AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0029 21.4 YES
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Added to CISA KEV, due Sep 23 Sep 9 Published (CNA: Chrome)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 4 to KEV; 654 CVEs published, led by Google (231).
654 CVEs published September 9, 2026: 55 critical, 188 high, 280 medium, 42 low; 1 in the KEV catalog at press time; 4 with a public exploit reference; 89 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 254 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4401 | 39287 | — | — |
| KEV catalog size | 1703 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2491 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 200 | 4283 | 420 | 2021 | 706 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +154 ▲ |
| microsoft | 975 | 2874 | 189 | 1972 | 697 | 16 | 289 | 30 | 1.0 | 7.8 | .0044 | +942 ▲ |
| 360 | 2526 | 315 | 917 | 1061 | 106 | 79 | 8 | 0.3 | 7.5 | .0025 | +317 ▲ | |
| red hat | 59 | 684 | 43 | 286 | 318 | 37 | 2 | 0 | 0.0 | 6.8 | .0028 | +17 ▲ |
| apple | 0 | 316 | 59 | 85 | 165 | 7 | 88 | 8 | 2.5 | 6.5 | .0029 | -1 ▼ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 10 | 38 | 5 | 21 | 11 | 1 | 0 | 0 | 0.0 | 7.5 | .0035 | +5 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 12 | 96 | 24 | 46 | 26 | 0 | 57 | 14 | 14.6 | 7.5 | .0041 | -18 ▼ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| fortinet | 9 | 39 | 8 | 11 | 17 | 3 | 29 | 7 | 17.9 | 6.7 | .0038 | +9 ▲ |
| palo alto networks | 0 | 37 | 1 | 3 | 21 | 12 | 13 | 2 | 5.4 | 4.7 | .0020 | 0 |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0025 | +2 ▲ |
| ivanti | 10 | 24 | 10 | 12 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0146 | +10 ▲ |
| f5 | 7 | 24 | 6 | 14 | 3 | 1 | 4 | 1 | 4.2 | 8.7 | .0047 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 19 | 528 | 107 | 221 | 178 | 13 | 33 | 2 | 0.4 | 7.5 | .0049 | -41 ▼ |
| mozilla | 35 | 222 | 80 | 79 | 63 | 0 | 9 | 0 | 0.0 | 8.1 | .0029 | +34 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0024 | +26 ▲ |
| gitlab | 0 | 76 | 3 | 17 | 47 | 9 | 4 | 2 | 2.6 | 5.3 | .0029 | 0 |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | +1 ▲ |
| docker | 0 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | 0 |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -1 ▼ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | 0 |
| adobe | 170 | 776 | 57 | 344 | 365 | 10 | 20 | 4 | 0.5 | 7.5 | .0023 | +162 ▲ |
| ibm | 72 | 691 | 153 | 309 | 220 | 9 | 6 | 1 | 0.1 | 7.5 | .0029 | +40 ▲ |
| progress | 2 | 63 | 14 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0035 | -9 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | -10 ▼ |
| zohocorp | 5 | 15 | 3 | 6 | 6 | 0 | 0 | 0 | 0.0 | 8.4 | .0099 | +5 ▲ |
| atlassian | 0 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 8 | 53 | 16 | 19 | 10 | 8 | 3 | 0 | 0.0 | 8.5 | .0157 | -7 ▼ |
| siemens | 14 | 51 | 6 | 33 | 9 | 3 | 0 | 0 | 0.0 | 7.3 | .0018 | +14 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +18 ▲ |
| synology | 0 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -1 ▼ |
| schneider electric | 7 | 16 | 1 | 11 | 4 | 0 | 0 | 0 | 0.0 | 8.5 | .0032 | +7 ▲ |
| hitachi energy | 4 | 7 | 0 | 3 | 4 | 0 | 0 | 0 | 0.0 | 6.9 | .0017 | +4 ▲ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| hikvision | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.2 | .0040 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 127 | 298 | 21 | 140 | 119 | 18 | 2 | 1 | 0.3 | 7.2 | .0019 | +119 ▲ |
| sourcecodester | 26 | 195 | 0 | 0 | 114 | 81 | 0 | 0 | 0.0 | 5.5 | .0028 | +15 ▲ |
| spring | 0 | 170 | 12 | 59 | 84 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | 0 |
| nvidia | 32 | 166 | 20 | 117 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +16 ▲ |
| itsourcecode | 24 | 140 | 0 | 0 | 36 | 104 | 0 | 0 | 0.0 | 2.1 | .0026 | +16 ▲ |
| mongodb | 34 | 132 | 4 | 81 | 43 | 4 | 1 | 0 | 0.0 | 7.1 | .0026 | +34 ▲ |
| elastic | 42 | 129 | 1 | 27 | 98 | 3 | 1 | 0 | 0.0 | 6.5 | .0028 | +42 ▲ |
| splunk | 0 | 128 | 6 | 47 | 70 | 5 | 1 | 1 | 0.8 | 6.5 | .0025 | 0 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-72898 | .9422 | 99.8 | 10.0 |
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-73570 | .3238 | 98.2 | 8.9 |
| CVE-2026-71362 | .2514 | 97.8 | 9.1 |
| CVE-2026-64849 | .1641 | 96.8 | 9.3 |
| CVE-2026-48376 | .1548 | 96.6 | 5.4 |
| CVE-2026-83549 | .1384 | 96.3 | 7.8 |
| CVE-2026-19681 | .0780 | 94.3 | 9.4 |
| CVE-2026-82329 | .0767 | 94.2 | 9.8 |
| CVE-2026-83548 | .0745 | 94.1 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-72898 | 10.0 | .9422 | KEV |
| CVE-2026-83548 | 10.0 | .0745 | KEV |
| CVE-2026-48362 | 10.0 | .0431 | |
| CVE-2026-75650 | 10.0 | .0215 | KEV |
| CVE-2026-19188 | 10.0 | .0193 | |
| CVE-2026-86152 | 10.0 | .0186 | |
| CVE-2026-58231 | 10.0 | .0171 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-69836 | 10.0 | .0155 |
| Vendor | CVEs |
|---|---|
| linux | 1455 |
| microsoft | 1419 |
| oracle | 890 |
| 719 | |
| ibm | 430 |
| adobe | 263 |
| red hat | 212 |
| dell | 191 |
| apache | 112 |
| splunk | 110 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 14 |
| apple | 8 |
| 8 | |
| fortinet | 7 |
| ivanti | 5 |
| adobe | 4 |
| berriai | 4 |
| oracle | 4 |
| solarwinds | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 34 |
| Packagist | 34 |
| npm | 14 |
| PyPI | 12 |
| RubyGems | 2 |
| Go | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-20349 | Cisco | 0 |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-72898 | Metabase | 0 |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-64849 | mlflow | 1 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1757 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1757 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1757 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1757 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1757 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1757 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1757 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1757 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1757 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1757 |
ADDED TO KEV — CVE-2025-25249 (Fortinet FortiSwitchManager). Remediation due September 12, 2026.
ADDED TO KEV — CVE-2026-19490 (NetScaler ADC). Remediation due September 12, 2026.
