Security Box Score — September 9, 2026 — page 2
Edition of September 9, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-87930 | 9.2 | — | MaxSite | MaxSite CMS | CWE-502 | MaxSite CMS through 109.6 PHP Object Injection via ci_session |
| CVE-2026-22590 | 9.1 | — | eProsima | Fast-DDS | CWE-125 | Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DA… |
| CVE-2026-87806 | 9.1 | — | parse-community | parse-server | CWE-287 | Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password |
| CVE-2026-67403 | 9.0 | — | Sage | Sage AR Automation | CWE-639 | Cash Collect contains an improper authorization vulnerability in the Sage AR … |
| CVE-2026-68484 | 9.0 | — | Sage | Sage AR Automation | CWE-862 | Cash Collect contains an improper authorization vulnerability in the Sage AR … |
| CVE-2026-87911 | 9.0 | — | AWS | AWS Labs postgres MCP Server | CWE-78 | Read-only enforcement bypass enabling operating system command execution in t… |
| CVE-2026-80914 | 8.8 | — | Linux | Linux | — | Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready |
| CVE-2026-80921 | 8.8 | — | Linux | Linux | — | KVM: s390: vsie: zero stale crypto bits |
| CVE-2026-86099 | 8.8 | — | Chainlit | chainlit | CWE-22 | Chainlit through 2.12.0 Path Traversal via socket.io sessionId |
| CVE-2026-86775 | 8.8 | — | knowns-dev | knowns | CWE-22 | knowns before 0.30.0 Path Traversal via Document API |
| CVE-2026-87795 | 8.8 | — | luben | zstd-jni | CWE-125 | zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress |
| CVE-2026-87823 | 8.8 | — | luben | zstd-jni | CWE-190 | zstd-jni 1.1.1 through 1.5.7-13 Out-of-Bounds Read via Direct ByteBuffer Fram… |
| CVE-2026-87927 | 8.8 | — | MaxSite | MaxSite CMS | CWE-98 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher |
| CVE-2023-54355 | 8.7 | — | pmmp | PocketMine-MP | CWE-347 | PocketMine-MP 5.2.0 Server Crash via Incorrect EC Curve |
| CVE-2023-54390 | 8.7 | — | pmmp | PocketMine-MP | CWE-1025 | PocketMine-MP before 5.3.1 Denial of Service via LoginPacket |
| CVE-2023-54393 | 8.7 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.20.5 Denial of Service via LoginPacket |
| CVE-2024-58381 | 8.7 | — | pmmp | PocketMine-MP | CWE-502 | PocketMine-MP before 5.11.1 Denial of Service via LoginPacket |
| CVE-2024-58382 | 8.7 | — | thephpleague | commonmark | CWE-407 | league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity |
| CVE-2026-77120 | 8.7 | — | Schneider Electric | PowerLogic T300 | CWE-78 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('O… |
| CVE-2026-81640 | 8.7 | — | Softish | EarVision Android application | CWE-798 | Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Cre… |
| CVE-2026-86199 | 8.7 | — | pmmp | PocketMine-MP | CWE-184 | PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login |
| CVE-2026-86201 | 8.7 | — | pmmp | PocketMine-MP | CWE-400 | PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData |
| CVE-2026-87807 | 8.7 | — | siyuan-note | siyuan | CWE-89 | siyuan before v3.8.2 SQL Injection via fullTextSearchBlock |
| CVE-2026-87808 | 8.7 | — | siyuan-note | siyuan | CWE-693 | SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock |
| CVE-2026-87816 | 8.7 | — | pglombardo | PasswordPusher | CWE-362 | PasswordPusher before 2.11.1 Race Condition View Limit Bypass |
| CVE-2026-87817 | 8.7 | — | gitpython-developers | GitPython | CWE-94 | GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation |
| CVE-2026-87819 | 8.7 | — | gitpython-developers | GitPython | CWE-1333 | GitPython before 3.1.60 Denial of Service via ReDoS |
| CVE-2026-87822 | 8.7 | — | tdunning | t-digest | CWE-407 | t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingD… |
| CVE-2026-87824 | 8.7 | — | luben | zstd-jni | CWE-125 | zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBuffer… |
| CVE-2026-87995 | 8.7 | — | open-webui | open-webui | CWE-79 | Open WebUI: Same-origin XSS to account takeover via terminal port-preview ifr… |
| CVE-2026-8044 | 8.6 | — | Schneider Electric | EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) | CWE-88 | CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argumen… |
| CVE-2026-19233 | 8.6 | — | Schneider Electric | EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) | CWE-918 | CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could c… |
| CVE-2026-26212 | 8.6 | — | Rara Themes | Rara One Click Demo Import | CWE-434 | Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE |
| CVE-2026-56711 | 8.6 | — | VideoLAN | VLC media player | CWE-190 | VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Ov… |
