boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, September 7, 2026 · all times UTC← 2026-09-06 · archive

Security Box Score — September 7, 2026

252 CVEs published, led by Dell (36).

252 CVEs published September 7, 2026: 13 critical, 74 high, 119 medium, 42 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 4 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 227 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published218337055——
KEV catalog size1695

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2392 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux1884270420201569511230.17.8.0016+144 ▲
google382202280856978887870.37.5.0026-5 ▼
microsoft91908148129045515287281.57.8.0044-24 ▼
red hat436694227931335200.06.7.0028+2 ▲
apple0316598516578882.56.5.0029-1 ▼
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse937521101000.07.5.0036+4 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco11952445260561313.77.5.0042-19 ▼
ubiquiti059362210335.19.1.00490
palo alto networks0371321121325.44.7.00200
netgear03200275000.04.3.00250
fortinet0307814128620.07.0.00500
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050+3 ▲
vmware019410327210.58.3.00400
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache9515103217176133320.47.5.0049-51 ▼
mozilla342218079620900.08.1.0029+33 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+1 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm706891503012289610.17.5.0029+38 ▲
adobe36095130224791930.57.8.0021-5 ▼
progress2631439100611.68.1.0035-9 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0144+5 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link6511617108300.08.5.0160+6 ▲
rockwell automation184353260000.08.6.0029+18 ▲
siemens13822583000.07.3.0016+1 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric4131840000.08.2.0032+4 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell5522615119875210.47.2.0021+47 ▲
sourcecodester261950011481000.05.5.0028+15 ▲
spring017012598415000.06.5.00240
nvidia3016420115290000.07.8.0028+14 ▲
itsourcecode221380036102000.02.1.0026+16 ▲
elastic42129127983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250
siyuan-note131164434371000.08.6.0027+5 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-72898.942299.810.0
CVE-2026-60004.867899.79.8
CVE-2026-73570.323898.28.9
CVE-2026-71362.251497.89.1
CVE-2026-64849.164196.89.3
CVE-2026-48376.154896.65.4
CVE-2026-19681.078094.39.4
CVE-2026-82329.076794.29.8
CVE-2026-71386.069493.78.8
CVE-2026-68820.061893.07.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.9422KEV
CVE-2026-4836210.0.0431
CVE-2026-1918810.0.0193
CVE-2026-8615210.0.0186
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
Most disclosures (vendor)
VendorCVEs
linux1787
oracle890
microsoft453
ibm428
google397
red hat229
dell119
apache117
splunk110
adobe96
Most KEV additions (YTD)
VendorKEV
microsoft28
cisco13
apple8
google7
fortinet6
ivanti5
berriai4
oracle4
solarwinds4
sonicwall4
Most-affected ecosystems
EcosystemAdvisories
Maven33
Packagist32
npm13
PyPI11
Go1
RubyGems1
Fastest to KEV
CVEVendorDays
CVE-2026-20349Cisco0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-64849mlflow1
CVE-2026-81578PaperCut3
CVE-2026-82078PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171755
CVE-2021-27102n/a2021-11-171755
CVE-2021-27101n/a2021-11-171755
CVE-2021-27103n/a2021-11-171755
CVE-2021-21017Adobe2021-11-171755
CVE-2021-28550Adobe2021-11-171755
CVE-2021-42013Apache Software Foundation2021-11-171755
CVE-2021-41773Apache Software Foundation2021-11-171755
CVE-2021-30858Apple2021-11-171755
CVE-2021-30860Apple2021-11-171755

Transactions

EXPLOIT PUBLISHED — axios: 16 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-42044, CVE-2026-42264, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — patriksimek vm2: 7 CVEs (CVE-2026-43997, CVE-2026-43998, CVE-2026-43999, CVE-2026-44005, CVE-2026-44007, CVE-2026-44009, CVE-2026-45411). Public exploit references added.

EXPLOIT PUBLISHED — netty: 5 CVEs (CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587). Public exploit references added.

