boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 9, 2026 · all times UTC← 2026-09-08 · archive

Security Box Score — September 9, 2026 — page 2

Edition of September 9, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–654 of 654
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-879309.2—MaxSiteMaxSite CMSCWE-502MaxSite CMS through 109.6 PHP Object Injection via ci_session
CVE-2026-225909.1—eProsimaFast-DDSCWE-125Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DA…
CVE-2026-878069.1—parse-communityparse-serverCWE-287Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password
CVE-2026-674039.0—SageSage AR AutomationCWE-639Cash Collect contains an improper authorization vulnerability in the Sage AR …
CVE-2026-684849.0—SageSage AR AutomationCWE-862Cash Collect contains an improper authorization vulnerability in the Sage AR …
CVE-2026-879119.0—AWSAWS Labs postgres MCP ServerCWE-78Read-only enforcement bypass enabling operating system command execution in t…
CVE-2026-809148.8—LinuxLinux—Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
CVE-2026-809218.8—LinuxLinux—KVM: s390: vsie: zero stale crypto bits
CVE-2026-860998.8—ChainlitchainlitCWE-22Chainlit through 2.12.0 Path Traversal via socket.io sessionId
CVE-2026-867758.8—knowns-devknownsCWE-22knowns before 0.30.0 Path Traversal via Document API
CVE-2026-877958.8—lubenzstd-jniCWE-125zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress
CVE-2026-878238.8—lubenzstd-jniCWE-190zstd-jni 1.1.1 through 1.5.7-13 Out-of-Bounds Read via Direct ByteBuffer Fram…
CVE-2026-879278.8—MaxSiteMaxSite CMSCWE-98MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher
CVE-2023-543558.7—pmmpPocketMine-MPCWE-347PocketMine-MP 5.2.0 Server Crash via Incorrect EC Curve
CVE-2023-543908.7—pmmpPocketMine-MPCWE-1025PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
CVE-2023-543938.7—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.20.5 Denial of Service via LoginPacket
CVE-2024-583818.7—pmmpPocketMine-MPCWE-502PocketMine-MP before 5.11.1 Denial of Service via LoginPacket
CVE-2024-583828.7—thephpleaguecommonmarkCWE-407league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity
CVE-2026-771208.7—Schneider ElectricPowerLogic T300CWE-78CWE-78: Improper Neutralization of Special Elements used in an OS Command ('O…
CVE-2026-816408.7—SoftishEarVision Android applicationCWE-798Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Cre…
CVE-2026-861998.7—pmmpPocketMine-MPCWE-184PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login
CVE-2026-862018.7—pmmpPocketMine-MPCWE-400PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData
CVE-2026-878078.7—siyuan-notesiyuanCWE-89siyuan before v3.8.2 SQL Injection via fullTextSearchBlock
CVE-2026-878088.7—siyuan-notesiyuanCWE-693SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock
CVE-2026-878168.7—pglombardoPasswordPusherCWE-362PasswordPusher before 2.11.1 Race Condition View Limit Bypass
CVE-2026-878178.7—gitpython-developersGitPythonCWE-94GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation
CVE-2026-878198.7—gitpython-developersGitPythonCWE-1333GitPython before 3.1.60 Denial of Service via ReDoS
CVE-2026-878228.7—tdunningt-digestCWE-407t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingD…
CVE-2026-878248.7—lubenzstd-jniCWE-125zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBuffer…
CVE-2026-879958.7—open-webuiopen-webuiCWE-79Open WebUI: Same-origin XSS to account takeover via terminal port-preview ifr…
CVE-2026-80448.6—Schneider ElectricEcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)CWE-88CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argumen…
CVE-2026-192338.6—Schneider ElectricEcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)CWE-918CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could c…
CVE-2026-262128.6—Rara ThemesRara One Click Demo ImportCWE-434Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE
CVE-2026-567118.6—VideoLANVLC media playerCWE-190VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Ov…
CVE-2026-793228.6—n/an/aCWE-89SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (ma…
CVE-2026-867628.6—grokabilitysnipe-itCWE-862Snipe-IT before 8.7.0 Authentication Bypass via API Middleware
CVE-2026-867708.6—grokabilitysnipe-itCWE-178Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
CVE-2026-877948.6—nfriedlybestzipCWE-88bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
CVE-2026-779748.5—SoftishEarVision Android applicationCWE-306Softish C6 Ear Camera and EarVision Android Application Missing authenticatio…
