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability
CVE-2026-851107.4—TendaHG10CWE-119Tenda HG10 Boa Web Server formWlanSetup buffer overflow
CVE-2026-154317.3—HP Inc.HP Support AssistantCWE-1220HP Support Assistant – Potential Escalation of Privilege
CVE-2026-850287.3—AWSaws-fpgaCWE-379Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA…
CVE-2026-847617.2—LiteSpeed TechnologiesLiteSpeed CacheCWE-918WordPress LiteSpeed Cache plugin <= 7.9 - Server Side Request Forgery (SSRF) …
CVE-2026-847737.2—作者: Shane BishopEWWW Image OptimizerCWE-79WordPress EWWW Image Optimizer plugin <= 8.7.6 - Cross Site Scripting (XSS) v…
CVE-2026-851607.2—WWBNAVideoCWE-73AVideo through c91b5975d CSRF and Path Traversal via stopLive.php
CVE-2026-851657.2—n8n-ion8nCWE-95n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement
CVE-2026-851667.2—n8n-ion8nCWE-863n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node
CVE-2026-852137.2—killbillkillbillCWE-862Kill Bill through 0.24.21 Missing Authorization on AdminResource Endpoints
CVE-2026-852147.2—lenvevhrCWE-639vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite
CVE-2026-537287.1—medplummedplumCWE-345Medplum - Improper Validation of Redirect URI in External Auth Callback allow…
CVE-2026-750357.1—SUSERancherCWE-639Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-…
CVE-2026-780657.1—j2commerce.comJ2Store extension for JoomlaCWE-639Joomla Extension - j2commerce.com - Guest checkout address disclosure to any …
CVE-2026-812927.1—Ido KobelkowskySimple PaymentCWE-79WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnera…
CVE-2026-812957.1—UnderConstructionPageUnder ConstructionCWE-79WordPress Under Construction plugin <= 5.82 - Cross Site Scripting (XSS) vuln…
CVE-2026-813007.1—silverplugins217Calculation For Contact Form 7CWE-79WordPress Calculation For Contact Form 7 plugin <= 1.0 - Cross Site Scripting…
CVE-2026-817737.1—Saturday DriveNinja Forms File Uploads ExtensionCWE-79WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Sc…
CVE-2026-817767.1—advanpixWP QuickLaTeXCWE-79WordPress WP QuickLaTeX plugin <= 3.8.8 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-839617.1—AdobeColdFusion 2025CWE-287ColdFusion | Improper Authentication (CWE-287)
CVE-2026-847567.1—WC LoversWCFM MembershipCWE-266WordPress WCFM Membership plugin <= 2.11.11 - Privilege Escalation vulnerability
CVE-2026-847637.1—romethemeRTMKitCWE-79WordPress RTMKit plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability
CVE-2026-847657.1—John HavlikBreadcrumb NavXTCWE-79WordPress Breadcrumb NavXT plugin <= 7.5.1 - Cross Site Scripting (XSS) vulne…
CVE-2026-848127.1—wordplusBP Better MessagesCWE-79WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) v…
CVE-2026-848367.1—kirillbdevWC Ukraine ShippingCWE-639WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object Refer…
CVE-2026-848487.1—brightvesseldevQuick Event ManagerCWE-79WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vul…
CVE-2026-849717.1—MongoDBlibmongocryptCWE-617Persistent client crash loop via undersized FLE2 insert-update ciphertext in …
CVE-2026-849897.1—ntopntopngCWE-862ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete a…
CVE-2026-851627.1—WWBNAVideoCWE-352AVideo through c91b5975d CSRF via saveLive.php
CVE-2026-851637.1—WWBNAVideoCWE-918AVideo Server-Side Request Forgery via epg_link parameter
CVE-2026-851647.1—WWBNAVideoCWE-918WWBN AVideo Server-Side Request Forgery via set_api_userImages
CVE-2026-851707.1—n8n-ion8nCWE-20n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes
CVE-2026-851717.1—n8n-ion8nCWE-532n8n before 1.123.73 Credential Exposure via Error Logging
CVE-2026-852397.1—mispmispCWE-20MISP Event Template Definition Validation Bypass Allows Persistent Denial of …
CVE-2026-853897.1—WorklenzworklenzCWE-639Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints
CVE-2026-853907.1—bluewave-labsCheckmateCWE-862Checkmate through 3.11.0 Missing Authorization on Maintenance Window, Notific…
