| CVE-2026-11496 | 6.5 | 18.2 | edgarrojas | PDF Builder for WooCommerce. Create invoices,packing slips and more | CWE-862 | Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direc… |
| CVE-2026-89173 | 6.9 | 17.8 | Kingdom Communication Associated | EH3040 | CWE-204 | Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data… |
| CVE-2026-19985 | 6.1 | 17.8 | comesio | Relevanssi – A Better Search | CWE-79 | Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting |
| CVE-2026-77150 | 6.1 | 16.9 | unitecms | Unlimited Elements For Elementor | CWE-79 | Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting |
| CVE-2026-89176 | 8.7 | 16.3 | Howyar | WeenyGenius | CWE-306 | Howyar|WeenyGenius - Missing Authentication |
| CVE-2026-19486 | 8.7 | 16.0 | Google Cloud | Gemini Enterprise Agent Platform App Builder | CWE-918 | SSRF in Gemini Enterprise Agent Platform App Builder |
| CVE-2026-81754 | 7.2 | 15.2 | fernandot | Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… | CWE-79 | Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting |
| CVE-2026-6640 | 6.4 | 15.2 | dglingren | Media Library Assistant | CWE-79 | Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-89092 | 4.2 | 15.2 | The GNU C Library | glibc | CWE-789 | Stack overflow in nscd due to unbounded alloca use |
| CVE-2026-89060 | 7.7 | 14.4 | — | multicluster-observability-addon | CWE-551 | Stolostron/multicluster-observability-addon: cross-namespace secret disclosur… |
| CVE-2026-11446 | 5.3 | 14.4 | arraytics | Booktics – Appointment Booking Calendar for Service Businesses | CWE-862 | Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23… |
| CVE-2026-80469 | 8.3 | 13.8 | SICK AG | Sentio Creator Extension 'Device Manager' | CWE-347 | CVE-2026-80469 |
| CVE-2026-86815 | 5.5 | 13.8 | Unknown | BackWPup | CWE-862 | BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration … |
| CVE-2026-89178 | 8.7 | 13.6 | Howyar | WeenyGenius | CWE-940 | Howyar|WeenyGenius - Origin Validation Error |
| CVE-2026-14560 | 10.0 | 13.5 | Unknown | teddy-bear-customize-addon | CWE-94 | Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload |
| CVE-2026-89177 | 8.7 | 13.5 | Howyar | WeenyGenius | CWE-757 | Howyar|WeenyGenius - Use of Insecure Protocol |
| CVE-2026-18562 | 6.1 | 13.4 | realmag777 | HUSKY – Products Filter for WooCommerce Professional | CWE-79 | HUSKY <= 1.4.3 - Reflected Cross-Site Scripting |
| CVE-2026-78131 | 3.7 | 13.3 | strongSwan | strongSwan | CWE-401 | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effe… |
| CVE-2026-84960 | 6.1 | 12.8 | cbutlerjr | WP-Members Membership Plugin | CWE-79 | WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting |
| CVE-2026-89158 | 6.5 | 12.6 | PCRE | PCRE2 | CWE-190 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overf… |
| CVE-2026-18964 | 6.1 | 12.6 | premio | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty | CWE-79 | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeCh… |
| CVE-2026-89160 | 3.7 | 12.6 | PCRE | PCRE2 | CWE-125 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATC… |
| CVE-2026-6641 | 6.4 | 12.1 | dglingren | Media Library Assistant | CWE-79 | Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-6642 | 6.4 | 12.1 | dglingren | Media Library Assistant | CWE-79 | Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site S… |
| CVE-2026-78172 | 6.1 | 11.3 | themifyme | Themify – WooCommerce Product Filter | CWE-79 | Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting |
| CVE-2026-7438 | 6.4 | 10.7 | boldthemes | Bold Timeline Lite | CWE-79 | Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site … |
| CVE-2026-88260 | 8.7 | 9.8 | Brainzcompany | Zenius EMS 8.0 | CWE-288 | Authentication bypass using an alternate path or channel and Improper validat… |
| CVE-2026-78124 | 3.7 | 8.7 | strongSwan | strongSwan | CWE-401 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the o… |
| CVE-2026-86782 | 5.5 | 7.9 | Unknown | Visualizer | CWE-639 | Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR |
| CVE-2026-73784 | 8.8 | 7.3 | Hewlett Packard Enterprise | HPE IceWall products | CWE-347 | HPE IceWall products, Remote Bypass of Security Restrictions |
| CVE-2026-85677 | 8.8 | 6.8 | Unknown | Gutenverse News | CWE-79 | Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content |
| CVE-2026-86812 | 6.5 | 6.3 | Unknown | WPCafe | CWE-284 | WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification vi… |
| CVE-2026-14565 | 5.4 | 5.3 | Unknown | advanced-customized-prompts | CWE-79 | Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Pop… |
| CVE-2026-13326 | 6.9 | 4.7 | qt | qt | CWE-125 | Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord … |
| CVE-2026-83545 | 6.8 | 4.7 | Unknown | CoolClock | CWE-79 | CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON |
| CVE-2026-83546 | 6.8 | 4.7 | Unknown | CoolClock | CWE-79 | CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute |
| CVE-2026-85678 | 6.8 | 4.7 | Unknown | AI Builder | CWE-79 | AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript |
| CVE-2026-86780 | 6.8 | 4.7 | Unknown | Featured Image with URL | CWE-79 | Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text |
| CVE-2025-15695 | 3.5 | 4.7 | Unknown | Translate WordPress with GTranslate | CWE-79 | GTranslate < 3.0.10 - Admin+ Stored XSS |
| CVE-2026-89151 | 3.5 | 4.5 | Forgejo | Forgejo | CWE-863 | Forgejo before 16.0.4 allows use of restricted API tokens for unintended acce… |
| CVE-2026-14562 | 5.3 | 4.1 | Unknown | teddy-bear-customize-addon | CWE-200 | Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure |
| CVE-2026-14559 | 9.8 | 3.4 | Unknown | teddy-bear-customize-addon | CWE-287 | Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover |
| CVE-2026-14563 | 9.8 | 3.4 | Unknown | advanced-customized-prompts | CWE-287 | Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover |
| CVE-2026-82305 | 5.3 | 3.4 | Unknown | YITH WooCommerce Wishlist | CWE-639 | YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Renam… |
| CVE-2026-74925 | 7.2 | 3.1 | Unknown | MultiVendorX | CWE-269 | MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator |
| CVE-2026-14566 | 4.3 | 3.1 | Unknown | advanced-customized-prompts | CWE-639 | Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Met… |
| CVE-2026-86779 | 2.7 | 3.1 | Unknown | Visualizer | CWE-862 | Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart |
| CVE-2026-89145 | 2.4 | 2.8 | flextype | flextype | CWE-79 | Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory |
| CVE-2026-88914 | 4.4 | 2.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-190 | Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read i… |
| CVE-2026-86781 | 5.3 | 1.9 | Unknown | SSL Zen — SSL Certificate Installer & HTTPS Redirects | CWE-287 | SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure |
| CVE-2025-15679 | 7.3 | 1.5 | Bull | BullSequana XH3406 | CWE-258 | BMC root account active without password on BullSequana XH3406 and XH3515 |
| CVE-2026-89161 | 7.4 | 1.4 | PCRE | PCRE2 | CWE-590 | In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject… |
| CVE-2026-89169 | 4.1 | 1.4 | Debian | live-boot | CWE-347 | live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-s… |
| CVE-2026-89179 | 5.3 | 1.2 | Howyar | WeenyGenius | CWE-353 | Howyar|WeenyGenius - Missing Support for Integrity Check |
| CVE-2026-89162 | 2.9 | 1.2 | PCRE | PCRE2 | CWE-669 | In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an … |
| CVE-2026-89157 | 5.7 | 1.0 | PCRE | PCRE2 | CWE-190 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-b… |
| CVE-2026-89156 | 2.9 | 1.0 | PCRE | PCRE2 | CWE-125 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback … |
| CVE-2026-80462 | 10.0 | — | Progress Software | Chef Automate | CWE-306 | Privilege Escalation in Progress Chef Automate |
| CVE-2026-82617 | 10.0 | — | Apache Software Foundation | Apache OpenNLP | CWE-1333 | Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFa… |
| CVE-2026-87985 | 10.0 | — | mistralai | mistral-vibe | CWE-184 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker … |
| CVE-2026-87986 | 10.0 | — | mistralai | mistral-vibe | CWE-228 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker … |
| CVE-2026-87987 | 10.0 | — | mistralai | mistral-vibe | CWE-15 | An arbitrary code execution vulnerability in Mistral Vibe allows an attacker … |
| CVE-2026-87988 | 10.0 | — | mistralai | mistral-vibe | CWE-732 | An arbitrary file access vulnerability in Mistral Vibe allows an attacker to … |
| CVE-2026-53952 | 9.8 | — | GetSimpleCMS-CE | GetSimpleCMS-CE | CWE-285 | GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creatio… |
| CVE-2026-62103 | 9.8 | — | wpeverest | Everest Forms | CWE-502 | WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability |
| CVE-2026-62105 | 9.8 | — | ThemeRex | ThemeREX Addons | CWE-502 | WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability |
| CVE-2026-71644 | 9.8 | — | n/a | n/a | CWE-843 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version… |
| CVE-2026-79395 | 9.8 | — | n/a | n/a | CWE-287 | An improper authentication vulnerability in the WS-Security (wsse:UsernameTok… |
| CVE-2026-84390 | 9.8 | — | Fortinet | FortiMonitorOnSight | CWE-540 | A inclusion of sensitive information in source code vulnerability in Fortinet… |
| CVE-2026-38056 | 9.4 | — | ST Engineering iDirect | Evolution iQ‑Series terminals | CWE-862 | ST Engineering iDirect iQ-Series Terminals Missing Authorization |
| CVE-2026-54072 | 9.3 | — | authorizerdev | authorizer | CWE-601 | Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to att… |
| CVE-2026-72709 | 9.3 | — | SPIP | SPIP | CWE-862 | SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur |
| CVE-2026-72710 | 9.3 | — | SPIP | SPIP | CWE-915 | SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection |
| CVE-2026-87984 | 9.3 | — | mistralai | mistral-vibe | CWE-22 | An arbitrary file write vulnerability in Mistral Vibe, introduced in version … |
| CVE-2026-89010 | 9.3 | — | WAVLINK Technology | WN535M1 | CWE-78 | WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server |
| CVE-2026-89249 | 9.3 | — | WWBN | AVideo | CWE-79 | AVideo YPTWallet Stored XSS via CryptoWallet Configuration |
| CVE-2026-89253 | 9.3 | — | WWBN | AVideo | CWE-79 | AVideo Stored XSS via donationLink in watch page button |
| CVE-2026-89254 | 9.3 | — | WWBN | AVideo | CWE-79 | AVideo CustomizeUser Stored XSS via field_name Parameter |
| CVE-2026-89255 | 9.3 | — | WWBN | AVideo | CWE-79 | AVideo LoginControl Stored XSS via PGP Public Key |
| CVE-2026-89256 | 9.3 | — | WWBN | AVideo | CWE-79 | AVideo Bookmark Plugin Stored XSS via Chapter Names |
| CVE-2026-89258 | 9.3 | — | gohugoio | hugo | CWE-59 | Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get |
| CVE-2026-89259 | 9.3 | — | gohugoio | hugo | CWE-250 | Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS |
| CVE-2026-3869 | 9.2 | — | Schneider Electric | Modicon M580 | CWE-303 | CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability … |
| CVE-2026-54047 | 9.2 | — | LaciSynchroni | server | CWE-287 | Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation vi… |
| CVE-2026-87983 | 9.2 | — | mistralai | mistral-vibe | CWE-22 | An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2… |
| CVE-2026-89212 | 9.2 | — | Perforce | Akana | CWE-611 | XML External Entity in Akana API Platform |
| CVE-2026-89243 | 9.2 | — | WWBN | AVideo | CWE-79 | WWBN AVideo Stored XSS via UserGroups setGroup_name |
| CVE-2026-90456 | 9.2 | — | CISA | Malcolm | CWE-1392 | An example environment-configuration file for a bundled inventory-management … |
