boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 11, 2026 · all times UTC← 2026-09-10 · archive

Security Box Score — September 11, 2026

CISA adds 4 to KEV; 703 CVEs published, led by Linux (431).

703 CVEs published September 11, 2026: 36 critical, 81 high, 134 medium, 11 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 441 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 303 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published548840372——
KEV catalog size1709

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2550 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6314714420202170611230.17.8.0016+241 ▲
microsoft9772876189197869316289301.07.8.0044+542 ▲
google361252731897311101207980.37.5.0025+312 ▲
red hat736984328932937200.06.7.0028-31 ▼
apple0316598516578882.56.5.0029-1 ▼
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.00200
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco12962446260571414.67.5.0041-19 ▼
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022+9 ▲
fortinet1040101017329717.57.0.0038+10 ▲
netgear23400277000.04.3.0025-7 ▼
ivanti102410122025520.88.8.0146+7 ▲
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32541117228181133320.47.5.0049-45 ▼
mozilla352228079630900.08.1.0029+34 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab076317479533.95.3.00290
github32011090000.07.3.0044+1 ▲
docker090630000.07.2.00160
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
adobe17077657343366102040.57.5.0023+110 ▲
ibm1217401613412299610.17.5.0030+89 ▲
progress3641539100611.68.1.0035-8 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+3 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link8531619108300.08.5.0157-7 ▼
siemens145163393000.07.3.0018-3 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric91821150000.08.5.0039+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1343052514012218210.37.2.0020+126 ▲
sourcecodester261950011481000.05.5.0028+14 ▲
spring017012608315000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb50148487534100.07.1.0026+25 ▲
itsourcecode241400036104000.02.1.0026+16 ▲
elastic42129127983100.06.5.0028+42 ▲
splunk0128647705110.86.5.00250

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-73570.323898.28.9
CVE-2026-64849.164196.89.3
CVE-2026-83549.085194.77.8
CVE-2026-19681.078094.39.4
CVE-2026-82329.076794.29.8
CVE-2026-19478.058192.79.1
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.49.3
CVE-2026-79756.051591.98.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-1918810.0.0193
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-7367810.0.0114
Most disclosures (vendor)
VendorCVEs
linux1864
microsoft1015
oracle890
google714
ibm411
adobe211
dell194
red hat176
splunk110
apache106
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco14
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven48
Packagist38
npm19
PyPI15
RubyGems2
Go1
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171759
CVE-2021-27102n/a2021-11-171759
CVE-2021-27101n/a2021-11-171759
CVE-2021-27103n/a2021-11-171759
CVE-2021-21017Adobe2021-11-171759
CVE-2021-28550Adobe2021-11-171759
CVE-2021-42013Apache Software Foundation2021-11-171759
CVE-2021-41773Apache Software Foundation2021-11-171759
CVE-2021-30858Apple2021-11-171759
CVE-2021-30860Apple2021-11-171759

Transactions

ADDED TO KEV — CVE-2026-42016 (jfrog artifactory). Remediation due September 25, 2026.

ADDED TO KEV — CVE-2026-42018 (jfrog artifactory). Remediation due September 25, 2026.

ADDED TO KEV — CVE-2026-84869 (ConnectWise ScreenConnect). Remediation due September 14, 2026.

ADDED TO KEV — CVE-2026-85706 (GitLab). Remediation due September 14, 2026.

EXPLOIT PUBLISHED — XenForo: 14 CVEs (CVE-2026-73309, CVE-2026-73310, CVE-2026-73311, CVE-2026-73312, CVE-2026-73313, CVE-2026-73314, CVE-2026-73315, CVE-2026-73316, CVE-2026-73317, CVE-2026-73318, CVE-2026-73319, CVE-2026-73320, CVE-2026-73321, CVE-2026-74239). Public exploit references added.

EXPLOIT PUBLISHED — Canonical LXD: 11 CVEs (CVE-2026-16033, CVE-2026-62420, CVE-2026-63294, CVE-2026-63295, CVE-2026-63296, CVE-2026-63297, CVE-2026-63298, CVE-2026-63299, CVE-2026-63300, CVE-2026-66897, CVE-2026-66898). Public exploit references added.

EXPLOIT PUBLISHED — curl: 9 CVEs (CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209). Public exploit references added.

EXPLOIT PUBLISHED — axios: 8 CVEs (CVE-2026-42264, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496). Public exploit references added.

EXPLOIT PUBLISHED — Google Chrome: 5 CVEs (CVE-2026-87468, CVE-2026-87493, CVE-2026-87580, CVE-2026-87584, CVE-2026-87589). Public exploit references added.

EXPLOIT PUBLISHED — FreeRDP: 4 CVEs (CVE-2026-67292, CVE-2026-67294, CVE-2026-67296, CVE-2026-67297). Public exploit references added.

EXPLOIT PUBLISHED — netty: 4 CVEs (CVE-2026-42578, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587). Public exploit references added.

EXPLOIT PUBLISHED — FlowiseAI Flowise: 3 CVEs (CVE-2026-70473, CVE-2026-70474, CVE-2026-70476). Public exploit references added.

EXPLOIT PUBLISHED — itsourcecode Sales and Inventory System: 3 CVEs (CVE-2026-85383, CVE-2026-86236, CVE-2026-86310). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-29181 (open-telemetry opentelemetry-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45736 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58592 (LadybirdBrowser Ladybird). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73694 (FileRun). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79698 (Advantech WISE-6610-NB). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82537 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85378 (light0011 cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85402 (code-projects Doctor Appointment System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85408 (Eleveo Quality Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85516 (code-projects Vehicle Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85638 (jofpin trape). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85703 (ramon-victor freegpt-webui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86161 (SourceCodester Online Voting System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86166 (Tenda HG10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86172 (DefaultFuction CRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86183 (diem-project diem). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86212 (Open5GS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86217 (code-projects Hotel and Tourism Reservation in PHP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86224 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86231 (mwiede jsch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86241 (liufee FeehiCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86262 (sfturing hosp_order). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86268 (itsourcecode School Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86273 (projeto-siga siga). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86281 (SourceCodester Syllabus-Aligned Learning Management & Examination System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86289 (Ollama). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86294 (SourceCodester Simple Traffic Offense System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86299 (Linksys RE7000). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86305 (light0011 cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86509 (D-Link DIR-895L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86514 (vgmstream). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86519 (code-projects Student Crud Operation). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86668 (aircheng-org iWebShop-5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86672 (ningzichun Student Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86674 (ningzichun Student Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86808 (moltis-org moltis). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87923 (Rizwan17 inventory-management-system). Public exploit reference added.

