boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 9, 2026 · all times UTC← 2026-09-08 · archive

Security Box Score — September 9, 2026

CISA adds 4 to KEV; 654 CVEs published, led by Google (231).

654 CVEs published September 9, 2026: 55 critical, 188 high, 280 medium, 42 low; 1 in the KEV catalog at press time; 4 with a public exploit reference; 89 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 254 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published440139287——
KEV catalog size1703

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2491 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux2004283420202170611230.17.8.0016+154 ▲
microsoft9752874189197269716289301.07.8.0044+942 ▲
google360252631591710611067980.37.5.0025+317 ▲
red hat596844328631837200.06.8.0028+17 ▲
apple0316598516578882.56.5.0029-1 ▼
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse1038521111000.07.5.0035+5 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco12962446260571414.67.5.0041-18 ▼
ubiquiti059362210335.19.1.00490
fortinet93981117329717.96.7.0038+9 ▲
palo alto networks0371321121325.44.7.00200
netgear23400277000.04.3.0025+2 ▲
ivanti102410122025520.88.8.0146+10 ▲
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050+3 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache19528107221178133320.47.5.0049-41 ▼
mozilla352228079630900.08.1.0029+34 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+1 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
adobe17077657344365102040.57.5.0023+162 ▲
ibm726911533092209610.17.5.0029+40 ▲
progress2631439100611.68.1.0035-9 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+5 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link8531619108300.08.5.0157-7 ▼
siemens145163393000.07.3.0018+14 ▲
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric71611140000.08.5.0032+7 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
hikvision060420000.07.2.00400
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1272982114011918210.37.2.0019+119 ▲
sourcecodester261950011481000.05.5.0028+15 ▲
spring017012598415000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
itsourcecode241400036104000.02.1.0026+16 ▲
mongodb34132481434100.07.1.0026+34 ▲
elastic42129127983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-72898.942299.810.0
CVE-2026-60004.867899.79.8
CVE-2026-73570.323898.28.9
CVE-2026-71362.251497.89.1
CVE-2026-64849.164196.89.3
CVE-2026-48376.154896.65.4
CVE-2026-83549.138496.37.8
CVE-2026-19681.078094.39.4
CVE-2026-82329.076794.29.8
CVE-2026-83548.074594.110.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7289810.0.9422KEV
CVE-2026-8354810.0.0745KEV
CVE-2026-4836210.0.0431
CVE-2026-7565010.0.0215KEV
CVE-2026-1918810.0.0193
CVE-2026-8615210.0.0186
CVE-2026-5823110.0.0171
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
Most disclosures (vendor)
VendorCVEs
linux1455
microsoft1419
oracle890
google719
ibm430
adobe263
red hat212
dell191
apache112
splunk110
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco14
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
oracle4
solarwinds4
Most-affected ecosystems
EcosystemAdvisories
Maven34
Packagist34
npm14
PyPI12
RubyGems2
Go1
Fastest to KEV
CVEVendorDays
CVE-2026-20349Cisco0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-72898Metabase0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171757
CVE-2021-27102n/a2021-11-171757
CVE-2021-27101n/a2021-11-171757
CVE-2021-27103n/a2021-11-171757
CVE-2021-21017Adobe2021-11-171757
CVE-2021-28550Adobe2021-11-171757
CVE-2021-42013Apache Software Foundation2021-11-171757
CVE-2021-41773Apache Software Foundation2021-11-171757
CVE-2021-30858Apple2021-11-171757
CVE-2021-30860Apple2021-11-171757

Transactions

ADDED TO KEV — CVE-2025-25249 (Fortinet FortiSwitchManager). Remediation due September 12, 2026.

ADDED TO KEV — CVE-2026-19490 (NetScaler ADC). Remediation due September 12, 2026.

ADDED TO KEV — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). Remediation due September 12, 2026.

ADDED TO KEV — CVE-2026-87491 (Google Chrome). Remediation due September 23, 2026.

EXPLOIT PUBLISHED — XenForo: 14 CVEs (CVE-2026-73309, CVE-2026-73310, CVE-2026-73311, CVE-2026-73312, CVE-2026-73313, CVE-2026-73314, CVE-2026-73315, CVE-2026-73316, CVE-2026-73317, CVE-2026-73318, CVE-2026-73319, CVE-2026-73320, CVE-2026-73321, CVE-2026-74239). Public exploit references added.

EXPLOIT PUBLISHED — axios: 12 CVEs (CVE-2026-25639, CVE-2026-40175, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — netty: 6 CVEs (CVE-2026-33870, CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587). Public exploit references added.

EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.

EXPLOIT PUBLISHED — itsourcecode Sales and Inventory System: 3 CVEs (CVE-2026-86234, CVE-2026-86265, CVE-2026-86517). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33231 (nltk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33487 (russellhaering goxmldsig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-35172 (distribution). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-37171. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-39883 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-41242 (protobufjs protobuf.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-46625 (js-cookie). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71625. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85089 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85090 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86170 (DefaultFuction CRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86181 (code-projects Task Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86210 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86215 (Mstfakts College-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86222 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86227 (valkey-io valkey). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86239 (liufee FeehiCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86260 (sfturing hosp_order). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86271 (FluentCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86276 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86279 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86285 (BookStack). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86292 (SourceCodester Simple Traffic Offense System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86297 (D-Link DIR-605). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86302 (code-projects Hospital Information System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86308 (light0011 cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86319 (java-json-tools json-patch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86431 (thephpleague commonmark). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86512 (java-json-tools json-patch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87528 (Google Chrome). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87629 (Google Chrome). Public exploit reference added.

RESCORED — Dell Secure Connect Gateway 5.0 - Application: 6 CVEs (CVE-2026-79734, CVE-2026-80128, CVE-2026-80129, CVE-2026-80130, CVE-2026-80131, CVE-2026-80164). CVSS rescored — before/after on each CVE page.