CVE-2026-867548.5—grokabilitysnipe-itCWE-863Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
CVE-2026-825638.4—SoftishEarVision Android applicationCWE-290Softish C6 Ear Camera and EarVision Android Application Authentication bypass…
CVE-2026-867418.4—grokabilitysnipe-itCWE-73Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
CVE-2026-867518.4—grokabilitysnipe-itCWE-73Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
CVE-2026-878118.4—siyuan-notesiyuanCWE-79SiYuan before v3.8.2 Stored XSS via notebook template paths
CVE-2026-878138.4—siyuan-notesiyuanCWE-79SiYuan before v3.8.2 Stored XSS via unescaped asset filenames
CVE-2026-878148.4—siyuan-notesiyuanCWE-79SiYuan before v3.8.2 Stored XSS via Asset Preview
CVE-2026-878158.4—siyuan-notesiyuanCWE-73SiYuan before v3.8.2 Path Traversal via removeRiffDeck
CVE-2026-867508.3—grokabilitysnipe-itCWE-863snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
CVE-2026-867718.3—grokabilitysnipe-itCWE-918Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
CVE-2026-181478.1—Red HatRed Hat Enterprise Linux 10CWE-79Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrar…
CVE-2026-651818.1—Apache Software FoundationApache ImpalaCWE-913Apache Impala: RCE via External Data Source Class Loading
CVE-2026-870168.1—open-webuiopen-webuiCWE-155Open WebUI: Sign-in as another user via wildcard characters in the OAuth subj…
CVE-2026-878748.1—Red HatRed Hat Ceph Storage 5CWE-502Community.general: community.general: memcached cache plugin deserializes unt…
CVE-2026-784827.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-89Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-784847.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-77Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-784937.8—DellSecure Connect Gateway 5.0 - ApplicationCWE-77Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-151407.7—EverpurePortworx OperatorCWE-266A privilege-escalation issue in the Portworx Operator when deployed on Red Ha…
CVE-2026-159137.7—FortraGoAnywhere MFTCWE-23Path Traversal in Fortra's GoAnywhere MFT Endpoint
CVE-2026-796377.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-879967.7—open-webuiopen-webuiCWE-367Open WebUI: SSRF into internal services via DNS rebinding in the Playwright w…
CVE-2026-225917.5—eProsimaFast-DDSCWE-400Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS)
CVE-2026-737867.5—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Network-Based Denial of Service in CPPM systems
CVE-2026-784907.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-307Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-793237.5—n/an/aCWE-200Information disclosure in the blogComments GraphQL query in Magefan Blog Grap…
CVE-2026-793247.5—n/an/aCWE-639Missing authorization in the Address Delete controller in Mageplaza GDPR for …
CVE-2026-796417.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-78Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797387.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-798Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797407.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-798Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799507.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-798Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-809247.5—LinuxLinux—crypto: krb5 - use kfree_sensitive() for derived key buffers
CVE-2026-870117.5—open-webuiopen-webuiCWE-405Open WebUI: Unauthenticated requests can stall the server via uncached OIDC f…
CVE-2026-878537.5—Red HatRed Hat Enterprise Linux 10CWE-187Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation
CVE-2026-784927.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799637.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-494Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-867467.4—grokabilitysnipe-itCWE-269Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay
CVE-2026-878127.4—siyuan-notesiyuanCWE-79SiYuan before v3.8.2 Stored XSS via Bazaar iconURL
CVE-2026-784857.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-22Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-796357.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-918Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-796927.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-73Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-796957.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-409Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-238557.2—DelliDRAC9CWE-78Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.3…
CVE-2026-737697.2—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Remote Code Execution in CPPM Web Interface