DUE DATE PASSED — CVE-2026-66384 (jfrog artifactory). CISA remediation deadline was September 10, 2026; still in catalog.

REJECTED — CVE-2026-82455 (rubygems). Record withdrawn by the CNA.

RESCORED — Esri Portal for ArcGIS: 5 CVEs (CVE-2026-69224, CVE-2026-69225, CVE-2026-69230, CVE-2026-69237, CVE-2026-69238). CVSS rescored — before/after on each CVE page.

RESCORED — Dell Secure Connect Gateway 5.0 - Application: 3 CVEs (CVE-2026-80133, CVE-2026-80135, CVE-2026-80178). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-65646 (WebPros Plesk). CVSS 8.7 → 9.9 (NVD).

PATCH SHIPPED — CVE-2026-81789 (Studio Wombat Advanced Product Fields Extended for WooCommerce). Fixed in Advanced Product Fields Extended for WooCommerce 3.1.7.

PATCH SHIPPED — CVE-2026-86169 (axolotl-ai-cloud axolotl). Fixed in axolotl 0.19.0.

PATCH SHIPPED — CVE-2026-87875 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 2.4.19-4.1.hum1.

PATCH SHIPPED — CVE-2026-89060 (multicluster-observability-addon). Fixed in multicluster-observability-addon ad36a3ba9fd946c04de71621e47486f7aa2634fd.

Yesterday's Results

How to read these box scores · glossary

703 CVEs published. 25 box scores and 375 table rows below; the remaining 303 continue on page 2 — every CVE is listed, nothing truncated.