ADDED TO KEV — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). Remediation due September 12, 2026.
ADDED TO KEV — CVE-2026-87491 (Google Chrome). Remediation due September 23, 2026.
EXPLOIT PUBLISHED — XenForo: 14 CVEs (CVE-2026-73309, CVE-2026-73310, CVE-2026-73311, CVE-2026-73312, CVE-2026-73313, CVE-2026-73314, CVE-2026-73315, CVE-2026-73316, CVE-2026-73317, CVE-2026-73318, CVE-2026-73319, CVE-2026-73320, CVE-2026-73321, CVE-2026-74239). Public exploit references added.
EXPLOIT PUBLISHED — axios: 12 CVEs (CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44495, CVE-2026-44496). Public exploit references added.
EXPLOIT PUBLISHED — netty: 6 CVEs (CVE-2026-33870, CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587). Public exploit references added.
EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.
EXPLOIT PUBLISHED — itsourcecode Sales and Inventory System: 3 CVEs (CVE-2026-86234, CVE-2026-86265, CVE-2026-86517). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33231 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37171. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-39883 (open-telemetry opentelemetry-go). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71625. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85089 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85090 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86170 (DefaultFuction CRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86181 (code-projects Task Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86210 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86215 (Mstfakts College-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86222 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86227 (valkey-io valkey). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86239 (liufee FeehiCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86260 (sfturing hosp_order). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86271 (FluentCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86276 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86279 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86285 (BookStack). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86292 (SourceCodester Simple Traffic Offense System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86297 (D-Link DIR-605). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86302 (code-projects Hospital Information System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86308 (light0011 cms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86319 (java-json-tools json-patch). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86431 (thephpleague commonmark). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86512 (java-json-tools json-patch). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87528 (Google Chrome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87629 (Google Chrome). Public exploit reference added.
RESCORED — Dell Secure Connect Gateway 5.0 - Application: 6 CVEs (CVE-2026-79734, CVE-2026-80128, CVE-2026-80129, CVE-2026-80130, CVE-2026-80131, CVE-2026-80164). CVSS rescored — before/after on each CVE page.
RESCORED — IBM App Connect Enterprise: 5 CVEs (CVE-2026-17442, CVE-2026-17443, CVE-2026-17444, CVE-2026-19649, CVE-2026-78543). CVSS rescored — before/after on each CVE page.
RESCORED — Microsoft SharePoint Server Subscription Edition: 5 CVEs (CVE-2026-69402, CVE-2026-69417, CVE-2026-69615, CVE-2026-69683, CVE-2026-69690). CVSS rescored — before/after on each CVE page.
RESCORED — IBM i: 3 CVEs (CVE-2026-17469, CVE-2026-17470, CVE-2026-17499). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2026-17483 (IBM Db2 Mirror for i). CVSS 4.3 → 3.3 (NVD).
RESCORED — CVE-2026-17627 (IBM Langflow OSS). CVSS 4.9 → 7.1 (NVD).
RESCORED — CVE-2026-17631 (IBM Langflow OSS). CVSS 5 → 6.5 (NVD).
RESCORED — CVE-2026-21042 (Samsung Mobile Devices). CVSS 8.4 → 8.7 (NVD).
RESCORED — CVE-2026-4765 (RD Station Conversas Tallos Chat). CVSS 5.1 → 0 (NVD).
RESCORED — CVE-2026-69739 (Microsoft 365 Apps for Enterprise). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2026-69857 (Microsoft Azure Cosmos DB). CVSS 8.5 → 8.8 (NVD).
RESCORED — CVE-2026-77503 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD).
PATCH SHIPPED — CVE-2026-19546 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.643-26.el10_2.4.
PATCH SHIPPED — CVE-2026-74860 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.15.4-0.1.hum1.
How to read these box scores · glossary
654 CVEs published. 25 box scores and 375 table rows below; the remaining 254 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0029 21.4 YES
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Added to CISA KEV, due Sep 23 Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0068 50.3 —
AFFECTED Product Versions Fixed Ninja Forms – The Contact Form Builder That Grows With You unspecified —
TIMELINE Jun 5 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0067 50.0 —
AFFECTED Product Versions Fixed Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce unspecified —
TIMELINE Jul 10 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0056 45.0 —
AFFECTED Product Versions Fixed Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce unspecified —
TIMELINE Jul 13 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0052 42.2 —
AFFECTED Product Versions Fixed Next-Cart Store to WooCommerce Migration unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0051 41.7 —
AFFECTED Product Versions Fixed WP Plugin Web unspecified — WP Plugin Crazy Domains unspecified — WP Module Data unspecified — WP Plugin Hostgator unspecified — WP Plugin Bluehost unspecified —
TIMELINE Aug 25 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0050 41.3 —
AFFECTED Product Versions Fixed FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment unspecified —
TIMELINE Aug 19 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0049 40.8 —
AFFECTED Product Versions Fixed Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Single Sign-On 7 unspecified —
TIMELINE Aug 13 Reserved by CNA Sep 9 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0044 37.2 —
AFFECTED Product Versions Fixed Shopping Cart & eCommerce Store unspecified —
TIMELINE Jul 27 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0044 36.9 —
AFFECTED Product Versions Fixed Agent Development Kit (ADK) for Python 2.0.0 – —
TIMELINE Aug 25 Reserved by CNA Sep 9 Published (CNA: GoogleCloud)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L H N 8.8 .0041 34.5 —
AFFECTED Product Versions Fixed Samsung Mobile Devices unspecified SMR Sep-2026 Release in Android 14, 15, 16, 17
TIMELINE Dec 11 Reserved by CNA Sep 9 Published (CNA: SamsungMobile)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0041 34.2 —
AFFECTED Product Versions Fixed Samsung Mobile Devices unspecified SMR Sep-2026 Release in Android 14, 15, 16, 17
TIMELINE Dec 11 Reserved by CNA Sep 9 Published (CNA: SamsungMobile)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0041 34.2 —
AFFECTED Product Versions Fixed Samsung Mobile Devices unspecified SMR Sep-2026 Release in Android 14, 15, 16, 17
TIMELINE Dec 11 Reserved by CNA Sep 9 Published (CNA: SamsungMobile)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H N N 6.9 .0041 34.2 —
AFFECTED Product Versions Fixed Enterprise Cloud Database all – —
TIMELINE Sep 9 Reserved by CNA Sep 9 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0039 32.0 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0037 30.3 —