CVE-2026-737877.2—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web …
CVE-2026-799727.2—DellSecure Connect Gateway 5.0 - ApplicationCWE-89Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2023-543927.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacket
CVE-2023-543967.1—pmmpPocketMine-MPCWE-129PocketMine-MP before 4.8.1 Server Crash via Banner NBT
CVE-2024-583807.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 5.11.2 Denial of Service via BookEditPacket
CVE-2025-714177.1—pmmpPocketMine-MPCWE-20PocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponseP…
CVE-2026-501657.1—alfio-eventalf.ioCWE-284alf.io has Improper Access Control for Organization Owners that Exposes Syste…
CVE-2026-796177.1—TÜBİTAK BİLGEM Software Technologies Research InstitutePardus LightDM GreeterCWE-732Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardu…
CVE-2026-813307.1—SoftishEarVision Android applicationCWE-319Softish C6 Ear Camera and EarVision Android Application Cleartext transmissio…
CVE-2026-862047.1—pmmpPocketMine-MPCWE-400PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket
CVE-2026-867577.1—grokabilitysnipe-itCWE-862Snipe-IT before 8.7.0 Information Disclosure via Custom Fields
CVE-2026-867587.1—grokabilitysnipe-itCWE-204Snipe-IT before 8.7.0 License Key Exposure via CSV Export
CVE-2026-867597.1—grokabilitysnipe-itCWE-862Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer
CVE-2026-867647.1—grokabilitysnipe-itCWE-862Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components
CVE-2026-867657.1—grokabilitysnipe-itCWE-862Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint
CVE-2026-867667.1—grokabilitysnipe-itCWE-362Snipe-IT 8.6.3 Race Condition via Consumable Checkout
CVE-2026-878097.1—siyuan-notesiyuanCWE-639Siyuan before v3.8.2 Information Disclosure via Export Preview
CVE-2026-878187.1—gitpython-developersGitPythonCWE-88GitPython 3.1.59 Local File Content Oracle via --no-index
CVE-2026-878217.1—laradashboardlaradashboardCWE-918Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Mar…
CVE-2026-879987.1—open-webuiopen-webuiCWE-269Open WebUI: Non-admin users can delete admin-owned external knowledge connect…
CVE-2026-879997.1—open-webuiopen-webuiCWE-918Open WebUI: Any authenticated user can reach the Azure platform channel via s…
CVE-2026-867497.0—grokabilitysnipe-itCWE-252snipe-it before 8.7.0 Data Loss via Failed Image Write
CVE-2026-878257.0—lubenzstd-jniCWE-416zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompres…
CVE-2026-878777.0—lubenzstd-jniCWE-416zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After clo…
CVE-2025-714186.9—pmmpPocketMine-MPCWE-400PocketMine-MP before 5.25.2 Denial of Service via explode
CVE-2026-733246.9—VideoLANVLC media playerCWE-125VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminate…
CVE-2026-825306.9—IP2LocationIP2Location Country BlockerCWE-290IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header
CVE-2026-835306.9—Googlecel-goCWE-789Uncontrolled Memory Allocation in cel-go
CVE-2026-862006.9—pmmpPocketMine-MPCWE-779PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT
CVE-2026-865476.9—mrubycmrubycCWE-476mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
CVE-2026-867486.9—grokabilitysnipe-itCWE-460Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
CVE-2026-867776.9—AlchemyCMSalchemy_cmsCWE-862AlchemyCMS before 7.4.16 and 8.x before 8.3.6 Missing Authorization on GET /a…
CVE-2026-878106.9—siyuan-notesiyuanCWE-200Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock
CVE-2026-878206.9—usmannasircyberpanelCWE-200CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
CVE-2026-879256.9—Rizwan17inventory-management-systemCWE-89Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql…
CVE-2026-870156.8—open-webuiopen-webuiCWE-201Open WebUI: A user's session cookies are sent to tool servers configured for …
CVE-2026-878726.8—Red HatRed Hat Ceph Storage 5CWE-295Community.general: community.general: ocapi module_utils (ocapi_command, ocap…
CVE-2026-704256.7—DellPowerScale OneFSCWE-78Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 thr…
CVE-2026-737886.5—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Privilege Escalation in ClearPass OnGuard Agent
CVE-2026-784816.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-321Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-795136.5—n/an/a—A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function …
CVE-2026-795146.5—n/an/a—An out-of-bounds read in the gf_dm_data_received function (downloader.c) of G…
