boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, September 10, 2026 · all times UTC← 2026-09-09 · archive

Security Box Score — September 10, 2026

CISA adds 2 to KEV; 384 CVEs published, led by IBM (49).

384 CVEs published September 10, 2026: 59 critical, 170 high, 135 medium, 7 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 13 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 359 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published478539670——
KEV catalog size1705

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2514 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux2004283420202170611230.17.8.0016-190 ▼
microsoft9752874189197769216289301.07.8.0044+942 ▲
google360252631897311091207980.37.5.0025+317 ▲
red hat676924328832437200.06.7.0028-8 ▼
apple0316598516578882.56.5.0029-1 ▼
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco12962446260571414.67.5.0041-18 ▼
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0021+9 ▲
fortinet93991017329717.96.7.0038+9 ▲
netgear23400277000.04.3.0025+2 ▲
ivanti102410122025520.88.8.0146+10 ▲
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050+3 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache30539116228181133320.47.5.0048-45 ▼
mozilla352228079630900.08.1.0029+34 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab076317479422.65.3.00290
github32011090000.07.3.0044+1 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
adobe17077657343366102040.57.5.0023+162 ▲
ibm1217401613412299610.17.5.0029+89 ▲
progress2631439100611.68.1.0035-9 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+5 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link8531619108300.08.5.0157-7 ▼
siemens145163393000.07.3.0018+14 ▲
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric71611140000.08.5.0039+7 ▲
hikvision390540000.07.1.0040+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1343052514012218210.37.2.0020+126 ▲
sourcecodester261950011481000.05.5.0028+14 ▲
spring017012608315000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb49147486534100.07.1.0026+49 ▲
itsourcecode241400036104000.02.1.0026+16 ▲
elastic42129127983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-73570.323898.28.9
CVE-2026-64849.164196.89.3
CVE-2026-83549.085194.77.8
CVE-2026-19681.078094.39.4
CVE-2026-82329.076794.29.8
CVE-2026-19490.060092.99.3
CVE-2026-19478.058192.79.1
CVE-2026-19586.057092.69.3
CVE-2026-79756.051591.98.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-1918810.0.0193
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8200410.0.0144
CVE-2026-7329910.0.0121
CVE-2026-7367810.0.0114
Most disclosures (vendor)
VendorCVEs
linux1455
microsoft1017
oracle890
google713
ibm479
adobe211
dell198
red hat191
apache121
splunk110
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco14
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
oracle4
solarwinds4
Most-affected ecosystems
EcosystemAdvisories
Maven45
Packagist38
npm19
PyPI15
RubyGems2
Go1
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171758
CVE-2021-27102n/a2021-11-171758
CVE-2021-27101n/a2021-11-171758
CVE-2021-27103n/a2021-11-171758
CVE-2021-21017Adobe2021-11-171758
CVE-2021-28550Adobe2021-11-171758
CVE-2021-42013Apache Software Foundation2021-11-171758
CVE-2021-41773Apache Software Foundation2021-11-171758
CVE-2021-30858Apple2021-11-171758
CVE-2021-30860Apple2021-11-171758

Transactions

ADDED TO KEV — CVE-2026-67277 (Mikrotik RouterOS). Remediation due September 13, 2026.

ADDED TO KEV — CVE-2026-86060 (Mikrotik RouterOS). Remediation due September 13, 2026.

EXPLOIT PUBLISHED — Google Chrome: 25 CVEs (CVE-2026-87441, CVE-2026-87445, CVE-2026-87447, CVE-2026-87475, CVE-2026-87482, CVE-2026-87483, CVE-2026-87484, CVE-2026-87486, CVE-2026-87496, CVE-2026-87497, CVE-2026-87501, CVE-2026-87503, CVE-2026-87505, CVE-2026-87513, CVE-2026-87515, CVE-2026-87528, CVE-2026-87532, CVE-2026-87533, CVE-2026-87535, CVE-2026-87540, CVE-2026-87577, CVE-2026-87586, CVE-2026-87596, CVE-2026-87599, CVE-2026-87615). Public exploit references added.

EXPLOIT PUBLISHED — axios: 14 CVEs (CVE-2025-62718, CVE-2026-25639, CVE-2026-42033, CVE-2026-42039, CVE-2026-42041, CVE-2026-42043, CVE-2026-42044, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — GNOME GLib: 5 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015). Public exploit references added.

EXPLOIT PUBLISHED — jsrsasign: 5 CVEs (CVE-2026-4598, CVE-2026-4599, CVE-2026-4600, CVE-2026-4601, CVE-2026-4602). Public exploit references added.

EXPLOIT PUBLISHED — XenForo: 5 CVEs (CVE-2026-73311, CVE-2026-73314, CVE-2026-73316, CVE-2026-73319, CVE-2026-73321). Public exploit references added.

EXPLOIT PUBLISHED — authlib: 3 CVEs (CVE-2026-27962, CVE-2026-28498, CVE-2026-28802). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2022-41352. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-22373 (Grassroot DICOM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-25249 (Fortinet FortiSwitchManager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-2332 (Eclipse Foundation Eclipse Jetty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-24049 (pypa wheel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-25896 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26278 (NaturalIntelligence fast-xml-parser). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-27606 (rollup). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29063 (immutable-js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-29074 (svgo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-30922 (pyasn1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-32597 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42945 (F5 NGINX Plus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48526 (jpadilla pyjwt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56101 (OpenBSD). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-61517 (Netis Systems NX10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67277 (Mikrotik RouterOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-6958 (Invicti Security Corp. Acunetix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80093 (Microsoft Windows 10 Version 1809). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80113 (PassMark Software PerformanceTest). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80118 (PassMark Software PerformanceTest). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82533 (DeepSeek Harness). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85639 (jofpin trape). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85704 (ramon-victor freegpt-webui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86060 (Mikrotik RouterOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86208 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86213 (Mstfakts College-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86666 (aircheng-org iWebShop-5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86675 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86776 (KeePass). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87922 (Rizwan17 inventory-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87924 (Rizwan17 inventory-management-system). Public exploit reference added.

DUE DATE PASSED — CVE-2015-3246. CISA remediation deadline was September 9, 2026; still in catalog.

DUE DATE PASSED — CVE-2015-5287. CISA remediation deadline was September 9, 2026; still in catalog.

DUE DATE PASSED — CVE-2021-23758 (AjaxPro.2). CISA remediation deadline was September 9, 2026; still in catalog.

DUE DATE PASSED — CVE-2022-0995 (kernel). CISA remediation deadline was September 9, 2026; still in catalog.

REJECTED — CVE-2026-73392 (highwarden Super Store Finder). Record withdrawn by the CNA.

RESCORED — Microsoft Windows 10 Version 1607: 5 CVEs (CVE-2026-69803, CVE-2026-69929, CVE-2026-69930, CVE-2026-70124, CVE-2026-78523). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2016-4117. CVSS 7.8 → 9.8 (NVD).

RESCORED — CVE-2020-14498 (HMS Industrial Networks AB eCatcher). CVSS 9.6 → 10 (NVD).

