AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0164 74.7 —
AFFECTED Product Versions Fixed CRMEB 6.0 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
346 CVEs published, led by Linux (32).
346 CVEs published September 3, 2026: 40 critical, 172 high, 108 medium, 10 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 16 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 321 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1145 | 35881 | — | — |
| KEV catalog size | 1694 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2273 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 32 | 3993 | 420 | 2007 | 669 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +32 ▲ |
| 38 | 2202 | 279 | 856 | 977 | 88 | 77 | 6 | 0.3 | 7.5 | .0026 | +38 ▲ | |
| microsoft | 9 | 1908 | 149 | 1288 | 456 | 15 | 287 | 28 | 1.5 | 7.8 | .0044 | -7 ▼ |
| red hat | 27 | 653 | 40 | 271 | 307 | 35 | 2 | 0 | 0.0 | 6.6 | .0028 | +17 ▲ |
| apple | 0 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | 0 |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 9 | 37 | 5 | 21 | 10 | 1 | 0 | 0 | 0.0 | 7.5 | .0039 | +9 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 11 | 95 | 24 | 45 | 26 | 0 | 56 | 13 | 13.7 | 7.5 | .0042 | +11 ▲ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 0 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | 0 |
| netgear | 0 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | 0 |
| fortinet | 0 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | 0 |
| f5 | 7 | 24 | 6 | 14 | 3 | 1 | 4 | 1 | 4.2 | 8.7 | .0047 | +7 ▲ |
| vmware | 0 | 19 | 4 | 10 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | 0 |
| sonicwall | 2 | 16 | 4 | 8 | 4 | 0 | 19 | 4 | 25.0 | 7.8 | .0033 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 1 | 508 | 103 | 217 | 174 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | -4 ▼ |
| mozilla | 34 | 221 | 80 | 79 | 62 | 0 | 9 | 0 | 0.0 | 8.1 | .0029 | +34 ▲ |
| drupal | 26 | 94 | 11 | 9 | 65 | 8 | 4 | 1 | 1.1 | 5.7 | .0023 | +26 ▲ |
| gitlab | 0 | 76 | 3 | 17 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0029 | 0 |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | +3 ▲ |
| docker | 0 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | 0 |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | 0 |
| ibm | 6 | 625 | 148 | 287 | 182 | 8 | 6 | 1 | 0.2 | 7.5 | .0030 | +6 ▲ |
| adobe | 2 | 608 | 50 | 302 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | -5 ▼ |
| progress | 2 | 63 | 14 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0036 | +2 ▲ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | 0 |
| zohocorp | 1 | 11 | 3 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.8 | .0144 | +1 ▲ |
| atlassian | 0 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 3 | 48 | 15 | 16 | 9 | 8 | 3 | 0 | 0.0 | 8.5 | .0157 | +3 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0027 | +18 ▲ |
| siemens | 1 | 38 | 2 | 25 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | +1 ▲ |
| synology | 0 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -1 ▼ |
| schneider electric | 4 | 13 | 1 | 8 | 4 | 0 | 0 | 0 | 0.0 | 8.2 | .0032 | +4 ▲ |
| hitachi energy | 4 | 7 | 0 | 3 | 4 | 0 | 0 | 0 | 0.0 | 6.9 | .0017 | +4 ▲ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 19 | 190 | 13 | 103 | 69 | 5 | 2 | 1 | 0.5 | 7.3 | .0021 | +16 ▲ |
| spring | 0 | 170 | 11 | 59 | 85 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | 0 |
| sourcecodester | 0 | 169 | 0 | 0 | 92 | 77 | 0 | 0 | 0.0 | 5.5 | .0029 | 0 |
| nvidia | 30 | 164 | 20 | 115 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0028 | +30 ▲ |
| elastic | 42 | 129 | 0 | 28 | 98 | 3 | 1 | 0 | 0.0 | 6.5 | .0028 | +42 ▲ |
| splunk | 0 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | 0 |
| itsourcecode | 5 | 121 | 0 | 0 | 35 | 86 | 0 | 0 | 0.0 | 2.1 | .0027 | +5 ▲ |
| openclaw | 0 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | 0 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-63077 | .8771 | 99.7 | 9.8 |
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-72898 | .8232 | 99.6 | 10.0 |
| CVE-2026-73570 | .3238 | 98.2 | 8.9 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-64849 | .1641 | 96.8 | 9.3 |
| CVE-2026-48376 | .1392 | 96.3 | 5.4 |
| CVE-2026-15733 | .1354 | 96.2 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .8232 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1672 |
| oracle | 890 |
| microsoft | 470 |
| 438 | |
| ibm | 396 |
| red hat | 236 |
| apache | 164 |
| splunk | 110 |
| adobe | 96 |
| mozilla | 93 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| fortinet | 6 |
| 6 | |
| ivanti | 5 |
| berriai | 4 |
| oracle | 4 |
| solarwinds | 4 |
| sonicwall | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 62 |
| Packagist | 32 |
| npm | 14 |
| PyPI | 11 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-63077 | JetBrains | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-64849 | mlflow | 1 |
| CVE-2026-81578 | PaperCut | 3 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1751 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1751 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1751 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1751 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1751 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1751 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1751 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1751 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1751 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1751 |
EXPLOIT PUBLISHED — gitpython-developers GitPython: 14 CVEs (CVE-2026-67322, CVE-2026-67323, CVE-2026-67324, CVE-2026-67325, CVE-2026-73619, CVE-2026-73620, CVE-2026-73621, CVE-2026-73622, CVE-2026-73623, CVE-2026-73625, CVE-2026-76217, CVE-2026-76218, CVE-2026-76219, CVE-2026-76220). Public exploit references added.
EXPLOIT PUBLISHED — FlowiseAI Flowise: 6 CVEs (CVE-2026-73483, CVE-2026-73484, CVE-2026-73485, CVE-2026-73486, CVE-2026-73487, CVE-2026-73488). Public exploit references added.
EXPLOIT PUBLISHED — axios: 3 CVEs (CVE-2026-44492, CVE-2026-44495, CVE-2026-44496). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-10522 (Unknown MemberHero). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-14216 (Unknown Booking for Appointments and Events Calendar). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19586 (TP-Link Systems Inc. ER7212PC v2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-19722 (Unknown WPvivid — Backup, Migration & Staging). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42581 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42587 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-62911 (Microsoft Exchange Server 2016 Cumulative Update 23). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63293 (Canonical LXD). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66401 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66418 (tugcantopaloglu openclaw-dashboard). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66421 (tugcantopaloglu openclaw-dashboard). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67291 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75134 (SEOWriting). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77790 (Unknown RegistrationMagic). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-83613 (xmldom). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84110 (Releasit COD Form & Upsells). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84127 (Mozilla Firefox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84287 (NousResearch hermes-agent). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84423 (Casdoor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84427 (zhayujie CowAgent). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84437 (OpenCart). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84441 (Piwigo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84832 (SEPPmail AG SEPPmail Secure Email Gateway (SEG)). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84833 (ntegrals openbrowser). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84839 (tsi-coop tsi-dpdp-cms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84856 (rowboatlabs rowboat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84857 (sigoden aichat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-9586 (Sangoma Switchvox SMB Edition). Public exploit reference added.
DUE DATE PASSED — CVE-2026-64849 (mlflow). CISA remediation deadline was September 2, 2026; still in catalog.
REJECTED — CVE-2026-19582 (Red Hat Migration Toolkit for Containers). Record withdrawn by the CNA.
