boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, September 13, 2026 · all times UTC← 2026-09-12 · archive

Security Box Score — September 13, 2026

132 CVEs published, led by jaychouchannel (5).

132 CVEs published September 13, 2026: 5 critical, 27 high, 56 medium, 44 low; 0 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 107 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published571440599——
KEV catalog size1709

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2607 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6314714491222870611230.17.8.0016+215 ▲
microsoft9772876189197869316289301.07.8.0044+538 ▲
google361252731897311101207980.37.5.0025+312 ▲
red hat736984328932937200.06.7.0028-58 ▼
apple0316598516578882.56.5.0029-2 ▼
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco12962446260571414.67.5.0041-19 ▼
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
ivanti102410122025520.88.8.0146+7 ▲
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32541117228181133320.47.5.0049-63 ▼
mozilla352228079630900.08.1.0029+34 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab278517479533.85.3.0029-11 ▼
github32011090000.07.3.0044-2 ▼
docker090630000.07.2.0016-1 ▼
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
adobe17077657343366102040.57.5.0023+110 ▲
ibm1217401613412299610.17.5.0030-53 ▼
progress3641539100611.68.1.0035-13 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+1 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link8531619108300.08.5.0157-7 ▼
siemens145163393000.07.3.0018-3 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1343052514012218210.37.2.0020+122 ▲
sourcecodester301990011881000.05.5.0028+17 ▲
spring017012608315000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb50148487534100.07.1.0026+18 ▲
itsourcecode281440036108000.02.1.0026+20 ▲
wwbn891292143650000.06.9.0024+87 ▲
elastic42129127983100.06.5.0028-6 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-64849.164196.89.3
CVE-2026-83549.085194.77.8
CVE-2026-82329.076794.29.8
CVE-2026-19478.058192.79.1
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.59.3
CVE-2026-79756.051591.98.7
CVE-2026-83548.046791.210.0
CVE-2026-15748.046191.29.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8570610.0.0116KEV
CVE-2026-8782710.0.0107
Most disclosures (vendor)
VendorCVEs
linux1860
microsoft1012
oracle890
google714
ibm319
adobe211
dell188
red hat159
splunk110
wwbn105
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco14
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven46
Packagist38
npm19
PyPI15
RubyGems2
Go1
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171761
CVE-2021-27102n/a2021-11-171761
CVE-2021-27101n/a2021-11-171761
CVE-2021-27103n/a2021-11-171761
CVE-2021-21017Adobe2021-11-171761
CVE-2021-28550Adobe2021-11-171761
CVE-2021-42013Apache Software Foundation2021-11-171761
CVE-2021-41773Apache Software Foundation2021-11-171761
CVE-2021-30858Apple2021-11-171761
CVE-2021-30860Apple2021-11-171761

Transactions

EXPLOIT PUBLISHED — CVE-2026-81578 (PaperCut MF/NG). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82078 (PaperCut MF/NG). Public exploit reference added.

DUE DATE PASSED — CVE-2025-25249 (Fortinet FortiSwitchManager). CISA remediation deadline was September 12, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-19490 (NetScaler ADC). CISA remediation deadline was September 12, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-20079 (Cisco Secure Firewall Management Center (FMC)). CISA remediation deadline was September 12, 2026; still in catalog.

RESCORED — CVE-2025-25252 (Fortinet FortiOS). CVSS 4.3 → 6.5 (NVD).

RESCORED — CVE-2026-52295 (FFmpeg). CVSS 6.2 → 2.9 (NVD).

RESCORED — CVE-2026-90488 (Xuxueli xxl-job). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-90489 (Xuxueli xxl-job). CVSS 5.1 → 2 (NVD).

PATCH SHIPPED — CVE-2025-69130 (Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme). Fixed in Entrepreneur - Booking for Small Businesses WordPress Theme 3.1.5.

PATCH SHIPPED — CVE-2026-18369 (Red Hat Certificate System 10.4 EUS for RHEL-8). Fixed in Red Hat Certificate System 10.4 EUS for RHEL-8 8060020260814202723.07fb4edf.

