AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0122 66.6 —
AFFECTED Product Versions Fixed XING CPTrans-ME-X unspecified —
TIMELINE Aug 10 Reserved by CNA Sep 4 Published (CNA: jpcert)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 563 CVEs published, led by Linux (156).
563 CVEs published September 4, 2026: 44 critical, 143 high, 162 medium, 18 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 196 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 163 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1708 | 36451 | — | — |
| KEV catalog size | 1695 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2335 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 188 | 4149 | 420 | 2015 | 694 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +183 ▲ |
| 38 | 2202 | 280 | 856 | 978 | 88 | 78 | 7 | 0.3 | 7.5 | .0026 | +36 ▲ | |
| microsoft | 9 | 1908 | 148 | 1290 | 455 | 15 | 287 | 28 | 1.5 | 7.8 | .0044 | -7 ▼ |
| red hat | 33 | 659 | 40 | 273 | 311 | 35 | 2 | 0 | 0.0 | 6.6 | .0028 | +14 ▲ |
| apple | 0 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | 0 |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 9 | 37 | 5 | 21 | 10 | 1 | 0 | 0 | 0.0 | 7.5 | .0036 | +9 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 11 | 95 | 24 | 45 | 26 | 0 | 56 | 13 | 13.7 | 7.5 | .0042 | +11 ▲ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 0 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | 0 |
| netgear | 0 | 32 | 0 | 0 | 27 | 5 | 0 | 0 | 0.0 | 4.3 | .0025 | 0 |
| fortinet | 0 | 30 | 7 | 8 | 14 | 1 | 28 | 6 | 20.0 | 7.0 | .0050 | 0 |
| f5 | 7 | 24 | 6 | 14 | 3 | 1 | 4 | 1 | 4.2 | 8.7 | .0047 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0033 | +5 ▲ |
| vmware | 0 | 19 | 4 | 10 | 3 | 2 | 7 | 2 | 10.5 | 8.3 | .0040 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 8 | 514 | 103 | 217 | 176 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | +2 ▲ |
| mozilla | 34 | 221 | 80 | 79 | 62 | 0 | 9 | 0 | 0.0 | 8.1 | .0029 | +33 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0023 | +26 ▲ |
| gitlab | 0 | 76 | 3 | 17 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0029 | 0 |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | +3 ▲ |
| docker | 0 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | 0 |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | 0 |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | 0 |
| ibm | 70 | 689 | 150 | 301 | 228 | 9 | 6 | 1 | 0.1 | 7.5 | .0030 | +70 ▲ |
| adobe | 2 | 608 | 50 | 302 | 247 | 9 | 19 | 3 | 0.5 | 7.8 | .0021 | -5 ▼ |
| progress | 2 | 63 | 14 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0036 | +2 ▲ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | -10 ▼ |
| zohocorp | 1 | 11 | 3 | 6 | 2 | 0 | 0 | 0 | 0.0 | 8.8 | .0144 | +1 ▲ |
| atlassian | 0 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 3 | 48 | 15 | 16 | 9 | 8 | 3 | 0 | 0.0 | 8.5 | .0160 | +3 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +18 ▲ |
| siemens | 1 | 38 | 2 | 25 | 8 | 3 | 0 | 0 | 0.0 | 7.3 | .0016 | +1 ▲ |
| synology | 0 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -1 ▼ |
| schneider electric | 4 | 13 | 1 | 8 | 4 | 0 | 0 | 0 | 0.0 | 8.2 | .0032 | +4 ▲ |
| hitachi energy | 4 | 7 | 0 | 3 | 4 | 0 | 0 | 0 | 0.0 | 6.9 | .0017 | +4 ▲ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 19 | 190 | 13 | 103 | 69 | 5 | 2 | 1 | 0.5 | 7.3 | .0021 | +16 ▲ |
| sourcecodester | 1 | 170 | 0 | 0 | 93 | 77 | 0 | 0 | 0.0 | 5.5 | .0029 | +1 ▲ |
| spring | 0 | 170 | 12 | 59 | 84 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | 0 |
| nvidia | 30 | 164 | 20 | 115 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0028 | +14 ▲ |
| elastic | 42 | 129 | 1 | 27 | 98 | 3 | 1 | 0 | 0.0 | 6.5 | .0028 | +42 ▲ |
| splunk | 0 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | 0 |
| itsourcecode | 6 | 122 | 0 | 0 | 35 | 87 | 0 | 0 | 0.0 | 2.1 | .0026 | +6 ▲ |
| siyuan-note | 11 | 114 | 44 | 33 | 36 | 1 | 0 | 0 | 0.0 | 8.6 | .0027 | +3 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-8037 | .9957 | 99.9 | 9.8 |
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-72898 | .8232 | 99.6 | 10.0 |
| CVE-2026-73570 | .3238 | 98.2 | 8.9 |
| CVE-2026-64638 | .3120 | 98.1 | 8.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-64849 | .1641 | 96.8 | 9.3 |
| CVE-2026-48376 | .1392 | 96.3 | 5.4 |
| CVE-2026-15733 | .1354 | 96.2 | 9.8 |
| CVE-2026-65400 | .0990 | 95.2 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .8232 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-73299 | 10.0 | .0121 | |
| CVE-2026-73678 | 10.0 | .0114 | |
| CVE-2026-77554 | 10.0 | .0099 |
| Vendor | CVEs |
|---|---|
| linux | 1811 |
| oracle | 890 |
| microsoft | 470 |
| 438 | |
| ibm | 428 |
| red hat | 227 |
| apache | 137 |
| splunk | 110 |
| adobe | 96 |
| mozilla | 93 |
| Vendor | KEV |
|---|---|
| microsoft | 28 |
| cisco | 13 |
| apple | 8 |
| 7 | |
| fortinet | 6 |
| ivanti | 5 |
| berriai | 4 |
| oracle | 4 |
| solarwinds | 4 |
| sonicwall | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 45 |
| Packagist | 32 |
| npm | 14 |
| PyPI | 11 |
| Go | 1 |
| RubyGems | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-8037 | Progress Software | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-64849 | mlflow | 1 |
| CVE-2026-81578 | PaperCut | 3 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1752 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1752 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1752 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1752 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1752 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1752 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1752 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1752 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1752 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1752 |
ADDED TO KEV — CVE-2026-85046 (Google Chrome). Remediation due September 18, 2026.
EXPLOIT PUBLISHED — patriksimek vm2: 7 CVEs (CVE-2026-43997, CVE-2026-43998, CVE-2026-43999, CVE-2026-44005, CVE-2026-44007, CVE-2026-44009, CVE-2026-45411). Public exploit references added.
EXPLOIT PUBLISHED — axios: 6 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42043). Public exploit references added.
EXPLOIT PUBLISHED — FlowiseAI Flowise: 5 CVEs (CVE-2026-67620, CVE-2026-71962, CVE-2026-73602, CVE-2026-73603, CVE-2026-73604). Public exploit references added.
EXPLOIT PUBLISHED — handlebars-lang handlebars.js: 5 CVEs (CVE-2026-33937, CVE-2026-33938, CVE-2026-33939, CVE-2026-33940, CVE-2026-33941). Public exploit references added.
EXPLOIT PUBLISHED — itsourcecode Online Medicine Delivery System: 4 CVEs (CVE-2026-85186, CVE-2026-85187, CVE-2026-85207, CVE-2026-85208). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33891 (digitalbazaar forge). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33896 (digitalbazaar forge). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39956 (jqlang jq). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43820 (Apple swift-nio-ssl). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-52022. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56718 (AJCloud AJY IPC Firmware). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82526 (SciPhi-AI R2R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82527 (SciPhi-AI R2R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84841 (tsi-coop tsi-dpdp-cms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84886 (simular-ai Agent-S). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85030 (HKUDS AI-Trader). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85137 (SeaCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85222 (D-Link DNS-340L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85223 (D-Link DNS-340L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85224 (D-Link DNS-320 ShareCenter). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85225 (code-projects Doctor Appointment System). Public exploit reference added.
DUE DATE PASSED — CVE-2026-72530 (TrueConf Server). CISA remediation deadline was September 3, 2026; still in catalog.