mulika MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields. — MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0062   47.9     —
AFFECTED
  Product                                                                              Versions     Fixed
  MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.  unspecified  —
TIMELINE
  May 17  Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
stiofansisland UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP — UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0042   35.6     —
AFFECTED
  Product                                                                                            Versions     Fixed
  UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP  unspecified  —
TIMELINE
  Aug 16  Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
strongSwan strongSwan — libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0042   35.1     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  6.0.0 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-416 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0041   34.7     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  5.0.2 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-825 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0041   34.7     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  4.1.10 –  —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-476 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0041   34.7     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  4.6.2 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-835 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
hbs vulnerable to Denial of Service via unhandled exception in async helper output escaping
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  H    5.9   .0041   34.7     —
AFFECTED
  Product  Versions  Fixed
  hbs      4.3.0 –   4.3.1
TIMELINE
  Sep 8   Reserved by CNA
  Sep 11  Published (CNA: openjs)
CWE-248 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
Hewlett Packard Enterprise HPE IceWall products — HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0040   33.9     —
AFFECTED
  Product               Versions  Fixed
  HPE IceWall products  4.0 –     —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 11  Published (CNA: hpe)
CWE-241 · CNA: hpe · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0037   30.8     —
AFFECTED
  Product  Versions     Fixed
  EH3040   unspecified  —
  EH4200   unspecified  —
  EH1000B  unspecified  —
  EH2070   unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 11  Published (CNA: twcert)
CWE-307 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
strongSwan strongSwan — libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  N  L    3.7   .0035   28.6     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  4.1.2 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-401 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
strongSwan strongSwan — libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Beca…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  L  L    5.6   .0034   26.6     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  5.9.7 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-841 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
unitecms Unlimited Elements For Elementor — Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0033   25.8     —
AFFECTED
  Product                           Versions     Fixed
  Unlimited Elements For Elementor  unspecified  —
TIMELINE
  Aug 1   Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
xootix OTP Login & Register Woocommerce — OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0032   24.8     —
AFFECTED
  Product                           Versions     Fixed
  OTP Login & Register Woocommerce  unspecified  —
TIMELINE
  Jun 14  Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  L    7.1   .0032   24.6     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  4.5.0 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-863 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0032   24.6     —
AFFECTED
  Product  Versions     Fixed
  EH3040   unspecified  —
  EH4200   unspecified  —
  EH1000B  unspecified  —
  EH2070   unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 11  Published (CNA: twcert)
CWE-602 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Cloud Foundry Foundation UAA — Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0032   24.3     —
AFFECTED
  Product        Versions     Fixed
  UAA            unspecified  77.31.0
  cf-deployment  unspecified  48.10.0
TIMELINE
  May 20  Reserved by CNA
  Sep 11  Published (CNA: vmware)
CWE-284 · CNA: vmware · CVSS v4.0 · 1 reference · NVD status: Received
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate pa…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0031   23.5     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  4.2.0 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-476 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for i…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0031   23.5     —
AFFECTED
  Product     Versions  Fixed
  strongSwan  5.1.3 –   —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 11  Published (CNA: mitre)
CWE-835 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis
morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0031   23.4     —
AFFECTED
  Product  Versions     Fixed
  morgan   unspecified  1.12.1
TIMELINE
  Sep 9   Reserved by CNA
  Sep 11  Published (CNA: openjs)
CWE-117 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
gingerplugins Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons — Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0030   22.9     —
AFFECTED
  Product                                                                                               Versions     Fixed
  Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons  unspecified  —
TIMELINE
  Jul 10  Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
multiparty vulnerable to Denial of Service via unbounded part-header accumulation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0030   22.1     —
AFFECTED
  Product     Versions  Fixed
  multiparty  2.1.0 –   4.3.1
TIMELINE
  Sep 9   Reserved by CNA
  Sep 11  Published (CNA: openjs)
CWE-400, CWE-770 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
opajaap WP Photo Album Plus — WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0029   21.6     —
AFFECTED
  Product              Versions     Fixed
  WP Photo Album Plus  unspecified  —
TIMELINE
  Aug 2   Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
themeum Kirki – Freeform Page Builder, Website Builder & Customizer — Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0028   20.3     —
AFFECTED
  Product                                                      Versions     Fixed
  Kirki – Freeform Page Builder, Website Builder & Customizer  unspecified  —
TIMELINE
  Jul 24  Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
specialk Simple Ajax Chat – Add a Fast, Secure Chat Box — Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0028   20.1     —
AFFECTED
  Product                                         Versions     Fixed
  Simple Ajax Chat – Add a Fast, Secure Chat Box  unspecified  —
TIMELINE
  Aug 27  Reserved by CNA
  Sep 11  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
appleple inc. a-blog cms — a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   N    6.9   .0028   19.9     —
AFFECTED
  Product     Versions     Fixed
  a-blog cms  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 11  Published (CNA: jpcert)
CWE-22 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-114966.518.2edgarrojasPDF Builder for WooCommerce. Create invoices,packing slips and moreCWE-862Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direc…
CVE-2026-891736.917.8Kingdom Communication AssociatedEH3040CWE-204Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data…
CVE-2026-199856.117.8comesioRelevanssi – A Better SearchCWE-79Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting
CVE-2026-771506.116.9unitecmsUnlimited Elements For ElementorCWE-79Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting
CVE-2026-891768.716.3HowyarWeenyGeniusCWE-306Howyar|WeenyGenius - Missing Authentication
CVE-2026-194868.716.0Google CloudGemini Enterprise Agent Platform App BuilderCWE-918SSRF in Gemini Enterprise Agent Platform App Builder
CVE-2026-817547.215.2fernandotVigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…CWE-79Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting
CVE-2026-66406.415.2dglingrenMedia Library AssistantCWE-79Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-890924.215.2The GNU C LibraryglibcCWE-789Stack overflow in nscd due to unbounded alloca use
CVE-2026-890607.714.4—multicluster-observability-addonCWE-551Stolostron/multicluster-observability-addon: cross-namespace secret disclosur…
CVE-2026-114465.314.4arrayticsBooktics – Appointment Booking Calendar for Service BusinessesCWE-862Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23…
CVE-2026-804698.313.8SICK AGSentio Creator Extension 'Device Manager'CWE-347CVE-2026-80469
CVE-2026-868155.513.8UnknownBackWPupCWE-862BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration …
CVE-2026-891788.713.6HowyarWeenyGeniusCWE-940Howyar|WeenyGenius - Origin Validation Error
CVE-2026-1456010.013.5Unknownteddy-bear-customize-addonCWE-94Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload
CVE-2026-891778.713.5HowyarWeenyGeniusCWE-757Howyar|WeenyGenius - Use of Insecure Protocol
CVE-2026-185626.113.4realmag777HUSKY – Products Filter for WooCommerce ProfessionalCWE-79HUSKY <= 1.4.3 - Reflected Cross-Site Scripting
CVE-2026-781313.713.3strongSwanstrongSwanCWE-401strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effe…
CVE-2026-849606.112.8cbutlerjrWP-Members Membership PluginCWE-79WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting
CVE-2026-891586.512.6PCREPCRE2CWE-190PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overf…
CVE-2026-189646.112.6premioFloating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – ChatyCWE-79Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeCh…
CVE-2026-891603.712.6PCREPCRE2CWE-125PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATC…
CVE-2026-66416.412.1dglingrenMedia Library AssistantCWE-79Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-S…
CVE-2026-66426.412.1dglingrenMedia Library AssistantCWE-79Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site S…
CVE-2026-781726.111.3themifymeThemify – WooCommerce Product FilterCWE-79Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting
CVE-2026-74386.410.7boldthemesBold Timeline LiteCWE-79Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site …
CVE-2026-882608.79.8BrainzcompanyZenius EMS 8.0CWE-288Authentication bypass using an alternate path or channel and Improper validat…
CVE-2026-781243.78.7strongSwanstrongSwanCWE-401strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the o…
CVE-2026-867825.57.9UnknownVisualizerCWE-639Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR
CVE-2026-737848.87.3Hewlett Packard EnterpriseHPE IceWall productsCWE-347HPE IceWall products, Remote Bypass of Security Restrictions
CVE-2026-856778.86.8UnknownGutenverse NewsCWE-79Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content
CVE-2026-868126.56.3UnknownWPCafeCWE-284WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification vi…
CVE-2026-145655.45.3Unknownadvanced-customized-promptsCWE-79Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Pop…
CVE-2026-133266.94.7qtqtCWE-125Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord …
CVE-2026-835456.84.7UnknownCoolClockCWE-79CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON
CVE-2026-835466.84.7UnknownCoolClockCWE-79CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute
CVE-2026-856786.84.7UnknownAI BuilderCWE-79AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript
CVE-2026-867806.84.7UnknownFeatured Image with URLCWE-79Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text
CVE-2025-156953.54.7UnknownTranslate WordPress with GTranslateCWE-79GTranslate < 3.0.10 - Admin+ Stored XSS
CVE-2026-891513.54.5ForgejoForgejoCWE-863Forgejo before 16.0.4 allows use of restricted API tokens for unintended acce…
CVE-2026-145625.34.1Unknownteddy-bear-customize-addonCWE-200Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure
CVE-2026-145599.83.4Unknownteddy-bear-customize-addonCWE-287Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover
CVE-2026-145639.83.4Unknownadvanced-customized-promptsCWE-287Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover
CVE-2026-823055.33.4UnknownYITH WooCommerce WishlistCWE-639YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Renam…
CVE-2026-749257.23.1UnknownMultiVendorXCWE-269MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator
CVE-2026-145664.33.1Unknownadvanced-customized-promptsCWE-639Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Met…
CVE-2026-867792.73.1UnknownVisualizerCWE-862Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart
CVE-2026-891452.42.8flextypeflextypeCWE-79Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory
CVE-2026-889144.42.4Red HatRed Hat Enterprise Linux 10CWE-190Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read i…
CVE-2026-867815.31.9UnknownSSL Zen — SSL Certificate Installer & HTTPS RedirectsCWE-287SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure
CVE-2025-156797.31.5BullBullSequana XH3406CWE-258BMC root account active without password on BullSequana XH3406 and XH3515
CVE-2026-891617.41.4PCREPCRE2CWE-590In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject…
CVE-2026-891694.11.4Debianlive-bootCWE-347live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-s…
CVE-2026-891795.31.2HowyarWeenyGeniusCWE-353Howyar|WeenyGenius - Missing Support for Integrity Check
CVE-2026-891622.91.2PCREPCRE2CWE-669In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an …
CVE-2026-891575.71.0PCREPCRE2CWE-190PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-b…
CVE-2026-891562.91.0PCREPCRE2CWE-125PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback …
CVE-2026-8046210.0—Progress SoftwareChef AutomateCWE-306Privilege Escalation in Progress Chef Automate
CVE-2026-8261710.0—Apache Software FoundationApache OpenNLPCWE-1333Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFa…
CVE-2026-8798510.0—mistralaimistral-vibeCWE-184An arbitrary code execution vulnerability in Mistral Vibe allows an attacker …
CVE-2026-8798610.0—mistralaimistral-vibeCWE-228An arbitrary code execution vulnerability in Mistral Vibe allows an attacker …
CVE-2026-8798710.0—mistralaimistral-vibeCWE-15An arbitrary code execution vulnerability in Mistral Vibe allows an attacker …
CVE-2026-8798810.0—mistralaimistral-vibeCWE-732An arbitrary file access vulnerability in Mistral Vibe allows an attacker to …
CVE-2026-539529.8—GetSimpleCMS-CEGetSimpleCMS-CECWE-285GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creatio…
CVE-2026-621039.8—wpeverestEverest FormsCWE-502WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability
CVE-2026-621059.8—ThemeRexThemeREX AddonsCWE-502WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability
CVE-2026-716449.8—n/an/aCWE-843An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version…
CVE-2026-793959.8—n/an/aCWE-287An improper authentication vulnerability in the WS-Security (wsse:UsernameTok…
CVE-2026-843909.8—FortinetFortiMonitorOnSightCWE-540A inclusion of sensitive information in source code vulnerability in Fortinet…
CVE-2026-380569.4—ST Engineering iDirectEvolution iQ‑Series terminalsCWE-862ST Engineering iDirect iQ-Series Terminals Missing Authorization
CVE-2026-540729.3—authorizerdevauthorizerCWE-601Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to att…
CVE-2026-727099.3—SPIPSPIPCWE-862SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur
CVE-2026-727109.3—SPIPSPIPCWE-915SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection
CVE-2026-879849.3—mistralaimistral-vibeCWE-22An arbitrary file write vulnerability in Mistral Vibe, introduced in version …
CVE-2026-890109.3—WAVLINK TechnologyWN535M1CWE-78WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server
CVE-2026-892499.3—WWBNAVideoCWE-79AVideo YPTWallet Stored XSS via CryptoWallet Configuration
CVE-2026-892539.3—WWBNAVideoCWE-79AVideo Stored XSS via donationLink in watch page button
CVE-2026-892549.3—WWBNAVideoCWE-79AVideo CustomizeUser Stored XSS via field_name Parameter
CVE-2026-892559.3—WWBNAVideoCWE-79AVideo LoginControl Stored XSS via PGP Public Key
CVE-2026-892569.3—WWBNAVideoCWE-79AVideo Bookmark Plugin Stored XSS via Chapter Names
CVE-2026-892589.3—gohugoiohugoCWE-59Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get
CVE-2026-892599.3—gohugoiohugoCWE-250Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS
CVE-2026-38699.2—Schneider ElectricModicon M580CWE-303CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability …
CVE-2026-540479.2—LaciSynchroniserverCWE-287Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation vi…
CVE-2026-879839.2—mistralaimistral-vibeCWE-22An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2…
CVE-2026-892129.2—PerforceAkanaCWE-611XML External Entity in Akana API Platform
CVE-2026-892439.2—WWBNAVideoCWE-79WWBN AVideo Stored XSS via UserGroups setGroup_name
CVE-2026-904569.2—CISAMalcolmCWE-1392An example environment-configuration file for a bundled inventory-management …
CVE-2026-621028.8—Gato GraphQLGato GraphQLCWE-266WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
CVE-2026-621068.8—Cozy Vision Technologies Pvt. Ltd.SMS Alert Order NotificationsCWE-266WordPress SMS Alert Order Notifications plugin <= 3.9.9 - Privilege Escalatio…
CVE-2026-621078.8—masteriyoMasteriyo - LMSCWE-502WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability
CVE-2026-714168.8—headroomlabs-aiheadroomCWE-287Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
CVE-2026-782248.8—NextGen HealthcareMirth ConnectCWE-611NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity …
CVE-2026-890098.8—WAVLINK TechnologyWN535M1CWE-36WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server
CVE-2026-892668.8—nothingsstb_vorbisCWE-787stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands
CVE-2026-447158.7—openmrsorg.openmrs.module:legacyui-apiCWE-285OpenMRS has Broken Access Control in HL7 Configuration
CVE-2026-727088.7—SPIPSPIPCWE-89SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter
CVE-2026-825788.7—NextGen HealthcareMirth ConnectCWE-611NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity …
CVE-2026-890138.7—DolibarrDolibarrCWE-863Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document…
CVE-2026-891468.7—libp2plibp2p-rendezvousCWE-190libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration…
CVE-2026-891478.7—net-snmpNet-SNMPCWE-400Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX …
CVE-2026-892508.7—WWBNAVideoCWE-306WWBN AVideo Unauthenticated File Read via getRecordedFile.php
CVE-2026-892608.7—moxi624MoguBlogCWE-611MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeC…
CVE-2026-892628.7—moxi624MoguBlogCWE-639MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check
CVE-2026-904448.7—CISAMalcolmCWE-78A file-transfer interface that requires valid credentials accepts attacker-co…
CVE-2026-380588.6—ST Engineering iDirectEvolution iQ‑Series terminalsCWE-497ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Infor…
CVE-2026-859798.6—Perforce SoftwarePuppet EnterpriseCWE-20Command Injection in Puppet Enterprise
CVE-2026-703418.5—MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-78638.4—TUBITAK BILGEM Software Technologies Research InstitutePardus SoftwareCWE-78OS Command Injection in TUBITAK BILGEM's Pardus Software
CVE-2026-890668.4—AWSprojenCWE-78OS command injection in the task synthesis component in projen
CVE-2026-541748.3—chainguard-devmelangeCWE-345melange: Incomplete package integrity verification allows data section substi…
CVE-2026-890908.2—AWSAWS SDK for Go v2CWE-248Denial of service in the event stream header decoder in AWS SDK for Go v2
CVE-2026-904518.2—CISAMalcolmCWE-1392An example environment-configuration file ships with a fixed, publicly-known …
CVE-2026-494648.1—nl-portalnl-portal-backend-librariesCWE-639NL Portal: IDOR allows any authenticated user to complete and tamper with ano…
CVE-2026-83017.8—TUBITAK BILGEM Software Technologies Research InstitutePardus Boot RepairCWE-78OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair
CVE-2026-83037.8—TUBITAK BILGEM Software Technologies Research InstitutePardus-softwareCWE-266Privilege Escalation in TUBITAK BILGEM's Pardus-software
CVE-2026-890997.7—MongoDBMongoDB ServerCWE-362Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption
CVE-2026-621097.6—wowDevsSky Addons for ElementorCWE-89WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability
CVE-2026-621127.6—Melograno Venture StudioAmeliaCWE-89WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability
CVE-2026-904607.6—OpenStackKeystoneCWE-863An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained …
CVE-2026-498467.5—signalwirelibksCWE-22libks has path traversal in kws HTTP parser via URI segment overflow
CVE-2026-500137.5—SpectoLabshoverflyCWE-362Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
CVE-2026-541357.5—SimulPiscatorAirSaneCWE-400AirSane has a Remote Denial of Service (OOM) via Unvalidated Content-Length i…
CVE-2026-684977.5—FasterXMLjackson-databindCWE-400jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalenda…
CVE-2026-793937.5—n/an/aCWE-122A heap-based buffer overflow vulnerability in the WS-Addressing Action transf…
CVE-2026-877767.5—compressioncompressionCWE-401compression vulnerable to Denial of Service via memory leak on premature resp…
CVE-2026-542407.4—strukturaglibde265CWE-190libde265: Pixel accessor signed integer overflow causes heap OOB read/write
CVE-2026-542417.4—strukturaglibde265CWE-122libde265: SAO sequential filter heap buffer overflow via signed integer overflow
CVE-2026-578427.3—The NetBSD FoundationNetBSDCWE-415NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen
CVE-2026-477737.2—arduino-librariesArduinoBLECWE-131ArduinoBLE: Memory corruption via malformed ATT write request
CVE-2026-825837.2—NextGen HealthcareMirth ConnectCWE-89NextGen Healthcare Mirth Connect SQL Injection
CVE-2026-870207.2—OrthancDICOM ServerCWE-190Orthanc DICOM Server Integer Overflow or Wraparound
CVE-2026-541667.1—Shelf-nushelf.nuCWE-918Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import i…
CVE-2026-620897.1—Pixar LabsMaster Addons for ElementorCWE-862WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control…
CVE-2026-788077.1—n/an/aCWE-346An issue in wpa_supplicant all versions before v.2.12 allows a local attacker…
CVE-2026-890127.1—DolibarrDolibarrCWE-178Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter
CVE-2026-892457.1—WWBNAVideoCWE-352WWBN AVideo Cross-Site Request Forgery via playlistRemove.php
CVE-2026-892517.1—WWBNAVideoCWE-345AVideo Missing Authorization via AD_Server log.php Wallet Credit
CVE-2026-892527.1—WWBNAVideoCWE-639AVideo Missing Authorization in addLiveLink.php LiveLink Update
CVE-2026-904457.1—CISAMalcolmCWE-22An interface that accepts file uploads from authenticated users extracts the …
CVE-2026-904477.1—CISAMalcolmCWE-290A routing rule selects between two different authentication mechanisms for th…
CVE-2026-904487.1—CISAMalcolmCWE-862A deployment mode intended to expose only read access to stored data proxies …
CVE-2026-850837.0—CareCamANJIA AJL33PC0801 FirmwareCWE-798CareCam Pro IP Cameras Use of Hard-coded Credentials
CVE-2026-450566.9—matrix-orgmatrix-rust-sdkCWE-290Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
CVE-2026-484906.9—arduinoArduinoCore-avrCWE-120ArduinoCore-AVR: Stack-Based Buffer Overflow in String float/double concatena…
CVE-2026-500256.9—t-martmouseholeCWE-200Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM co…
CVE-2026-892426.9—WWBNAVideoCWE-918WWBN AVideo Unauthenticated SSRF via login.json.php
CVE-2026-892486.9—WWBNAVideoCWE-200AVideo WebRTC Plugin Information Disclosure via status.json.php
CVE-2026-892616.9—moxi624MoguBlogCWE-306MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Managemen…
CVE-2026-892636.9—moxi624MoguBlogCWE-306MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification…
CVE-2026-904496.9—CISAMalcolmCWE-306When a particular authentication mode is configured, the reverse proxy forwar…
CVE-2026-904576.9—CISAMalcolmCWE-916The administrative password is hashed using a comparatively weak, fast algori…
CVE-2026-157106.8—NetskopeEndpoint DLPCWE-908Netskope Client Endpoint DLP Kernel Driver Information Leakage
CVE-2026-578436.8—The NetBSD FoundationNetBSDCWE-732NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure
CVE-2026-890656.8—AWSprojenCWE-23Relative path traversal in the generated file manifest cleanup component in p…
CVE-2026-893326.7—AWSKiro IDECWE-201Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Co…
CVE-2026-154396.5—rubengcGamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AICWE-89GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection
CVE-2026-494636.5—nl-portalnl.nl-portal:besluitenCWE-200NL Portal: Missing per-user authorization on document and decision GraphQL qu…
CVE-2026-500186.5—SpectoLabshoverflyCWE-400Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions
CVE-2026-542486.5—kimdredoco-cdCWE-347Doco-CD has an OCI Trust Policy Bypass via Artifact-Contained Configuration
CVE-2026-542586.5—ZoneMinderzoneminderCWE-639Cross-monitor event media authorization bypass in direct event media endpoints
CVE-2026-621106.5—boldthemesBold Page BuilderCWE-79WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vuln…
CVE-2026-621116.5—Ido KobelkowskySimple PaymentCWE-79WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnera…
CVE-2026-621386.5—Visual ComposerVisual Composer Website BuilderCWE-79WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scri…
CVE-2026-851166.5—UnknownSimple CAPTCHA with Cloudflare TurnstileCWE-74Simple CAPTCHA with Cloudflare Turnstile 1.2.2 - 1.42.1 - Unauthenticated Arb…
CVE-2026-541656.4—smgdkngtdobaseCWE-79Stored DOM-XSS in public shared-folder image gallery (one-click, unauthentica…
CVE-2026-499926.3—kimaikimaiCWE-352Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team…
CVE-2026-904556.3—CISAMalcolmCWE-1395A prior update that raised a bundled HTTP client library to a version remedia…
CVE-2026-904616.3—OpenStackIronicCWE-923OpenStack Ironic through 38.0.0 may send a username and password to an unexpe…
CVE-2026-484966.2—open-telemetryopentelemetry-ebpf-profilerCWE-770opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of ser…
CVE-2026-893296.2—Red HatRed Hat Enterprise Linux 10CWE-1322Device-mapper-multipath: local denial of service via blocking ipc send operat…
CVE-2026-72986.1—IdeaSoft Software Industry and Trade Inc.Smart E-CommerceCWE-79Reflected XSS in IdeaSoft's Smart E-Commerce
CVE-2026-184956.1—Red HatRed Hat Hardened ImagesCWE-122Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw…
CVE-2026-774906.1—MicrosoftMicrosoft Edge (Chromium-based)CWE-79Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-819076.1—Concrete CMSConcrete CMSCWE-352Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSR…
CVE-2026-180616.0—AWSAWS Advanced JDBC WrapperCWE-611Improper Restriction of XML External Entity References in AWS Advanced JDBC W…
CVE-2026-181226.0—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted…
CVE-2026-685286.0—Concrete CMSConcrete CMSCWE-79Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Blo…
CVE-2026-819086.0—Concrete CMSConcrete CMSCWE-862Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List End…
CVE-2026-904526.0—CISAMalcolmCWE-295Requests from the reverse proxy to the identity-provider service for token di…
CVE-2026-818615.9—Schneider ElectricSCADAPack 47xCWE-522CWE-522: Insufficiently Protected Credentials vulnerability that could result…
CVE-2026-819095.9—Concrete CMSConcrete CMSCWE-862Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the or…
CVE-2026-819105.9—Concrete CMSConcrete CMSCWE-1336Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection …
CVE-2026-822155.9—UnknownPayment Gateway PayPay for WooCommerceCWE-345WC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified…
CVE-2026-819115.8—Concrete CMSConcrete CMSCWE-79Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Cus…
CVE-2026-819125.7—Concrete CMSConcrete CMSCWE-352Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the …
CVE-2026-879105.7—Python Software FoundationCPythonCWE-22tarfile hardlink fallback ignores custom extraction filter rejection via None
CVE-2026-83045.5—TUBITAK BILGEM Software Technologies Research InstitutePardus AboutCWE-862Information Disclosure in TUBITAK BILGEM's Pardus About
CVE-2026-771595.5—Red HatRed Hat Enterprise Linux 10CWE-61Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file o…
CVE-2026-621335.4—romethemeRTMKitCWE-352WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerab…
CVE-2026-273785.3—magepeopleteamDeposits and Partial Payments for WooCommerceCWE-862WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Bro…
CVE-2026-494625.3—nl-portalnl.nl-portal:appCWE-200nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by …
CVE-2026-498655.3—kimaikimaiCWE-918Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown I…
CVE-2026-620885.3—10upElasticPressCWE-201WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability
CVE-2026-621145.3—WP ChillPasssterCWE-862WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability
CVE-2026-621325.3—masteriyoMasteriyo - LMSCWE-862WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
CVE-2026-621355.3—ArrayticsBookticsCWE-862WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability
CVE-2026-621365.3—wpdeskFlexible Quantity – Measurement Price Calculator for WooCommerceCWE-862WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce pl…
CVE-2026-621375.3—John James JacobybbPressCWE-862WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability
CVE-2026-621405.3—ExpressTech SystemsQuiz And Survey MasterCWE-639WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object Re…
CVE-2026-685265.3—Concrete CMSConcrete CMSCWE-352Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplica…
CVE-2026-819135.3—Concrete CMSConcrete CMSCWE-601Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via…
CVE-2026-822135.3—UnknownNexi XPay BuildCWE-639Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosur…
CVE-2026-825355.3—chamilochamilo-lmsCWE-79Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
CVE-2026-868095.3—UnknownPersian ElementorCWE-345Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authori…
CVE-2026-892395.3—WWBNAVideoCWE-79WWBN AVideo Reflected XSS via Referer Header Comment Breakout
CVE-2026-892405.3—WWBNAVideoCWE-79WWBN AVideo Reflected XSS via confirmLivePassword.php
CVE-2026-892415.3—WWBNAVideoCWE-79WWBN AVideo Reflected XSS via confirmLivePassword.php
CVE-2026-892445.3—WWBNAVideoCWE-79WWBN AVideo Reflected XSS via Gallery Category getBackURL
CVE-2026-892475.3—WWBNAVideoCWE-91WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php
CVE-2026-892575.3—WWBNAVideoCWE-639AVideo through 29.0 Cross-User Category Asset Deletion via Missing Ownership …
CVE-2026-892645.3—moxi624MoguBlogCWE-639MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity
CVE-2026-892655.3—moxi624MoguBlogCWE-862MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid E…
CVE-2026-904435.3—CISAMalcolmCWE-79A web interface reflects a portion of the request URL into a script context a…
CVE-2026-904465.3—CISAMalcolmCWE-918An application programming interface endpoint accepts a user-supplied value a…
CVE-2026-904505.3—CISAMalcolmCWE-863The application's role-authorization lookup defaults to granting access when …
CVE-2026-904545.3—CISAMalcolmCWE-862A deployment mode intended to expose only read access to a bundled packet-ana…
CVE-2026-685355.1—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Con…
CVE-2026-819155.1—Concrete CMSConcrete CMSCWE-639In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
CVE-2026-819165.1—Concrete CMSConcrete CMSCWE-639Incorrect Authorization in the Concrete CMS Express Entries Dashboard below v…
CVE-2026-819175.1—Concrete CMSConcrete CMSCWE-79Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library …
CVE-2026-891485.1—WWBNAVideoCWE-352AVideo Open Redirect via playlistSort.php Referer Header
CVE-2026-892465.1—WWBNAVideoCWE-1236WWBN AVideo CSV Formula Injection via myComments.download.php
CVE-2026-904535.1—CISAMalcolmCWE-601A file-upload handler redirects the authenticated client's browser to a URL t…
CVE-2026-450574.9—matrix-orgmatrix-sdk-uiCWE-345matrix-sdk-ui: Incomplete edit validation
CVE-2026-892984.9—Red HatRed Hat Build of KeycloakCWE-200Keycloak-services: keycloak-services: confidential client secret disclosed to…
CVE-2026-785464.8—CitirxWorkspace app for WindowsCWE-125Out-of-Bounds Read
CVE-2026-819184.8—Concrete CMSConcrete CMSCWE-79Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format fiel…
CVE-2026-868134.8—UnknownMetFormCWE-93MetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Rep…
CVE-2026-785474.4—CitrixCitrix Workspace app for WindowsCWE-787Out-of-Bounds Write
CVE-2024-121454.3—buddypressBuddyPressCWE-862BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Dele…
CVE-2026-91604.3—Arma Digital Media Inc.Website TemplateCWE-1336CSTI in Arma Digital's Website Template
CVE-2026-494394.3—openremoteopenremoteCWE-862OpenRemote read-only asset users can write predicted datapoints
CVE-2026-621134.3—Anh TranSlim SEOCWE-639WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR…
CVE-2026-621344.3—Brainstorm ForceStarter TemplatesCWE-639WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object Referenc…
CVE-2026-621394.3—GoogleSite Kit by GoogleCWE-352WordPress Site Kit by Google plugin <= 1.186.0 - Cross Site Request Forgery (…
CVE-2026-117653.3—TUBITAK BILGEM Software Technologies Research InstitutePardus PenCWE-88Argument Injection in TUBITAK BILGEM's Pardus Pen
CVE-2025-69904await—n/an/a—Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an…
CVE-2026-52630await—n/an/a—SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote…
CVE-2026-67211await—Apache Software FoundationApache OpenNLPCWE-789Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerial…
CVE-2026-71641await—n/an/a—An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a958804…
CVE-2026-71646await—n/an/a—An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version…
CVE-2026-79035await—n/an/a—A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com comp…
CVE-2026-79362await—n/an/a—Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.…
CVE-2026-79394await—n/an/a—An insecure default configuration in the embedded Happytime RTSP server withi…
CVE-2026-79396await—n/an/a—Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT…
CVE-2026-80926await—LinuxLinux—ksmbd: fix use-after-free in oplock break notification
CVE-2026-80927await—LinuxLinux—timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
CVE-2026-80928await—LinuxLinux—smack: fix cred UAF in smack_file_send_sigiotask()
CVE-2026-80929await—LinuxLinux—sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
CVE-2026-80930await—LinuxLinux—tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
CVE-2026-80931await—LinuxLinux—w1: ds28e17: reject an oversize length on an I2C block read
CVE-2026-80932await—LinuxLinux—vsock/virtio: flush works in dependency order
CVE-2026-80933await—LinuxLinux—wifi: mt76: mt7996: validate default EEPROM firmware size
CVE-2026-80934await—LinuxLinux—wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
CVE-2026-80935await—LinuxLinux—wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
CVE-2026-80936await—LinuxLinux—wifi: mt76: mt7925: cancel mlo_pm_work on stop
CVE-2026-80937await—LinuxLinux—wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
CVE-2026-80938await—LinuxLinux—wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
CVE-2026-80939await—LinuxLinux—wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
CVE-2026-80940await—LinuxLinux—wifi: rtw88: pci: fix resource leak on failed NAPI setup
CVE-2026-80941await—LinuxLinux—wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
CVE-2026-80942await—LinuxLinux—wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
CVE-2026-80943await—LinuxLinux—wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
CVE-2026-80944await—LinuxLinux—wifi: mwifiex: Detach sync cmd buffer on interrupted wait
CVE-2026-80945await—LinuxLinux—crypto: iaa - unmap dst before software fallback on decompress
CVE-2026-80946await—LinuxLinux—fuse: copy request headers via a stack buffer for io-uring
CVE-2026-80947await—LinuxLinux—wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
CVE-2026-80948await—LinuxLinux—wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
CVE-2026-80949await—LinuxLinux—wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
CVE-2026-80950await—LinuxLinux—i3c: renesas: Check that the transfer is valid before accessing it
CVE-2026-80951await—LinuxLinux—i3c: master: svc: bound IBI payload to the requested max_payload_len
CVE-2026-80952await—LinuxLinux—i3c: master: Fix info leak and UAF in device unregister path
CVE-2026-80953await—LinuxLinux—i3c: master: adi: initialize the lock before enabling interrupts
CVE-2026-80954await—LinuxLinux—i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_m…
CVE-2026-80955await—LinuxLinux—dm-pcache: fix use-after-free and invalid seg operations in kset_replay()
CVE-2026-80956await—LinuxLinux—dm-pcache: only hand out initialized cache segments
CVE-2026-80957await—LinuxLinux—dm-pcache: detect a cycle in the last-kset chain during replay
CVE-2026-80958await—LinuxLinux—dm-pcache: clamp the tail kset read to the segment data region
CVE-2026-80959await—LinuxLinux—dm-pcache: bound the persisted tail-position offset
CVE-2026-80960await—LinuxLinux—dm-pcache: validate on-media seg_num against the cache device size
CVE-2026-80961await—LinuxLinux—dm-pcache: validate kset key_num and intra-segment bounds
CVE-2026-80962await—LinuxLinux—dm-pcache: validate geometry fields from on-disk cache_info
CVE-2026-80963await—LinuxLinux—dm-stats: fix a crash if allocation of per-cpu data fails
CVE-2026-80964await—LinuxLinux—ALSA: virmidi: Check card index validity at probe
CVE-2026-80965await—LinuxLinux—ALSA: serial-u16550: Check card index validity at probe
CVE-2026-80966await—LinuxLinux—ALSA: portman2x4: Check card index validity at probe
CVE-2026-80967await—LinuxLinux—ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
CVE-2026-80968await—LinuxLinux—ALSA: mts64: Check card index validity at probe
CVE-2026-80969await—LinuxLinux—ALSA: mpu401: Check card index validity at probe
CVE-2026-80970await—LinuxLinux—ALSA: FCP: do not copy out an uninitialised init response
CVE-2026-80971await—LinuxLinux—ALSA: bcd2000: clear the URB pointers on disconnect
CVE-2026-80972await—LinuxLinux—ALSA: aloop: Check card index validity at probe
CVE-2026-80973await—LinuxLinux—ALSA: 6fire: bound the MIDI event length from the device
CVE-2026-80974await—LinuxLinux—mfd: sm501: Fix potential memory leaks during remove
CVE-2026-80975await—LinuxLinux—mfd: qnap-mcu: keep the reply buffer alive past a command timeout
CVE-2026-80976await—LinuxLinux—seg6: reset IP6CB after IPv6 decapsulation
CVE-2026-80977await—LinuxLinux—net: skbuff: don't touch shared zerocopy state in skb_tx_error()
CVE-2026-80978await—LinuxLinux—net: cap advertised IP tunnel headroom
CVE-2026-80979await—LinuxLinux—net/smc: unregister the connection before draining the rx tasklet
CVE-2026-80980await—LinuxLinux—net/smc: stop killed, freed and out_of_sync sharing a byte
CVE-2026-80981await—LinuxLinux—net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
CVE-2026-80982await—LinuxLinux—net/smc: fix use-after-free in smc_rx_pipe_buf_release()
CVE-2026-80983await—LinuxLinux—net/smc: fix socket refcount leak in smc_switch_conns()
CVE-2026-80984await—LinuxLinux—net/smc: do not dereference an unset send buffer on the SMC-D teardown path
CVE-2026-80985await—LinuxLinux—net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
CVE-2026-80986await—LinuxLinux—net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
CVE-2026-80987await—LinuxLinux—NTB: ntb_transport: Reject oversized TX buffers
CVE-2026-80988await—LinuxLinux—NTB: ntb_transport: Fail TX enqueue when the QP link is down
CVE-2026-80989await—LinuxLinux—net: thunderbolt: Mark the connection down when bringing it up fails
CVE-2026-80990await—LinuxLinux—net: thunderbolt: Release the Rx HopID that was handed out on mismatch
CVE-2026-80991await—LinuxLinux—net: ravb: serialize PTP clock teardown
CVE-2026-80992await—LinuxLinux—net: ravb: avoid dereferencing an invalid PTP clock
CVE-2026-80993await—LinuxLinux—net: phylink: correctly validate returned PCS in phylink_inband_caps
CVE-2026-80994await—LinuxLinux—net: openvswitch: fix flow mask use-after-free on flow deletion
CVE-2026-80995await—LinuxLinux—net: mctp: hold a reference to the route device in mctp_route_lookup()
CVE-2026-80996await—LinuxLinux—net: l2tp: do not propagate multicast notification errors
CVE-2026-80997await—LinuxLinux—net: ipa: fix stalled modem TX queue after runtime resume
CVE-2026-80998await—LinuxLinux—net: bnxt: ring the doorbell when SW USO exits early
CVE-2026-80999await—LinuxLinux—net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
CVE-2026-81000await—LinuxLinux—net: tun: bound receive headroom
CVE-2026-81001await—LinuxLinux—slip: fix use-after-free in sl_sync()
CVE-2026-81002await—LinuxLinux—xdp: fix zero-copy frame layout
CVE-2026-81003await—LinuxLinux—net/iucv: filter frames in afiucv_hs_rcv() by ingress device
CVE-2026-81004await—LinuxLinux—ipmi:msghandler: Cancel work cleanly on an error
CVE-2026-81005await—LinuxLinux—ipmi: si: Fix NULL pointer dereference after failed registration
CVE-2026-81006await—LinuxLinux—ipmi: Remove all sysfs files on registration failure
CVE-2026-81007await—LinuxLinux—ipmi: ipmb: validate write message length
CVE-2026-81008await—LinuxLinux—interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
CVE-2026-81009await—LinuxLinux—io_uring/query: cap user size passed to copy_struct_to_user
CVE-2026-81010await—LinuxLinux—io_uring/waitid: honor task_work cancellation
CVE-2026-81011await—LinuxLinux—platform/x86: hp-bioscfg: pass validated element count to package parsers
CVE-2026-81012await—LinuxLinux—platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
CVE-2026-81013await—LinuxLinux—platform/x86: hp-bioscfg: fix heap OOB read on empty password write
CVE-2026-81014await—LinuxLinux—platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
CVE-2026-81015await—LinuxLinux—platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
CVE-2026-81016await—LinuxLinux—platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
CVE-2026-81017await—LinuxLinux—platform/chrome: sensorhub: Bound the EC-reported sensor number
CVE-2026-81018await—LinuxLinux—platform/x86: think-lmi: Free system certificate signatures
CVE-2026-86793await—SGLangSGLang—CVE-2026-86793
CVE-2026-89436await—LinuxLinux—platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]
CVE-2026-89437await—LinuxLinux—platform/x86: int1092: Fix potential memory leak in sar_probe()
CVE-2026-89438await—LinuxLinux—platform/x86: ISST: Validate logical CPU id and clos id
CVE-2026-89439await—LinuxLinux—platform/x86: ISST: Add a NULL check for sst_inst[]
CVE-2026-89440await—LinuxLinux—mmc: via-sdmmc: stop card-detect handling on probe failure
CVE-2026-89441await—LinuxLinux—mmc: via-sdmmc: cancel card-detect work on remove
CVE-2026-89442await—LinuxLinux—platform/x86: ISST: Validate socket ID in clos_assoc ioctl
CVE-2026-89443await—LinuxLinux—platform/x86: ISST: Validate level in perf mask ioctls
CVE-2026-89444await—LinuxLinux—platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
CVE-2026-89445await—LinuxLinux—iommufd: Fix UAF in selftest IOPF reporting
CVE-2026-89446await—LinuxLinux—iommufd: Release current IOAS on xa_store() failure
CVE-2026-89447await—LinuxLinux—iommufd: Avoid locking internal accesses during unmap
CVE-2026-89448await—LinuxLinux—iommu/vt-d: Force requesting ACS when tboot is enabled
CVE-2026-89449await—LinuxLinux—iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add
CVE-2026-89450await—LinuxLinux—iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
CVE-2026-89451await—LinuxLinux—iommu/sva: Set handle->dev before the SVA handle is visible
CVE-2026-89452await—LinuxLinux—iommu/msm: Unwind probe state on registration failure
CVE-2026-89453await—LinuxLinux—iommu/amd: Put PCI device after handling PPR faults
CVE-2026-89454await—LinuxLinux—PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
CVE-2026-89455await—LinuxLinux—PCI: plda: Fix use-after-free of event IRQs during teardown
CVE-2026-89456await—LinuxLinux—s390/dasd: Propagate partial completion length across ERP recovery
CVE-2026-89457await—LinuxLinux—s390/dasd: Guard sysfs discipline callbacks against unallocated private data
CVE-2026-89458await—LinuxLinux—s390/dasd: Do not complete a failed ESE read as successful
CVE-2026-89459await—LinuxLinux—s390/percpu: Fix MVIY_PERCPU() with older binutils
CVE-2026-89460await—LinuxLinux—s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
CVE-2026-89461await—LinuxLinux—power: supply: max17040: synchronize work cancellation on suspend
CVE-2026-89462await—LinuxLinux—power: supply: max17040: propagate register read errors
CVE-2026-89463await—LinuxLinux—power: supply: ucs1002: fix use-after-free on remove
CVE-2026-89464await—LinuxLinux—power: supply: twl4030_charger: cancel workers via devm
CVE-2026-89465await—LinuxLinux—power: supply: rt9455: quiesce delayed work before teardown
CVE-2026-89466await—LinuxLinux—power: supply: qcom_battmgr: terminate the strings from firmware
CVE-2026-89467await—LinuxLinux—power: supply: qcom_battmgr: fix use-after-free
CVE-2026-89468await—LinuxLinux—power: supply: lp8788-charger: fix use-after-free on remove
CVE-2026-89469await—LinuxLinux—power: supply: lp8727: fix use-after-free in lp8727_release_irq()
CVE-2026-89470await—LinuxLinux—power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS

Results continue: ranks 401–703.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-11 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.