REJECTED — CVE-2026-76848 (typeorm). Record withdrawn by the CNA.
RESCORED — Mozilla Firefox: 4 CVEs (CVE-2026-84136, CVE-2026-84137, CVE-2026-84138, CVE-2026-84139). CVSS rescored — before/after on each CVE page.
RESCORED — simular-ai Agent-S: 3 CVEs (CVE-2026-84885, CVE-2026-84886, CVE-2026-84887). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2025-12107 (WSO2 Identity Server). CVSS 8.4 → 7.2 (NVD).
RESCORED — CVE-2026-11835 (Caliptra Core ROM). CVSS 5.6 → 5.7 (NVD).
RESCORED — CVE-2026-64631 (Veeam ONE). CVSS 8.5 → 8.6 (NVD).
RESCORED — CVE-2026-72680 (Elastic Kibana). CVSS 6.5 → 5.4 (NVD).
RESCORED — CVE-2026-72681 (Elastic Kibana). CVSS 6.5 → 8.8 (NVD).
RESCORED — CVE-2026-7326 (Progress Software Corporation MarkLogic Server). CVSS 7.5 → 8.8 (NVD).
RESCORED — CVE-2026-84888 (RightNow-AI OpenFang). CVSS 5.3 → 2.1 (NVD).
PATCH SHIPPED — Red Hat Hardened Images: 3 CVEs (CVE-2026-78408, CVE-2026-78409, CVE-2026-78410). Fix versions published.
PATCH SHIPPED — CVE-2026-16493 (Red Hat Satellite 6.17 for RHEL 9). Fixed in Red Hat Satellite 6.17 for RHEL 9 1:2.16.19-1.el9sat.
PATCH SHIPPED — CVE-2026-18255 (Red Hat Quay 3.15). Fixed in Red Hat Quay 3.15 1788191755.
PATCH SHIPPED — CVE-2026-82451 (getformwork Formwork). Fixed in Formwork 2.3.11.
ENRICHED — Linux: 43 CVEs (CVE-2026-64064, CVE-2026-64065, CVE-2026-64070, CVE-2026-64071, CVE-2026-64072, CVE-2026-64075, CVE-2026-64079, CVE-2026-64083, CVE-2026-64085, CVE-2026-64087, CVE-2026-64301, CVE-2026-64302, CVE-2026-64305, CVE-2026-64306, CVE-2026-64314, CVE-2026-64316, CVE-2026-64331, CVE-2026-64332, CVE-2026-64334, CVE-2026-64335, CVE-2026-64336, CVE-2026-64337, CVE-2026-64338, CVE-2026-64339, CVE-2026-64340, CVE-2026-64341, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64345, CVE-2026-64346, CVE-2026-64347, CVE-2026-64348, CVE-2026-64349, CVE-2026-64350, CVE-2026-64351, CVE-2026-64352, CVE-2026-64353, CVE-2026-64429, CVE-2026-64433, CVE-2026-64446, CVE-2026-64451, CVE-2026-64453). Received CVSS/CPE analysis.
How to read these box scores · glossary
346 CVEs published. 25 box scores, 321 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0164 74.7 —
AFFECTED Product Versions Fixed CRMEB 6.0 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0107 62.5 —
AFFECTED Product Versions Fixed Secure Email Gateway unspecified —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: NCSC.ch)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0061 46.9 —
AFFECTED Product Versions Fixed SEPPmail Secure Email Gateway (SEG) unspecified —
TIMELINE Sep 2 Reserved by CNA Sep 3 Public exploit reference published Sep 3 Published (CNA: NCSC.ch)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0058 45.4 —
AFFECTED Product Versions Fixed CP450 4.1.0 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N L 2.1 .0052 42.3 —
AFFECTED Product Versions Fixed agent-squad 1.1.0 – —
TIMELINE Sep 3 Reserved by CNA Sep 3 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 9.4 .0049 40.1 —
AFFECTED Product Versions Fixed Ocsreports 2.12.6 – —
TIMELINE Aug 19 Reserved by CNA Sep 3 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H H 7.7 .0045 37.6 —
AFFECTED Product Versions Fixed SEPPmail Secure Email Gateway (SEG) unspecified —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: NCSC.ch)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N N H H 8.3 .0044 37.0 —
AFFECTED Product Versions Fixed zlib 1.3.1.2 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0039 32.1 —
AFFECTED Product Versions Fixed FreeRDP 3.0.0 – 3.31.0
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H N 6.5 .0038 31.1 —
AFFECTED Product Versions Fixed PowerProtect Data Manager unspecified —
TIMELINE Aug 16 Reserved by CNA Sep 3 Published (CNA: dell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N L N 2.1 .0037 29.8 —
AFFECTED Product Versions Fixed dify 1.13.0 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N N L N 2.9 .0036 28.5 —
AFFECTED Product Versions Fixed AI-Trader d03ff6c056b32ced735adf7c19ed8175adb1c8df – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U N N H 5.9 .0035 28.0 —
AFFECTED Product Versions Fixed RTU500 series CMU firmware 12.7.1 – —
TIMELINE Jul 27 Reserved by CNA Sep 3 Published (CNA: Hitachi Energy)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H N 7.1 .0035 27.9 —
AFFECTED Product Versions Fixed ShizenBox2 (edge-app) unspecified —
TIMELINE Aug 26 Reserved by CNA Sep 3 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N R U H H N 6.8 .0035 27.8 —
AFFECTED Product Versions Fixed PowerProtect Data Manager unspecified —
TIMELINE Jul 31 Reserved by CNA Sep 3 Published (CNA: dell)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N C L N N 4.1 .0035 27.8 —
AFFECTED Product Versions Fixed PowerProtect Data Manager unspecified —
TIMELINE Aug 16 Reserved by CNA Sep 3 Published (CNA: dell)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0034 26.3 —
AFFECTED Product Versions Fixed Ocsreports 2.12.6 – —
TIMELINE Aug 19 Reserved by CNA Sep 3 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H N 8.6 .0033 25.6 —
AFFECTED Product Versions Fixed Ocsreports 2.12.6 – —
TIMELINE Aug 19 Reserved by CNA Sep 3 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H N 8.6 .0033 25.6 —
AFFECTED Product Versions Fixed Ocsreports 2.12.6 – —
TIMELINE Aug 19 Reserved by CNA Sep 3 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV P L N N N H H H 7.0 .0033 25.7 —
AFFECTED Product Versions Fixed ShizenBox2 (dev-conf) unspecified —
TIMELINE Aug 26 Reserved by CNA Sep 3 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0032 24.3 —
AFFECTED Product Versions Fixed core 1.8.0 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P L N L 5.3 .0030 22.3 —
AFFECTED Product Versions Fixed FreeRDP 3.0.0 – 3.31.0
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P N L N 2.0 .0027 18.8 —
AFFECTED Product Versions Fixed dify 1.13.0 – —
TIMELINE Sep 2 Reserved by CNA Sep 3 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0025 16.2 —
AFFECTED Product Versions Fixed GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor unspecified —
TIMELINE Feb 16 Reserved by CNA Sep 3 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0025 16.2 —
AFFECTED Product Versions Fixed Divi unspecified —
TIMELINE Mar 9 Reserved by CNA Sep 3 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-80731 | 7.8 | 15.4 | Linux | Linux | — | net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header |
| CVE-2026-80744 | await | 13.2 | Linux | Linux | — | netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path |
| CVE-2026-80752 | 8.4 | 11.2 | Linux | Linux | — | Input: psxpad-spi - set driver data before use |
| CVE-2026-80732 | 7.8 | 11.2 | Linux | Linux | — | ata: pata_sl82c105: fix bridge revision use-after-free |