RESCORED — CVE-2024-14047 (Elastic Security). CVSS 7.2 → 7.1 (NVD).

RESCORED — CVE-2025-25249 (Fortinet FortiSwitchManager). CVSS 7.4 → 9.8 (NVD).

RESCORED — CVE-2026-16481 (Google MCP Toolbox for Databases (googleapis/mcp-toolbox)). CVSS 8.4 → 6 (NVD).

RESCORED — CVE-2026-18622 (Foxit Software Inc. Foxit PDF Editor). CVSS 4.7 → 5.5 (NVD).

RESCORED — CVE-2026-24301 (Microsoft Copilot Web). CVSS 8.8 → 7.5 (NVD).

RESCORED — CVE-2026-47878 (Spring Batch). CVSS 5.6 → 7.3 (NVD).

RESCORED — CVE-2026-47879 (Spring Cloud Gateway). CVSS 7.7 → 8.7 (NVD).

RESCORED — CVE-2026-73763 (Hewlett Packard Enterprise (HPE) AOS-CX). CVSS 7.1 → 8.8 (NVD).

RESCORED — CVE-2026-73778 (Hewlett Packard Enterprise (HPE) AOS-CX). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-75003 (Roundcube Webmail). CVSS 5.8 → 9.8 (NVD).

RESCORED — CVE-2026-81994 (Adobe Acrobat). CVSS 8.2 → 6.3 (NVD).

RESCORED — CVE-2026-87534 (Google Chrome). CVSS 6.5 → 9.8 (NVD).

RESCORED — CVE-2026-87641 (Google Chrome). CVSS 5.3 → 4.2 (NVD).

RESCORED — CVE-2026-87925 (Rizwan17 inventory-management-system). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-87926 (Rizwan17 inventory-management-system). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-87931 (Behavioral Technology Group Pavlok Behavioral Conditioning Wearable). CVSS 9.4 → 8.6 (NVD).

RESCORED — CVE-2026-9736 (IBM Netezza Software). CVSS 5.3 → 4.3 (NVD).

RESCORED — CVE-2026-9744 (IBM Netezza Software). CVSS 5.3 → 5.9 (NVD).

PATCH SHIPPED — CVE-2026-19654 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:8.2412.0-1.el10_0.1.

PATCH SHIPPED — CVE-2026-85150 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.2.

ENRICHED — Google Chrome: 6 CVEs (CVE-2026-87544, CVE-2026-87546, CVE-2026-87551, CVE-2026-87571, CVE-2026-87575, CVE-2026-87656). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