RESCORED — IBM App Connect Enterprise: 5 CVEs (CVE-2026-17442, CVE-2026-17443, CVE-2026-17444, CVE-2026-19649, CVE-2026-78543). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft SharePoint Server Subscription Edition: 5 CVEs (CVE-2026-69402, CVE-2026-69417, CVE-2026-69615, CVE-2026-69683, CVE-2026-69690). CVSS rescored — before/after on each CVE page.

RESCORED — IBM i: 3 CVEs (CVE-2026-17469, CVE-2026-17470, CVE-2026-17499). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-17483 (IBM Db2 Mirror for i). CVSS 4.3 → 3.3 (NVD).

RESCORED — CVE-2026-17627 (IBM Langflow OSS). CVSS 4.9 → 7.1 (NVD).

RESCORED — CVE-2026-17631 (IBM Langflow OSS). CVSS 5 → 6.5 (NVD).

RESCORED — CVE-2026-21042 (Samsung Mobile Devices). CVSS 8.4 → 8.7 (NVD).

RESCORED — CVE-2026-4765 (RD Station Conversas Tallos Chat). CVSS 5.1 → 0 (NVD).

RESCORED — CVE-2026-69739 (Microsoft 365 Apps for Enterprise). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-69857 (Microsoft Azure Cosmos DB). CVSS 8.5 → 8.8 (NVD).

RESCORED — CVE-2026-77503 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD).

PATCH SHIPPED — CVE-2026-19546 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.643-26.el10_2.4.

PATCH SHIPPED — CVE-2026-74860 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.15.4-0.1.hum1.

Yesterday's Results

How to read these box scores · glossary

654 CVEs published. 25 box scores and 375 table rows below; the remaining 254 continue on page 2 — every CVE is listed, nothing truncated.