| CVE-2026-80737 | 7.8 | 11.2 | Linux | Linux | — | serial: amba-pl011: synchronize DMA teardown |
| CVE-2026-80754 | 7.8 | 11.2 | Linux | Linux | — | Input: synaptics-rmi4 - fix F55 transmitter electrode count typo |
| CVE-2026-80733 | await | 11.2 | Linux | Linux | — | net: remove WARN_ON_ONCE() from sk_mc_loop() |
| CVE-2026-80742 | await | 11.2 | Linux | Linux | — | af_packet: Don't send zero-byte data in tpacket_snd(). |
| CVE-2026-80743 | await | 11.2 | Linux | Linux | — | ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers |
| CVE-2026-80756 | await | 11.2 | Linux | Linux | — | selinux: do not cancel a policy conversion that never started |
| CVE-2026-80757 | await | 11.2 | Linux | Linux | — | selinux: reject a class permission count below its inherited common |
| CVE-2026-80728 | await | 11.0 | Linux | Linux | — | Revert "drm/amdgpu: fix aperture mapping leak" |
| CVE-2026-80735 | 7.3 | 10.7 | Linux | Linux | — | ovpn: ensure socket is owned by ovpn before deref sk_user_data |
| CVE-2026-80740 | await | 10.7 | Linux | Linux | — | drm/log: Fix infinite loop when scale is too large for display |
| CVE-2026-80726 | 9.3 | 10.6 | Linux | Linux | — | KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page |
| CVE-2026-80730 | await | 10.6 | Linux | Linux | — | ring-buffer: Fix crash passing ERR_PTR to kthread_stop() |
| CVE-2026-80736 | 7.8 | 9.8 | Linux | Linux | — | thunderbolt: Fix bandwidth group reservation indexing |
| CVE-2026-80749 | 7.1 | 9.8 | Linux | Linux | — | drm/connector/hdmi: Fix out of bounds memory read |
| CVE-2026-80727 | await | 9.8 | Linux | Linux | — | x86/mce: Set up the polling timer before CMCI discovery |
| CVE-2026-80739 | await | 9.8 | Linux | Linux | — | net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock |
| CVE-2026-80755 | await | 9.8 | Linux | Linux | — | selinux: reject a permission value exceeding the class permission count |
| CVE-2026-80734 | 8.8 | 9.6 | Linux | Linux | — | btrfs: initialize inode mapping flags for cached inodes |
| CVE-2026-80745 | 8.4 | 9.6 | Linux | Linux | — | regulator: fp9931: Fix VPOS/VNEG voltage selector table |
| CVE-2026-80750 | 8.4 | 9.6 | Linux | Linux | — | pmdomain: mediatek: fix remaining %pOF after of_node_put() |
| CVE-2026-80753 | 8.4 | 9.6 | Linux | Linux | — | ovpn: run deferred work on a module-owned workqueue |
| CVE-2026-80748 | 7.8 | 9.6 | Linux | Linux | — | mmc: loongson2: Fix sg iteration in data reorder functions |
| CVE-2026-80738 | 7.3 | 9.6 | Linux | Linux | — | bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie |
| CVE-2026-80741 | 7.1 | 9.6 | Linux | Linux | — | drm/log: Fix out-of-bounds read on empty message length |
| CVE-2026-80747 | 8.0 | 8.6 | Linux | Linux | — | drm/amdkfd: Add bounds check for CRAT subtype length |
| CVE-2026-80751 | 7.8 | 8.6 | Linux | Linux | — | pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev() |
| CVE-2026-9852 | 4.6 | 8.6 | Hitachi Energy | MicroSCADA SYS600 | CWE-1236 | A CSV injection vulnerability exists in SYS600. Injected malicious formulas c… |
| CVE-2026-80729 | await | 8.6 | Linux | Linux | — | mm/huge_memory: initialise workingset state before folio split |
| CVE-2026-80746 | await | 8.6 | Linux | Linux | — | clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK |
| CVE-2026-73600 | 7.8 | 8.0 | Dell | PowerProtect Data Manager | CWE-121 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack … |
| CVE-2026-76642 | 8.5 | 6.0 | util-linux | util-linux | CWE-390 | util-linux libmount Privilege Escalation via Failed Mount Helper |
| CVE-2021-38489 | 8.2 | 5.5 | Insyde Software | InsydeH2O | CWE-256 | HDD Password Stored In Plaintext |
| CVE-2026-85092 | 5.2 | 4.7 | jtsylve | LiME | CWE-59 | LiME through 1.12.0 Arbitrary File Overwrite via Symlink Following |
| CVE-2021-43614 | 6.7 | 3.0 | Insyde Software | InsydeH2O | CWE-120 | VariableEditSmm: Error checking of UEFI variables could cause buffer overflow… |
| CVE-2026-9853 | 8.5 | 2.2 | Hitachi Energy | MicroSCADA SYS600 | CWE-303 | A vulnerability exists in SYS600 which allows any user authenticated to the o… |
| CVE-2026-9854 | 8.5 | 2.2 | Hitachi Energy | MicroSCADA SYS600 | CWE-303 | A vulnerability exists in SYS600 RBAC mechanism where users having access to … |
| CVE-2021-43613 | 6.5 | 1.6 | Insyde Software | InsydeH2O | CWE-732 | SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leadin… |
| CVE-2026-70352 | 10.0 | — | Microsoft | Azure AI Language Authoring | CWE-306 | Azure AI Language Elevation of Privilege Vulnerability |
| CVE-2026-83711 | 10.0 | — | Microsoft | Entra | CWE-639 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability |
| CVE-2026-85061 | 10.0 | — | maplibre | maplibre-gl-js | CWE-79 | MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap … |
| CVE-2026-84238 | 9.8 | — | YITH | YITH Request a Quote for WooCommerce Premium | CWE-862 | WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Brok… |
| CVE-2026-84753 | 9.8 | — | WPFunnels | Mail Mint | CWE-502 | WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability |
| CVE-2026-84814 | 9.8 | — | Bricksforge. | Bricksforge | CWE-266 | WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability |
| CVE-2026-84834 | 9.8 | — | eyecix | JobSearch | CWE-502 | WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability |
| CVE-2026-85042 | 9.6 | — | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a … | |
| CVE-2026-85047 | 9.6 | — | Chrome | CWE-20 | Improper input validation in Transactions Platform in Google Chrome on on iOS… | |
| CVE-2026-85050 | 9.6 | — | Chrome | CWE-787 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.79… | |
| CVE-2026-78069 | 9.5 | — | j2commerce.com | J2Store extension for Joomla | CWE-862 | Joomla Extension - j2commerce.com - Missing authorization on Apps controller … |
| CVE-2026-82180 | 9.5 | — | Eclipse Foundation | Eclipse Arrowhead | CWE-290 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enable… |
| CVE-2026-85216 | 9.5 | — | misp | misp | CWE-521 | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-78080 | 9.3 | — | joodb.feenders.de | JooDatabase Lite extension for Joomla | CWE-89 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase… |
| CVE-2026-80098 | 9.3 | — | Microsoft | Microsoft Copilot Studio | CWE-347 | Copilot Studio Elevation of Privilege Vulnerability |
| CVE-2026-82526 | 9.3 | — | SciPhi-AI | R2R | CWE-89 | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint |
| CVE-2026-84768 | 9.3 | — | e4jvikwp | VikAppointments Services Booking Calendar | CWE-89 | WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL In… |
| CVE-2026-84813 | 9.3 | — | Paolo | GeoDirectory | CWE-89 | WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability |
| CVE-2026-85154 | 9.3 | — | WWBN | AVideo | CWE-269 | WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash |
| CVE-2026-85181 | 9.3 | — | dianping | cat | CWE-565 | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum |
| CVE-2026-85183 | 9.3 | — | Avaiga | taipy | CWE-1385 | Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS |
| CVE-2026-85391 | 9.3 | — | Peppermint-Lab | peppermint | CWE-798 | Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compo… |
| CVE-2026-85394 | 9.3 | — | mpdavis | python-jose | CWE-347 | python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as H… |
| CVE-2026-85424 | 9.3 | — | themoos | core-moos | CWE-306 | MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subs… |
| CVE-2026-85425 | 9.3 | — | moos-ivp | moos-ivp | CWE-78 | MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS |
| CVE-2026-85426 | 9.3 | — | moos-ivp | moos-ivp | CWE-78 | MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names |
| CVE-2026-85428 | 9.3 | — | themoos | core-moos | CWE-306 | MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write |
| CVE-2026-85433 | 9.3 | — | themoos | essential-moos | CWE-862 | MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfig… |
| CVE-2026-85434 | 9.3 | — | moos-ivp | moos-ivp | CWE-345 | MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified… |
| CVE-2026-85435 | 9.3 | — | moos-ivp | moos-ivp | CWE-345 | MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment |
| CVE-2026-85437 | 9.3 | — | moos-ivp | moos-ivp | CWE-787 | MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders |
| CVE-2026-85438 | 9.3 | — | moos-ivp | moos-ivp | CWE-190 | MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts |
| CVE-2026-85440 | 9.3 | — | themoos | core-moos | CWE-787 | MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Neg… |
| CVE-2026-67402 | 9.2 | — | WebPros | ConfigServer Security & Firewall | CWE-552 | An insecure Apache configuration in ConfigServer Security & Firewall maps /us… |
| CVE-2026-76178 | 9.2 | — | OCS Inventory NG | Ocsreports | CWE-79 | Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
| CVE-2026-85427 | 9.2 | — | themoos | essential-moos | CWE-494 | MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthen… |
| CVE-2026-58400 | 9.1 | — | geonetwork | core-geonetwork | CWE-94 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processo… |
| CVE-2026-62916 | 9.1 | — | Microsoft | Microsoft Entra | CWE-288 | Microsoft Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-80515 | 8.9 | — | Eclipse Foundation | Eclipse Arrowhead | CWE-647 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorizatio… |
| CVE-2026-85109 | 8.9 | — | Tenda | HG10 | CWE-119 | Tenda HG10 Boa Web Server formLogin buffer overflow |
| CVE-2026-78064 | 8.8 | — | j2commerce.com | J2Store extension for Joomla | CWE-639 | Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inher… |
| CVE-2026-80465 | 8.8 | — | Siemens | Mendix SAML (Mendix 10 compatible) | CWE-347 | A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (Al… |
| CVE-2026-84752 | 8.8 | — | rometheme | RTMKit | CWE-502 | WordPress RTMKit plugin <= 2.1.5 - PHP Object Injection vulnerability |
| CVE-2026-85046 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote… | |
| CVE-2026-85049 | 8.8 | — | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remo… | |
| CVE-2026-85051 | 8.8 | — | Chrome | CWE-843 | Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed… | |
| CVE-2026-85053 | 8.8 | — | Chrome | CWE-668 | Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.79… | |
| CVE-2026-85199 | 8.8 | — | Eclipse Foundation | Eclipse aeriOS | CWE-22 | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path trave… |
| CVE-2026-85236 | 8.8 | — | misp | misp | CWE-352 | MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request |
| CVE-2026-85430 | 8.8 | — | themoos | essential-moos | CWE-345 | MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republ… |
| CVE-2026-85432 | 8.8 | — | themoos | core-moos | CWE-290 | MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity |
| CVE-2026-85455 | 8.8 | — | themoos | core-moos | CWE-125 | MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet |
| CVE-2026-53924 | 8.7 | — | 1Hive | gardens-v2 | CWE-284 | Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes |
| CVE-2026-57445 | 8.7 | — | 1Hive | gardens-v2 | CWE-703 | Gardens v2: Approve-side dispute resolution drains active streaming escrow re… |
| CVE-2026-71404 | 8.7 | — | SUSE | Rancher | CWE-639 | Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name… |
| CVE-2026-77999 | 8.7 | — | j2commerce.com | J2Store extension for Joomla | CWE-472 | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery l… |
| CVE-2026-82520 | 8.7 | — | domainaware | parsedmarc | CWE-409 | parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments |
| CVE-2026-82527 | 8.7 | — | SciPhi-AI | R2R | CWE-89 | R2R 3.6.6 SQL Injection via Retrieval Search Filter Key |
| CVE-2026-85155 | 8.7 | — | WWBN | AVideo | CWE-89 | WWBN AVideo SQL Injection via get.json.php APIName channels |
| CVE-2026-85169 | 8.7 | — | n8n-io | n8n | CWE-94 | n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak |
| CVE-2026-85174 | 8.7 | — | siyuan-note | siyuan | CWE-532 | SiYuan before v3.8.2 API Token Exposure via Log File |
| CVE-2026-85175 | 8.7 | — | siyuan-note | siyuan | CWE-552 | SiYuan before v3.8.2 TLS Private Key Disclosure via getFile |
| CVE-2026-85176 | 8.7 | — | dbgate | dbgate | CWE-73 | DbGate through 7.2.6 Arbitrary File Read and Write via file:// jslid |
| CVE-2026-85180 | 8.7 | — | ollama | ollama | CWE-918 | Ollama 0.30.0 through 0.33.2 SSRF via Cross-Host Tensor Blob Redirect |
| CVE-2026-85212 | 8.7 | — | crmeb | CRMEB | CWE-862 | CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check |
| CVE-2026-85393 | 8.7 | — | digitalbazaar | forge | CWE-347 | node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestA… |
| CVE-2026-85396 | 8.7 | — | rubyzip | rubyzip | CWE-22 | rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directo… |
| CVE-2026-85429 | 8.7 | — | moos-ivp | moos-ivp | CWE-345 | MOOS-IvP through 24.8.1 uFldNodeComms Node Message Source Spoofing |
| CVE-2026-85431 | 8.7 | — | themoos | essential-moos | CWE-345 | MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Inj… |
| CVE-2026-85436 | 8.7 | — | themoos | essential-moos | CWE-191 | MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative U… |
| CVE-2026-85441 | 8.7 | — | themoos | core-moos | CWE-195 | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialize… |
| CVE-2026-85442 | 8.7 | — | themoos | core-moos | CWE-789 | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet A… |
| CVE-2026-85443 | 8.7 | — | themoos | core-moos | CWE-400 | MOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of Service |
| CVE-2026-85444 | 8.7 | — | moos-ivp | moos-ivp | CWE-125 | MOOS-IvP through 24.8.1 Out-of-Bounds Read in isBraced, isQuoted and isChevroned |