384 CVEs published. 25 box scores, 359 table rows — nothing truncated.

Palo Alto Networks Checkov by Prisma Cloud — Checkov by Prisma Cloud: OS Command Injection Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   P   N   L   N    1.1   .0082   55.2     —
AFFECTED
  Product                  Versions  Fixed
  Checkov by Prisma Cloud  3.2.0 –   3.2.502
TIMELINE
  Nov 3   Reserved by CNA
  Sep 10  Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
addonsorg Drag and Drop File Upload for Elementor Forms — Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.4     —
AFFECTED
  Product                                        Versions     Fixed
  Drag and Drop File Upload for Elementor Forms  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Sep 10  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
cssimmon WP BackItUp Community Edition — WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0075   52.7     —
AFFECTED
  Product                        Versions     Fixed
  WP BackItUp Community Edition  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Sep 10  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
kamalyon Direct Download for WooCommerce — Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0068   50.2     —
AFFECTED
  Product                          Versions     Fixed
  Direct Download for WooCommerce  unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Sep 10  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Rapid7 Velociraptor — Velociraptor Required Permissions bypass by using client monitoring queries
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  L    9.9   .0060   46.8     —
AFFECTED
  Product       Versions     Fixed
  Velociraptor  unspecified  —
TIMELINE
  Aug 11  Reserved by CNA
  Sep 10  Published (CNA: rapid7)
CWE-732 · CNA: rapid7 · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
joomlart.com T4 Page Builder extension for Joomla — Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   L    6.9   .0054   43.6     —
AFFECTED
  Product                               Versions       Fixed
  T4 Page Builder extension for Joomla  1.0.0-2.2.0 –  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 10  Published (CNA: Joomla)
CWE-201 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Deferred
joomshaper.com SP Property extension for Joomla — Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0049   40.6     —
AFFECTED
  Product                           Versions       Fixed
  SP Property extension for Joomla  1.0.0-4.1.3 –  —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 10  Published (CNA: Joomla)
CWE-89 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Deferred
Palo Alto Networks Cloud NGFW — PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   P   H   N   H   H   H    4.0   .0045   37.7     —
AFFECTED
  Product        Versions     Fixed
  Cloud NGFW     unspecified  All
  PAN-OS         12.2.0 –     12.2.3
  Prisma Access  unspecified  All
TIMELINE
  Nov 3   Reserved by CNA
  Sep 10  Published (CNA: palo_alto)
CWE-78 · CNA: palo_alto · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
SUSE Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 — fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0044   36.9     —
AFFECTED
  Product                                         Versions  Fixed
  Container suse/kiosk/tigervnc-x11vnc:1.14-63.8  ? –       —
  Container suse/kiosk/xorg:21.1-83.7             ? –       —
  Image SLES15-SP6-SAP                            ? –       —
  Image SLES15-SP6-SAP-Azure                      ? –       —
  Image SLES15-SP6-SAP-Azure-3P                   ? –       —
  Image SLES15-SP6-SAP-BYOS                       ? –       —
  Image SLES15-SP6-SAP-BYOS-Azure                 ? –       —
  Image SLES15-SP6-SAP-BYOS-EC2                   ? –       —
  Image SLES15-SP6-SAP-BYOS-GCE                   ? –       —
  Image SLES15-SP6-SAP-EC2                        ? –       —
  + 96 more
TIMELINE
  May 8   Reserved by CNA
  Sep 10  Published (CNA: suse)
CWE-122 · CNA: suse · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
joomshaper.com SP Property extension for Joomla — Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   L    8.6   .0044   36.8     —
AFFECTED
  Product                           Versions       Fixed
  SP Property extension for Joomla  1.0.0-4.1.3 –  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 10  Published (CNA: Joomla)
CWE-79 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Deferred
D-ZERO CO.,LTD. BurgerEditor — BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   N    8.5   .0043   36.7     —
AFFECTED
  Product       Versions                 Fixed
  BurgerEditor  3.2.0 through 3.4.0 –    —
  BurgerEditor  2.28.0 through 2.30.0 –  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 10  Published (CNA: jpcert)
CWE-434 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Deferred
joomshaper.com SP Property extension for Joomla — Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   L    6.9   .0043   36.1     —
AFFECTED
  Product                           Versions       Fixed
  SP Property extension for Joomla  1.0.0-4.1.3 –  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 10  Published (CNA: Joomla)
CWE-201 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Deferred
SUSE Container suse/kiosk/tigervnc-x11vnc:1.14-63.8 — fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.2   .0041   34.6     —
AFFECTED
  Product                                         Versions  Fixed
  Container suse/kiosk/tigervnc-x11vnc:1.14-63.8  ? –       —
  Container suse/kiosk/xorg:21.1-83.7             ? –       —
  Image SLES15-SP6-SAP                            ? –       —
  Image SLES15-SP6-SAP-Azure                      ? –       —
  Image SLES15-SP6-SAP-Azure-3P                   ? –       —
  Image SLES15-SP6-SAP-BYOS                       ? –       —
  Image SLES15-SP6-SAP-BYOS-Azure                 ? –       —
  Image SLES15-SP6-SAP-BYOS-EC2                   ? –       —
  Image SLES15-SP6-SAP-BYOS-GCE                   ? –       —
  Image SLES15-SP6-SAP-EC2                        ? –       —
  + 96 more
TIMELINE
  Jul 6   Reserved by CNA
  Sep 10  Published (CNA: suse)
CWE-787 · CNA: suse · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
GeoVision Inc. GV-LPC2011/LPC2211 — GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   30.5     —
AFFECTED
  Product             Versions  Fixed
  GV-LPC2011/LPC2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPC2011/LPC2211 — GV-LPC2011/LPC2211 - Wireless SSID Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   30.5     —
AFFECTED
  Product             Versions  Fixed
  GV-LPC2011/LPC2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPC2011/LPC2211 — GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   30.5     —
AFFECTED
  Product             Versions  Fixed
  GV-LPC2011/LPC2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   30.5     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPC2011/LPC2211 — GV-LPC2011/LPC2211 - Arbitrary File Read Through BKDownloadLink.cgi Symlink Creation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0037   29.9     —
AFFECTED
  Product             Versions  Fixed
  GV-LPC2011/LPC2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-36 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPCLPC2011/2211 — GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0034   27.4     —
AFFECTED
  Product             Versions  Fixed
  GV-LPCLPC2011/2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-78 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
Palo Alto Networks Cloud NGFW — PAN-OS: Buffer Overflow Vulnerability via XML Processing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    7.2   .0034   26.8     —
AFFECTED
  Product        Versions  Fixed
  Cloud NGFW     All –     —
  PAN-OS         12.2.0 –  12.2.3
  Prisma Access  11.2.0 –  12.1.0
TIMELINE
  Nov 3   Reserved by CNA
  Sep 10  Published (CNA: palo_alto)
CWE-787 · CNA: palo_alto · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
davidanderson Redux Framework — Redux Framework <= 4.5.13.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   26.4     —
AFFECTED