CVE-2026-795226.5—n/an/a—An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloa…
CVE-2026-797286.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-23Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-870146.5—open-webuiopen-webuiCWE-613Open WebUI: Admin demoted through SSO role sync keeps read and write access t…
CVE-2026-880006.5—open-webuiopen-webuiCWE-835Open WebUI: Any authenticated user can hang the server via message deletion i…
CVE-2026-880026.5—open-webuiopen-webuiCWE-835Open WebUI: Any authenticated user can hang the server via a cyclic chat mess…
CVE-2026-862036.3—pmmpPocketMine-MPCWE-664PocketMine-MP before 5.39.2 Item Duplication via Despawn State
CVE-2026-784835.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-784895.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799625.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-567Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799685.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-367Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799695.9—DellSecure Connect Gateway 5.0 - ApplicationCWE-567Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-857885.7—AWSAWS Labs MySQL MCP ServerCWE-184Incomplete list of disallowed inputs in awslabs mysql-mcp-server
CVE-2026-797305.6—DellSecure Connect Gateway 5.0 - ApplicationCWE-367Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799705.6—DellSecure Connect Gateway 5.0 - ApplicationCWE-347Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2025-516195.5—n/an/aCWE-20A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4…
CVE-2026-390205.5—n/an/aCWE-20An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of serv…
CVE-2026-796945.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-215Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799455.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-77Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799475.5—DellSecure Connect Gateway 5.0 - ApplicationCWE-89Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-879215.5—Rizwan17inventory-management-systemCWE-74Rizwan17 inventory-management-system manage.php update_record sql injection
CVE-2026-879225.5—Rizwan17inventory-management-systemCWE-287Rizwan17 inventory-management-system AJAX Backend process.php DBOperation.add…
CVE-2026-879245.5—Rizwan17inventory-management-systemCWE-287Rizwan17 inventory-management-system Invoice Generation invoice_bill.php miss…
CVE-2026-154605.4—zephyrprojectzephyrCWE-666Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path
CVE-2026-406355.4—DellPowerScale OneFSCWE-377Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure …
CVE-2026-539565.4—condarattler_cacheCWE-22Rattler vulnerable to package cache path traversal via conda package build st…
CVE-2023-543945.3—pmmpPocketMine-MPCWE-770PocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTrans…
CVE-2023-543955.3—pmmpPocketMine-MPCWE-407PocketMine-MP before 4.12.5 Denial of Service via ModalFormResponsePacket
CVE-2026-648575.3—tirrenotechnologiestirrenoCWE-384tirreno has Session Fixation in Login Authentication
CVE-2026-737895.3—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM…
CVE-2026-796385.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-693Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797415.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-77Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799465.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-87Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799525.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-116Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799615.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-306Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799645.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-116Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799655.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-625Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799715.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-1236Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-801745.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-613Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-862025.3—pmmpPocketMine-MPCWE-406PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
CVE-2026-867435.3—grokabilitysnipe-itCWE-639Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
CVE-2026-867475.3—grokabilitysnipe-itCWE-863snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User
CVE-2026-867525.3—grokabilitysnipe-itCWE-863snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
