boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, September 14, 2026 · all times UTC← 2026-09-13 · archive

Security Box Score — September 14, 2026

CISA adds 1 to KEV; 777 CVEs published, led by Apple (245).

777 CVEs published September 14, 2026: 54 critical, 181 high, 218 medium, 97 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 227 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 377 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published649141410——
KEV catalog size1710

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2630 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6314722491223071211230.17.8.0016+215 ▲
microsoft9792878189198069316289301.07.8.0044+537 ▲
google361252731997411141207980.37.5.0025+312 ▲
red hat817064329333337200.06.7.0028-61 ▼
apple2455626010117178881.46.5.0029+243 ▲
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco181022947260581514.77.5.0041-13 ▼
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
ivanti102410122025520.88.8.0146+7 ▲
f572461431414.28.7.0047+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache71581134242191133320.37.5.0049-25 ▼
mozilla352228079630900.08.1.0029+34 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab278517479533.85.3.0029-11 ▼
github32011090000.07.3.0044-2 ▼
docker090630000.07.2.0016-1 ▼
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle022694841170519962840.27.8.00340
ibm18280116335826511610.17.5.0030-10 ▼
adobe17077657343366102040.57.5.0023+110 ▲
progress3641539100611.68.1.0035-13 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+1 ▲
atlassian0615001300.08.1.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link176219221011300.08.5.0157+2 ▲
siemens145163393000.07.3.0018-5 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1343052514012218210.37.2.0020+116 ▲
sourcecodester352040011886000.05.5.0028+19 ▲
spring017012608315000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb50148487534100.07.1.0026+18 ▲
itsourcecode321480037111000.02.1.0026+23 ▲
elastic42130128983100.06.5.0028-6 ▼
wwbn891292143650000.06.9.0024+87 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-64849.164196.89.3
CVE-2026-85706.111195.710.0
CVE-2026-83549.085194.77.8
CVE-2026-82329.076794.29.8
CVE-2026-19478.058192.79.1
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.59.3
CVE-2026-79756.051591.98.7
CVE-2026-83548.046791.210.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1111KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8782710.0.0107
Most disclosures (vendor)
VendorCVEs
linux1015
microsoft1014
oracle890
google714
ibm380
apple287
adobe211
dell188
red hat167
apache139
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco15
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven82
Packagist39
npm19
PyPI15
RubyGems2
Go1
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171762
CVE-2021-27102n/a2021-11-171762
CVE-2021-27101n/a2021-11-171762
CVE-2021-27103n/a2021-11-171762
CVE-2021-21017Adobe2021-11-171762
CVE-2021-28550Adobe2021-11-171762
CVE-2021-42013Apache Software Foundation2021-11-171762
CVE-2021-41773Apache Software Foundation2021-11-171762
CVE-2021-30858Apple2021-11-171762
CVE-2021-30860Apple2021-11-171762

Transactions

ADDED TO KEV — CVE-2026-76461 (Cisco Secure Email). Remediation due September 17, 2026.

EXPLOIT PUBLISHED — FlowiseAI Flowise: 14 CVEs (CVE-2026-69250, CVE-2026-69251, CVE-2026-69252, CVE-2026-69253, CVE-2026-69254, CVE-2026-69255, CVE-2026-69256, CVE-2026-69257, CVE-2026-69258, CVE-2026-69259, CVE-2026-69262, CVE-2026-69263, CVE-2026-69264, CVE-2026-70470). Public exploit references added.

EXPLOIT PUBLISHED — grokability snipe-it: 13 CVEs (CVE-2026-86739, CVE-2026-86740, CVE-2026-86741, CVE-2026-86742, CVE-2026-86743, CVE-2026-86744, CVE-2026-86745, CVE-2026-86746, CVE-2026-86747, CVE-2026-86748, CVE-2026-86749, CVE-2026-86750, CVE-2026-86751). Public exploit references added.

EXPLOIT PUBLISHED — Rizwan17 inventory-management-system: 4 CVEs (CVE-2026-87921, CVE-2026-87926, CVE-2026-90566, CVE-2026-90599). Public exploit references added.

EXPLOIT PUBLISHED — open-webui: 3 CVEs (CVE-2026-88000, CVE-2026-88001, CVE-2026-88002). Public exploit references added.

EXPLOIT PUBLISHED — SPIP: 3 CVEs (CVE-2026-72708, CVE-2026-72709, CVE-2026-72710). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-9086 (curl). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-33870 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3805 (curl). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43502 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43760 (Apple macOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74933 (Unknown GenieWords). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75429. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78849. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79515. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80115 (PassMark Software PerformanceTest). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81022 (Unknown SupportCandy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81648 (Unknown CryptoPayment Gateway). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85129 (Unknown Hoo Companion). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87719 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87929 (MaxSite CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-88793 (Unknown YouTube Embed). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-88802 (Unknown MDJM Event Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-89050 (Unknown Quads Ads Manager for Google AdSense). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90487 (Xuxueli xxl-job). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90490 (lenve vhr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90493 (Tonec Internet Download Manager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90495 (Fengoffice Feng Office). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90497 (Fengoffice Feng Office). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90500 (lenve vhr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90502 (stilleshan ServerStatus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90505 (vvbbnn00 WARP-Clash-API). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90507 (vvbbnn00 WARP-Clash-API). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90510 (dromara orion-visor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90516 (SourceCodester School Registration and Fee System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90518 (PHPGurukul Bank Locker Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90521 (jaychouchannel Tourism-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90523 (jaychouchannel Tourism-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90526 (SourceCodester School Registration and Fee System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90543 (WWBN AVideo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90574 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90576 (GPAC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90579 (cheshire-cat-ai Cheshire Cat AI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90581 (cym1102 nginxWebUI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90584 (TooTallNate Java-WebSocket). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90594 (wxiaoqi Spring-Cloud-Platform). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90597 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90648 (WebAssembly wabt). Public exploit reference added.

DUE DATE PASSED — CVE-2026-67277 (Mikrotik RouterOS). CISA remediation deadline was September 13, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-86060 (Mikrotik RouterOS). CISA remediation deadline was September 13, 2026; still in catalog.

REJECTED — CVE-2026-63310 (nltk). Record withdrawn by the CNA.

RESCORED — Totolink A3002MU: 3 CVEs (CVE-2026-90604, CVE-2026-90605, CVE-2026-90606). CVSS rescored — before/after on each CVE page.

RESCORED — vaadin: 3 CVEs (CVE-2022-29567, CVE-2023-25499, CVE-2023-25500). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-23191 (Linux). CVSS 7.8 → 7 (NVD).

RESCORED — CVE-2026-56711 (VideoLAN VLC media player). CVSS 8.6 → 7.3 (NVD).

RESCORED — CVE-2026-73324 (VideoLAN VLC media player). CVSS 6.9 → 5.3 (NVD).

PATCH SHIPPED — CVE-2026-25470 (ACPT (Pro) - Custom Post Types Plugin for WordPress). Fixed in ACPT (Pro) - Custom Post Types Plugin for WordPress 2.0.52.

