Security Box Score — September 8, 2026 — page 3
Edition of September 8, 2026, continued — page 3 of 3. Back to page 1 · page 2
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-69415 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows DHCP Server Elevation of Privilege Vulnerability |
| CVE-2026-69490 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability |
| CVE-2026-69566 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-71329 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows NTFS Remote Code Execution Vulnerability |
| CVE-2026-71348 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Spaceport.sys Remote Code Execution Vulnerability |
| CVE-2026-71349 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Spaceport.sys Remote Code Execution Vulnerability |
| CVE-2026-71350 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Spaceport.sys Remote Code Execution Vulnerability |
| CVE-2026-72985 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Volume Shadow Copy Elevation of Privilege Vulnerability |
| CVE-2026-72999 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Hub Driver Elevation of Privilege Vulnerability |
| CVE-2026-77892 | 6.8 | — | Microsoft | Windows 10 Version 1607 | CWE-693 | Windows Boot Manager Elevation of Privilege Vulnerability |
| CVE-2026-78451 | 6.8 | — | Microsoft | Windows 10 Version 1809 | CWE-822 | Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability |
| CVE-2026-78579 | 6.8 | — | Okta | Okta Access Gateway | CWE-90 | Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Inte… |
| CVE-2026-69350 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-69373 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Overlay Filter Elevation of Privilege Vulnerability |
| CVE-2026-69449 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows BitLocker Remote Code Execution Vulnerability |
| CVE-2026-71339 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-72927 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Winsock Elevation of Privilege Vulnerability |
| CVE-2026-72935 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Elevation of Privilege Vulnerability |
| CVE-2026-72948 | 6.7 | — | Microsoft | Windows 10 Version 1607 | CWE-23 | Windows DNS Elevation of Privilege Vulnerability |
| CVE-2026-78625 | 6.7 | — | Okta | Okta Access Gateway | CWE-94 | Insufficient Validation of Dashboard Application Labels in Okta Access Gatewa… |
| CVE-2026-78630 | 6.7 | — | Okta | Okta Access Gateway | CWE-78 | Improper Input Neutralization in Okta Access Gateway SNMP Configuration Proce… |
| CVE-2026-85981 | 6.7 | — | Auth0 | Auth0 AD/LDAP Connector | CWE-306 | Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector |
| CVE-2026-19201 | 6.6 | — | go-attestation | CWE-674 | Denial of Service via Unbounded Recursion in go-attestation Windows SIPA Parser | |
| CVE-2026-69469 | 6.6 | — | Microsoft | Windows 10 Version 1809 | CWE-122 | Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerab… |
| CVE-2026-78545 | 6.6 | — | Okta | Okta Access Gateway | CWE-94 | Improper Input Sanitization in Okta Access Gateway Application Label Configur… |
| CVE-2026-78550 | 6.6 | — | Okta | Okta Access Gateway | CWE-95 | Improper Input Handling in Okta Access Gateway Management Console Exception H… |
| CVE-2026-17509 | 6.5 | — | WPML | WPML Multilingual CMS | CWE-89 | WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Su… |
| CVE-2026-18021 | 6.5 | — | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | CWE-94 | Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode… |
| CVE-2026-53637 | 6.5 | — | Sylius | Sylius | CWE-672 | Sylius: Cart FormComponent allows modification or deletion of an already-comp… |
| CVE-2026-58649 | 6.5 | — | Microsoft | .NET 10.0 | CWE-346 | .NET Information Disclosure Vulnerability |
| CVE-2026-62762 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Active Directory Domain Services Denial of Service Vulnerability |
| CVE-2026-62801 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-22 | Microsoft PowerShell Security Feature Bypass Vulnerability |
| CVE-2026-63523 | 6.5 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-79 | Skype for Business Spoofing Vulnerability |
| CVE-2026-64918 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-522 | Microsoft Office Spoofing Vulnerability |
| CVE-2026-66303 | 6.5 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-476 | Skype for Business and Lync Denial of Service Vulnerability |
| CVE-2026-66306 | 6.5 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-209 | Skype for Business Information Disclosure Vulnerability |
| CVE-2026-66308 | 6.5 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-125 | Skype for Business and Lync Denial of Service Vulnerability |
| CVE-2026-66816 | 6.5 | — | Microsoft | Microsoft SQL Server 2022 (CU 26) | CWE-778 | Microsoft SQL Server Security Feature Bypass Vulnerability |
| CVE-2026-67369 | 6.5 | — | Microsoft | Microsoft SQL Server 2025 (CU8) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67383 | 6.5 | — | Microsoft | Microsoft SQL Server 2025 (CU8) | CWE-209 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67386 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-908 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67389 | 6.5 | — | Microsoft | Microsoft SQL Server 2022 (CU 26) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67390 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-126 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67393 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-126 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67624 | 6.5 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67629 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67630 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67633 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Denial of Service Vulnerability |
| CVE-2026-67641 | 6.5 | — | Microsoft | Microsoft SQL Server 2022 (CU 26) | CWE-190 | Microsoft SQL Server Denial of Service Vulnerability |
| CVE-2026-67645 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-67648 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-908 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68776 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-908 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68777 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68778 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68779 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68780 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68781 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68784 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-68898 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows iSCSI Denial of Service Vulnerability |
| CVE-2026-69267 | 6.5 | — | Microsoft | Windows 10 Version 1809 | CWE-1220 | Windows Connected User Experiences and Telemetry Information Disclosure Vulne… |
| CVE-2026-69297 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-257 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-69361 | 6.5 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-918 | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-69374 | 6.5 | — | Microsoft | Windows 10 Version 21H2 | CWE-770 | Windows SMB Server Denial of Service Vulnerability |
| CVE-2026-69375 | 6.5 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-639 | Microsoft Exchange Server Tampering Vulnerability |
| CVE-2026-69395 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-134 | Active Directory Certificate Services (AD CS) Information Disclosure Vulnerab… |
| CVE-2026-69409 | 6.5 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-250 | Microsoft Office SharePoint Information Disclosure Vulnerability |