| CVE-2026-79322 | 8.6 | — | n/a | n/a | CWE-89 | SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (ma… |
| CVE-2026-86762 | 8.6 | — | grokability | snipe-it | CWE-862 | Snipe-IT before 8.7.0 Authentication Bypass via API Middleware |
| CVE-2026-86770 | 8.6 | — | grokability | snipe-it | CWE-178 | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation |
| CVE-2026-87794 | 8.6 | — | nfriedly | bestzip | CWE-88 | bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination |
| CVE-2026-77974 | 8.5 | — | Softish | EarVision Android application | CWE-306 | Softish C6 Ear Camera and EarVision Android Application Missing authenticatio… |
| CVE-2026-86754 | 8.5 | — | grokability | snipe-it | CWE-863 | Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients |
| CVE-2026-82563 | 8.4 | — | Softish | EarVision Android application | CWE-290 | Softish C6 Ear Camera and EarVision Android Application Authentication bypass… |
| CVE-2026-86741 | 8.4 | — | grokability | snipe-it | CWE-73 | Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA |
| CVE-2026-86751 | 8.4 | — | grokability | snipe-it | CWE-73 | Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown |
| CVE-2026-87811 | 8.4 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.2 Stored XSS via notebook template paths |
| CVE-2026-87813 | 8.4 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.2 Stored XSS via unescaped asset filenames |
| CVE-2026-87814 | 8.4 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.2 Stored XSS via Asset Preview |
| CVE-2026-87815 | 8.4 | — | siyuan-note | siyuan | CWE-73 | SiYuan before v3.8.2 Path Traversal via removeRiffDeck |
| CVE-2026-86750 | 8.3 | — | grokability | snipe-it | CWE-863 | snipe-it before 8.7.0 Authorization Bypass via API User Create/Update |
| CVE-2026-86771 | 8.3 | — | grokability | snipe-it | CWE-918 | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num |
| CVE-2026-18147 | 8.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-79 | Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrar… |
| CVE-2026-65181 | 8.1 | — | Apache Software Foundation | Apache Impala | CWE-913 | Apache Impala: RCE via External Data Source Class Loading |
| CVE-2026-87016 | 8.1 | — | open-webui | open-webui | CWE-155 | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subj… |
| CVE-2026-87874 | 8.1 | — | Red Hat | Red Hat Ceph Storage 5 | CWE-502 | Community.general: community.general: memcached cache plugin deserializes unt… |
| CVE-2026-78482 | 7.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-89 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-78484 | 7.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-77 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-78493 | 7.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-77 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-15140 | 7.7 | — | Everpure | Portworx Operator | CWE-266 | A privilege-escalation issue in the Portworx Operator when deployed on Red Ha… |
| CVE-2026-15913 | 7.7 | — | Fortra | GoAnywhere MFT | CWE-23 | Path Traversal in Fortra's GoAnywhere MFT Endpoint |
| CVE-2026-79637 | 7.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87996 | 7.7 | — | open-webui | open-webui | CWE-367 | Open WebUI: SSRF into internal services via DNS rebinding in the Playwright w… |
| CVE-2026-22591 | 7.5 | — | eProsima | Fast-DDS | CWE-400 | Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS) |
| CVE-2026-73786 | 7.5 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Network-Based Denial of Service in CPPM systems |
| CVE-2026-78490 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-307 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79323 | 7.5 | — | n/a | n/a | CWE-200 | Information disclosure in the blogComments GraphQL query in Magefan Blog Grap… |
| CVE-2026-79324 | 7.5 | — | n/a | n/a | CWE-639 | Missing authorization in the Address Delete controller in Mageplaza GDPR for … |
| CVE-2026-79641 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-78 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79738 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-798 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79740 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-798 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79950 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-798 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80924 | 7.5 | — | Linux | Linux | — | crypto: krb5 - use kfree_sensitive() for derived key buffers |