Google Chrome — Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbi…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0029   21.4   YES
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Added to CISA KEV, due Sep 23
  Sep 9   Published (CNA: Chrome)
CWE-787 · CNA: Chrome · CVSS v3.1 · 3 references · NVD status: Modified · KEV due September 23, 2026
kstover Ninja Forms – The Contact Form Builder That Grows With You — Ninja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form Import
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0068   50.3     —
AFFECTED
  Product                                                     Versions     Fixed
  Ninja Forms – The Contact Form Builder That Grows With You  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
arraytics Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce — Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0067   50.0     —
AFFECTED
  Product                                                                 Versions     Fixed
  Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
arraytics Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce — Eventin <= 4.1.22 - Authenticated (Contirbutor+) Local File Inclusion via 'event_layout' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0056   45.0     —
AFFECTED
  Product                                                                 Versions     Fixed
  Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce  unspecified  —
TIMELINE
  Jul 13  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
martinnguyen1990 Next-Cart Store to WooCommerce Migration — Next-Cart Store to WooCommerce Migration <= 3.9.8 - Unauthenticated Authentication Bypass via Default '__token__' Fallback in REST Migration Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0052   42.2     —
AFFECTED
  Product                                   Versions     Fixed
  Next-Cart Store to WooCommerce Migration  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Newfold WP Plugin Web — Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0051   41.7     —
AFFECTED
  Product                  Versions     Fixed
  WP Plugin Web            unspecified  —
  WP Plugin Crazy Domains  unspecified  —
  WP Module Data           unspecified  —
  WP Plugin Hostgator      unspecified  —
  WP Plugin Bluehost       unspecified  —
TIMELINE
  Aug 25  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
fireplugins FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment — FireBox <= 3.1.10 - Authenticated (Author+) Remote Code Execution to Privilege Escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0050   41.3     —
AFFECTED
  Product                                                                                 Versions     Fixed
  FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment  unspecified  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Red Hat Red Hat Build of Keycloak — Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0049   40.8     —
AFFECTED
  Product                    Versions     Fixed
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Single Sign-On 7   unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 9   Published (CNA: redhat)
CWE-22 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
levelfourstorefront Shopping Cart & eCommerce Store — Shopping Cart & eCommerce Store <= 5.9.3 - Authenticated (Store Manager+) Privilege Escalation to ec_ajax_save_page_default_options AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0044   37.2     —
AFFECTED
  Product                          Versions     Fixed
  Shopping Cart & eCommerce Store  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Google Cloud Agent Development Kit (ADK) for Python — Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0044   36.9     —
AFFECTED
  Product                                 Versions  Fixed
  Agent Development Kit (ADK) for Python  2.0.0 –   —
TIMELINE
  Aug 25  Reserved by CNA
  Sep 9   Published (CNA: GoogleCloud)
CWE-184 · CNA: GoogleCloud · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis
Samsung Mobile Samsung Mobile Devices — Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   H   N    8.8   .0041   34.5     —
AFFECTED
  Product                 Versions     Fixed
  Samsung Mobile Devices  unspecified  SMR Sep-2026 Release in Android 14, 15, 16, 17
TIMELINE
  Dec 11  Reserved by CNA
  Sep 9   Published (CNA: SamsungMobile)
CNA: SamsungMobile · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Samsung Mobile Samsung Mobile Devices — Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0041   34.2     —
AFFECTED
  Product                 Versions     Fixed
  Samsung Mobile Devices  unspecified  SMR Sep-2026 Release in Android 14, 15, 16, 17
TIMELINE
  Dec 11  Reserved by CNA
  Sep 9   Published (CNA: SamsungMobile)
CNA: SamsungMobile · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Samsung Mobile Samsung Mobile Devices — Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0041   34.2     —
AFFECTED
  Product                 Versions     Fixed
  Samsung Mobile Devices  unspecified  SMR Sep-2026 Release in Android 14, 15, 16, 17
TIMELINE
  Dec 11  Reserved by CNA
  Sep 9   Published (CNA: SamsungMobile)
CNA: SamsungMobile · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Ragic|Enterprise Cloud Database - Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   N   N    6.9   .0041   34.2     —
AFFECTED
  Product                    Versions  Fixed
  Enterprise Cloud Database  all –     —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 9   Published (CNA: twcert)
CWE-23 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Google Chrome — Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacke…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0039   32.0     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-787 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Tanium addressed an unauthorized code execution vulnerability in Comply.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   30.3     —
AFFECTED
  Product  Versions  Fixed
  Comply   2.32 –    —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Tanium)
CWE-1336 · CNA: Tanium · CVSS v3.1 · 1 reference · NVD status: Undergoing Analysis
Google Chrome — Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0036   29.6     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0036   28.9     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-122 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arb…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0035   28.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0035   28.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6   .0035   28.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute ar…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0035   28.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-125 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
Google Chrome — Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute ar…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0035   28.7     —
AFFECTED
  Product  Versions         Fixed
  Chrome   153.0.8010.36 –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 9   Published (CNA: Chrome)
CWE-119 · CNA: Chrome · CVSS v3.1 · 2 references · NVD status: Analyzed
stylemix Checkout Custom Fields Builder for WooCommerce — Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0035   28.1     —
AFFECTED
  Product                                         Versions     Fixed
  Checkout Custom Fields Builder for WooCommerce  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0034   27.3     —
AFFECTED
  Product                                                                      Versions     Fixed