| CVE-2026-69497 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-401 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-69562 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-69624 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-184 | Active Directory Certificate Services (AD CS) Tampering Vulnerability |
| CVE-2026-69626 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-69636 | 6.5 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-89 | Microsoft Office SharePoint Information Disclosure Vulnerability |
| CVE-2026-69642 | 6.5 | — | Microsoft | Skype for Business Server 2015 CU13 | CWE-79 | Skype for Business Spoofing Vulnerability |
| CVE-2026-69683 | 6.5 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-918 | Microsoft Office SharePoint Information Disclosure Vulnerability |
| CVE-2026-69719 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-69734 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-69739 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-69781 | 6.5 | — | Microsoft | Windows 11 Version 24H2 | CWE-401 | Windows DHCP Client Denial of Service Vulnerability |
| CVE-2026-69839 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-248 | Windows iSCSI Target Service Denial of Service Vulnerability |
| CVE-2026-70019 | 6.5 | — | Microsoft | Windows 11 version 23H2 | CWE-65 | Windows Compressed Folder Information Disclosure Vulnerability |
| CVE-2026-72938 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Office PowerPoint Information Disclosure Vulnerability |
| CVE-2026-72939 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-476 | Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability |
| CVE-2026-72942 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Spaceport.sys Information Disclosure Vulnerability |
| CVE-2026-72956 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-822 | Microsoft Office PowerPoint Information Disclosure Vulnerability |
| CVE-2026-72974 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Excel Information Disclosure Vulnerability |
| CVE-2026-72975 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office PowerPoint Information Disclosure Vulnerability |
| CVE-2026-72977 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Office PowerPoint Information Disclosure Vulnerability |
| CVE-2026-73029 | 6.5 | — | Microsoft | Microsoft SQL Server 2019 (CU 32) | CWE-126 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-76000 | 6.5 | — | Adobe | ColdFusion 2025 | CWE-400 | ColdFusion | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-77896 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-190 | Windows Remote Desktop Client Denial of Service Vulnerability |
| CVE-2026-77911 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-78441 | 6.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-125 | Windows OLE DB Information Disclosure Vulnerability |
| CVE-2026-78453 | 6.5 | — | Microsoft | Windows 10 Version 1607 | CWE-191 | Microsoft Windows SCSI Class System File Information Disclosure Vulnerability |
| CVE-2026-78502 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-78503 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-78515 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Excel Information Disclosure Vulnerability |
| CVE-2026-78520 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Outlook Information Disclosure Vulnerability |
| CVE-2026-78522 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-80073 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Outlook Information Disclosure Vulnerability |
| CVE-2026-80076 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-80078 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-80079 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-80082 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-80084 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Outlook Information Disclosure Vulnerability |
| CVE-2026-80086 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office PowerPoint Information Disclosure Vulnerability |
| CVE-2026-80087 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-122 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-80088 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-80089 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-80090 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-80091 | 6.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Office Information Disclosure Vulnerability |
| CVE-2026-81377 | 6.5 | — | Microsoft | Visual Studio Code | CWE-22 | Visual Studio Code Tampering Vulnerability |
| CVE-2026-81381 | 6.5 | — | Microsoft | Visual Studio Code | CWE-522 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-84391 | 6.5 | — | Fortinet | FortiAnalyzer | CWE-457 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3… |
| CVE-2026-84685 | 6.5 | — | Auth0 | react-native-auth0 | CWE-488 | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credent… |
| CVE-2026-12230 | 6.4 | — | thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | CWE-79 | LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-33388 | 6.4 | — | Nozomi Networks | Guardian | CWE-863 | Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 |
| CVE-2026-69878 | 6.4 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-70582 | 6.4 | — | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Management Instrumentation Elevation of Privilege Vulnerability |
| CVE-2026-71338 | 6.4 | — | Microsoft | Windows 10 Version 1607 | CWE-415 | Windows Failover Cluster Elevation of Privilege Vulnerability |
| CVE-2026-72947 | 6.4 | — | Microsoft | Windows 10 Version 1607 | CWE-191 | Windows File History Service Elevation of Privilege Vulnerability |
| CVE-2026-76931 | 6.4 | — | dylanjkotze | Zephyr Project Manager | CWE-79 | Zephyr Project Manager <= 3.3.205 - Authenticated (Custom+) Stored Cross-Site… |
| CVE-2026-77887 | 6.4 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-77891 | 6.4 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Remote Code Execution Vulnerability |
| CVE-2026-53639 | 6.3 | — | Sylius | Sylius | CWE-639 | Sylius: IDOR on Shop Payment Request API endpoints |
| CVE-2026-81824 | 6.3 | — | AVEVA | Pipeline Integrity Monitor | CWE-79 | AVEVA Pipeline Integrity Monitor cross-site scripting |
| CVE-2026-81904 | 6.3 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS before 9.5.3 is vulnerable to Missing Authorization in Stack/Con… |
| CVE-2026-81997 | 6.3 | — | Adobe | Adobe Acrobat | CWE-863 | Acrobat Reader | Incorrect Authorization (CWE-863) |
| CVE-2026-84942 | 6.3 | — | AWS | Amazon OpenSearch Service | CWE-79 | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch… |
| CVE-2026-86077 | 6.3 | — | n8n-io | n8n | CWE-862 | n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebS… |
| CVE-2026-86079 | 6.3 | — | n8n-io | n8n | CWE-22 | n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded … |
| CVE-2026-86080 | 6.3 | — | n8n-io | n8n | CWE-347 | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Sign… |
| CVE-2026-53937 | 6.2 | — | modelcontextprotocol | io.modelcontextprotocol:kotlin-sdk | CWE-400 | MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTra… |
| CVE-2026-18090 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted i… |
| CVE-2026-76002 | 6.1 | — | Adobe | ColdFusion 2025 | CWE-79 | ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-77654 | 6.1 | — | Algosec | Horizon Security Analyzer | CWE-266 | Local Privilege Escalation via Misconfigured Sudoers Entry in Horizon Securit… |
| CVE-2026-56101 | 6.0 | — | OpenBSD | OpenBSD | CWE-697 | OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS |
| CVE-2026-78216 | 6.0 | — | ash-project | ash_lua | CWE-1220 | AshLua eval read operations can read field-policy-protected fields via aggreg… |
| CVE-2026-78230 | 6.0 | — | ash-project | ash_ai | CWE-1220 | AshAi aggregate tool can read field-policy-protected fields |
| CVE-2026-78552 | 6.0 | — | Okta | Okta Access Gateway | CWE-693 | Validation Bypass in Okta Access Gateway Custom Directives |
| CVE-2026-78622 | 6.0 | — | Okta | Okta Verify for Windows | CWE-59 | Improper Link Resolution in Okta Verify for Windows Uninstaller Data Removal |
| CVE-2026-82056 | 6.0 | — | MongoDB | MongoDB Server | CWE-416 | Race Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-A… |
| CVE-2026-82059 | 6.0 | — | MongoDB | MongoDB Server | CWE-617 | Improper Access Restriction of Internal Aggregation Expression in MongoDB Ser… |
| CVE-2026-82063 | 6.0 | — | MongoDB | MongoDB Server | CWE-416 | Use-After-Free in MongoDB Server Cursor Management Component Leads to Denial … |
| CVE-2026-86078 | 6.0 | — | n8n-io | n8n | CWE-1321 | n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of… |
| CVE-2026-86084 | 6.0 | — | n8n-io | n8n | CWE-288 | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions |
| CVE-2026-69304 | 5.9 | — | Microsoft | .NET 10.0 | CWE-409 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-69382 | 5.9 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-327 | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2026-69803 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-69929 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-69930 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-70091 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows DNS Denial of Service Vulnerability |
| CVE-2026-70124 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Information Disclosure Vulnerability |
| CVE-2026-72978 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-770 | Active Directory Federation Services (AD FS) Denial of Service Vulnerability |
| CVE-2026-78523 | 5.9 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows DNS Server Denial of Service Vulnerability |
| CVE-2026-78620 | 5.9 | — | Okta | Okta Access Gateway | CWE-73 | Improper Path Validation in Okta Access Gateway Kerberos Configuration Handling |
| CVE-2026-86073 | 5.9 | — | n8n-io | n8n | CWE-863 | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Sub… |
| CVE-2026-86074 | 5.9 | — | n8n-io | n8n | CWE-918 | n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched … |
| CVE-2026-86735 | 5.9 | — | grokability | snipe-it | CWE-918 | snipe-it before 8.7.0 SSRF via IPv6 transition address bypass |
| CVE-2026-86993 | 5.9 | — | n8n-io | n8n | CWE-862 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Withou… |
| CVE-2026-69559 | 5.8 | — | Microsoft | Microsoft Teams for Android | CWE-346 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2026-68874 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Program Compatibility Assistant Service Information Disclosure Vulner… |
| CVE-2026-69317 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Client Information Disclosure Vulnerability |
| CVE-2026-69349 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Management Instrumentation Information Disclosure Vulnerability |
| CVE-2026-69372 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Network File System Denial of Service Vulnerability |
| CVE-2026-69393 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Spaceport.sys Information Disclosure Vulnerability |
| CVE-2026-69405 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-401 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-69416 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-69507 | 5.7 | — | Microsoft | Windows 11 version 23H2 | CWE-538 | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-69552 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-209 | Windows Print Spooler Components Information Disclosure Vulnerability |
| CVE-2026-69569 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-822 | Windows Print Spooler Components Denial of Service Vulnerability |
| CVE-2026-69572 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-69591 | 5.7 | — | Microsoft | Windows 10 Version 1809 | CWE-125 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-69637 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-69679 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DHCP Server Denial of Service Vulnerability |
| CVE-2026-69723 | 5.7 | — | Microsoft | Windows 10 Version 1607 | CWE-497 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-69832 | 5.6 | — | Microsoft | Windows 10 Version 1607 | CWE-497 | Win32k Information Disclosure Vulnerability |
| CVE-2026-78629 | 5.6 | — | Okta | Okta Hyperdrive Agent | CWE-303 | Improper Authentication Verification in the Okta Hyperdrive Agent MFA Respons… |
| CVE-2026-54611 | 5.5 | — | instantsoft | icms2 | CWE-94 | InstantCMS has Remote Code Execution in package installer |
| CVE-2026-68830 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-59 | Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vul… |
| CVE-2026-68831 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-552 | Windows Defender Firewall Service Information Disclosure Vulnerability |
| CVE-2026-68842 | 5.5 | — | Microsoft | Windows 11 Version 24H2 | CWE-497 | Windows MIDI Service Module Information Disclosure Vulnerability |
| CVE-2026-68843 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-68851 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-68852 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-200 | Microsoft Account Information Disclosure Vulnerability |
| CVE-2026-68873 | 5.5 | — | Microsoft | Windows 11 version 23H2 | CWE-532 | Windows Program Compatibility Assistant Service Information Disclosure Vulner… |
| CVE-2026-68881 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Standard XPS Information Disclosure Vulnerability |
| CVE-2026-68886 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-209 | Windows Network Connection Broker Information Disclosure Vulnerability |
| CVE-2026-68895 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-197 | Internet Storage Name Service Information Disclosure Vulnerability |
| CVE-2026-69286 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-20 | Windows USB Audio Class Driver Information Disclosure Vulnerability |
| CVE-2026-69288 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows GDI+ Information Disclosure Vulnerability |
| CVE-2026-69294 | 5.5 | — | Microsoft | Windows 10 Version 1809 | CWE-209 | Microsoft COM for Windows Information Disclosure Vulnerability |
| CVE-2026-69303 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Push Message Routing Service Information Disclosure Vulnerability |
| CVE-2026-69308 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Standard XPS Information Disclosure Vulnerability |
| CVE-2026-69315 | 5.5 | — | Microsoft | Windows 10 Version 1809 | CWE-497 | Windows License Manager Information Disclosure Vulnerability |
| CVE-2026-69318 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Imaging Component Information Disclosure Vulnerability |
| CVE-2026-69321 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Power Dependency Coordinator Tampering Vulnerability |
| CVE-2026-69339 | 5.5 | — | Microsoft | Windows 11 Version 24H2 | CWE-497 | Windows MIDI Service Module Information Disclosure Vulnerability |
| CVE-2026-69343 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2026-69344 | 5.5 | — | Microsoft | Windows 10 Version 21H2 | CWE-125 | Windows Print Spooler Components Information Disclosure Vulnerability |
| CVE-2026-69345 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Standard XPS Information Disclosure Vulnerability |