| CVE-2026-62102 | 8.8 | — | Gato GraphQL | Gato GraphQL | CWE-266 | WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability |
| CVE-2026-62106 | 8.8 | — | Cozy Vision Technologies Pvt. Ltd. | SMS Alert Order Notifications | CWE-266 | WordPress SMS Alert Order Notifications plugin <= 3.9.9 - Privilege Escalatio… |
| CVE-2026-62107 | 8.8 | — | masteriyo | Masteriyo - LMS | CWE-502 | WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability |
| CVE-2026-71416 | 8.8 | — | headroomlabs-ai | headroom | CWE-287 | Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) |
| CVE-2026-78224 | 8.8 | — | NextGen Healthcare | Mirth Connect | CWE-611 | NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity … |
| CVE-2026-89009 | 8.8 | — | WAVLINK Technology | WN535M1 | CWE-36 | WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server |
| CVE-2026-89266 | 8.8 | — | nothings | stb_vorbis | CWE-787 | stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands |
| CVE-2026-44715 | 8.7 | — | openmrs | org.openmrs.module:legacyui-api | CWE-285 | OpenMRS has Broken Access Control in HL7 Configuration |
| CVE-2026-72708 | 8.7 | — | SPIP | SPIP | CWE-89 | SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter |
| CVE-2026-82578 | 8.7 | — | NextGen Healthcare | Mirth Connect | CWE-611 | NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity … |
| CVE-2026-89013 | 8.7 | — | Dolibarr | Dolibarr | CWE-863 | Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document… |
| CVE-2026-89146 | 8.7 | — | libp2p | libp2p-rendezvous | CWE-190 | libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration… |
| CVE-2026-89147 | 8.7 | — | net-snmp | Net-SNMP | CWE-400 | Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX … |
| CVE-2026-89250 | 8.7 | — | WWBN | AVideo | CWE-306 | WWBN AVideo Unauthenticated File Read via getRecordedFile.php |
| CVE-2026-89260 | 8.7 | — | moxi624 | MoguBlog | CWE-611 | MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeC… |
| CVE-2026-89262 | 8.7 | — | moxi624 | MoguBlog | CWE-639 | MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check |
| CVE-2026-90444 | 8.7 | — | CISA | Malcolm | CWE-78 | A file-transfer interface that requires valid credentials accepts attacker-co… |
| CVE-2026-38058 | 8.6 | — | ST Engineering iDirect | Evolution iQ‑Series terminals | CWE-497 | ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Infor… |
| CVE-2026-85979 | 8.6 | — | Perforce Software | Puppet Enterprise | CWE-20 | Command Injection in Puppet Enterprise |
| CVE-2026-70341 | 8.5 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-416 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-7863 | 8.4 | — | TUBITAK BILGEM Software Technologies Research Institute | Pardus Software | CWE-78 | OS Command Injection in TUBITAK BILGEM's Pardus Software |
| CVE-2026-89066 | 8.4 | — | AWS | projen | CWE-78 | OS command injection in the task synthesis component in projen |
| CVE-2026-54174 | 8.3 | — | chainguard-dev | melange | CWE-345 | melange: Incomplete package integrity verification allows data section substi… |
| CVE-2026-89090 | 8.2 | — | AWS | AWS SDK for Go v2 | CWE-248 | Denial of service in the event stream header decoder in AWS SDK for Go v2 |
| CVE-2026-90451 | 8.2 | — | CISA | Malcolm | CWE-1392 | An example environment-configuration file ships with a fixed, publicly-known … |
| CVE-2026-49464 | 8.1 | — | nl-portal | nl-portal-backend-libraries | CWE-639 | NL Portal: IDOR allows any authenticated user to complete and tamper with ano… |
| CVE-2026-8301 | 7.8 | — | TUBITAK BILGEM Software Technologies Research Institute | Pardus Boot Repair | CWE-78 | OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair |
| CVE-2026-8303 | 7.8 | — | TUBITAK BILGEM Software Technologies Research Institute | Pardus-software | CWE-266 | Privilege Escalation in TUBITAK BILGEM's Pardus-software |
| CVE-2026-89099 | 7.7 | — | MongoDB | MongoDB Server | CWE-362 | Race Condition in MongoDB Server Document Value Layer Leads to Memory Corruption |
| CVE-2026-62109 | 7.6 | — | wowDevs | Sky Addons for Elementor | CWE-89 | WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability |
| CVE-2026-62112 | 7.6 | — | Melograno Venture Studio | Amelia | CWE-89 | WordPress Amelia plugin <= 2.4.9 - SQL Injection vulnerability |
| CVE-2026-90460 | 7.6 | — | OpenStack | Keystone | CWE-863 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained … |
| CVE-2026-49846 | 7.5 | — | signalwire | libks | CWE-22 | libks has path traversal in kws HTTP parser via URI segment overflow |
| CVE-2026-50013 | 7.5 | — | SpectoLabs | hoverfly | CWE-362 | Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode |
| CVE-2026-54135 | 7.5 | — | SimulPiscator | AirSane | CWE-400 | AirSane has a Remote Denial of Service (OOM) via Unvalidated Content-Length i… |
| CVE-2026-68497 | 7.5 | — | FasterXML | jackson-databind | CWE-400 | jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalenda… |
| CVE-2026-79393 | 7.5 | — | n/a | n/a | CWE-122 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transf… |
| CVE-2026-87776 | 7.5 | — | compression | compression | CWE-401 | compression vulnerable to Denial of Service via memory leak on premature resp… |
| CVE-2026-54240 | 7.4 | — | strukturag | libde265 | CWE-190 | libde265: Pixel accessor signed integer overflow causes heap OOB read/write |
| CVE-2026-54241 | 7.4 | — | strukturag | libde265 | CWE-122 | libde265: SAO sequential filter heap buffer overflow via signed integer overflow |
| CVE-2026-57842 | 7.3 | — | The NetBSD Foundation | NetBSD | CWE-415 | NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen |
| CVE-2026-47773 | 7.2 | — | arduino-libraries | ArduinoBLE | CWE-131 | ArduinoBLE: Memory corruption via malformed ATT write request |
| CVE-2026-82583 | 7.2 | — | NextGen Healthcare | Mirth Connect | CWE-89 | NextGen Healthcare Mirth Connect SQL Injection |