| CVE-2026-85445 | 8.7 | — | moos-ivp | moos-ivp | CWE-789 | MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count |
| CVE-2026-85446 | 8.7 | — | moos-ivp | moos-ivp | CWE-407 | MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service |
| CVE-2026-85447 | 8.7 | — | moos-ivp | moos-ivp | CWE-770 | MOOS-IvP through 24.8.1 pRealm Unbounded REALMCAST_REQ Subscription Denial of… |
| CVE-2026-85448 | 8.7 | — | moos-ivp | moos-ivp | CWE-770 | MOOS-IvP through 24.8.1 uFldShoreBroker Unbounded Community State Retention |
| CVE-2026-85449 | 8.7 | — | moos-ivp | moos-ivp | CWE-770 | MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_R… |
| CVE-2026-85450 | 8.7 | — | themoos | core-moos | CWE-770 | MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion |
| CVE-2026-85452 | 8.7 | — | themoos | ui-moos | CWE-787 | MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers |
| CVE-2026-63219 | 8.6 | — | geonetwork | core-geonetwork | CWE-862 | Unauthenticated file upload via missing authorization on formatter upload end… |
| CVE-2026-64199 | 8.6 | — | measX | DASYLab | CWE-125 | Out Of Bounds Read outside the bounds of an allocated data structure when par… |
| CVE-2026-71963 | 8.6 | — | NousResearch | hermes-agent | CWE-78 | Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection |
| CVE-2026-85223 | 8.6 | — | D-Link | DNS-340L | CWE-77 | D-Link DNS-340L CGI dropbox.cgi os command injection |
| CVE-2026-85237 | 8.6 | — | misp | misp | CWE-307 | Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentica… |
| CVE-2026-85388 | 8.6 | — | Worklenz | worklenz | CWE-89 | Worklenz through 3.0.0 SQL Injection via the sort-field Query Parameter |
| CVE-2026-64195 | 8.5 | — | measX | DASYLab | CWE-787 | Out Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper vali… |
| CVE-2026-64196 | 8.5 | — | measX | DASYLab | CWE-787 | Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper valid… |
| CVE-2026-64197 | 8.5 | — | measX | DASYLab | CWE-787 | Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper valid… |
| CVE-2026-64198 | 8.5 | — | measX | DASYLab | CWE-125 | Out Of Bounds Read in file handling when parsing a .DSB file in DASYLab |
| CVE-2026-64200 | 8.5 | — | measX | DASYLab | CWE-125 | Out Of Bounds Read in during string conversionwhen parsing a .DSB file in DAS… |
| CVE-2026-65818 | 8.5 | — | Microsoft | Microsoft Power Platform | CWE-918 | Power Automate Elevation of Privilege Vulnerability |
| CVE-2026-67397 | 8.5 | — | WebPros | Plesk | CWE-22 | Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 a… |
| CVE-2026-69857 | 8.5 | — | Microsoft | Azure Cosmos DB | CWE-639 | Azure Cosmos DB Spoofing Vulnerability |
| CVE-2026-70178 | 8.5 | — | Microsoft | Microsoft Fabric | CWE-862 | Microsoft Fabric Elevation of Privilege Vulnerability |
| CVE-2026-85012 | 8.5 | — | AWS | @amazon-codecatalyst/blueprints.blueprint | CWE-78 | OS command injection in the Amazon CodeCatalyst blueprints SDK |
| CVE-2026-85222 | 8.5 | — | D-Link | DNS-340L | CWE-77 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection |
| CVE-2026-85224 | 8.5 | — | D-Link | DNS-320 ShareCenter | CWE-77 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection |
| CVE-2026-85439 | 8.5 | — | moos-ivp | moos-ivp | CWE-78 | MOOS-IvP through 24.8.1 alogsplit Command Injection via Input Pathname |
| CVE-2025-12737 | 8.4 | — | WSO2 | WSO2 Open Banking AM | CWE-78 | Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Produ… |
| CVE-2026-85179 | 8.4 | — | HumanSignal | label-studio | CWE-918 | Label Studio through 1.23.0 SSRF via Unvalidated Webhook URL |
| CVE-2026-84736 | 8.3 | — | Eclipse Foundation | Eclipse aeriOS | CWE-295 | In the current development version of Eclipse aeriOS, for which no official r… |
| CVE-2026-85048 | 8.3 | — | Chrome | CWE-416 | Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed… | |
| CVE-2026-85178 | 8.3 | — | Helicone | helicone | CWE-639 | Helicone Cross-Tenant Provider Key Disclosure via Missing Organization Filter |
| CVE-2026-85211 | 8.3 | — | HumanSignal | label-studio | CWE-639 | Label Studio through 1.23.0 Cross-Organization Storage URI Resolution |
| CVE-2026-44506 | 8.2 | — | medplum | medplum | CWE-200 | Medplum - Exposure of OAuth client secret via dynamic registration endpoint i… |
| CVE-2026-63376 | 8.2 | — | BinaryMuse | toml-node | CWE-1321 | toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__… |
| CVE-2026-67398 | 8.2 | — | WebPros | WHMCS | CWE-862 | Missing authorization vulnerability has been discovered in 2Checkout payment … |
| CVE-2026-84757 | 8.2 | — | AresIT | WP Compress | CWE-862 | WordPress WP Compress plugin <= 7.21.28 - Settings Change vulnerability |
| CVE-2026-84964 | 8.2 | — | MongoDB | C Driver | CWE-415 | Heap corruption via OCSP request double free from crafted multi-URL certifica… |
| CVE-2026-78583 | 8.1 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Privilege Escalation |
| CVE-2026-82302 | 8.1 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Unauthorized Configuration Modif… |
| CVE-2026-84779 | 8.1 | — | Sheikh Heera | Agentimus – AI SEO, llms.txt & MCP for AI Agents | CWE-862 | WordPress Agentimus – AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 -… |
| CVE-2026-83959 | 7.8 | — | Adobe | Adobe Substance 3D Sampler | CWE-122 | Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-18167 | 7.7 | — | TP-Link Systems Inc. | Archer AX55 v4 | CWE-121 | Stack-based buffer overflow in TP-Link Archer AX55 v4 |
| CVE-2026-55658 | 7.7 | — | 1Hive | gardens-v2 | CWE-862 | Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on canc… |
| CVE-2026-75033 | 7.7 | — | SUSE | Rancher | CWE-639 | Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoo… |
| CVE-2026-85168 | 7.7 | — | n8n-io | n8n | CWE-78 | n8n before 1.123.73 Remote Code Execution via Git Node |
| CVE-2026-85182 | 7.7 | — | lenve | vhr | CWE-639 | vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change |
| CVE-2026-85221 | 7.6 | — | misp | misp | CWE-295 | MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-… |
| CVE-2026-85238 | 7.6 | — | misp | misp | CWE-384 | Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking |
| CVE-2026-6071 | 7.5 | — | Rockwell Automation | Arena | CWE-787 | Code Execution Vulnerability in Arena® |
| CVE-2026-8862 | 7.5 | — | IBM | Netezza Software | CWE-522 | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-33630 | 7.5 | — | c-ares | c-ares | CWE-415 | c-ares : Use-after-free / double-free in c-ares query-completion handling, re… |
| CVE-2026-48486 | 7.5 | — | signum-network | signum-node | CWE-190 | Signum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary… |
| CVE-2026-77465 | 7.5 | — | BinaryMuse | toml-node | CWE-674 | toml-node: Uncontrolled Recursion |
