boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 4, 2026 · all times UTC← 2026-09-03 · archive

Security Box Score — September 4, 2026

CISA adds 1 to KEV; 563 CVEs published, led by Linux (156).

563 CVEs published September 4, 2026: 44 critical, 143 high, 162 medium, 18 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 196 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 163 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published170836451——
KEV catalog size1695

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2335 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux1884149420201569411230.17.8.0016+183 ▲
google382202280856978887870.37.5.0026+36 ▲
microsoft91908148129045515287281.57.8.0044-7 ▼
red hat336594027331135200.06.6.0028+14 ▲
apple0316598516578882.56.5.00290
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse937521101000.07.5.0036+9 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco11952445260561313.77.5.0042+11 ▲
ubiquiti059362210335.19.1.00490
palo alto networks0371321121325.44.7.00200
netgear03200275000.04.3.00250
fortinet0307814128620.07.0.00500
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0033+5 ▲
vmware019410327210.58.3.00400
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache8514103217176133320.47.5.0049+2 ▲
mozilla342218079620900.08.1.0029+33 ▲
drupal2694119668411.15.7.0023+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+3 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.31200
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm706891503012289610.17.5.0030+70 ▲
adobe26085030224791930.57.8.0021-5 ▼
progress2631439100611.68.1.0036+2 ▲
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp1113620000.08.8.0144+1 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link348151698300.08.5.0160+3 ▲
rockwell automation184353260000.08.6.0029+18 ▲
siemens13822583000.07.3.0016+1 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric4131840000.08.2.0032+4 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1919013103695210.57.3.0021+16 ▲
sourcecodester1170009377000.05.5.0029+1 ▲
spring017012598415000.06.5.00240
nvidia3016420115290000.07.8.0028+14 ▲
elastic42129127983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250
itsourcecode6122003587000.02.1.0026+6 ▲
siyuan-note111144433361000.08.6.0027+3 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-8037.995799.99.8
CVE-2026-60004.867899.79.8
CVE-2026-72898.823299.610.0
CVE-2026-73570.323898.28.9
CVE-2026-64638.312098.18.9
CVE-2026-71362.251497.89.1
CVE-2026-64849.164196.89.3
CVE-2026-48376.139296.35.4
CVE-2026-15733.135496.29.8
CVE-2026-65400.099095.29.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.8232KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
CVE-2026-7755410.0.0099
Most disclosures (vendor)
VendorCVEs
linux1811
oracle890
microsoft470
google438
ibm428
red hat227
apache137
splunk110
adobe96
mozilla93
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
google7
fortinet6
ivanti5
berriai4
oracle4
solarwinds4
sonicwall4
Most-affected ecosystems
EcosystemAdvisories
Maven45
Packagist32
npm14
PyPI11
Go1
RubyGems1
Fastest to KEV
CVEVendorDays
CVE-2026-20349Cisco0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-8037Progress Software0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-64849mlflow1
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171752
CVE-2021-27102n/a2021-11-171752
CVE-2021-27101n/a2021-11-171752
CVE-2021-27103n/a2021-11-171752
CVE-2021-21017Adobe2021-11-171752
CVE-2021-28550Adobe2021-11-171752
CVE-2021-42013Apache Software Foundation2021-11-171752
CVE-2021-41773Apache Software Foundation2021-11-171752
CVE-2021-30858Apple2021-11-171752
CVE-2021-30860Apple2021-11-171752

Transactions

ADDED TO KEV — CVE-2026-85046 (Google Chrome). Remediation due September 18, 2026.

EXPLOIT PUBLISHED — patriksimek vm2: 7 CVEs (CVE-2026-43997, CVE-2026-43998, CVE-2026-43999, CVE-2026-44005, CVE-2026-44007, CVE-2026-44009, CVE-2026-45411). Public exploit references added.

EXPLOIT PUBLISHED — axios: 6 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42043). Public exploit references added.

EXPLOIT PUBLISHED — FlowiseAI Flowise: 5 CVEs (CVE-2026-67620, CVE-2026-71962, CVE-2026-73602, CVE-2026-73603, CVE-2026-73604). Public exploit references added.

EXPLOIT PUBLISHED — handlebars-lang handlebars.js: 5 CVEs (CVE-2026-33937, CVE-2026-33938, CVE-2026-33939, CVE-2026-33940, CVE-2026-33941). Public exploit references added.

EXPLOIT PUBLISHED — itsourcecode Online Medicine Delivery System: 4 CVEs (CVE-2026-85186, CVE-2026-85187, CVE-2026-85207, CVE-2026-85208). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-32141 (WebReflection flatted). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33228 (WebReflection flatted). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33891 (digitalbazaar forge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33896 (digitalbazaar forge). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39956 (jqlang jq). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41035 (Samba rsync). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43820 (Apple swift-nio-ssl). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-52022. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56718 (AJCloud AJY IPC Firmware). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82526 (SciPhi-AI R2R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82527 (SciPhi-AI R2R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84841 (tsi-coop tsi-dpdp-cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84886 (simular-ai Agent-S). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85030 (HKUDS AI-Trader). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85137 (SeaCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85222 (D-Link DNS-340L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85223 (D-Link DNS-340L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85224 (D-Link DNS-320 ShareCenter). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85225 (code-projects Doctor Appointment System). Public exploit reference added.

DUE DATE PASSED — CVE-2026-72530 (TrueConf Server). CISA remediation deadline was September 3, 2026; still in catalog.

REJECTED — CVE-2026-61485 (Apache Software Foundation Apache Lucy). Record withdrawn by the CNA.

RESCORED — Spring Cloud Stream: 4 CVEs (CVE-2026-59303, CVE-2026-59304, CVE-2026-59305, CVE-2026-59306). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2025-67038 (Lantronix EDS5000 series). CVSS 9.8 → 9.3 (NVD).

RESCORED — CVE-2026-12261 (nltk/nltk). CVSS 5.3 → 6.5 (NVD).

RESCORED — CVE-2026-13732 (Red Hat Enterprise Linux 10). CVSS 7.8 → 7 (NVD).

RESCORED — CVE-2026-18165 (@fastify/oauth2). CVSS 4.2 → 5.4 (NVD).

RESCORED — CVE-2026-18824 (IBM AIX). CVSS 8.4 → 8.8 (NVD).

RESCORED — CVE-2026-47834 (Spring Data JPA). CVSS 4.8 → 6.5 (NVD).

RESCORED — CVE-2026-47836 (Spring Cloud Config). CVSS 7.2 → 8.1 (NVD).

RESCORED — CVE-2026-47837 (Spring Cloud Config). CVSS 6.8 → 9.8 (NVD).

RESCORED — CVE-2026-47844 (Spring Reactor Netty). CVSS 5.3 → 3.7 (NVD).