AFFECTED Product Versions Fixed Comply 2.32 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Tanium)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0036 29.6 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0036 28.9 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0035 28.7 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0035 28.7 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H H H 9.6 .0035 28.7 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0035 28.7 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0035 28.7 —
AFFECTED Product Versions Fixed Chrome 153.0.8010.36 – —
TIMELINE Sep 8 Reserved by CNA Sep 9 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N L N 4.3 .0035 28.1 —
AFFECTED Product Versions Fixed Checkout Custom Fields Builder for WooCommerce unspecified —
TIMELINE Aug 13 Reserved by CNA Sep 9 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0034 27.3 —
AFFECTED Product Versions Fixed User Role Editor – PublishPress Capabilities: Access Control and User Roles unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 9 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-87487 | 8.3 | 27.2 | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87639 | 8.3 | 26.9 | Chrome | CWE-416 | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87646 | 9.6 | 26.5 | Chrome | CWE-416 | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 … | |
| CVE-2026-87654 | 9.6 | 26.4 | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.3… | |
| CVE-2026-87634 | 9.6 | 25.9 | Chrome | CWE-416 | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87643 | 9.6 | 25.9 | Chrome | CWE-190 | Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36… | |
| CVE-2026-87547 | 9.6 | 25.3 | Chrome | CWE-706 | Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.… | |
| CVE-2026-19800 | 4.9 | 24.3 | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | CWE-89 | Mail Mint <= 1.31.0 - Authenticated (Custom+) SQL Injection via 'status' Para… |
| CVE-2026-87555 | 4.7 | 24.0 | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8… | |
| CVE-2026-57825 | 5.7 | 23.9 | OCaml | opam | CWE-61 | In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism … |
| CVE-2026-87556 | 4.3 | 23.7 | Chrome | CWE-862 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87434 | 3.1 | 23.7 | Chrome | CWE-862 | Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87442 | 3.1 | 23.7 | Chrome | CWE-441 | Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed … | |
| CVE-2026-14505 | 6.6 | 23.5 | Tanium | Tanium Data Service | CWE-22 | Tanium addressed a path traversal vulnerability in Tanium Data Service. |
| CVE-2026-87548 | await | 23.0 | Chrome | CWE-754 | Improper state validation in Installer in Google Chrome prior to 153.0.8010.3… | |
| CVE-2026-83593 | 7.2 | 22.9 | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | CWE-79 | WPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversatio… |
| CVE-2026-87023 | 8.5 | 22.8 | Tanium | Comply | CWE-22 | Tanium addressed a path traversal vulnerability in Comply. |
| CVE-2026-87481 | 8.3 | 22.7 | Chrome | CWE-863 | Incorrect authorization in WebView in Google Chrome on on Android prior to 15… | |
| CVE-2025-3271 | 4.8 | 22.7 | OpenText™ | Documentum Webtop | CWE-79 | DOM-based XSS vulnerability in OpenText™ Documentum Webtop |
| CVE-2026-87636 | 8.8 | 22.7 | Chrome | CWE-843 | Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remot… | |
| CVE-2026-87470 | 9.6 | 22.2 | Chrome | CWE-1284 | Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.… | |
| CVE-2026-87520 | 9.6 | 22.2 | Chrome | CWE-416 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 … | |
| CVE-2026-87558 | 9.6 | 22.2 | Chrome | CWE-416 | Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 … | |
| CVE-2026-87479 | 8.3 | 22.2 | Chrome | CWE-807 | Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0… | |
| CVE-2026-87480 | 8.3 | 22.2 | Chrome | CWE-416 | Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87510 | 8.3 | 22.2 | Chrome | CWE-20 | Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 … | |
| CVE-2026-87524 | 8.3 | 22.2 | Chrome | CWE-416 | Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-87553 | 8.3 | 22.2 | Chrome | CWE-20 | Improper input validation in SiteIsolation in Google Chrome prior to 153.0.80… | |
| CVE-2026-87429 | await | 21.8 | Chrome | CWE-862 | Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.3… | |
| CVE-2026-87471 | await | 21.8 | Chrome | CWE-863 | Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010… | |
| CVE-2026-87513 | await | 21.8 | Chrome | CWE-862 | Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010… | |
| CVE-2026-84293 | 7.2 | 21.6 | addonsorg | Repeater Fields for Gravity Forms | CWE-79 | Repeater Fields for Gravity Forms <= 3.0.4 - Unauthenticated Stored Cross-Sit… |
| CVE-2026-87642 | 4.3 | 21.6 | Chrome | CWE-908 | Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-87527 | 9.6 | 21.3 | Chrome | CWE-122 | Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a re… | |
| CVE-2026-87734 | 7.5 | 21.3 | OCaml | utcp | CWE-923 | An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-or… |
| CVE-2026-87652 | 3.1 | 21.3 | Chrome | CWE-863 | Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87478 | 6.5 | 21.1 | Chrome | CWE-203 | Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87445 | 5.4 | 21.1 | Chrome | CWE-451 | UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-87435 | 5.3 | 21.1 | Chrome | CWE-200 | Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87439 | 5.3 | 21.1 | Chrome | CWE-200 | Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87472 | 4.2 | 21.1 | Chrome | CWE-20 | Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-15398 | 4.3 | 21.1 | arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | CWE-862 | Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) … |
| CVE-2026-87447 | await | 21.0 | Chrome | CWE-863 | Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87522 | await | 21.0 | Chrome | CWE-862 | Missing authorization in WebView in Google Chrome on on Android prior to 153.… | |
| CVE-2026-87030 | 8.5 | 20.6 | Tanium | Comply | CWE-22 | Tanium addressed a path traversal vulnerability in Comply. |
| CVE-2026-87436 | await | 20.5 | Chrome | CWE-459 | Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87446 | await | 20.5 | Chrome | CWE-459 | Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87464 | 9.6 | 20.5 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a rem… | |
| CVE-2026-87529 | 9.6 | 20.2 | Chrome | CWE-197 | Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87616 | 8.3 | 20.2 | Chrome | CWE-665 | Improper initialization in Views in Google Chrome on on Windows prior to 153.… | |
| CVE-2026-87549 | await | 20.3 | Chrome | CWE-459 | Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-14989 | 7.2 | 20.1 | wplegalpages | WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode | CWE-79 | Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Sc… |
| CVE-2026-87637 | 9.6 | 20.0 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.3… | |
| CVE-2026-87638 | 9.6 | 20.0 | Chrome | CWE-787 | Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed … | |
| CVE-2026-87650 | 9.6 | 20.0 | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a… | |
| CVE-2026-87648 | 8.3 | 20.0 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36… | |
| CVE-2026-87443 | 6.5 | 20.0 | Chrome | CWE-862 | Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87432 | 4.2 | 20.0 | Chrome | CWE-863 | Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36… | |