EXPLOIT PUBLISHED — Mikrotik RouterOS: 3 CVEs (CVE-2026-67276, CVE-2026-67278, CVE-2026-67281). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-69534. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-23745 (isaacs node-tar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24842 (isaacs node-tar). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42880 (argoproj argo-cd). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4740 (Red Hat multicluster engine for Kubernetes 2.1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.

RESCORED — itsourcecode Sales and Inventory System: 3 CVEs (CVE-2026-86233, CVE-2026-86234, CVE-2026-86235). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-2670 (Advantech WISE-6610-NB). CVSS 8.6 → 7.3 (NVD).

PATCH SHIPPED — CVE-2026-16118 (xdgmime). Fixed in Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.22.

PATCH SHIPPED — CVE-2026-63622 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:10.10.0-8.11.el10_0.

PATCH SHIPPED — CVE-2026-78701 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.2.0-10.el10_2.

ENRICHED — Linux: 5 CVEs (CVE-2025-21817, CVE-2025-22127, CVE-2025-38205, CVE-2025-38621, CVE-2026-43344). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

252 CVEs published. 25 box scores, 227 table rows — nothing truncated.

Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0335   87.9     —
AFFECTED
  Product          Versions          Fixed
  WISE-6610-NB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-TB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-JB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-CB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-NB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-EB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-TB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-JB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-CB  1.2.1_20251110 –  1.2.4_20260821
  + 3 more
TIMELINE
  Aug 25  Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Received
Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0170   75.7     —
AFFECTED
  Product          Versions          Fixed
  WISE-6610-NB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-TB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-JB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-CB     1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-NB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-EB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-TB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-JB  1.2.1_20251110 –  1.2.4_20260821
  WISE-6610-EL-CB  1.2.1_20251110 –  1.2.4_20260821
  + 3 more
TIMELINE
  Aug 25  Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Received
OpenVPN OpenVPN — Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0054   43.7     —
AFFECTED
  Product  Versions     Fixed
  OpenVPN  unspecified  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 7   Published (CNA: OpenVPN)
CWE-190 · CNA: OpenVPN · CVSS v4.0 · 1 reference · NVD status: Received
openagents-org openagents http.py test_default_model server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0051   41.9     —
AFFECTED
  Product     Versions  Fixed
  openagents  0.8.0 –   —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0051   41.6     —
AFFECTED
  Product   Versions  Fixed
  FeehiCMS  2.1.0 –   —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
liufee FeehiCMS Cookie Validation main-local.php hard-coded key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   N   N    2.1   .0046   38.4     —
AFFECTED
  Product   Versions  Fixed
  FeehiCMS  2.1.0 –   —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-320, CWE-321 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    5.5   .0043   36.0     —
AFFECTED
  Product     Versions                                    Fixed
  hosp_order  627f426331da8086ce8fff2017d65b1ddef384f8 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-620, CWE-640 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
projeto-siga Authentication Flow ExAutenticacaoController.java ExAutenticacaoController.autenticar authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0043   36.0     —
AFFECTED
  Product  Versions    Fixed
  siga     11.0.2.0 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-862, CWE-863 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
projectworlds Online Examination System Feedback Form feedback.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0042   35.4     —
AFFECTED
  Product                    Versions  Fixed
  Online Examination System  1.0 –     —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
sfturing hosp_order Order Controller OrderController.java authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.0     —
AFFECTED
  Product     Versions                                    Fixed
  hosp_order  627f426331da8086ce8fff2017d65b1ddef384f8 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.0     —
AFFECTED
  Product     Versions                                    Fixed