| CVE-2026-87020 | 7.2 | — | Orthanc | DICOM Server | CWE-190 | Orthanc DICOM Server Integer Overflow or Wraparound |
| CVE-2026-54166 | 7.1 | — | Shelf-nu | shelf.nu | CWE-918 | Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import i… |
| CVE-2026-62089 | 7.1 | — | Pixar Labs | Master Addons for Elementor | CWE-862 | WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control… |
| CVE-2026-78807 | 7.1 | — | n/a | n/a | CWE-346 | An issue in wpa_supplicant all versions before v.2.12 allows a local attacker… |
| CVE-2026-89012 | 7.1 | — | Dolibarr | Dolibarr | CWE-178 | Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter |
| CVE-2026-89245 | 7.1 | — | WWBN | AVideo | CWE-352 | WWBN AVideo Cross-Site Request Forgery via playlistRemove.php |
| CVE-2026-89251 | 7.1 | — | WWBN | AVideo | CWE-345 | AVideo Missing Authorization via AD_Server log.php Wallet Credit |
| CVE-2026-89252 | 7.1 | — | WWBN | AVideo | CWE-639 | AVideo Missing Authorization in addLiveLink.php LiveLink Update |
| CVE-2026-90445 | 7.1 | — | CISA | Malcolm | CWE-22 | An interface that accepts file uploads from authenticated users extracts the … |
| CVE-2026-90447 | 7.1 | — | CISA | Malcolm | CWE-290 | A routing rule selects between two different authentication mechanisms for th… |
| CVE-2026-90448 | 7.1 | — | CISA | Malcolm | CWE-862 | A deployment mode intended to expose only read access to stored data proxies … |
| CVE-2026-85083 | 7.0 | — | CareCam | ANJIA AJL33PC0801 Firmware | CWE-798 | CareCam Pro IP Cameras Use of Hard-coded Credentials |
| CVE-2026-45056 | 6.9 | — | matrix-org | matrix-rust-sdk | CWE-290 | Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution |
| CVE-2026-48490 | 6.9 | — | arduino | ArduinoCore-avr | CWE-120 | ArduinoCore-AVR: Stack-Based Buffer Overflow in String float/double concatena… |
| CVE-2026-50025 | 6.9 | — | t-mart | mousehole | CWE-200 | Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM co… |
| CVE-2026-89242 | 6.9 | — | WWBN | AVideo | CWE-918 | WWBN AVideo Unauthenticated SSRF via login.json.php |
| CVE-2026-89248 | 6.9 | — | WWBN | AVideo | CWE-200 | AVideo WebRTC Plugin Information Disclosure via status.json.php |
| CVE-2026-89261 | 6.9 | — | moxi624 | MoguBlog | CWE-306 | MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Managemen… |
| CVE-2026-89263 | 6.9 | — | moxi624 | MoguBlog | CWE-306 | MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification… |
| CVE-2026-90449 | 6.9 | — | CISA | Malcolm | CWE-306 | When a particular authentication mode is configured, the reverse proxy forwar… |
| CVE-2026-90457 | 6.9 | — | CISA | Malcolm | CWE-916 | The administrative password is hashed using a comparatively weak, fast algori… |
| CVE-2026-15710 | 6.8 | — | Netskope | Endpoint DLP | CWE-908 | Netskope Client Endpoint DLP Kernel Driver Information Leakage |
| CVE-2026-57843 | 6.8 | — | The NetBSD Foundation | NetBSD | CWE-732 | NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure |
| CVE-2026-89065 | 6.8 | — | AWS | projen | CWE-23 | Relative path traversal in the generated file manifest cleanup component in p… |
| CVE-2026-89332 | 6.7 | — | AWS | Kiro IDE | CWE-201 | Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Co… |
| CVE-2026-15439 | 6.5 | — | rubengc | GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI | CWE-89 | GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection |
| CVE-2026-49463 | 6.5 | — | nl-portal | nl.nl-portal:besluiten | CWE-200 | NL Portal: Missing per-user authorization on document and decision GraphQL qu… |
| CVE-2026-50018 | 6.5 | — | SpectoLabs | hoverfly | CWE-400 | Hoverfly: Denial of Service via Goroutine Leak in Remote Post-Serve Actions |
| CVE-2026-54248 | 6.5 | — | kimdre | doco-cd | CWE-347 | Doco-CD has an OCI Trust Policy Bypass via Artifact-Contained Configuration |
| CVE-2026-54258 | 6.5 | — | ZoneMinder | zoneminder | CWE-639 | Cross-monitor event media authorization bypass in direct event media endpoints |
| CVE-2026-62110 | 6.5 | — | boldthemes | Bold Page Builder | CWE-79 | WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-62111 | 6.5 | — | Ido Kobelkowsky | Simple Payment | CWE-79 | WordPress Simple Payment plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnera… |
| CVE-2026-62138 | 6.5 | — | Visual Composer | Visual Composer Website Builder | CWE-79 | WordPress Visual Composer Website Builder plugin <= 45.16.1 - Cross Site Scri… |
| CVE-2026-85116 | 6.5 | — | Unknown | Simple CAPTCHA with Cloudflare Turnstile | CWE-74 | Simple CAPTCHA with Cloudflare Turnstile 1.2.2 - 1.42.1 - Unauthenticated Arb… |
| CVE-2026-54165 | 6.4 | — | smgdkngt | dobase | CWE-79 | Stored DOM-XSS in public shared-folder image gallery (one-click, unauthentica… |
| CVE-2026-49992 | 6.3 | — | kimai | kimai | CWE-352 | Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team… |
| CVE-2026-90455 | 6.3 | — | CISA | Malcolm | CWE-1395 | A prior update that raised a bundled HTTP client library to a version remedia… |
| CVE-2026-90461 | 6.3 | — | OpenStack | Ironic | CWE-923 | OpenStack Ironic through 38.0.0 may send a username and password to an unexpe… |
| CVE-2026-48496 | 6.2 | — | open-telemetry | opentelemetry-ebpf-profiler | CWE-770 | opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of ser… |
| CVE-2026-89329 | 6.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-1322 | Device-mapper-multipath: local denial of service via blocking ipc send operat… |
| CVE-2026-7298 | 6.1 | — | IdeaSoft Software Industry and Trade Inc. | Smart E-Commerce | CWE-79 | Reflected XSS in IdeaSoft's Smart E-Commerce |
| CVE-2026-18495 | 6.1 | — | Red Hat | Red Hat Hardened Images | CWE-122 | Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw… |