REJECTED — CVE-2026-61485 (Apache Software Foundation Apache Lucy). Record withdrawn by the CNA.
RESCORED — Spring Cloud Stream: 4 CVEs (CVE-2026-59303, CVE-2026-59304, CVE-2026-59305, CVE-2026-59306). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2025-67038 (Lantronix EDS5000 series). CVSS 9.8 → 9.3 (NVD).
RESCORED — CVE-2026-12261 (nltk/nltk). CVSS 5.3 → 6.5 (NVD).
RESCORED — CVE-2026-13732 (Red Hat Enterprise Linux 10). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2026-18165 (@fastify/oauth2). CVSS 4.2 → 5.4 (NVD).
RESCORED — CVE-2026-18824 (IBM AIX). CVSS 8.4 → 8.8 (NVD).
RESCORED — CVE-2026-47834 (Spring Data JPA). CVSS 4.8 → 6.5 (NVD).
RESCORED — CVE-2026-47836 (Spring Cloud Config). CVSS 7.2 → 8.1 (NVD).
RESCORED — CVE-2026-47837 (Spring Cloud Config). CVSS 6.8 → 9.8 (NVD).
RESCORED — CVE-2026-47844 (Spring Reactor Netty). CVSS 5.3 → 3.7 (NVD).
RESCORED — CVE-2026-47859 (Spring Integration). CVSS 5.4 → 6.5 (NVD).
RESCORED — CVE-2026-59301 (Spring Cloud Function). CVSS 3.1 → 4.9 (NVD).
RESCORED — CVE-2026-63509 (Microsoft Fabric). CVSS 9.9 → 8.8 (NVD).
RESCORED — CVE-2026-69419 (Microsoft Azure Data Manager for Energy). CVSS 8.5 → 8.8 (NVD).
RESCORED — CVE-2026-70105 (Microsoft 365 Apps for Enterprise). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2026-72670 (Elastic Kibana). CVSS 7.7 → 6.5 (NVD).
RESCORED — CVE-2026-72676 (Elastic Fleet Server). CVSS 6.5 → 9.1 (NVD).
PATCH SHIPPED — CVE-2025-67038 (Lantronix EDS5000 series). Fixed in EDS5000 series 2.2.0.0R1.
PATCH SHIPPED — CVE-2026-55985 (Tycon Systems TPDIN-Monitor-WEB2). Fixed in TPDIN-Monitor-WEB2 2.4.5.
PATCH SHIPPED — CVE-2026-61884 (Tycon Systems TPDIN-Monitor-WEB2). Fixed in TPDIN-Monitor-WEB2 2.4.5.
ENRICHED — Linux: 33 CVEs (CVE-2026-64307, CVE-2026-64308, CVE-2026-64309, CVE-2026-64310, CVE-2026-64321, CVE-2026-64325, CVE-2026-64326, CVE-2026-64327, CVE-2026-64328, CVE-2026-64329, CVE-2026-64330, CVE-2026-64356, CVE-2026-64357, CVE-2026-64358, CVE-2026-64359, CVE-2026-64360, CVE-2026-64362, CVE-2026-64363, CVE-2026-64365, CVE-2026-64404, CVE-2026-64405, CVE-2026-64407, CVE-2026-64409, CVE-2026-64415, CVE-2026-64416, CVE-2026-64417, CVE-2026-64419, CVE-2026-64421, CVE-2026-64424, CVE-2026-64425, CVE-2026-64426, CVE-2026-64427, CVE-2026-64428). Received CVSS/CPE analysis.
How to read these box scores · glossary
563 CVEs published. 25 box scores and 375 table rows below; the remaining 163 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0122 66.6 —
AFFECTED Product Versions Fixed XING CPTrans-ME-X unspecified —
TIMELINE Aug 10 Reserved by CNA Sep 4 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0083 55.0 —
AFFECTED Product Versions Fixed AI Website Builder (GitHub build) 1.0.0 – —
TIMELINE Aug 31 Reserved by CNA Sep 4 Published (CNA: WPScan)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0054 43.6 —
AFFECTED Product Versions Fixed @fastify/middie 9.1.0 – 9.3.4
TIMELINE Sep 3 Reserved by CNA Sep 4 Published (CNA: openjs)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0054 43.6 —
AFFECTED Product Versions Fixed DreamMaker all – —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0053 42.8 —
AFFECTED Product Versions Fixed fastify 4.0.0 – 5.12.2
TIMELINE Aug 19 Reserved by CNA Sep 4 Published (CNA: openjs)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H N 7.5 .0052 42.2 —
AFFECTED Product Versions Fixed fastify unspecified 5.12.2
TIMELINE Sep 1 Reserved by CNA Sep 4 Published (CNA: openjs)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0046 38.0 —
AFFECTED Product Versions Fixed Divi Ajax Filter unspecified —
TIMELINE Jun 8 Reserved by CNA Sep 4 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0039 32.0 —
AFFECTED Product Versions Fixed FreeIPMI unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0039 32.0 —
AFFECTED Product Versions Fixed FreeIPMI unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0039 32.0 —
AFFECTED Product Versions Fixed FreeIPMI unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0039 32.0 —
AFFECTED Product Versions Fixed FreeIPMI unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0039 32.0 —
AFFECTED Product Versions Fixed FreeIPMI unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0039 31.8 —
AFFECTED Product Versions Fixed fastify unspecified 5.12.2
TIMELINE Sep 1 Reserved by CNA Sep 4 Published (CNA: openjs)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N N 6.3 .0038 31.1 —
AFFECTED Product Versions Fixed smartLink HW-PN 1.04 – 1.10
TIMELINE Jun 24 Reserved by CNA Sep 4 Published (CNA: Softing)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0035 27.9 —
AFFECTED Product Versions Fixed SmartIT Desktop Manager unspecified —
TIMELINE Sep 3 Reserved by CNA Sep 4 Published (CNA: twcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0035 27.9 —
AFFECTED Product Versions Fixed SmartIT Desktop Manager unspecified —
TIMELINE Sep 3 Reserved by CNA Sep 4 Published (CNA: twcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A N L L 6.2 .0034 27.1 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: CIRCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0034 26.7 —
AFFECTED Product Versions Fixed FreeIPMI unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0034 26.7 —
AFFECTED Product Versions Fixed Quality Management 9.7.0 – —
TIMELINE Sep 3 Reserved by CNA Sep 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0033 26.2 —
AFFECTED Product Versions Fixed cms c774dce31c6df0055568a8d5c53d964d99be199d – —
TIMELINE Sep 3 Reserved by CNA Sep 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H L 8.3 .0030 22.3 —
AFFECTED Product Versions Fixed misp unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 4 Published (CNA: CIRCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0030 22.2 —
AFFECTED Product Versions Fixed ACPT (Premium) unspecified —
TIMELINE Jul 10 Reserved by CNA Sep 4 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0029 21.3 —
AFFECTED Product Versions Fixed XING CPTrans-ME-X unspecified —
TIMELINE Aug 10 Reserved by CNA Sep 4 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0029 21.3 —
AFFECTED Product Versions Fixed XING CPTrans-ME-X unspecified —
TIMELINE Aug 10 Reserved by CNA Sep 4 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0029 21.0 —
AFFECTED Product Versions Fixed cms c774dce31c6df0055568a8d5c53d964d99be199d – —
TIMELINE Sep 3 Reserved by CNA Sep 4 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-85382 | 2.1 | 19.3 | light0011 | cms | CWE-79 | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode c… |
| CVE-2026-81666 | 6.5 | 19.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Corosync: corosync: integer overflow in check_memb_commit_token_sanity may by… |
| CVE-2026-85407 | 2.1 | 19.0 | Eleveo | Quality Management | CWE-404 | Eleveo Quality Management Conversation events denial of service |
| CVE-2026-85402 | 5.5 | 18.7 | code-projects | Doctor Appointment System | CWE-74 | code-projects Doctor Appointment System booking.php sql injection |
| CVE-2026-85379 | 5.5 | 17.9 | light0011 | cms | CWE-74 | light0011 cms Query Builder ChapterController.class.php searchChapter sql inj… |
| CVE-2026-85397 | 5.5 | 17.9 | code-projects | Hospital Information System | CWE-74 | code-projects Hospital Information System addReq.php findBySearch sql injection |
| CVE-2026-85398 | 5.5 | 17.9 | code-projects | Hospital Information System | CWE-74 | code-projects Hospital Information System viewReq.php viewReq sql injection |
| CVE-2026-85399 | 5.5 | 17.9 | code-projects | Hospital Information System | CWE-74 | code-projects Hospital Information System PrespController.php getSinglePresp … |
| CVE-2026-85403 | 5.5 | 17.9 | code-projects | Doctor Appointment System | CWE-74 | code-projects Doctor Appointment System contactus.php sql injection |