ENRICHED — Linux: 18 CVEs (CVE-2024-50017, CVE-2024-56545, CVE-2024-56639, CVE-2025-21651, CVE-2025-22101, CVE-2025-22103, CVE-2025-23129, CVE-2025-37833, CVE-2025-38266, CVE-2025-38591, CVE-2025-71142, CVE-2026-23137, CVE-2026-23201, CVE-2026-23447, CVE-2026-23448, CVE-2026-31420, CVE-2026-43088, CVE-2026-43288). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

777 CVEs published. 25 box scores and 375 table rows below; the remaining 377 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Secure Email Gateway SQL Injection Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —   YES
AFFECTED
  Product             Versions      Fixed
  Cisco Secure Email  14.0.0-698 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 14  Added to CISA KEV, due Sep 17
  Sep 14  Published (CNA: cisco)
CWE-89 · CNA: cisco · CVSS v3.1 · 2 references · NVD status: Undergoing Analysis · KEV due September 17, 2026
GH05TCREW PentestAgent MCP HTTP Server main.py run_task os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0160   74.4     —
AFFECTED
  Product       Versions                                    Fixed
  PentestAgent  cf882dabea3ed91cef016cdd115e5426315665a2 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0160   74.4     —
AFFECTED
  Product       Versions                                    Fixed
  PentestAgent  cf882dabea3ed91cef016cdd115e5426315665a2 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0159   74.3     —
AFFECTED
  Product   Versions  Fixed
  DWR-M920  1.1.7 –   —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0136   70.2     —
AFFECTED
  Product       Versions                                    Fixed
  HexStrike AI  d689933ff579d839c676c82b231f8e98326c5f04 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0135   69.9     —
AFFECTED
  Product       Versions                                    Fixed
  HexStrike AI  d689933ff579d839c676c82b231f8e98326c5f04 –  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Contec Co., Ltd. FXA5000 — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0119   66.1     —
AFFECTED
  Product       Versions     Fixed
  FXA5000       unspecified  —
  FXA5020       unspecified  —
  FXA5020-[][]  unspecified  —
  FXE5000       unspecified  —
  FXE5000-[][]  unspecified  —
  FXS5000-[][]  unspecified  —
  FXS5021       unspecified  —
  FXE4000       unspecified  —
  FXE4000-WP    unspecified  —
  FXS4000       unspecified  —
  + 10 more
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Contec Co., Ltd. SGA1000 — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0119   66.1     —
AFFECTED
  Product  Versions     Fixed
  SGA1000  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Contec Co., Ltd. M2M Gateway Integrated Type CPS-MG341* — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0119   66.1     —
AFFECTED
  Product                                       Versions     Fixed
  M2M Gateway Integrated Type CPS-MG341*        unspecified  —
  M2M Gateway Configurable type CPS-MGS341*     unspecified  —
  M2M Controller Integrated Type CPS-MC341      unspecified  —
  M2M Controller Configurable type CPS-MCS341*  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Contec Co., Ltd. Integrated Type CPS-PC341[][]-*-9201 — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0119   66.1     —
AFFECTED
  Product                                    Versions     Fixed
  Integrated Type CPS-PC341[][]-*-9201       unspecified  —
  Configurable type CPS-PCS341[][]-DS1-1201  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
ipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0109   63.4     —
AFFECTED
  Product          Versions  Fixed
  HackingBuddyGPT  0.1 –     —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Contec Co., Ltd CPS-TM341G5MB-ADSC1-931 — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0102   61.6     —
AFFECTED
  Product                  Versions     Fixed
  CPS-TM341G5MB-ADSC1-931  unspecified  —
  CPS-TM341MB-ADSC1-931    unspecified  —
  CPS-TM341GMB-ADSC1-931   unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Contec Co., Ltd. CAN-2-WF — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0102   61.6     —
AFFECTED
  Product    Versions     Fixed
  CAN-2-WF   unspecified  —
  CAN-2-USB  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
Contec Co., Ltd. SV-CPT-MC310 — SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerabi…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0102   61.6     —
AFFECTED
  Product        Versions     Fixed
  SV-CPT-MC310   unspecified  —
  SV-CPT-MC310F  unspecified  —
TIMELINE
  Aug 31  Reserved by CNA
  Sep 14  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
DataEase DataEase — A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0101   61.1     —
AFFECTED
  Product   Versions     Fixed
  DataEase  unspecified  —
TIMELINE
  Aug 22  Reserved by CNA
  Sep 14  Published (CNA: mitre)
CWE-23 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Received
Totolink A3002MU boa formPortFw buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0080   54.4     —
AFFECTED
  Product  Versions             Fixed
  A3002MU  Hh-B20211125.1046 –  —
TIMELINE
  Sep 12  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Nagios Nagios XI — An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a inse…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  L  N  N    3.5   .0077   53.5     —
AFFECTED
  Product    Versions     Fixed
  Nagios XI  unspecified  —
TIMELINE
  Jan 21  Reserved by CNA
  Sep 14  Published (CNA: mitre)
CWE-208 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
Paessler PRTG Network Monitor — A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read loc…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0066   49.6     —
AFFECTED
  Product               Versions     Fixed
  PRTG Network Monitor  unspecified  —
TIMELINE
  Oct 14  Reserved by CNA
  Sep 14  Published (CNA: mitre)
CWE-23 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
Tenda W20E formDelWebAuthWhiteUser stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0060   46.9     —
AFFECTED
  Product  Versions                         Fixed
  W20E     15.11.0.61068_1546_841_CN_TDC –  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0051   42.0     —
AFFECTED
  Product   Versions             Fixed
  DIR-823G  1.0.2B05_20181207 –  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
n/a GPAC — GPAC MP4Box loader_bt.c gf_bt_report memory corruption
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0050   41.1     —
AFFECTED
  Product  Versions    Fixed
  GPAC     f1219cde –  abi-16.23
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-119 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
n/a memcached — memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0050   41.1     —
AFFECTED
  Product    Versions  Fixed
  memcached  1.6.41 –  1.6.44
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-119, CWE-125 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
regularlabs.com Conditional Content Pro extension for Joomla — Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4   .0049   40.3     —
AFFECTED
  Product                                       Versions       Fixed
  Conditional Content Pro extension for Joomla  1.0.0-7.1.0 –  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 14  Published (CNA: Joomla)