  Product          Versions     Fixed
  Redux Framework  unspecified  —
TIMELINE
  Apr 2   Reserved by CNA
  Sep 10  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
GeoVision Inc. GV-LPC2011/LPC2211 — GV-LPC2011/LPC2211 - Multiple Pre-Authentication Stack Buffer Overflows in VLSVR Request Handlers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0033   25.6     —
AFFECTED
  Product             Versions         Fixed
  GV-LPC2011/LPC2211  1.14 20260903 –  1.14 20260909
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-121 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
joomshaper.com SP Property extension for Joomla — Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   L    6.9   .0032   25.3     —
AFFECTED
  Product                           Versions       Fixed
  SP Property extension for Joomla  1.0.0-4.1.3 –  —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 10  Published (CNA: Joomla)
CWE-284, CWE-352 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Deferred
Armiya Information Technologies Ltd. Co. Access Control System — SQLi in Armiya Information Technologies' Access Control System
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0032   24.8     —
AFFECTED
  Product                Versions     Fixed
  Access Control System  unspecified  —
TIMELINE
  Apr 27  Reserved by CNA
  Sep 10  Published (CNA: TR-CERT)
CWE-89 · CNA: TR-CERT · CVSS v3.1 · 1 reference · NVD status: Deferred
GeoVision Inc. GV-LPC2011/LPC2211 — GV-LPC2011/LPC2211 -ONVIF Discovery Probe Scopes Stack-Frame Overflow Denial of Service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0031   24.0     —
AFFECTED
  Product             Versions  Fixed
  GV-LPC2011/LPC2211  1.13 –    1.14
TIMELINE
  Sep 10  Reserved by CNA
  Sep 10  Published (CNA: GV)
CWE-121 · CNA: GV · CVSS v3.1 · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-878037.123.3Countlycountly-serverCWE-863An authorization bypass vulnerability exists in the Countly Server DBViewer d…
CVE-2026-879335.523.2DaveGamblecJSONCWE-119DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free
CVE-2026-882727.222.5GeoVision Inc.GV-LPC2011/LPC2211CWE-78GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection
CVE-2026-882827.222.5GeoVision Inc.GV-LPCLPC2011/2211CWE-78GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
CVE-2026-137459.222.4Google CloudGemini CLICWE-20Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
CVE-2026-840625.322.1D-ZERO CO.,LTD.BurgerEditorCWE-639BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass …
CVE-2026-675939.121.2Apache Software FoundationApache ArtemisCWE-306Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Arte…
CVE-2026-829258.121.2UnknownSite ReviewsCWE-502Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Si…
CVE-2026-493637.521.0Apache Software FoundationApache ArtemisCWE-306Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Discl…
CVE-2026-579679.820.2Apache Software FoundationApache ArtemisCWE-306Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE proto…
CVE-2026-882859.419.6GeoVision Inc.GV-LPC2011/LPC2211CWE-306GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service
CVE-2026-882789.818.9GeoVision Inc.GV-LPCLPC2011/2211CWE-294GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay
CVE-2026-03081.118.4Palo Alto NetworksCloud NGFWCWE-79PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
CVE-2026-882867.518.0GeoVision Inc.GV-LPC2011/LPC2211CWE-400GV-LPC2011/LPC2211 - PTZ Connection-State Accept-Loop Denial of Service
CVE-2026-882907.518.0GeoVision Inc.GV-LPC2011/LPC2211CWE-400GV-LPC2011/LPC2211 - Unauthenticated VLSVR Slowloris and Memory Resource Exha…
CVE-2026-83239.316.9Armiya Information Technologies Ltd. Co.Access Control SystemCWE-601Open Redirect in Armiya Information Technologies' Access Control System
CVE-2026-428047.616.9Bosch SensortecBHI360_SensorAPI (C-Library)CWE-121A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI…
CVE-2026-882794.916.6GeoVision Inc.GV-LPC2011/LPC2211CWE-121GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow…
CVE-2026-882804.916.6GeoVision Inc.GV-LPC2011/LPC2211CWE-121GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service
CVE-2026-882814.916.6GeoVision Inc.GV-LPC2011/LPC2211CWE-121GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial…
CVE-2026-882834.916.6GeoVision Inc.GV-LPC2011/LPC2211CWE-121GV-LPC2011/LPC2211 - ONVIF CreateUsers Repeated-Element Stack-Frame Overflow …
CVE-2026-882844.916.6GeoVision Inc.GV-LPC2011/LPC2211 -CWE-121GV-LPC2011/LPC2211 - ONVIF SetUser Repeated-Element Stack-Frame Overflow Deni…
CVE-2026-158896.416.3arubadevAruba HiSpeed CacheCWE-79Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-887635.916.3Red HatRed Hat Service Interconnect 2CWE-674Skupper-router: skupper-router: unbounded recursion in amqp field parser lead…
CVE-2026-46576.415.2sunny_johalEasy Google FontsCWE-79Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Script…
CVE-2026-882686.514.8GeoVision Inc.GV-LPCLPC2011/2211CWE-121GV-LPC2011/LPC2211 - SSVR Fragment-Reassembly Stack Overflow Denial of Service
CVE-2026-765627.214.6otwthemesSidebar Manager LightCWE-79Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting v…
CVE-2026-148738.014.5rubenwBulk Password ResetCWE-862Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password…
CVE-2026-882718.814.0GeoVision Inc.GV-LPC2011/LPC2211CWE-862GV-LPC2011/LPC2211 - SSVR Guest Configuration Overwrite and Administrative Cr…
CVE-2026-493627.513.3Apache Software FoundationApache ArtemisCWE-306Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Proto…
CVE-2026-03044.812.2Palo Alto NetworksCortex XDR Broker VMCWE-88Cortex XDR Broker VM: Privilege Escalation Vulnerability
CVE-2026-856456.111.910webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-79Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.1…
CVE-2026-887706.511.6Red HatRed Hat Build of KeycloakCWE-307Keycloak-services: keycloak-services: device authorization grant issues token…
CVE-2026-185944.311.6vsourz1tdAdvanced Contact form 7 DBCWE-862Advanced Contact form 7 DB <= 2.1.3 - Missing Authorization to Authenticated …
CVE-2026-849399.111.5Apache Software FoundationApache FreeMarkerCWE-23Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable f…
CVE-2026-882706.511.2GeoVision Inc.GV-LPC2011/LPC2211CWE-862GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown…
CVE-2026-878706.410.8Saturday DriveNinja Forms - Scheduled ExportsCWE-79Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored…
CVE-2026-158234.310.9builderallBuilderall for WordPressCWE-862Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (S…
CVE-2026-780837.110.6joomshaper.comSP Property extension for JoomlaCWE-352Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Proper…
CVE-2026-428078.010.4Bosch SensortecCOINES_SDKCWE-122A heap-based buffer overflow vulnerability in the PC bridge protocol decoder …
CVE-2026-882696.510.0GeoVision Inc.GV-LPC2011/LPC2211CWE-862GV-LPC2011/LPC2211 - SSVR Guest Configuration and Credential Disclosure
CVE-2026-158206.410.0builderallBuilderall for WordPressCWE-79Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross…
CVE-2026-825825.310.0SHIRASAGI ProjectSHIRASAGICWE-639An authorization bypass vulnerability exists in SHIRASAGI through a user-cont…
CVE-2026-157966.49.1builderallBuilderall for WordPressCWE-79Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross…
CVE-2026-428086.88.8Bosch SensortecCOINES_SDKCWE-120An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.…
CVE-2026-195847.78.7Rapid7VelociraptorCWE-94Velociraptor VQL injection during notebook restore from backup
CVE-2026-803519.87.9Apache Software FoundationApache Camel KCWE-95Apache Camel K: Camel K Tenant repositories reach Maven execution inside oper…
CVE-2026-578226.56.7Apache Software FoundationApache ArtemisCWE-502Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter d…
CVE-2026-803529.85.9Apache Software FoundationApache Camel KCWE-94Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets C…
CVE-2026-493649.15.8Apache Software FoundationApache ArtemisCWE-306Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Arte…
CVE-2026-758806.55.4Apache Software FoundationApache ArtemisCWE-1333Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling c…