Yesterday's Results

How to read these box scores · glossary

132 CVEs published. 25 box scores, 107 table rows — nothing truncated.

Unknown CryptoPayment Gateway — CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0      —      —     —
AFFECTED
  Product                Versions  Fixed
  CryptoPayment Gateway  1.2.1 –   —
TIMELINE
  Aug 27  Reserved by CNA
  Sep 13  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Totolink A3002MU boa formFilter buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4      —      —     —
AFFECTED
  Product  Versions             Fixed
  A3002MU  Hh-B20211125.1046 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 13  Published (CNA: VulDB)
CWE-120, CWE-119 · CNA: VulDB · CVSS v4.0 · 6 references
Totolink A3002MU boa formIpv6Setup buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4      —      —     —
AFFECTED
  Product  Versions             Fixed
  A3002MU  Hh-B20211125.1046 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 13  Published (CNA: VulDB)
CWE-120, CWE-119 · CNA: VulDB · CVSS v4.0 · 6 references
Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   P   H   H   N    9.3      —      —     —
AFFECTED
  Product  Versions  Fixed
  strapi   4.0.0 –   —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
langbot-app LangBot — LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2      —      —     —
AFFECTED
  Product  Versions   Fixed
  LangBot  4.0.8.1 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-331 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
Unknown GenieWords — GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8      —      —     —
AFFECTED
  Product     Versions  Fixed
  GenieWords  1.5.27 –  —
TIMELINE
  Aug 17  Reserved by CNA
  Sep 13  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Hoo Companion — Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8      —      —     —
AFFECTED
  Product        Versions  Fixed
  Hoo Companion  1.0.2 –   —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 13  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown YouTube Embed — YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8      —      —     —
AFFECTED
  Product        Versions  Fixed
  YouTube Embed  10.0 –    —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 13  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
UnrealIRCd UnrealIRCd — The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request head…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7      —      —     —
AFFECTED
  Product     Versions  Fixed
  UnrealIRCd  6.0.5 –   —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: mitre)
CWE-770 · CNA: mitre · CVSS v4.0 · 2 references · NVD status: Received
openspug spug — Spug through 3.4.0 Remote Code Execution via ping_check
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7      —      —     —
AFFECTED
  Product  Versions     Fixed
  spug     unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
orhun rustypaste — rustypaste before 0.18.1 Path Traversal via filename header
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   N   H   N    8.7      —      —     —
AFFECTED
  Product     Versions     Fixed
  rustypaste  unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7      —      —     —
AFFECTED
  Product     Versions  Fixed
  nodemailer  9.1.0 –   10.0.5
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-407 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
ESPnet before 202609 Remote Code Execution via Unsafe Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7      —      —     —
AFFECTED
  Product  Versions     Fixed
  espnet   unspecified  202609
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-502 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7      —      —     —
AFFECTED
  Product  Versions     Fixed
  sipp     unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-120 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7      —      —     —
AFFECTED
  Product  Versions     Fixed
  sipp     unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7      —      —     —
AFFECTED
  Product  Versions     Fixed
  sipp     unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-120 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
kevoreilly CAPEv2 — CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   N   H   H   N    8.6      —      —     —
AFFECTED
  Product  Versions     Fixed
  CAPEv2   unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
Tonec Internet Download Manager Kernel Driver idmwfp.sys access control
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    8.5      —      —     —
AFFECTED
  Product                    Versions         Fixed
  Internet Download Manager  6.42 Build 63 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 13  Published (CNA: VulDB)
CWE-266, CWE-284 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Moritz Bunkus MKVToolNix — MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   L   L   N   N   P   H   H   H    8.5      —      —     —