CWE-94 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Received
Softing Secure Integration Server — An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server throug…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0049   40.4     —
AFFECTED
  Product                    Versions     Fixed
  Secure Integration Server  unspecified  —
TIMELINE
  Apr 5   Reserved by CNA
  Sep 14  Published (CNA: mitre)
CWE-23 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    9.4   .0047   39.6     —
AFFECTED
  Product  Versions  Fixed
  DIR-878  120B05 –  —
TIMELINE
  Sep 13  Reserved by CNA
  Sep 14  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-906939.439.6D-LinkDIR-878CWE-119D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow
CVE-2026-906078.639.1TotolinkA3002MUCWE-119Totolink A3002MU boa formNewSchedule buffer overflow
CVE-2026-827708.738.6Contec Co., Ltd.RP-WAH-SR1CWE-120Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote …
CVE-2026-827728.738.6Contec Co., Ltd.ECE1000CWE-120Buffer overflow vulnerability exists in Contec EC1000 series. If a remote att…
CVE-2026-711987.037.9OpenStackGlanceCWE-918In OpenStack Glance before 32.0.1, the location API does not validate destina…
CVE-2026-906915.536.20x4m4HexStrike AICWE-220x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManag…
CVE-2026-906887.133.3TendaW20ECWE-119Tenda W20E HTTP formIPMacBindAdd stack-based overflow
CVE-2026-906205.532.60x4m4HexStrike AICWE-2870x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentic…
CVE-2023-240343.132.0NagiosNagios XICWE-601An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3.…
CVE-2023-460355.929.7fnandosvg_optimizerCWE-776The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untr…
CVE-2026-827878.729.3Contec Co., Ltd.CPSL-08P1ENCWE-306Missing authentication for critical function vulnerability exists in CPSL-08P…
CVE-2026-827688.628.4Contec Co., Ltd.SGA1000CWE-23Path traversal vulnerability exists in SGA1000. If this vulnerability is expl…
CVE-2026-827938.628.4Contec Co., Ltd.CAN-2-WFCWE-434Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.…
CVE-2026-827808.726.8Contec Co., LtdCPS-TM341G5MB-ADSC1-931CWE-434Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM …
CVE-2025-267903.726.3WithSecureAtlantCWE-125Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote …
CVE-2023-504618.825.4TYPO3direct_mailCWE-863An issue was discovered in the direct_mail (aka Direct Mail) extension throug…
CVE-2026-827658.624.3Contec Co., Ltd.FXA5000CWE-23Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, a…
CVE-2026-827755.324.3Contec Co., Ltd.M2M Gateway Integrated Type CPS-MG341*CWE-548An exposure of information through directory listing issue exists in CONPROSY…
CVE-2026-889325.324.1multermulterCWE-400multer vulnerable to Denial of Service via orphaned disk writes on aborted up…
CVE-2023-462738.823.9extremenetworksIQ EngineCWE-121Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.…
CVE-2026-827898.723.1ContecCONPROSYS HMI System(CHS)CWE-95An improper neutralization of directives in dynamically evaluated code ('Eval…
CVE-2026-827855.322.2Contec Co., Ltd.Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*CWE-121Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (…
CVE-2026-906872.121.7n/aGPACCWE-119GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free
CVE-2026-906152.119.6SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System subject1.php cross site scri…
CVE-2026-827825.319.0Contec Co., Ltd.Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*CWE-787Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving …
CVE-2023-504625.318.8TYPO3content_consentCWE-863An issue was discovered in the content_consent (aka Content Consent) extensio…
CVE-2026-893214.318.5Eclipse FoundationEclipse OpenVSXCWE-409Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-…
CVE-2026-906232.918.3andreashappecochiseCWE-287andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certific…
CVE-2026-827785.318.1Contec Co., Ltd.Integrated Type CPS-PC341[][]-*-9201CWE-548An exposure of information through directory listing issue exists in CONPROSY…
CVE-2026-851965.317.5regularlabs.comArticles Anywhere (Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere exten…
CVE-2026-851897.516.0regularlabs.comModals (Free, Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL…
CVE-2026-851907.516.0regularlabs.comQuick Index (Free, Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via class option i…
CVE-2026-851917.516.0regularlabs.comTabs & Accordions (Free, Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias opt…
CVE-2026-851957.516.0regularlabs.comArticles Anywhere (Free, Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via link option in…
CVE-2026-888527.516.0regularlabs.comSnippets (Free) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via url option in …
CVE-2026-888537.516.0regularlabs.comModals (Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via event handler …
CVE-2026-906145.316.0FedML-AIFedMLCWE-20FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read…
CVE-2023-504595.414.9TYPO3femanagerCWE-863An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3…
CVE-2023-504605.414.9TYPO3femanagerCWE-863An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3…
CVE-2026-906972.114.9SourceCodesterInventory Management SystemCWE-285SourceCodester Inventory Management System invoice.php authorization
CVE-2023-348546.613.6digitaldruidHotelDruidCWE-434HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup…
CVE-2023-226312.713.2PaesslerPRTG Network MonitorCWE-88PRTG Network Monitor before 23.1.82 allows remote attackers to write to files…
CVE-2023-226322.713.2PaesslerPRTG Network MonitorCWE-88PRTG Network Monitor before 23.1.82 allows remote attackers to write to files…
CVE-2023-327783.312.9ILIASILIASCWE-23An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker ca…
CVE-2026-851886.912.3regularlabs.comAdvanced Module Manager (Free, Pro) extension for JoomlaCWE-200Joomla Extension - regularlabs.com - Database data disclosure in Advanced Mod…
CVE-2026-258323.712.3TrustedFirmwareMbed TLSCWE-669In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client acc…
CVE-2023-281487.211.2PaesslerPRTG Network MonitorCWE-79A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.
CVE-2026-827846.910.1Contec Co., Ltd.Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*CWE-306Missing authentication for critical function vulnerability exists in Remote I…
CVE-2026-907002.110.0itsourcecodeSales and Inventory SystemCWE-74itsourcecode Sales and Inventory System pro_edit1.php sql injection
CVE-2026-906942.09.8SourceCodesterInventory Management SystemCWE-79SourceCodester Inventory Management System Customer Management customers_hand…
CVE-2026-906952.09.8SourceCodesterInventory Management SystemCWE-79SourceCodester Inventory Management System Vendor Management vendors_handler.…
CVE-2026-906962.09.8SourceCodesterInventory Management SystemCWE-79SourceCodester Inventory Management System Product Management products_handle…
CVE-2026-237933.59.7SamsungExynos 1330 firmwareCWE-787An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, …
CVE-2026-339703.59.7SamsungExynos 850 firmwareCWE-476An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearabl…