RESCORED — CVE-2026-47859 (Spring Integration). CVSS 5.4 → 6.5 (NVD).

RESCORED — CVE-2026-59301 (Spring Cloud Function). CVSS 3.1 → 4.9 (NVD).

RESCORED — CVE-2026-63509 (Microsoft Fabric). CVSS 9.9 → 8.8 (NVD).

RESCORED — CVE-2026-69419 (Microsoft Azure Data Manager for Energy). CVSS 8.5 → 8.8 (NVD).

RESCORED — CVE-2026-70105 (Microsoft 365 Apps for Enterprise). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-72670 (Elastic Kibana). CVSS 7.7 → 6.5 (NVD).

RESCORED — CVE-2026-72676 (Elastic Fleet Server). CVSS 6.5 → 9.1 (NVD).

PATCH SHIPPED — CVE-2025-67038 (Lantronix EDS5000 series). Fixed in EDS5000 series 2.2.0.0R1.

PATCH SHIPPED — CVE-2026-55985 (Tycon Systems TPDIN-Monitor-WEB2). Fixed in TPDIN-Monitor-WEB2 2.4.5.

PATCH SHIPPED — CVE-2026-61884 (Tycon Systems TPDIN-Monitor-WEB2). Fixed in TPDIN-Monitor-WEB2 2.4.5.

ENRICHED — Linux: 33 CVEs (CVE-2026-64307, CVE-2026-64308, CVE-2026-64309, CVE-2026-64310, CVE-2026-64321, CVE-2026-64325, CVE-2026-64326, CVE-2026-64327, CVE-2026-64328, CVE-2026-64329, CVE-2026-64330, CVE-2026-64356, CVE-2026-64357, CVE-2026-64358, CVE-2026-64359, CVE-2026-64360, CVE-2026-64362, CVE-2026-64363, CVE-2026-64365, CVE-2026-64404, CVE-2026-64405, CVE-2026-64407, CVE-2026-64409, CVE-2026-64415, CVE-2026-64416, CVE-2026-64417, CVE-2026-64419, CVE-2026-64421, CVE-2026-64424, CVE-2026-64425, CVE-2026-64426, CVE-2026-64427, CVE-2026-64428). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

563 CVEs published. 25 box scores and 375 table rows below; the remaining 163 continue on page 2 — every CVE is listed, nothing truncated.