  User Role Editor – PublishPress Capabilities: Access Control and User Roles  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 9   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-874878.327.2GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-876398.326.9GoogleChromeCWE-416Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-876469.626.5GoogleChromeCWE-416Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 …
CVE-2026-876549.626.4GoogleChromeCWE-122Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.3…
CVE-2026-876349.625.9GoogleChromeCWE-416Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-876439.625.9GoogleChromeCWE-190Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36…
CVE-2026-875479.625.3GoogleChromeCWE-706Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.…
CVE-2026-198004.924.3getwpfunnelsMail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce EmailsCWE-89Mail Mint <= 1.31.0 - Authenticated (Custom+) SQL Injection via 'status' Para…
CVE-2026-875554.724.0GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8…
CVE-2026-578255.723.9OCamlopamCWE-61In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism …
CVE-2026-875564.323.7GoogleChromeCWE-862Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-874343.123.7GoogleChromeCWE-862Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-874423.123.7GoogleChromeCWE-441Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed …
CVE-2026-145056.623.5TaniumTanium Data ServiceCWE-22Tanium addressed a path traversal vulnerability in Tanium Data Service.
CVE-2026-87548await23.0GoogleChromeCWE-754Improper state validation in Installer in Google Chrome prior to 153.0.8010.3…
CVE-2026-835937.222.9quantumcloudWPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-79WPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversatio…
CVE-2026-870238.522.8TaniumComplyCWE-22Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-874818.322.7GoogleChromeCWE-863Incorrect authorization in WebView in Google Chrome on on Android prior to 15…
CVE-2025-32714.822.7OpenText™Documentum WebtopCWE-79DOM-based XSS vulnerability in OpenText™ Documentum Webtop
CVE-2026-876368.822.7GoogleChromeCWE-843Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remot…
CVE-2026-874709.622.2GoogleChromeCWE-1284Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.…
CVE-2026-875209.622.2GoogleChromeCWE-416Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 …
CVE-2026-875589.622.2GoogleChromeCWE-416Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 …
CVE-2026-874798.322.2GoogleChromeCWE-807Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0…
CVE-2026-874808.322.2GoogleChromeCWE-416Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875108.322.2GoogleChromeCWE-20Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 …
CVE-2026-875248.322.2GoogleChromeCWE-416Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 …
CVE-2026-875538.322.2GoogleChromeCWE-20Improper input validation in SiteIsolation in Google Chrome prior to 153.0.80…
CVE-2026-87429await21.8GoogleChromeCWE-862Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.3…
CVE-2026-87471await21.8GoogleChromeCWE-863Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010…
CVE-2026-87513await21.8GoogleChromeCWE-862Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010…
CVE-2026-842937.221.6addonsorgRepeater Fields for Gravity FormsCWE-79Repeater Fields for Gravity Forms <= 3.0.4 - Unauthenticated Stored Cross-Sit…
CVE-2026-876424.321.6GoogleChromeCWE-908Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-875279.621.3GoogleChromeCWE-122Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a re…
CVE-2026-877347.521.3OCamlutcpCWE-923An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-or…
CVE-2026-876523.121.3GoogleChromeCWE-863Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-874786.521.1GoogleChromeCWE-203Observable discrepancy in Autofill in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-874455.421.1GoogleChromeCWE-451UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-874355.321.1GoogleChromeCWE-200Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-874395.321.1GoogleChromeCWE-200Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-874724.221.1GoogleChromeCWE-20Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-153984.321.1arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCWE-862Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) …
CVE-2026-87447await21.0GoogleChromeCWE-863Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-87522await21.0GoogleChromeCWE-862Missing authorization in WebView in Google Chrome on on Android prior to 153.…
CVE-2026-870308.520.6TaniumComplyCWE-22Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87436await20.5GoogleChromeCWE-459Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-87446await20.5GoogleChromeCWE-459Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-874649.620.5GoogleChromeCWE-416Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a rem…
CVE-2026-875299.620.2GoogleChromeCWE-197Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-876168.320.2GoogleChromeCWE-665Improper initialization in Views in Google Chrome on on Windows prior to 153.…
CVE-2026-87549await20.3GoogleChromeCWE-459Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-149897.220.1wplegalpagesWPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeCWE-79Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Sc…
CVE-2026-876379.620.0GoogleChromeCWE-416Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.3…
CVE-2026-876389.620.0GoogleChromeCWE-787Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed …
CVE-2026-876509.620.0GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a…
CVE-2026-876488.320.0GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36…
CVE-2026-874436.520.0GoogleChromeCWE-862Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-874324.220.0GoogleChromeCWE-863Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36…
CVE-2026-876324.319.7GoogleChromeCWE-79Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 …
CVE-2026-875269.619.7GoogleChromeCWE-416Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a…
CVE-2026-759054.319.6brechtvdsWP Recipe MakerCWE-862WP Recipe Maker <= 10.8.0 - Missing Authorization to Authenticated (Contribut…
CVE-2026-87473await19.6GoogleChromeCWE-863Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.…
CVE-2026-87441await19.2GoogleChromeCWE-862Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-197786.518.9aukejommWPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & ShoppingCWE-89WPMR Google Feed Manager for WooCommerce <= 2.23.7 - Authenticated (Administr…
CVE-2026-874376.518.8GoogleChromeCWE-200Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-874776.518.8GoogleChromeCWE-200Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a re…
CVE-2026-876355.418.8GoogleChromeCWE-451UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-876448.318.7GoogleChromeCWE-863Incorrect authorization in Views in Google Chrome on on Windows prior to 153.…
CVE-2026-199444.918.7themeumWP CrowdfundingCWE-89WP Crowdfunding <= 2.2.1 - Authenticated (Shop Manager+) SQL Injection via 'w…
CVE-2026-78046.117.8woobewooProduct Filter for WooCommerce by WBWCWE-79Product Filter for WooCommerce by WBW <= 3.4.2 - Reflected Cross-Site Scripti…
CVE-2026-875084.317.8GoogleChromeCWE-863Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-874853.117.8GoogleChromeCWE-863Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-87483await17.8GoogleChromeCWE-863Incorrect authorization in Browser in Google Chrome on on Android prior to 15…
CVE-2026-87656await17.8GoogleChromeCWE-754Improper state validation in Safebrowsing in Google Chrome prior to 153.0.801…
CVE-2026-877246.517.7torprjectTorCWE-669Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST…
CVE-2026-759666.417.5eteubertPodlove Podcast PublisherCWE-79Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cros…
CVE-2026-874559.617.2GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remo…