| CVE-2026-85541 | 4.8 | 18.0 | Interinfo | DreamMaker | CWE-79 | Interinfo|DreamMaker - Reflected Cross-site Scripting |
| CVE-2026-66840 | 8.7 | 17.6 | Xing Inc. | XING CPTrans-ME-X | CWE-497 | XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an … |
| CVE-2026-85401 | 2.1 | 16.2 | n/a | Dolibarr | CWE-266 | Dolibarr Legacy File Manager config.inc.php access control |
| CVE-2026-85149 | 6.9 | 16.2 | Lightstar | SmartIT Desktop Manager | CWE-798 | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-57777 | 7.6 | 14.3 | Automattic | WooCommerce | CWE-89 | WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability |
| CVE-2026-85094 | 8.8 | 14.1 | Canva | Canva | CWE-212 | The Canva Android App before 2.376.0 did not restrict the headers returned to… |
| CVE-2026-85408 | 2.1 | 14.1 | Eleveo | Quality Management | CWE-913 | Eleveo Quality Management Conversation events dynamically-determined object a… |
| CVE-2026-27086 | 6.5 | 13.0 | Xtemos | WoodMart | CWE-79 | WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-85085 | 9.6 | 12.5 | Canva | Canva | CWE-940 | The Canva Android App before 2.376.0 allowed an external origin to be loaded … |
| CVE-2026-85533 | 7.6 | 12.3 | misp | misp | CWE-862 | MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter |
| CVE-2026-75754 | 10.0 | 11.8 | ASUS | Control Center Enterprise (ACC) | CWE-306 | Missing Authentication for Critical Function, Server-Side Request Forgery (SS… |
| CVE-2026-81665 | 7.5 | 11.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-122 | Corosync: corosync: heap-based buffer overflow in totempg assembly buffer dur… |
| CVE-2026-80180 | 6.1 | 10.8 | Apache Software Foundation | Apache Allura | CWE-79 | Apache Allura: Stored XSS via markdown HTML processing |
| CVE-2026-80181 | await | 10.6 | Apache Software Foundation | Apache Allura | CWE-918 | Apache Allura: Server-side request forgery |
| CVE-2026-85147 | 8.7 | 10.0 | Lightstar | SmartIT Desktop Manager | CWE-284 | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
| CVE-2026-81270 | 7.5 | 9.8 | Apache Software Foundation | Apache Allura | CWE-200 | Apache Allura: Information exposure via search |
| CVE-2026-85383 | 2.1 | 9.9 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System inv_del.php sql injection |
| CVE-2026-85546 | 8.6 | 9.7 | misp | misp | CWE-352 | MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests |
| CVE-2026-85405 | 2.0 | 8.8 | Eleveo | Call Recording Software | CWE-79 | Eleveo Call Recording Software roleAddAction.do cross site scripting |
| CVE-2026-85406 | 2.0 | 8.8 | Eleveo | Quality Management | CWE-79 | Eleveo Quality Management Conversation Review cross site scripting |
| CVE-2026-80190 | 6.1 | 8.6 | Apache Software Foundation | Apache Allura | CWE-79 | Apache Allura: Stored XSS via code repositories |
| CVE-2026-27432 | 5.4 | 8.2 | sc Internet Vivoo | WP Rentals | CWE-639 | WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR… |
| CVE-2026-85197 | 7.6 | 8.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-416 | Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read()… |
| CVE-2026-85528 | 5.3 | 7.8 | Snowflake | Snowflake JDBC Driver | CWE-20 | Snowflake JDBC Driver auto-configuration account validation permits credentia… |
| CVE-2026-32480 | 5.3 | 7.2 | WC Lovers | WCFM Membership | CWE-862 | WordPress WCFM Membership plugin <= 2.11.11 - Broken Access Control vulnerabi… |
| CVE-2026-85311 | 5.3 | 7.2 | Kings Plugins | MarketKing | CWE-862 | WordPress MarketKing plugin <= 2.1.60 - Broken Access Control vulnerability |
| CVE-2026-19224 | 7.2 | 6.5 | Unknown | Hummingbird Performance | CWE-94 | Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite |
| CVE-2026-84043 | 5.3 | 5.7 | Unknown | ePayco Payment Gateway for WooCommerce | CWE-345 | ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Conf… |
| CVE-2026-84044 | 5.3 | 5.7 | Unknown | Restaurant Menu and Food Ordering | — | Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass v… |
| CVE-2026-82186 | 4.1 | 5.7 | Unknown | WPLP Cookie Consent | CWE-89 | WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter |
| CVE-2026-85229 | await | 5.5 | Apache Software Foundation | Apache SkyWalking | CWE-79 | Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incompl… |
| CVE-2026-82193 | 5.5 | 5.2 | Unknown | WPvivid — Backup, Migration & Staging | CWE-22 | WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup D… |
| CVE-2026-81302 | 8.5 | 4.8 | JAL Information Technology Co., Ltd. | PALLET CONTROL | CWE-276 | PALLET CONTROL products contain an incorrect default permission vulnerability… |
| CVE-2026-81347 | 5.9 | 4.1 | Unknown | Frontend Admin by DynamiApps | CWE-73 | Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.… |
| CVE-2026-17517 | 5.3 | 4.1 | Unknown | Content Views | CWE-200 | Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure … |
| CVE-2026-79631 | 5.3 | 4.1 | Unknown | WPFunnels | CWE-200 | WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-… |
| CVE-2026-15937 | 5.3 | 3.7 | Checkmk GmbH | Checkmk | CWE-295 | Agent receiver certificate confusion allows authentication with a certificate… |
| CVE-2026-74853 | 6.8 | 3.6 | Unknown | Pods | CWE-552 | Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback |
| CVE-2026-82194 | 5.5 | 3.6 | Unknown | WPvivid — Backup, Migration & Staging | CWE-73 | WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Pat… |
| CVE-2026-84146 | 5.3 | 3.6 | Unknown | Xpro Addons — 140+ Widgets for Elementor | CWE-200 | Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclos… |
| CVE-2026-45200 | await | 3.6 | Imagination Technologies | Graphics DDK | CWE-416 | GPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by… |
| CVE-2025-15691 | 5.3 | 3.4 | Unknown | WPFunnels | CWE-863 | WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms |
| CVE-2026-79630 | 5.3 | 3.4 | Unknown | WPFunnels | CWE-639 | WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Produc… |
| CVE-2026-79632 | 5.3 | 3.4 | Unknown | WPFunnels | CWE-862 | WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wp… |
| CVE-2026-16281 | 7.1 | 3.1 | Unknown | Classified Listing | CWE-639 | Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Li… |
| CVE-2026-80438 | 5.9 | 3.1 | Unknown | Ninja Forms | CWE-284 | Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and S… |
| CVE-2026-84066 | 3.1 | 3.1 | Unknown | Directorist: AI-Powered Business Directory, Listings & Classified Ads | CWE-862 | Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_atta… |
| CVE-2026-45197 | await | 1.5 | Imagination Technologies | Graphics DDK | CWE-367 | GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet |
| CVE-2026-6217 | 6.3 | 1.4 | Pik Online Software Solutions Inc. | Pik Online Portal | CWE-759 | Information Disclosure in Pik Online Software's Portal |
| CVE-2026-71216 | await | 1.4 | Apache Software Foundation | Apache SkyWalking | CWE-319 | Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key… |
| CVE-2026-85525 | 7.4 | 1.2 | Snowflake | Snowflake Connector for Python | CWE-295 | Improper OCSP response validation in Snowflake drivers |
| CVE-2026-18658 | 9.8 | — | IBM | Operational Decision Manager | CWE-89 | IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed |
| CVE-2026-31020 | 9.8 | — | n/a | n/a | CWE-94 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature… |
| CVE-2026-75430 | 9.8 | — | n/a | n/a | CWE-306 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /work… |
| CVE-2026-19274 | 9.6 | — | IBM | Observability with Instana (Agent) | CWE-284 | IBM Instana Observability is affected by multiple vulnerabilities within Inst… |
| CVE-2026-52777 | 9.4 | — | YesWiki | yeswiki | CWE-352 | YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