CVE-2023-372523.19.6MediaWikiCheckUserCWE-669An issue was discovered in the CheckUser extension for MediaWiki through 1.39…
CVE-2023-372533.19.6MediaWikiProofreadPageCWE-669An issue was discovered in the ProofreadPage extension for MediaWiki through …
CVE-2026-851255.19.1YAMAP INC.YAMAP -Social Trekking GPS AppCWE-940The Android application "YAMAP -Social Trekking GPS App" contains an improper…
CVE-2026-827868.28.7Contec Co., Ltd.Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*CWE-522Insufficiently protected credentials issue exists in Remote I/O Coupler Unit …
CVE-2023-517696.18.6FrappeFrappeCWE-79Frappe before 14.49.0 allows an XSS attack that is associated with blog pages…
CVE-2026-827735.18.6Contec Co., Ltd.M2M Gateway Integrated Type CPS-MG341*CWE-79Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and…
CVE-2026-827765.18.6Contec Co., Ltd.Integrated Type CPS-PC341[][]-*-9201CWE-79Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vu…
CVE-2023-328037.58.1Amazonca-certificatesCWE-669The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Li…
CVE-2026-689558.47.8Rakuten Kobo Inc.The installer for Rakuten Kobo Desktop Application (Windows version)CWE-427The installer for Rakuten Kobo Desktop Application (Windows version) insecure…
CVE-2024-231765.46.7MediaWikiMassMessageCWE-79An issue was discovered in the MassMessage extension in MediaWiki before 1.40…
CVE-2026-827694.86.4Contec Co., Ltd.RP-WAH-SR1CWE-79Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this…
CVE-2026-827714.86.4Contec Co., Ltd.ECE1000CWE-79Cross-site scripting vulnerability exists in Contec EC1000 series. If this vu…
CVE-2026-827674.85.6Contec Co., Ltd.SGA1000CWE-79Cross-site scripting vulnerability exists in SGA1000. If this vulnerability i…
CVE-2026-906221.95.6GNUlibredwgCWE-404GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference
CVE-2026-827885.14.9Contec Co., Ltd.CPSL-08P1ENCWE-79Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerabili…
CVE-2026-312787.74.6supremaincBioStar 2CWE-319An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2…
CVE-2026-827924.84.5Contec Co., Ltd.CAN-2-WFCWE-79Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wi…
CVE-2026-827645.14.4Contec Co., Ltd.FXA5000CWE-352Cross-site request forgery vulnerability exists in multiple Contec products. …
CVE-2026-827815.13.6Contec Co., Ltd.Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*CWE-79Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this v…
CVE-2026-827955.13.6Contec Co., Ltd.SV-CPT-MC310CWE-79SolarView Compact contains a cross-site scripting vulnerability in Schedule S…
CVE-2026-827965.13.6Contec Co., Ltd.SV-CPT-MC310CWE-79SolarView Compact contains a cross-site scripting vulnerability in Image Mana…
CVE-2026-827634.83.5Contec Co., Ltd.FXA5000CWE-79Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 ser…
CVE-2026-827904.83.5Contec Co., Ltd.PC-HELPER Wireless I/O DIO-0404RY-LWFCWE-79Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404R…
CVE-2023-450234.23.2TYPO3femanagerCWE-863The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control…
CVE-2026-237924.03.1SamsungExynos 1080 firmwareCWE-346An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exyno…
CVE-2026-827834.12.8Contec Co., Ltd.Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*CWE-256Plaintext storage of a password issue exists in CONPROSYS nano Series . If th…
CVE-2026-906821.92.4Matthias-WandeljheadCWE-119Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow
CVE-2025-640312.52.4libarchivelibarchiveCWE-122libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the …
CVE-2023-242842.92.2Simon TathamPortable Puzzle CollectionCWE-120Portable Puzzle Collection before 20230116.5782e29 was discovered to contain …
CVE-2023-242852.92.2Simon TathamPortable Puzzle CollectionCWE-120Portable Puzzle Collection before 20230116.5782e29 was discovered to contain …
CVE-2023-242872.92.2Simon TathamPortable Puzzle CollectionCWE-120Portable Puzzle Collection before 20230116.5782e29 was discovered to contain …
CVE-2023-242912.92.2Simon TathamPortable Puzzle CollectionCWE-120Portable Puzzle Collection before 20230116.5782e29 was discovered to contain …
CVE-2026-906111.92.0n/aGPACCWE-617GPAC MP4Box loader_xmt.c xmt_parse_element assertion
CVE-2026-906091.91.9n/aGPACCWE-404GPAC MP4Box vrml_tools.c null pointer dereference
CVE-2026-906101.91.9n/aGPACCWE-119GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read
CVE-2026-906121.91.9n/aGPACCWE-617GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion
CVE-2026-906131.91.9n/aGPACCWE-617GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion
CVE-2026-906831.91.9n/aGPACCWE-617GPAC MP4Box base_scenegraph.c gf_node_unregister assertion
CVE-2023-242832.91.6Simon TathamPortable Puzzle CollectionCWE-120Portable Puzzle Collection before 20230116.5782e29 was discovered to contain …
CVE-2026-906811.91.5Matthias-WandeljheadCWE-119Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds
CVE-2026-906840.91.5n/aGPACCWE-617GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion
CVE-2026-906850.91.5n/aGPACCWE-617GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion
CVE-2023-242882.91.4Simon TathamPortable Puzzle CollectionCWE-190An issue in Portable Puzzle Collection before 20230116.5782e29 allows attacke…
CVE-2026-237897.81.4SamsungExynos 850 firmwareCWE-415An issue was discovered in MFC in Samsung Mobile Processor and Wearable Proce…
CVE-2026-125188.51.3LogitechLogi Options+CWE-269Local privilege escalation in the Logi Options+ updater service on Windows
CVE-2026-339637.51.2SamsungExynos 1330 firmwareCWE-121An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13…
CVE-2026-167266.81.2panasonicPANATERM v6CWE-120Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A…
CVE-2023-242862.91.1Simon TathamPortable Puzzle CollectionCWE-120Portable Puzzle Collection before 20230116.5782e29 was discovered to contain …
CVE-2026-237884.21.0SamsungExynos 1280 firmwareCWE-122An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,…
CVE-2026-339646.40.8SamsungExynos 1580 firmwareCWE-822An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and…
CVE-2026-339574.20.7SamsungExynos 1580 firmwareCWE-787An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1…
CVE-2026-339622.80.7SamsungExynos 850 firmwareCWE-125An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280…
CVE-2026-339662.80.7SamsungExynos 1330 firmwareCWE-215An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13…
CVE-2026-237874.20.6SamsungExynos 1280 firmwareCWE-416An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,…
CVE-2026-237904.20.6SamsungExynos 1280 firmwareCWE-415An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,…
CVE-2026-237914.20.6SamsungExynos 1280 firmwareCWE-787An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,…
CVE-2023-373662.80.5SamsungExynos 850 firmwareCWE-835An issue was discovered in Samsung Exynos Mobile Processor, Automotive Proces…
CVE-2026-339562.80.6SamsungExynos 1330 firmwareCWE-787An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13…
CVE-2026-339602.80.6SamsungExynos 1330 firmwareCWE-787An issue was discovered in Samsung Mobile Processor and Wearable Processor Ex…
CVE-2026-339672.80.6SamsungExynos 1330 firmwareCWE-787An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13…