CVE-2026-867535.3—grokabilitysnipe-itCWE-863snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
CVE-2026-867555.3—grokabilitysnipe-itCWE-863Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
CVE-2026-867565.3—grokabilitysnipe-itCWE-601Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState
CVE-2026-867605.3—grokabilitysnipe-itCWE-863snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
CVE-2026-867615.3—grokabilitysnipe-itCWE-639snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
CVE-2026-867675.3—grokabilitysnipe-itCWE-200Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
CVE-2026-867685.3—grokabilitysnipe-itCWE-20Snipe-IT before 8.7.0 Improper Input Validation via API Checkout
CVE-2026-867695.3—grokabilitysnipe-itCWE-282Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
CVE-2026-867735.3—grokabilitysnipe-itCWE-863Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
CVE-2026-867745.3—grokabilitysnipe-itCWE-284Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
CVE-2026-879265.3—Rizwan17inventory-management-systemCWE-79Rizwan17 inventory-management-system Login Page index.php cross site scripting
CVE-2026-867405.1—grokabilitysnipe-itCWE-212Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
CVE-2026-867425.1—grokabilitysnipe-itCWE-1236Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report
CVE-2026-867455.1—grokabilitysnipe-itCWE-1236Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export
CVE-2026-867635.1—grokabilitysnipe-itCWE-639snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer
CVE-2026-867725.1—grokabilitysnipe-itCWE-79Snipe-IT 8.6.3 Stored XSS via Department Names
CVE-2026-879285.1—MaxSiteMaxSite CMSCWE-434MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page
CVE-2026-880015.0—open-webuiopen-webuiCWE-918Open WebUI: Server-side fetches reach blocked and internal hosts via unvalida…
CVE-2026-801714.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-331Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-867764.6—KeePassKeePassCWE-789KeePass 2.35 through 2.61.1 Memory Exhaustion via KDBX Header Field Size
CVE-2026-784864.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-321Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797314.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-798Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797354.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-321Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-619074.3—cyrusimapCyrus IMAPCWE-863An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the…
CVE-2026-619114.3—cyrusimapCyrus IMAPCWE-497An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox…
CVE-2026-795154.3—n/an/a—An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb co…
CVE-2026-870124.3—open-webuiopen-webuiCWE-754Open WebUI: Any authenticated user can suppress calendar alerts instance-wide…
CVE-2026-870134.3—open-webuiopen-webuiCWE-835Open WebUI: Any authenticated user can start a non-terminating request via a …
CVE-2026-870174.3—open-webuiopen-webuiCWE-200Open WebUI: Inaccessible knowledge bases are exposed through the built-in kno…
CVE-2026-878754.3—Red HatRed Hat Enterprise Linux 10CWE-125Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via mis…
CVE-2026-879944.3—open-webuiopen-webuiCWE-639Open WebUI: Channel members can overwrite another member's message via the ch…
CVE-2026-879974.3—open-webuiopen-webuiCWE-639Open WebUI: Any authenticated user can inject chats into another user's folde…
CVE-2026-619154.2—cyrusimapCyrus IMAPCWE-415An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARA…
CVE-2026-795164.0—n/an/a—An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of noth…
CVE-2026-796903.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797293.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797323.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx…
CVE-2026-797363.7—DellSecure Connect Gateway 5.0 - ApplicationCWE-295Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-464603.5—DellPowerScale OneFSCWE-863Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 th…
CVE-2026-619093.5—cyrusimapCyrus IMAPCWE-420An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget …
CVE-2026-619103.5—cyrusimapCyrus IMAPCWE-863An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee…