| CVE-2026-75925 | 9.4 | — | IXON | IXON VPN Client | CWE-93 | IXON VPN Client CRLF Injection |
| CVE-2026-44402 | 9.3 | — | Voltronic Power | SNMP Web Pro | CWE-434 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi |
| CVE-2026-85595 | 9.3 | — | traefik | traefik | CWE-287 | Traefik before v2.11.55 Authentication Bypass via digestAuth |
| CVE-2026-85602 | 9.3 | — | getgrav | grav | CWE-807 | Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass |
| CVE-2026-85661 | 9.3 | — | haris-musa | excel-mcp-server | CWE-22 | excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode |
| CVE-2026-85663 | 9.3 | — | aimhubio | aim | CWE-306 | Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch |
| CVE-2026-85667 | 9.3 | — | TeamWiseFlow | xiaobei | CWE-306 | xiaobei through 5.5.2 Unauthenticated Webhook Message Injection |
| CVE-2026-85672 | 9.3 | — | getomni-ai | zerox | CWE-78 | zerox 1.1.20 OS Command Injection via Document URL File Extension |
| CVE-2026-85688 | 9.3 | — | TEN-framework | ten-framework | CWE-306 | TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer |
| CVE-2026-85695 | 9.3 | — | lm-sys | FastChat | CWE-306 | FastChat Unauthenticated Worker Registration SSRF and Model Spoofing |
| CVE-2026-85696 | 9.3 | — | OpenTalker | SadTalker | CWE-78 | SadTalker OS Command Injection via Audio Filename |
| CVE-2026-9317 | 9.2 | — | NangoHQ | nango | CWE-306 | Nango < 0.71.6 Missing Authentication RCE via runner tRPC server |
| CVE-2026-85614 | 9.2 | — | Openpanel-dev | openpanel | CWE-918 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker |
| CVE-2026-85620 | 9.2 | — | crystaldba | postgres-mcp | CWE-863 | Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function |
| CVE-2026-85625 | 9.2 | — | crcn | sift.js | CWE-1321 | sift 17.1.3 Prototype Pollution Remote Code Execution via $where |
| CVE-2026-85660 | 9.2 | — | MladenSU | cli-mcp-server | CWE-78 | cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution |
| CVE-2026-85694 | 9.2 | — | lavague-ai | LaVague | CWE-94 | LaVague 0.2.35 Remote Code Execution via eval extraction |
| CVE-2026-52766 | 9.1 | — | YesWiki | yeswiki | CWE-276 | YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}… |
| CVE-2026-75160 | 9.1 | — | n/a | n/a | CWE-269 | An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to esc… |
| CVE-2026-75431 | 9.1 | — | n/a | n/a | CWE-321 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT sig… |
| CVE-2026-78327 | 9.1 | — | SonicWall | Network Security Manager (NSM) | CWE-78 | An Improper Neutralization of Special Elements used in an OS Command ('OS Com… |
| CVE-2026-78328 | 9.1 | — | SonicWall | Network Security Manager (NSM) | CWE-862 | A missing authorization vulnerability in the SonicWall Network Security Manag… |
| CVE-2026-81939 | 9.1 | — | SonicWall | Network Security Manager (NSM) | CWE-22 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-P… |
| CVE-2026-48019 | 8.9 | — | laravel | framework | CWE-93 | CRLF injection in Laravel's default email rule enables SMTP smuggling and spo… |
| CVE-2026-18198 | 8.8 | — | TAC Information Services Internal and External Trade Inc. | GOLDENHORN ONEIT | CWE-89 | SQL Injection in TAC Information's GoldenHorn |
| CVE-2026-18486 | 8.8 | — | IBM | ContextForge MCP Gateway | CWE-200 | IBM ContextForge MCP Gateway is affected by credential disclosure and privile… |
| CVE-2026-19298 | 8.8 | — | IBM | Langflow OSS | CWE-94 | Langflow is vulnerable to remote code execution due to authorization policy b… |
| CVE-2026-52775 | 8.8 | — | YesWiki | yeswiki | CWE-89 | YesWiki Authenticated SQL Injection in ReactionManager |
| CVE-2026-57161 | 8.8 | — | pjsip | pjproject | CWE-121 | PJSIP: Stack overflow handling Service-Route headers in a registration response |
| CVE-2026-57162 | 8.8 | — | pjsip | pjproject | CWE-121 | PJSIP: Stack overflow parsing SDP a=crypto attributes |
| CVE-2026-57163 | 8.8 | — | pjsip | pjproject | CWE-121 | PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuT… |
| CVE-2026-85684 | 8.8 | — | datalab-to | marker | CWE-73 | marker through 2.0.0 Path Traversal via upload filename |
| CVE-2026-46636 | 8.7 | — | twigphp | Twig | CWE-1336 | Twig: Sandbox method allowlist bypass via `Markup` subclass |
| CVE-2026-53758 | 8.7 | — | emlog | emlog | CWE-79 | Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized |
| CVE-2026-77393 | 8.7 | — | Inductive Automation | Ignition | CWE-276 | Inductive Automation Ignition Incorrect Default Permissions |
| CVE-2026-79707 | 8.7 | — | Google Cloud | Agent Development Kit (ADK) | CWE-22 | Arbitrary File Read in Google Agent Development Kit (ADK) |
| CVE-2026-82538 | 8.7 | — | ILIAS-eLearning e.V. | ILIAS | CWE-89 | ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter |
| CVE-2026-85581 | 8.7 | — | siyuan-note | siyuan | CWE-770 | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registr… |
| CVE-2026-85584 | 8.7 | — | siyuan-note | siyuan | CWE-770 | SiYuan before v3.8.2 Denial of Service via Auth Throttle |
| CVE-2026-85585 | 8.7 | — | siyuan-note | siyuan | CWE-400 | SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
| CVE-2026-85604 | 8.7 | — | getgrav | grav | CWE-94 | Grav before 2.0.19 Remote Code Execution via sort filter |
| CVE-2026-85606 | 8.7 | — | firecrawl | firecrawl-mcp-server | CWE-22 | firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath |
| CVE-2026-85607 | 8.7 | — | blinkospace | blinko | CWE-639 | Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router |
| CVE-2026-85608 | 8.7 | — | Evil0ctal | Douyin_TikTok_Download_API | CWE-918 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter |
| CVE-2026-85610 | 8.7 | — | Openpanel-dev | openpanel | CWE-94 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas |
| CVE-2026-85612 | 8.7 | — | Openpanel-dev | openpanel | CWE-918 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints |
| CVE-2026-85617 | 8.7 | — | grokability | snipe-it | CWE-639 | snipe-it before 8.6.3 Authorization Bypass via Bulk Delete |
| CVE-2026-85623 | 8.7 | — | aaif-goose | goose | CWE-94 | goose 1.37.0 Arbitrary Command Execution via Recipe Extensions |
| CVE-2026-85626 | 8.7 | — | cyanheads | git-mcp-server | CWE-88 | git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters |
| CVE-2026-85664 | 8.7 | — | chroma-core | chroma | CWE-770 | Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion |
| CVE-2026-85666 | 8.7 | — | ogx-ai | ogx | CWE-918 | ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url |
| CVE-2026-85668 | 8.7 | — | xorbitsai | inference | CWE-73 | Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/… |
| CVE-2026-85671 | 8.7 | — | netease-youdao | QAnything | CWE-306 | QAnything 2.0.0 Unauthenticated Cross-User File Disclosure |
| CVE-2026-85673 | 8.7 | — | hiyouga | LlamaFactory | CWE-918 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding |
| CVE-2026-85675 | 8.7 | — | camel-ai | owl | CWE-918 | OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching |
| CVE-2026-85685 | 8.7 | — | agentscope-ai | agentscope | CWE-22 | AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill |
| CVE-2026-85686 | 8.7 | — | modelscope | ms-swift | CWE-918 | ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs |
| CVE-2026-85687 | 8.7 | — | datalab-to | surya | CWE-73 | surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server |
| CVE-2026-85691 | 8.7 | — | The-Vibe-Company | megaparse | CWE-918 | MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url |
| CVE-2026-85699 | 8.7 | — | jina-ai | reader | CWE-918 | jina-ai reader server-side request forgery via redirect validation bypass |
| CVE-2026-85786 | 8.7 | — | Amazon | ion-java | CWE-409 | Incomplete fix for CVE-2026-75936 memory-amplification denial of service in A… |
| CVE-2026-19305 | 8.6 | — | IBM | Langflow OSS | CWE-918 | Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas… |