CVE-2026-853957.1—unopimunopimCWE-862UnoPim before 2.1.3 Missing Authorization on Integration Management Routes
CVE-2026-854517.1—themooscore-moosCWE-798MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multi…
CVE-2026-712207.0—Red HatRed Hat Enterprise Linux 7CWE-787Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in …
CVE-2026-712217.0—Red HatRed Hat Enterprise Linux 7CWE-787Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in sav…
CVE-2026-796797.0—B&R Industrial Automation GmbHmapp ServicesCWE-1391Use of Weak Credentials
CVE-2026-159336.9—OptimiDocOptimiDoc ServerCWE-256Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)
CVE-2026-849686.9—MongoDBPHP DriverCWE-125Heap out-of-bounds read via corrupt nested BSON in field path error message
CVE-2026-850626.9—omgovichcolordCWE-1333Colord: Slow rejection of oversized malformed color strings
CVE-2026-850636.9—adaltasnode-csvCWE-1321node-csv: Prototype replacement still reachable via columns path
CVE-2026-851056.9—NousResearchhermes-agentCWE-285NousResearch hermes-agent Session Management s71.py _sess_nowait authorization
CVE-2026-851566.9—WWBNAVideoCWE-200WWBN AVideo Broken Access Control via Channel Page
CVE-2026-851576.9—WWBNAVideoCWE-200WWBN AVideo Broken Access Control via feed/index.php program_id
CVE-2026-852426.9—LookylooPlaywrightCaptureCWE-918Server-Side Request Forgery via Favicon Redirect to Local Network Resources i…
CVE-2026-825256.8—ExterroFTK ImagerCWE-611Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
CVE-2026-854566.8—moos-ivpmoos-ivpCWE-22MOOS-IvP through 24.8.1 alog Splitting Path Traversal on Windows
CVE-2026-829186.7—Keyence CorporationXG-X VisionTerminalCWE-611XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation imp…
CVE-2026-97456.5—IBMNetezza SoftwareCWE-283Vulnerabilities exists in IBM Netezza Software
CVE-2026-494556.5—wakujswakuCWE-352Waku: Cross-Origin CSRF on RSC Server Action Dispatch
CVE-2026-756026.5—OpenListTeamOpenListCWE-22OpenList: Authenticated arbitrary file write via Content-Disposition path tra…
CVE-2026-812816.5—silverksGrapheneCWE-79WordPress Graphene theme <= 2.9.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-812826.5—VillaThemeProduct Variations Swatches for WooCommerceCWE-79WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cros…
CVE-2026-822996.5—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Information Disclosure
CVE-2026-842156.5—ArrayticsTimeticsCWE-862WordPress Timetics plugin <= 1.0.61 - Broken Access Control vulnerability
CVE-2026-847546.5—WPFunnelsWPFunnelsCWE-862WordPress WPFunnels plugin <= 3.12.13 - Broken Access Control vulnerability
CVE-2026-847556.5—WPFunnelsMail MintCWE-862WordPress Mail Mint plugin <= 1.31.0 - Broken Access Control vulnerability
CVE-2026-847586.5—Strategy11 TeamBusiness DirectoryCWE-862WordPress Business Directory plugin <= 6.4.26 - Broken Access Control vulnera…
CVE-2026-847696.5—Strategy11 TeamBusiness DirectoryCWE-639WordPress Business Directory plugin <= 6.4.26 - Insecure Direct Object Refere…
CVE-2026-848496.5—brightvesseldevPre-Orders for WooCommerceCWE-290WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vul…
CVE-2026-853026.5—WPKoi WordPress ThemesWPKoi Templates for ElementorCWE-79WordPress WPKoi Templates for Elementor plugin <= 3.7.2 - Cross Site Scriptin…
CVE-2026-853036.5—Magepeople inc.Booking and Rental ManagerCWE-79WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (…
CVE-2026-853066.5—Cascadia Web ServicesMountDev AI MCP Connector for WordPressCWE-862WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Ac…
CVE-2026-825216.3—domainawareparsedmarcCWE-22parsedmarc 9.0.6 < 11.0.1 Path Traversal via Forensic Report Subject
CVE-2026-849636.3—MongoDBC DriverCWE-681Silent field truncation via unchecked int cast of huge JSON string values in …
CVE-2026-849696.3—MongoDBC DriverCWE-787Heap overflow via truncated base64 encoding of binary fields in length-limite…
CVE-2026-851676.3—n8n-ion8nCWE-943n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes
CVE-2026-197956.2—IBMQiskit SDKCWE-502Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the av…