| CVE-2026-69351 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-359 | Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vul… |
| CVE-2026-69353 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Text Shaping Information Disclosure Vulnerability |
| CVE-2026-69367 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Standard XPS Information Disclosure Vulnerability |
| CVE-2026-69369 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows DNS Information Disclosure Vulnerability |
| CVE-2026-69376 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Standard XPS Information Disclosure Vulnerability |
| CVE-2026-69390 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Spaceport.sys Information Disclosure Vulnerability |
| CVE-2026-69403 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-862 | Windows SMB Server Information Disclosure Vulnerability |
| CVE-2026-69406 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-497 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2026-69453 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-862 | Microsoft Windows Search Component Tampering Vulnerability |
| CVE-2026-69457 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Driver Information Disclosure Vulnerability |
| CVE-2026-69504 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows NTFS Information Disclosure Vulnerability |
| CVE-2026-69527 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows USB Mass Storage Class Driver Information Disclosure Vulnerability |
| CVE-2026-69531 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-441 | Microsoft Windows Speech Tampering Vulnerability |
| CVE-2026-69554 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-306 | Microsoft Windows Search Component Tampering Vulnerability |
| CVE-2026-69568 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Storage Spaces Controller Information Disclosure Vulnerability |
| CVE-2026-69609 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Win32k Information Disclosure Vulnerability |
| CVE-2026-69616 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Services Information Disclosure Vulnerability |
| CVE-2026-69618 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows SMB Client Information Disclosure Vulnerability |
| CVE-2026-69627 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
| CVE-2026-69672 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows DNS Information Disclosure Vulnerability |
| CVE-2026-69674 | 5.5 | — | Microsoft | Windows 10 Version 1809 | CWE-306 | Windows Modern Device Management (MDM) Security Feature Bypass Vulnerability |
| CVE-2026-69684 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-209 | Windows Error Reporting Information Disclosure Vulnerability |
| CVE-2026-69741 | 5.5 | — | Microsoft | Windows 10 Version 21H2 | CWE-125 | Windows Spaceport.sys Information Disclosure Vulnerability |
| CVE-2026-69770 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Spaceport.sys Information Disclosure Vulnerability |
| CVE-2026-69794 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
| CVE-2026-69808 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Win32k Information Disclosure Vulnerability |
| CVE-2026-69862 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Wireless Wide Area Network Service Information Disclosure Vulnerability |
| CVE-2026-70145 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Windows Search Component Information Disclosure Vulnerability |
| CVE-2026-70290 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Win32k Information Disclosure Vulnerability |
| CVE-2026-71341 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Partition Management Driver Information Disclosure Vulnerability |
| CVE-2026-72937 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Storage Port Driver Information Disclosure Vulnerability |
| CVE-2026-72945 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Windows Task Scheduler Information Disclosure Vulnerability |
| CVE-2026-72964 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-306 | Windows Internet Connection Sharing (ICS) Tampering Vulnerability |
| CVE-2026-72966 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-862 | Windows Remote Access Connection Manager Tampering Vulnerability |
| CVE-2026-73004 | 5.5 | — | Microsoft | Windows 10 Version 21H2 | CWE-306 | Windows Autopilot Tampering Vulnerability |
| CVE-2026-73008 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-359 | Windows Biometric Service Information Disclosure Vulnerability |
| CVE-2026-77488 | 5.5 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-191 | Microsoft SQL Server Information Disclosure Vulnerability |
| CVE-2026-77491 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows GDI Information Disclosure Vulnerability |
| CVE-2026-77492 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Storage Port Driver Information Disclosure Vulnerability |
| CVE-2026-78454 | 5.5 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows CD-ROM Driver Information Disclosure Vulnerability |
| CVE-2026-78506 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-170 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-78513 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office PowerPoint Information Disclosure Vulnerability |
| CVE-2026-79910 | 5.5 | — | Adobe | Adobe Acrobat | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-80160 | 5.5 | — | Adobe | Adobe Acrobat | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-80162 | 5.5 | — | Adobe | Adobe Acrobat | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-81387 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-497 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81390 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81391 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81392 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-20 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81393 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81394 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-497 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81395 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81399 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81400 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81401 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-843 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81958 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-908 | Microsoft Excel Information Disclosure Vulnerability |
| CVE-2026-81977 | 5.5 | — | Adobe | Adobe Acrobat | CWE-191 | Acrobat Reader | Integer Underflow (Wrap or Wraparound) (CWE-191) |
| CVE-2026-81978 | 5.5 | — | Adobe | Adobe Acrobat | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-81982 | 5.5 | — | Adobe | Adobe Acrobat | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-81984 | 5.5 | — | Adobe | Adobe Acrobat | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-81991 | 5.5 | — | Adobe | Adobe Acrobat | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-81993 | 5.5 | — | Adobe | Adobe Acrobat | CWE-122 | Acrobat Reader | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-82001 | 5.5 | — | Adobe | Adobe Acrobat | CWE-400 | Acrobat Reader | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-83501 | 5.5 | — | Microsoft | Windows 11 version 23H2 | CWE-125 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability |
| CVE-2026-83949 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-83951 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-126 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-83991 | 5.5 | — | Microsoft | Windows 10 Version 1809 | CWE-306 | Windows Cloud Files Mini Filter Driver Tampering Vulnerability |