CVE-2026-820797.05.2NintendoNintendo SwitchCWE-121Potential Leakage of Nintendo Switch System Information Through a Proximity-B…
CVE-2026-428064.34.8Bosch SensortecBME690 SensorAPI (C)CWE-125An out-of-bounds read vulnerability was discovered in the Bosch BME690 Sensor…
CVE-2026-816355.14.6SHIRASAGI ProjectSHIRASAGICWE-79A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an …
CVE-2026-194397.54.1UnknownUltimate Gift Cards for WooCommerceCWE-200Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card…
CVE-2026-428058.43.8Bosch SensortecBHI385 SensorAPI (C Library)CWE-121A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI…
CVE-2026-803548.13.7Apache Software FoundationApache Camel KCWE-639Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tena…
CVE-2026-783619.13.4UnknownzipMoney(Zip Co) Payments Plugin for WooCommerceCWE-862zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Ar…
CVE-2026-194367.53.4UnknownUltimate Gift Cards for WooCommerceCWE-284Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Valu…
CVE-2026-7777010.03.1UnknownminiOrange 2FACWE-862miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via O…
CVE-2026-777717.53.1UnknownminiOrange 2FACWE-287miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
CVE-2026-814317.23.1UnknownRegistration Form for WooCommerceCWE-269Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Esca…
CVE-2026-198406.53.1UnknownNotiqooCWE-863Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Act…
CVE-2026-03032.42.8Palo Alto NetworksCheckov by Prisma CloudCWE-829Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
CVE-2026-882655.62.0Red HatRed Hat Hardened ImagesCWE-59Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mou…
CVE-2026-882645.61.9Red HatRed Hat Hardened ImagesCWE-59Crun: crun: /dev/console symlink follow allows root-owned file creation outsi…
CVE-2026-03075.91.2Palo Alto NetworksGlobalProtect AppCWE-426GlobalProtect App: Local Privilege Escalation Vulnerabilities
CVE-2026-03065.81.2Palo Alto NetworksPrisma Access AgentCWE-693Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows
CVE-2026-840427.80.9Red HatRed Hat Hardened ImagesCWE-269Crun: crun: rootful krun with passt executes container payload as host root
CVE-2026-03054.30.9Palo Alto NetworksPrisma Access AgentCWE-200Prisma Access Agent: Information Disclosure Vulnerability on Linux
CVE-2026-684879.9—WebProsPleskCWE-36Path traversal in Plesk's Backup Manager causes arbitrary file write as root …
CVE-2026-684889.9—WebProsPleskCWE-367A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symli…
CVE-2026-890949.9—ForgejoForgejoCWE-1336Forgejo before 16.0.4 allows remote code execution via a crafted template rep…
CVE-2026-91639.8—GIS InformaticsGisLab Laboratory Management SystemCWE-89SQLi in GIS Informatics' GisLab Laboratory Management System
CVE-2026-520989.8—n/an/aCWE-94An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code …
CVE-2026-785739.8—IBMContextForge MCP GatewayCWE-1392IBM ContextForge MCP Gateway is affected by use of default credentials
CVE-2026-797249.8—IBMLangflow OSSCWE-78Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-812049.8—IBMLangflow OSSCWE-94Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-814679.8—DellThinOS 10CWE-78Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutral…
CVE-2026-850259.8—IBMLangflow OSSCWE-863Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-880189.8—rclonercloneCWE-287rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full …
CVE-2026-810489.6—DellThinOS 10CWE-77Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutraliz…
CVE-2026-821009.6—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-821079.6—IBMDataStage on Cloud Pak for DataCWE-287DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-656399.5—WebProsConfigServer Security & FirewallCWE-78OS command injection in the advanced-rule parser of ConfigServer Security & F…
CVE-2026-880629.5—diegosouzapwOmniRouteCWE-94OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
CVE-2026-810469.4—DellThinOS 10CWE-284Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanis…
CVE-2026-759409.3—LenovoHealth ApplicationCWE-798A vulnerability was reported in Lenovo Health Android Application, distribute…
CVE-2026-818009.3—Par avisverifiesVerified Reviews (Avis Vérifiés)CWE-89WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vu…
CVE-2026-888609.3—Cap-gocapgo.appCWE-863Capgo Authorization Bypass via Stale Channel Permission Overrides
CVE-2026-888649.3—Cap-gocapgo.appCWE-284Capgo SSO Provider Authentication Bypass via PostgREST Direct Write
CVE-2026-888669.3—WWBNAVideoCWE-79WWBN AVideo LoginControl Stored XSS via User-Agent Header
CVE-2026-888679.3—WWBNAVideoCWE-79WWBN AVideo Stored XSS via Category Name and Icon Class
CVE-2026-888689.3—WWBNAVideoCWE-79AVideo LiveLinks Stored XSS via title and description fields
CVE-2026-888699.3—WWBNAVideoCWE-79AVideo AD_Server Stored XSS via log.php label parameter
CVE-2026-888779.3—traefiktraefikCWE-639Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
CVE-2026-888999.3—knowns-devknownsCWE-73knowns before 0.31.0 External Control of Agent Working Directory via x-openco…
CVE-2026-890429.3—krakenjspassport-saml-encryptedCWE-347passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Sign…
CVE-2026-656389.2—WebProsConfigServer Security & FirewallCWE-78Improper escaping of a request URL in ConfigServer Security & Firewall allows…
CVE-2026-888809.2—renovatebotrenovateCWE-601Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-888819.2—renovatebotrenovateCWE-601Renovate before 44.11.3 Credential Exfiltration via Link Header
CVE-2026-888829.2—renovatebotrenovateCWE-601Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-888879.2—renovatebotrenovateCWE-601Renovate before 44.11.2 Credential Exfiltration via Link Header
CVE-2026-196469.1—IBMCommon LicensingCWE-1149Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-457649.1—OISFsuricataCWE-843Suricata http2: protocol-change type confusion can lead to denial of service
CVE-2026-804249.1—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-814689.1—DellThinOS 10CWE-78Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutral…
CVE-2026-880079.1—traefiktraefikCWE-287Traefik HTTP/3 Backend NTLM Connection Reuse
CVE-2026-880449.1—rclonercloneCWE-863rclone: RC per-server auth-proxy bypass
CVE-2026-890439.1—krakenjspassport-saml-encryptedCWE-347passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion P…
CVE-2026-890869.1—OCamljoseCWE-347In the jose package before 0.11.0 for OCaml, library calls to validate an RSA…
CVE-2026-756248.8—IBMApp Connect EnterpriseCWE-863IBM App Connect Enterprise is vulnerable to privilege escalation and Denial o…
CVE-2026-757778.8—IBMAspera Enterprise WebAppsCWE-269Multiple vulnerabilities in IBM Aspera Enterprise Webapps
CVE-2026-760598.8—IBMLangflow OSSCWE-693Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-785698.8—IBMLangflow OSSCWE-78Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-785718.8—IBMLangflow OSSCWE-94Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-785758.8—IBMLangflow OSSCWE-78Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-797428.8—IBMLangflow OSSCWE-94Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-812118.8—IBMLangflow OSSCWE-862Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-815508.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-815518.8—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-815548.8—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-819408.8—IBMLangflow OSSCWE-94Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-819418.8—IBMLangflow OSSCWE-284Langflow is vulnerable to arbitrary code execution due to multiple incomplete…
CVE-2026-820928.8—IBMDataStage on Cloud Pak for DataCWE-36DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-820958.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-820978.8—IBMDataStage on Cloud Pak for DataCWE-918DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-820988.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-820998.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-848898.8—IBMLangflow OSSCWE-22A path traversal vulnerability in file handling components could allow an aut…