  hosp_order  627f426331da8086ce8fff2017d65b1ddef384f8 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
sfturing hosp_order Order Cancellation OrderController.java orderRecordsService.cancelOrder authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   34.0     —
AFFECTED
  Product     Versions                                    Fixed
  hosp_order  627f426331da8086ce8fff2017d65b1ddef384f8 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
n/a Ollama — Ollama GGUF Decoder gguf.go readGGUFV1String integer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   L    2.1   .0040   33.2     —
AFFECTED
  Product  Versions  Fixed
  Ollama   0.31.0 –  0.31.2-rc1
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-189, CWE-190 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
OpenVPN OpenVPN — An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   H    7.7   .0038   31.5     —
AFFECTED
  Product  Versions    Fixed
  OpenVPN  2.1_rc10 –  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 7   Published (CNA: OpenVPN)
CWE-78, CWE-88 · CNA: OpenVPN · CVSS v4.0 · 1 reference · NVD status: Received
Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0038   31.4     —
AFFECTED
  Product                    Versions             Fixed
  U+Smart Enjoyment WebSite  18.6001.1096.1000 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-284, CWE-434 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0038   31.1     —
AFFECTED
  Product   Versions  Fixed
  FeehiCMS  2.1.0 –   —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
PrestaShop PrestaShop — Incorrect access control in PrestaShop
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0035   27.9     —
AFFECTED
  Product     Versions     Fixed
  PrestaShop  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 7   Published (CNA: INCIBE)
CWE-290 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Received
NEC Corporation UNIVERGE IX-R/IX-V — An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypa…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   L    9.3   .0033   25.9     —
AFFECTED
  Product             Versions                                                                                                Fixed
  UNIVERGE IX-R/IX-V  All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23 –  —
TIMELINE
  Jul 24  Reserved by CNA
  Sep 7   Published (CNA: NEC)
CWE-306 · CNA: NEC · CVSS v4.0 · 1 reference · NVD status: Received
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   P   N   L   L    2.3   .0033   25.8     —
AFFECTED
  Product  Versions  Fixed
  OpenVPN  2.5.0 –   —
TIMELINE
  Aug 27  Reserved by CNA
  Sep 7   Published (CNA: OpenVPN)
CWE-121, CWE-193, CWE-787 · CNA: OpenVPN · CVSS v4.0 · 1 reference · NVD status: Received
jaychouchannel Tourism-Management-System CommonController.java getOption information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0032   24.8     —
AFFECTED
  Product                    Versions                                    Fixed
  Tourism-Management-System  8122bf020d91199eddfff3ee02d1632a70a9a132 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Received
SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0030   22.6     —
AFFECTED
  Product                                                    Versions  Fixed
  Syllabus-Aligned Learning Management & Examination System  1.0 –     —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
ModelCloud GPTQModel Triton dequantization kernel tritonv2.py out-of-bounds
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   L    2.1   .0029   21.5     —
AFFECTED
  Product    Versions  Fixed
  GPTQModel  7.0 –     7.3.0
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-119, CWE-125 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.1     —
AFFECTED
  Product  Versions  Fixed
  siga     11.1.0 –  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0029   21.1     —
AFFECTED
  Product                                                    Versions  Fixed
  Syllabus-Aligned Learning Management & Examination System  1.0 –     —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-259, CWE-798 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
SourceCodester Syllabus-Aligned Learning Management & Examination System auth.php register privileges management
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    5.5   .0029   20.8     —
AFFECTED
  Product                                                    Versions  Fixed
  Syllabus-Aligned Learning Management & Examination System  1.0 –     —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 7   Published (CNA: VulDB)
CWE-266, CWE-269 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-862442.119.4n/aFastAdminCWE-79FastAdmin User Controller User.php login cross site scripting
CVE-2026-862782.119.4SourceCodesterSyllabus-Aligned Learning Management & Examination SystemCWE-79SourceCodester Syllabus-Aligned Learning Management & Examination System mana…