CVE-2026-339682.80.6SamsungExynos 1330 firmwareCWE-125An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13…
CVE-2026-237862.80.2SamsungExynos 1280 firmwareCWE-367An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,…
CVE-2026-8243410.0—Apache Software FoundationApache Storm NimbusCWE-522Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeepe…
CVE-2026-163389.9—IBMDataStage on Cloud Pak for DataCWE-73DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-203539.8—CiscoCisco Secure EmailCWE-664Cisco Secure Email Gateway Security Hardening Release
CVE-2026-543339.8—theopolisuefi-firmware-parserCWE-787UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable
CVE-2026-543349.8—theopolisuefi-firmware-parserCWE-787UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen`
CVE-2026-552099.8—equinorresdataCWE-120resdata insufficiently validates untrusted GRDECL files
CVE-2026-571239.8—MervinPraisonpraisonaiagentsCWE-306PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Orig…
CVE-2026-571249.8—MervinPraisonPraisonAICWE-78PraisonAI UI MCP connect endpoint allows unauthenticated local command execution
CVE-2026-571259.8—MervinPraisonPraisonAICWE-306PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
CVE-2026-571279.8—MervinPraisonPraisonAICWE-306praisonai: recipe serve auth middleware silently disables itself when no secr…
CVE-2026-571319.8—MervinPraisonPraisonAICWE-94praisonai: Jobs API exposes agent-execution endpoints with no authentication
CVE-2026-591789.8—esphomedevice-builderCWE-306ESPHome Device Builder: Renamed auth env vars silently disable dashboard auth…
CVE-2026-654149.8—AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-733709.8—Apache Software FoundationApache SyncopeCWE-863Apache Syncope: Cross-Realm boundaries reconciliation bypass
CVE-2026-734709.8—Apache Software FoundationApache SyncopeCWE-269Apache Syncope: Delegating users can grant unowned Roles
CVE-2026-735799.8—Apache Software FoundationApache SyncopeCWE-863Apache Syncope: Non-recursive Any search could skip Realms restrictions
CVE-2026-736689.8—Apache Software FoundationApache SyncopeCWE-863Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configu…
CVE-2026-750309.8—Apache Software FoundationApache SyncopeCWE-862Apache Syncope: Incomplete authorization checks for Group members deprovisioning
CVE-2026-764409.8—CiscoCisco Secure EmailCWE-23Cisco Secure Email Gateway Security Hardening Release
CVE-2026-764419.8—CiscoCisco Secure Email and Web ManagerCWE-284Cisco Secure Email Gateway Security Hardening Release
CVE-2026-764439.8—CiscoCisco Secure EmailCWE-707Cisco Secure Email Gateway Security Hardening Release
CVE-2026-770519.8—Apache Software FoundationApache SyncopeCWE-89Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit …
CVE-2026-771819.8—Apache Software FoundationApache SyncopeCWE-863Apache Syncope: ClientApp update entitlement not effective
CVE-2026-783309.8—Apache Software FoundationApache SyncopeCWE-266Apache Syncope: Privilege escalation for admin user via JWT authentication
CVE-2026-822329.8—Apache Software FoundationApache SyncopeCWE-89Apache Syncope: SQL injection via sort parameter in Task search
CVE-2026-824319.8—Apache Software FoundationApache Storm ClientCWE-863Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Wi…
CVE-2026-824359.8—Apache Software FoundationApache Storm WorkerCWE-789Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker M…
CVE-2026-824399.8—Apache Software FoundationApache Storm DRPCCWE-770Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC
CVE-2026-864609.8—Apache Software FoundationApache SyncopeCWE-89Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
CVE-2026-908989.8—maximhqBifrostCWE-284Bifrost unauthenticated remote code execution via MCP stdio client registration
CVE-2026-129449.6—IBMLangflow OSSCWE-918Incomplete Security Scanner Blocklist Enables Network-Based Code Execution
CVE-2026-213919.5—Ping IdentityPingAMCWE-290Improper Claim Validation in PingAM OIDC Provider
CVE-2026-909379.4—froxlorfroxlorCWE-93froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redir…
CVE-2026-673999.3—WebProsWHMCSCWE-502Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 befor…
CVE-2026-909199.3—ModelTCLightLLMCWE-502LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Serve…
CVE-2026-909429.3—casdoorcasdoorCWE-863Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints
CVE-2026-909439.3—parallaxfilament-commentsCWE-79parallax filament-comments through 3.0.0 Stored XSS via Comment Body
CVE-2026-909459.3—crawlab-teamcrawlabCWE-321Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret
CVE-2026-909619.3—MISPMISPCWE-20MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Cr…
CVE-2026-122589.2—HiperdinoREST APICWE-284Inadequate access control in the Hiperdino REST API
CVE-2026-575789.2—rigantidotvvmCWE-862DotVVM: Missing authorization in AuthorizeActionFilter
CVE-2026-500069.1—julien040anyqueryCWE-22Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Executio…
CVE-2026-537139.1—envoyproxygatewayCWE-20Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyEx…
CVE-2026-571459.1—MervinPraisonPraisonAICWE-22PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Valida…
CVE-2026-615349.1—confettiyaysonCWE-1321Yayson: Prototype pollution in the Store/LegacyStore deserialization
CVE-2026-782999.1—Eclipse FoundationEclipse Embedded CDT (C/C++ Development Tools)CWE-22In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extract…
CVE-2026-824419.1—Apache Software FoundationApache Storm NimbusCWE-20Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service…
CVE-2026-877859.1—Apache Software FoundationApache SyncopeCWE-290Apache Syncope: JWT subject spoofing
CVE-2026-878029.1—Apache Software FoundationApache SyncopeCWE-347Apache Syncope: SRA OAuth2 JWT signature verification bypass
CVE-2026-132938.8—IBMMQCWE-502IBM MQ Java messaging is vulnerable to remote code execution
CVE-2026-164288.8—IBMDataStage on Cloud Pak for DataCWE-94DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-164668.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-166738.8—IBMDataStage on Cloud Pak for Data—DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-436928.8—ApplemacOSCWE-20A validation issue was addressed with improved input sanitization. This issue…
CVE-2026-554168.8—pimcorepimcoreCWE-89Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concaten…
CVE-2026-617018.8—cesargblaravel-magiclinkCWE-502Laravel MagicLink: Insecure Deserialization of MagicLink Actions Leads to Rem…
CVE-2026-725248.8—Apache Software FoundationApache DorisCWE-863Apache Doris: Authorization bypass allowing a low-privilege user to read/writ…
CVE-2026-824288.8—Apache Software FoundationApache Storm ClientCWE-22Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable…
CVE-2026-890238.8—ThemeAtelierDomain For SaleCWE-862ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API
CVE-2026-909388.8—langbot-appLangBotCWE-306LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket
CVE-2026-909448.8—krayinlaravel-crmCWE-306Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse
CVE-2026-492508.7—edmundhungconformCWE-407Conform: parseSubmission vulnerable to CPU exhaustion when parsing many uniqu…
CVE-2026-684898.7—WebProsPlesk extension "Ruby"CWE-96Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js To…