| CVE-2026-85875 | 5.5 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Excel Information Disclosure Vulnerability |
| CVE-2026-86665 | 5.5 | — | aircheng-org | iWebShop-5 | CWE-862 | aircheng-org iWebShop-5 update.php index authorization |
| CVE-2026-86666 | 5.5 | — | aircheng-org | iWebShop-5 | CWE-284 | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload |
| CVE-2026-86669 | 5.5 | — | aircheng-org | iWebShop-5 | CWE-287 | aircheng-org iWebShop-5 systemseller.php login improper authentication |
| CVE-2026-86672 | 5.5 | — | ningzichun | Student Management System | CWE-200 | ningzichun Student Management System Backup example.7z information disclosure |
| CVE-2026-86673 | 5.5 | — | ningzichun | Student Management System | CWE-259 | ningzichun Student Management System Database Connection database.php mysqli_… |
| CVE-2026-86716 | 5.5 | — | Cesanta | mJS | CWE-119 | Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow |
| CVE-2026-86808 | 5.5 | — | moltis-org | moltis | CWE-287 | moltis-org moltis vault.rs vault_recovery_handler missing authentication |
| CVE-2025-64542 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2025-64584 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64588 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64589 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64610 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64618 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64830 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64838 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64854 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64866 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2025-64868 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-2520 | 5.4 | — | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-862 | Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing A… |
| CVE-2026-19479 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-19612 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-19644 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-19713 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-27227 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-71356 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-71357 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-71388 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-71440 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-71565 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-72626 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-72627 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75629 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75635 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75636 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75637 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75639 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75640 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75642 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75643 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75644 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75646 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75647 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75651 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75652 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75657 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75659 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75660 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75661 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75666 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75667 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75668 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75669 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75670 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75671 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75672 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75674 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75675 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75677 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75678 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75679 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75680 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75681 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75683 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75685 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75687 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75690 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75691 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75692 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75693 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75694 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75695 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75696 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75700 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75701 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75702 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75704 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75705 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75706 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75707 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75708 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75709 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75710 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75711 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75712 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75713 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75714 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75715 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75716 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75717 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75718 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75719 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75720 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75722 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75724 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75725 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-75727 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75729 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75730 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75731 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75733 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75734 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75735 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75736 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75737 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75738 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75739 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75740 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75741 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75742 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-79905 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-84385 | 5.4 | — | Fortinet | FortiSOAR on-premise | CWE-284 | A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 thro… |
| CVE-2026-19614 | 5.3 | — | CyberELF | NanoXML | CWE-611 | XML External Entity (XXE) Injection in CyberELF NanoXML |
| CVE-2026-19625 | 5.3 | — | IBM | Enterprise Build of Quarkus | CWE-284 | IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities |
| CVE-2026-33389 | 5.3 | — | Nozomi Networks | Guardian | CWE-671 | Disabled and non-configurable certificate/host key validation in Smart Pollin… |