| CVE-2026-87632 | 4.3 | 19.7 | Chrome | CWE-79 | Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 … | |
| CVE-2026-87526 | 9.6 | 19.7 | Chrome | CWE-416 | Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a… | |
| CVE-2026-75905 | 4.3 | 19.6 | brechtvds | WP Recipe Maker | CWE-862 | WP Recipe Maker <= 10.8.0 - Missing Authorization to Authenticated (Contribut… |
| CVE-2026-87473 | await | 19.6 | Chrome | CWE-863 | Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.… | |
| CVE-2026-87441 | await | 19.2 | Chrome | CWE-862 | Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-19778 | 6.5 | 18.9 | aukejomm | WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping | CWE-89 | WPMR Google Feed Manager for WooCommerce <= 2.23.7 - Authenticated (Administr… |
| CVE-2026-87437 | 6.5 | 18.8 | Chrome | CWE-200 | Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87477 | 6.5 | 18.8 | Chrome | CWE-200 | Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a re… | |
| CVE-2026-87635 | 5.4 | 18.8 | Chrome | CWE-451 | UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87644 | 8.3 | 18.7 | Chrome | CWE-863 | Incorrect authorization in Views in Google Chrome on on Windows prior to 153.… | |
| CVE-2026-19944 | 4.9 | 18.7 | themeum | WP Crowdfunding | CWE-89 | WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'w… |
| CVE-2026-7804 | 6.1 | 17.8 | woobewoo | Product Filter for WooCommerce by WBW | CWE-79 | Product Filter for WooCommerce by WBW <= 3.4.2 - Reflected Cross-Site Scripti… |
| CVE-2026-87508 | 4.3 | 17.8 | Chrome | CWE-863 | Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87485 | 3.1 | 17.8 | Chrome | CWE-863 | Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-87483 | await | 17.8 | Chrome | CWE-863 | Incorrect authorization in Browser in Google Chrome on on Android prior to 15… | |
| CVE-2026-87656 | await | 17.8 | Chrome | CWE-754 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.801… | |
| CVE-2026-87724 | 6.5 | 17.7 | torprject | Tor | CWE-669 | Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST… |
| CVE-2026-75966 | 6.4 | 17.5 | eteubert | Podlove Podcast Publisher | CWE-79 | Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cros… |
| CVE-2026-87455 | 9.6 | 17.2 | Chrome | CWE-416 | Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remo… | |
| CVE-2026-87581 | 9.6 | 17.2 | Chrome | CWE-416 | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87607 | 9.6 | 17.2 | Chrome | CWE-416 | Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 al… | |
| CVE-2026-87617 | 8.8 | 17.2 | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87550 | 4.3 | 17.3 | Chrome | CWE-116 | Improper encoding or escaping of output in CSS in Google Chrome prior to 153.… | |
| CVE-2026-87431 | await | 17.2 | Chrome | CWE-862 | Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2025-7062 | 5.2 | 16.8 | Lumi Education UG | h5p-nodejs-library | CWE-20 | Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library… |
| CVE-2026-49310 | 8.6 | 16.3 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the event notification module. Impact: Su… |
| CVE-2026-11838 | 4.3 | 16.3 | Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. | Library Reservation System | CWE-306 | Improper Authorization in Yordam Informatics' Library Reservation System |
| CVE-2026-87572 | 8.3 | 16.1 | Chrome | CWE-74 | Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remot… | |
| CVE-2026-87557 | 4.3 | 16.0 | Chrome | CWE-862 | Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8… | |
| CVE-2026-87475 | await | 16.0 | Chrome | CWE-862 | Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87515 | await | 16.0 | Chrome | CWE-863 | Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87519 | await | 16.0 | Chrome | CWE-863 | Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.… | |
| CVE-2026-14359 | 8.8 | 15.8 | Yith | YITH WooCommerce Waitlist Premium | CWE-269 | YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Pri… |
| CVE-2026-87582 | 8.3 | 15.9 | Chrome | CWE-441 | Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-19733 | 5.3 | 15.8 | Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. | Library Information and Document Automation Program | CWE-918 | SSRF in Yordam Informatics's Library Automation System |
| CVE-2026-19946 | 4.3 | 15.9 | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | CWE-862 | Awesome Support <= 6.3.9 - Missing Authorization to Authenticated (Subscriber… |
| CVE-2026-87657 | 3.1 | 15.8 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87647 | 3.4 | 15.8 | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87433 | await | 15.5 | Chrome | CWE-367 | Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a r… | |
| CVE-2026-84908 | 5.3 | 15.5 | getwpfunnels | WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell | CWE-862 | WPFunnels <= 3.12.13 - Missing Authorization to Unauthenticated Arbitrary Pro… |
| CVE-2026-87484 | 5.4 | 15.3 | Chrome | CWE-451 | UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87507 | 5.4 | 15.3 | Chrome | CWE-451 | UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87518 | 5.3 | 15.3 | Chrome | CWE-203 | Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 15… | |
| CVE-2026-87516 | 4.3 | 15.3 | Chrome | CWE-203 | Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 … | |
| CVE-2026-87630 | 4.3 | 15.3 | Chrome | CWE-190 | Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87559 | 4.2 | 15.3 | Chrome | CWE-451 | UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87521 | 3.1 | 15.3 | Chrome | CWE-200 | Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87645 | await | 14.9 | Chrome | CWE-754 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.801… | |
| CVE-2026-87649 | await | 14.9 | Chrome | CWE-451 | UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-12956 | 5.3 | 14.8 | arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | CWE-862 | Eventin <= 4.1.22 - Missing Authorization to Unauthenticated Arbitrary Order … |
| CVE-2026-87579 | 8.8 | 14.7 | Chrome | CWE-122 | Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a r… | |
| CVE-2026-87655 | 5.4 | 14.6 | Chrome | CWE-1021 | Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a r… | |
| CVE-2026-87504 | 9.6 | 14.6 | Chrome | CWE-416 | Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remo… | |
| CVE-2026-87609 | 9.6 | 14.6 | Chrome | CWE-416 | Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 a… | |
| CVE-2026-13359 | 7.2 | 14.6 | bestweblayout | Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress | CWE-79 | Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Sit… |
| CVE-2026-87528 | 9.6 | 14.3 | Chrome | CWE-843 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-87612 | 8.8 | 14.3 | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87618 | 8.3 | 14.3 | Chrome | CWE-706 | Incorrect reference resolution in Storage in Google Chrome on on Windows prio… | |
| CVE-2026-87476 | 6.5 | 14.1 | Chrome | CWE-863 | Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87629 | 6.5 | 14.1 | Chrome | CWE-863 | Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87658 | 4.3 | 13.4 | Chrome | CWE-200 | Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87564 | 4.3 | 13.3 | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87456 | 3.4 | 13.3 | Chrome | CWE-908 | Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-19945 | 6.4 | 13.1 | themeum | WP Crowdfunding | CWE-79 | WP Crowdfunding <= 2.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scri… |