CVE-2026-820288.7—absmachmagistralaCWE-89Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API
CVE-2026-844458.7—grpcgrpc-goCWE-129gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `H…
CVE-2026-891808.7—Thinking Software TechnologyEFenceCWE-89Thinking Software Technology|EFence - SQL Injection
CVE-2026-909348.7—espocrmespocrmCWE-863EspoCRM before 10.0.4 Field-level Security Bypass via Attendees
CVE-2026-909468.7—AsyncFuncAIdeepwiki-openCWE-73DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket
CVE-2026-910808.7—adnanhwebhookCWE-770webhook through 2.8.3 Memory Exhaustion via Oversized Request Body
CVE-2026-911448.7—zfile-devzfileCWE-639ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint
CVE-2026-912008.7—devspacedevspaceCWE-22DevSpace through 6.3.21 Path Traversal via tar extraction
CVE-2026-78488.6—Alior BankratyCWE-89SQL Injection in Alior Bank raty PrestaShop module
CVE-2026-156008.6—Alior BankratyCWE-89SQL Injection in Alior Bank raty PrestaShop module
CVE-2026-546288.6—julien040anyqueryCWE-284Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual …
CVE-2026-571228.6—MervinPraisonPraisonAICWE-345PraisonAI: Webhook signature verification skipped (fail-open) when secret uns…
CVE-2026-783758.6—joomshaper.comSP Page Builder (Free and Pro) extension for JoomlaCWE-89Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in…
CVE-2026-868308.6—AWSiam-identity-center-teamCWE-266Incorrect privilege assignment in Temporary Elevated Access Management (TEAM)…
CVE-2026-909328.6—laradashboardlaradashboardCWE-73LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE
CVE-2026-207738.5—Ping IdentityPingFederateCWE-863Improper Authorization in PingFederate Administrative Expression Evaluation E…
CVE-2026-550728.5—pimcorepimcoreCWE-20Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection vi…
CVE-2026-571268.5—MervinPraisonPraisonAICWE-918praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
CVE-2026-813018.5—EkiaFile ManagerCWE-926Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file a…
CVE-2026-907028.5—D-LinkDWR-M921CWE-77D-Link DWR-M921 formDiskFormat system os command injection
CVE-2026-907038.5—D-LinkDWR-M921CWE-77D-Link DWR-M921 formDiskCreateShare system os command injection
CVE-2024-583838.4—froxlorfroxlorCWE-732Froxlor before 2.2.0 Insecure File Permissions mysql.conf
CVE-2026-544478.4—cyberjunkypython-garminconnectCWE-732garminconnect: Insecure Permission Assignment for Garmin OAuth Token Store
CVE-2026-820498.4—Python Software FoundationCPythonCWE-59tarfile extraction filters allow file modification and content disclosure via…
CVE-2026-868368.4—Eclipse FoundationEclipse AnkaiosCWE-276In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload f…
CVE-2026-908958.4—MISPMISPCWE-150MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Te…
CVE-2026-554518.3—locizegettext-converterCWE-1321gettext-converter: Prototype pollution in js2i18next() via crafted translatio…
CVE-2026-174678.2—IBMCloud Pak for Data System (Yosemite 1.0)CWE-327Vulnerabilities exists in IBM Cloud Pak for Data System
CVE-2026-341518.2—xwikixwiki-platformCWE-24XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+
CVE-2026-571328.2—MervinPraisonPraisonAICWE-287PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally …
CVE-2026-575778.2—rigantidotvvmCWE-1333DotVVM: ReDOS in routing
CVE-2026-658388.2—zalandoskipperCWE-754Skipper: an oversized declared-`Content-Length` body still hands OPA an empty…
CVE-2026-859218.2—MicrosoftWindows 11 version 26H1CWE-415Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-908968.2—MarcosCamara01Ecommerce TemplateCWE-306Missing authentication in Ecommerce Template checkout session endpoint allows…
CVE-2026-163358.1—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-256878.1—ZscalerClient ConnectorCWE-366ZCC race condition in ZPA tunnel handler
CVE-2026-541788.1—Laravel-BackpackCRUDCWE-22backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[]…
CVE-2026-541828.1—Laravel-BackpackCRUDCWE-20backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-co…
CVE-2026-571308.1—MervinPraisonpraisonaiagentsCWE-20PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
CVE-2026-595698.1—ZscalerClient ConnectorCWE-20Android ZCC VPN API method privilege escalation
CVE-2026-824328.1—Apache Software FoundationApache Storm NimbusCWE-863Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configurati…
CVE-2026-824388.1—Apache Software FoundationApache Storm WebappCWE-346Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Ori…
CVE-2026-171337.8—IBMApp Connect EnterpriseCWE-78IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution …
CVE-2026-171567.8—IBMApp Connect EnterpriseCWE-502IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution …
CVE-2026-174167.8—IBMApp Connect EnterpriseCWE-502IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution …
CVE-2026-196247.8——NetworkManager-l2tpCWE-88NetworkManager-l2tp: local privilege escalation via ipsec.conf injection
CVE-2026-436897.8—AppleiOS and iPadOSCWE-862A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-436917.8—ApplemacOSCWE-22A path handling issue was addressed with improved validation. This issue is f…
CVE-2026-437837.8—ApplemacOSCWE-362A race condition was addressed with improved locking. This issue is fixed in …
CVE-2026-437867.8—ApplemacOSCWE-280This issue was addressed with additional entitlement checks. This issue is fi…
CVE-2026-647017.8—ApplemacOSCWE-280A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-647127.8—ApplemacOSCWE-284This issue was addressed with improved checks. This issue is fixed in macOS G…
CVE-2026-653627.8—ApplemacOSCWE-284This issue was addressed with improved checks. This issue is fixed in macOS G…
CVE-2026-824277.8—Apache Software FoundationApache Storm NimbusCWE-22Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Bl…
CVE-2026-824297.8—Apache Software FoundationApache Storm Worker LauncherCWE-367Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-o…
CVE-2026-824307.8—Apache Software FoundationApache Storm Worker LauncherCWE-367Apache Storm Worker Launcher: Local Privilege Escalation to Root via Containe…
CVE-2026-845057.8—ApplemacOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-845687.8—ApplemacOSCWE-22A path traversal issue was addressed with improved path validation. This issu…
CVE-2026-846317.8—ApplemacOSCWE-280This issue was addressed with additional entitlement checks. This issue is fi…
CVE-2026-858927.8—MicrosoftMicrosoft Edge (Chromium-based)CWE-362Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-869177.8—ApplemacOSCWE-280A permissions issue was addressed with additional restrictions. This issue is…
CVE-2026-908947.8—ParallelsParallels Desktop for MacCWE-78Parallels Desktop local privilege escalation via appliance extract argument i…
CVE-2026-909477.8—Red HatRed Hat Enterprise Linux 6CWE-787Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset…
CVE-2026-909487.8—Red HatRed Hat Enterprise Linux 6CWE-787Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in …
CVE-2026-909497.8—Red HatRed Hat Enterprise Linux 6CWE-787Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel…
CVE-2026-164327.7—IBMDataStage on Cloud Pak for DataCWE-611DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc…