| CVE-2026-33391 | 5.3 | — | Nozomi Networks | Guardian | CWE-863 | Incorrect authorization in Smart Polling configuration in Guardian/CMC before… |
| CVE-2026-47680 | 5.3 | — | fluxcd | source-controller | CWE-23 | Source controller: Improper path handling allows traversal |
| CVE-2026-70575 | 5.3 | — | Microsoft | Windows 11 version 23H2 | CWE-476 | Windows Schannel Denial of Service Vulnerability |
| CVE-2026-78446 | 5.3 | — | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Distributed File System (DFS) Denial of Service Vulnerability |
| CVE-2026-78631 | 5.3 | — | Okta | Okta Hyperdrive Agent | CWE-532 | Improper Restriction of Sensitive Information in Okta Hyperdrive Agent Logging |
| CVE-2026-81380 | 5.3 | — | Microsoft | Visual Studio Code | CWE-77 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability |
| CVE-2026-82066 | 5.3 | — | MongoDB | MongoDB Server | CWE-125 | Heap Out-of-Bounds Read in MongoDB Server Query Planning Component |
| CVE-2026-86714 | 5.3 | — | PX4 | PX4-Autopilot | CWE-125 | PX4 Autopilot through 1.17.0 Stack Buffer Over-read via netman |
| CVE-2026-86719 | 5.3 | — | WWBN | AVideo | CWE-352 | WWBN AVideo CustomizeUser Cross-Site Request Forgery Session Hijacking |
| CVE-2026-86736 | 5.3 | — | grokability | snipe-it | CWE-682 | snipe-it before 8.7.0 Checkout Request Counter Integrity Failure |
| CVE-2026-86737 | 5.3 | — | grokability | snipe-it | CWE-862 | snipe-it before 8.7.0 Missing Authorization via barcode endpoint |
| CVE-2026-86994 | 5.3 | — | n8n-io | n8n | CWE-862 | n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing… |
| CVE-2026-86995 | 5.3 | — | n8n-io | n8n | CWE-22 | n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restricti… |
| CVE-2026-86996 | 5.3 | — | n8n-io | n8n | CWE-862 | n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy |
| CVE-2026-33387 | 5.1 | — | Nozomi Networks | Guardian | CWE-1336 | Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 |
| CVE-2026-33920 | 5.1 | — | Nozomi Networks | Guardian | CWE-352 | Cross-site request forgery in the Guardian/CMC login before 26.3.0 |
| CVE-2026-73317 | 5.1 | — | XenForo | XenForo | CWE-863 | XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild Dispatcher |
| CVE-2026-73318 | 5.1 | — | XenForo | XenForo | CWE-863 | XenForo < 2.3.13 Missing Authorization via force-agreement Controller |
| CVE-2026-73319 | 5.1 | — | XenForo | XenForo | CWE-79 | XenForo < 2.3.13 XSS via Dynamic Redirect Handler |
| CVE-2026-73320 | 5.1 | — | XenForo | XenForo | CWE-639 | XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl Endpoint |
| CVE-2026-82069 | 5.1 | — | MongoDB | MongoDB Server | CWE-212 | Improper Redaction of Query Literals in MongoDB Server Query Statistics Seria… |
| CVE-2026-84386 | 5.1 | — | Fortinet | FortiClientWindows | CWE-283 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 thr… |
| CVE-2026-86085 | 5.1 | — | n8n-io | n8n | CWE-862 | n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope… |
| CVE-2026-72976 | 5.0 | — | Microsoft | Microsoft 365 Apps for Enterprise | CWE-125 | Microsoft Office Word Information Disclosure Vulnerability |
| CVE-2026-78635 | 5.0 | — | Okta | Okta Privileged Access Client | CWE-88 | Improper Input Validation in the Okta Privileged Access SSH Client URL Handle… |
| CVE-2026-79904 | 5.0 | — | Adobe | Photoshop Android | CWE-22 | Photoshop Mobile | Improper Limitation of a Pathname to a Restricted Director… |
| CVE-2026-22575 | 4.9 | — | Fortinet | FortiManager | CWE-284 | An improper access control vulnerability in Fortinet FortiManager 7.6.0 throu… |
| CVE-2026-68785 | 4.9 | — | Microsoft | Microsoft SQL Server 2017 (CU 31) | CWE-122 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-78624 | 4.9 | — | Okta | Okta Access Gateway | CWE-22 | Improper Path Validation in Okta Access Gateway Backup and Restore Functionality |
| CVE-2026-69474 | 4.8 | — | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2026-78560 | 4.8 | — | Okta | Okta Access Gateway | CWE-287 | Improper Authentication Validation in Okta Access Gateway Pass-Through Authen… |
| CVE-2026-68849 | 4.7 | — | Microsoft | Windows 10 Version 21H2 | CWE-125 | Windows Bluetooth Port Driver Information Disclosure Vulnerability |
| CVE-2026-68891 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Microsoft Standard XPS Information Disclosure Vulnerability |
| CVE-2026-69316 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Overlay Filter Information Disclosure Vulnerability |
| CVE-2026-69425 | 4.7 | — | Microsoft | Windows 11 version 23H2 | CWE-59 | Windows NTFS Tampering Vulnerability |
| CVE-2026-69483 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Image Acquisition Information Disclosure Vulnerability |
| CVE-2026-69771 | 4.7 | — | Microsoft | Windows 11 version 23H2 | CWE-59 | Windows Container Manager Service Security Feature Bypass Vulnerability |
| CVE-2026-69792 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Win32K Security Feature Bypass Vulnerability |
| CVE-2026-69853 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-908 | Win32k Information Disclosure Vulnerability |
| CVE-2026-69895 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Spaceport.sys Information Disclosure Vulnerability |
| CVE-2026-72931 | 4.7 | — | Microsoft | Windows 10 Version 1607 | CWE-772 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability |
| CVE-2026-69381 | 4.6 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows Storage Port Driver Information Disclosure Vulnerability |
| CVE-2026-69548 | 4.6 | — | Microsoft | Windows 10 Version 1607 | CWE-122 | Windows RNDIS Information Disclosure Vulnerability |
| CVE-2026-69690 | 4.6 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-78452 | 4.6 | — | Microsoft | Windows 10 Version 1809 | CWE-125 | Microsoft Windows SCSI Class System File Information Disclosure Vulnerability |
| CVE-2026-78508 | 4.6 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Windows CD-ROM Driver Information Disclosure Vulnerability |
| CVE-2026-0001 | 4.4 | — | Arm Ltd | Bifrost GPU Kernel Driver | CWE-416 | Mali GPU Kernel Driver allows access to already freed memory |
| CVE-2026-69713 | 4.4 | — | Microsoft | Windows 10 Version 1607 | CWE-1395 | Windows Secure Boot Security Feature Bypass Vulnerability |
| CVE-2026-72980 | 4.4 | — | Microsoft | Windows 10 Version 1607 | CWE-427 | Windows Hello Security Feature Bypass Vulnerability |
| CVE-2026-53638 | 4.3 | — | Sylius | Sylius | CWE-863 | Sylius: Channel-based payment method restriction bypass on shop account order… |
| CVE-2026-73019 | 4.3 | — | Microsoft | Windows 10 Version 1607 | CWE-41 | Windows URL Moniker Security Feature Bypass Vulnerability |
| CVE-2026-78455 | 4.3 | — | Microsoft | Windows 10 Version 1607 | CWE-125 | Xbox Information Disclosure Vulnerability |
| CVE-2026-78516 | 4.3 | — | Microsoft | Windows 10 Version 1607 | CWE-126 | Windows Storage Information Disclosure Vulnerability |
| CVE-2026-79603 | 4.3 | — | Xen | Xen | CWE-664 | Unconditionally do TLB flushing ahead of page scrubbing |
| CVE-2026-86853 | 4.3 | — | Mozilla | Firefox for iOS | CWE-451 | Repeated external URL scheme launches could potentially cause a denial of ser… |
| CVE-2026-80159 | 4.0 | — | Adobe | Adobe Acrobat | CWE-426 | Acrobat Reader | Untrusted Search Path (CWE-426) |
| CVE-2026-69615 | 3.5 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-79 | Microsoft Office SharePoint Spoofing Vulnerability |
| CVE-2026-69904 | 3.5 | — | Microsoft | Microsoft SharePoint Server Subscription Edition | CWE-918 | Microsoft Office SharePoint Information Disclosure Vulnerability |
| CVE-2026-75726 | 3.5 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-20 | Adobe Experience Manager | Improper Input Validation (CWE-20) |