CVE-2026-875819.617.2GoogleChromeCWE-416Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-876079.617.2GoogleChromeCWE-416Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 al…
CVE-2026-876178.817.2GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875504.317.3GoogleChromeCWE-116Improper encoding or escaping of output in CSS in Google Chrome prior to 153.…
CVE-2026-87431await17.2GoogleChromeCWE-862Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 a…
CVE-2025-70625.216.8Lumi Education UGh5p-nodejs-libraryCWE-20Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library…
CVE-2026-493108.616.3HuaweiHarmonyOSCWE-264Permission control vulnerability in the event notification module. Impact: Su…
CVE-2026-118384.316.3Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc.Library Reservation SystemCWE-306Improper Authorization in Yordam Informatics' Library Reservation System
CVE-2026-875728.316.1GoogleChromeCWE-74Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remot…
CVE-2026-875574.316.0GoogleChromeCWE-862Missing authorization in LocalNetworkAccess in Google Chrome prior to 153.0.8…
CVE-2026-87475await16.0GoogleChromeCWE-862Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-87515await16.0GoogleChromeCWE-863Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-87519await16.0GoogleChromeCWE-863Incorrect authorization in Safebrowsing in Google Chrome prior to 153.0.8010.…
CVE-2026-143598.815.8YithYITH WooCommerce Waitlist PremiumCWE-269YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Pri…
CVE-2026-875828.315.9GoogleChromeCWE-441Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-197335.315.8Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc.Library Information and Document Automation ProgramCWE-918SSRF in Yordam Informatics's Library Automation System
CVE-2026-199464.315.9awesomesupportAwesome Support – WordPress HelpDesk & Support PluginCWE-862Awesome Support <= 6.3.9 - Missing Authorization to Authenticated (Subscriber…
CVE-2026-876573.115.8GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-876473.415.8GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-87433await15.5GoogleChromeCWE-367Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a r…
CVE-2026-849085.315.5getwpfunnelsWPFunnels – Funnel Builder for WooCommerce with Checkout & One Click UpsellCWE-862WPFunnels <= 3.12.13 - Missing Authorization to Unauthenticated Arbitrary Pro…
CVE-2026-874845.415.3GoogleChromeCWE-451UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-875075.415.3GoogleChromeCWE-451UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-875185.315.3GoogleChromeCWE-203Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 15…
CVE-2026-875164.315.3GoogleChromeCWE-203Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 …
CVE-2026-876304.315.3GoogleChromeCWE-190Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875594.215.3GoogleChromeCWE-451UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875213.115.3GoogleChromeCWE-200Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-87645await14.9GoogleChromeCWE-754Improper state validation in Safebrowsing in Google Chrome prior to 153.0.801…
CVE-2026-87649await14.9GoogleChromeCWE-451UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-129565.314.8arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCWE-862Eventin <= 4.1.22 - Missing Authorization to Unauthenticated Arbitrary Order …
CVE-2026-875798.814.7GoogleChromeCWE-122Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a r…
CVE-2026-876555.414.6GoogleChromeCWE-1021Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a r…
CVE-2026-875049.614.6GoogleChromeCWE-416Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remo…
CVE-2026-876099.614.6GoogleChromeCWE-416Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 a…
CVE-2026-133597.214.6bestweblayoutContact Form to DB by BestWebSoft – Messages Database Plugin For WordPressCWE-79Contact Form to DB by BestWebSoft <= 1.7.5 - Unauthenticated Stored Cross-Sit…
CVE-2026-875289.614.3GoogleChromeCWE-843Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 …
CVE-2026-876128.814.3GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-876188.314.3GoogleChromeCWE-706Incorrect reference resolution in Storage in Google Chrome on on Windows prio…
CVE-2026-874766.514.1GoogleChromeCWE-863Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-876296.514.1GoogleChromeCWE-863Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-876584.313.4GoogleChromeCWE-200Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-875644.313.3GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-874563.413.3GoogleChromeCWE-908Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-199456.413.1themeumWP CrowdfundingCWE-79WP Crowdfunding <= 2.2.1 - Authenticated (Subscriber+) Stored Cross-Site Scri…
CVE-2026-876535.413.1GoogleChromeCWE-451UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 15…
CVE-2026-87640await13.1GoogleChromeCWE-125Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8…
CVE-2026-874664.313.0GoogleChromeCWE-863Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-87469await12.5GoogleChromeCWE-20Improper input validation in Extensions in Google Chrome prior to 153.0.8010.…
CVE-2026-87503await12.5GoogleChromeCWE-841Inappropriate implementation in Downloads in Google Chrome on on Android prio…
CVE-2026-87600await12.5GoogleChromeCWE-20Improper input validation in Safebrowsing in Google Chrome on on Android prio…
CVE-2026-876316.512.0GoogleChromeCWE-862Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed …
CVE-2026-876514.312.0GoogleChromeCWE-863Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-874949.611.8GoogleChromeCWE-416Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.…
CVE-2026-875009.611.8GoogleChromeCWE-129Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8…
CVE-2026-876219.611.8GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.80…
CVE-2026-874608.811.8GoogleChromeCWE-416Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875368.811.8GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-875428.811.8GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a rem…
CVE-2026-875878.811.8GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-875888.811.8GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed …
CVE-2026-875068.311.8GoogleChromeCWE-250Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed …
CVE-2026-876048.311.8GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a…
CVE-2026-801776.511.9DellSecure Connect Gateway 5.0 - ApplicationCWE-89Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-197976.111.9gm_alexUser Access ManagerCWE-79User Access Manager <= 2.3.18 - Reflected Cross-Site Scripting via 'tab_group…
CVE-2026-87511await11.8GoogleChromeCWE-862Missing authorization in DevTools in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-877375.911.5OCamlmirage-crypto-ecCWE-208An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCam…
CVE-2026-877364.311.5OCamlmirage-crypto-ecCWE-125An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCam…
CVE-2026-800554.411.3DellSecure Connect Gateway 5.0 - ApplicationCWE-90Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-870368.111.2TaniumComplyCWE-862Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-870758.111.2TaniumComplyCWE-863Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-875656.511.0GoogleChromeCWE-200Information leak in Passwords in Google Chrome on on Android prior to 153.0.8…
CVE-2026-874585.411.0GoogleChromeCWE-451UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-874965.411.0GoogleChromeCWE-451UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allow…
CVE-2026-816475.311.0HuaweiHarmonyOSCWE-680Out-of-bounds read vulnerability in the graphics module. Impact: Successful e…