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0122   66.6     —
AFFECTED
  Product            Versions     Fixed
  XING CPTrans-ME-X  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Sep 4   Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Unknown AI Website Builder (GitHub build) — AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0083   55.0     —
AFFECTED
  Product                            Versions  Fixed
  AI Website Builder (GitHub build)  1.0.0 –   —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 4   Published (CNA: WPScan)
CWE-862 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0054   43.6     —
AFFECTED
  Product          Versions  Fixed
  @fastify/middie  9.1.0 –   9.3.4
TIMELINE
  Sep 3   Reserved by CNA
  Sep 4   Published (CNA: openjs)
CWE-436 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
Interinfo|DreamMaker - SQL Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0054   43.6     —
AFFECTED
  Product     Versions  Fixed
  DreamMaker  all –     —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: twcert)
CWE-89 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0053   42.8     —
AFFECTED
  Product  Versions  Fixed
  fastify  4.0.0 –   5.12.2
TIMELINE
  Aug 19  Reserved by CNA
  Sep 4   Published (CNA: openjs)
CWE-288 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
fastify vulnerable to request validation bypass via skipped boolean false schemas
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  N    7.5   .0052   42.2     —
AFFECTED
  Product  Versions     Fixed
  fastify  unspecified  5.12.2
TIMELINE
  Sep 1   Reserved by CNA
  Sep 4   Published (CNA: openjs)
CWE-20 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   38.0     —
AFFECTED
  Product           Versions     Fixed
  Divi Ajax Filter  unspecified  —
TIMELINE
  Jun 8   Reserved by CNA
  Sep 4   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0039   32.0     —
AFFECTED
  Product   Versions     Fixed
  FreeIPMI  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
FreeIPMI FreeIPMI — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0039   32.0     —
AFFECTED
  Product   Versions     Fixed
  FreeIPMI  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
FreeIPMI FreeIPMI — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0039   32.0     —
AFFECTED
  Product   Versions     Fixed
  FreeIPMI  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
FreeIPMI FreeIPMI — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0039   32.0     —
AFFECTED
  Product   Versions     Fixed
  FreeIPMI  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c wh…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0039   32.0     —
AFFECTED
  Product   Versions     Fixed
  FreeIPMI  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: mitre)
CWE-121 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
fastify vulnerable to request body replacement via an async validation result collision
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0039   31.8     —
AFFECTED
  Product  Versions     Fixed
  fastify  unspecified  5.12.2
TIMELINE
  Sep 1   Reserved by CNA
  Sep 4   Published (CNA: openjs)
CWE-20 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
Softing smartLink HW-PN — Memory leak in scan method
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   N    6.3   .0038   31.1     —
AFFECTED
  Product          Versions  Fixed
  smartLink HW-PN  1.04 –    1.10
TIMELINE
  Jun 24  Reserved by CNA
  Sep 4   Published (CNA: Softing)
CWE-401 · CNA: Softing · CVSS v4.0 · 2 references · NVD status: Received
Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0035   27.9     —
AFFECTED
  Product                  Versions     Fixed
  SmartIT Desktop Manager  unspecified  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 4   Published (CNA: twcert)
CWE-798 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0035   27.9     —
AFFECTED
  Product                  Versions     Fixed
  SmartIT Desktop Manager  unspecified  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 4   Published (CNA: twcert)
CWE-798 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
misp misp — Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISP
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   N   L   L    6.2   .0034   27.1     —
AFFECTED
  Product  Versions     Fixed
  misp     unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: CIRCL)
CWE-352 · CNA: CIRCL · CVSS v4.0 · 1 reference · NVD status: Received
FreeIPMI FreeIPMI — ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_lon…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0034   26.7     —
AFFECTED
  Product   Versions     Fixed
  FreeIPMI  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: mitre)
CWE-125 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
Eleveo Quality Management Questionnaire Service QuestionnaireService.runDataExportNow path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0034   26.7     —
AFFECTED
  Product             Versions  Fixed
  Quality Management  9.7.0 –   —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 4   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
light0011 cms Chapter Controller ChapterController.class.php authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0033   26.2     —
AFFECTED
  Product  Versions                                    Fixed
  cms      c774dce31c6df0055568a8d5c53d964d99be199d –  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 4   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   L    8.3   .0030   22.3     —
AFFECTED
  Product  Versions     Fixed
  misp     unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 4   Published (CNA: CIRCL)
CWE-863 · CNA: CIRCL · CVSS v4.0 · 1 reference · NVD status: Received
Mauro Cassani ACPT (Premium) — ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0030   22.2     —
AFFECTED
  Product         Versions     Fixed
  ACPT (Premium)  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Sep 4   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credentia…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0029   21.3     —
AFFECTED
  Product            Versions     Fixed
  XING CPTrans-ME-X  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Sep 4   Published (CNA: jpcert)
CWE-1393 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credent…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0029   21.3     —
AFFECTED
  Product            Versions     Fixed
  XING CPTrans-ME-X  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Sep 4   Published (CNA: jpcert)
CWE-259 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
light0011 cms UEditor controller.php catchimage server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.0     —
AFFECTED
  Product  Versions                                    Fixed
  cms      c774dce31c6df0055568a8d5c53d964d99be199d –  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 4   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-853822.119.3light0011cmsCWE-79light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode c…
CVE-2026-816666.519.0Red HatRed Hat Enterprise Linux 10CWE-190Corosync: corosync: integer overflow in check_memb_commit_token_sanity may by…
CVE-2026-854072.119.0EleveoQuality ManagementCWE-404Eleveo Quality Management Conversation events denial of service
CVE-2026-854025.518.7code-projectsDoctor Appointment SystemCWE-74code-projects Doctor Appointment System booking.php sql injection
CVE-2026-853795.517.9light0011cmsCWE-74light0011 cms Query Builder ChapterController.class.php searchChapter sql inj…
CVE-2026-853975.517.9code-projectsHospital Information SystemCWE-74code-projects Hospital Information System addReq.php findBySearch sql injection
CVE-2026-853985.517.9code-projectsHospital Information SystemCWE-74code-projects Hospital Information System viewReq.php viewReq sql injection