| CVE-2026-84776 | 7.5 | — | malcare | MalCare Security | CWE-770 | WordPress MalCare Security plugin <= 6.69 - Denial of Service Attack vulnerab… |
| CVE-2026-84778 | 7.5 | — | migrateguru | Migrate Guru – Site Migration & Cloning | CWE-770 | WordPress Migrate Guru – Site Migration & Cloning plugin <= 6.65 - Denial of … |
| CVE-2026-84847 | 7.5 | — | brightvesseldev | Quick Event Manager | CWE-862 | WordPress Quick Event Manager plugin <= 9.17 - Broken Access Control vulnerab… |
| CVE-2026-85045 | 7.5 | — | Chrome | CWE-367 | Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote… | |
| CVE-2026-85124 | 7.5 | — | @fastify/http-proxy | @fastify/http-proxy | CWE-22 | @fastify/http-proxy vulnerable to prefix escape via backslash dot-segments |
| CVE-2026-85150 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_r… |
| CVE-2026-62906 | 7.4 | — | Microsoft | Microsoft Discovery Studio | CWE-943 | Microsoft Discovery Studio Information Disclosure Vulnerability |
| CVE-2026-75034 | 7.4 | — | SUSE | Rancher | CWE-294 | Rancher: SAML Assertion Replay |
| CVE-2026-84777 | 7.4 | — | Really Simple Plugins | Really Simple SSL | CWE-288 | WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass vulnerability |
| CVE-2026-85110 | 7.4 | — | Tenda | HG10 | CWE-119 | Tenda HG10 Boa Web Server formWlanSetup buffer overflow |
| CVE-2026-15431 | 7.3 | — | HP Inc. | HP Support Assistant | CWE-1220 | HP Support Assistant – Potential Escalation of Privilege |
| CVE-2026-85028 | 7.3 | — | AWS | aws-fpga | CWE-379 | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA… |
| CVE-2026-84761 | 7.2 | — | LiteSpeed Technologies | LiteSpeed Cache | CWE-918 | WordPress LiteSpeed Cache plugin <= 7.9 - Server Side Request Forgery (SSRF) … |
| CVE-2026-84773 | 7.2 | — | 作者: Shane Bishop | EWWW Image Optimizer | CWE-79 | WordPress EWWW Image Optimizer plugin <= 8.7.6 - Cross Site Scripting (XSS) v… |
| CVE-2026-85160 | 7.2 | — | WWBN | AVideo | CWE-73 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php |
| CVE-2026-85165 | 7.2 | — | n8n-io | n8n | CWE-95 | n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement |
| CVE-2026-85166 | 7.2 | — | n8n-io | n8n | CWE-863 | n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node |
| CVE-2026-85213 | 7.2 | — | killbill | killbill | CWE-862 | Kill Bill through 0.24.21 Missing Authorization on AdminResource Endpoints |
| CVE-2026-85214 | 7.2 | — | lenve | vhr | CWE-639 | vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite |
| CVE-2026-53728 | 7.1 | — | medplum | medplum | CWE-345 | Medplum - Improper Validation of Redirect URI in External Auth Callback allow… |
| CVE-2026-75035 | 7.1 | — | SUSE | Rancher | CWE-639 | Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-… |
| CVE-2026-78065 | 7.1 | — | j2commerce.com | J2Store extension for Joomla | CWE-639 | Joomla Extension - j2commerce.com - Guest checkout address disclosure to any … |
| CVE-2026-81292 | 7.1 | — | Ido Kobelkowsky | Simple Payment | CWE-79 | WordPress Simple Payment plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-81295 | 7.1 | — | UnderConstructionPage | Under Construction | CWE-79 | WordPress Under Construction plugin <= 5.82 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-81300 | 7.1 | — | silverplugins217 | Calculation For Contact Form 7 | CWE-79 | WordPress Calculation For Contact Form 7 plugin <= 1.0 - Cross Site Scripting… |
| CVE-2026-81773 | 7.1 | — | Saturday Drive | Ninja Forms File Uploads Extension | CWE-79 | WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Sc… |
| CVE-2026-81776 | 7.1 | — | advanpix | WP QuickLaTeX | CWE-79 | WordPress WP QuickLaTeX plugin <= 3.8.8 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-83961 | 7.1 | — | Adobe | ColdFusion 2025 | CWE-287 | ColdFusion | Improper Authentication (CWE-287) |
| CVE-2026-84756 | 7.1 | — | WC Lovers | WCFM Membership | CWE-266 | WordPress WCFM Membership plugin <= 2.11.11 - Privilege Escalation vulnerability |
| CVE-2026-84763 | 7.1 | — | rometheme | RTMKit | CWE-79 | WordPress RTMKit plugin <= 2.1.5 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-84765 | 7.1 | — | John Havlik | Breadcrumb NavXT | CWE-79 | WordPress Breadcrumb NavXT plugin <= 7.5.1 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-84812 | 7.1 | — | wordplus | BP Better Messages | CWE-79 | WordPress BP Better Messages plugin <= 2.15.27 - Cross Site Scripting (XSS) v… |
| CVE-2026-84836 | 7.1 | — | kirillbdev | WC Ukraine Shipping | CWE-639 | WordPress WC Ukraine Shipping plugin <= 1.22.3 - Insecure Direct Object Refer… |
| CVE-2026-84848 | 7.1 | — | brightvesseldev | Quick Event Manager | CWE-79 | WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vul… |
| CVE-2026-84971 | 7.1 | — | MongoDB | libmongocrypt | CWE-617 | Persistent client crash loop via undersized FLE2 insert-update ciphertext in … |
| CVE-2026-84989 | 7.1 | — | ntop | ntopng | CWE-862 | ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete a… |
| CVE-2026-85162 | 7.1 | — | WWBN | AVideo | CWE-352 | AVideo through c91b5975d CSRF via saveLive.php |
| CVE-2026-85163 | 7.1 | — | WWBN | AVideo | CWE-918 | AVideo Server-Side Request Forgery via epg_link parameter |
| CVE-2026-85164 | 7.1 | — | WWBN | AVideo | CWE-918 | WWBN AVideo Server-Side Request Forgery via set_api_userImages |
| CVE-2026-85170 | 7.1 | — | n8n-io | n8n | CWE-20 | n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes |
| CVE-2026-85171 | 7.1 | — | n8n-io | n8n | CWE-532 | n8n before 1.123.73 Credential Exposure via Error Logging |
| CVE-2026-85239 | 7.1 | — | misp | misp | CWE-20 | MISP Event Template Definition Validation Bypass Allows Persistent Denial of … |
| CVE-2026-85389 | 7.1 | — | Worklenz | worklenz | CWE-639 | Worklenz before 3.0.0 Authorization Bypass on Task-Scoped Endpoints |
| CVE-2026-85390 | 7.1 | — | bluewave-labs | Checkmate | CWE-862 | Checkmate through 3.11.0 Missing Authorization on Maintenance Window, Notific… |
| CVE-2026-85395 | 7.1 | — | unopim | unopim | CWE-862 | UnoPim before 2.1.3 Missing Authorization on Integration Management Routes |
| CVE-2026-85451 | 7.1 | — | themoos | core-moos | CWE-798 | MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multi… |
| CVE-2026-71220 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 7 | CWE-787 | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in … |
| CVE-2026-71221 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 7 | CWE-787 | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in sav… |
| CVE-2026-79679 | 7.0 | — | B&R Industrial Automation GmbH | mapp Services | CWE-1391 | Use of Weak Credentials |
| CVE-2026-15933 | 6.9 | — | OptimiDoc | OptimiDoc Server | CWE-256 | Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise) |
| CVE-2026-84968 | 6.9 | — | MongoDB | PHP Driver | CWE-125 | Heap out-of-bounds read via corrupt nested BSON in field path error message |