| CVE-2026-77490 | 6.1 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-79 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-81907 | 6.1 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSR… |
| CVE-2026-18061 | 6.0 | — | AWS | AWS Advanced JDBC Wrapper | CWE-611 | Improper Restriction of XML External Entity References in AWS Advanced JDBC W… |
| CVE-2026-18122 | 6.0 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted… |
| CVE-2026-68528 | 6.0 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.5.2 and below is vulnerable to Stored XSS in RSS Displayer Blo… |
| CVE-2026-81908 | 6.0 | — | Concrete CMS | Concrete CMS | CWE-862 | Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List End… |
| CVE-2026-90452 | 6.0 | — | CISA | Malcolm | CWE-295 | Requests from the reverse proxy to the identity-provider service for token di… |
| CVE-2026-81861 | 5.9 | — | Schneider Electric | SCADAPack 47x | CWE-522 | CWE-522: Insufficiently Protected Credentials vulnerability that could result… |
| CVE-2026-81909 | 5.9 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the or… |
| CVE-2026-81910 | 5.9 | — | Concrete CMS | Concrete CMS | CWE-1336 | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection … |
| CVE-2026-82215 | 5.9 | — | Unknown | Payment Gateway PayPay for WooCommerce | CWE-345 | WC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified… |
| CVE-2026-81911 | 5.8 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Cus… |
| CVE-2026-81912 | 5.7 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the … |
| CVE-2026-87910 | 5.7 | — | Python Software Foundation | CPython | CWE-22 | tarfile hardlink fallback ignores custom extraction filter rejection via None |
| CVE-2026-8304 | 5.5 | — | TUBITAK BILGEM Software Technologies Research Institute | Pardus About | CWE-862 | Information Disclosure in TUBITAK BILGEM's Pardus About |
| CVE-2026-77159 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-61 | Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file o… |
| CVE-2026-62133 | 5.4 | — | rometheme | RTMKit | CWE-352 | WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerab… |
| CVE-2026-27378 | 5.3 | — | magepeopleteam | Deposits and Partial Payments for WooCommerce | CWE-862 | WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Bro… |
| CVE-2026-49462 | 5.3 | — | nl-portal | nl.nl-portal:app | CWE-200 | nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by … |
| CVE-2026-49865 | 5.3 | — | kimai | kimai | CWE-918 | Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown I… |
| CVE-2026-62088 | 5.3 | — | 10up | ElasticPress | CWE-201 | WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability |
| CVE-2026-62114 | 5.3 | — | WP Chill | Passster | CWE-862 | WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability |
| CVE-2026-62132 | 5.3 | — | masteriyo | Masteriyo - LMS | CWE-862 | WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability |
| CVE-2026-62135 | 5.3 | — | Arraytics | Booktics | CWE-862 | WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability |
| CVE-2026-62136 | 5.3 | — | wpdesk | Flexible Quantity – Measurement Price Calculator for WooCommerce | CWE-862 | WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce pl… |
| CVE-2026-62137 | 5.3 | — | John James Jacoby | bbPress | CWE-862 | WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability |
| CVE-2026-62140 | 5.3 | — | ExpressTech Systems | Quiz And Survey Master | CWE-639 | WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object Re… |
| CVE-2026-68526 | 5.3 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS before 9.5.3 is vulnerable to CSRF in the Calendar event duplica… |
| CVE-2026-81913 | 5.3 | — | Concrete CMS | Concrete CMS | CWE-601 | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via… |
| CVE-2026-82213 | 5.3 | — | Unknown | Nexi XPay Build | CWE-639 | Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosur… |
| CVE-2026-82535 | 5.3 | — | chamilo | chamilo-lms | CWE-79 | Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php |
| CVE-2026-86809 | 5.3 | — | Unknown | Persian Elementor | CWE-345 | Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authori… |
| CVE-2026-89239 | 5.3 | — | WWBN | AVideo | CWE-79 | WWBN AVideo Reflected XSS via Referer Header Comment Breakout |
| CVE-2026-89240 | 5.3 | — | WWBN | AVideo | CWE-79 | WWBN AVideo Reflected XSS via confirmLivePassword.php |
| CVE-2026-89241 | 5.3 | — | WWBN | AVideo | CWE-79 | WWBN AVideo Reflected XSS via confirmLivePassword.php |
| CVE-2026-89244 | 5.3 | — | WWBN | AVideo | CWE-79 | WWBN AVideo Reflected XSS via Gallery Category getBackURL |
| CVE-2026-89247 | 5.3 | — | WWBN | AVideo | CWE-91 | WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php |
| CVE-2026-89257 | 5.3 | — | WWBN | AVideo | CWE-639 | AVideo through 29.0 Cross-User Category Asset Deletion via Missing Ownership … |
| CVE-2026-89264 | 5.3 | — | moxi624 | MoguBlog | CWE-639 | MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity |
| CVE-2026-89265 | 5.3 | — | moxi624 | MoguBlog | CWE-862 | MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid E… |
| CVE-2026-90443 | 5.3 | — | CISA | Malcolm | CWE-79 | A web interface reflects a portion of the request URL into a script context a… |
| CVE-2026-90446 | 5.3 | — | CISA | Malcolm | CWE-918 | An application programming interface endpoint accepts a user-supplied value a… |
| CVE-2026-90450 | 5.3 | — | CISA | Malcolm | CWE-863 | The application's role-authorization lookup defaults to granting access when … |
| CVE-2026-90454 | 5.3 | — | CISA | Malcolm | CWE-862 | A deployment mode intended to expose only read access to a bundled packet-ana… |
| CVE-2026-68535 | 5.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to Missing authorization in the Con… |
| CVE-2026-81915 | 5.1 | — | Concrete CMS | Concrete CMS | CWE-639 | In Concrete CMS below 9.5.3, Page Type update omits object-level authorization |