CVE-2026-862825.519.3jaychouchannelTourism-Management-SystemCWE-74jaychouchannel Tourism-Management-System CommonDao CommonController.java sql …
CVE-2026-862685.518.8itsourcecodeSchool Management SystemCWE-74itsourcecode School Management System User_Login.php sql injection
CVE-2026-862905.518.8SourceCodesterOnline Voting SystemCWE-74SourceCodester Online Voting System ajax.php save_category sql injection
CVE-2026-863425.318.8MISPMISPCWE-862MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event an…
CVE-2026-862642.118.0sfturingssm_proCWE-79sfturing ssm_pro Order Endpoint OrderController.java cross site scripting
CVE-2026-862712.013.9n/aFluentCMSCWE-862FluentCMS PermissionManager.cs GetAccessible authorization
CVE-2026-862792.113.3SourceCodesterSyllabus-Aligned Learning Management & Examination SystemCWE-384SourceCodester Syllabus-Aligned Learning Management & Examination System Logi…
CVE-2026-862852.112.7n/aBookStackCWE-266BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm acc…
CVE-2026-862805.511.9SourceCodesterSyllabus-Aligned Learning Management & Examination SystemCWE-310SourceCodester Syllabus-Aligned Learning Management & Examination System cict…
CVE-2026-863326.511.5Red HatRed Hat OpenShift AI (RHOAI)CWE-862Odh-dashboard: odh-dashboard: nim credential secret readable by any authentic…
CVE-2026-862692.110.4itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System emp_edit1.php sql injection
CVE-2026-205035.310.2MediaTek, Inc.MediaTek chipsetCWE-617In Modem, there is a possible system crash due to a missing bounds check. Thi…
CVE-2026-205045.310.2MediaTek, Inc.MediaTek chipsetCWE-617In Modem, there is a possible system crash due to a missing bounds check. Thi…
CVE-2026-205134.49.8MediaTek, Inc.MediaTek chipsetCWE-35In Audio HAL, there is a possible information disclosure due to improper inpu…
CVE-2026-862362.19.9itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System pro_transac.php add sql injection
CVE-2026-862452.19.9itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System sup_transac.php sql injection
CVE-2026-862652.19.9itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System us_transac.php sql injection
CVE-2026-862672.19.9itsourcecodeInformation System Society Membership SystemCWE-74itsourcecode Information System Society Membership System check_student.php s…
CVE-2026-862702.19.9itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System settings_edit.php sql injection
CVE-2026-78254await8.7Apache Software FoundationApache AntCWE-23Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
CVE-2026-780435.66.7OpenVPNOpenVPNCWE-22The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows lo…
CVE-2026-862812.15.3SourceCodesterSyllabus-Aligned Learning Management & Examination SystemCWE-352SourceCodester Syllabus-Aligned Learning Management & Examination System cros…
CVE-2026-142978.75.0Nordic Semiconductor ASAnRF Connect SDKCWE-787The Continuous Glucose Monitoring Service's Record Access Control Point (RACP…
CVE-2026-205018.44.5MediaTek, Inc.MediaTek chipsetCWE-122In vdec, there is a possible out of bounds write due to a heap buffer overflo…
CVE-2026-205028.44.3MediaTek, Inc.MediaTek chipsetCWE-122In vdec, there is a possible out of bounds write due to a missing bounds chec…
CVE-2026-205155.54.3MediaTek, Inc.MediaTek chipsetCWE-416In gpu, there is a possible system crash due to use after free. This could le…
CVE-2026-842268.53.8OpenVPNOpenVPNCWE-426OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows …
CVE-2026-205005.53.7MediaTek, Inc.MediaTek chipsetCWE-295In Modem, there is a possible system crash due to improper input validation. …
CVE-2026-205165.53.7MediaTek, Inc.MediaTek chipsetCWE-926In MiracastService, there is a possible escalation of privilege due to a conf…
CVE-2026-205096.73.6MediaTek, Inc.MediaTek chipsetCWE-121In Power HAL, there is a possible out of bounds write due to a missing bounds…
CVE-2026-205106.73.6MediaTek, Inc.MediaTek chipsetCWE-415In camera middleware, there is a possible escalation of privilege due to doub…
CVE-2026-205184.43.6MediaTek, Inc.MediaTek chipsetCWE-125In geniezone, there is a possible information disclosure due to a missing bou…
CVE-2026-205066.73.1MediaTek, Inc.MediaTek chipsetCWE-416In Audio HAL, there is a possible escalation of privilege due to use after fr…
CVE-2026-205076.73.1MediaTek, Inc.MediaTek chipsetCWE-416In Audio HAL, there is a possible escalation of privilege due to use after fr…
CVE-2026-205086.73.1MediaTek, Inc.MediaTek chipsetCWE-843In Power HAL, there is a possible escalation of privilege due to type confusi…
CVE-2026-205116.73.2MediaTek, Inc.MediaTek chipsetCWE-416In SurfaceFlinger, there is a possible memory corruption due to use after fre…
CVE-2026-205176.73.1MediaTek, Inc.MediaTek chipsetCWE-416In geniezone, there is a possible escalation of privilege due to use after fr…
CVE-2026-205144.42.6MediaTek, Inc.MediaTek chipsetCWE-307In Audio HAL, there is a possible information disclosure due to a missing per…
CVE-2026-20512await2.6MediaTek, Inc.MediaTek chipsetCWE-307In Audio HAL, there is a possible escalation of privilege due to improper inp…