| CVE-2026-87011 | 7.5 | — | open-webui | open-webui | CWE-405 | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC f… |
| CVE-2026-87853 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-187 | Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation |
| CVE-2026-78492 | 7.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79963 | 7.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-494 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86746 | 7.4 | — | grokability | snipe-it | CWE-269 | Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay |
| CVE-2026-87812 | 7.4 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.2 Stored XSS via Bazaar iconURL |
| CVE-2026-78485 | 7.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-22 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79635 | 7.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-918 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79692 | 7.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-73 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79695 | 7.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-409 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-23855 | 7.2 | — | Dell | iDRAC9 | CWE-78 | Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.3… |
| CVE-2026-73769 | 7.2 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Remote Code Execution in CPPM Web Interface |
| CVE-2026-73787 | 7.2 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web … |
| CVE-2026-79972 | 7.2 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-89 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2023-54392 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacket |
| CVE-2023-54396 | 7.1 | — | pmmp | PocketMine-MP | CWE-129 | PocketMine-MP before 4.8.1 Server Crash via Banner NBT |
| CVE-2024-58380 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 5.11.2 Denial of Service via BookEditPacket |
| CVE-2025-71417 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponseP… |
| CVE-2026-50165 | 7.1 | — | alfio-event | alf.io | CWE-284 | alf.io has Improper Access Control for Organization Owners that Exposes Syste… |
| CVE-2026-79617 | 7.1 | — | TÜBİTAK BİLGEM Software Technologies Research Institute | Pardus LightDM Greeter | CWE-732 | Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardu… |
| CVE-2026-81330 | 7.1 | — | Softish | EarVision Android application | CWE-319 | Softish C6 Ear Camera and EarVision Android Application Cleartext transmissio… |
| CVE-2026-86204 | 7.1 | — | pmmp | PocketMine-MP | CWE-400 | PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket |
| CVE-2026-86757 | 7.1 | — | grokability | snipe-it | CWE-862 | Snipe-IT before 8.7.0 Information Disclosure via Custom Fields |
| CVE-2026-86758 | 7.1 | — | grokability | snipe-it | CWE-204 | Snipe-IT before 8.7.0 License Key Exposure via CSV Export |
| CVE-2026-86759 | 7.1 | — | grokability | snipe-it | CWE-862 | Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer |
| CVE-2026-86764 | 7.1 | — | grokability | snipe-it | CWE-862 | Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components |
| CVE-2026-86765 | 7.1 | — | grokability | snipe-it | CWE-862 | Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint |
| CVE-2026-86766 | 7.1 | — | grokability | snipe-it | CWE-362 | Snipe-IT 8.6.3 Race Condition via Consumable Checkout |
| CVE-2026-87809 | 7.1 | — | siyuan-note | siyuan | CWE-639 | Siyuan before v3.8.2 Information Disclosure via Export Preview |
| CVE-2026-87818 | 7.1 | — | gitpython-developers | GitPython | CWE-88 | GitPython 3.1.59 Local File Content Oracle via --no-index |
| CVE-2026-87821 | 7.1 | — | laradashboard | laradashboard | CWE-918 | Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Mar… |
| CVE-2026-87998 | 7.1 | — | open-webui | open-webui | CWE-269 | Open WebUI: Non-admin users can delete admin-owned external knowledge connect… |
| CVE-2026-87999 | 7.1 | — | open-webui | open-webui | CWE-918 | Open WebUI: Any authenticated user can reach the Azure platform channel via s… |
| CVE-2026-86749 | 7.0 | — | grokability | snipe-it | CWE-252 | snipe-it before 8.7.0 Data Loss via Failed Image Write |
| CVE-2026-87825 | 7.0 | — | luben | zstd-jni | CWE-416 | zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompres… |
| CVE-2026-87877 | 7.0 | — | luben | zstd-jni | CWE-416 | zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After clo… |