| CVE-2026-81916 | 5.1 | — | Concrete CMS | Concrete CMS | CWE-639 | Incorrect Authorization in the Concrete CMS Express Entries Dashboard below v… |
| CVE-2026-81917 | 5.1 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS in the Document Library … |
| CVE-2026-89148 | 5.1 | — | WWBN | AVideo | CWE-352 | AVideo Open Redirect via playlistSort.php Referer Header |
| CVE-2026-89246 | 5.1 | — | WWBN | AVideo | CWE-1236 | WWBN AVideo CSV Formula Injection via myComments.download.php |
| CVE-2026-90453 | 5.1 | — | CISA | Malcolm | CWE-601 | A file-upload handler redirects the authenticated client's browser to a URL t… |
| CVE-2026-45057 | 4.9 | — | matrix-org | matrix-sdk-ui | CWE-345 | matrix-sdk-ui: Incomplete edit validation |
| CVE-2026-89298 | 4.9 | — | Red Hat | Red Hat Build of Keycloak | CWE-200 | Keycloak-services: keycloak-services: confidential client secret disclosed to… |
| CVE-2026-78546 | 4.8 | — | Citirx | Workspace app for Windows | CWE-125 | Out-of-Bounds Read |
| CVE-2026-81918 | 4.8 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format fiel… |
| CVE-2026-86813 | 4.8 | — | Unknown | MetForm | CWE-93 | MetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Rep… |
| CVE-2026-78547 | 4.4 | — | Citrix | Citrix Workspace app for Windows | CWE-787 | Out-of-Bounds Write |
| CVE-2024-12145 | 4.3 | — | buddypress | BuddyPress | CWE-862 | BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Dele… |
| CVE-2026-9160 | 4.3 | — | Arma Digital Media Inc. | Website Template | CWE-1336 | CSTI in Arma Digital's Website Template |
| CVE-2026-49439 | 4.3 | — | openremote | openremote | CWE-862 | OpenRemote read-only asset users can write predicted datapoints |
| CVE-2026-62113 | 4.3 | — | Anh Tran | Slim SEO | CWE-639 | WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR… |
| CVE-2026-62134 | 4.3 | — | Brainstorm Force | Starter Templates | CWE-639 | WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object Referenc… |
| CVE-2026-62139 | 4.3 | — | Google | Site Kit by Google | CWE-352 | WordPress Site Kit by Google plugin <= 1.186.0 - Cross Site Request Forgery (… |
| CVE-2026-11765 | 3.3 | — | TUBITAK BILGEM Software Technologies Research Institute | Pardus Pen | CWE-88 | Argument Injection in TUBITAK BILGEM's Pardus Pen |
| CVE-2025-69904 | await | — | n/a | n/a | — | Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an… |
| CVE-2026-52630 | await | — | n/a | n/a | — | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote… |
| CVE-2026-67211 | await | — | Apache Software Foundation | Apache OpenNLP | CWE-789 | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerial… |
| CVE-2026-71641 | await | — | n/a | n/a | — | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a958804… |
| CVE-2026-71646 | await | — | n/a | n/a | — | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version… |
| CVE-2026-79035 | await | — | n/a | n/a | — | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com comp… |
| CVE-2026-79362 | await | — | n/a | n/a | — | Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.… |
| CVE-2026-79394 | await | — | n/a | n/a | — | An insecure default configuration in the embedded Happytime RTSP server withi… |
| CVE-2026-79396 | await | — | n/a | n/a | — | Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT… |
| CVE-2026-80926 | await | — | Linux | Linux | — | ksmbd: fix use-after-free in oplock break notification |
| CVE-2026-80927 | await | — | Linux | Linux | — | timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() |
| CVE-2026-80928 | await | — | Linux | Linux | — | smack: fix cred UAF in smack_file_send_sigiotask() |
| CVE-2026-80929 | await | — | Linux | Linux | — | sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] |
| CVE-2026-80930 | await | — | Linux | Linux | — | tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout |
| CVE-2026-80931 | await | — | Linux | Linux | — | w1: ds28e17: reject an oversize length on an I2C block read |
| CVE-2026-80932 | await | — | Linux | Linux | — | vsock/virtio: flush works in dependency order |
| CVE-2026-80933 | await | — | Linux | Linux | — | wifi: mt76: mt7996: validate default EEPROM firmware size |
| CVE-2026-80934 | await | — | Linux | Linux | — | wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames |
| CVE-2026-80935 | await | — | Linux | Linux | — | wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy |
| CVE-2026-80936 | await | — | Linux | Linux | — | wifi: mt76: mt7925: cancel mlo_pm_work on stop |
| CVE-2026-80937 | await | — | Linux | Linux | — | wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy |
| CVE-2026-80938 | await | — | Linux | Linux | — | wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex |
| CVE-2026-80939 | await | — | Linux | Linux | — | wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot |
| CVE-2026-80940 | await | — | Linux | Linux | — | wifi: rtw88: pci: fix resource leak on failed NAPI setup |
| CVE-2026-80941 | await | — | Linux | Linux | — | wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() |
| CVE-2026-80942 | await | — | Linux | Linux | — | wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() |
| CVE-2026-80943 | await | — | Linux | Linux | — | wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids |
| CVE-2026-80944 | await | — | Linux | Linux | — | wifi: mwifiex: Detach sync cmd buffer on interrupted wait |
| CVE-2026-80945 | await | — | Linux | Linux | — | crypto: iaa - unmap dst before software fallback on decompress |
| CVE-2026-80946 | await | — | Linux | Linux | — | fuse: copy request headers via a stack buffer for io-uring |
| CVE-2026-80947 | await | — | Linux | Linux | — | wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop |
| CVE-2026-80948 | await | — | Linux | Linux | — | wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() |