AFFECTED
  Product     Versions     Fixed
  MKVToolNix  unspecified  1495126138e086080f0163bee27fafbdf956a1d0
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-680 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
lfnovo open-notebook — Open Notebook before 1.11.0 Server-Side Request Forgery via link-source
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    8.3      —      —     —
AFFECTED
  Product        Versions     Fixed
  open-notebook  unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-918 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
amundsen-io amundsen-frontend — Amundsen Frontend through 4.3.0 Stored XSS via Description
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   L   P   H   L   N    8.3      —      —     —
AFFECTED
  Product            Versions     Fixed
  amundsen-frontend  unspecified  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 13  Published (CNA: VulnCheck)
CWE-79 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Received
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a…
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   L   H   N   N  C  H  H  L    8.1      —      —     —
AFFECTED
  Product  Versions     Fixed
  CrewAI   unspecified  —
TIMELINE
  Apr 6   Reserved by CNA
  Sep 13  Published (CNA: mitre)
CWE-424 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same co…
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   L   N  C  N  H  N    7.7      —      —     —
AFFECTED
  Product     Versions     Fixed
  CyberPanel  unspecified  —
TIMELINE
  Mar 4   Reserved by CNA
  Sep 13  Published (CNA: mitre)
CWE-1025 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
zephyrproject zephyr — NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5      —      —     —
AFFECTED
  Product  Versions  Fixed
  zephyr   4.1.0 –   —
TIMELINE
  Jul 15  Reserved by CNA
  Sep 13  Published (CNA: zephyr)
CWE-476 · CNA: zephyr · CVSS v3.1 · 2 references · NVD status: Received
Unknown User Registration & Membership — User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership Purchase
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5      —      —     —
AFFECTED
  Product                         Versions  Fixed
  User Registration & Membership  4.4.6 –   —
TIMELINE
  Sep 7   Reserved by CNA
  Sep 13  Published (CNA: WPScan)
CWE-269 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-888027.5—UnknownMDJM Event Management—MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary P…
CVE-2026-890807.5—UnknownReally Simple SecurityCWE-287Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provide…
CVE-2026-906787.5—HAProxyHAProxyCWE-130An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 throug…
CVE-2026-364537.4—RhymixRhymixCWE-425Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1.…
CVE-2026-800717.2—UnknownUser Registration & MembershipCWE-269User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Admi…
CVE-2026-907677.1—froxlorFroxlorCWE-93Froxlor before 2.3.12 SSH Key Injection via authorized_keys
CVE-2026-907757.1—PostGISaddress_standardizerCWE-125PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated…
CVE-2026-904946.9—restifynode-restifyCWE-22restify node-restify static.js serveStatic path traversal
CVE-2026-905136.9—simalexanapi-lambda-send-email-sesCWE-287simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sen…
CVE-2026-905936.9—n/aembedded-graphicsCWE-189embedded-graphics image_raw.rs draw_sub_image integer overflow
CVE-2026-905966.9—n/aembedded-graphicsCWE-189embedded-graphics image_raw.rs new/bytes_per_row integer overflow
CVE-2026-906016.9—getzepgraphitiCWE-287getzep graphiti REST API main.py improper authentication
CVE-2026-906036.9—Anil-matchaOpen-Generative-AICWE-284Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload
CVE-2022-429176.7—FRRoutingFRRoutingCWE-367In FRRouting FRR before 8.5, the service user (usually frr) can escalate its …
CVE-2025-708196.3—ZettlabD6 UltraCWE-24Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in …
CVE-2026-907716.3—hapijsjoiCWE-1321joi before 17.13.8 and 18.2.9 Prototype Pollution via messages
CVE-2026-907826.0—SysterelS2OPCCWE-476S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_it…
CVE-2026-369895.8—LuxSoftLuxCal Web CalendarCWE-89A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rss…
CVE-2024-539225.7—SamsungExynos 8890 firmwareCWE-1284An issue was discovered in the buffer queue driver in Samsung Automotive Proc…
CVE-2026-904955.5—FengofficeFeng OfficeCWE-74Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll …
CVE-2026-904985.5—lenvevhrCWE-1392lenve vhr vhr.sql default credentials
CVE-2026-905045.5—vvbbnn00WARP-Clash-APICWE-287vvbbnn00 WARP-Clash-API authorized missing authentication
CVE-2026-905095.5—dromaraorion-visorCWE-259dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard…