CVE-2026-853995.517.9code-projectsHospital Information SystemCWE-74code-projects Hospital Information System PrespController.php getSinglePresp …
CVE-2026-854035.517.9code-projectsDoctor Appointment SystemCWE-74code-projects Doctor Appointment System contactus.php sql injection
CVE-2026-855414.818.0InterinfoDreamMakerCWE-79Interinfo|DreamMaker - Reflected Cross-site Scripting
CVE-2026-668408.717.6Xing Inc.XING CPTrans-ME-XCWE-497XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an …
CVE-2026-854012.116.2n/aDolibarrCWE-266Dolibarr Legacy File Manager config.inc.php access control
CVE-2026-851496.916.2LightstarSmartIT Desktop ManagerCWE-798Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
CVE-2026-577777.614.3AutomatticWooCommerceCWE-89WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability
CVE-2026-850948.814.1CanvaCanvaCWE-212The Canva Android App before 2.376.0 did not restrict the headers returned to…
CVE-2026-854082.114.1EleveoQuality ManagementCWE-913Eleveo Quality Management Conversation events dynamically-determined object a…
CVE-2026-270866.513.0XtemosWoodMartCWE-79WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-850859.612.5CanvaCanvaCWE-940The Canva Android App before 2.376.0 allowed an external origin to be loaded …
CVE-2026-855337.612.3mispmispCWE-862MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter
CVE-2026-7575410.011.8ASUSControl Center Enterprise (ACC)CWE-306Missing Authentication for Critical Function, Server-Side Request Forgery (SS…
CVE-2026-816657.511.4Red HatRed Hat Enterprise Linux 10CWE-122Corosync: corosync: heap-based buffer overflow in totempg assembly buffer dur…
CVE-2026-801806.110.8Apache Software FoundationApache AlluraCWE-79Apache Allura: Stored XSS via markdown HTML processing
CVE-2026-80181await10.6Apache Software FoundationApache AlluraCWE-918Apache Allura: Server-side request forgery
CVE-2026-851478.710.0LightstarSmartIT Desktop ManagerCWE-284Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
CVE-2026-812707.59.8Apache Software FoundationApache AlluraCWE-200Apache Allura: Information exposure via search
CVE-2026-853832.19.9itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System inv_del.php sql injection
CVE-2026-855468.69.7mispmispCWE-352MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests
CVE-2026-854052.08.8EleveoCall Recording SoftwareCWE-79Eleveo Call Recording Software roleAddAction.do cross site scripting
CVE-2026-854062.08.8EleveoQuality ManagementCWE-79Eleveo Quality Management Conversation Review cross site scripting
CVE-2026-801906.18.6Apache Software FoundationApache AlluraCWE-79Apache Allura: Stored XSS via code repositories
CVE-2026-274325.48.2sc Internet VivooWP RentalsCWE-639WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR…
CVE-2026-851977.68.0Red HatRed Hat Enterprise Linux 10CWE-416Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read()…
CVE-2026-855285.37.8SnowflakeSnowflake JDBC DriverCWE-20Snowflake JDBC Driver auto-configuration account validation permits credentia…
CVE-2026-324805.37.2WC LoversWCFM MembershipCWE-862WordPress WCFM Membership plugin <= 2.11.11 - Broken Access Control vulnerabi…
CVE-2026-853115.37.2Kings PluginsMarketKingCWE-862WordPress MarketKing plugin <= 2.1.60 - Broken Access Control vulnerability
CVE-2026-192247.26.5UnknownHummingbird PerformanceCWE-94Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite
CVE-2026-840435.35.7UnknownePayco Payment Gateway for WooCommerceCWE-345ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Conf…
CVE-2026-840445.35.7UnknownRestaurant Menu and Food Ordering—Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass v…
CVE-2026-821864.15.7UnknownWPLP Cookie ConsentCWE-89WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter
CVE-2026-85229await5.5Apache Software FoundationApache SkyWalkingCWE-79Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incompl…
CVE-2026-821935.55.2UnknownWPvivid — Backup, Migration & StagingCWE-22WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup D…
CVE-2026-813028.54.8JAL Information Technology Co., Ltd.PALLET CONTROLCWE-276PALLET CONTROL products contain an incorrect default permission vulnerability…
CVE-2026-813475.94.1UnknownFrontend Admin by DynamiAppsCWE-73Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.…
CVE-2026-175175.34.1UnknownContent ViewsCWE-200Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure …
CVE-2026-796315.34.1UnknownWPFunnelsCWE-200WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-…
CVE-2026-159375.33.7Checkmk GmbHCheckmkCWE-295Agent receiver certificate confusion allows authentication with a certificate…
CVE-2026-748536.83.6UnknownPodsCWE-552Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback
CVE-2026-821945.53.6UnknownWPvivid — Backup, Migration & StagingCWE-73WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Pat…
CVE-2026-841465.33.6UnknownXpro Addons — 140+ Widgets for ElementorCWE-200Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclos…
CVE-2026-45200await3.6Imagination TechnologiesGraphics DDKCWE-416GPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by…
CVE-2025-156915.33.4UnknownWPFunnelsCWE-863WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms
CVE-2026-796305.33.4UnknownWPFunnelsCWE-639WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Produc…
CVE-2026-796325.33.4UnknownWPFunnelsCWE-862WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wp…
CVE-2026-162817.13.1UnknownClassified ListingCWE-639Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Li…
CVE-2026-804385.93.1UnknownNinja FormsCWE-284Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and S…
CVE-2026-840663.13.1UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-862Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_atta…
CVE-2026-45197await1.5Imagination TechnologiesGraphics DDKCWE-367GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet
CVE-2026-62176.31.4Pik Online Software Solutions Inc.Pik Online PortalCWE-759Information Disclosure in Pik Online Software's Portal
CVE-2026-71216await1.4Apache Software FoundationApache SkyWalkingCWE-319Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key…
CVE-2026-855257.41.2SnowflakeSnowflake Connector for PythonCWE-295Improper OCSP response validation in Snowflake drivers
CVE-2026-186589.8—IBMOperational Decision ManagerCWE-89IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
CVE-2026-310209.8—n/an/aCWE-94In DocsGPT 0.15.0 and below, the application provides a custom prompt feature…
CVE-2026-754309.8—n/an/aCWE-306PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /work…
CVE-2026-192749.6—IBMObservability with Instana (Agent)CWE-284IBM Instana Observability is affected by multiple vulnerabilities within Inst…
CVE-2026-527779.4—YesWikiyeswikiCWE-352YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
CVE-2026-759259.4—IXONIXON VPN ClientCWE-93IXON VPN Client CRLF Injection
CVE-2026-444029.3—Voltronic PowerSNMP Web ProCWE-434Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
CVE-2026-855959.3—traefiktraefikCWE-287Traefik before v2.11.55 Authentication Bypass via digestAuth
CVE-2026-856029.3—getgravgravCWE-807Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
CVE-2026-856619.3—haris-musaexcel-mcp-serverCWE-22excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
CVE-2026-856639.3—aimhubioaimCWE-306Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch
CVE-2026-856679.3—TeamWiseFlowxiaobeiCWE-306xiaobei through 5.5.2 Unauthenticated Webhook Message Injection
CVE-2026-856729.3—getomni-aizeroxCWE-78zerox 1.1.20 OS Command Injection via Document URL File Extension
CVE-2026-856889.3—TEN-frameworkten-frameworkCWE-306TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer
CVE-2026-856959.3—lm-sysFastChatCWE-306FastChat Unauthenticated Worker Registration SSRF and Model Spoofing
CVE-2026-856969.3—OpenTalkerSadTalkerCWE-78SadTalker OS Command Injection via Audio Filename