CVE-2026-852288.8—AmazonDeep Java LibraryCWE-190Integer overflow in tensor buffer validation in Deep Java Library
CVE-2026-880098.8—traefiktraefikCWE-444Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbat…
CVE-2026-890468.8—lubenzstd-jniCWE-125zstd-jni 1.5.5-6 through 1.5.7-13 Out-of-Bounds Read via Negative Offset
CVE-2026-161748.7—NetskopeEndpoint DLPCWE-190Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow
CVE-2026-648368.7—ICEcoderICEcoderCWE-22ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement
CVE-2026-648378.7—ICEcoderICEcoderCWE-78ICEcoder through 8.1 OS Command Injection via lib/properties.php
CVE-2026-648388.7—ICEcoderICEcoderCWE-22ICEcoder through 8.1 Path Traversal via oldFileName Parameter
CVE-2026-736938.7—FileRunFileRunCWE-78FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler
CVE-2026-755848.7—nasa-jplION-DTNCWE-617ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion
CVE-2026-799878.7—craftcmscmsCWE-470Low-privilege RCE through element-search eager loading
CVE-2026-879628.7—tdunningt-digestCWE-1284t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in M…
CVE-2026-888618.7—Cap-gocapgo.appCWE-288Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization
CVE-2026-888628.7—Cap-gocapgo.appCWE-863Capgo API Key Manager Authentication Bypass via x-limited-key-id
CVE-2026-888748.7—WWBNAVideoCWE-200AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass
CVE-2026-888768.7—WWBNAVideoCWE-200AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD
CVE-2026-888938.7—Openpanel-devopenpanelCWE-200OpenPanel Unauthenticated Share Lookup Information Disclosure
CVE-2026-889398.7—knowns-devknownsCWE-863knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
CVE-2026-889598.7—anchorcmsAnchor CMSCWE-862Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on A…
CVE-2026-41298.6—NISystemLinkCWE-862Improper Access Controls in NI SystemLink
CVE-2026-736948.6—FileRunFileRunCWE-78FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition
CVE-2026-736988.6—FileRunFileRunCWE-89FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
CVE-2026-736998.6—FileRunFileRunCWE-502FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()
CVE-2026-812138.6—IBMLangflow OSSCWE-918Langflow is vulnerable to server-side request forgery due to missing egress v…
CVE-2026-817898.6—Maarten BAdvanced Product Fields Extended for WooCommerceCWE-22WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - …
CVE-2026-852178.6—AutodeskFusionCWE-15Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
CVE-2026-880478.6—tesseract-ocrtesseractCWE-121Tesseract: ReadNormProtos stack buffer overflow
CVE-2026-880488.6—tesseract-ocrtesseractCWE-125Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer…
CVE-2026-880498.6—tesseract-ocrtesseractCWE-787Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dime…
CVE-2026-880518.6—tesseract-ocrtesseractCWE-787Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independ…
CVE-2026-880538.6—tesseract-ocrtesseractCWE-787Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalid…
CVE-2026-880568.6—angularangularCWE-918Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discr…
CVE-2026-880588.6—angularangularCWE-79Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fall…
CVE-2026-880608.6—angularangularCWE-79Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Bou…
CVE-2026-888638.6—Cap-gocapgo.appCWE-269capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org
CVE-2026-888658.6—WWBNAVideoCWE-639AVideo Missing Authorization via getRestream.json.php
CVE-2026-888958.6—usmannasircyberpanelCWE-287CyberPanel before 3.0.5 Authentication Bypass via API
CVE-2026-889378.6—knowns-devknownsCWE-22knowns through 0.33.0 Path Traversal via Template Engine
CVE-2026-118138.5—LenovoFileZ ClientCWE-276A potential improper permissions vulnerability was reported in the Lenovo Fil…
CVE-2026-634278.5—LenovoSoftware FixCWE-290An authentication bypass vulnerability was discovered in Lenovo Software Fix …
CVE-2026-803788.5—IBMDataStage on Cloud Pak for DataCWE-285DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-804368.5—IBMDataStage on Cloud Pak for DataCWE-285DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-812078.5—IBMDataStage on Cloud Pak for DataCWE-918DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-815408.5—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-888868.5—renovatebotrenovateCWE-78Renovate before 44.14.7 Command Injection via gradle-wrapper
CVE-2026-888898.5—renovatebotrenovateCWE-78Renovate before 44.14.7 Command Injection via distributionType
CVE-2026-890498.5—AWSAmazon SSM AgentCWE-918Server-side request forgery in the Session Manager port forwarding functional…
CVE-2026-41308.4—NISystemLinkCWE-312Storage of Sensitive Information in Cleartext in NI SystemLink
CVE-2026-189948.4—LenovoFile Manager ApplicationCWE-926A potential improper authorization vulnerability was reported in the Lenovo F…
CVE-2026-191368.4—LenovoTianxi AI Agent PC ApplicationCWE-78A potential command injection vulnerability was reported in the Tianxi AI Age…
CVE-2026-880228.4—MongoDBLaravel MongoDB (PHP)CWE-943Unauthorized document disclosure and deletion via query-operator injection in…
CVE-2026-888908.4—Openpanel-devopenpanelCWE-89OpenPanel SQL Injection via unvalidated profile filter column identifier
CVE-2026-870908.3—HashiCorpConsulCWE-863Consul vulnerable to an authorization bypass in the catalog node-write path
CVE-2026-888838.3—renovatebotrenovateCWE-532Renovate before 44.14.4 TLS Private Key Log Sanitisation
CVE-2026-880328.2—MongoDBJava DriverCWE-416Application denial of service via cancellation race in reactive client-side e…
CVE-2026-888978.2—flextypeflextypeCWE-598Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
CVE-2026-890548.2—The OpenNMS GroupHorizonCWE-862OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticat…
CVE-2026-812688.1—IBMLangflow OSSCWE-613Langflow is vulnerable to authentication bypass and insufficient session expi…
CVE-2026-817848.1—MarcinWise ChatCWE-502WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability
CVE-2026-818018.1—UDX Usability DynamicsWP-StatelessCWE-862WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
CVE-2026-818058.1—SiteSkiteSiteSkiteCWE-266WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
CVE-2026-879588.1—IBMDb2CWE-269IBM® Db2® is vulnerable to a denial of service where a specific functionality…
CVE-2026-23107.8—IBMwebMethods Integration ServerCWE-91IBM webMethods Integration Server is vulnerable to an XML external entity inj…
CVE-2026-880527.8—tesseract-ocrtesseractCWE-129Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/i…
CVE-2026-171767.7—TP-Link Systems Inc.Deco BE11000 V2CWE-78OS command injection Vulnerability in Deco BE11000
CVE-2026-812107.7—IBMDataStage on Cloud Pak for DataCWE-639DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-879937.7—HashiCorpToolingCWE-532Consul-template vulnerable to an information disclosure issue in error handling
CVE-2026-62857.5—Ankaref Innovation and Technology Inc.LIBRID/LIBREFCWE-640Improper Authentication in Ankaref's LIBRID/LIBREF
CVE-2026-91667.5—GIS InformaticsGisLab Laboratory Management SystemCWE-22LFI in GIS Informatics' GisLab Laboratory Management System
CVE-2026-457477.5—OISFsuricataCWE-476Suricata lua/tls: null dereference in TlsGetCertInfo
CVE-2026-457597.5—OISFsuricataCWE-400Suricata http1: quadratic Content-Disposition processing can lead to denial o…
CVE-2026-457627.5—OISFsuricataCWE-843Suricata defrag: missing address-family check can lead to remote crash
CVE-2026-457657.5—OISFsuricataCWE-400Suricata dnp3: unbounded reassembly can lead to resource exhaustion
CVE-2026-457667.5—OISFsuricataCWE-400Suricata nfs: unbounded stateful structures can lead to resource exhaustion
CVE-2026-457687.5—OISFsuricataCWE-400Suricata ldap: unbounded responses per transaction can lead to resource exhau…
CVE-2026-457697.5—OISFsuricataCWE-400ikev2: unbounded client transform storage can lead to resource exhaustion
CVE-2026-457707.5—OISFsuricataCWE-693Suricata lua: excessive flow variable registration can bypass sandbox
CVE-2026-463877.5—OISFsuricataCWE-409Suricata http2: decompression bomb can cause denial of service in Suricata