| CVE-2025-71418 | 6.9 | — | pmmp | PocketMine-MP | CWE-400 | PocketMine-MP before 5.25.2 Denial of Service via explode |
| CVE-2026-73324 | 6.9 | — | VideoLAN | VLC media player | CWE-125 | VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminate… |
| CVE-2026-82530 | 6.9 | — | IP2Location | IP2Location Country Blocker | CWE-290 | IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header |
| CVE-2026-83530 | 6.9 | — | cel-go | CWE-789 | Uncontrolled Memory Allocation in cel-go | |
| CVE-2026-86200 | 6.9 | — | pmmp | PocketMine-MP | CWE-779 | PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT |
| CVE-2026-86547 | 6.9 | — | mrubyc | mrubyc | CWE-476 | mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER |
| CVE-2026-86748 | 6.9 | — | grokability | snipe-it | CWE-460 | Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive |
| CVE-2026-86777 | 6.9 | — | AlchemyCMS | alchemy_cms | CWE-862 | AlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /a… |
| CVE-2026-87810 | 6.9 | — | siyuan-note | siyuan | CWE-200 | Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock |
| CVE-2026-87820 | 6.9 | — | usmannasir | cyberpanel | CWE-200 | CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner |
| CVE-2026-87925 | 6.9 | — | Rizwan17 | inventory-management-system | CWE-89 | Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql… |
| CVE-2026-87015 | 6.8 | — | open-webui | open-webui | CWE-201 | Open WebUI: A user's session cookies are sent to tool servers configured for … |
| CVE-2026-87872 | 6.8 | — | Red Hat | Red Hat Ceph Storage 5 | CWE-295 | Community.general: community.general: ocapi module_utils (ocapi_command, ocap… |
| CVE-2026-70425 | 6.7 | — | Dell | PowerScale OneFS | CWE-78 | Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 thr… |
| CVE-2026-73788 | 6.5 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Privilege Escalation in ClearPass OnGuard Agent |
| CVE-2026-78481 | 6.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-321 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79513 | 6.5 | — | n/a | n/a | — | A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function … |
| CVE-2026-79514 | 6.5 | — | n/a | n/a | — | An out-of-bounds read in the gf_dm_data_received function (downloader.c) of G… |
| CVE-2026-79522 | 6.5 | — | n/a | n/a | — | An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloa… |
| CVE-2026-79728 | 6.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-23 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87014 | 6.5 | — | open-webui | open-webui | CWE-613 | Open WebUI: Admin demoted through SSO role sync keeps read and write access t… |
| CVE-2026-88000 | 6.5 | — | open-webui | open-webui | CWE-835 | Open WebUI: Any authenticated user can hang the server via message deletion i… |
| CVE-2026-88002 | 6.5 | — | open-webui | open-webui | CWE-835 | Open WebUI: Any authenticated user can hang the server via a cyclic chat mess… |
| CVE-2026-86203 | 6.3 | — | pmmp | PocketMine-MP | CWE-664 | PocketMine-MP before 5.39.2 Item Duplication via Despawn State |
| CVE-2026-78483 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-78489 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79962 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-567 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79968 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-367 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79969 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-567 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-85788 | 5.7 | — | AWS | AWS Labs MySQL MCP Server | CWE-184 | Incomplete list of disallowed inputs in awslabs mysql-mcp-server |
| CVE-2026-79730 | 5.6 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-367 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79970 | 5.6 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-347 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2025-51619 | 5.5 | — | n/a | n/a | CWE-20 | A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4… |
| CVE-2026-39020 | 5.5 | — | n/a | n/a | CWE-20 | An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of serv… |
| CVE-2026-79694 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-215 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79945 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-77 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79947 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-89 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-87921 | 5.5 | — | Rizwan17 | inventory-management-system | CWE-74 | Rizwan17 inventory-management-system manage.php update_record sql injection |