CVE-2026-93179.2—NangoHQnangoCWE-306Nango < 0.71.6 Missing Authentication RCE via runner tRPC server
CVE-2026-856149.2—Openpanel-devopenpanelCWE-918OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker
CVE-2026-856209.2—crystaldbapostgres-mcpCWE-863Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function
CVE-2026-856259.2—crcnsift.jsCWE-1321sift 17.1.3 Prototype Pollution Remote Code Execution via $where
CVE-2026-856609.2—MladenSUcli-mcp-serverCWE-78cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution
CVE-2026-856949.2—lavague-aiLaVagueCWE-94LaVague 0.2.35 Remote Code Execution via eval extraction
CVE-2026-527669.1—YesWikiyeswikiCWE-276YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}…
CVE-2026-751609.1—n/an/aCWE-269An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to esc…
CVE-2026-754319.1—n/an/aCWE-321PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT sig…
CVE-2026-783279.1—SonicWallNetwork Security Manager (NSM)CWE-78An Improper Neutralization of Special Elements used in an OS Command ('OS Com…
CVE-2026-783289.1—SonicWallNetwork Security Manager (NSM)CWE-862A missing authorization vulnerability in the SonicWall Network Security Manag…
CVE-2026-819399.1—SonicWallNetwork Security Manager (NSM)CWE-22A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-P…
CVE-2026-480198.9—laravelframeworkCWE-93CRLF injection in Laravel's default email rule enables SMTP smuggling and spo…
CVE-2026-181988.8—TAC Information Services Internal and External Trade Inc.GOLDENHORN ONEITCWE-89SQL Injection in TAC Information's GoldenHorn
CVE-2026-184868.8—IBMContextForge MCP GatewayCWE-200IBM ContextForge MCP Gateway is affected by credential disclosure and privile…
CVE-2026-192988.8—IBMLangflow OSSCWE-94Langflow is vulnerable to remote code execution due to authorization policy b…
CVE-2026-527758.8—YesWikiyeswikiCWE-89YesWiki Authenticated SQL Injection in ReactionManager
CVE-2026-571618.8—pjsippjprojectCWE-121PJSIP: Stack overflow handling Service-Route headers in a registration response
CVE-2026-571628.8—pjsippjprojectCWE-121PJSIP: Stack overflow parsing SDP a=crypto attributes
CVE-2026-571638.8—pjsippjprojectCWE-121PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuT…
CVE-2026-856848.8—datalab-tomarkerCWE-73marker through 2.0.0 Path Traversal via upload filename
CVE-2026-466368.7—twigphpTwigCWE-1336Twig: Sandbox method allowlist bypass via `Markup` subclass
CVE-2026-537588.7—emlogemlogCWE-79Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized
CVE-2026-773938.7—Inductive AutomationIgnitionCWE-276Inductive Automation Ignition Incorrect Default Permissions
CVE-2026-797078.7—Google CloudAgent Development Kit (ADK)CWE-22Arbitrary File Read in Google Agent Development Kit (ADK)
CVE-2026-825388.7—ILIAS-eLearning e.V.ILIASCWE-89ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter
CVE-2026-855818.7—siyuan-notesiyuanCWE-770SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registr…
CVE-2026-855848.7—siyuan-notesiyuanCWE-770SiYuan before v3.8.2 Denial of Service via Auth Throttle
CVE-2026-855858.7—siyuan-notesiyuanCWE-400SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency
CVE-2026-856048.7—getgravgravCWE-94Grav before 2.0.19 Remote Code Execution via sort filter
CVE-2026-856068.7—firecrawlfirecrawl-mcp-serverCWE-22firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath
CVE-2026-856078.7—blinkospaceblinkoCWE-639Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router
CVE-2026-856088.7—Evil0ctalDouyin_TikTok_Download_APICWE-918Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter
CVE-2026-856108.7—Openpanel-devopenpanelCWE-94OpenPanel before 2.3.0 Remote Code Execution via chart formulas
CVE-2026-856128.7—Openpanel-devopenpanelCWE-918OpenPanel before 2.3.0 SSRF via favicon and og endpoints
CVE-2026-856178.7—grokabilitysnipe-itCWE-639snipe-it before 8.6.3 Authorization Bypass via Bulk Delete
CVE-2026-856238.7—aaif-goosegooseCWE-94goose 1.37.0 Arbitrary Command Execution via Recipe Extensions
CVE-2026-856268.7—cyanheadsgit-mcp-serverCWE-88git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters
CVE-2026-856648.7—chroma-corechromaCWE-770Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion
CVE-2026-856668.7—ogx-aiogxCWE-918ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url
CVE-2026-856688.7—xorbitsaiinferenceCWE-73Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/…
CVE-2026-856718.7—netease-youdaoQAnythingCWE-306QAnything 2.0.0 Unauthenticated Cross-User File Disclosure
CVE-2026-856738.7—hiyougaLlamaFactoryCWE-918LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding
CVE-2026-856758.7—camel-aiowlCWE-918OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching
CVE-2026-856858.7—agentscope-aiagentscopeCWE-22AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill
CVE-2026-856868.7—modelscopems-swiftCWE-918ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs
CVE-2026-856878.7—datalab-tosuryaCWE-73surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server
CVE-2026-856918.7—The-Vibe-CompanymegaparseCWE-918MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url
CVE-2026-856998.7—jina-aireaderCWE-918jina-ai reader server-side request forgery via redirect validation bypass
CVE-2026-857868.7—Amazonion-javaCWE-409Incomplete fix for CVE-2026-75936 memory-amplification denial of service in A…
CVE-2026-193058.6—IBMLangflow OSSCWE-918Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas…
CVE-2026-505538.6—enchant97note-markCWE-20Note Mark: Path traversal via unsanitized book/note slug in migrate export (s…
CVE-2026-826848.6—Tycon SystemsTPDIN-Monitor-WEB3CWE-862Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization
CVE-2026-827128.6—Tycon SystemsTPDIN-Monitor-WEB3CWE-352Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery
CVE-2026-46448.5—Google CloudIntegration ConnectorsCWE-863Improper Authorization in Google Cloud Integration Connectors Leads to Projec…
CVE-2026-69588.5—Invicti Security Corp.AcunetixCWE-427Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe
CVE-2026-801128.5—PassMark SoftwarePerformanceTestCWE-732PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control…
CVE-2026-801148.5—PassMark SoftwarePerformanceTestCWE-321PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials …
CVE-2026-801168.5—PassMark SoftwarePerformanceTestCWE-782PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation vi…
CVE-2026-801198.5—PassMark SoftwarePerformanceTestCWE-73PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclos…
CVE-2026-856568.5—Amazonlog4j-cve-2021-44228-hotpatchCWE-78OS command injection in Amazon log4j-cve-2021-44228-hotpatch
CVE-2026-856748.5—Aider-AIaiderCWE-94aider 0.86.2 Remote Code Execution via .aider.conf.yml
CVE-2026-856908.5—plandex-aiplandexCWE-22Plandex 2.2.1 Path Traversal via ApplyFiles
CVE-2026-860958.5—Unidatanetcdf-cCWE-787Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attrib…
CVE-2026-571598.4—pjsippjprojectCWE-129PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance
CVE-2026-801188.4—PassMark SoftwarePerformanceTestCWE-73PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Der…
CVE-2026-856138.4—Openpanel-devopenpanelCWE-79OpenPanel Unauthenticated XSS via SVG Favicon Proxy
CVE-2026-856168.4—grokabilitysnipe-itCWE-639Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance
CVE-2026-856518.4—triggerdotdevtrigger.devCWE-862Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay
CVE-2026-527698.3—YesWikiyeswikiCWE-918YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signatu…
CVE-2026-527718.3—YesWikiyeswikiCWE-89YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag…
CVE-2026-571648.3—pjsippjprojectCWE-122PJSIP: Heap overflow in the HTTP client
CVE-2026-860988.3—ntopnDPICWE-787ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape
CVE-2026-527678.2—YesWikiyeswikiCWE-347YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!open…