CVE-2026-714296.2—uhopstream-jsonCWE-407stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input…
CVE-2026-183306.1—TP-Link Systems Inc.Archer AX55 v4CWE-321Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4
CVE-2026-714036.1—SUSERancherCWE-639Rancher: Identity-field mutation in /v3/users allows account hijack via princ…
CVE-2026-847746.1—VeronaLabsWP StatisticsCWE-79WordPress WP Statistics plugin <= 14.16.11 - Cross Site Scripting (XSS) vulne…
CVE-2026-852276.1—mispmispCWE-79Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes a…
CVE-2026-34165.9—WSO2WSO2 API ManagerCWE-330Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation…
CVE-2026-90365.9—IBMNetezza SoftwareCWE-295Vulnerabilities exists in IBM Netezza Software
CVE-2026-841855.9—Red HatRed Hat Ansible Automation Platform 2CWE-347Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verific…
CVE-2026-847665.9—WP Manage NinjaFluentBooking ProCWE-290WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability
CVE-2026-849655.9—MongoDBC DriverCWE-190Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds
CVE-2026-849665.9—MongoDBC++ DriverCWE-681BSON element injection via NUL-embedded document keys in builder append
CVE-2026-849705.9—MongoDBC++ DriverCWE-681Heap over-read or silent misparse via 32-bit truncation of JSON length in BSO…
CVE-2026-848155.8—KriesiEnfoldCWE-79WordPress Enfold theme <= 8.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-849625.7—MongoDBlibmongocryptCWE-93Authenticated KMS request forgery via CRLF injection in GCP key identifier st…
CVE-2026-851375.5—n/aSeaCMSCWE-74SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection
CVE-2026-851385.5—n/aSeaCMSCWE-74SeaCMS WeChat index.php addslashes sql injection
CVE-2026-851875.5—itsourcecodeOnline Medicine Delivery SystemCWE-74itsourcecode Online Medicine Delivery System Order Status Update controller.p…
CVE-2026-852085.5—itsourcecodeOnline Medicine Delivery SystemCWE-284itsourcecode Online Medicine Delivery System Order Management Controller cont…
CVE-2026-852255.5—code-projectsDoctor Appointment SystemCWE-74code-projects Doctor Appointment System patient_login.php sql injection
CVE-2026-853785.5—light0011cmsCWE-285light0011 cms Chapter Controller ChapterController.class.php _initialize auth…
CVE-2026-853055.4—SEOPressSEOPressCWE-918WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulner…
CVE-2026-97365.3—IBMNetezza SoftwareCWE-117Vulnerabilities exists in IBM Netezza Software
CVE-2026-97445.3—IBMNetezza SoftwareCWE-297Vulnerabilities exists in IBM Netezza Software
CVE-2026-505545.3—enchant97note-markCWE-200Note Mark: Unauthenticated disclosure of soft-deleted note metadata via delet…
CVE-2026-712225.3—Red HatRed Hat Enterprise Linux 7CWE-125Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in …
CVE-2026-750365.3—SUSEFleetCWE-918Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template p…
CVE-2026-780005.3—j2commerce.comJ2Store extension for JoomlaCWE-79Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Sto…
CVE-2026-820235.3—ThimPressLearnPressCWE-863LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Qui…
CVE-2026-847625.3—Saad IqbalWP EasyPayCWE-472WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability
CVE-2026-847675.3—NexcessBookItCWE-345WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability
CVE-2026-851065.3—NousResearchhermes-agentCWE-918NousResearch hermes-agent Link Title Fetch index.tsx fetchLinkTitle server-si…
CVE-2026-851075.3—NousResearchhermes-agentCWE-400NousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl…
CVE-2026-851355.3—n/aILIASCWE-284ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted …
CVE-2026-851585.3—WWBNAVideoCWE-79AVideo Reflected XSS via videoEmbeded.php link parameter
CVE-2026-851595.3—WWBNAVideoCWE-79AVideo Reflected XSS via cancelUri in userLogin.php
CVE-2026-851615.3—WWBNAVideoCWE-352AVideo removePoster.php Cross-Site Request Forgery File Deletion