| CVE-2026-50553 | 8.6 | — | enchant97 | note-mark | CWE-20 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (s… |
| CVE-2026-82684 | 8.6 | — | Tycon Systems | TPDIN-Monitor-WEB3 | CWE-862 | Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization |
| CVE-2026-82712 | 8.6 | — | Tycon Systems | TPDIN-Monitor-WEB3 | CWE-352 | Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery |
| CVE-2026-4644 | 8.5 | — | Google Cloud | Integration Connectors | CWE-863 | Improper Authorization in Google Cloud Integration Connectors Leads to Projec… |
| CVE-2026-6958 | 8.5 | — | Invicti Security Corp. | Acunetix | CWE-427 | Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe |
| CVE-2026-80112 | 8.5 | — | PassMark Software | PerformanceTest | CWE-732 | PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control… |
| CVE-2026-80114 | 8.5 | — | PassMark Software | PerformanceTest | CWE-321 | PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials … |
| CVE-2026-80116 | 8.5 | — | PassMark Software | PerformanceTest | CWE-782 | PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation vi… |
| CVE-2026-80119 | 8.5 | — | PassMark Software | PerformanceTest | CWE-73 | PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclos… |
| CVE-2026-85656 | 8.5 | — | Amazon | log4j-cve-2021-44228-hotpatch | CWE-78 | OS command injection in Amazon log4j-cve-2021-44228-hotpatch |
| CVE-2026-85674 | 8.5 | — | Aider-AI | aider | CWE-94 | aider 0.86.2 Remote Code Execution via .aider.conf.yml |
| CVE-2026-85690 | 8.5 | — | plandex-ai | plandex | CWE-22 | Plandex 2.2.1 Path Traversal via ApplyFiles |
| CVE-2026-86095 | 8.5 | — | Unidata | netcdf-c | CWE-787 | Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attrib… |
| CVE-2026-57159 | 8.4 | — | pjsip | pjproject | CWE-129 | PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance |
| CVE-2026-80118 | 8.4 | — | PassMark Software | PerformanceTest | CWE-73 | PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Der… |
| CVE-2026-85613 | 8.4 | — | Openpanel-dev | openpanel | CWE-79 | OpenPanel Unauthenticated XSS via SVG Favicon Proxy |
| CVE-2026-85616 | 8.4 | — | grokability | snipe-it | CWE-639 | Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance |
| CVE-2026-85651 | 8.4 | — | triggerdotdev | trigger.dev | CWE-862 | Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay |
| CVE-2026-52769 | 8.3 | — | YesWiki | yeswiki | CWE-918 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signatu… |
| CVE-2026-52771 | 8.3 | — | YesWiki | yeswiki | CWE-89 | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag… |
| CVE-2026-57164 | 8.3 | — | pjsip | pjproject | CWE-122 | PJSIP: Heap overflow in the HTTP client |
| CVE-2026-86098 | 8.3 | — | ntop | nDPI | CWE-787 | ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape |
| CVE-2026-52767 | 8.2 | — | YesWiki | yeswiki | CWE-347 | YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!open… |
| CVE-2026-53761 | 8.2 | — | frappe | crm | CWE-287 | Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api |
| CVE-2026-77822 | 8.2 | — | IBM | ContextForge MCP Gateway | CWE-918 | IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS … |
| CVE-2026-82728 | 8.2 | — | elixir-mint | mint | CWE-770 | Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes mem… |
| CVE-2026-85596 | 8.2 | — | traefik | traefik | CWE-287 | Traefik v3.7 Authentication Bypass via TLS Option Conflict |
| CVE-2026-85597 | 8.2 | — | traefik | traefik | CWE-863 | Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict |
| CVE-2026-85730 | 8.2 | — | squirrelchat | smol-toml | CWE-606 | smol-toml: Denial of Service via malformed TOML documents |
| CVE-2026-18175 | 8.1 | — | IBM | i | CWE-285 | IBM i is Affected By Improper Authorization and Authentication Vulnerabilitie… |
| CVE-2026-18221 | 8.1 | — | IBM | i | CWE-287 | IBM i is Affected By Improper Authorization and Authentication Vulnerabilitie… |
| CVE-2026-19303 | 8.1 | — | IBM | Langflow OSS | CWE-22 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion du… |
| CVE-2026-61699 | 8.1 | — | forgekeep | nebula-mesh | CWE-299 | nebula-mesh: Certificate revocation is never enforced at the mesh |
| CVE-2026-53932 | 8.0 | — | stefanzweifel | laravel-backup-restore | CWE-77 | wnx/laravel-backup-restore: Improper Neutralization of Special Elements used … |
| CVE-2026-85649 | 7.9 | — | chewkeanho | software-actualizer | CWE-252 | (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open… |
| CVE-2026-18905 | 7.7 | — | IBM | ContextForge MCP Gateway (`mcp-contextforge-gateway`) | CWE-918 | IBM ContextForge MCP Gateway is affected by server-side request forgery via D… |
| CVE-2026-19283 | 7.7 | — | IBM | Observability with Instana (Agent) | CWE-863 | IBM Instana Observability is affected by multiple vulnerabilities within Inst… |
| CVE-2026-19304 | 7.7 | — | IBM | Langflow OSS | CWE-918 | Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas… |
| CVE-2026-19306 | 7.7 | — | IBM | Langflow OSS | CWE-22 | Langflow is vulnerable to arbitrary local file read due to path traversal in … |
| CVE-2026-63464 | 7.7 | — | forgekeep | nebula-mesh | CWE-862 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via… |
| CVE-2026-81832 | 7.7 | — | IBM | App Connect Enterprise | CWE-611 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-85619 | 7.7 | — | AppFlowy-IO | AppFlowy-Cloud | CWE-863 | AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API |
| CVE-2021-44320 | 7.5 | — | n/a | n/a | CWE-400 | Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to preve… |
| CVE-2026-12483 | 7.5 | — | StellarWP | LearnDash LMS | CWE-434 | LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload vi… |
| CVE-2026-19080 | 7.5 | — | Menulux Software Inc. | Menulux Portal | CWE-204 | Username Enumeration in Menulux Software's Menulux Portal |
| CVE-2026-19205 | 7.5 | — | GastroMenum | GastroMenum Web Panel | CWE-204 | User Enumeration in GastroMenum's GastroMenum Web Panel |
| CVE-2026-19300 | 7.5 | — | IBM | Langflow OSS | CWE-200 | Langflow is vulnerable to information disclosure due to cross-user MCP tool c… |
| CVE-2026-19534 | 7.5 | — | undici | undici | CWE-248 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| CVE-2026-52770 | 7.5 | — | YesWiki | yeswiki | CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje… |
| CVE-2026-61686 | 7.5 | — | SolidInvoice | SolidInvoice | CWE-502 | SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid … |
| CVE-2026-84428 | 7.5 | — | fastify | fastify | CWE-178 | fastify vulnerable to header validation bypass via incomplete schema case nor… |
| CVE-2026-18489 | 7.4 | — | IBM | ContextForge MCP Gateway - Translate utility | CWE-488 | IBM ContextForge Translate is affected by cross-client credential context con… |
| CVE-2026-84961 | 7.4 | — | undici | undici | CWE-295 | undici vulnerable to TLS certificate validation bypass via dropped connect op… |
| CVE-2026-85152 | 7.4 | — | undici | undici | CWE-346 | undici vulnerable to cross-origin cache poisoning via missing origin isolatio… |
| CVE-2022-35499 | 7.1 | — | n/a | n/a | CWE-79 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable t… |
| CVE-2026-19051 | 7.1 | — | Menulux Software Inc. | Menulux Portal | CWE-256 | Plaintext Storage of User Credentials in Menulux Software's Menulux Portal |
| CVE-2026-52762 | 7.1 | — | YesWiki | yeswiki | CWE-1336 | YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code … |
| CVE-2026-53603 | 7.1 | — | forgekeep | nebula-mesh | CWE-312 | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-53604 | 7.1 | — | forgekeep | nebula-mesh | CWE-212 | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
| CVE-2026-74237 | 7.1 | — | GFI Software | GFI Exinda AI | CWE-88 | GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client |