| CVE-2026-87922 | 5.5 | — | Rizwan17 | inventory-management-system | CWE-287 | Rizwan17 inventory-management-system AJAX Backend process.php DBOperation.add… |
| CVE-2026-87924 | 5.5 | — | Rizwan17 | inventory-management-system | CWE-287 | Rizwan17 inventory-management-system Invoice Generation invoice_bill.php miss… |
| CVE-2026-15460 | 5.4 | — | zephyrproject | zephyr | CWE-666 | Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path |
| CVE-2026-40635 | 5.4 | — | Dell | PowerScale OneFS | CWE-377 | Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure … |
| CVE-2026-53956 | 5.4 | — | conda | rattler_cache | CWE-22 | Rattler vulnerable to package cache path traversal via conda package build st… |
| CVE-2023-54394 | 5.3 | — | pmmp | PocketMine-MP | CWE-770 | PocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTrans… |
| CVE-2023-54395 | 5.3 | — | pmmp | PocketMine-MP | CWE-407 | PocketMine-MP before 4.12.5 Denial of Service via ModalFormResponsePacket |
| CVE-2026-64857 | 5.3 | — | tirrenotechnologies | tirreno | CWE-384 | tirreno has Session Fixation in Login Authentication |
| CVE-2026-73789 | 5.3 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM… |
| CVE-2026-79638 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-693 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79741 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-77 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79946 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-87 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79952 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-116 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79961 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-306 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79964 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-116 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79965 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-625 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79971 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-1236 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80174 | 5.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-613 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86202 | 5.3 | — | pmmp | PocketMine-MP | CWE-406 | PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket |
| CVE-2026-86743 | 5.3 | — | grokability | snipe-it | CWE-639 | Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report |
| CVE-2026-86747 | 5.3 | — | grokability | snipe-it | CWE-863 | snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User |
| CVE-2026-86752 | 5.3 | — | grokability | snipe-it | CWE-863 | snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints |
| CVE-2026-86753 | 5.3 | — | grokability | snipe-it | CWE-863 | snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint |
| CVE-2026-86755 | 5.3 | — | grokability | snipe-it | CWE-863 | Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth |
| CVE-2026-86756 | 5.3 | — | grokability | snipe-it | CWE-601 | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState |
| CVE-2026-86760 | 5.3 | — | grokability | snipe-it | CWE-863 | snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag |
| CVE-2026-86761 | 5.3 | — | grokability | snipe-it | CWE-639 | snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints |
| CVE-2026-86767 | 5.3 | — | grokability | snipe-it | CWE-200 | Snipe-IT before 8.7.0 Cross-Company Read via requested-assets |
| CVE-2026-86768 | 5.3 | — | grokability | snipe-it | CWE-20 | Snipe-IT before 8.7.0 Improper Input Validation via API Checkout |
| CVE-2026-86769 | 5.3 | — | grokability | snipe-it | CWE-282 | Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout |
| CVE-2026-86773 | 5.3 | — | grokability | snipe-it | CWE-863 | Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints |
| CVE-2026-86774 | 5.3 | — | grokability | snipe-it | CWE-284 | Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy |
| CVE-2026-87926 | 5.3 | — | Rizwan17 | inventory-management-system | CWE-79 | Rizwan17 inventory-management-system Login Page index.php cross site scripting |
| CVE-2026-86740 | 5.1 | — | grokability | snipe-it | CWE-212 | Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains |
| CVE-2026-86742 | 5.1 | — | grokability | snipe-it | CWE-1236 | Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report |