CVE-2026-851725.3—n8n-ion8nCWE-918n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass
CVE-2026-851735.3—n8n-ion8nCWE-639n8n before 2.36.2 Missing Authorization via Insights API
CVE-2026-851775.3—crmebCRMEBCWE-639CRMEB through 6.0.0 Unauthorized Message Modification via edit_message
CVE-2026-852055.3—itsourcecodeOnline Medicine Delivery SystemCWE-74itsourcecode Online Medicine Delivery System Wishlist controller.php addwishl…
CVE-2026-852105.3—oppiaoppiaCWE-862Oppia through 3.5.2 Missing Authorization on AdminRoleHandler GET
CVE-2026-852265.3—mispmispCWE-862MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of …
CVE-2026-852305.3—mispmispCWE-20MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection
CVE-2026-852415.3—SpecterOpsBloodHoundCWE-266SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization
CVE-2026-853045.3—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-862WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-853075.3—Kevin PirnieKP Agent ReadyCWE-201WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability
CVE-2026-853085.3—Brainstorm ForceSureFormsCWE-639WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDO…
CVE-2026-853095.3—SupsysticUltimate Maps by SupsysticCWE-862WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control …
CVE-2026-853925.3—Peppermint-LabpeppermintCWE-639Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint
CVE-2026-854535.3—themooscore-moosCWE-79MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting
CVE-2026-854545.2—themooscore-moosCWE-193MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram H…
CVE-2026-537205.1—jetperchpymonocypherCWE-122pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when …
CVE-2026-561265.1—NetgatepfSense PlusCWE-79pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php
CVE-2026-561275.1—NetgatepfSense PlusCWE-79pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php
CVE-2026-561285.1—NetgatepfSense PlusCWE-79pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php
CVE-2026-820245.1—ThimPressLearnPressCWE-79LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles
CVE-2026-849675.1—MongoDBMongoDB for VS CodeCWE-78Arbitrary command execution via shell-expanded connection string in Launch Mo…
CVE-2026-351605.0—DellSmartFabric OS10 SoftwareCWE-78Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Impr…
CVE-2026-636945.0—DellSmartFabric OS10CWE-77Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Impr…
CVE-2026-712194.7—Red HatRed Hat Enterprise Linux 7CWE-770Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table …
CVE-2026-712244.7—Red HatRed Hat Enterprise Linux 7CWE-770Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk
CVE-2026-495094.4—Samsung OpensourcerLottieCWE-125Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overre…
CVE-2026-785934.3—ElasticKibanaCWE-94Improper Control of Generation of Code in Kibana Leading to Privilege Escalation
CVE-2026-785954.3—ElasticKibanaCWE-862Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Dat…
CVE-2026-785964.3—ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Ope…
CVE-2026-822984.3—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Denial of Service
CVE-2026-494563.1—wakujswakuCWE-601Waku: Open Redirect via `unstable_redirect` Helper
CVE-2026-850523.1—GoogleChromeCWE-125Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 …
CVE-2026-851862.1—itsourcecodeOnline Medicine Delivery SystemCWE-284itsourcecode Online Medicine Delivery System Customer Controller controller.p…
CVE-2026-854582.1—XpdfXpdfCWE-369Divide-by-zero in Xpdf 4.06 due to zero-height Type 3 glyph
CVE-2026-852072.0—itsourcecodeOnline Medicine Delivery SystemCWE-79itsourcecode Online Medicine Delivery System index.php cross site scripting
CVE-2026-85043await—GoogleChromeCWE-459Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed…
CVE-2026-85044await—GoogleChromeCWE-672Use of released resource in Mobile in Google Chrome on on Android prior to 15…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-03 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.