CVE-2026-537618.2—frappecrmCWE-287Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api
CVE-2026-778228.2—IBMContextForge MCP GatewayCWE-918IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS …
CVE-2026-827288.2—elixir-mintmintCWE-770Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes mem…
CVE-2026-855968.2—traefiktraefikCWE-287Traefik v3.7 Authentication Bypass via TLS Option Conflict
CVE-2026-855978.2—traefiktraefikCWE-863Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict
CVE-2026-857308.2—squirrelchatsmol-tomlCWE-606smol-toml: Denial of Service via malformed TOML documents
CVE-2026-181758.1—IBMiCWE-285IBM i is Affected By Improper Authorization and Authentication Vulnerabilitie…
CVE-2026-182218.1—IBMiCWE-287IBM i is Affected By Improper Authorization and Authentication Vulnerabilitie…
CVE-2026-193038.1—IBMLangflow OSSCWE-22Langflow is vulnerable to arbitrary file write and arbitrary file deletion du…
CVE-2026-616998.1—forgekeepnebula-meshCWE-299nebula-mesh: Certificate revocation is never enforced at the mesh
CVE-2026-539328.0—stefanzweifellaravel-backup-restoreCWE-77wnx/laravel-backup-restore: Improper Neutralization of Special Elements used …
CVE-2026-856497.9—chewkeanhosoftware-actualizerCWE-252(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open…
CVE-2026-189057.7—IBMContextForge MCP Gateway (`mcp-contextforge-gateway`)CWE-918IBM ContextForge MCP Gateway is affected by server-side request forgery via D…
CVE-2026-192837.7—IBMObservability with Instana (Agent)CWE-863IBM Instana Observability is affected by multiple vulnerabilities within Inst…
CVE-2026-193047.7—IBMLangflow OSSCWE-918Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas…
CVE-2026-193067.7—IBMLangflow OSSCWE-22Langflow is vulnerable to arbitrary local file read due to path traversal in …
CVE-2026-634647.7—forgekeepnebula-meshCWE-862Nebula-mesh allows non-admin operators to disable webhook SSRF protection via…
CVE-2026-818327.7—IBMApp Connect EnterpriseCWE-611IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-856197.7—AppFlowy-IOAppFlowy-CloudCWE-863AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API
CVE-2021-443207.5—n/an/aCWE-400Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to preve…
CVE-2026-124837.5—StellarWPLearnDash LMSCWE-434LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload vi…
CVE-2026-190807.5—Menulux Software Inc.Menulux PortalCWE-204Username Enumeration in Menulux Software's Menulux Portal
CVE-2026-192057.5—GastroMenumGastroMenum Web PanelCWE-204User Enumeration in GastroMenum's GastroMenum Web Panel
CVE-2026-193007.5—IBMLangflow OSSCWE-200Langflow is vulnerable to information disclosure due to cross-user MCP tool c…
CVE-2026-195347.5—undiciundiciCWE-248undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
CVE-2026-527707.5—YesWikiyeswikiCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje…
CVE-2026-616867.5—SolidInvoiceSolidInvoiceCWE-502SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid …
CVE-2026-844287.5—fastifyfastifyCWE-178fastify vulnerable to header validation bypass via incomplete schema case nor…
CVE-2026-184897.4—IBMContextForge MCP Gateway - Translate utilityCWE-488IBM ContextForge Translate is affected by cross-client credential context con…
CVE-2026-849617.4—undiciundiciCWE-295undici vulnerable to TLS certificate validation bypass via dropped connect op…
CVE-2026-851527.4—undiciundiciCWE-346undici vulnerable to cross-origin cache poisoning via missing origin isolatio…
CVE-2022-354997.1—n/an/aCWE-79In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable t…
CVE-2026-190517.1—Menulux Software Inc.Menulux PortalCWE-256Plaintext Storage of User Credentials in Menulux Software's Menulux Portal
CVE-2026-527627.1—YesWikiyeswikiCWE-1336YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code …
CVE-2026-536037.1—forgekeepnebula-meshCWE-312nebula-mesh: Operator session tokens stored in plaintext in the database
CVE-2026-536047.1—forgekeepnebula-meshCWE-212nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
CVE-2026-742377.1—GFI SoftwareGFI Exinda AICWE-88GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client
CVE-2026-778477.1—Tycon SystemsTPDIN-Monitor-WEB3CWE-798Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials
CVE-2026-855787.1—siyuan-notesiyuanCWE-862SiYuan through 3.8.1 Authorization Bypass via getFile
CVE-2026-855807.1—siyuan-notesiyuanCWE-22SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch
CVE-2026-855827.1—siyuan-notesiyuanCWE-770SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth
CVE-2026-855837.1—siyuan-notesiyuanCWE-59SiYuan before v3.8.2 Path Traversal via symlink in file API
CVE-2026-855907.1—thorstenphpMyFAQCWE-308phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
CVE-2026-855917.1—thorstenphpMyFAQCWE-620phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
CVE-2026-856037.1—getgravgravCWE-73Grav Admin Plugin Path Traversal via Save As Language Code
CVE-2026-856187.1—C4illinConvertXCWE-22ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives
CVE-2026-856247.1—blinkospaceblinkoCWE-639Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList
CVE-2026-856547.1—Amazonawslabs.dynamodb-mcp-serverCWE-1336Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
CVE-2026-856657.1—usebrunobrunoCWE-22Bruno 3.4.2 Arbitrary File Read via Unconfined Body File Path
CVE-2026-856697.1—potpie-aipotpieCWE-862potpie through 2.0.0 Missing Ownership Check via code-changes sync
CVE-2026-856707.1—huggingfacetokenizersCWE-787tokenizers BpeBuilder Buffer Overflow via merge token
CVE-2026-856897.1—llmware-aillmwareCWE-89llmware 0.4.6 SQL Injection via unescaped filter values
CVE-2026-856927.1—ccfosnightingaleCWE-918Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding
CVE-2026-856937.1—mckaywrigleychatbot-uiCWE-639Chatbot UI Cross-User Private File Content Disclosure via Retrieval API
CVE-2026-856977.1—documensodocumensoCWE-863Documenso 2.17.0 PDF Route Ignores Document Visibility
CVE-2026-857007.1—onyx-dot-apponyxCWE-522Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints
CVE-2026-857877.1—Amazonpostgres-mcp-serverCWE-184An incomplete list of disallowed inputs in the SQL validation component of Am…
CVE-2026-860907.1—ntopntopngCWE-862ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint a…
CVE-2026-860917.1—ntopntopngCWE-862ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete H…
CVE-2026-860977.1—PX4PX4-AutopilotCWE-476PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select
CVE-2026-742367.0—GFI SoftwareGFI Exinda AICWE-22GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion…
CVE-2026-855947.0—traefiktraefikCWE-639Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware
CVE-2026-536026.9—forgekeepnebula-meshCWE-285nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can re…
CVE-2026-537576.9—emlogemlogCWE-22Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE
CVE-2026-571606.9—pjsippjprojectCWE-193PJSIP: SIP message header buffer overflow
CVE-2026-738486.9—emlogemlogCWE-79Emlog: Stored XSS via Tag Name in Article Editor
CVE-2026-742356.9—GFI SoftwareGFI Exinda AICWE-22GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download H…
CVE-2026-801136.9—PassMark SoftwarePerformanceTestCWE-782PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via…
CVE-2026-801156.9—PassMark SoftwarePerformanceTestCWE-782PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via Direct…
CVE-2026-801176.9—PassMark SoftwarePerformanceTestCWE-782PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Acce…
CVE-2026-855866.9—thorstenphpMyFAQCWE-799phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
CVE-2026-856056.9—andrii-kryvoviazslinkCWE-862Slink before 1.12.3 Missing Authorization on Image Comment Endpoints
CVE-2026-856096.9—Openpanel-devopenpanelCWE-918Openpanel before 2.3.0 SSRF via Site Checker Endpoint