CVE-2026-194997.7—The GNU C LibraryglibcCWE-122Buffer overflow in strfmon and strfmon_l right-justification padding
CVE-2026-477017.7—open-telemetryopentelemetry-operatorCWE-200OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local …
CVE-2026-541557.7—node-opcuanode-opcuaCWE-347node-opcua: Missing nonce verification in UserNameIdentityToken authentication
CVE-2026-552537.7—langchain-ailangchain-mongodbCWE-943LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to…
CVE-2026-734967.7—soopersetmcp-atlassianCWE-22MCP Atlassian: Arbitrary server-side file read via attachment upload
CVE-2026-540877.6—EasyCorpEasyAdminBundleCWE-79EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline…
CVE-2026-541757.6—Laravel-BackpackCRUDCWE-620backpack/crud: Unverified password change in MyAccountController via mass ass…
CVE-2026-541807.6—Laravel-BackpackCRUDCWE-639backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, an…
CVE-2026-909307.6—filebrowserfilebrowserCWE-59File Browser through 2.63.23 Path Traversal via Symlink Alias
CVE-2026-159557.5—IBMDb2CWE-22IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to pe…
CVE-2026-192907.5—IBMSterling File GatewayCWE-284IBM Sterling File Gateway is Vulnerable to Improper Access Control
CVE-2026-289607.5—AppleiOS and iPadOSCWE-20A denial-of-service issue was addressed with improved validation. This issue …
CVE-2026-502707.5—DataDogdd-trace-javaCWE-770dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-502767.5—DataDogdd-trace-rbCWE-770dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-536597.5—http4khttp4kCWE-409http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilter…
CVE-2026-537527.5—plutextdocx4jCWE-674docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of …
CVE-2026-541567.5—node-opcuanode-opcuaCWE-770node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
CVE-2026-545677.5—jugmac00flask-reuploadedCWE-178Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in nam…
CVE-2026-546297.5—julien040anyqueryCWE-22Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules…
CVE-2026-546327.5—sipsorcery-orgsipsorceryCWE-20SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate…
CVE-2026-550917.5—joaonunoflat-to-nested-jsCWE-915flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__…
CVE-2026-571197.5—MervinPraisonPraisonAICWE-22PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jo…
CVE-2026-571297.5—MervinPraisonpraisonaiagentsCWE-22PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
CVE-2026-575797.5—AlchemyCMSalchemy_cmsCWE-862Alchemy: Unauthenticated nested page API leaks restricted & unpublished content
CVE-2026-595707.5—ZscalerClient ConnectorCWE-20Android ZCC denial of service
CVE-2026-599607.5—argos-ciargos-javascriptCWE-78Argos JavaScript: CI Branch Name OS Command Injection in @argos-ci/core
CVE-2026-653647.5—ApplemacOSCWE-125An out-of-bounds read was addressed with improved bounds checking. This issue…
CVE-2026-731787.5—Apache Software FoundationApache SyncopeCWE-200Apache Syncope: JWT Access Token takeover
CVE-2026-732367.5—Apache Software FoundationApache SyncopeCWE-863Apache Syncope: Cross-Realm authorization bypass in delegated administration
CVE-2026-764427.5—CiscoCisco Secure EmailCWE-1284Cisco Secure Email Gateway Security Hardening Release
CVE-2026-783367.5—Apache Software FoundationApache SyncopeCWE-201Apache Syncope: OIDCC4UI provider list discloses client secrets to any authen…
CVE-2026-845537.5—ApplemacOSCWE-400A resource exhaustion issue was addressed with improved input validation. Thi…
CVE-2026-877797.5—Apache Software FoundationApache SyncopeCWE-532Apache Syncope: AES Secret Key disclosure via log output
CVE-2026-537147.4—envoyproxygatewayCWE-306Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway op…
CVE-2026-706587.4—pay-railspayCWE-208pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook si…
CVE-2026-734947.4—http4sblazeCWE-444blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire pa…
CVE-2026-181167.3—Concrete CMSConcrete CMSCWE-79Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Nam…
CVE-2026-181177.3—Concrete CMSConcrete CMSCWE-79Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias …
CVE-2026-472537.3—julien040anyqueryCWE-22Anyquery: Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory D…
CVE-2026-568397.3—MervinPraisonPraisonAICWE-22PraisonAI Code agent tools fail open without a workspace boundary
CVE-2026-731957.3—Apache Software FoundationApache SyncopeCWE-116Apache Syncope: CSV export spreadsheet formula injection
CVE-2026-819007.3—Concrete CMSConcrete CMSCWE-79Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (v…
CVE-2026-819017.2—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing author…
CVE-2026-909297.2—filebrowserfilebrowserCWE-863File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup
CVE-2026-88217.1—MattermostMattermostCWE-862Playbooks run owner channel membership permission bypass
CVE-2026-127567.1—IBMBusiness Automation Workflow containers and traditionalCWE-611Multiple secuirty vulnerabilies addressed with IBM Business Automation Workfl…
CVE-2026-131077.1—IBMBusiness Automation Workflow containers and traditionalCWE-611Multiple secuirty vulnerabilies addressed with IBM Business Automation Workfl…
CVE-2026-132757.1—IBMMQCWE-611IBM MQ Managed File Transfer is vulnerable to XML external entity injection
CVE-2026-132857.1—IBMMQCWE-611IBM MQ Managed File Transfer is vulnerable to XML external entity injection
CVE-2026-132877.1—IBMMQCWE-611IBM MQ Managed File Transfer is vulnerable to XML external entity injection
CVE-2026-198167.1——PackageKitCWE-863PackageKit: dnf5 backend ignores SIMULATE on RepoRemove
CVE-2026-778847.1—Brain TrustGallery - Private Photo VaultCWE-552Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP fil…
CVE-2026-819027.1—Concrete CMSConcrete CMSCWE-352Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup
CVE-2026-820357.1—PyMuPDFPyMuPDFCWE-22PyMuPDF 1.28.2 Path Traversal via extract_objects() Font Branch
CVE-2026-909277.1—filebrowserfilebrowserCWE-400filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message
CVE-2026-909287.1—filebrowserfilebrowserCWE-400File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint
CVE-2026-909337.1—laradashboardlaradashboardCWE-862laradashboard through 1.2.2 Missing Authorization via License API
CVE-2026-909397.1—201206030novel-plusCWE-862novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list En…
CVE-2026-911457.1—ActivitiActivitiCWE-917Activiti through 7.1.0.M6 Expression Injection via Mail Task
CVE-2026-911977.1—flowableflowable-engineCWE-611Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory
CVE-2026-181197.0—Concrete CMSConcrete CMSCWE-79Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline b…
CVE-2026-815647.0—joomshaper.comSP Page Builder (Free and Pro) extension for JoomlaCWE-22Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Re…
CVE-2026-819037.0—Concrete CMSConcrete CMSCWE-79Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon
CVE-2026-541506.9—muxincnext-videoCWE-22next-video: Unauthenticated arbitrary file read via /api/video request handler
CVE-2026-545596.9—cmusphinxpocketsphinxCWE-119PocketSphinx: Buffer overflows in language and acoustic model loading code
CVE-2026-557956.9—craftcmscommerceCWE-307Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass
CVE-2026-797006.9—joomshaper.comSP Page Builder (Pro) extension for JoomlaCWE-807Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Reques…
CVE-2026-797016.9—joomshaper.comSP Page Builder (Pro) extension for JoomlaCWE-807Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module …
CVE-2026-815656.9—joomshaper.comSP Page Builder (Free and Pro) extension for JoomlaCWE-22Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Up…
CVE-2026-890216.9—MikroTikRouterOSCWE-22MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction
CVE-2026-907076.9—n/aOpen5GSCWE-119Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discov…
CVE-2026-908096.9—HKUDSnanobotCWE-74HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection
CVE-2026-908196.9—a2aprojecta2a-javaCWE-93a2aproject a2a-java Authorization Header Construction BasePushNotificationSen…
CVE-2026-908406.9—PHPGurukulBlood Donor Management SystemCWE-287PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __co…
CVE-2026-908416.9—PHPGurukulBlood Donor Management SystemCWE-89PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injec…
CVE-2026-909406.9—201206030novel-plusCWE-1392novel-plus through 5.3.3 Default Cache Management Password in the Front Portal
CVE-2026-910816.9—suitenumeriquedocsCWE-918Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint
CVE-2026-911436.9—snail007goproxyCWE-288goproxy through 15.3 Authentication Bypass via CONNECT
CVE-2026-911986.9—growthbookgrowthbookCWE-201GrowthBook through 5.0.1 Information Disclosure via Public Endpoints
CVE-2025-248906.8—GitoxideLabsgitoxideCWE-283gix-sec safe.directory protections absent for elevated administrators
CVE-2026-129856.8—MattermostMattermostCWE-601Mattermost DCR redirect URI allowlist bypass via improper URL component valid…
CVE-2026-132656.8—IBMMQCWE-611IBM MQ Managed File Transfer REST API is vulnerable to XML external entity in…
CVE-2026-149866.8—zephyrprojectzephyrCWE-787Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transac…
CVE-2026-161476.8—zephyrprojectzephyrCWE-416it82xx2 USB device controller submits incomplete OUT transfer buffers, causin…
CVE-2026-534956.8—containerdcontainerdCWE-400containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service
CVE-2026-558376.8—dbt-labsdbt-mcpCWE-200dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
CVE-2026-908906.8—ASRockASRock Polychrome SYNC/RGB for MBCWE-822ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Derefe…
CVE-2026-908916.8—ASRockASRock Polychrome SYNC/RGB for MBCWE-1256ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control
CVE-2026-537086.6—IBMmcp-context-forgeCWE-350ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admi…
CVE-2026-541776.6—Laravel-BackpackCRUDCWE-434backpack/crud: HasUploadFields keeps the attacker-supplied file extension — p…
CVE-2026-51326.5—MattermostMattermostCWE-409Unbounded zlib decompression in Calls SDP WebSocket messages
CVE-2026-98126.5—MattermostMattermostCWE-639Missing property field ownership validation in Playbooks run property update …
CVE-2026-127596.5—IBMCloud Pak for Business AutomationCWE-400Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine…
CVE-2026-127656.5—IBMLangflow OSSCWE-918Langflow OSS is affected by server-side request forgery due to missing URL va…
CVE-2026-127676.5—IBMLangflow OSSCWE-918Langflow is vulnerable to server-side request forgery due to missing egress v…
CVE-2026-153966.5—IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-154126.5—IBMWebSphere Application ServerCWE-601IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-156346.5—IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-158146.5—MattermostMattermostCWE-409Uploading a crafted image causes excessive memory allocation in the Mattermos…
CVE-2026-158936.5—zephyrprojectzephyrCWE-617Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advert…
CVE-2026-161876.5—IBMWebSphere Application ServerCWE-862IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-167026.5—IBMDb2CWE-476IBM® Db2® federated server could allow a remote authenticated attacker to cau…
CVE-2026-174636.5—IBMDb2CWE-400IBM® Db2® could allow a remote authenticated attacker to cause a denial of se…
CVE-2026-501576.5—auth0symfonyCWE-598Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony…
CVE-2026-537166.5—envoyproxygatewayCWE-789Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
CVE-2026-537176.5—envoyproxygatewayCWE-789Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untru…
CVE-2026-537196.5—envoyproxygatewayCWE-476Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without s…
CVE-2026-541766.5—Laravel-BackpackCRUDCWE-287backpack/crud: MyAccountController allows changing the login email without a …
CVE-2026-547236.5—devpidevpiCWE-304devpi: Database contents leak
CVE-2026-571156.5—MervinPraisonPraisonAICWE-918PraisonAI: SpiderTools redirect-target SSRF protection bypass
CVE-2026-571206.5—MervinPraisonpraisonaiagentsCWE-693PraisonAI: execute_code sandbox bypass: str.format C-level attribute access r…
CVE-2026-575706.5—Laravel-BackpackCRUDCWE-862backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re…
CVE-2026-685706.5—Apache Software FoundationApache DorisCWE-863Apache Doris: Authorization bypass leading to unauthorized data access
CVE-2026-734976.5—soopersetmcp-atlassianCWE-918MCP Atlassian is a Model Context Protocol (MCP): DNS-rebinding TOCTOU bypass …
CVE-2026-771476.5—Apache Software FoundationApache SyncopeCWE-94Apache Syncope: Groovy Sandbox escape for empty CommandArgs
CVE-2026-824266.5—Apache Software FoundationApache Storm NimbusCWE-22Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded J…
CVE-2026-824336.5—Apache Software FoundationApache Storm NimbusCWE-522Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configu…
CVE-2026-841796.5—Apache Software FoundationApache Storm NimbusCWE-200Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon …
CVE-2026-845386.5—ApplemacOSCWE-20A denial-of-service issue was addressed with improved input validation. This …
CVE-2026-868796.5—AppleiOS and iPadOSCWE-20A denial-of-service issue was addressed with improved input validation. This …
CVE-2026-911816.5—MattermostMattermostCWE-863Data Retention Teams Endpoint Leaks Private Team Invite ID
CVE-2026-41036.4—WSO2WSO2 API Control PlaneCWE-79Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Po…
CVE-2026-161856.4—IBMWebSphere Application ServerCWE-862IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-537186.4—envoyproxygatewayCWE-862Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
CVE-2026-142756.3—IBMi Access FamilyCWE-78IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
CVE-2026-142766.3—IBMi Access FamilyCWE-78IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
CVE-2026-142776.3—IBMi Access FamilyCWE-78IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
CVE-2026-544526.3—doyensecsafeurlCWE-918safeurl: Missing IPv6 CIDR Ranges in Blocklist
CVE-2026-888196.3—Eclipse FoundationEclipse Data Plane CoreCWE-290In Siglet current and past versions the refresh token handler do not enforce …
CVE-2026-908426.3—PHPGurukulBlood Donor Management SystemCWE-313PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in…

Results continue: ranks 401–777.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-14 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.