CVE-2026-863146.22.5Samsung OpensourceWalrusCWE-190Integer overflow in the source-bounds check in Memory::init() (src/runtime/Me…
CVE-2026-863156.22.4Samsung OpensourceEscargotCWE-197An out-of-bounds write caused by numeric truncation Samsung Open Source Escar…
CVE-2026-863137.81.8Samsung OpensourceWalrusCWE-787Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflo…
CVE-2026-782215.91.8OpenVPNOpenVPNCWE-131An incorrect buffer size calculation in the Windows Interactive Service in Op…
CVE-2026-142967.51.4Nordic Semiconductor ASAnRF54H20CWE-347nRF54H20: MCUBoot can be tricked to executing unauthenticated code
CVE-2026-818305.61.2OpenVPNOpenVPNCWE-73The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local …
CVE-2026-823121.81.0OpenVPNOpenVPNCWE-412OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows l…
CVE-2026-187966.80.1Nordic Semiconductor ASAnRF5340CWE-1342QSPI flash encryption side-channel leakage
CVE-2026-7565010.0—AdobeAdobe CommerceCWE-1336Adobe Commerce | Improper Neutralization of Special Elements Used in a Templa…
CVE-2026-78619.8—Next4Biz Information Technologies Inc.CSM (Customer Service Management)CWE-502Code Injection in Next4Biz's CSM (Customer Service Management)
CVE-2026-189229.8—Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-287389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalati…
CVE-2026-765789.8—Red HatRed Hat Enterprise Linux 10CWE-306Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator c…
CVE-2026-864789.8—JetBrainsYouTrackCWE-290In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authenticat…
CVE-2026-864809.8—JetBrainsHubCWE-306In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could regist…
CVE-2026-62239.4—Bahçelievler MuncipalityBiHayat AppCWE-307OTP Bypass in Bahçelievler Muncipality's BiHayat App
CVE-2026-614109.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-862Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-802389.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-250Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-862969.3—D-LinkDIR-822ACWE-119D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow
CVE-2026-865439.3—knowns-devknownsCWE-306knowns before 0.30.0 Unauthenticated Management API Exposure
CVE-2026-864269.2—librenmslibrenmsCWE-287LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
CVE-2026-864048.8—Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7CWE-502Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildf…
CVE-2026-864828.8—JetBrainsYouTrackCWE-266In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes …
CVE-2026-865428.8—knowns-devknownsCWE-22knowns before 0.30.0 Path Traversal via Import Name
CVE-2022-510178.7—pmmpPocketMine-MPCWE-20PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data
CVE-2026-192048.7—Eclipse FoundationEclipse JettyCWE-770A client may send a WebSocket frame with an unknown opcode and a very large d…
CVE-2026-864278.7—librenmslibrenmsCWE-77LibreNMS before 26.8.0 Argument Injection via graph_title
CVE-2026-864288.7—thephpleaguecommonmarkCWE-407commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes
CVE-2026-864298.7—thephpleaguecommonmarkCWE-407commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
CVE-2026-864308.7—thephpleaguecommonmarkCWE-407league/commonmark before 2.9.1 Denial of Service via parsing
CVE-2026-864338.7—thephpleaguecommonmarkCWE-407commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes
CVE-2026-864348.7—thephpleaguecommonmarkCWE-407commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision
CVE-2026-864358.7—thephpleaguecommonmarkCWE-407commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote
CVE-2026-864398.7—knowns-devknownsCWE-22knowns before 0.30.0 Path Traversal via MCP doc and memory tools
CVE-2026-864528.7—MISPMISPCWE-400MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and R…
CVE-2026-865388.7—knowns-devknownsCWE-22knowns before 0.30.0 Path Traversal via templateFile parameter
CVE-2026-862998.6—LinksysRE7000CWE-77Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
CVE-2026-864378.6—laradashboardlaradashboardCWE-863Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive U…
CVE-2026-864388.6—laradashboardlaradashboardCWE-862Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Insta…
CVE-2026-864928.5—JetBrainsYouTrackCWE-488In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-…
CVE-2026-865408.5—knowns-devknownsCWE-78knowns before 0.30.0 Arbitrary Code Execution via LSP Binary
CVE-2026-198438.4—Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-78389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit …
CVE-2026-865028.4—JetBrainsIntelliJ IDEACWE-306In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on …
CVE-2026-841738.3—Eclipse FoundationEclipse AnkaiosCWE-863In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Int…
CVE-2026-796458.2—DellSecure Connect Gateway 5.0 - ApplicationCWE-306Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-825868.2—ash-projectash_luaCWE-424AshLua read operation aggregate bypasses the exposed-field allow-list, exposi…