CVE-2026-856216.9—lobehublobehubCWE-345LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
CVE-2026-856626.9—marqo-aimarqoCWE-918Marqo 2.26.0 Server-Side Request Forgery via Media URLs
CVE-2026-616086.8—SolidInvoiceSolidInvoiceCWE-613SolidInvoice's user invitation tokens have no expiry, allowing indefinite una…
CVE-2026-856986.8—tursodatabasetursoCWE-125Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service
CVE-2026-55226.7—IBMQRadarCWE-798QRadar contains hard-coded credentials
CVE-2026-91386.5—IBMLangflow OSSCWE-22Langflow is vulnerable to arbitrary file write and arbitrary file deletion du…
CVE-2026-91866.5—IBMLangflow OSSCWE-284Langflow is vulnerable to stored cross-site scripting and IP spoofing due to …
CVE-2026-144706.5—IBMLangflow OSSCWE-22Langflow OSS is affected by arbitrary file read due to path traversal vulnera…
CVE-2026-170576.5—IBMiCWE-306IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]
CVE-2026-172076.5—IBMiCWE-787IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ]
CVE-2026-172736.5—IBMiCWE-476IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-176226.5—IBMLangflow OSSCWE-22Langflow OSS is affected by arbitrary file read due to path traversal vulnera…
CVE-2026-188876.5—IBMiCWE-200IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []
CVE-2026-192996.5—IBMLangflow OSSCWE-22Langflow is vulnerable to arbitrary local file read due to path traversal in …
CVE-2026-193026.5—IBMLangflow OSSCWE-22Langflow is vulnerable to arbitrary local file read due to path traversal in …
CVE-2026-196456.5—IBMMQ AgentCWE-400Multiple vulnerabilities in IBM MQ Agent images
CVE-2026-527636.5—YesWikiyeswikiCWE-89YesWiki: SQL injection via the `recentchanges` action `period` argument leadi…
CVE-2026-537696.5—avo-hqavoCWE-862Avo: Direct attachment upload endpoint lacks upload authorization and bypasse…
CVE-2026-616886.5—SolidInvoiceSolidInvoiceCWE-639SolidInvoice allows cross-user access to API token request history via writab…
CVE-2026-751636.5—n/an/aCWE-200An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-…
CVE-2026-751646.5—n/an/aCWE-552An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solut…
CVE-2026-786586.5—IBMUCD - IBM UrbanCode DeployCWE-212IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an informati…
CVE-2026-789706.5—n/an/aCWE-862JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in…
CVE-2026-849336.5—undiciundiciCWE-200undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in s…
CVE-2026-857696.5—Red HatRed Hat Enterprise Linux 10CWE-125Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unc…
CVE-2026-183416.3—IBMiCWE-122IBM i is Affected By Buffer Overflow Vulnerability []
CVE-2026-571656.3—pjsippjprojectCWE-121PJSIP: Pre-authentication overflow in the telnet CLI history
CVE-2026-571666.3—pjsippjprojectCWE-121PJSIP: Pre-authentication overflow in the telnet CLI error
CVE-2026-751686.3—n/an/aCWE-284An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X…
CVE-2026-827296.3—elixir-mintmintCWE-407Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS
CVE-2026-855926.3—thorstenphpMyFAQCWE-863phpMyFAQ before 4.1.8 Authorization Bypass via question/create
CVE-2026-166896.2—IBMApp Connect EnterpriseCWE-532IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-196496.2—IBMApp Connect EnterpriseCWE-532IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-818596.2—IBMCloud Pak for Business AutomationCWE-327Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine…
CVE-2026-84476.1—IBMLangflow OSSCWE-79Langflow is vulnerable to stored cross-site scripting and IP spoofing due to …
CVE-2026-197276.1—Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.Library Information and Document Automation ProgramCWE-79HTML Injection via Improper Input Sanitization in Yordam Informatics's Librar…
CVE-2026-527736.1—YesWikiyeswikiCWE-80Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/p…
CVE-2026-527746.1—YesWikiyeswikiCWE-80Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in…
CVE-2026-778186.1—Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.Library Information and Document Automation ProgramCWE-79Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library A…
CVE-2026-856226.0—AppFlowy-IOAppFlowy-CloudCWE-863AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket
CVE-2026-860966.0—PX4PX4-AutopilotCWE-416PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task …
CVE-2026-181495.9—undiciundiciCWE-772undici vulnerable to Denial of Service via orphaned RetryHandler response body
CVE-2026-616145.9—SolidInvoiceSolidInvoiceCWE-598SolidInvoice's long-lived API tokens accepted as URL query parameters, exposi…
CVE-2026-848905.9—undiciundiciCWE-770undici vulnerable to Denial of Service via unbounded decompression of compres…
CVE-2026-850145.9—undiciundiciCWE-248undici vulnerable to Denial of Service via WebSocketStream unclean close
CVE-2026-850245.9—undiciundiciCWE-248undici vulnerable to Denial of Service via unhandled error in WebSocket perme…
CVE-2026-855345.9—Red HatRed Hat Enterprise Linux 10CWE-617Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when se…
CVE-2026-769255.8—Red HatRed Hat Enterprise Linux 10CWE-367Flatpak: flatpak: toctou race condition allows symlink redirection
CVE-2026-161805.7—IBMApp Connect EnterpriseCWE-776IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-174405.5—IBMApp Connect EnterpriseCWE-674IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-527725.5—YesWikiyeswikiCWE-79YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.labe…
CVE-2026-855125.5—SourceCodesterClass and Exam Timetabling SystemCWE-862SourceCodester Class and Exam Timetabling System session.php authorization
CVE-2026-855165.5—code-projectsVehicle Management SystemCWE-74code-projects Vehicle Management System busprofile.php sql injection
CVE-2026-855175.5—code-projectsVehicle Management SystemCWE-200code-projects Vehicle Management System SQL Database Backup File vehicle_mana…
CVE-2026-855225.5—valkey-iovalkeyCWE-119valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob ou…
CVE-2026-856365.5—jofpintrapeCWE-287jofpin trape Login Endpoint stats.py missing authentication
CVE-2026-856375.5—jofpintrapeCWE-287jofpin trape Admin Endpoint sockets.py join_room missing authentication
CVE-2026-856385.5—jofpintrapeCWE-285jofpin trape user.py authorization
CVE-2026-857015.5—ramon-victorfreegpt-webuiCWE-287ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.cr…
CVE-2026-857025.5—ramon-victorfreegpt-webuiCWE-287ramon-victor freegpt-webui Backend Conversation API backend.py _conversation …
CVE-2026-857035.5—ramon-victorfreegpt-webuiCWE-400ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation …
CVE-2026-168925.4—IBMiCWE-287IBM i is Affected By An Improper Authentication Vulnerability in Network Auth…
CVE-2026-172745.4—IBMiCWE-330IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-176215.4—IBMLangflow OSSCWE-22Langflow OSS is affected by arbitrary file read due to path traversal vulnera…
CVE-2026-189575.4—Menulux Software Inc.Menulux PortalCWE-79Stored XSS in Menulux Software's Menulux Portal
CVE-2026-190575.4—GastromenumGastromenum Ticket and QR Menu SystemCWE-79Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System
CVE-2026-555135.4—forgekeepnebula-meshCWE-613nebula-mesh: Web UI host creation ignores configured enrollment token TTL and…
CVE-2026-143505.3—IBMCloud Pak for Data SystemCWE-117Vulnerabilities exists in IBM Cloud Pak for Data System
CVE-2026-166605.3—IBMDb2 Mirror for iCWE-125IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
CVE-2026-168265.3—IBMiCWE-78IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-174435.3—IBMApp Connect EnterpriseCWE-611IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-174445.3—IBMApp Connect EnterpriseCWE-611IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-174695.3—IBMiCWE-787IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon…