CVE-2026-905105.5—dromaraorion-visorCWE-320dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey har…
CVE-2026-905145.5—SourceCodesterSchool Registration and Fee SystemCWE-74SourceCodester School Registration and Fee System save_stud.php sql injection
CVE-2026-905155.5—SourceCodesterSchool Registration and Fee SystemCWE-74SourceCodester School Registration and Fee System delete_stud.php sql injection
CVE-2026-905165.5—SourceCodesterSchool Registration and Fee SystemCWE-74SourceCodester School Registration and Fee System pay_report.php sql injection
CVE-2026-905175.5—PHPGurukulBank Locker Management SystemCWE-285PHPGurukul Bank Locker Management System view-assign-locker.php authorization
CVE-2026-905225.5—jaychouchannelTourism-Management-SystemCWE-640jaychouchannel Tourism-Management-System Password Recovery UsersController.ja…
CVE-2026-905235.5—jaychouchannelTourism-Management-SystemCWE-266jaychouchannel Tourism-Management-System User Register Endpoint UsersControll…
CVE-2026-905245.5—jaychouchannelTourism-Management-SystemCWE-287jaychouchannel Tourism-Management-System Update Endpoint missing authentication
CVE-2026-905265.5—SourceCodesterSchool Registration and Fee SystemCWE-74SourceCodester School Registration and Fee System save_class.php sql injection
CVE-2026-905655.5—Rizwan17inventory-management-systemCWE-266Rizwan17 inventory-management-system dashboard.php access control
CVE-2026-905665.5—Rizwan17inventory-management-systemCWE-266Rizwan17 inventory-management-system Registration register.php createUserAcco…
CVE-2026-905795.5—cheshire-cat-aiCheshire Cat AICWE-287cheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key mi…
CVE-2026-905825.5—evanchiuserverless-todoCWE-400evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consum…
CVE-2026-905845.5—TooTallNateJava-WebSocketCWE-400TooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuo…
CVE-2025-638425.4—Repeticoweb backendCWE-79A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetic…
CVE-2026-887645.4—UnknownSimple MembershipCWE-269Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPa…
CVE-2026-158925.3—zephyrprojectzephyrCWE-401Heap memory leak in mcumgr settings-management handlers on access-hook reject…
CVE-2026-777735.3—UnknownContact Form to Chat Apps | Click to Chat to OrderCWE-200Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entr…
CVE-2026-889955.3—UnknownBookit — Booking & Appointment CalendarCWE-200Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availabilit…
CVE-2026-905275.3—quequnlongshiyi-blogCWE-79quequnlong shiyi-blog Add Message API index.vue cross site scripting
CVE-2026-905715.3—ExrickxmallCWE-79Exrick xmall Order Printing order-print.jsp cross site scripting
CVE-2026-905835.3—kagisearchsmallwebCWE-79kagisearch smallweb Query String Rendering sw.py index cross site scripting
CVE-2026-905285.1—TDuckApptduck-platformCWE-79TDuckApp tduck-platform Form Write View index.vue cross site scripting
CVE-2026-905295.1—n/aDataEaseCWE-79DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting
CVE-2026-905635.1—maliangnanshengbbs-springbootCWE-79maliangnansheng bbs-springboot ArticleController.java utils.toToc cross site …
CVE-2026-905645.1—quequnlongshiyi-blogCWE-79quequnlong shiyi-blog chat sendMsg Endpoint index.vue SysChatMsgMapper.getCha…
CVE-2026-905675.1—quequnlongshiyi-blogCWE-79quequnlong shiyi-blog Search index.vue highlightKeyword cross site scripting
CVE-2026-905685.1—moxi624Mogu Blog v2CWE-79moxi624 Mogu Blog v2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSo…
CVE-2026-906025.1—Anil-matchaOpen-Generative-AICWE-79Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory…
CVE-2026-906045.1—TotolinkA3002MUCWE-79Totolink A3002MU Anchor Tag cross site scripting
CVE-2020-158755.0—LibreNMSLibreNMSCWE-89An issue was discovered in LibreNMS 1.65. A remote authenticated attacker wit…
CVE-2026-905694.8—linlinjavalitemallCWE-79linlinjava litemall Admin Topic index.vue AdminTopicController.validate cross…
CVE-2026-905704.8—linlinjavalitemallCWE-79linlinjava litemall Product Detail index.vue AdminGoodsService.validate cross…
CVE-2026-907814.8—ALSA Projectalsa-libCWE-193alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii…
CVE-2026-800724.7—UnknownUser Registration & MembershipCWE-601User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Lo…
CVE-2026-298104.3—CyberPanelCyberPanelCWE-390CyberPanel before 2.4.4 omits a "return 0" that is required by the business l…
CVE-2026-298124.3—CyberPanelCyberPanelCWE-778CyberPanel before 2.4.4 has no logging for actions that could potentially man…
CVE-2026-890504.3—UnknownQuads Ads Manager for Google AdSense—Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment…
CVE-2026-906794.3—ForgejoForgejoCWE-348Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has…
CVE-2026-889124.2—UnknownrtMedia for WordPress, BuddyPress and bbPressCWE-639rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrar…