CVE-2026-778077.5—acybaAcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressCWE-22AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution …
CVE-2026-812657.5—IBMLangflow OSSCWE-918Langflow is vulnerable to server-side request forgery due to missing egress v…
CVE-2026-817867.5—VillaThemeThank You Page Customizer for WooCommerceCWE-862WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken …
CVE-2026-817947.5—mlfactoryShirt Product Designer for WooCommerceCWE-862WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access…
CVE-2026-817997.5—WP SwingsReturn Refund and Exchange For WooCommerceCWE-862WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken…
CVE-2026-818037.5—Ateeq RafeeqRepairBuddyCWE-94WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerab…
CVE-2026-818047.5—Zain HassanZHBackup – Backup, Restore &amp; MigrationCWE-201WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive …
CVE-2026-848217.5—EpsiloncoolWP Fast Total SearchCWE-862WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vul…
CVE-2026-860937.5—IBMDb2CWE-121IBM® Db2® federated server could allow an attacker with the ability to contro…
CVE-2026-880457.5—rclonercloneCWE-789rclone: S3 multipart declared-length memory exhaustion
CVE-2026-804347.4—IBMDataStage on Cloud Pak for DataCWE-639DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-817967.3—WP TravelWP TravelCWE-288WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability
CVE-2026-880177.3—rclonercloneCWE-488rclone: FTP cross-session auth-proxy backend confusion
CVE-2026-888857.3—renovatebotrenovateCWE-78Renovate before 44.14.7 Command Injection via depName
CVE-2026-888887.3—renovatebotrenovateCWE-78Renovate before 44.14.7 Command Injection via Mix organization
CVE-2026-890877.3—OCamlcstructCWE-573The cstruct package before 6.3.0 for OCaml mishandles indexes.
CVE-2026-888917.2—Openpanel-devopenpanelCWE-269OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
CVE-2026-803807.1—IBMDataStage on Cloud Pak for DataCWE-352DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-817837.1—mailmunchMailMunch – Grow your Email ListCWE-288WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentic…
CVE-2026-817957.1—Denis BotićPage Visits Counter &#8211; LiteCWE-79WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (…
CVE-2026-848167.1—RealMag777WPCSCWE-79WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
CVE-2026-848197.1—Greg WiniarskiWPAdvertsCWE-79WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-855457.1—HikvisionHikCentral Access ControlCWE-284There is an Vulnerability in some HikCentral Access Control versions. Authent…
CVE-2026-879617.1—schreibfaul1ESP32-audioI2SCWE-125ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed…
CVE-2026-880167.1—rclonercloneCWE-59rclone: Directory metadata (chmod/chown/chtimes) applied through a planted sy…
CVE-2026-880217.1—HashiCorpConsulCWE-185Consul vulnerable to an authorization bypass in the Connect service mesh
CVE-2026-880267.1—MongoDBC# DriverCWE-943Regular expression injection via unescaped characters in LINQ query translati…
CVE-2026-880277.1—MongoDBLaravel MongoDB (PHP)CWE-943Mass deletion and overwrite of embedded documents via query-operator injectio…
CVE-2026-880287.1—MongoDBLaravel MongoDB (PHP)CWE-943Unauthorized document disclosure via query-operator injection in polymorphic …
CVE-2026-888707.1—WWBNAVideoCWE-352WWBN AVideo LoginControl PGP Key CSRF via GET Request
CVE-2026-888727.1—WWBNAVideoCWE-352AVideo CustomizeUser setPassword.json.php CSRF
CVE-2026-888737.1—WWBNAVideoCWE-352WWBN AVideo Cross-Site Request Forgery via logArchive.json.php
CVE-2026-888987.1—AppFlowy-IOAppFlowy-CloudCWE-862AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk P…
CVE-2026-889157.1—MISPMISPCWE-862MISP Event Template Instantiation Bypasses Sharing Group and Tagging Authoriz…
CVE-2026-889387.1—knowns-devknownsCWE-22knowns through 0.33.0 Path Traversal via code.find MCP tool
CVE-2026-890117.1—isomorphic-gitisomorphic-gitCWE-1321isomorphic-git < 1.42.0 Prototype Pollution via getRemoteInfo
CVE-2026-154197.0—Silicon Labssilabser.sys driverCWE-121CP210x Driver Memory Corruption results in Arbitrary Code Execution
CVE-2026-880047.0—traefiktraefikCWE-436Traefik entrypoint header-name sanitization bypassed via request trailers
CVE-2026-880087.0—traefiktraefikCWE-444Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response…
CVE-2026-889247.0—Red HatRed Hat Enterprise Linux 10CWE-367Gvfs: gvfs-admin socket ownership race permits local root
CVE-2026-154176.9—Silicon Labssilabser.sys driverCWE-369CP210x Denial of Service
CVE-2026-170386.9—drErykdrEryk GabinetCWE-798Use of Hard-coded Credentials in drEryk Gabinet
CVE-2026-780856.9—joomshaper.comSP Property extension for JoomlaCWE-22Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Managemen…
CVE-2026-849416.9—TP-Link Systems Inc.Omada Software Controller (Windows)CWE-611Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Par…
CVE-2026-880506.9—tesseract-ocrtesseractCWE-787Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder cod…
CVE-2026-880546.9—tesseract-ocrtesseractCWE-125Tesseract: Denial of service via empty-stack dereference in Plumbing/Series a…
CVE-2026-888786.9—traefiktraefikCWE-770Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass
CVE-2026-888846.9—renovatebotrenovateCWE-863Renovate before 44.3.1 Authentication Bypass via Digest Updates
CVE-2026-888966.9—espocrmespocrmCWE-918EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass
CVE-2026-889406.9—knowns-devknownsCWE-22knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse en…
CVE-2026-890446.9—nettynettyCWE-444Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Fin…
CVE-2026-520976.8—n/an/aCWE-94An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary cod…
CVE-2026-810526.8—DellThinOS 10CWE-494Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Wi…
CVE-2026-91766.7—IBMWebSphere Application ServerCWE-94IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-810516.6—DellThinOS 10CWE-1328Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Nu…
CVE-2026-92256.5—IBMLangflow OSSCWE-639Langflow is vulnerable to unauthorized file system access due to path travers…
CVE-2026-93366.5—IBMWebSphere Application ServerCWE-306IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-540546.5—transmute-apptransmuteCWE-918Transmute has full-read SSRF in URL file import (POST /api/files/url) — no ho…
CVE-2026-666326.5—Elliot Sowers/ RelyWPSimple Cloudflare TurnstileCWE-94WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Content Injection vu…
CVE-2026-785366.5—robokassaRobokassa payment gateway for WoocommerceCWE-862WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken …
CVE-2026-797256.5—IBMLangflow OSSCWE-284Langflow is vulnerable to unauthorized file system access due to path travers…
CVE-2026-812756.5—YouzifyYouzifyCWE-22WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability
CVE-2026-817826.5—Fahad MahmoodWP DocsCWE-79WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-817856.5—ThemekraftBuddyFormsCWE-862WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability
CVE-2026-817876.5—IDX BrokerIMPress for IDX BrokerCWE-288WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vuln…
CVE-2026-817916.5—Ashan PereraEventONCWE-79WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability
CVE-2026-817936.5—Dimitri GrassiSalon booking systemCWE-862WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vuln…
CVE-2026-848286.5—Red HatRed Hat Enterprise Linux 10CWE-732Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth …
CVE-2026-853106.5—Adrian TobeyGroundhoggCWE-35WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability
CVE-2026-871066.5—HashiCorpConsulCWE-400Consul vulnerable to a denial of service in the native RPC listener
CVE-2026-880056.5—open-webuiopen-webuiCWE-863Open WebUI: Users denied by the OAuth domain allowlist or role policy can sti…
CVE-2026-880066.5—open-webuiopen-webuiCWE-863Open WebUI: Users denied by the OAuth role policy can still sign in via token…
CVE-2026-890896.5—The OpenNMS GroupMeridianCWE-89OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_…