CVE-2026-174705.3—IBMiCWE-787IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon…
CVE-2026-273475.3—CrocoblockJetPopupCWE-862WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability
CVE-2026-555125.3—forgekeepnebula-meshCWE-400nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memor…
CVE-2026-785435.3—IBMApp Connect EnterpriseCWE-835IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-840455.3—UnknownE-cab Taxi Booking Manager for Woocommerce—E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Ma…
CVE-2026-855775.3—WWBNAVideoCWE-79AVideo userLogin.php Reflected XSS via error parameter
CVE-2026-855795.3—siyuan-notesiyuanCWE-639SiYuan before v3.8.2 Information Disclosure via undoState
CVE-2026-855875.3—thorstenphpMyFAQCWE-863phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages
CVE-2026-855885.3—thorstenphpMyFAQCWE-200phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export
CVE-2026-855895.3—thorstenphpMyFAQCWE-862phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API
CVE-2026-856115.3—Openpanel-devopenpanelCWE-639OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures
CVE-2026-856155.3—Openpanel-devopenpanelCWE-639Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts
CVE-2026-856505.3—triggerdotdevtrigger.devCWE-918Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel
CVE-2026-856765.3—dubincdubCWE-601Dub Open Redirect via Unrestricted redir_url Parameter
CVE-2026-861005.3—owen2345CamaleonCMSCWE-918Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL
CVE-2026-537605.2—AdmidioadmidioCWE-352Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Re…
CVE-2026-174425.1—IBMApp Connect EnterpriseCWE-532IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are…
CVE-2026-829115.1—RoskusProspero Flow CRMCWE-352CSRF in Prospero Flow CRM order confirmation allows unauthorized order state …
CVE-2026-855935.1—thorstenphpMyFAQCWE-79phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode
CVE-2026-855985.1—getgravgravCWE-79Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages
CVE-2026-855995.1—getgravgravCWE-79Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters
CVE-2026-856005.1—getgravgravCWE-79Grav Admin before 2.0.21 Stored XSS via username
CVE-2026-856015.1—getgravgravCWE-79Grav Admin before 2.0.20 Cross-Site Scripting via marked.js
CVE-2026-857815.1—awsaws-efs-csi-driverCWE-283Unverified access point ownership in Amazon EFS CSI Driver
CVE-2026-176315.0—IBMLangflow OSSCWE-918Langflow OSS is affected by server-side request forgery due to missing URL va…
CVE-2026-193015.0—IBMLangflow OSSCWE-918Langflow is vulnerable to Server-Side Request Forgery due to missing or bypas…
CVE-2026-176274.9—IBMLangflow OSSCWE-639Langflow is affected by improper authorization due to missing access control …
CVE-2026-537564.9—emlogemlogCWE-89Emlog Blind SQL Injection via Authentication Cookie
CVE-2026-166934.4—IBMiCWE-327IBM i is Affected By Cryptographic Algorithm Weakness in DCM []
CVE-2026-174994.4—IBMiCWE-78IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-180734.4—IBMiCWE-78IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-185674.4—IBMDb2 Mirror for iCWE-367IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
CVE-2026-144664.3—StormshieldStormshield Network SecurityCWE-79Possible XSS in the SNS web administration panel
CVE-2026-169414.3—IBMiCWE-863IBM i is Affected By An Incorrect Authorization Vulnerability []
CVE-2026-172554.3—IBMiCWE-787IBM i is Affected By Denial of Service Vulnerability []
CVE-2026-172594.3—IBMiCWE-121IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-172704.3—IBMiCWE-121IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-174834.3—IBMDb2 Mirror for iCWE-285IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
CVE-2026-180764.3—IBMiCWE-401IBM i is Affected By Multiple Vulnerabilities in Debug Server
CVE-2026-180784.3—IBMiCWE-190IBM i is Affected By Denial of Service Vulnerability in Save Restore []
CVE-2026-190434.3—Menulux Software Inc.Menulux PortalCWE-862Authorization Bypass Critical POS Management Functions in Menulux Software's …
CVE-2026-190814.3—GastromenumGastromenum Ticket and QR Menu SystemCWE-862Missing Authorization Allows Unauthorized Access to Critical POS Functions in…
CVE-2026-185403.7—undiciundiciCWE-444undici vulnerable to downstream response splitting via retry interceptor
CVE-2026-849473.7—undiciundiciCWE-20undici vulnerable to response truncation via oversized chunked responses in t…
CVE-2026-850083.7—undiciundiciCWE-345undici vulnerable to caching and replay of unsafe HTTP method responses
CVE-2026-188583.3—IBMiCWE-267IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
CVE-2026-856392.9—jofpintrapeCWE-362jofpin trape Telemetry Endpoint user.py race condition
CVE-2026-857042.9—ramon-victorfreegpt-webuiCWE-362ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition
CVE-2026-855132.1—StackStormst2CWE-266StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management
CVE-2026-855142.1—StackStormst2CWE-266StackStorm st2 API Key auth.py privileges management
CVE-2026-856432.0—code-projectsOnline Shopping SystemCWE-74code-projects Online Shopping System adduser.php mysqli_query sql injection
CVE-2021-44319await—n/an/a—Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Par…
CVE-2022-26961await—n/an/a—Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NA…
CVE-2022-35497await—n/an/a—In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session iden…
CVE-2025-67066await—n/an/a—SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attack…
CVE-2026-13297await—IBMVerify Identity AccessCWE-1336Security vulnerabilities have been addressed in IBM Verify Identity Access an…
CVE-2026-38961await—n/an/a—Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense…
CVE-2026-50894await—n/an/a—easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerou…
CVE-2026-52691await—Apache Software FoundationApache Griffin Hive Metastore ModuleCWE-89Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Met…
CVE-2026-71620await—n/an/a—File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote att…
CVE-2026-71622await—n/an/a—SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote a…
CVE-2026-71624await—n/an/a—An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary c…
CVE-2026-71625await—n/an/a—An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate…
CVE-2026-71626await—n/an/a—An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensiti…
CVE-2026-75161await—n/an/a—An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-…
CVE-2026-75162await—n/an/a—An information disclosure vulnerability in the opcua-configuration method of …
CVE-2026-75165await—n/an/a—An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_…
CVE-2026-75166await—n/an/a—Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V…
CVE-2026-75167await—n/an/a—A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/…
CVE-2026-75169await—n/an/a—An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solut…
CVE-2026-75170await—n/an/a—Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endp…
CVE-2026-75171await—n/an/a—An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges …
CVE-2026-75429await—n/an/a—PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code ex…
CVE-2026-75438await—n/an/a—Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to c…
CVE-2026-75439await—n/an/a—An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of ser…
CVE-2026-78745await—n/an/a—An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a rem…
CVE-2026-78839await—n/an/a—An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attack…
CVE-2026-78849await—n/an/a—Cross Site Scripting vulnerability in Netgate pfSense Plus software versions …
CVE-2026-79389await—n/an/a—Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command …

Results continue: ranks 401–563.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-04 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.