| CVE-2026-85062 | 6.9 | — | omgovich | colord | CWE-1333 | Colord: Slow rejection of oversized malformed color strings |
| CVE-2026-85063 | 6.9 | — | adaltas | node-csv | CWE-1321 | node-csv: Prototype replacement still reachable via columns path |
| CVE-2026-85105 | 6.9 | — | NousResearch | hermes-agent | CWE-285 | NousResearch hermes-agent Session Management s71.py _sess_nowait authorization |
| CVE-2026-85156 | 6.9 | — | WWBN | AVideo | CWE-200 | WWBN AVideo Broken Access Control via Channel Page |
| CVE-2026-85157 | 6.9 | — | WWBN | AVideo | CWE-200 | WWBN AVideo Broken Access Control via feed/index.php program_id |
| CVE-2026-85242 | 6.9 | — | Lookyloo | PlaywrightCapture | CWE-918 | Server-Side Request Forgery via Favicon Redirect to Local Network Resources i… |
| CVE-2026-82525 | 6.8 | — | Exterro | FTK Imager | CWE-611 | Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing |
| CVE-2026-85456 | 6.8 | — | moos-ivp | moos-ivp | CWE-22 | MOOS-IvP through 24.8.1 alog Splitting Path Traversal on Windows |
| CVE-2026-82918 | 6.7 | — | Keyence Corporation | XG-X VisionTerminal | CWE-611 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation imp… |
| CVE-2026-9745 | 6.5 | — | IBM | Netezza Software | CWE-283 | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-49455 | 6.5 | — | wakujs | waku | CWE-352 | Waku: Cross-Origin CSRF on RSC Server Action Dispatch |
| CVE-2026-75602 | 6.5 | — | OpenListTeam | OpenList | CWE-22 | OpenList: Authenticated arbitrary file write via Content-Disposition path tra… |
| CVE-2026-81281 | 6.5 | — | silverks | Graphene | CWE-79 | WordPress Graphene theme <= 2.9.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-81282 | 6.5 | — | VillaTheme | Product Variations Swatches for WooCommerce | CWE-79 | WordPress Product Variations Swatches for WooCommerce plugin <= 1.1.18 - Cros… |
| CVE-2026-82299 | 6.5 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-84215 | 6.5 | — | Arraytics | Timetics | CWE-862 | WordPress Timetics plugin <= 1.0.61 - Broken Access Control vulnerability |
| CVE-2026-84754 | 6.5 | — | WPFunnels | WPFunnels | CWE-862 | WordPress WPFunnels plugin <= 3.12.13 - Broken Access Control vulnerability |
| CVE-2026-84755 | 6.5 | — | WPFunnels | Mail Mint | CWE-862 | WordPress Mail Mint plugin <= 1.31.0 - Broken Access Control vulnerability |
| CVE-2026-84758 | 6.5 | — | Strategy11 Team | Business Directory | CWE-862 | WordPress Business Directory plugin <= 6.4.26 - Broken Access Control vulnera… |
| CVE-2026-84769 | 6.5 | — | Strategy11 Team | Business Directory | CWE-639 | WordPress Business Directory plugin <= 6.4.26 - Insecure Direct Object Refere… |
| CVE-2026-84849 | 6.5 | — | brightvesseldev | Pre-Orders for WooCommerce | CWE-290 | WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vul… |
| CVE-2026-85302 | 6.5 | — | WPKoi WordPress Themes | WPKoi Templates for Elementor | CWE-79 | WordPress WPKoi Templates for Elementor plugin <= 3.7.2 - Cross Site Scriptin… |
| CVE-2026-85303 | 6.5 | — | Magepeople inc. | Booking and Rental Manager | CWE-79 | WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (… |
| CVE-2026-85306 | 6.5 | — | Cascadia Web Services | MountDev AI MCP Connector for WordPress | CWE-862 | WordPress MountDev AI MCP Connector for WordPress plugin <= 1.6.5 - Broken Ac… |
| CVE-2026-82521 | 6.3 | — | domainaware | parsedmarc | CWE-22 | parsedmarc 9.0.6 < 11.0.1 Path Traversal via Forensic Report Subject |
| CVE-2026-84963 | 6.3 | — | MongoDB | C Driver | CWE-681 | Silent field truncation via unchecked int cast of huge JSON string values in … |
| CVE-2026-84969 | 6.3 | — | MongoDB | C Driver | CWE-787 | Heap overflow via truncated base64 encoding of binary fields in length-limite… |
| CVE-2026-85167 | 6.3 | — | n8n-io | n8n | CWE-943 | n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes |
| CVE-2026-19795 | 6.2 | — | IBM | Qiskit SDK | CWE-502 | Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the av… |
| CVE-2026-71429 | 6.2 | — | uhop | stream-json | CWE-407 | stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input… |
| CVE-2026-18330 | 6.1 | — | TP-Link Systems Inc. | Archer AX55 v4 | CWE-321 | Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4 |
| CVE-2026-71403 | 6.1 | — | SUSE | Rancher | CWE-639 | Rancher: Identity-field mutation in /v3/users allows account hijack via princ… |
| CVE-2026-84774 | 6.1 | — | VeronaLabs | WP Statistics | CWE-79 | WordPress WP Statistics plugin <= 14.16.11 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-85227 | 6.1 | — | misp | misp | CWE-79 | Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes a… |
| CVE-2026-3416 | 5.9 | — | WSO2 | WSO2 API Manager | CWE-330 | Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation… |
| CVE-2026-9036 | 5.9 | — | IBM | Netezza Software | CWE-295 | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-84185 | 5.9 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-347 | Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verific… |
| CVE-2026-84766 | 5.9 | — | WP Manage Ninja | FluentBooking Pro | CWE-290 | WordPress FluentBooking Pro plugin <= 2.2.1 - Bypass Vulnerability vulnerability |
| CVE-2026-84965 | 5.9 | — | MongoDB | C Driver | CWE-190 | Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds |
| CVE-2026-84966 | 5.9 | — | MongoDB | C++ Driver | CWE-681 | BSON element injection via NUL-embedded document keys in builder append |
| CVE-2026-84970 | 5.9 | — | MongoDB | C++ Driver | CWE-681 | Heap over-read or silent misparse via 32-bit truncation of JSON length in BSO… |
| CVE-2026-84815 | 5.8 | — | Kriesi | Enfold | CWE-79 | WordPress Enfold theme <= 8.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-84962 | 5.7 | — | MongoDB | libmongocrypt | CWE-93 | Authenticated KMS request forgery via CRLF injection in GCP key identifier st… |
| CVE-2026-85137 | 5.5 | — | n/a | SeaCMS | CWE-74 | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection |
| CVE-2026-85138 | 5.5 | — | n/a | SeaCMS | CWE-74 | SeaCMS WeChat index.php addslashes sql injection |
| CVE-2026-85187 | 5.5 | — | itsourcecode | Online Medicine Delivery System | CWE-74 | itsourcecode Online Medicine Delivery System Order Status Update controller.p… |
| CVE-2026-85208 | 5.5 | — | itsourcecode | Online Medicine Delivery System | CWE-284 | itsourcecode Online Medicine Delivery System Order Management Controller cont… |
| CVE-2026-85225 | 5.5 | — | code-projects | Doctor Appointment System | CWE-74 | code-projects Doctor Appointment System patient_login.php sql injection |
| CVE-2026-85378 | 5.5 | — | light0011 | cms | CWE-285 | light0011 cms Chapter Controller ChapterController.class.php _initialize auth… |
| CVE-2026-85305 | 5.4 | — | SEOPress | SEOPress | CWE-918 | WordPress SEOPress plugin <= 10.1 - Server Side Request Forgery (SSRF) vulner… |