| CVE-2026-86745 | 5.1 | — | grokability | snipe-it | CWE-1236 | Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export |
| CVE-2026-86763 | 5.1 | — | grokability | snipe-it | CWE-639 | snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer |
| CVE-2026-86772 | 5.1 | — | grokability | snipe-it | CWE-79 | Snipe-IT 8.6.3 Stored XSS via Department Names |
| CVE-2026-87928 | 5.1 | — | MaxSite | MaxSite CMS | CWE-434 | MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page |
| CVE-2026-88001 | 5.0 | — | open-webui | open-webui | CWE-918 | Open WebUI: Server-side fetches reach blocked and internal hosts via unvalida… |
| CVE-2026-80171 | 4.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-331 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86776 | 4.6 | — | KeePass | KeePass | CWE-789 | KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size |
| CVE-2026-78486 | 4.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-321 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79731 | 4.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-798 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79735 | 4.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-321 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-61907 | 4.3 | — | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the… |
| CVE-2026-61911 | 4.3 | — | cyrusimap | Cyrus IMAP | CWE-497 | An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox… |
| CVE-2026-79515 | 4.3 | — | n/a | n/a | — | An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb co… |
| CVE-2026-87012 | 4.3 | — | open-webui | open-webui | CWE-754 | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide… |
| CVE-2026-87013 | 4.3 | — | open-webui | open-webui | CWE-835 | Open WebUI: Any authenticated user can start a non-terminating request via a … |
| CVE-2026-87017 | 4.3 | — | open-webui | open-webui | CWE-200 | Open WebUI: Inaccessible knowledge bases are exposed through the built-in kno… |
| CVE-2026-87875 | 4.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via mis… |
| CVE-2026-87994 | 4.3 | — | open-webui | open-webui | CWE-639 | Open WebUI: Channel members can overwrite another member's message via the ch… |
| CVE-2026-87997 | 4.3 | — | open-webui | open-webui | CWE-639 | Open WebUI: Any authenticated user can inject chats into another user's folde… |
| CVE-2026-61915 | 4.2 | — | cyrusimap | Cyrus IMAP | CWE-415 | An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARA… |
| CVE-2026-79516 | 4.0 | — | n/a | n/a | — | An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of noth… |
| CVE-2026-79690 | 3.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79729 | 3.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79732 | 3.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx… |
| CVE-2026-79736 | 3.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-46460 | 3.5 | — | Dell | PowerScale OneFS | CWE-863 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 th… |
| CVE-2026-61909 | 3.5 | — | cyrusimap | Cyrus IMAP | CWE-420 | An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget … |
| CVE-2026-61910 | 3.5 | — | cyrusimap | Cyrus IMAP | CWE-863 | An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee… |
| CVE-2026-79693 | 3.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-272 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79942 | 3.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-250 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79944 | 3.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-272 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79727 | 3.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-1258 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79966 | 3.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-532 | CWE-532: Insertion of Sensitive Information into Log File |
| CVE-2026-80169 | 3.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-532 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-61908 | 3.1 | — | cyrusimap | Cyrus IMAP | CWE-125 | An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob… |
| CVE-2026-87876 | 3.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-178 | Cups: openprinting cups: remaining case-insensitive username matching in sche… |
| CVE-2026-80239 | 2.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-1258 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86198 | 2.3 | — | pmmp | PocketMine-MP | CWE-837 | PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponseP… |