CVE-2026-875744.311.0GoogleChromeCWE-200Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-874513.111.0GoogleChromeCWE-200Information leak in Downloads in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-875393.111.0GoogleChromeCWE-203Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-874929.610.8GoogleChromeCWE-863Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-771866.410.9joedolsonMy Calendar – Accessible Event ManagerCWE-79My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-875614.310.8GoogleChromeCWE-863Incorrect authorization in Web Authentication in Google Chrome prior to 153.0…
CVE-2026-87626await10.9GoogleChromeCWE-863Incorrect authorization in DeviceBoundSessionCredentials in Google Chrome pri…
CVE-2026-171496.410.7saadiqbalPoints Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCredCWE-79myCred – Points Management System For Gamification, Ranks, Badges, and Loyalt…
CVE-2026-870835.110.8tile-aitilelangCWE-20tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_d…
CVE-2026-875173.110.5GoogleChromeCWE-367Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 al…
CVE-2026-876338.610.2GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a loc…
CVE-2026-87535await10.2GoogleChromeCWE-221Information loss or omission in Safebrowsing in Google Chrome on on Mac prior…
CVE-2026-870847.710.0TaniumEnforceCWE-918Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2025-468086.810.1SUSEneuvectorCWE-532Sensitive information is leaked into NeuVector’s manager container logs
CVE-2026-137096.410.0iqonicdesignGraphina – Charts and Graphs For ElementorCWE-79Graphina <= 3.1.11 - Authenticated (Author+) Stored Cross-Site Scripting via …
CVE-2026-874535.39.9GoogleChromeCWE-441Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-875384.29.9GoogleChromeCWE-1021Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remot…
CVE-2026-874523.19.9GoogleChromeCWE-863Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010…
CVE-2026-876139.09.7GoogleChromeCWE-706Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.…
CVE-2026-875858.89.7GoogleChromeCWE-415Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 a…
CVE-2026-876258.89.7GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-87641await9.5GoogleChromeCWE-362Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a r…
CVE-2026-86154.39.4ghera74ilGhera Reviso Exporter for WooCommerceCWE-862ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to A…
CVE-2026-87591await9.4GoogleChromeCWE-863Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36…
CVE-2026-148924.39.3TaniumTanium ServerCWE-863Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2026-771876.49.1joedolsonMy Calendar – Accessible Event ManagerCWE-79My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripti…
CVE-2026-875235.39.0GoogleChromeCWE-367Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-87590await8.9GoogleChromeCWE-20Improper input validation in Passwords in Google Chrome prior to 153.0.8010.3…
CVE-2026-875378.18.8GoogleChromeCWE-862Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-149628.68.7UnknownELEX WooCommerce Request a QuoteCWE-89ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id
CVE-2026-118215.48.8arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCWE-862Eventin <= 4.1.17 - Missing Authorization to Authenticated (Subscriber+) Noti…
CVE-2026-874974.38.8GoogleChromeCWE-908Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-875624.38.8GoogleChromeCWE-706Incorrect reference resolution in Accessibility in Google Chrome on on Mac pr…
CVE-2026-875763.48.8GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8…
CVE-2026-870348.38.7TaniumComplyCWE-89Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-875604.38.6GoogleChromeCWE-862Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-875774.38.6GoogleChromeCWE-863Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-875984.38.6GoogleChromeCWE-863Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010…
CVE-2026-876224.38.6GoogleChromeCWE-862Missing authorization in FedCM in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-874983.18.6GoogleChromeCWE-862Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-876143.18.6GoogleChromeCWE-863Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010…
CVE-2026-87580await8.6GoogleChromeCWE-863Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.801…
CVE-2026-87584await8.6GoogleChromeCWE-863Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-874898.88.2GoogleChromeCWE-119Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a rem…
CVE-2026-783776.18.2Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc.Library Information and Document Automation ProgramCWE-601Open Redirect in Yordam Informatics's Library Automation System
CVE-2026-875734.38.2GoogleChromeCWE-20Improper input validation in Network in Google Chrome prior to 153.0.8010.36 …
CVE-2026-87450await8.2GoogleChromeCWE-863Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.3…
CVE-2026-87532await8.2GoogleChromeCWE-754Improper state validation in Safebrowsing in Google Chrome prior to 153.0.801…
CVE-2026-87541await8.2GoogleChromeCWE-200Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-801237.58.0DellSecure Connect Gateway 5.0 - ApplicationCWE-918Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-198556.58.0UnknownCleanTalkCWE-74Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Ar…
CVE-2026-851176.58.0UnknownContact Form 7 CaptchaCWE-74Contact Form 7 Captcha 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Ex…
CVE-2026-799746.48.0DellSecure Connect Gateway 5.0 - ApplicationCWE-287Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-874864.07.6GoogleChromeCWE-1021Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to …
CVE-2026-875698.87.5GoogleChromeCWE-862Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowe…
CVE-2026-87468await7.5GoogleChromeCWE-863Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-87493await7.5GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-87499await7.5GoogleChromeCWE-863Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-87543await7.5GoogleChromeCWE-862Missing authorization in Core in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-87589await7.5GoogleChromeCWE-863Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010…
CVE-2026-87595await7.5GoogleChromeCWE-918Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36…
CVE-2026-87603await7.5GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-87606await7.5GoogleChromeCWE-862Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.3…
CVE-2026-87610await7.5GoogleChromeCWE-863Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-840688.67.3UnknownQuentn WPCWE-89Quentn WP 1.2.13 - 1.2.14 - Unauthenticated SQLi via 'qntn_wp' Parameter
CVE-2026-87551await7.4GoogleChromeCWE-295Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.…
CVE-2026-870324.37.3TaniumTanium ServerCWE-200Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-870354.37.3TaniumComplyCWE-200Tanium addressed an information disclosure vulnerability in Comply.
CVE-2026-211036.87.0Samsung MobileSamsung Mobile Devices—Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows ph…
CVE-2026-870736.57.1TaniumComplyCWE-862Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-874546.57.0GoogleChromeCWE-200Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.…
CVE-2026-874596.57.0GoogleChromeCWE-203Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-875456.57.0GoogleChromeCWE-200Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 …
CVE-2026-876206.57.0GoogleChromeCWE-203Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-876236.57.0GoogleChromeCWE-203Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-874625.47.0GoogleChromeCWE-451UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-875015.47.0GoogleChromeCWE-451UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-875995.47.0GoogleChromeCWE-20Improper input validation in Interstitials in Google Chrome prior to 153.0.80…