CVE-2026-796933.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-272Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799423.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-250Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799443.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-272Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-797273.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-1258Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-799663.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-532CWE-532: Insertion of Sensitive Information into Log File
CVE-2026-801693.3—DellSecure Connect Gateway 5.0 - ApplicationCWE-532Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-619083.1—cyrusimapCyrus IMAPCWE-125An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob…
CVE-2026-878763.0—Red HatRed Hat Enterprise Linux 10CWE-178Cups: openprinting cups: remaining case-insensitive username matching in sche…
CVE-2026-802392.4—DellSecure Connect Gateway 5.0 - ApplicationCWE-1258Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat…
CVE-2026-861982.3—pmmpPocketMine-MPCWE-837PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponseP…
CVE-2026-867392.3—grokabilitysnipe-itCWE-252Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence
CVE-2026-867442.1—grokabilitysnipe-itCWE-362snipe-it before 8.7.0 Race Condition in Asset Checkout
CVE-2026-879232.1—Rizwan17inventory-management-systemCWE-79Rizwan17 inventory-management-system List DBOperation.php cross site scripting
CVE-2026-36433await—n/an/a—An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46…
CVE-2026-38998await—n/an/a—A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia…
CVE-2026-41869await—Apache Software FoundationApache NutchCWE-404Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch S…
CVE-2026-41870await—Apache Software FoundationApache NutchCWE-94Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection …
CVE-2026-41871await—Apache Software FoundationApache NutchCWE-470Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server …
CVE-2026-52482await—n/an/a—An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote att…
CVE-2026-54048await—Apache Software FoundationApache ImpalaCWE-918Apache Impala: Avro Schema URL Server-Side Request Forgery
CVE-2026-56207await—Apache Software FoundationApache ImpalaCWE-347Apache Impala: SAML authentication bypass via forged bearer token
CVE-2026-57866await—Apache Software FoundationApache ImpalaCWE-918Apache Impala: Secrets Exfiltration via SSRF
CVE-2026-71612await—n/an/a—Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef…
CVE-2026-71613await—n/an/a—Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef…
CVE-2026-71614await—n/an/a—An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker …
CVE-2026-71616await—n/an/a—An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker …
CVE-2026-71801await—n/an/a—An issue was discovered in s-pms SPMS-Server through v1.0. The application co…
CVE-2026-71802await—n/an/a—A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement …
CVE-2026-71803await—n/an/a—money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. Whe…
CVE-2026-71805await—n/an/a—An arbitrary file upload and path traversal vulnerability exists in LZ-litchi…
CVE-2026-71807await—n/an/a—In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task…
CVE-2026-71808await—n/an/a—A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows rem…
CVE-2026-71809await—n/an/a—Authentication Bypass via Hardcoded Master Verification Code vulnerability in…
CVE-2026-73334await—Apache Software FoundationApache Parquet HadoopCWE-20Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsC…
CVE-2026-74761await—Apache Software FoundationApache ActiveMQ BrokerCWE-20Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of Rem…
CVE-2026-75307await—n/an/a—zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG file upl…
CVE-2026-75308await—n/an/a—yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload …
CVE-2026-79387await—n/an/a—SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows a…
CVE-2026-80915await—LinuxLinux—drm/xe: Fix DPT allocation paths.
CVE-2026-80916await—LinuxLinux—kcov: fix data corruption and race conditions on PREEMPT_RT
CVE-2026-80917await—LinuxLinux—PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
CVE-2026-80918await—LinuxLinux—HID: core: fix number/pointer type confusion on long items
CVE-2026-80919await—LinuxLinux—drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
CVE-2026-80920await—LinuxLinux—io_uring: defer eventfd signaling when queued from a wakeup handler
CVE-2026-80922await—LinuxLinux—crypto: qcom-rng - Allow zero as a random number
CVE-2026-80923await—LinuxLinux—xhci: dbgtty: Fix unregister on tty_register_driver() failure
CVE-2026-80925await—LinuxLinux—vlan: fix skb_under_panic and races when toggling HW VLAN offload