| CVE-2026-86739 | 2.3 | — | grokability | snipe-it | CWE-252 | Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence |
| CVE-2026-86744 | 2.1 | — | grokability | snipe-it | CWE-362 | snipe-it before 8.7.0 Race Condition in Asset Checkout |
| CVE-2026-87923 | 2.1 | — | Rizwan17 | inventory-management-system | CWE-79 | Rizwan17 inventory-management-system List DBOperation.php cross site scripting |
| CVE-2026-36433 | await | — | n/a | n/a | — | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46… |
| CVE-2026-38998 | await | — | n/a | n/a | — | A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia… |
| CVE-2026-41869 | await | — | Apache Software Foundation | Apache Nutch | CWE-404 | Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch S… |
| CVE-2026-41870 | await | — | Apache Software Foundation | Apache Nutch | CWE-94 | Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection … |
| CVE-2026-41871 | await | — | Apache Software Foundation | Apache Nutch | CWE-470 | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server … |
| CVE-2026-52482 | await | — | n/a | n/a | — | An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att… |
| CVE-2026-54048 | await | — | Apache Software Foundation | Apache Impala | CWE-918 | Apache Impala: Avro Schema URL Server-Side Request Forgery |
| CVE-2026-56207 | await | — | Apache Software Foundation | Apache Impala | CWE-347 | Apache Impala: SAML authentication bypass via forged bearer token |
| CVE-2026-57866 | await | — | Apache Software Foundation | Apache Impala | CWE-918 | Apache Impala: Secrets Exfiltration via SSRF |
| CVE-2026-71612 | await | — | n/a | n/a | — | Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef… |
| CVE-2026-71613 | await | — | n/a | n/a | — | Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef… |
| CVE-2026-71614 | await | — | n/a | n/a | — | An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker … |
| CVE-2026-71616 | await | — | n/a | n/a | — | An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker … |
| CVE-2026-71801 | await | — | n/a | n/a | — | An issue was discovered in s-pms SPMS-Server through v1.0. The application co… |
| CVE-2026-71802 | await | — | n/a | n/a | — | A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement … |
| CVE-2026-71803 | await | — | n/a | n/a | — | money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. Whe… |
| CVE-2026-71805 | await | — | n/a | n/a | — | An arbitrary file upload and path traversal vulnerability exists in LZ-litchi… |
| CVE-2026-71807 | await | — | n/a | n/a | — | In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task… |
| CVE-2026-71808 | await | — | n/a | n/a | — | A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows rem… |
| CVE-2026-71809 | await | — | n/a | n/a | — | Authentication Bypass via Hardcoded Master Verification Code vulnerability in… |
| CVE-2026-73334 | await | — | Apache Software Foundation | Apache Parquet Hadoop | CWE-20 | Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsC… |
| CVE-2026-74761 | await | — | Apache Software Foundation | Apache ActiveMQ Broker | CWE-20 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of Rem… |
| CVE-2026-75307 | await | — | n/a | n/a | — | zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG file upl… |
| CVE-2026-75308 | await | — | n/a | n/a | — | yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload … |
| CVE-2026-79387 | await | — | n/a | n/a | — | SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows a… |
| CVE-2026-80915 | await | — | Linux | Linux | — | drm/xe: Fix DPT allocation paths. |
| CVE-2026-80916 | await | — | Linux | Linux | — | kcov: fix data corruption and race conditions on PREEMPT_RT |
| CVE-2026-80917 | await | — | Linux | Linux | — | PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems |
| CVE-2026-80918 | await | — | Linux | Linux | — | HID: core: fix number/pointer type confusion on long items |
| CVE-2026-80919 | await | — | Linux | Linux | — | drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format |
| CVE-2026-80920 | await | — | Linux | Linux | — | io_uring: defer eventfd signaling when queued from a wakeup handler |
| CVE-2026-80922 | await | — | Linux | Linux | — | crypto: qcom-rng - Allow zero as a random number |
| CVE-2026-80923 | await | — | Linux | Linux | — | xhci: dbgtty: Fix unregister on tty_register_driver() failure |
| CVE-2026-80925 | await | — | Linux | Linux | — | vlan: fix skb_under_panic and races when toggling HW VLAN offload |