| CVE-2026-86564 | 3.3 | — | Red Hat | Fast Datapath for RHEL 10 | CWE-125 | Dpdk: dpdk: missing length validation before reading command_data in virtio-n… |
| CVE-2026-48707 | 3.1 | — | instantsoft | icms2 | CWE-918 | InstantCMS vulnerable to SSRF via upload redirect bypass allows internal netw… |
| CVE-2026-84389 | 3.1 | — | Fortinet | FortiSIEM | CWE-601 | A url redirection to untrusted site ('open redirect') vulnerability in Fortin… |
| CVE-2026-86670 | 2.9 | — | aircheng-org | iWebShop-5 | CWE-326 | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash |
| CVE-2026-84392 | 2.7 | — | Fortinet | FortiOS | CWE-476 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet … |
| CVE-2026-82060 | 2.3 | — | MongoDB | MongoDB Server | CWE-943 | Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query … |
| CVE-2026-86668 | 2.1 | — | aircheng-org | iWebShop-5 | CWE-79 | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting |
| CVE-2026-86674 | 2.1 | — | ningzichun | Student Management System | CWE-384 | ningzichun Student Management System login.php session_start session fixiation |
| CVE-2026-86675 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System us_edit.php sql injection |
| CVE-2026-86644 | 2.0 | — | star7th | showdoc | CWE-79 | star7th showdoc API Page Save Endpoint editormd.js cross site scripting |
| CVE-2026-86667 | 2.0 | — | aircheng-org | iWebShop-5 | CWE-74 | aircheng-org iWebShop-5 member.php member_list sql injection |
| CVE-2026-9215 | 1.8 | — | NETGEAR | XR1000 | CWE-352 | A CSRF vulnerability exists in certain NETGEAR XR series devices |
| CVE-2026-9216 | 1.2 | — | NETGEAR | RAX30 | CWE-121 | Insufficient input validation vulnerability exists in certain NETGEAR RAX Models |
| CVE-2026-0054 | await | — | Android | — | In isCallerAllowed of WalletContextualLocationsService.kt, there is a possibl… | |
| CVE-2026-0065 | await | — | Android | — | In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.ja… | |
| CVE-2026-0084 | await | — | Android | — | In multiple functions of HostEmulationManager.java, there is a possible backg… | |
| CVE-2026-0860 | await | — | Arm Ltd | Valhall GPU Kernel Driver | CWE-200 | Mali GPU Kernel Driver allows access to sensitive kernel information |
| CVE-2026-5729 | await | — | Arm Ltd | Valhall GPU Kernel Driver | CWE-416 | Mali GPU Kernel Driver allows access to already freed memory |
| CVE-2026-7476 | await | — | Arm Ltd | Bifrost GPU Kernel Driver | CWE-416 | Mali GPU Kernel Driver allows access to already freed memory |
| CVE-2026-7477 | await | — | Arm Ltd | Bifrost GPU Kernel Driver | CWE-416 | Mali GPU Kernel Driver allows access to already freed memory |
| CVE-2026-9034 | await | — | Arm Ltd | Bifrost GPU Userspace Driver | CWE-416 | Mali GPU Userspace Driver allows access to already freed memory |
| CVE-2026-9040 | await | — | Arm Ltd | Bifrost GPU Kernel Driver | CWE-362 | Mali GPU Kernel Driver allows denial of service or disclosure of sensitive in… |
| CVE-2026-11891 | await | — | Arm Ltd | Valhall GPU Userspace Driver | CWE-416 | Mali GPU Userspace Driver allows access to already freed memory |
| CVE-2026-12285 | await | — | Arm Ltd | Bifrost GPU Kernel Driver | CWE-416 | Mali GPU Kernel Driver allows access to already freed memory |
| CVE-2026-12387 | await | — | Arm Ltd | Bifrost GPU Kernel Driver | CWE-416 | Mali GPU Kernel Driver allows access to already freed memory |
| CVE-2026-19872 | await | — | — | HTML-FormHandler | CWE-79 | HTML::FormHandler versions before 0.410000 for Perl allow cross-site scriptin… |
| CVE-2026-28572 | await | — | Android | — | In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a t… | |
| CVE-2026-28582 | await | — | Android | — | In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unau… | |
| CVE-2026-28583 | await | — | Android | — | In validate_camera_metadata_structure of camera_metadata.c, there is a possib… | |
| CVE-2026-28584 | await | — | Android | — | In createSessionInternal of PackageInstallerService.java, there is a possible… | |
| CVE-2026-28590 | await | — | Android | — | In multiple locations, there is a possible improper encryption key validation… | |
| CVE-2026-28593 | await | — | Android | — | In getItemList of SettingsFragment.java, there is a possible user interaction… | |
| CVE-2026-28594 | await | — | Android | — | In multiple locations, there is a possible use after free due to a logic erro… | |
| CVE-2026-28596 | await | — | Android | — | In parseInterventionFromXml of GameManagerService.java, there is a possible p… | |
| CVE-2026-28599 | await | — | Android | — | In addCreatorToken of ActivityManagerService.java, there is a possible Intent… | |
| CVE-2026-28600 | await | — | Android | — | In onCreate of PaymentDefaultDialog.java, there is a possible way to change d… | |
| CVE-2026-28602 | await | — | Android | — | In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, th… | |
| CVE-2026-28603 | await | — | Android | — | In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is … | |
| CVE-2026-28604 | await | — | Android | — | In multiple locations, there is a possible use after free due to a race condi… | |
| CVE-2026-28606 | await | — | Android | — | In handleBondStateChanged of AdapterService.java, there is a possible way to … | |
| CVE-2026-28607 | await | — | Android | — | In multiple functions in multiple locations, there is a possible background a… | |
| CVE-2026-28609 | await | — | Android | — | In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due… | |
| CVE-2026-28611 | await | — | Android | — | In multiple functions of NfcService.java, there is a possible silent payment … | |
| CVE-2026-28612 | await | — | Android | — | In resolveActivity of ActivityStarter.java, there is a possible way to perfor… | |
| CVE-2026-28613 | await | — | Android | — | In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch a… | |
| CVE-2026-28614 | await | — | Android | — | In onCreate of SlicePermissionActivity.java, there is a possible permission b… | |
| CVE-2026-28616 | await | — | Android | — | In Setup Wizard, there is a possible way to force connection to a malicious n… | |
| CVE-2026-28617 | await | — | Android | — | In add of WifiNetworkSuggestionsManager.java, there is a possible persistent … | |
| CVE-2026-28618 | await | — | Android | — | In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buf… | |
| CVE-2026-28620 | await | — | Android | — | In multiple locations, there is a possible unauthorized URI access due to a p… | |
| CVE-2026-28622 | await | — | Android | — | In getQueryBuilderInternal of MediaProvider.java, there is a possible way to … | |
| CVE-2026-28623 | await | — | Android | — | In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way … | |
| CVE-2026-28624 | await | — | Android | — | In multiple locations, there is a possible read/write access to files without… | |
| CVE-2026-28626 | await | — | Android | — | In onCreate of SetupPassthroughActivity.java, there is a possible way to laun… | |
| CVE-2026-28627 | await | — | Android | — | In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack… | |
| CVE-2026-28630 | await | — | Android | — | In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI d… | |
| CVE-2026-28631 | await | — | Android | — | In buildMiniResolver of IntentForwarderActivity.java, there is a possible con… | |
| CVE-2026-28633 | await | — | Android | — | In initForUserNoTracing of VoiceInteractionManagerService.java, there is a po… | |
| CVE-2026-28634 | await | — | Android | — | In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way t… | |
| CVE-2026-28636 | await | — | Android | — | In setupLayout of PickActivity.java, there is a possible bypass of the "Insta… | |