CVE-2026-875665.37.0GoogleChromeCWE-203Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-874954.37.0GoogleChromeCWE-200Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875864.37.0GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a…
CVE-2026-875924.37.0GoogleChromeCWE-125Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-875964.37.0GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a…
CVE-2026-876194.37.0GoogleChromeCWE-203Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 al…
CVE-2026-875313.17.0GoogleChromeCWE-200Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a re…
CVE-2026-87534await7.0GoogleChromeCWE-862Missing authorization in WebView in Google Chrome on on Android prior to 153.…
CVE-2026-169607.56.9UnknownLoops & LogicCWE-200Loops & Logic < 4.3.0 - Unauthenticated User Data and Site Option Disclosure
CVE-2026-874494.36.8GoogleChromeCWE-352Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome …
CVE-2026-870727.16.7TaniumComplyCWE-862Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87546await6.7GoogleChromeCWE-704Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac …
CVE-2026-87627await6.7GoogleChromeCWE-436Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 1…
CVE-2026-875148.16.6GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a loc…
CVE-2026-870255.46.6TaniumComplyCWE-639Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-870335.46.6TaniumComplyCWE-639Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-870485.46.6TaniumComplyCWE-862Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-876288.36.4GoogleChromeCWE-416Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adj…
CVE-2026-875405.46.4GoogleChromeCWE-863Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-875945.36.4GoogleChromeCWE-863Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.…
CVE-2026-874654.26.4GoogleChromeCWE-863Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 …
CVE-2026-875024.26.4GoogleChromeCWE-441Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed…
CVE-2026-876113.16.4GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 a…
CVE-2026-875308.16.2GoogleChromeCWE-427Uncontrolled search path element in CredentialProvider in Google Chrome on on…
CVE-2026-87544await6.1GoogleChromeCWE-863Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36…
CVE-2026-87575await6.1GoogleChromeCWE-863Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-876017.56.0GoogleChromeCWE-362Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote…
CVE-2026-875708.86.0GoogleChromeCWE-863Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010…
CVE-2026-87505await6.0GoogleChromeCWE-863Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36…
CVE-2025-156906.85.8UnknownContent MaskCWE-79Content Mask 1.7.1 - 1.8.5.5 - Contributor+ Stored XSS via Post Scripts and S…
CVE-2026-784918.25.7DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-874906.55.8GoogleChromeCWE-200Information leak in Transactions Platform in Google Chrome prior to 153.0.801…
CVE-2026-875936.55.8GoogleChromeCWE-200Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a…
CVE-2026-875835.45.8GoogleChromeCWE-451UI misrepresentation in Passwords in Google Chrome on on Android prior to 153…
CVE-2026-876024.75.8GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.801…
CVE-2026-876244.25.8GoogleChromeCWE-451UI misrepresentation in Passwords in Google Chrome on on Android prior to 153…
CVE-2026-875974.85.6GoogleChromeCWE-451UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 15…
CVE-2026-875674.35.6GoogleChromeCWE-451UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36…
CVE-2026-875684.35.6GoogleChromeCWE-20Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36…
CVE-2026-876055.35.1GoogleChromeCWE-862Missing authorization in Contacts in Google Chrome prior to 153.0.8010.36 all…
CVE-2026-841134.15.1UnknownQuentn WPCWE-89Quentn WP < 1.2.15 - Admin+ SQLi via 'orderby'/'order' Parameter
CVE-2026-870476.34.8TaniumComplyCWE-639Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-804404.84.9UnknownHustleCWE-74Hustle < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution via Success…
CVE-2026-875098.14.7GoogleChromeCWE-863Incorrect authorization in Updater in Google Chrome on on Windows prior to 15…
CVE-2026-835416.84.7UnknownSina Extension for ElementorCWE-79Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Tab…
CVE-2026-854185.44.7UnknownOrbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCWE-79Orbit Fox < 3.0.9 - Contributor+ Stored XSS via Beaver Builder Pricing Table …
CVE-2026-870194.34.7TaniumComplyCWE-639Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-870464.34.7TaniumComplyCWE-863Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-784947.44.5DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-874614.34.5GoogleChromeCWE-200Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a re…
CVE-2026-87482await4.5GoogleChromeCWE-319Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on…
CVE-2026-87552await4.5GoogleChromeCWE-862Missing authorization in TrustedWebActivities in Google Chrome on on Android …
CVE-2026-796405.44.3DellSecure Connect Gateway 5.0 - ApplicationCWE-89Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-875252.74.3GoogleChromeCWE-125Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.…
CVE-2026-87608await4.3GoogleChromeCWE-295Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010…
CVE-2026-180425.34.2UnknownWP TravelCWE-862WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation
CVE-2026-131443.74.2UnknownWP TravelCWE-284WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset
CVE-2026-131463.74.2UnknownWP TravelCWE-639WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR
CVE-2026-803395.34.1UnknownPayment Plugins for Stripe WooCommerceCWE-200Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PI…
CVE-2026-803405.34.1UnknownPayment Plugins for PayPal WooCommerceCWE-200Payment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PI…
CVE-2026-810215.34.1UnknownSupportCandyCWE-200SupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Disclosure
CVE-2026-810225.34.1UnknownSupportCandyCWE-200SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Au…
CVE-2026-842225.34.1UnknownKirkiCWE-200Kirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via …
CVE-2026-162729.14.0PayTR Payment and Electronic Money Institution Inc.PayTR Virtual Pos iFrame API (v9x) WHMCS ModuleCWE-348Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iF…
CVE-2026-758616.53.8UnknownUltimate Gift Cards for WooCommerceCWE-862Ultimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft an…
CVE-2026-877354.33.8OCamlmirage-crypto-pkCWE-1284An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCam…
CVE-2026-877668.83.6Red HatRed Hat Enterprise Linux 10CWE-59Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files o…
CVE-2026-876155.43.6GoogleChromeCWE-362Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-870375.43.5TaniumComplyCWE-862Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-801227.33.4DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-210946.13.3Samsung MobileSamsung Mobile Devices—Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 a…
CVE-2026-828485.33.4UnknownMasteriyo LMSCWE-862Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure
CVE-2026-850375.33.4UnknownSunshine Photo CartCWE-639Sunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOR
CVE-2026-817414.73.4UnknownGroundhogg — CRM, Newsletters, and Marketing AutomationCWE-601Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter
CVE-2026-816444.33.3HuaweiHarmonyOSCWE-264DoS vulnerability in the preview service module. Impact: Successful exploitat…
CVE-2026-875634.33.4GoogleChromeCWE-346Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allo…
CVE-2026-875548.13.3GoogleChromeCWE-367Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.80…