CVE-2026-827538.2—ash-projectash_authentication_oauth2_serverCWE-770Unauthenticated authorize requests create unbounded, never-expiring CIMD clie…
CVE-2026-862978.2—D-LinkDIR-605CWE-189D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one
CVE-2026-796788.1—Red HatRed Hat Enterprise Linux 10CWE-95Freeipa: idm: freeipa: idp-add eval() reachable before authorization check al…
CVE-2026-801328.1—DellSecure Connect Gateway 5.0 - ApplicationCWE-306ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicati…
CVE-2026-864798.1—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missin…
CVE-2026-801667.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-269Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-865047.8—JetBrainsIntelliJ IDEACWE-829In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation…
CVE-2026-801347.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-798Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-864947.7—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauth…
CVE-2026-864987.7—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link…
CVE-2026-796397.6—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-63777.5—Next4Biz Information Technologies Inc.CSM (Customer Service Management)CWE-22Path Traversal in Next4Biz's CSM (Customer Service Management)
CVE-2026-144447.5—Very Good PluginsWP Fusion (Pro)CWE-269WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation…
CVE-2026-183557.5—Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-191389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length…
CVE-2026-184537.5—Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-476389-ds-base: 389-ds-base: pre-authentication null pointer dereference via pag…
CVE-2026-765607.5—Red HatRed Hat Directory Server 11.7 E4S for RHEL 8CWE-863389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule ch…
CVE-2026-784807.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-306Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801357.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-703Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-796447.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801317.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-22Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801337.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-23Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801647.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-614097.3—DellSecure Connect Gateway (SCG) 5.0 ApplicationCWE-78Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.…
CVE-2026-796437.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-480Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-796917.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-64317.2—cozmoslabsUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-79User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting …
CVE-2026-801277.2—DellSecure Connect Gateway 5.0 - ApplicationCWE-78Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-865417.2—knowns-devknownsCWE-22knowns before 0.30.0 Path Traversal via code.replace MCP action
CVE-2026-865447.2—knowns-devknownsCWE-863knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions
CVE-2022-510107.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.4.2 Server Crash via Item ID
CVE-2022-510127.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization
CVE-2022-510137.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata
CVE-2022-510147.1—pmmpPocketMine-MPCWE-248PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding
CVE-2022-510157.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket
CVE-2022-510187.1—pmmpPocketMine-MPCWE-400PocketMine-MP before 3.26.5 Input Validation via Book Pages
CVE-2026-801307.1—DellSecure Connect Gateway 5.0 - ApplicationCWE-23Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-863477.1—MISPMISPCWE-400MISP Missing Authorization on Template File Upload Allows Authenticated Disk …
CVE-2026-864087.1—MISPMISPCWE-639MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys fro…
CVE-2026-864197.0—MISPMISPCWE-200MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosu…
CVE-2026-783256.9—Standard NotesStandard NotesCWE-79XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML …
CVE-2026-863036.9—92181markdownCWE-11992181 markdown md.c lds out-of-bounds
CVE-2026-863176.9—ggml-orgllama.cppCWE-617ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
CVE-2026-864316.9—thephpleaguecommonmarkCWE-79commonmark before 2.9.1 XSS via AttributesExtension form feed bypass
CVE-2026-864326.9—thephpleaguecommonmarkCWE-405commonmark 2.0.0 before 2.8.4 Denial of Service via XML
CVE-2026-865396.9—knowns-devknownsCWE-918knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint
CVE-2026-823256.8—OpenVPNovpn-dco-winCWE-415A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5…
CVE-2026-852016.8—Eclipse FoundationEclipse AnkaiosCWE-789In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the…