| CVE-2026-77847 | 7.1 | — | Tycon Systems | TPDIN-Monitor-WEB3 | CWE-798 | Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials |
| CVE-2026-85578 | 7.1 | — | siyuan-note | siyuan | CWE-862 | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85580 | 7.1 | — | siyuan-note | siyuan | CWE-22 | SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
| CVE-2026-85582 | 7.1 | — | siyuan-note | siyuan | CWE-770 | SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
| CVE-2026-85583 | 7.1 | — | siyuan-note | siyuan | CWE-59 | SiYuan before v3.8.2 Path Traversal via symlink in file API |
| CVE-2026-85590 | 7.1 | — | thorsten | phpMyFAQ | CWE-308 | phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable |
| CVE-2026-85591 | 7.1 | — | thorsten | phpMyFAQ | CWE-620 | phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change |
| CVE-2026-85603 | 7.1 | — | getgrav | grav | CWE-73 | Grav Admin Plugin Path Traversal via Save As Language Code |
| CVE-2026-85618 | 7.1 | — | C4illin | ConvertX | CWE-22 | ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives |
| CVE-2026-85624 | 7.1 | — | blinkospace | blinko | CWE-639 | Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList |
| CVE-2026-85654 | 7.1 | — | Amazon | awslabs.dynamodb-mcp-server | CWE-1336 | Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server |
| CVE-2026-85665 | 7.1 | — | usebruno | bruno | CWE-22 | Bruno 3.4.2 Arbitrary File Read via Unconfined Body File Path |
| CVE-2026-85669 | 7.1 | — | potpie-ai | potpie | CWE-862 | potpie through 2.0.0 Missing Ownership Check via code-changes sync |
| CVE-2026-85670 | 7.1 | — | huggingface | tokenizers | CWE-787 | tokenizers BpeBuilder Buffer Overflow via merge token |
| CVE-2026-85689 | 7.1 | — | llmware-ai | llmware | CWE-89 | llmware 0.4.6 SQL Injection via unescaped filter values |
| CVE-2026-85692 | 7.1 | — | ccfos | nightingale | CWE-918 | Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding |
| CVE-2026-85693 | 7.1 | — | mckaywrigley | chatbot-ui | CWE-639 | Chatbot UI Cross-User Private File Content Disclosure via Retrieval API |
| CVE-2026-85697 | 7.1 | — | documenso | documenso | CWE-863 | Documenso 2.17.0 PDF Route Ignores Document Visibility |
| CVE-2026-85700 | 7.1 | — | onyx-dot-app | onyx | CWE-522 | Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints |
| CVE-2026-85787 | 7.1 | — | Amazon | postgres-mcp-server | CWE-184 | An incomplete list of disallowed inputs in the SQL validation component of Am… |
| CVE-2026-86090 | 7.1 | — | ntop | ntopng | CWE-862 | ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint a… |
| CVE-2026-86091 | 7.1 | — | ntop | ntopng | CWE-862 | ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete H… |
| CVE-2026-86097 | 7.1 | — | PX4 | PX4-Autopilot | CWE-476 | PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select |
| CVE-2026-74236 | 7.0 | — | GFI Software | GFI Exinda AI | CWE-22 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion… |
| CVE-2026-85594 | 7.0 | — | traefik | traefik | CWE-639 | Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware |
| CVE-2026-53602 | 6.9 | — | forgekeep | nebula-mesh | CWE-285 | nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can re… |
| CVE-2026-53757 | 6.9 | — | emlog | emlog | CWE-22 | Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE |
| CVE-2026-57160 | 6.9 | — | pjsip | pjproject | CWE-193 | PJSIP: SIP message header buffer overflow |
| CVE-2026-73848 | 6.9 | — | emlog | emlog | CWE-79 | Emlog: Stored XSS via Tag Name in Article Editor |
| CVE-2026-74235 | 6.9 | — | GFI Software | GFI Exinda AI | CWE-22 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download H… |
| CVE-2026-80113 | 6.9 | — | PassMark Software | PerformanceTest | CWE-782 | PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via… |
| CVE-2026-80115 | 6.9 | — | PassMark Software | PerformanceTest | CWE-782 | PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via Direct… |
| CVE-2026-80117 | 6.9 | — | PassMark Software | PerformanceTest | CWE-782 | PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Acce… |
| CVE-2026-85586 | 6.9 | — | thorsten | phpMyFAQ | CWE-799 | phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter |
| CVE-2026-85605 | 6.9 | — | andrii-kryvoviaz | slink | CWE-862 | Slink before 1.12.3 Missing Authorization on Image Comment Endpoints |
| CVE-2026-85609 | 6.9 | — | Openpanel-dev | openpanel | CWE-918 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint |
| CVE-2026-85621 | 6.9 | — | lobehub | lobehub | CWE-345 | LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu |
| CVE-2026-85662 | 6.9 | — | marqo-ai | marqo | CWE-918 | Marqo 2.26.0 Server-Side Request Forgery via Media URLs |
| CVE-2026-61608 | 6.8 | — | SolidInvoice | SolidInvoice | CWE-613 | SolidInvoice's user invitation tokens have no expiry, allowing indefinite una… |
| CVE-2026-85698 | 6.8 | — | tursodatabase | turso | CWE-125 | Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service |
| CVE-2026-5522 | 6.7 | — | IBM | QRadar | CWE-798 | QRadar contains hard-coded credentials |
| CVE-2026-9138 | 6.5 | — | IBM | Langflow OSS | CWE-22 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion du… |
| CVE-2026-9186 | 6.5 | — | IBM | Langflow OSS | CWE-284 | Langflow is vulnerable to stored cross-site scripting and IP spoofing due to … |
| CVE-2026-14470 | 6.5 | — | IBM | Langflow OSS | CWE-22 | Langflow OSS is affected by arbitrary file read due to path traversal vulnera… |
| CVE-2026-17057 | 6.5 | — | IBM | i | CWE-306 | IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] |
| CVE-2026-17207 | 6.5 | — | IBM | i | CWE-787 | IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] |
| CVE-2026-17273 | 6.5 | — | IBM | i | CWE-476 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-17622 | 6.5 | — | IBM | Langflow OSS | CWE-22 | Langflow OSS is affected by arbitrary file read due to path traversal vulnera… |
| CVE-2026-18887 | 6.5 | — | IBM | i | CWE-200 | IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE [] |
| CVE-2026-19299 | 6.5 | — | IBM | Langflow OSS | CWE-22 | Langflow is vulnerable to arbitrary local file read due to path traversal in … |
| CVE-2026-19302 | 6.5 | — | IBM | Langflow OSS | CWE-22 | Langflow is vulnerable to arbitrary local file read due to path traversal in … |
| CVE-2026-19645 | 6.5 | — | IBM | MQ Agent | CWE-400 | Multiple vulnerabilities in IBM MQ Agent images |
| CVE-2026-52763 | 6.5 | — | YesWiki | yeswiki | CWE-89 | YesWiki: SQL injection via the `recentchanges` action `period` argument leadi… |
| CVE-2026-53769 | 6.5 | — | avo-hq | avo | CWE-862 | Avo: Direct attachment upload endpoint lacks upload authorization and bypasse… |
| CVE-2026-61688 | 6.5 | — | SolidInvoice | SolidInvoice | CWE-639 | SolidInvoice allows cross-user access to API token request history via writab… |
| CVE-2026-75163 | 6.5 | — | n/a | n/a | CWE-200 | An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-… |
| CVE-2026-75164 | 6.5 | — | n/a | n/a | CWE-552 | An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solut… |
| CVE-2026-78658 | 6.5 | — | IBM | UCD - IBM UrbanCode Deploy | CWE-212 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an informati… |
| CVE-2026-78970 | 6.5 | — | n/a | n/a | CWE-862 | JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in… |
| CVE-2026-84933 | 6.5 | — | undici | undici | CWE-200 | undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in s… |
| CVE-2026-85769 | 6.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unc… |
| CVE-2026-18341 | 6.3 | — | IBM | i | CWE-122 | IBM i is Affected By Buffer Overflow Vulnerability [] |
| CVE-2026-57165 | 6.3 | — | pjsip | pjproject | CWE-121 | PJSIP: Pre-authentication overflow in the telnet CLI history |