| CVE-2026-80949 | await | — | Linux | Linux | — | wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() |
| CVE-2026-80950 | await | — | Linux | Linux | — | i3c: renesas: Check that the transfer is valid before accessing it |
| CVE-2026-80951 | await | — | Linux | Linux | — | i3c: master: svc: bound IBI payload to the requested max_payload_len |
| CVE-2026-80952 | await | — | Linux | Linux | — | i3c: master: Fix info leak and UAF in device unregister path |
| CVE-2026-80953 | await | — | Linux | Linux | — | i3c: master: adi: initialize the lock before enabling interrupts |
| CVE-2026-80954 | await | — | Linux | Linux | — | i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_m… |
| CVE-2026-80955 | await | — | Linux | Linux | — | dm-pcache: fix use-after-free and invalid seg operations in kset_replay() |
| CVE-2026-80956 | await | — | Linux | Linux | — | dm-pcache: only hand out initialized cache segments |
| CVE-2026-80957 | await | — | Linux | Linux | — | dm-pcache: detect a cycle in the last-kset chain during replay |
| CVE-2026-80958 | await | — | Linux | Linux | — | dm-pcache: clamp the tail kset read to the segment data region |
| CVE-2026-80959 | await | — | Linux | Linux | — | dm-pcache: bound the persisted tail-position offset |
| CVE-2026-80960 | await | — | Linux | Linux | — | dm-pcache: validate on-media seg_num against the cache device size |
| CVE-2026-80961 | await | — | Linux | Linux | — | dm-pcache: validate kset key_num and intra-segment bounds |
| CVE-2026-80962 | await | — | Linux | Linux | — | dm-pcache: validate geometry fields from on-disk cache_info |
| CVE-2026-80963 | await | — | Linux | Linux | — | dm-stats: fix a crash if allocation of per-cpu data fails |
| CVE-2026-80964 | await | — | Linux | Linux | — | ALSA: virmidi: Check card index validity at probe |
| CVE-2026-80965 | await | — | Linux | Linux | — | ALSA: serial-u16550: Check card index validity at probe |
| CVE-2026-80966 | await | — | Linux | Linux | — | ALSA: portman2x4: Check card index validity at probe |
| CVE-2026-80967 | await | — | Linux | Linux | — | ALSA: pcxhr: initialize mutexes before requesting threaded IRQ |
| CVE-2026-80968 | await | — | Linux | Linux | — | ALSA: mts64: Check card index validity at probe |
| CVE-2026-80969 | await | — | Linux | Linux | — | ALSA: mpu401: Check card index validity at probe |
| CVE-2026-80970 | await | — | Linux | Linux | — | ALSA: FCP: do not copy out an uninitialised init response |
| CVE-2026-80971 | await | — | Linux | Linux | — | ALSA: bcd2000: clear the URB pointers on disconnect |
| CVE-2026-80972 | await | — | Linux | Linux | — | ALSA: aloop: Check card index validity at probe |
| CVE-2026-80973 | await | — | Linux | Linux | — | ALSA: 6fire: bound the MIDI event length from the device |
| CVE-2026-80974 | await | — | Linux | Linux | — | mfd: sm501: Fix potential memory leaks during remove |
| CVE-2026-80975 | await | — | Linux | Linux | — | mfd: qnap-mcu: keep the reply buffer alive past a command timeout |
| CVE-2026-80976 | await | — | Linux | Linux | — | seg6: reset IP6CB after IPv6 decapsulation |
| CVE-2026-80977 | await | — | Linux | Linux | — | net: skbuff: don't touch shared zerocopy state in skb_tx_error() |
| CVE-2026-80978 | await | — | Linux | Linux | — | net: cap advertised IP tunnel headroom |
| CVE-2026-80979 | await | — | Linux | Linux | — | net/smc: unregister the connection before draining the rx tasklet |
| CVE-2026-80980 | await | — | Linux | Linux | — | net/smc: stop killed, freed and out_of_sync sharing a byte |
| CVE-2026-80981 | await | — | Linux | Linux | — | net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() |
| CVE-2026-80982 | await | — | Linux | Linux | — | net/smc: fix use-after-free in smc_rx_pipe_buf_release() |
| CVE-2026-80983 | await | — | Linux | Linux | — | net/smc: fix socket refcount leak in smc_switch_conns() |
| CVE-2026-80984 | await | — | Linux | Linux | — | net/smc: do not dereference an unset send buffer on the SMC-D teardown path |
| CVE-2026-80985 | await | — | Linux | Linux | — | net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry |
| CVE-2026-80986 | await | — | Linux | Linux | — | net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages |
| CVE-2026-80987 | await | — | Linux | Linux | — | NTB: ntb_transport: Reject oversized TX buffers |
| CVE-2026-80988 | await | — | Linux | Linux | — | NTB: ntb_transport: Fail TX enqueue when the QP link is down |
| CVE-2026-80989 | await | — | Linux | Linux | — | net: thunderbolt: Mark the connection down when bringing it up fails |
| CVE-2026-80990 | await | — | Linux | Linux | — | net: thunderbolt: Release the Rx HopID that was handed out on mismatch |
| CVE-2026-80991 | await | — | Linux | Linux | — | net: ravb: serialize PTP clock teardown |
| CVE-2026-80992 | await | — | Linux | Linux | — | net: ravb: avoid dereferencing an invalid PTP clock |
| CVE-2026-80993 | await | — | Linux | Linux | — | net: phylink: correctly validate returned PCS in phylink_inband_caps |
| CVE-2026-80994 | await | — | Linux | Linux | — | net: openvswitch: fix flow mask use-after-free on flow deletion |
| CVE-2026-80995 | await | — | Linux | Linux | — | net: mctp: hold a reference to the route device in mctp_route_lookup() |
| CVE-2026-80996 | await | — | Linux | Linux | — | net: l2tp: do not propagate multicast notification errors |
| CVE-2026-80997 | await | — | Linux | Linux | — | net: ipa: fix stalled modem TX queue after runtime resume |
| CVE-2026-80998 | await | — | Linux | Linux | — | net: bnxt: ring the doorbell when SW USO exits early |
| CVE-2026-80999 | await | — | Linux | Linux | — | net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO |
| CVE-2026-81000 | await | — | Linux | Linux | — | net: tun: bound receive headroom |
| CVE-2026-81001 | await | — | Linux | Linux | — | slip: fix use-after-free in sl_sync() |