CVE-2026-864976.8—JetBrainsYouTrackCWE-201In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-…
CVE-2026-127576.5—icegramEmail Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-94Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortco…
CVE-2026-784886.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-78Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801266.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-667Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801296.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-22Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801706.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-798Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-864886.5—JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueLi…
CVE-2026-864896.5—JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API dis…
CVE-2026-864906.5—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed …
CVE-2026-864936.5—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed …
CVE-2026-864956.5—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed c…
CVE-2026-23906.4—codesupplycoPowerkit – Supercharge your WordPress SiteCWE-79Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting …
CVE-2026-801286.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-287Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-776976.3—ZohocorpManageEngine Endpoint CentralCWE-269Privilege Escalation
CVE-2026-827546.3—ash-projectash_authentication_oauth2_serverCWE-424ash_authentication_oauth2_server aliases every protocol endpoint under /.well…
CVE-2026-827556.3—ash-projectash_authentication_oauth2_serverCWE-524ash_authentication_oauth2_server serves tenant-specific OAuth metadata as pub…
CVE-2026-827566.3—ash-projectash_authentication_oauth2_serverCWE-116ash_authentication_oauth2_server interpolates a tenant-derived value into the…
CVE-2026-827576.3—ash-projectash_authentication_oauth2_serverCWE-918ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and sit…
CVE-2026-827586.3—ash-projectash_authentication_oauth2_serverCWE-287ash_authentication_oauth2_server treats an empty resolved secret as valid, op…
CVE-2026-856406.3—ZohocorpManageEngine Endpoint CentralCWE-269Privilege Escalation
CVE-2026-864206.3—ImageMagickImageMagickCWE-400ImageMagick before 7.1.2-30 Denial of Service Memory Budget
CVE-2026-864216.3—ImageMagickImageMagickCWE-400ImageMagick before 7.1.2-30 Memory Leak via MSL decoder
CVE-2026-797345.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801255.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-865065.9—JetBrainsGoLandCWE-306In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand pr…
CVE-2026-776985.7—ZohocorpManageEngine Endpoint CentralCWE-269Privilege Escalation
CVE-2026-796425.6—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-784875.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-321Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799755.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-800545.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-732Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-800565.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-532Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-800575.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-321Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-800585.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-312Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801675.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-321Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801785.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-269Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-862925.5—SourceCodesterSimple Traffic Offense SystemCWE-287SourceCodester Simple Traffic Offense System User Creation saveuser.php missi…
CVE-2026-862935.5—SourceCodesterSimple Traffic Offense SystemCWE-287SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.ph…
CVE-2026-862955.5—D-LinkDIR-895LCWE-74D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
CVE-2026-862985.5—SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System delete_subject.php sql injec…
CVE-2026-863005.5—TendaAC9CWE-287Tenda AC9 Web Management R7WebsSecurityHandler improper authentication
CVE-2026-863025.5—code-projectsHospital Information SystemCWE-200code-projects Hospital Information System SQL Database Backup File his.sql in…
CVE-2026-863055.5—light0011cmsCWE-284light0011 cms Upload.class.php upload unrestricted upload
CVE-2026-863065.5—light0011cmsCWE-287light0011 cms Cookie Helper UserModel.class.php improper authentication
CVE-2026-863085.5—light0011cmsCWE-200light0011 cms Debug Mode config.php information disclosure
CVE-2026-863185.5—java-json-toolsjson-patchCWE-119java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fro…
CVE-2026-863195.5—java-json-toolsjson-patchCWE-400java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply res…
CVE-2026-863215.5—java-json-toolsjackson-coreutilsCWE-918java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.f…