| CVE-2026-87653 | 5.4 | 13.1 | Chrome | CWE-451 | UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 15… | |
| CVE-2026-87640 | await | 13.1 | Chrome | CWE-125 | Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8… | |
| CVE-2026-87466 | 4.3 | 13.0 | Chrome | CWE-863 | Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87469 | await | 12.5 | Chrome | CWE-20 | Improper input validation in Extensions in Google Chrome prior to 153.0.8010.… | |
| CVE-2026-87503 | await | 12.5 | Chrome | CWE-841 | Inappropriate implementation in Downloads in Google Chrome on on Android prio… | |
| CVE-2026-87600 | await | 12.5 | Chrome | CWE-20 | Improper input validation in Safebrowsing in Google Chrome on on Android prio… | |
| CVE-2026-87631 | 6.5 | 12.0 | Chrome | CWE-862 | Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed … | |
| CVE-2026-87651 | 4.3 | 12.0 | Chrome | CWE-863 | Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87494 | 9.6 | 11.8 | Chrome | CWE-416 | Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-87500 | 9.6 | 11.8 | Chrome | CWE-129 | Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8… | |
| CVE-2026-87621 | 9.6 | 11.8 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.80… | |
| CVE-2026-87460 | 8.8 | 11.8 | Chrome | CWE-416 | Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87536 | 8.8 | 11.8 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87542 | 8.8 | 11.8 | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a rem… | |
| CVE-2026-87587 | 8.8 | 11.8 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87588 | 8.8 | 11.8 | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed … | |
| CVE-2026-87506 | 8.3 | 11.8 | Chrome | CWE-250 | Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed … | |
| CVE-2026-87604 | 8.3 | 11.8 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a… | |
| CVE-2026-80177 | 6.5 | 11.9 | Dell | Secure Connect Gateway 5.0 - Application | CWE-89 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-19797 | 6.1 | 11.9 | gm_alex | User Access Manager | CWE-79 | User Access Manager <= 2.3.18 - Reflected Cross-Site Scripting via 'tab_group… |
| CVE-2026-87511 | await | 11.8 | Chrome | CWE-862 | Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87737 | 5.9 | 11.5 | OCaml | mirage-crypto-ec | CWE-208 | An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCam… |
| CVE-2026-87736 | 4.3 | 11.5 | OCaml | mirage-crypto-ec | CWE-125 | An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCam… |
| CVE-2026-80055 | 4.4 | 11.3 | Dell | Secure Connect Gateway 5.0 - Application | CWE-90 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87036 | 8.1 | 11.2 | Tanium | Comply | CWE-862 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87075 | 8.1 | 11.2 | Tanium | Comply | CWE-863 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87565 | 6.5 | 11.0 | Chrome | CWE-200 | Information leak in Passwords in Google Chrome on on Android prior to 153.0.8… | |
| CVE-2026-87458 | 5.4 | 11.0 | Chrome | CWE-451 | UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87496 | 5.4 | 11.0 | Chrome | CWE-451 | UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allow… | |
| CVE-2026-81647 | 5.3 | 11.0 | Huawei | HarmonyOS | CWE-680 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful e… |
| CVE-2026-87574 | 4.3 | 11.0 | Chrome | CWE-200 | Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87451 | 3.1 | 11.0 | Chrome | CWE-200 | Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87539 | 3.1 | 11.0 | Chrome | CWE-203 | Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87492 | 9.6 | 10.8 | Chrome | CWE-863 | Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-77186 | 6.4 | 10.9 | joedolson | My Calendar – Accessible Event Manager | CWE-79 | My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-87561 | 4.3 | 10.8 | Chrome | CWE-863 | Incorrect authorization in Web Authentication in Google Chrome prior to 153.0… | |
| CVE-2026-87626 | await | 10.9 | Chrome | CWE-863 | Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome pri… | |
| CVE-2026-17149 | 6.4 | 10.7 | saadiqbal | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | CWE-79 | myCred – Points Management System For Gamification, Ranks, Badges, and Loyalt… |
| CVE-2026-87083 | 5.1 | 10.8 | tile-ai | tilelang | CWE-20 | tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_d… |
| CVE-2026-87517 | 3.1 | 10.5 | Chrome | CWE-367 | Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 al… | |
| CVE-2026-87633 | 8.6 | 10.2 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a loc… | |
| CVE-2026-87535 | await | 10.2 | Chrome | CWE-221 | Information loss or omission in Safebrowsing in Google Chrome on on Mac prior… | |
| CVE-2026-87084 | 7.7 | 10.0 | Tanium | Enforce | CWE-918 | Tanium addressed a server-side request forgery vulnerability in Enforce. |
| CVE-2025-46808 | 6.8 | 10.1 | SUSE | neuvector | CWE-532 | Sensitive information is leaked into NeuVector’s manager container logs |
| CVE-2026-13709 | 6.4 | 10.0 | iqonicdesign | Graphina – Charts and Graphs For Elementor | CWE-79 | Graphina <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting via … |
| CVE-2026-87453 | 5.3 | 9.9 | Chrome | CWE-441 | Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87538 | 4.2 | 9.9 | Chrome | CWE-1021 | Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remot… | |
| CVE-2026-87452 | 3.1 | 9.9 | Chrome | CWE-863 | Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010… | |
| CVE-2026-87613 | 9.0 | 9.7 | Chrome | CWE-706 | Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.… | |
| CVE-2026-87585 | 8.8 | 9.7 | Chrome | CWE-415 | Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 a… | |
| CVE-2026-87625 | 8.8 | 9.7 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87641 | await | 9.5 | Chrome | CWE-362 | Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a r… | |
| CVE-2026-8615 | 4.3 | 9.4 | ghera74 | ilGhera Reviso Exporter for WooCommerce | CWE-862 | ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to A… |
| CVE-2026-87591 | await | 9.4 | Chrome | CWE-863 | Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36… | |
| CVE-2026-14892 | 4.3 | 9.3 | Tanium | Tanium Server | CWE-863 | Tanium addressed an improper access controls vulnerability in Tanium Server. |
| CVE-2026-77187 | 6.4 | 9.1 | joedolson | My Calendar – Accessible Event Manager | CWE-79 | My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripti… |
| CVE-2026-87523 | 5.3 | 9.0 | Chrome | CWE-367 | Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87590 | await | 8.9 | Chrome | CWE-20 | Improper input validation in Passwords in Google Chrome prior to 153.0.8010.3… | |
| CVE-2026-87537 | 8.1 | 8.8 | Chrome | CWE-862 | Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-14962 | 8.6 | 8.7 | Unknown | ELEX WooCommerce Request a Quote | CWE-89 | ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id |
| CVE-2026-11821 | 5.4 | 8.8 | arraytics | Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce | CWE-862 | Eventin <= 4.1.17 - Missing Authorization to Authenticated (Subscriber+) Noti… |
| CVE-2026-87497 | 4.3 | 8.8 | Chrome | CWE-908 | Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87562 | 4.3 | 8.8 | Chrome | CWE-706 | Incorrect reference resolution in Accessibility in Google Chrome on on Mac pr… | |
| CVE-2026-87576 | 3.4 | 8.8 | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8… | |
| CVE-2026-87034 | 8.3 | 8.7 | Tanium | Comply | CWE-89 | Tanium addressed a SQL injection vulnerability in Comply. |
| CVE-2026-87560 | 4.3 | 8.6 | Chrome | CWE-862 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87577 | 4.3 | 8.6 | Chrome | CWE-863 | Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87598 | 4.3 | 8.6 | Chrome | CWE-863 | Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010… | |
| CVE-2026-87622 | 4.3 | 8.6 | Chrome | CWE-862 | Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87498 | 3.1 | 8.6 | Chrome | CWE-862 | Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87614 | 3.1 | 8.6 | Chrome | CWE-863 | Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010… | |
| CVE-2026-87580 | await | 8.6 | Chrome | CWE-863 | Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.801… | |
| CVE-2026-87584 | await | 8.6 | Chrome | CWE-863 | Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87489 | 8.8 | 8.2 | Chrome | CWE-119 | Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a rem… | |
| CVE-2026-78377 | 6.1 | 8.2 | Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. | Library Information and Document Automation Program | CWE-601 | Open Redirect in Yordam Informatics's Library Automation System |
| CVE-2026-87573 | 4.3 | 8.2 | Chrome | CWE-20 | Improper input validation in Network in Google Chrome prior to 153.0.8010.36 … | |
| CVE-2026-87450 | await | 8.2 | Chrome | CWE-863 | Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.3… | |
| CVE-2026-87532 | await | 8.2 | Chrome | CWE-754 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.801… | |
| CVE-2026-87541 | await | 8.2 | Chrome | CWE-200 | Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-80123 | 7.5 | 8.0 | Dell | Secure Connect Gateway 5.0 - Application | CWE-918 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-19855 | 6.5 | 8.0 | Unknown | CleanTalk | CWE-74 | Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Ar… |
| CVE-2026-85117 | 6.5 | 8.0 | Unknown | Contact Form 7 Captcha | CWE-74 | Contact Form 7 Captcha 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Ex… |
| CVE-2026-79974 | 6.4 | 8.0 | Dell | Secure Connect Gateway 5.0 - Application | CWE-287 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87486 | 4.0 | 7.6 | Chrome | CWE-1021 | Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to … | |
| CVE-2026-87569 | 8.8 | 7.5 | Chrome | CWE-862 | Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowe… | |
| CVE-2026-87468 | await | 7.5 | Chrome | CWE-863 | Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87493 | await | 7.5 | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87499 | await | 7.5 | Chrome | CWE-863 | Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87543 | await | 7.5 | Chrome | CWE-862 | Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87589 | await | 7.5 | Chrome | CWE-863 | Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010… | |
| CVE-2026-87595 | await | 7.5 | Chrome | CWE-918 | Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36… | |
| CVE-2026-87603 | await | 7.5 | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87606 | await | 7.5 | Chrome | CWE-862 | Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.3… | |
| CVE-2026-87610 | await | 7.5 | Chrome | CWE-863 | Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-84068 | 8.6 | 7.3 | Unknown | Quentn WP | CWE-89 | Quentn WP 1.2.13 - 1.2.14 - Unauthenticated SQLi via 'qntn_wp' Parameter |
| CVE-2026-87551 | await | 7.4 | Chrome | CWE-295 | Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.… | |
| CVE-2026-87032 | 4.3 | 7.3 | Tanium | Tanium Server | CWE-200 | Tanium addressed an information disclosure vulnerability in Tanium Server. |
| CVE-2026-87035 | 4.3 | 7.3 | Tanium | Comply | CWE-200 | Tanium addressed an information disclosure vulnerability in Comply. |
| CVE-2026-21103 | 6.8 | 7.0 | Samsung Mobile | Samsung Mobile Devices | — | Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows ph… |
| CVE-2026-87073 | 6.5 | 7.1 | Tanium | Comply | CWE-862 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87454 | 6.5 | 7.0 | Chrome | CWE-200 | Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.… | |
| CVE-2026-87459 | 6.5 | 7.0 | Chrome | CWE-203 | Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87545 | 6.5 | 7.0 | Chrome | CWE-200 | Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 … | |
| CVE-2026-87620 | 6.5 | 7.0 | Chrome | CWE-203 | Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87623 | 6.5 | 7.0 | Chrome | CWE-203 | Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87462 | 5.4 | 7.0 | Chrome | CWE-451 | UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87501 | 5.4 | 7.0 | Chrome | CWE-451 | UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87599 | 5.4 | 7.0 | Chrome | CWE-20 | Improper input validation in Interstitials in Google Chrome prior to 153.0.80… | |
| CVE-2026-87566 | 5.3 | 7.0 | Chrome | CWE-203 | Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87495 | 4.3 | 7.0 | Chrome | CWE-200 | Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87586 | 4.3 | 7.0 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a… | |
| CVE-2026-87592 | 4.3 | 7.0 | Chrome | CWE-125 | Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87596 | 4.3 | 7.0 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a… | |
| CVE-2026-87619 | 4.3 | 7.0 | Chrome | CWE-203 | Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 al… | |
| CVE-2026-87531 | 3.1 | 7.0 | Chrome | CWE-200 | Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a re… | |
| CVE-2026-87534 | await | 7.0 | Chrome | CWE-862 | Missing authorization in WebView in Google Chrome on on Android prior to 153.… | |
| CVE-2026-16960 | 7.5 | 6.9 | Unknown | Loops & Logic | CWE-200 | Loops & Logic < 4.3.0 - Unauthenticated User Data and Site Option Disclosure |
| CVE-2026-87449 | 4.3 | 6.8 | Chrome | CWE-352 | Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome … | |
| CVE-2026-87072 | 7.1 | 6.7 | Tanium | Comply | CWE-862 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87546 | await | 6.7 | Chrome | CWE-704 | Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac … | |
| CVE-2026-87627 | await | 6.7 | Chrome | CWE-436 | Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 1… | |
| CVE-2026-87514 | 8.1 | 6.6 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a loc… | |
| CVE-2026-87025 | 5.4 | 6.6 | Tanium | Comply | CWE-639 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87033 | 5.4 | 6.6 | Tanium | Comply | CWE-639 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87048 | 5.4 | 6.6 | Tanium | Comply | CWE-862 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87628 | 8.3 | 6.4 | Chrome | CWE-416 | Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adj… | |
| CVE-2026-87540 | 5.4 | 6.4 | Chrome | CWE-863 | Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87594 | 5.3 | 6.4 | Chrome | CWE-863 | Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.… | |
| CVE-2026-87465 | 4.2 | 6.4 | Chrome | CWE-863 | Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 … | |
| CVE-2026-87502 | 4.2 | 6.4 | Chrome | CWE-441 | Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed… | |
| CVE-2026-87611 | 3.1 | 6.4 | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a… | |
| CVE-2026-87530 | 8.1 | 6.2 | Chrome | CWE-427 | Uncontrolled search path element in CredentialProvider in Google Chrome on on… | |
| CVE-2026-87544 | await | 6.1 | Chrome | CWE-863 | Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36… | |
| CVE-2026-87575 | await | 6.1 | Chrome | CWE-863 | Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-87601 | 7.5 | 6.0 | Chrome | CWE-362 | Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote… | |