| CVE-2026-9736 | 5.3 | — | IBM | Netezza Software | CWE-117 | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-9744 | 5.3 | — | IBM | Netezza Software | CWE-297 | Vulnerabilities exists in IBM Netezza Software |
| CVE-2026-50554 | 5.3 | — | enchant97 | note-mark | CWE-200 | Note Mark: Unauthenticated disclosure of soft-deleted note metadata via delet… |
| CVE-2026-71222 | 5.3 | — | Red Hat | Red Hat Enterprise Linux 7 | CWE-125 | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in … |
| CVE-2026-75036 | 5.3 | — | SUSE | Fleet | CWE-918 | Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template p… |
| CVE-2026-78000 | 5.3 | — | j2commerce.com | J2Store extension for Joomla | CWE-79 | Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Sto… |
| CVE-2026-82023 | 5.3 | — | ThimPress | LearnPress | CWE-863 | LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Qui… |
| CVE-2026-84762 | 5.3 | — | Saad Iqbal | WP EasyPay | CWE-472 | WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability |
| CVE-2026-84767 | 5.3 | — | Nexcess | BookIt | CWE-345 | WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability |
| CVE-2026-85106 | 5.3 | — | NousResearch | hermes-agent | CWE-918 | NousResearch hermes-agent Link Title Fetch index.tsx fetchLinkTitle server-si… |
| CVE-2026-85107 | 5.3 | — | NousResearch | hermes-agent | CWE-400 | NousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl… |
| CVE-2026-85135 | 5.3 | — | n/a | ILIAS | CWE-284 | ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted … |
| CVE-2026-85158 | 5.3 | — | WWBN | AVideo | CWE-79 | AVideo Reflected XSS via videoEmbeded.php link parameter |
| CVE-2026-85159 | 5.3 | — | WWBN | AVideo | CWE-79 | AVideo Reflected XSS via cancelUri in userLogin.php |
| CVE-2026-85161 | 5.3 | — | WWBN | AVideo | CWE-352 | AVideo removePoster.php Cross-Site Request Forgery File Deletion |
| CVE-2026-85172 | 5.3 | — | n8n-io | n8n | CWE-918 | n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass |
| CVE-2026-85173 | 5.3 | — | n8n-io | n8n | CWE-639 | n8n before 2.36.2 Missing Authorization via Insights API |
| CVE-2026-85177 | 5.3 | — | crmeb | CRMEB | CWE-639 | CRMEB through 6.0.0 Unauthorized Message Modification via edit_message |
| CVE-2026-85205 | 5.3 | — | itsourcecode | Online Medicine Delivery System | CWE-74 | itsourcecode Online Medicine Delivery System Wishlist controller.php addwishl… |
| CVE-2026-85210 | 5.3 | — | oppia | oppia | CWE-862 | Oppia through 3.5.2 Missing Authorization on AdminRoleHandler GET |
| CVE-2026-85226 | 5.3 | — | misp | misp | CWE-862 | MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of … |
| CVE-2026-85230 | 5.3 | — | misp | misp | CWE-20 | MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection |
| CVE-2026-85241 | 5.3 | — | SpecterOps | BloodHound | CWE-266 | SpecterOps BloodHound Graph Write Endpoint v2.go NewV2API improper authorization |
| CVE-2026-85304 | 5.3 | — | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-862 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-85307 | 5.3 | — | Kevin Pirnie | KP Agent Ready | CWE-201 | WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability |
| CVE-2026-85308 | 5.3 | — | Brainstorm Force | SureForms | CWE-639 | WordPress SureForms plugin <= 2.12.5 - Insecure Direct Object References (IDO… |
| CVE-2026-85309 | 5.3 | — | Supsystic | Ultimate Maps by Supsystic | CWE-862 | WordPress Ultimate Maps by Supsystic plugin <= 1.5.3 - Broken Access Control … |
| CVE-2026-85392 | 5.3 | — | Peppermint-Lab | peppermint | CWE-639 | Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint |
| CVE-2026-85453 | 5.3 | — | themoos | core-moos | CWE-79 | MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting |
| CVE-2026-85454 | 5.2 | — | themoos | core-moos | CWE-193 | MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram H… |
| CVE-2026-53720 | 5.1 | — | jetperch | pymonocypher | CWE-122 | pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when … |
| CVE-2026-56126 | 5.1 | — | Netgate | pfSense Plus | CWE-79 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php |
| CVE-2026-56127 | 5.1 | — | Netgate | pfSense Plus | CWE-79 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php |
| CVE-2026-56128 | 5.1 | — | Netgate | pfSense Plus | CWE-79 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php |
| CVE-2026-82024 | 5.1 | — | ThimPress | LearnPress | CWE-79 | LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles |
| CVE-2026-84967 | 5.1 | — | MongoDB | MongoDB for VS Code | CWE-78 | Arbitrary command execution via shell-expanded connection string in Launch Mo… |
| CVE-2026-35160 | 5.0 | — | Dell | SmartFabric OS10 Software | CWE-78 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Impr… |
| CVE-2026-63694 | 5.0 | — | Dell | SmartFabric OS10 | CWE-77 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Impr… |
| CVE-2026-71219 | 4.7 | — | Red Hat | Red Hat Enterprise Linux 7 | CWE-770 | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table … |
| CVE-2026-71224 | 4.7 | — | Red Hat | Red Hat Enterprise Linux 7 | CWE-770 | Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk |
| CVE-2026-49509 | 4.4 | — | Samsung Opensource | rLottie | CWE-125 | Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overre… |
| CVE-2026-78593 | 4.3 | — | Elastic | Kibana | CWE-94 | Improper Control of Generation of Code in Kibana Leading to Privilege Escalation |
| CVE-2026-78595 | 4.3 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Fleet Plugin Leading to Cross-Space Agent Dat… |
| CVE-2026-78596 | 4.3 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Cross-Space Write Ope… |
| CVE-2026-82298 | 4.3 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Denial of Service |
| CVE-2026-49456 | 3.1 | — | wakujs | waku | CWE-601 | Waku: Open Redirect via `unstable_redirect` Helper |
| CVE-2026-85052 | 3.1 | — | Chrome | CWE-125 | Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 … | |
| CVE-2026-85186 | 2.1 | — | itsourcecode | Online Medicine Delivery System | CWE-284 | itsourcecode Online Medicine Delivery System Customer Controller controller.p… |
| CVE-2026-85458 | 2.1 | — | Xpdf | Xpdf | CWE-369 | Divide-by-zero in Xpdf 4.06 due to zero-height Type 3 glyph |
| CVE-2026-85207 | 2.0 | — | itsourcecode | Online Medicine Delivery System | CWE-79 | itsourcecode Online Medicine Delivery System index.php cross site scripting |
| CVE-2026-85043 | await | — | Chrome | CWE-459 | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed… | |
| CVE-2026-85044 | await | — | Chrome | CWE-672 | Use of released resource in Mobile in Google Chrome on on Android prior to 15… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-03 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.