CVE-2026-865005.5—JetBrainsYouTrackCWE-266In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a us…
CVE-2026-128535.4—rocklobsterincFlamingoCWE-862Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Una…
CVE-2026-864835.4—JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Ag…
CVE-2022-510115.3—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.2.10 Denial of Service via Chat Messages
CVE-2022-510165.3—pmmpPocketMine-MPCWE-294PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay
CVE-2026-49455.3—themeisleOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSECWE-639Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Ver…
CVE-2026-82795.3—masteriyoMasteriyo LMS – LMS Course Builder, Quizzes & CertificatesCWE-862Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary C…
CVE-2026-864165.3—ILIAS-eLearning e.V.ILIASCWE-862ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Acti…
CVE-2026-864175.3—MISPMISPCWE-200MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Un…
CVE-2026-864365.3—laradashboardlaradashboardCWE-862Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Uploa…
CVE-2026-864515.3—MISPMISPCWE-639MISP Event Graph Object Reference Lookup Exposes References from Unauthorized…
CVE-2026-864695.3—Red HatRed Hat Enterprise Linux 10CWE-59Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path
CVE-2026-863515.1—MISPMISPCWE-20MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol…
CVE-2026-864405.1—MISPMISPCWE-20MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Bac…
CVE-2026-776995.0—ZohocorpManageEngine Endpoint CentralCWE-269Privilege Escalation
CVE-2026-799434.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-297Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-864234.8—ImageMagickImageMagickCWE-416ImageMagick before 7.1.2-30 Heap-use-after-free via GetList
CVE-2026-864254.8—ImageMagickImageMagickCWE-416ImageMagick before 7.1.2-30 Heap-use-after-free via Layer
CVE-2026-801764.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-257Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-864844.6—JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.2.18634 angularJS template injection in ass…
CVE-2026-864814.3—JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure…
CVE-2026-864964.3—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk …
CVE-2026-864994.3—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all…
CVE-2026-864863.7—JetBrainsYouTrackCWE-306In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler fai…
CVE-2025-526513.5—HCL SoftwareMyXalyticsCWE-20HCL MyXalytics is affected by multiple security vulnerabilities.
CVE-2025-526523.5—HCL SoftwareMyXalyticsCWE-451HCL MyXalytics is affected by multiple security vulnerabilities.
CVE-2025-526573.5—HCL SoftwareMyXalyticsCWE-770HCL MyXalytics is affected by multiple security vulnerabilities.
CVE-2026-864913.5—JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project…
CVE-2026-864853.3—JetBrainsYouTrackCWE-291In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowe…
CVE-2026-865033.3—JetBrainsIntelliJ IDEACWE-918In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could…
CVE-2026-865053.3—JetBrainsIntelliJ IDEACWE-201In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked…
CVE-2026-864873.1—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed…
CVE-2026-865012.8—JetBrainsIntelliJ IDEACWE-532In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be wr…
CVE-2026-825842.3—ash-projectigniterCWE-150Terminal escape sequence injection in the mix igniter.install confirmation pr…
CVE-2026-864182.3—MISPMISPCWE-200MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Un…
CVE-2026-864412.3—MISPMISPCWE-200MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions an…
CVE-2026-816382.1—ash-projectash_double_entryCWE-173Non-canonical ULID spellings are accepted and alias to the same record in ash…
CVE-2026-862912.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System us_edit1.php sql injection
CVE-2026-862942.1—SourceCodesterSimple Traffic Offense SystemCWE-79SourceCodester Simple Traffic Offense System Settings Update Endpoint save-se…
CVE-2026-863072.1—light0011cmsCWE-352light0011 cms cross-site request forgery
CVE-2026-863092.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System pro_searchfrm.php sql injection
CVE-2026-863102.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System cust_edit1.php sql injection
CVE-2026-863012.0—code-projectsHospital Information SystemCWE-79code-projects Hospital Information System Patient Management editPatient.php …
CVE-2026-864242.0—ImageMagickImageMagickCWE-59ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race
CVE-2026-864221.0—ImageMagickImageMagickCWE-59ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race
CVE-2026-16028await——Protocol-HTTP2CWE-401Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via clo…
CVE-2026-86287await——Net-IP-LPMCWE-1287Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-07 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.