| CVE-2026-87570 | 8.8 | 6.0 | Chrome | CWE-863 | Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010… | |
| CVE-2026-87505 | await | 6.0 | Chrome | CWE-863 | Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36… | |
| CVE-2025-15690 | 6.8 | 5.8 | Unknown | Content Mask | CWE-79 | Content Mask 1.7.1 - 1.8.5.5 - Contributor+ Stored XSS via Post Scripts and S… |
| CVE-2026-78491 | 8.2 | 5.7 | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87490 | 6.5 | 5.8 | Chrome | CWE-200 | Information leak in Transactions Platform in Google Chrome prior to 153.0.801… | |
| CVE-2026-87593 | 6.5 | 5.8 | Chrome | CWE-200 | Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a… | |
| CVE-2026-87583 | 5.4 | 5.8 | Chrome | CWE-451 | UI misrepresentation in Passwords in Google Chrome on on Android prior to 153… | |
| CVE-2026-87602 | 4.7 | 5.8 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.801… | |
| CVE-2026-87624 | 4.2 | 5.8 | Chrome | CWE-451 | UI misrepresentation in Passwords in Google Chrome on on Android prior to 153… | |
| CVE-2026-87597 | 4.8 | 5.6 | Chrome | CWE-451 | UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 15… | |
| CVE-2026-87567 | 4.3 | 5.6 | Chrome | CWE-451 | UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36… | |
| CVE-2026-87568 | 4.3 | 5.6 | Chrome | CWE-20 | Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36… | |
| CVE-2026-87605 | 5.3 | 5.1 | Chrome | CWE-862 | Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 all… | |
| CVE-2026-84113 | 4.1 | 5.1 | Unknown | Quentn WP | CWE-89 | Quentn WP < 1.2.15 - Admin+ SQLi via 'orderby'/'order' Parameter |
| CVE-2026-87047 | 6.3 | 4.8 | Tanium | Comply | CWE-639 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-80440 | 4.8 | 4.9 | Unknown | Hustle | CWE-74 | Hustle < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution via Success… |
| CVE-2026-87509 | 8.1 | 4.7 | Chrome | CWE-863 | Incorrect authorization in Updater in Google Chrome on on Windows prior to 15… | |
| CVE-2026-83541 | 6.8 | 4.7 | Unknown | Sina Extension for Elementor | CWE-79 | Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Tab… |
| CVE-2026-85418 | 5.4 | 4.7 | Unknown | Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More | CWE-79 | Orbit Fox < 3.0.9 - Contributor+ Stored XSS via Beaver Builder Pricing Table … |
| CVE-2026-87019 | 4.3 | 4.7 | Tanium | Comply | CWE-639 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87046 | 4.3 | 4.7 | Tanium | Comply | CWE-863 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-78494 | 7.4 | 4.5 | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87461 | 4.3 | 4.5 | Chrome | CWE-200 | Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a re… | |
| CVE-2026-87482 | await | 4.5 | Chrome | CWE-319 | Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on… | |
| CVE-2026-87552 | await | 4.5 | Chrome | CWE-862 | Missing authorization in TrustedWebActivities in Google Chrome on on Android … | |
| CVE-2026-79640 | 5.4 | 4.3 | Dell | Secure Connect Gateway 5.0 - Application | CWE-89 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87525 | 2.7 | 4.3 | Chrome | CWE-125 | Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.… | |
| CVE-2026-87608 | await | 4.3 | Chrome | CWE-295 | Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010… | |
| CVE-2026-18042 | 5.3 | 4.2 | Unknown | WP Travel | CWE-862 | WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation |
| CVE-2026-13144 | 3.7 | 4.2 | Unknown | WP Travel | CWE-284 | WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset |
| CVE-2026-13146 | 3.7 | 4.2 | Unknown | WP Travel | CWE-639 | WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR |
| CVE-2026-80339 | 5.3 | 4.1 | Unknown | Payment Plugins for Stripe WooCommerce | CWE-200 | Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PI… |
| CVE-2026-80340 | 5.3 | 4.1 | Unknown | Payment Plugins for PayPal WooCommerce | CWE-200 | Payment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PI… |
| CVE-2026-81021 | 5.3 | 4.1 | Unknown | SupportCandy | CWE-200 | SupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Disclosure |
| CVE-2026-81022 | 5.3 | 4.1 | Unknown | SupportCandy | CWE-200 | SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Au… |
| CVE-2026-84222 | 5.3 | 4.1 | Unknown | Kirki | CWE-200 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via … |
| CVE-2026-16272 | 9.1 | 4.0 | PayTR Payment and Electronic Money Institution Inc. | PayTR Virtual Pos iFrame API (v9x) WHMCS Module | CWE-348 | Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iF… |
| CVE-2026-75861 | 6.5 | 3.8 | Unknown | Ultimate Gift Cards for WooCommerce | CWE-862 | Ultimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft an… |
| CVE-2026-87735 | 4.3 | 3.8 | OCaml | mirage-crypto-pk | CWE-1284 | An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCam… |
| CVE-2026-87766 | 8.8 | 3.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files o… |
| CVE-2026-87615 | 5.4 | 3.6 | Chrome | CWE-362 | Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-87037 | 5.4 | 3.5 | Tanium | Comply | CWE-862 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-80122 | 7.3 | 3.4 | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-21094 | 6.1 | 3.3 | Samsung Mobile | Samsung Mobile Devices | — | Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 a… |
| CVE-2026-82848 | 5.3 | 3.4 | Unknown | Masteriyo LMS | CWE-862 | Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure |
| CVE-2026-85037 | 5.3 | 3.4 | Unknown | Sunshine Photo Cart | CWE-639 | Sunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOR |
| CVE-2026-81741 | 4.7 | 3.4 | Unknown | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-601 | Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter |
| CVE-2026-81644 | 4.3 | 3.3 | Huawei | HarmonyOS | CWE-264 | DoS vulnerability in the preview service module. Impact: Successful exploitat… |
| CVE-2026-87563 | 4.3 | 3.4 | Chrome | CWE-346 | Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allo… | |
| CVE-2026-87554 | 8.1 | 3.3 | Chrome | CWE-367 | Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.80… | |
| CVE-2026-79973 | 6.3 | 3.3 | Dell | Secure Connect Gateway 5.0 - Application | CWE-567 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79636 | 7.0 | 3.1 | Dell | Secure Connect Gateway 5.0 - Application | CWE-297 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80341 | 5.9 | 3.1 | Unknown | Payment Plugins for PayPal WooCommerce | CWE-863 | Payment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment … |
| CVE-2026-85133 | 5.4 | 3.1 | Unknown | WPLP Cookie Consent | CWE-862 | WPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple … |
| CVE-2026-82185 | 4.3 | 3.1 | Unknown | WPLP Cookie Consent | CWE-862 | WPLP Cookie Consent < 4.4.2 - Subscriber+ Banner Settings Overwrite and A/B T… |
| CVE-2026-85132 | 4.3 | 3.1 | Unknown | WPLP Cookie Consent | CWE-862 | WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosu… |
| CVE-2026-21097 | 4.6 | 2.8 | Samsung Mobile | Samsung Mobile Devices | — | Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 R… |
| CVE-2026-87578 | 8.3 | 2.8 | Chrome | CWE-416 | Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an… | |
| CVE-2026-87571 | await | 2.7 | Chrome | CWE-295 | Improper certificate validation in Loader in Google Chrome prior to 153.0.801… | |
| CVE-2026-12855 | 8.2 | 2.5 | Insyde Software | InsydeH2O | CWE-20 | H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code … |