| CVE-2026-57166 | 6.3 | — | pjsip | pjproject | CWE-121 | PJSIP: Pre-authentication overflow in the telnet CLI error |
| CVE-2026-75168 | 6.3 | — | n/a | n/a | CWE-284 | An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X… |
| CVE-2026-82729 | 6.3 | — | elixir-mint | mint | CWE-407 | Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS |
| CVE-2026-85592 | 6.3 | — | thorsten | phpMyFAQ | CWE-863 | phpMyFAQ before 4.1.8 Authorization Bypass via question/create |
| CVE-2026-16689 | 6.2 | — | IBM | App Connect Enterprise | CWE-532 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-19649 | 6.2 | — | IBM | App Connect Enterprise | CWE-532 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-81859 | 6.2 | — | IBM | Cloud Pak for Business Automation | CWE-327 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-8447 | 6.1 | — | IBM | Langflow OSS | CWE-79 | Langflow is vulnerable to stored cross-site scripting and IP spoofing due to … |
| CVE-2026-19727 | 6.1 | — | Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. | Library Information and Document Automation Program | CWE-79 | HTML Injection via Improper Input Sanitization in Yordam Informatics's Librar… |
| CVE-2026-52773 | 6.1 | — | YesWiki | yeswiki | CWE-80 | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/p… |
| CVE-2026-52774 | 6.1 | — | YesWiki | yeswiki | CWE-80 | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in… |
| CVE-2026-77818 | 6.1 | — | Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. | Library Information and Document Automation Program | CWE-79 | Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library A… |
| CVE-2026-85622 | 6.0 | — | AppFlowy-IO | AppFlowy-Cloud | CWE-863 | AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket |
| CVE-2026-86096 | 6.0 | — | PX4 | PX4-Autopilot | CWE-416 | PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task … |
| CVE-2026-18149 | 5.9 | — | undici | undici | CWE-772 | undici vulnerable to Denial of Service via orphaned RetryHandler response body |
| CVE-2026-61614 | 5.9 | — | SolidInvoice | SolidInvoice | CWE-598 | SolidInvoice's long-lived API tokens accepted as URL query parameters, exposi… |
| CVE-2026-84890 | 5.9 | — | undici | undici | CWE-770 | undici vulnerable to Denial of Service via unbounded decompression of compres… |
| CVE-2026-85014 | 5.9 | — | undici | undici | CWE-248 | undici vulnerable to Denial of Service via WebSocketStream unclean close |
| CVE-2026-85024 | 5.9 | — | undici | undici | CWE-248 | undici vulnerable to Denial of Service via unhandled error in WebSocket perme… |
| CVE-2026-85534 | 5.9 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-617 | Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when se… |
| CVE-2026-76925 | 5.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-367 | Flatpak: flatpak: toctou race condition allows symlink redirection |
| CVE-2026-16180 | 5.7 | — | IBM | App Connect Enterprise | CWE-776 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-17440 | 5.5 | — | IBM | App Connect Enterprise | CWE-674 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-52772 | 5.5 | — | YesWiki | yeswiki | CWE-79 | YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.labe… |
| CVE-2026-85512 | 5.5 | — | SourceCodester | Class and Exam Timetabling System | CWE-862 | SourceCodester Class and Exam Timetabling System session.php authorization |
| CVE-2026-85516 | 5.5 | — | code-projects | Vehicle Management System | CWE-74 | code-projects Vehicle Management System busprofile.php sql injection |
| CVE-2026-85517 | 5.5 | — | code-projects | Vehicle Management System | CWE-200 | code-projects Vehicle Management System SQL Database Backup File vehicle_mana… |
| CVE-2026-85522 | 5.5 | — | valkey-io | valkey | CWE-119 | valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob ou… |
| CVE-2026-85636 | 5.5 | — | jofpin | trape | CWE-287 | jofpin trape Login Endpoint stats.py missing authentication |
| CVE-2026-85637 | 5.5 | — | jofpin | trape | CWE-287 | jofpin trape Admin Endpoint sockets.py join_room missing authentication |
| CVE-2026-85638 | 5.5 | — | jofpin | trape | CWE-285 | jofpin trape user.py authorization |
| CVE-2026-85701 | 5.5 | — | ramon-victor | freegpt-webui | CWE-287 | ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.cr… |
| CVE-2026-85702 | 5.5 | — | ramon-victor | freegpt-webui | CWE-287 | ramon-victor freegpt-webui Backend Conversation API backend.py _conversation … |
| CVE-2026-85703 | 5.5 | — | ramon-victor | freegpt-webui | CWE-400 | ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation … |
| CVE-2026-16892 | 5.4 | — | IBM | i | CWE-287 | IBM i is Affected By An Improper Authentication Vulnerability in Network Auth… |
| CVE-2026-17274 | 5.4 | — | IBM | i | CWE-330 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-17621 | 5.4 | — | IBM | Langflow OSS | CWE-22 | Langflow OSS is affected by arbitrary file read due to path traversal vulnera… |
| CVE-2026-18957 | 5.4 | — | Menulux Software Inc. | Menulux Portal | CWE-79 | Stored XSS in Menulux Software's Menulux Portal |
| CVE-2026-19057 | 5.4 | — | Gastromenum | Gastromenum Ticket and QR Menu System | CWE-79 | Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System |
| CVE-2026-55513 | 5.4 | — | forgekeep | nebula-mesh | CWE-613 | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and… |
| CVE-2026-14350 | 5.3 | — | IBM | Cloud Pak for Data System | CWE-117 | Vulnerabilities exists in IBM Cloud Pak for Data System |
| CVE-2026-16660 | 5.3 | — | IBM | Db2 Mirror for i | CWE-125 | IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] |
| CVE-2026-16826 | 5.3 | — | IBM | i | CWE-78 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-17443 | 5.3 | — | IBM | App Connect Enterprise | CWE-611 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-17444 | 5.3 | — | IBM | App Connect Enterprise | CWE-611 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-17469 | 5.3 | — | IBM | i | CWE-787 | IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon… |
| CVE-2026-17470 | 5.3 | — | IBM | i | CWE-787 | IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon… |
| CVE-2026-27347 | 5.3 | — | Crocoblock | JetPopup | CWE-862 | WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability |
| CVE-2026-55512 | 5.3 | — | forgekeep | nebula-mesh | CWE-400 | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memor… |
| CVE-2026-78543 | 5.3 | — | IBM | App Connect Enterprise | CWE-835 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-84045 | 5.3 | — | Unknown | E-cab Taxi Booking Manager for Woocommerce | — | E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Ma… |
| CVE-2026-85577 | 5.3 | — | WWBN | AVideo | CWE-79 | AVideo userLogin.php Reflected XSS via error parameter |
| CVE-2026-85579 | 5.3 | — | siyuan-note | siyuan | CWE-639 | SiYuan before v3.8.2 Information Disclosure via undoState |
| CVE-2026-85587 | 5.3 | — | thorsten | phpMyFAQ | CWE-863 | phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages |
| CVE-2026-85588 | 5.3 | — | thorsten | phpMyFAQ | CWE-200 | phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export |
| CVE-2026-85589 | 5.3 | — | thorsten | phpMyFAQ | CWE-862 | phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API |
| CVE-2026-85611 | 5.3 | — | Openpanel-dev | openpanel | CWE-639 | OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures |
| CVE-2026-85615 | 5.3 | — | Openpanel-dev | openpanel | CWE-639 | Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts |
| CVE-2026-85650 | 5.3 | — | triggerdotdev | trigger.dev | CWE-918 | Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel |
| CVE-2026-85676 | 5.3 | — | dubinc | dub | CWE-601 | Dub Open Redirect via Unrestricted redir_url Parameter |