| CVE-2026-28638 | await | — | Android | — | In multiple functions of XmpDataParser.java, there is a possible improper dat… | |
| CVE-2026-28639 | await | — | Android | — | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds writ… | |
| CVE-2026-28642 | await | — | Android | — | In executeRequest of ActivityStarter.java, there is a possible background act… | |
| CVE-2026-28644 | await | — | Android | — | In startNextMatchingActivity of ActivityTaskManagerService.java, there is a p… | |
| CVE-2026-28650 | await | — | Android | — | In setHiddenWhileSuspended of WindowState.java, there is a possible overlay b… | |
| CVE-2026-28652 | await | — | Android | — | In multiple functions of RangingServiceImpl.java, there is a possible MITM du… | |
| CVE-2026-28653 | await | — | Android | — | In multiple functions of rw_t3t.cc, there is a possible out of bounds write d… | |
| CVE-2026-28655 | await | — | Android | — | In multiple functions of RemoteViews.java, there is a possible background act… | |
| CVE-2026-28656 | await | — | Android | — | In multiple functions of DeviceAdminAdd.java, there is a possible way to an o… | |
| CVE-2026-28657 | await | — | Android | — | In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible… | |
| CVE-2026-28658 | await | — | Android | — | In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to … | |
| CVE-2026-28660 | await | — | Android | — | In getAllSessions of multiple files, there is a possible confused deputy due … | |
| CVE-2026-28662 | await | — | Android | — | In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out o… | |
| CVE-2026-28663 | await | — | Android | — | In buildIntentSenderForUser of LauncherAppsService.java, there is a possible … | |
| CVE-2026-28666 | await | — | Android | — | In multiple functions of LocalImageResolver.java, there is a possible Remote … | |
| CVE-2026-28668 | await | — | Android | — | In LimitRealloc of malloc_limit.cpp, there is a possible use after free due t… | |
| CVE-2026-28671 | await | — | Android | — | In updateInternal of MediaProvider.java, there is a possible expose contents … | |
| CVE-2026-30754 | await | — | n/a | n/a | — | A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encodi… |
| CVE-2026-45515 | await | — | Android | — | In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, the… | |
| CVE-2026-45519 | await | — | Android | — | In screenArgsForPermissionCheckIfAny of multiple locations there is a possibl… | |
| CVE-2026-45520 | await | — | Android | — | In onAttach of BiometricsSettingsBase.java, there is a possible authenticatio… | |
| CVE-2026-45521 | await | — | Android | — | In openFile of AppFuseBridge.java, there is a possible information disclosure… | |
| CVE-2026-45525 | await | — | Android | — | In multiple locations, there is a possible improper data sanitization due to … | |
| CVE-2026-45527 | await | — | Android | — | In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible w… | |
| CVE-2026-45528 | await | — | Android | — | In getManageSpaceActivityIntent of StorageManagerService.java, there is a pos… | |
| CVE-2026-45531 | await | — | Android | — | In read_boot_region of fsck.c, there is a possible out of bounds read due to … | |
| CVE-2026-49879 | await | — | Android | — | In multiple functions of rw_t3t.cc, there is a possible out of bounds write d… | |
| CVE-2026-49881 | await | — | Android | — | In serviceClassExists of InCallController.java, there is a possible arbitrary… | |
| CVE-2026-49882 | await | — | Android | — | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issu… | |
| CVE-2026-49884 | await | — | Android | — | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds writ… | |
| CVE-2026-49887 | await | — | Android | — | In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a… | |
| CVE-2026-49895 | await | — | Android | — | In get_eht_operation_channel_width of ieee802_11_common.c, there is a possibl… | |
| CVE-2026-49918 | await | — | Android | — | In multiple functions, there is a possible out of bounds write due to an inte… | |
| CVE-2026-49919 | await | — | Android | — | In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code exec… | |
| CVE-2026-52307 | await | — | n/a | n/a | — | An authenticated stored cross-site scripting (XSS) vulnerability in the Colum… |
| CVE-2026-52486 | await | — | n/a | n/a | — | An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of servi… |
| CVE-2026-55256 | await | — | Android | — | In parsePartHeaders of multiple files, there is a possible persistent denial … | |
| CVE-2026-55290 | await | — | Android | — | In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read du… | |
| CVE-2026-58820 | await | — | Android | — | In multiple locations, there is a possible memory safety issue due to integer… | |
| CVE-2026-62437 | await | — | Xen | Xen | — | x86: DMs may cause mem leak by IRQ binding |
| CVE-2026-78738 | await | — | n/a | n/a | — | Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Doc… |
| CVE-2026-78741 | await | — | n/a | n/a | — | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wy… |
| CVE-2026-78742 | await | — | n/a | n/a | — | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the M… |
| CVE-2026-78834 | await | — | n/a | n/a | — | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugi… |
| CVE-2026-78837 | await | — | n/a | n/a | — | A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachF… |
| CVE-2026-78838 | await | — | n/a | n/a | — | A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.p… |
| CVE-2026-78971 | await | — | n/a | n/a | — | In Halo <= 2.25.4, the plugin management feature allows users to install/upda… |
| CVE-2026-78997 | await | — | n/a | n/a | — | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) conta… |
| CVE-2026-79378 | await | — | n/a | n/a | — | An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Blue… |
| CVE-2026-79379 | await | — | n/a | n/a | — | A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd B… |
| CVE-2026-79570 | await | — | n/a | n/a | — | mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerabili… |
| CVE-2026-79571 | await | — | n/a | n/a | — | Incorrect access control in the SellerAuthorizeAspect component of springboot… |
| CVE-2026-79572 | await | — | n/a | n/a | — | An XXE (XML External Entity) vulnerability in the level-rule module of Distri… |
| CVE-2026-79573 | await | — | n/a | n/a | — | L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities… |
| CVE-2026-79574 | await | — | n/a | n/a | — | An issue in the gateway server of mpush v0.8.1 allows attackers to execute ar… |
| CVE-2026-79575 | await | — | n/a | n/a | — | The JWT signing secret in yfexam-exam v2.0 is derived from the username and t… |
| CVE-2026-79577 | await | — | n/a | n/a | — | An issue in the /cas/login component of sso-master v1.0.0 allows attackers to… |
| CVE-2026-79588 | await | — | n/a | n/a | — | U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of a… |
| CVE-2026-79602 | await | — | Xen | Xen | — | x86: improper handling of HVM emulation return codes |
| CVE-2026-84282 | await | — | Ascensio System SIA / OnlyOffice | ONLYOFFICE ownCloud integration plugin | — | A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE o… |
| CVE-2026-85484 | await | — | — | HTML-FormHandler | CWE-79 | HTML::FormHandler versions before 0.410002 for Perl render option group label… |
| CVE-2026-85485 | await | — | — | HTML-FormHandler | CWE-79 | HTML::FormHandler versions before 0.410002 for Perl render some error message… |
| CVE-2026-85630 | await | — | — | HTML-FormHandler | CWE-79 | HTML::FormHandler versions before 0.410002 for Perl render field attributes i… |
| CVE-2026-86840 | await | — | Bitfrost.io | Bifrost | — | Bifrost Unauthorized Channel Commission Attribution Allows Commission Diversion |