| CVE-2026-87533 | 8.1 | 2.4 | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a … | |
| CVE-2026-6485 | 8.2 | 2.2 | Insyde Software | InsydeH2O | CWE-489 | UEFI BIOS embedded Shell can be used to bypass Secure Boot |
| CVE-2026-87463 | 4.8 | 2.3 | Chrome | CWE-863 | Incorrect authorization in Certificate in Google Chrome on on Android prior t… | |
| CVE-2026-21087 | 8.6 | 2.2 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows loc… |
| CVE-2026-87088 | 7.0 | 2.1 | Tanium | Enforce | CWE-78 | Tanium addressed an unauthorized code execution vulnerability in Enforce. |
| CVE-2026-21088 | 6.9 | 2.0 | Samsung Mobile | Samsung Mobile Devices | — | Improper input validation in loading a subtitle frame in libsubextractor.so p… |
| CVE-2026-21102 | 9.3 | 1.8 | Samsung Mobile | Samsung Mobile Devices | — | Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privil… |
| CVE-2026-21101 | 8.4 | 1.8 | Samsung Mobile | Samsung Mobile Devices | — | Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 a… |
| CVE-2026-83537 | 5.3 | 1.7 | Unknown | WP Express Checkout | CWE-345 | WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process… |
| CVE-2026-21089 | 6.9 | 1.5 | Samsung Mobile | Samsung Mobile Devices | — | Improper input validation in removing style tag in libsubextractor.so prior t… |
| CVE-2026-21106 | 5.1 | 1.4 | Samsung Mobile | Samsung Cloud Assistant | — | Improper verification of intent by broadcast receiver in Samsung Cloud Assist… |
| CVE-2026-21110 | 6.9 | 1.3 | Samsung Mobile | libsavscmn.so | — | Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attacke… |
| CVE-2026-21085 | 8.4 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 all… |
| CVE-2026-21086 | 4.8 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows… |
| CVE-2026-21098 | 6.9 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 al… |
| CVE-2026-21100 | 6.9 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows lo… |
| CVE-2026-21108 | 6.9 | 1.2 | Samsung Mobile | Bixby Touch | CWE-926 | Improper export of android application components in Bixby Touch prior to ver… |
| CVE-2026-87733 | 6.2 | 1.2 | OCaml | mirage-crypto-ec | CWE-295 | An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCa… |
| CVE-2026-21105 | 5.9 | 1.2 | Samsung Mobile | Collection | — | Improper access control in Collection prior to version 1.0.1.14 in Android 15… |
| CVE-2026-79967 | 5.6 | 1.2 | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-21099 | 5.1 | 1.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 a… |
| CVE-2026-21109 | 2.1 | 1.2 | Samsung Mobile | Watch Plugin | — | Improper access control in Watch Plugin prior to Android Watch 17 allows loca… |
| CVE-2026-21104 | 7.1 | 0.9 | Samsung Mobile | Samsung Mobile Devices | — | Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Releas… |
| CVE-2026-80124 | 5.5 | 1.0 | Dell | Secure Connect Gateway 5.0 - Application | CWE-532 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-82184 | 5.3 | 0.9 | Unknown | WPLP Cookie Consent | CWE-862 | WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update |
| CVE-2026-21112 | 5.1 | 0.9 | Samsung Mobile | Samsung Tips | — | Improper input validation in Samsung Tips prior to Android 17 allows local at… |
| CVE-2026-21107 | 6.9 | 0.9 | Samsung Mobile | Samsung Notes | CWE-787 | Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local a… |
| CVE-2026-21111 | 6.9 | 0.9 | Samsung Mobile | libsthmbc | — | Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attacker… |
| CVE-2026-21090 | 4.8 | 0.9 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 al… |
| CVE-2026-21091 | 4.8 | 0.9 | Samsung Mobile | Samsung Mobile Devices | — | Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1… |
| CVE-2026-87457 | 8.1 | 0.8 | Chrome | CWE-367 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-87467 | 8.1 | 0.8 | Chrome | CWE-362 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-12858 | 8.5 | 0.7 | ESET spol. s.r.o. | ESET AV Remover (standalone) | CWE-269 | Local privilege escalation vulnerability in ESET AV Remover |
| CVE-2026-80175 | 3.3 | 0.7 | Dell | Secure Connect Gateway 5.0 - Application | CWE-538 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-49311 | 6.2 | 0.6 | Huawei | HarmonyOS | CWE-275 | Permission control vulnerability in the event notification module.Impact: Suc… |
| CVE-2026-21093 | 5.6 | 0.6 | Samsung Mobile | Samsung Mobile Devices | — | Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1… |
| CVE-2026-21113 | 4.8 | 0.5 | Samsung Mobile | Visual Voicemail | — | Improper export of android application components in Visual Voicemail prior t… |
| CVE-2026-81646 | 5.9 | 0.4 | Huawei | HarmonyOS | CWE-125 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful e… |
| CVE-2026-49314 | 7.3 | 0.3 | Huawei | HarmonyOS | CWE-125 | OOB write vulnerability in the rendering and composition module. Impact: Succ… |
| CVE-2026-49309 | 4.8 | 0.3 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the Settings module. Impact: Successful e… |
| CVE-2026-49315 | 7.1 | 0.2 | Huawei | HarmonyOS | CWE-264 | DoS vulnerability in the input device module. Impact: Successful exploitation… |
| CVE-2026-41987 | 6.2 | 0.2 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the app management module. Impact: Succes… |
| CVE-2026-87732 | 6.2 | 0.1 | OCaml | mirage-crypto | CWE-347 | An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. … |
| CVE-2026-49313 | 5.5 | 0.1 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the app lock module. Impact: Successful e… |
| CVE-2026-49312 | 4.0 | 0.1 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in the window module. Impact: Successful exp… |
| CVE-2026-85978 | 10.0 | — | Perforce | Akana | CWE-41 | Unauthenticated Remote Code Execution in Akana API Platform |
| CVE-2026-87827 | 10.0 | — | KGUARD | KGUARD_firmware | CWE-1188 | KGUARD DVR unauthenticated remote command execution vulnerability |
| CVE-2026-67401 | 9.9 | — | WebPros | cPanel | CWE-89 | A vulnerability in cPanel allows a mail-enabled account to achieve remote cod… |
| CVE-2026-79689 | 9.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-78 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79941 | 9.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-77 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80172 | 9.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-345 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-85102 | 9.8 | — | checkpoint | Quantum Security Gateway | CWE-295 | Improper Certificate Validation in Quantum Security Gateway |
| CVE-2026-85103 | 9.8 | — | checkpoint | Quantum Security Gateway | CWE-122 | Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding |
| CVE-2026-54694 | 9.6 | — | NationalSecurityAgency | skills-service | CWE-20 | NationalSecurityAgency/skills-service has Stored XSS via User Registration En… |
| CVE-2026-87931 | 9.4 | — | Behavioral Technology Group | Pavlok Behavioral Conditioning Wearable | CWE-120 | Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Not… |
| CVE-2026-47156 | 9.3 | — | mantisbt | mantisbt | CWE-287 | MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Adminis… |
| CVE-2026-87929 | 9.3 | — | MaxSite | MaxSite CMS | CWE-321 | MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key |
| CVE-2026-88069 | 9.3 | — | pandora-analysis | pandora | CWE-22 | Path traversal in Pandora archive extractor allows arbitrary file writes outs… |
Results continue: ranks 401–654.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-09 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.