CVE-2026-799736.33.3DellSecure Connect Gateway 5.0 - ApplicationCWE-567Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-796367.03.1DellSecure Connect Gateway 5.0 - ApplicationCWE-297Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-803415.93.1UnknownPayment Plugins for PayPal WooCommerceCWE-863Payment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment …
CVE-2026-851335.43.1UnknownWPLP Cookie ConsentCWE-862WPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple …
CVE-2026-821854.33.1UnknownWPLP Cookie ConsentCWE-862WPLP Cookie Consent < 4.4.2 - Subscriber+ Banner Settings Overwrite and A/B T…
CVE-2026-851324.33.1UnknownWPLP Cookie ConsentCWE-862WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosu…
CVE-2026-210974.62.8Samsung MobileSamsung Mobile Devices—Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 R…
CVE-2026-875788.32.8GoogleChromeCWE-416Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an…
CVE-2026-87571await2.7GoogleChromeCWE-295Improper certificate validation in Loader in Google Chrome prior to 153.0.801…
CVE-2026-128558.22.5Insyde SoftwareInsydeH2OCWE-20H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code …
CVE-2026-875338.12.4GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a …
CVE-2026-64858.22.2Insyde SoftwareInsydeH2OCWE-489UEFI BIOS embedded Shell can be used to bypass Secure Boot
CVE-2026-874634.82.3GoogleChromeCWE-863Incorrect authorization in Certificate in Google Chrome on on Android prior t…
CVE-2026-210878.62.2Samsung MobileSamsung Mobile Devices—Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows loc…
CVE-2026-870887.02.1TaniumEnforceCWE-78Tanium addressed an unauthorized code execution vulnerability in Enforce.
CVE-2026-210886.92.0Samsung MobileSamsung Mobile Devices—Improper input validation in loading a subtitle frame in libsubextractor.so p…
CVE-2026-211029.31.8Samsung MobileSamsung Mobile Devices—Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privil…
CVE-2026-211018.41.8Samsung MobileSamsung Mobile Devices—Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 a…
CVE-2026-835375.31.7UnknownWP Express CheckoutCWE-345WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process…
CVE-2026-210896.91.5Samsung MobileSamsung Mobile Devices—Improper input validation in removing style tag in libsubextractor.so prior t…
CVE-2026-211065.11.4Samsung MobileSamsung Cloud Assistant—Improper verification of intent by broadcast receiver in Samsung Cloud Assist…
CVE-2026-211106.91.3Samsung Mobilelibsavscmn.so—Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attacke…
CVE-2026-210858.41.2Samsung MobileSamsung Mobile Devices—Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 all…
CVE-2026-210864.81.2Samsung MobileSamsung Mobile Devices—Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows…
CVE-2026-210986.91.2Samsung MobileSamsung Mobile Devices—Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 al…
CVE-2026-211006.91.2Samsung MobileSamsung Mobile Devices—Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows lo…
CVE-2026-211086.91.2Samsung MobileBixby TouchCWE-926Improper export of android application components in Bixby Touch prior to ver…
CVE-2026-877336.21.2OCamlmirage-crypto-ecCWE-295An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCa…
CVE-2026-211055.91.2Samsung MobileCollection—Improper access control in Collection prior to version 1.0.1.14 in Android 15…
CVE-2026-799675.61.2DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-210995.11.2Samsung MobileSamsung Mobile Devices—Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 a…
CVE-2026-211092.11.2Samsung MobileWatch Plugin—Improper access control in Watch Plugin prior to Android Watch 17 allows loca…
CVE-2026-211047.10.9Samsung MobileSamsung Mobile Devices—Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Releas…
CVE-2026-801245.51.0DellSecure Connect Gateway 5.0 - ApplicationCWE-532Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-821845.30.9UnknownWPLP Cookie ConsentCWE-862WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update
CVE-2026-211125.10.9Samsung MobileSamsung Tips—Improper input validation in Samsung Tips prior to Android 17 allows local at…
CVE-2026-211076.90.9Samsung MobileSamsung NotesCWE-787Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local a…
CVE-2026-211116.90.9Samsung Mobilelibsthmbc—Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attacker…
CVE-2026-210904.80.9Samsung MobileSamsung Mobile Devices—Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 al…
CVE-2026-210914.80.9Samsung MobileSamsung Mobile Devices—Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1…
CVE-2026-874578.10.8GoogleChromeCWE-367Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.…
CVE-2026-874678.10.8GoogleChromeCWE-362Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.…
CVE-2026-128588.50.7ESET spol. s.r.o.ESET AV Remover (standalone)CWE-269Local privilege escalation vulnerability in ESET AV Remover
CVE-2026-801753.30.7DellSecure Connect Gateway 5.0 - ApplicationCWE-538Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-493116.20.6HuaweiHarmonyOSCWE-275Permission control vulnerability in the event notification module.Impact: Suc…
CVE-2026-210935.60.6Samsung MobileSamsung Mobile Devices—Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1…
CVE-2026-211134.80.5Samsung MobileVisual Voicemail—Improper export of android application components in Visual Voicemail prior t…
CVE-2026-816465.90.4HuaweiHarmonyOSCWE-125Out-of-bounds read vulnerability in the graphics module. Impact: Successful e…
CVE-2026-493147.30.3HuaweiHarmonyOSCWE-125OOB write vulnerability in the rendering and composition module. Impact: Succ…
CVE-2026-493094.80.3HuaweiHarmonyOSCWE-264Permission control vulnerability in the Settings module. Impact: Successful e…
CVE-2026-493157.10.2HuaweiHarmonyOSCWE-264DoS vulnerability in the input device module. Impact: Successful exploitation…
CVE-2026-419876.20.2HuaweiHarmonyOSCWE-264Permission control vulnerability in the app management module. Impact: Succes…
CVE-2026-877326.20.1OCamlmirage-cryptoCWE-347An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. …
CVE-2026-493135.50.1HuaweiHarmonyOSCWE-264Permission control vulnerability in the app lock module. Impact: Successful e…
CVE-2026-493124.00.1HuaweiHarmonyOSCWE-264Permission control vulnerability in the window module. Impact: Successful exp…
CVE-2026-8597810.0—PerforceAkanaCWE-41Unauthenticated Remote Code Execution in Akana API Platform
CVE-2026-8782710.0—KGUARDKGUARD_firmwareCWE-1188KGUARD DVR unauthenticated remote command execution vulnerability
CVE-2026-674019.9—WebProscPanelCWE-89A vulnerability in cPanel allows a mail-enabled account to achieve remote cod…
CVE-2026-796899.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-78Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799419.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-77Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801729.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-345Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-851029.8—checkpointQuantum Security GatewayCWE-295Improper Certificate Validation in Quantum Security Gateway
CVE-2026-851039.8—checkpointQuantum Security GatewayCWE-122Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
CVE-2026-546949.6—NationalSecurityAgencyskills-serviceCWE-20NationalSecurityAgency/skills-service has Stored XSS via User Registration En…
CVE-2026-879319.4—Behavioral Technology GroupPavlok Behavioral Conditioning WearableCWE-120Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Not…
CVE-2026-471569.3—mantisbtmantisbtCWE-287MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Adminis…
CVE-2026-879299.3—MaxSiteMaxSite CMSCWE-321MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key
CVE-2026-880699.3—pandora-analysispandoraCWE-22Path traversal in Pandora archive extractor allows arbitrary file writes outs…

Results continue: ranks 401–654.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-09 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.