| CVE-2026-86100 | 5.3 | — | owen2345 | CamaleonCMS | CWE-918 | Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL |
| CVE-2026-53760 | 5.2 | — | Admidio | admidio | CWE-352 | Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Re… |
| CVE-2026-17442 | 5.1 | — | IBM | App Connect Enterprise | CWE-532 | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are… |
| CVE-2026-82911 | 5.1 | — | Roskus | Prospero Flow CRM | CWE-352 | CSRF in Prospero Flow CRM order confirmation allows unauthorized order state … |
| CVE-2026-85593 | 5.1 | — | thorsten | phpMyFAQ | CWE-79 | phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode |
| CVE-2026-85598 | 5.1 | — | getgrav | grav | CWE-79 | Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages |
| CVE-2026-85599 | 5.1 | — | getgrav | grav | CWE-79 | Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters |
| CVE-2026-85600 | 5.1 | — | getgrav | grav | CWE-79 | Grav Admin before 2.0.21 Stored XSS via username |
| CVE-2026-85601 | 5.1 | — | getgrav | grav | CWE-79 | Grav Admin before 2.0.20 Cross-Site Scripting via marked.js |
| CVE-2026-85781 | 5.1 | — | aws | aws-efs-csi-driver | CWE-283 | Unverified access point ownership in Amazon EFS CSI Driver |
| CVE-2026-17631 | 5.0 | — | IBM | Langflow OSS | CWE-918 | Langflow OSS is affected by server-side request forgery due to missing URL va… |
| CVE-2026-19301 | 5.0 | — | IBM | Langflow OSS | CWE-918 | Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas… |
| CVE-2026-17627 | 4.9 | — | IBM | Langflow OSS | CWE-639 | Langflow is affected by improper authorization due to missing access control … |
| CVE-2026-53756 | 4.9 | — | emlog | emlog | CWE-89 | Emlog Blind SQL Injection via Authentication Cookie |
| CVE-2026-16693 | 4.4 | — | IBM | i | CWE-327 | IBM i is Affected By Cryptographic Algorithm Weakness in DCM [] |
| CVE-2026-17499 | 4.4 | — | IBM | i | CWE-78 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-18073 | 4.4 | — | IBM | i | CWE-78 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-18567 | 4.4 | — | IBM | Db2 Mirror for i | CWE-367 | IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] |
| CVE-2026-14466 | 4.3 | — | Stormshield | Stormshield Network Security | CWE-79 | Possible XSS in the SNS web administration panel |
| CVE-2026-16941 | 4.3 | — | IBM | i | CWE-863 | IBM i is Affected By An Incorrect Authorization Vulnerability [] |
| CVE-2026-17255 | 4.3 | — | IBM | i | CWE-787 | IBM i is Affected By Denial of Service Vulnerability [] |
| CVE-2026-17259 | 4.3 | — | IBM | i | CWE-121 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-17270 | 4.3 | — | IBM | i | CWE-121 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-17483 | 4.3 | — | IBM | Db2 Mirror for i | CWE-285 | IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] |
| CVE-2026-18076 | 4.3 | — | IBM | i | CWE-401 | IBM i is Affected By Multiple Vulnerabilities in Debug Server |
| CVE-2026-18078 | 4.3 | — | IBM | i | CWE-190 | IBM i is Affected By Denial of Service Vulnerability in Save Restore [] |
| CVE-2026-19043 | 4.3 | — | Menulux Software Inc. | Menulux Portal | CWE-862 | Authorization Bypass Critical POS Management Functions in Menulux Software's … |
| CVE-2026-19081 | 4.3 | — | Gastromenum | Gastromenum Ticket and QR Menu System | CWE-862 | Missing Authorization Allows Unauthorized Access to Critical POS Functions in… |
| CVE-2026-18540 | 3.7 | — | undici | undici | CWE-444 | undici vulnerable to downstream response splitting via retry interceptor |
| CVE-2026-84947 | 3.7 | — | undici | undici | CWE-20 | undici vulnerable to response truncation via oversized chunked responses in t… |
| CVE-2026-85008 | 3.7 | — | undici | undici | CWE-345 | undici vulnerable to caching and replay of unsafe HTTP method responses |
| CVE-2026-18858 | 3.3 | — | IBM | i | CWE-267 | IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH [] |
| CVE-2026-85639 | 2.9 | — | jofpin | trape | CWE-362 | jofpin trape Telemetry Endpoint user.py race condition |
| CVE-2026-85704 | 2.9 | — | ramon-victor | freegpt-webui | CWE-362 | ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition |
| CVE-2026-85513 | 2.1 | — | StackStorm | st2 | CWE-266 | StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management |
| CVE-2026-85514 | 2.1 | — | StackStorm | st2 | CWE-266 | StackStorm st2 API Key auth.py privileges management |
| CVE-2026-85643 | 2.0 | — | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System adduser.php mysqli_query sql injection |
| CVE-2021-44319 | await | — | n/a | n/a | — | Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Par… |
| CVE-2022-26961 | await | — | n/a | n/a | — | Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NA… |
| CVE-2022-35497 | await | — | n/a | n/a | — | In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session iden… |
| CVE-2025-67066 | await | — | n/a | n/a | — | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attack… |
| CVE-2026-13297 | await | — | IBM | Verify Identity Access | CWE-1336 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-38961 | await | — | n/a | n/a | — | Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense… |
| CVE-2026-50894 | await | — | n/a | n/a | — | easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerou… |
| CVE-2026-52691 | await | — | Apache Software Foundation | Apache Griffin Hive Metastore Module | CWE-89 | Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Met… |
| CVE-2026-71620 | await | — | n/a | n/a | — | File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote att… |
| CVE-2026-71622 | await | — | n/a | n/a | — | SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote a… |
| CVE-2026-71624 | await | — | n/a | n/a | — | An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary c… |
| CVE-2026-71625 | await | — | n/a | n/a | — | An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate… |
| CVE-2026-71626 | await | — | n/a | n/a | — | An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensiti… |
| CVE-2026-75161 | await | — | n/a | n/a | — | An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-… |
| CVE-2026-75162 | await | — | n/a | n/a | — | An information disclosure vulnerability in the opcua-configuration method of … |
| CVE-2026-75165 | await | — | n/a | n/a | — | An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_… |
| CVE-2026-75166 | await | — | n/a | n/a | — | Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V… |
| CVE-2026-75167 | await | — | n/a | n/a | — | A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/… |
| CVE-2026-75169 | await | — | n/a | n/a | — | An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solut… |
| CVE-2026-75170 | await | — | n/a | n/a | — | Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endp… |
| CVE-2026-75171 | await | — | n/a | n/a | — | An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges … |
| CVE-2026-75429 | await | — | n/a | n/a | — | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code ex… |
| CVE-2026-75438 | await | — | n/a | n/a | — | Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to c… |
| CVE-2026-75439 | await | — | n/a | n/a | — | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of ser… |
| CVE-2026-78745 | await | — | n/a | n/a | — | An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a rem… |
| CVE-2026-78839 | await | — | n/a | n/a | — | An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attack… |
| CVE-2026-78849 | await | — | n/a | n/a | — | Cross Site Scripting vulnerability in Netgate pfSense Plus software versions … |
| CVE-2026-79389 | await | — | n/a | n/a | — | Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command … |
Results continue: ranks 401–563.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-04 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.