CVE-2026-93276.3—IBMWebSphere Application ServerCWE-269IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-181216.3—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) …
CVE-2026-817886.3—IDX BrokerIMPress for IDX BrokerCWE-862WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vuln…
CVE-2026-819056.3—Concrete CMSConcrete CMSCWE-863Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption,…
CVE-2026-819066.3—Concrete CMSConcrete CMSCWE-288[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks
CVE-2026-880146.3—rclonercloneCWE-22rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious…
CVE-2026-888596.3—Red HatRed Hat Enterprise Linux 6CWE-84Evolution: evolution: javascript execution via spoofed vcard control bypasses…
CVE-2026-880236.1—MongoDBMongoDB PHP LibraryCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880246.1—MongoDBRust DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880256.1—MongoDBC# DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880296.1—MongoDBPython DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880306.1—MongoDBRuby DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880316.1—MongoDBGo DriverCWE-943GridFS data deletion via query-operator injection in file IDs in the MongoDB …
CVE-2026-880336.1—MongoDBJava DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880346.1—MongoDBC++ DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-880366.1—MongoDBC DriverCWE-943GridFS data disclosure and deletion via query-operator injection in file IDs …
CVE-2026-161726.0—NetskopeEndpoint DLPCWE-125Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash
CVE-2026-195965.9—The OpenNMS GroupMeridianCWE-611OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host
CVE-2026-457515.9—OISFsuricataCWE-416Suricata detect/transform: use-after-free in dotprefix transform
CVE-2026-457525.9—OISFsuricataCWE-416Suricata detect/transform: use-after-free in decompress transforms
CVE-2026-457635.9—OISFsuricataCWE-770Suricata lua: sandbox allocation limit not enforced for new allocations
CVE-2026-498375.9—osrggobgpCWE-125GoBGP: BGP OPEN capability parser may read capability values outside declared…
CVE-2026-498385.9—osrggobgpCWE-129GoBGP confederation validation panics on empty AS_PATH attribute
CVE-2026-685275.9—Concrete CMSConcrete CMSCWE-639Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass thr…
CVE-2026-880615.8—santifercareer-opsCWE-352career-ops: Local dashboard API accepted cross-origin and non-loopback reques…
CVE-2026-880355.7—MongoDBC DriverCWE-190Heap buffer overflow via wrapped size check during SASL username canonicaliza…
CVE-2026-666745.6—Elliot Sowers/ RelyWPSimple Cloudflare TurnstileCWE-290WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulne…
CVE-2026-880555.5—Mintplex-Labsanything-llmCWE-79AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in Me…
CVE-2026-126825.4—Ankaref Innovation and Technology Inc.LIBRID/LIBREFCWE-79Stored XSS in Ankaref's LIBRID/LIBREF
CVE-2026-126835.4—Ankaref Innovation and Technology Inc.LIBRID/LIBREFCWE-79Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF
CVE-2026-871075.4—HashiCorpConsulCWE-863Consul vulnerable to an authorization bypass in the catalog deregistration path
CVE-2026-91615.3—DernekPlusWebsite TemplateCWE-204User Enumeration in DernekPlus' Website Template
CVE-2026-93385.3—IBMWebSphere Application ServerCWE-400IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-96675.3—IBMWebSphere Application ServerCWE-918IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-154615.3—zephyrprojectzephyrCWE-843Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write fr…
CVE-2026-766535.3—TP-Link Systems Inc.TL-MR6400 v8CWE-126Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 a…
CVE-2026-844325.3—Concrete CMSConcrete CMSCWE-352Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot d…
CVE-2026-880115.3—traefiktraefikCWE-290Traefik: ForwardAuth identity spoofing via dot-form header alias
CVE-2026-880125.3—traefiktraefikCWE-770Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slo…
CVE-2026-880155.3—rclonercloneCWE-190rclone local: crafted Range request against a translated symlink panics (DoS)
CVE-2026-880465.3—rclonercloneCWE-22rclone: source object names can escape the configured root on upload
CVE-2026-880575.3—angularangularCWE-79Angular: Sanitization bypass via directive host bindings on concrete host ele…
CVE-2026-888715.3—WWBNAVideoCWE-352WWBN AVideo CustomizeUser setSubscribers CSRF via GET
CVE-2026-888755.3—WWBNAVideoCWE-359AVideo Incomplete API Sanitization Information Disclosure
CVE-2026-888795.3—traefiktraefikCWE-290Traefik before v2.11.56 Identity Spoofing via Header Alias
CVE-2026-888925.3—Openpanel-devopenpanelCWE-918OpenPanel SSRF via Unguarded Importer File URL Fetch
CVE-2026-888945.3—grokabilitysnipe-itCWE-863Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout
CVE-2026-855445.2—HikvisionDS-KV9503CWE-1310There is an Improper Encryption Configuration Vulnerability in some Hikvision…
CVE-2026-879125.1—AWSAWS Security Agent pluginCWE-283Missing S3 bucket ownership verification in the AWS Security Agent plugin for…
CVE-2026-879135.1—AWSAWS Security Agent MCP serverCWE-283Missing S3 bucket ownership verification in the AWS Security Agent MCP server
CVE-2026-889215.1—MISPMISPCWE-79MISP: Unescaped HTML Injection in PDF Report Element Rendering
CVE-2026-890455.1—lubenzstd-jniCWE-835zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length
CVE-2026-797235.0—IBMLangflow OSSCWE-918Langflow is vulnerable to server-side request forgery due to missing egress v…
CVE-2026-766524.8—TP-Link Systems Inc.TL-MR6400 v8CWE-22Authenticated Directory Traversal Vulnerability in File Upload Functionality …
CVE-2026-880384.8—cookiescookiesCWE-74cookies vulnerable to Set-Cookie attribute injection via unvalidated domain a…
CVE-2026-30964.7—WSO2WSO2 API Control PlaneCWE-20Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Ph…
CVE-2026-498364.6—psd-toolspsd-toolsCWE-22psd-tools: arbitrary file write via smart-object filename
CVE-2026-457674.4—OISFsuricataCWE-22Suricata datasets: save to absolute filename can be bypassed when combined wi…
CVE-2026-810494.4—DellThinOS 10CWE-353Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for…
CVE-2026-855434.3—HikvisionWi-Fi series cameraCWE-285Some Wi-Fi series camera products have insufficient permission validation on …
CVE-2026-860874.3—IBMDb2CWE-22IBM® Db2® could allow an authenticated user to send a specially crafted reque…
CVE-2026-880594.0—angularangularCWE-200Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequ…
CVE-2026-880133.7—rclonercloneCWE-200rclone: http backend forwards custom/auth headers to a different host on redi…
CVE-2026-457613.3—OISFsuricataCWE-122Suricata detect: case-insensitive frame handling can cause heap buffer overfl…
CVE-2026-154182.4—Silicon Labssilabser.sys driverCWE-130CP210x Memory Leakage
CVE-2026-887900.9—proma-aiPromaCWE-22proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath…
CVE-2022-26962await—n/an/a—Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-…
CVE-2025-57231await—n/an/a—Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthentic…
CVE-2026-36392await—n/an/a—FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS)…
CVE-2026-38626await—n/an/a—Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Reposit…
CVE-2026-68006await—n/an/a—An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arb…
CVE-2026-71640await—n/an/a—An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a958804…
CVE-2026-71642await—n/an/a—An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a958804…
CVE-2026-71643await—n/an/a—An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a958804…
CVE-2026-71645await—n/an/a—An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version…
CVE-2026-71647await—n/an/a—An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d56…
CVE-2026-79590await—n/an/a—A NULL pointer dereference vulnerability exists in the Prism parser component…
CVE-2026-79591await—n/an/a—A heap-buffer-overflow and use-after-free vulnerability exists in the xls_get…
CVE-2026-79592await—n/an/a—An out-of-bounds read vulnerability exists in the xls_dumpSummary() function …

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-10 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.