CVE-2026-864073.7—UnknownUser Registration & MembershipCWE-200User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure…
CVE-2025-708203.5—ZettlabD6 UltraCWE-36Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders…
CVE-2026-358673.1—LB-LINKAC1900 firmwareCWE-78A Command Injection vulnerability exists in the bs_SetLimitCli_info function …
CVE-2025-454803.0—projectfloodlightFloodlightCWE-669Floodlight 71fe8a7 allows disruption of host communication via link spoofing.…
CVE-2026-383322.9—cdcseacaveTinyEXIFCWE-125TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch…
CVE-2026-522962.9—FFmpegFFmpegCWE-125FFmpeg before 9.0 has an out-of-bounds read because of missing required paddi…
CVE-2026-522972.9—FFmpegFFmpegCWE-125FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently p…
CVE-2026-905752.9—PHPGurukulSmall CRMCWE-20PHPGurukul Small CRM Login Success login.php unserialize deserialization
CVE-2026-907732.4—dalanceprocsCWE-150procs through 0.14.12 Terminal Escape Sequence Injection via Command
CVE-2026-904902.1—lenvevhrCWE-20lenve vhr MailReceiver deserialization
CVE-2026-904912.1—sanjeviraugsubsCWE-74sanjevirau gsubs Electron index.js showQuerySuccessPage code injection
CVE-2026-904922.1—webgjcweb_robotCWE-77webgjc web_robot web.py controller_recover os command injection
CVE-2026-904992.1—lenvevhrCWE-266lenve vhr Password Update pass HrInfoController.updatePass improper authoriza…
CVE-2026-905002.1—lenvevhrCWE-284lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload
CVE-2026-905012.1—lenvevhrCWE-266lenve vhr HrMapper.xml HrInfoController.updateHr privileges management
CVE-2026-905072.1—vvbbnn00WARP-Clash-APICWE-266vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription a…
CVE-2026-905112.1—GongShengyueOnlineBooksCWE-74GongShengyue OnlineBooks listSplit BooksServlet.java sql injection
CVE-2026-905182.1—PHPGurukulBank Locker Management SystemCWE-266PHPGurukul Bank Locker Management System sidebar.php access control
CVE-2026-905192.1—PHPGurukulBank Locker Management SystemCWE-284PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload
CVE-2026-905202.1—jaychouchannelTourism-Management-SystemCWE-266jaychouchannel Tourism-Management-System Authorization Interceptor Authorizat…
CVE-2026-905212.1—jaychouchannelTourism-Management-SystemCWE-285jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java a…
CVE-2026-905252.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System cust_pos_trans.php sql injection
CVE-2026-905742.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System emp_transac.php add sql injection
CVE-2026-905802.1—FlowiseAIFlowiseCWE-918FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side reques…
CVE-2026-905812.1—cym1102nginxWebUICWE-74cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection
CVE-2026-905942.1—wxiaoqiSpring-Cloud-PlatformCWE-862wxiaoqi Spring-Cloud-Platform Permission Service PermissionService.java Permi…
CVE-2026-905952.1—wxiaoqiSpring-Cloud-PlatformCWE-862wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlin…
CVE-2026-905972.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System sup_edit1.php sql injection
CVE-2026-905982.1—jaygajera17E-commerce-project-springBootCWE-285jaygajera17 E-commerce-project-springBoot UserController.java UserController.…
CVE-2026-905992.1—Rizwan17inventory-management-systemCWE-352Rizwan17 inventory-management-system process.php cross-site request forgery
CVE-2026-906002.1—itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System inv_edit1.php sql injection
CVE-2026-904962.0—FengofficeFeng OfficeCWE-74Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimen…
CVE-2026-904972.0—FengofficeFeng OfficeCWE-79Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scr…
CVE-2026-905022.0—stilleshanServerStatusCWE-79stilleshan ServerStatus Stats Generation main.cpp cross site scripting
CVE-2026-905722.0—davenardellasnap7CWE-119davenardella snap7 s7_micro_client.cpp opUpload memory corruption
CVE-2026-905731.9—n/aGPACCWE-404GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference
CVE-2026-905761.9—n/aGPACCWE-404GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference
CVE-2026-905771.9—n/aGPACCWE-119GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow
CVE-2026-905781.9—n/aGPACCWE-119GPAC MP4Box list.c gf_list_count use after free
CVE-2025-640591.8—getgravGravCWE-79Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOT…
CVE-2026-905031.8—Chengdu Qilu TechnologyLudashiCWE-200Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information discl…
CVE-2026-905081.8—Chengdu Qilu TechnologyLudashiCWE-862Chengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageN…
CVE-2026-905051.3—vvbbnn00WARP-Clash-APICWE-362vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition
CVE-2026-905061.3—vvbbnn00WARP-Clash-APICWE-362vvbbnn00 WARP-Clash-API Save Account Job race condition

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-13 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.