| CVE-2026-81002 | await | — | Linux | Linux | — | xdp: fix zero-copy frame layout |
| CVE-2026-81003 | await | — | Linux | Linux | — | net/iucv: filter frames in afiucv_hs_rcv() by ingress device |
| CVE-2026-81004 | await | — | Linux | Linux | — | ipmi:msghandler: Cancel work cleanly on an error |
| CVE-2026-81005 | await | — | Linux | Linux | — | ipmi: si: Fix NULL pointer dereference after failed registration |
| CVE-2026-81006 | await | — | Linux | Linux | — | ipmi: Remove all sysfs files on registration failure |
| CVE-2026-81007 | await | — | Linux | Linux | — | ipmi: ipmb: validate write message length |
| CVE-2026-81008 | await | — | Linux | Linux | — | interconnect: Fix use after free in icc_get() and of_icc_get_by_index() |
| CVE-2026-81009 | await | — | Linux | Linux | — | io_uring/query: cap user size passed to copy_struct_to_user |
| CVE-2026-81010 | await | — | Linux | Linux | — | io_uring/waitid: honor task_work cancellation |
| CVE-2026-81011 | await | — | Linux | Linux | — | platform/x86: hp-bioscfg: pass validated element count to package parsers |
| CVE-2026-81012 | await | — | Linux | Linux | — | platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() |
| CVE-2026-81013 | await | — | Linux | Linux | — | platform/x86: hp-bioscfg: fix heap OOB read on empty password write |
| CVE-2026-81014 | await | — | Linux | Linux | — | platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() |
| CVE-2026-81015 | await | — | Linux | Linux | — | platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails |
| CVE-2026-81016 | await | — | Linux | Linux | — | platform/x86/amd/pmc: Propagate SMU errors and validate S2D address |
| CVE-2026-81017 | await | — | Linux | Linux | — | platform/chrome: sensorhub: Bound the EC-reported sensor number |
| CVE-2026-81018 | await | — | Linux | Linux | — | platform/x86: think-lmi: Free system certificate signatures |
| CVE-2026-86793 | await | — | SGLang | SGLang | — | CVE-2026-86793 |
| CVE-2026-89436 | await | — | Linux | Linux | — | platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] |
| CVE-2026-89437 | await | — | Linux | Linux | — | platform/x86: int1092: Fix potential memory leak in sar_probe() |
| CVE-2026-89438 | await | — | Linux | Linux | — | platform/x86: ISST: Validate logical CPU id and clos id |
| CVE-2026-89439 | await | — | Linux | Linux | — | platform/x86: ISST: Add a NULL check for sst_inst[] |
| CVE-2026-89440 | await | — | Linux | Linux | — | mmc: via-sdmmc: stop card-detect handling on probe failure |
| CVE-2026-89441 | await | — | Linux | Linux | — | mmc: via-sdmmc: cancel card-detect work on remove |
| CVE-2026-89442 | await | — | Linux | Linux | — | platform/x86: ISST: Validate socket ID in clos_assoc ioctl |
| CVE-2026-89443 | await | — | Linux | Linux | — | platform/x86: ISST: Validate level in perf mask ioctls |
| CVE-2026-89444 | await | — | Linux | Linux | — | platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer |
| CVE-2026-89445 | await | — | Linux | Linux | — | iommufd: Fix UAF in selftest IOPF reporting |
| CVE-2026-89446 | await | — | Linux | Linux | — | iommufd: Release current IOAS on xa_store() failure |
| CVE-2026-89447 | await | — | Linux | Linux | — | iommufd: Avoid locking internal accesses during unmap |
| CVE-2026-89448 | await | — | Linux | Linux | — | iommu/vt-d: Force requesting ACS when tboot is enabled |
| CVE-2026-89449 | await | — | Linux | Linux | — | iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add |
| CVE-2026-89450 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field |
| CVE-2026-89451 | await | — | Linux | Linux | — | iommu/sva: Set handle->dev before the SVA handle is visible |
| CVE-2026-89452 | await | — | Linux | Linux | — | iommu/msm: Unwind probe state on registration failure |
| CVE-2026-89453 | await | — | Linux | Linux | — | iommu/amd: Put PCI device after handling PPR faults |
| CVE-2026-89454 | await | — | Linux | Linux | — | PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() |
| CVE-2026-89455 | await | — | Linux | Linux | — | PCI: plda: Fix use-after-free of event IRQs during teardown |
| CVE-2026-89456 | await | — | Linux | Linux | — | s390/dasd: Propagate partial completion length across ERP recovery |
| CVE-2026-89457 | await | — | Linux | Linux | — | s390/dasd: Guard sysfs discipline callbacks against unallocated private data |
| CVE-2026-89458 | await | — | Linux | Linux | — | s390/dasd: Do not complete a failed ESE read as successful |
| CVE-2026-89459 | await | — | Linux | Linux | — | s390/percpu: Fix MVIY_PERCPU() with older binutils |
| CVE-2026-89460 | await | — | Linux | Linux | — | s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks |
| CVE-2026-89461 | await | — | Linux | Linux | — | power: supply: max17040: synchronize work cancellation on suspend |
| CVE-2026-89462 | await | — | Linux | Linux | — | power: supply: max17040: propagate register read errors |
| CVE-2026-89463 | await | — | Linux | Linux | — | power: supply: ucs1002: fix use-after-free on remove |
| CVE-2026-89464 | await | — | Linux | Linux | — | power: supply: twl4030_charger: cancel workers via devm |
| CVE-2026-89465 | await | — | Linux | Linux | — | power: supply: rt9455: quiesce delayed work before teardown |
| CVE-2026-89466 | await | — | Linux | Linux | — | power: supply: qcom_battmgr: terminate the strings from firmware |
| CVE-2026-89467 | await | — | Linux | Linux | — | power: supply: qcom_battmgr: fix use-after-free |
| CVE-2026-89468 | await | — | Linux | Linux | — | power: supply: lp8788-charger: fix use-after-free on remove |
| CVE-2026-89469 | await | — | Linux | Linux | — | power: supply: lp8727: fix use-after-free in lp8727_release_irq() |
| CVE-2026-89470 | await | — | Linux | Linux | — | power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS |