AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 — — YES
AFFECTED Product Versions Fixed Cisco Secure Email 14.0.0-698 – —
TIMELINE Aug 19 Reserved by CNA Sep 14 Added to CISA KEV, due Sep 17 Sep 14 Published (CNA: cisco)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 777 CVEs published, led by Apple (245).
777 CVEs published September 14, 2026: 54 critical, 181 high, 218 medium, 97 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 227 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 377 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 6491 | 41410 | — | — |
| KEV catalog size | 1710 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2630 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 631 | 4722 | 491 | 2230 | 712 | 1 | 12 | 3 | 0.1 | 7.8 | .0016 | +215 ▲ |
| microsoft | 979 | 2878 | 189 | 1980 | 693 | 16 | 289 | 30 | 1.0 | 7.8 | .0044 | +537 ▲ |
| 361 | 2527 | 319 | 974 | 1114 | 120 | 79 | 8 | 0.3 | 7.5 | .0025 | +312 ▲ | |
| red hat | 81 | 706 | 43 | 293 | 333 | 37 | 2 | 0 | 0.0 | 6.7 | .0028 | -61 ▼ |
| apple | 245 | 562 | 60 | 101 | 171 | 7 | 88 | 8 | 1.4 | 6.5 | .0029 | +243 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | -11 ▼ |
| suse | 12 | 40 | 7 | 21 | 11 | 1 | 0 | 0 | 0.0 | 7.6 | .0037 | +7 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 18 | 102 | 29 | 47 | 26 | 0 | 58 | 15 | 14.7 | 7.5 | .0041 | -13 ▼ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 10 | 40 | 10 | 10 | 17 | 3 | 29 | 7 | 17.5 | 7.0 | .0038 | +3 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0025 | -7 ▼ |
| ivanti | 10 | 24 | 10 | 12 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0146 | +7 ▲ |
| f5 | 7 | 24 | 6 | 14 | 3 | 1 | 4 | 1 | 4.2 | 8.7 | .0047 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 71 | 581 | 134 | 242 | 191 | 13 | 33 | 2 | 0.3 | 7.5 | .0049 | -25 ▼ |
| mozilla | 35 | 222 | 80 | 79 | 63 | 0 | 9 | 0 | 0.0 | 8.1 | .0029 | +34 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0024 | +26 ▲ |
| gitlab | 2 | 78 | 5 | 17 | 47 | 9 | 5 | 3 | 3.8 | 5.3 | .0029 | -11 ▼ |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | -2 ▼ |
| docker | 0 | 9 | 0 | 6 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0016 | -1 ▼ |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -1 ▼ |
| kubernetes | 0 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0035 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2269 | 484 | 1170 | 519 | 96 | 28 | 4 | 0.2 | 7.8 | .0034 | 0 |
| ibm | 182 | 801 | 163 | 358 | 265 | 11 | 6 | 1 | 0.1 | 7.5 | .0030 | -10 ▼ |
| adobe | 170 | 776 | 57 | 343 | 366 | 10 | 20 | 4 | 0.5 | 7.5 | .0023 | +110 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0035 | -13 ▼ |
| solarwinds | 0 | 23 | 17 | 3 | 3 | 0 | 10 | 4 | 17.4 | 9.1 | .0058 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | -10 ▼ |
| zohocorp | 5 | 15 | 3 | 6 | 6 | 0 | 0 | 0 | 0.0 | 8.4 | .0099 | +1 ▲ |
| atlassian | 0 | 6 | 1 | 5 | 0 | 0 | 13 | 0 | 0.0 | 8.1 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 17 | 62 | 19 | 22 | 10 | 11 | 3 | 0 | 0.0 | 8.5 | .0157 | +2 ▲ |
| siemens | 14 | 51 | 6 | 33 | 9 | 3 | 0 | 0 | 0.0 | 7.3 | .0018 | -5 ▼ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +18 ▲ |
| synology | 0 | 27 | 3 | 6 | 15 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -1 ▼ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0040 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0036 | +3 ▲ |
| hitachi energy | 4 | 7 | 0 | 3 | 4 | 0 | 0 | 0 | 0.0 | 6.9 | .0017 | +4 ▲ |
| abb | 0 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 134 | 305 | 25 | 140 | 122 | 18 | 2 | 1 | 0.3 | 7.2 | .0020 | +116 ▲ |
| sourcecodester | 35 | 204 | 0 | 0 | 118 | 86 | 0 | 0 | 0.0 | 5.5 | .0028 | +19 ▲ |
| spring | 0 | 170 | 12 | 60 | 83 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | 0 |
| nvidia | 32 | 166 | 20 | 117 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +16 ▲ |
| mongodb | 50 | 148 | 4 | 87 | 53 | 4 | 1 | 0 | 0.0 | 7.1 | .0026 | +18 ▲ |
| itsourcecode | 32 | 148 | 0 | 0 | 37 | 111 | 0 | 0 | 0.0 | 2.1 | .0026 | +23 ▲ |
| elastic | 42 | 130 | 1 | 28 | 98 | 3 | 1 | 0 | 0.0 | 6.5 | .0028 | -6 ▼ |
| wwbn | 89 | 129 | 21 | 43 | 65 | 0 | 0 | 0 | 0.0 | 6.9 | .0024 | +87 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-64849 | .1641 | 96.8 | 9.3 |
| CVE-2026-85706 | .1111 | 95.7 | 10.0 |
| CVE-2026-83549 | .0851 | 94.7 | 7.8 |
| CVE-2026-82329 | .0767 | 94.2 | 9.8 |
| CVE-2026-19478 | .0581 | 92.7 | 9.1 |
| CVE-2026-19586 | .0570 | 92.6 | 9.3 |
| CVE-2026-19490 | .0560 | 92.5 | 9.3 |
| CVE-2026-79756 | .0515 | 91.9 | 8.7 |
| CVE-2026-83548 | .0467 | 91.2 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .1111 | KEV |
| CVE-2026-83548 | 10.0 | .0467 | KEV |
| CVE-2026-75650 | 10.0 | .0215 | KEV |
| CVE-2026-86152 | 10.0 | .0186 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-82222 | 10.0 | .0155 | |
| CVE-2026-82004 | 10.0 | .0144 | |
| CVE-2026-87827 | 10.0 | .0107 |
| Vendor | CVEs |
|---|---|
| linux | 1015 |
| microsoft | 1014 |
| oracle | 890 |
| 714 | |
| ibm | 380 |
| apple | 287 |
| adobe | 211 |
| dell | 188 |
| red hat | 167 |
| apache | 139 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 15 |
| apple | 8 |
| 8 | |
| fortinet | 7 |
| ivanti | 5 |
| adobe | 4 |
| berriai | 4 |
| jfrog | 4 |
| oracle | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 82 |
| Packagist | 39 |
| npm | 19 |
| PyPI | 15 |
| RubyGems | 2 |
| Go | 1 |
| NuGet | 1 |
| crates.io | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-64849 | mlflow | 1 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1762 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1762 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1762 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1762 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1762 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1762 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1762 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1762 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1762 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1762 |
ADDED TO KEV — CVE-2026-76461 (Cisco Secure Email). Remediation due September 17, 2026.
EXPLOIT PUBLISHED — FlowiseAI Flowise: 14 CVEs (CVE-2026-69250, CVE-2026-69251, CVE-2026-69252, CVE-2026-69253, CVE-2026-69254, CVE-2026-69255, CVE-2026-69256, CVE-2026-69257, CVE-2026-69258, CVE-2026-69259, CVE-2026-69262, CVE-2026-69263, CVE-2026-69264, CVE-2026-70470). Public exploit references added.
EXPLOIT PUBLISHED — grokability snipe-it: 13 CVEs (CVE-2026-86739, CVE-2026-86740, CVE-2026-86741, CVE-2026-86742, CVE-2026-86743, CVE-2026-86744, CVE-2026-86745, CVE-2026-86746, CVE-2026-86747, CVE-2026-86748, CVE-2026-86749, CVE-2026-86750, CVE-2026-86751). Public exploit references added.
EXPLOIT PUBLISHED — Rizwan17 inventory-management-system: 4 CVEs (CVE-2026-87921, CVE-2026-87926, CVE-2026-90566, CVE-2026-90599). Public exploit references added.
EXPLOIT PUBLISHED — open-webui: 3 CVEs (CVE-2026-88000, CVE-2026-88001, CVE-2026-88002). Public exploit references added.
EXPLOIT PUBLISHED — SPIP: 3 CVEs (CVE-2026-72708, CVE-2026-72709, CVE-2026-72710). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2025-23368 (wildfly-core). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-9086 (curl). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-33870 (netty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3805 (curl). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43502 (Linux). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-43760 (Apple macOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-74933 (Unknown GenieWords). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75429. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-78849. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79515. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-80115 (PassMark Software PerformanceTest). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81022 (Unknown SupportCandy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81648 (Unknown CryptoPayment Gateway). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85129 (Unknown Hoo Companion). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87719 (GitLab). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87929 (MaxSite CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-88793 (Unknown YouTube Embed). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-88802 (Unknown MDJM Event Management). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-89050 (Unknown Quads Ads Manager for Google AdSense). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90487 (Xuxueli xxl-job). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90490 (lenve vhr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90493 (Tonec Internet Download Manager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90495 (Fengoffice Feng Office). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90497 (Fengoffice Feng Office). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90500 (lenve vhr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90502 (stilleshan ServerStatus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90505 (vvbbnn00 WARP-Clash-API). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90507 (vvbbnn00 WARP-Clash-API). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90510 (dromara orion-visor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90516 (SourceCodester School Registration and Fee System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90518 (PHPGurukul Bank Locker Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90521 (jaychouchannel Tourism-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90523 (jaychouchannel Tourism-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90526 (SourceCodester School Registration and Fee System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90543 (WWBN AVideo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90574 (itsourcecode Sales and Inventory System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90576 (GPAC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90579 (cheshire-cat-ai Cheshire Cat AI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90581 (cym1102 nginxWebUI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90584 (TooTallNate Java-WebSocket). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90594 (wxiaoqi Spring-Cloud-Platform). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90597 (itsourcecode Sales and Inventory System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90648 (WebAssembly wabt). Public exploit reference added.
DUE DATE PASSED — CVE-2026-67277 (Mikrotik RouterOS). CISA remediation deadline was September 13, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-86060 (Mikrotik RouterOS). CISA remediation deadline was September 13, 2026; still in catalog.
REJECTED — CVE-2026-63310 (nltk). Record withdrawn by the CNA.
RESCORED — Totolink A3002MU: 3 CVEs (CVE-2026-90604, CVE-2026-90605, CVE-2026-90606). CVSS rescored — before/after on each CVE page.
RESCORED — vaadin: 3 CVEs (CVE-2022-29567, CVE-2023-25499, CVE-2023-25500). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2026-23191 (Linux). CVSS 7.8 → 7 (NVD).
RESCORED — CVE-2026-56711 (VideoLAN VLC media player). CVSS 8.6 → 7.3 (NVD).
RESCORED — CVE-2026-73324 (VideoLAN VLC media player). CVSS 6.9 → 5.3 (NVD).
PATCH SHIPPED — CVE-2026-25470 (ACPT (Pro) - Custom Post Types Plugin for WordPress). Fixed in ACPT (Pro) - Custom Post Types Plugin for WordPress 2.0.52.
ENRICHED — Linux: 18 CVEs (CVE-2024-50017, CVE-2024-56545, CVE-2024-56639, CVE-2025-21651, CVE-2025-22101, CVE-2025-22103, CVE-2025-23129, CVE-2025-37833, CVE-2025-38266, CVE-2025-38591, CVE-2025-71142, CVE-2026-23137, CVE-2026-23201, CVE-2026-23447, CVE-2026-23448, CVE-2026-31420, CVE-2026-43088, CVE-2026-43288). Received CVSS/CPE analysis.
How to read these box scores · glossary
777 CVEs published. 25 box scores and 375 table rows below; the remaining 377 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 — — YES
AFFECTED Product Versions Fixed Cisco Secure Email 14.0.0-698 – —
TIMELINE Aug 19 Reserved by CNA Sep 14 Added to CISA KEV, due Sep 17 Sep 14 Published (CNA: cisco)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0160 74.4 —
AFFECTED Product Versions Fixed PentestAgent cf882dabea3ed91cef016cdd115e5426315665a2 – —
TIMELINE Sep 12 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0160 74.4 —
AFFECTED Product Versions Fixed PentestAgent cf882dabea3ed91cef016cdd115e5426315665a2 – —
TIMELINE Sep 12 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0159 74.3 —
AFFECTED Product Versions Fixed DWR-M920 1.1.7 – —
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0136 70.2 —
AFFECTED Product Versions Fixed HexStrike AI d689933ff579d839c676c82b231f8e98326c5f04 – —
TIMELINE Sep 12 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0135 69.9 —
AFFECTED Product Versions Fixed HexStrike AI d689933ff579d839c676c82b231f8e98326c5f04 – —
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0119 66.1 —
AFFECTED Product Versions Fixed FXA5000 unspecified — FXA5020 unspecified — FXA5020-[][] unspecified — FXE5000 unspecified — FXE5000-[][] unspecified — FXS5000-[][] unspecified — FXS5021 unspecified — FXE4000 unspecified — FXE4000-WP unspecified — FXS4000 unspecified — + 10 more
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0119 66.1 —
AFFECTED Product Versions Fixed SGA1000 unspecified —
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0119 66.1 —
AFFECTED Product Versions Fixed M2M Gateway Integrated Type CPS-MG341* unspecified — M2M Gateway Configurable type CPS-MGS341* unspecified — M2M Controller Integrated Type CPS-MC341 unspecified — M2M Controller Configurable type CPS-MCS341* unspecified —
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0119 66.1 —
AFFECTED Product Versions Fixed Integrated Type CPS-PC341[][]-*-9201 unspecified — Configurable type CPS-PCS341[][]-DS1-1201 unspecified —
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0109 63.4 —
AFFECTED Product Versions Fixed HackingBuddyGPT 0.1 – —
TIMELINE Sep 12 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0102 61.6 —
AFFECTED Product Versions Fixed CPS-TM341G5MB-ADSC1-931 unspecified — CPS-TM341MB-ADSC1-931 unspecified — CPS-TM341GMB-ADSC1-931 unspecified —
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0102 61.6 —
AFFECTED Product Versions Fixed CAN-2-WF unspecified — CAN-2-USB unspecified —
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0102 61.6 —
AFFECTED Product Versions Fixed SV-CPT-MC310 unspecified — SV-CPT-MC310F unspecified —
TIMELINE Aug 31 Reserved by CNA Sep 14 Published (CNA: jpcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N N 4.3 .0101 61.1 —
AFFECTED Product Versions Fixed DataEase unspecified —
TIMELINE Aug 22 Reserved by CNA Sep 14 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0080 54.4 —
AFFECTED Product Versions Fixed A3002MU Hh-B20211125.1046 – —
TIMELINE Sep 12 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N C L N N 3.5 .0077 53.5 —
AFFECTED Product Versions Fixed Nagios XI unspecified —
TIMELINE Jan 21 Reserved by CNA Sep 14 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H N N 8.6 .0066 49.6 —
AFFECTED Product Versions Fixed PRTG Network Monitor unspecified —
TIMELINE Oct 14 Reserved by CNA Sep 14 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0060 46.9 —
AFFECTED Product Versions Fixed W20E 15.11.0.61068_1546_841_CN_TDC – —
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0051 42.0 —
AFFECTED Product Versions Fixed DIR-823G 1.0.2B05_20181207 – —
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0050 41.1 —
AFFECTED Product Versions Fixed GPAC f1219cde – abi-16.23
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0050 41.1 —
AFFECTED Product Versions Fixed memcached 1.6.41 – 1.6.44
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 9.4 .0049 40.3 —
AFFECTED Product Versions Fixed Conditional Content Pro extension for Joomla 1.0.0-7.1.0 – —
TIMELINE Sep 3 Reserved by CNA Sep 14 Published (CNA: Joomla)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U H H H 6.6 .0049 40.4 —
AFFECTED Product Versions Fixed Secure Integration Server unspecified —
TIMELINE Apr 5 Reserved by CNA Sep 14 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 9.4 .0047 39.6 —
AFFECTED Product Versions Fixed DIR-878 120B05 – —
TIMELINE Sep 13 Reserved by CNA Sep 14 Published (CNA: VulDB)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-90693 | 9.4 | 39.6 | D-Link | DIR-878 | CWE-119 | D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow |
| CVE-2026-90607 | 8.6 | 39.1 | Totolink | A3002MU | CWE-119 | Totolink A3002MU boa formNewSchedule buffer overflow |
| CVE-2026-82770 | 8.7 | 38.6 | Contec Co., Ltd. | RP-WAH-SR1 | CWE-120 | Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote … |
| CVE-2026-82772 | 8.7 | 38.6 | Contec Co., Ltd. | ECE1000 | CWE-120 | Buffer overflow vulnerability exists in Contec EC1000 series. If a remote att… |
| CVE-2026-71198 | 7.0 | 37.9 | OpenStack | Glance | CWE-918 | In OpenStack Glance before 32.0.1, the location API does not validate destina… |
| CVE-2026-90691 | 5.5 | 36.2 | 0x4m4 | HexStrike AI | CWE-22 | 0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManag… |
| CVE-2026-90688 | 7.1 | 33.3 | Tenda | W20E | CWE-119 | Tenda W20E HTTP formIPMacBindAdd stack-based overflow |
| CVE-2026-90620 | 5.5 | 32.6 | 0x4m4 | HexStrike AI | CWE-287 | 0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentic… |
| CVE-2023-24034 | 3.1 | 32.0 | Nagios | Nagios XI | CWE-601 | An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3.… |
| CVE-2023-46035 | 5.9 | 29.7 | fnando | svg_optimizer | CWE-776 | The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untr… |
| CVE-2026-82787 | 8.7 | 29.3 | Contec Co., Ltd. | CPSL-08P1EN | CWE-306 | Missing authentication for critical function vulnerability exists in CPSL-08P… |
| CVE-2026-82768 | 8.6 | 28.4 | Contec Co., Ltd. | SGA1000 | CWE-23 | Path traversal vulnerability exists in SGA1000. If this vulnerability is expl… |
| CVE-2026-82793 | 8.6 | 28.4 | Contec Co., Ltd. | CAN-2-WF | CWE-434 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.… |
| CVE-2026-82780 | 8.7 | 26.8 | Contec Co., Ltd | CPS-TM341G5MB-ADSC1-931 | CWE-434 | Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM … |
| CVE-2025-26790 | 3.7 | 26.3 | WithSecure | Atlant | CWE-125 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote … |
| CVE-2023-50461 | 8.8 | 25.4 | TYPO3 | direct_mail | CWE-863 | An issue was discovered in the direct_mail (aka Direct Mail) extension throug… |
| CVE-2026-82765 | 8.6 | 24.3 | Contec Co., Ltd. | FXA5000 | CWE-23 | Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, a… |
| CVE-2026-82775 | 5.3 | 24.3 | Contec Co., Ltd. | M2M Gateway Integrated Type CPS-MG341* | CWE-548 | An exposure of information through directory listing issue exists in CONPROSY… |
| CVE-2026-88932 | 5.3 | 24.1 | multer | multer | CWE-400 | multer vulnerable to Denial of Service via orphaned disk writes on aborted up… |
| CVE-2023-46273 | 8.8 | 23.9 | extremenetworks | IQ Engine | CWE-121 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.… |
| CVE-2026-82789 | 8.7 | 23.1 | Contec | CONPROSYS HMI System(CHS) | CWE-95 | An improper neutralization of directives in dynamically evaluated code ('Eval… |
| CVE-2026-82785 | 5.3 | 22.2 | Contec Co., Ltd. | Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | CWE-121 | Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (… |
| CVE-2026-90687 | 2.1 | 21.7 | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free |
| CVE-2026-90615 | 2.1 | 19.6 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System subject1.php cross site scri… |
| CVE-2026-82782 | 5.3 | 19.0 | Contec Co., Ltd. | Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | CWE-787 | Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving … |
| CVE-2023-50462 | 5.3 | 18.8 | TYPO3 | content_consent | CWE-863 | An issue was discovered in the content_consent (aka Content Consent) extensio… |
| CVE-2026-89321 | 4.3 | 18.5 | Eclipse Foundation | Eclipse OpenVSX | CWE-409 | Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-… |
| CVE-2026-90623 | 2.9 | 18.3 | andreashappe | cochise | CWE-287 | andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certific… |
| CVE-2026-82778 | 5.3 | 18.1 | Contec Co., Ltd. | Integrated Type CPS-PC341[][]-*-9201 | CWE-548 | An exposure of information through directory listing issue exists in CONPROSY… |
| CVE-2026-85196 | 5.3 | 17.5 | regularlabs.com | Articles Anywhere (Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere exten… |
| CVE-2026-85189 | 7.5 | 16.0 | regularlabs.com | Modals (Free, Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL… |
| CVE-2026-85190 | 7.5 | 16.0 | regularlabs.com | Quick Index (Free, Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via class option i… |
| CVE-2026-85191 | 7.5 | 16.0 | regularlabs.com | Tabs & Accordions (Free, Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias opt… |
| CVE-2026-85195 | 7.5 | 16.0 | regularlabs.com | Articles Anywhere (Free, Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in… |
| CVE-2026-88852 | 7.5 | 16.0 | regularlabs.com | Snippets (Free) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in … |
| CVE-2026-88853 | 7.5 | 16.0 | regularlabs.com | Modals (Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler … |
| CVE-2026-90614 | 5.3 | 16.0 | FedML-AI | FedML | CWE-20 | FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read… |
| CVE-2023-50459 | 5.4 | 14.9 | TYPO3 | femanager | CWE-863 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3… |
| CVE-2023-50460 | 5.4 | 14.9 | TYPO3 | femanager | CWE-863 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3… |
| CVE-2026-90697 | 2.1 | 14.9 | SourceCodester | Inventory Management System | CWE-285 | SourceCodester Inventory Management System invoice.php authorization |
| CVE-2023-34854 | 6.6 | 13.6 | digitaldruid | HotelDruid | CWE-434 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup… |
| CVE-2023-22631 | 2.7 | 13.2 | Paessler | PRTG Network Monitor | CWE-88 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files… |
| CVE-2023-22632 | 2.7 | 13.2 | Paessler | PRTG Network Monitor | CWE-88 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files… |
| CVE-2023-32778 | 3.3 | 12.9 | ILIAS | ILIAS | CWE-23 | An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker ca… |
| CVE-2026-85188 | 6.9 | 12.3 | regularlabs.com | Advanced Module Manager (Free, Pro) extension for Joomla | CWE-200 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Mod… |
| CVE-2026-25832 | 3.7 | 12.3 | TrustedFirmware | Mbed TLS | CWE-669 | In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client acc… |
| CVE-2023-28148 | 7.2 | 11.2 | Paessler | PRTG Network Monitor | CWE-79 | A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520. |
| CVE-2026-82784 | 6.9 | 10.1 | Contec Co., Ltd. | Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | CWE-306 | Missing authentication for critical function vulnerability exists in Remote I… |
| CVE-2026-90700 | 2.1 | 10.0 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System pro_edit1.php sql injection |
| CVE-2026-90694 | 2.0 | 9.8 | SourceCodester | Inventory Management System | CWE-79 | SourceCodester Inventory Management System Customer Management customers_hand… |
| CVE-2026-90695 | 2.0 | 9.8 | SourceCodester | Inventory Management System | CWE-79 | SourceCodester Inventory Management System Vendor Management vendors_handler.… |
| CVE-2026-90696 | 2.0 | 9.8 | SourceCodester | Inventory Management System | CWE-79 | SourceCodester Inventory Management System Product Management products_handle… |
| CVE-2026-23793 | 3.5 | 9.7 | Samsung | Exynos 1330 firmware | CWE-787 | An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, … |
| CVE-2026-33970 | 3.5 | 9.7 | Samsung | Exynos 850 firmware | CWE-476 | An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearabl… |
| CVE-2023-37252 | 3.1 | 9.6 | MediaWiki | CheckUser | CWE-669 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39… |
| CVE-2023-37253 | 3.1 | 9.6 | MediaWiki | ProofreadPage | CWE-669 | An issue was discovered in the ProofreadPage extension for MediaWiki through … |
| CVE-2026-85125 | 5.1 | 9.1 | YAMAP INC. | YAMAP -Social Trekking GPS App | CWE-940 | The Android application "YAMAP -Social Trekking GPS App" contains an improper… |
| CVE-2026-82786 | 8.2 | 8.7 | Contec Co., Ltd. | Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | CWE-522 | Insufficiently protected credentials issue exists in Remote I/O Coupler Unit … |
| CVE-2023-51769 | 6.1 | 8.6 | Frappe | Frappe | CWE-79 | Frappe before 14.49.0 allows an XSS attack that is associated with blog pages… |
| CVE-2026-82773 | 5.1 | 8.6 | Contec Co., Ltd. | M2M Gateway Integrated Type CPS-MG341* | CWE-79 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and… |
| CVE-2026-82776 | 5.1 | 8.6 | Contec Co., Ltd. | Integrated Type CPS-PC341[][]-*-9201 | CWE-79 | Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vu… |
| CVE-2023-32803 | 7.5 | 8.1 | Amazon | ca-certificates | CWE-669 | The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Li… |
| CVE-2026-68955 | 8.4 | 7.8 | Rakuten Kobo Inc. | The installer for Rakuten Kobo Desktop Application (Windows version) | CWE-427 | The installer for Rakuten Kobo Desktop Application (Windows version) insecure… |
| CVE-2024-23176 | 5.4 | 6.7 | MediaWiki | MassMessage | CWE-79 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40… |
| CVE-2026-82769 | 4.8 | 6.4 | Contec Co., Ltd. | RP-WAH-SR1 | CWE-79 | Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this… |
| CVE-2026-82771 | 4.8 | 6.4 | Contec Co., Ltd. | ECE1000 | CWE-79 | Cross-site scripting vulnerability exists in Contec EC1000 series. If this vu… |
| CVE-2026-82767 | 4.8 | 5.6 | Contec Co., Ltd. | SGA1000 | CWE-79 | Cross-site scripting vulnerability exists in SGA1000. If this vulnerability i… |
| CVE-2026-90622 | 1.9 | 5.6 | GNU | libredwg | CWE-404 | GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference |
| CVE-2026-82788 | 5.1 | 4.9 | Contec Co., Ltd. | CPSL-08P1EN | CWE-79 | Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerabili… |
| CVE-2026-31278 | 7.7 | 4.6 | supremainc | BioStar 2 | CWE-319 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2… |
| CVE-2026-82792 | 4.8 | 4.5 | Contec Co., Ltd. | CAN-2-WF | CWE-79 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wi… |
| CVE-2026-82764 | 5.1 | 4.4 | Contec Co., Ltd. | FXA5000 | CWE-352 | Cross-site request forgery vulnerability exists in multiple Contec products. … |
| CVE-2026-82781 | 5.1 | 3.6 | Contec Co., Ltd. | Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | CWE-79 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this v… |
| CVE-2026-82795 | 5.1 | 3.6 | Contec Co., Ltd. | SV-CPT-MC310 | CWE-79 | SolarView Compact contains a cross-site scripting vulnerability in Schedule S… |
| CVE-2026-82796 | 5.1 | 3.6 | Contec Co., Ltd. | SV-CPT-MC310 | CWE-79 | SolarView Compact contains a cross-site scripting vulnerability in Image Mana… |
| CVE-2026-82763 | 4.8 | 3.5 | Contec Co., Ltd. | FXA5000 | CWE-79 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 ser… |
| CVE-2026-82790 | 4.8 | 3.5 | Contec Co., Ltd. | PC-HELPER Wireless I/O DIO-0404RY-LWF | CWE-79 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404R… |
| CVE-2023-45023 | 4.2 | 3.2 | TYPO3 | femanager | CWE-863 | The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control… |
| CVE-2026-23792 | 4.0 | 3.1 | Samsung | Exynos 1080 firmware | CWE-346 | An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exyno… |
| CVE-2026-82783 | 4.1 | 2.8 | Contec Co., Ltd. | Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | CWE-256 | Plaintext storage of a password issue exists in CONPROSYS nano Series . If th… |
| CVE-2026-90682 | 1.9 | 2.4 | Matthias-Wandel | jhead | CWE-119 | Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow |
| CVE-2025-64031 | 2.5 | 2.4 | libarchive | libarchive | CWE-122 | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the … |
| CVE-2023-24284 | 2.9 | 2.2 | Simon Tatham | Portable Puzzle Collection | CWE-120 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain … |
| CVE-2023-24285 | 2.9 | 2.2 | Simon Tatham | Portable Puzzle Collection | CWE-120 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain … |
| CVE-2023-24287 | 2.9 | 2.2 | Simon Tatham | Portable Puzzle Collection | CWE-120 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain … |
| CVE-2023-24291 | 2.9 | 2.2 | Simon Tatham | Portable Puzzle Collection | CWE-120 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain … |
| CVE-2026-90611 | 1.9 | 2.0 | n/a | GPAC | CWE-617 | GPAC MP4Box loader_xmt.c xmt_parse_element assertion |
| CVE-2026-90609 | 1.9 | 1.9 | n/a | GPAC | CWE-404 | GPAC MP4Box vrml_tools.c null pointer dereference |
| CVE-2026-90610 | 1.9 | 1.9 | n/a | GPAC | CWE-119 | GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read |
| CVE-2026-90612 | 1.9 | 1.9 | n/a | GPAC | CWE-617 | GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion |
| CVE-2026-90613 | 1.9 | 1.9 | n/a | GPAC | CWE-617 | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion |
| CVE-2026-90683 | 1.9 | 1.9 | n/a | GPAC | CWE-617 | GPAC MP4Box base_scenegraph.c gf_node_unregister assertion |
| CVE-2023-24283 | 2.9 | 1.6 | Simon Tatham | Portable Puzzle Collection | CWE-120 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain … |
| CVE-2026-90681 | 1.9 | 1.5 | Matthias-Wandel | jhead | CWE-119 | Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds |
| CVE-2026-90684 | 0.9 | 1.5 | n/a | GPAC | CWE-617 | GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion |
| CVE-2026-90685 | 0.9 | 1.5 | n/a | GPAC | CWE-617 | GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion |
| CVE-2023-24288 | 2.9 | 1.4 | Simon Tatham | Portable Puzzle Collection | CWE-190 | An issue in Portable Puzzle Collection before 20230116.5782e29 allows attacke… |
| CVE-2026-23789 | 7.8 | 1.4 | Samsung | Exynos 850 firmware | CWE-415 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Proce… |
| CVE-2026-12518 | 8.5 | 1.3 | Logitech | Logi Options+ | CWE-269 | Local privilege escalation in the Logi Options+ updater service on Windows |
| CVE-2026-33963 | 7.5 | 1.2 | Samsung | Exynos 1330 firmware | CWE-121 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13… |
| CVE-2026-16726 | 6.8 | 1.2 | panasonic | PANATERM v6 | CWE-120 | Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A… |
| CVE-2023-24286 | 2.9 | 1.1 | Simon Tatham | Portable Puzzle Collection | CWE-120 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain … |
| CVE-2026-23788 | 4.2 | 1.0 | Samsung | Exynos 1280 firmware | CWE-122 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,… |
| CVE-2026-33964 | 6.4 | 0.8 | Samsung | Exynos 1580 firmware | CWE-822 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and… |
| CVE-2026-33957 | 4.2 | 0.7 | Samsung | Exynos 1580 firmware | CWE-787 | An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1… |
| CVE-2026-33962 | 2.8 | 0.7 | Samsung | Exynos 850 firmware | CWE-125 | An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280… |
| CVE-2026-33966 | 2.8 | 0.7 | Samsung | Exynos 1330 firmware | CWE-215 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13… |
| CVE-2026-23787 | 4.2 | 0.6 | Samsung | Exynos 1280 firmware | CWE-416 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,… |
| CVE-2026-23790 | 4.2 | 0.6 | Samsung | Exynos 1280 firmware | CWE-415 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,… |
| CVE-2026-23791 | 4.2 | 0.6 | Samsung | Exynos 1280 firmware | CWE-787 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,… |
| CVE-2023-37366 | 2.8 | 0.5 | Samsung | Exynos 850 firmware | CWE-835 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Proces… |
| CVE-2026-33956 | 2.8 | 0.6 | Samsung | Exynos 1330 firmware | CWE-787 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13… |
| CVE-2026-33960 | 2.8 | 0.6 | Samsung | Exynos 1330 firmware | CWE-787 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Ex… |
| CVE-2026-33967 | 2.8 | 0.6 | Samsung | Exynos 1330 firmware | CWE-787 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13… |
| CVE-2026-33968 | 2.8 | 0.6 | Samsung | Exynos 1330 firmware | CWE-125 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 13… |
| CVE-2026-23786 | 2.8 | 0.2 | Samsung | Exynos 1280 firmware | CWE-367 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200,… |
| CVE-2026-82434 | 10.0 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-522 | Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeepe… |
| CVE-2026-16338 | 9.9 | — | IBM | DataStage on Cloud Pak for Data | CWE-73 | DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc… |
| CVE-2026-20353 | 9.8 | — | Cisco | Cisco Secure Email | CWE-664 | Cisco Secure Email Gateway Security Hardening Release |
| CVE-2026-54333 | 9.8 | — | theopolis | uefi-firmware-parser | CWE-787 | UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable |
| CVE-2026-54334 | 9.8 | — | theopolis | uefi-firmware-parser | CWE-787 | UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen` |
| CVE-2026-55209 | 9.8 | — | equinor | resdata | CWE-120 | resdata insufficiently validates untrusted GRDECL files |
| CVE-2026-57123 | 9.8 | — | MervinPraison | praisonaiagents | CWE-306 | PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Orig… |
| CVE-2026-57124 | 9.8 | — | MervinPraison | PraisonAI | CWE-78 | PraisonAI UI MCP connect endpoint allows unauthenticated local command execution |
| CVE-2026-57125 | 9.8 | — | MervinPraison | PraisonAI | CWE-306 | PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass |
| CVE-2026-57127 | 9.8 | — | MervinPraison | PraisonAI | CWE-306 | praisonai: recipe serve auth middleware silently disables itself when no secr… |
| CVE-2026-57131 | 9.8 | — | MervinPraison | PraisonAI | CWE-94 | praisonai: Jobs API exposes agent-execution endpoints with no authentication |
| CVE-2026-59178 | 9.8 | — | esphome | device-builder | CWE-306 | ESPHome Device Builder: Renamed auth env vars silently disable dashboard auth… |
| CVE-2026-65414 | 9.8 | — | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-73370 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-863 | Apache Syncope: Cross-Realm boundaries reconciliation bypass |
| CVE-2026-73470 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-269 | Apache Syncope: Delegating users can grant unowned Roles |
| CVE-2026-73579 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-863 | Apache Syncope: Non-recursive Any search could skip Realms restrictions |
| CVE-2026-73668 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-863 | Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configu… |
| CVE-2026-75030 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-862 | Apache Syncope: Incomplete authorization checks for Group members deprovisioning |
| CVE-2026-76440 | 9.8 | — | Cisco | Cisco Secure Email | CWE-23 | Cisco Secure Email Gateway Security Hardening Release |
| CVE-2026-76441 | 9.8 | — | Cisco | Cisco Secure Email and Web Manager | CWE-284 | Cisco Secure Email Gateway Security Hardening Release |
| CVE-2026-76443 | 9.8 | — | Cisco | Cisco Secure Email | CWE-707 | Cisco Secure Email Gateway Security Hardening Release |
| CVE-2026-77051 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-89 | Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit … |
| CVE-2026-77181 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-863 | Apache Syncope: ClientApp update entitlement not effective |
| CVE-2026-78330 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-266 | Apache Syncope: Privilege escalation for admin user via JWT authentication |
| CVE-2026-82232 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-89 | Apache Syncope: SQL injection via sort parameter in Task search |
| CVE-2026-82431 | 9.8 | — | Apache Software Foundation | Apache Storm Client | CWE-863 | Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Wi… |
| CVE-2026-82435 | 9.8 | — | Apache Software Foundation | Apache Storm Worker | CWE-789 | Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker M… |
| CVE-2026-82439 | 9.8 | — | Apache Software Foundation | Apache Storm DRPC | CWE-770 | Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC |
| CVE-2026-86460 | 9.8 | — | Apache Software Foundation | Apache Syncope | CWE-89 | Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence |
| CVE-2026-90898 | 9.8 | — | maximhq | Bifrost | CWE-284 | Bifrost unauthenticated remote code execution via MCP stdio client registration |
| CVE-2026-12944 | 9.6 | — | IBM | Langflow OSS | CWE-918 | Incomplete Security Scanner Blocklist Enables Network-Based Code Execution |
| CVE-2026-21391 | 9.5 | — | Ping Identity | PingAM | CWE-290 | Improper Claim Validation in PingAM OIDC Provider |
| CVE-2026-90937 | 9.4 | — | froxlor | froxlor | CWE-93 | froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redir… |
| CVE-2026-67399 | 9.3 | — | WebPros | WHMCS | CWE-502 | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 befor… |
| CVE-2026-90919 | 9.3 | — | ModelTC | LightLLM | CWE-502 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Serve… |
| CVE-2026-90942 | 9.3 | — | casdoor | casdoor | CWE-863 | Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints |
| CVE-2026-90943 | 9.3 | — | parallax | filament-comments | CWE-79 | parallax filament-comments through 3.0.0 Stored XSS via Comment Body |
| CVE-2026-90945 | 9.3 | — | crawlab-team | crawlab | CWE-321 | Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret |
| CVE-2026-90961 | 9.3 | — | MISP | MISP | CWE-20 | MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Cr… |
| CVE-2026-12258 | 9.2 | — | Hiperdino | REST API | CWE-284 | Inadequate access control in the Hiperdino REST API |
| CVE-2026-57578 | 9.2 | — | riganti | dotvvm | CWE-862 | DotVVM: Missing authorization in AuthorizeActionFilter |
| CVE-2026-50006 | 9.1 | — | julien040 | anyquery | CWE-22 | Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Executio… |
| CVE-2026-53713 | 9.1 | — | envoyproxy | gateway | CWE-20 | Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyEx… |
| CVE-2026-57145 | 9.1 | — | MervinPraison | PraisonAI | CWE-22 | PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Valida… |
| CVE-2026-61534 | 9.1 | — | confetti | yayson | CWE-1321 | Yayson: Prototype pollution in the Store/LegacyStore deserialization |
| CVE-2026-78299 | 9.1 | — | Eclipse Foundation | Eclipse Embedded CDT (C/C++ Development Tools) | CWE-22 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extract… |
| CVE-2026-82441 | 9.1 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-20 | Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service… |
| CVE-2026-87785 | 9.1 | — | Apache Software Foundation | Apache Syncope | CWE-290 | Apache Syncope: JWT subject spoofing |
| CVE-2026-87802 | 9.1 | — | Apache Software Foundation | Apache Syncope | CWE-347 | Apache Syncope: SRA OAuth2 JWT signature verification bypass |
| CVE-2026-13293 | 8.8 | — | IBM | MQ | CWE-502 | IBM MQ Java messaging is vulnerable to remote code execution |
| CVE-2026-16428 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-94 | DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc… |
| CVE-2026-16466 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc… |
| CVE-2026-16673 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | — | DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc… |
| CVE-2026-43692 | 8.8 | — | Apple | macOS | CWE-20 | A validation issue was addressed with improved input sanitization. This issue… |
| CVE-2026-55416 | 8.8 | — | pimcore | pimcore | CWE-89 | Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concaten… |
| CVE-2026-61701 | 8.8 | — | cesargb | laravel-magiclink | CWE-502 | Laravel MagicLink: Insecure Deserialization of MagicLink Actions Leads to Rem… |
| CVE-2026-72524 | 8.8 | — | Apache Software Foundation | Apache Doris | CWE-863 | Apache Doris: Authorization bypass allowing a low-privilege user to read/writ… |
| CVE-2026-82428 | 8.8 | — | Apache Software Foundation | Apache Storm Client | CWE-22 | Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable… |
| CVE-2026-89023 | 8.8 | — | ThemeAtelier | Domain For Sale | CWE-862 | ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API |
| CVE-2026-90938 | 8.8 | — | langbot-app | LangBot | CWE-306 | LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket |
| CVE-2026-90944 | 8.8 | — | krayin | laravel-crm | CWE-306 | Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse |
| CVE-2026-49250 | 8.7 | — | edmundhung | conform | CWE-407 | Conform: parseSubmission vulnerable to CPU exhaustion when parsing many uniqu… |
| CVE-2026-68489 | 8.7 | — | WebPros | Plesk extension "Ruby" | CWE-96 | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js To… |
| CVE-2026-82028 | 8.7 | — | absmach | magistrala | CWE-89 | Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API |
| CVE-2026-84445 | 8.7 | — | grpc | grpc-go | CWE-129 | gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `H… |
| CVE-2026-89180 | 8.7 | — | Thinking Software Technology | EFence | CWE-89 | Thinking Software Technology|EFence - SQL Injection |
| CVE-2026-90934 | 8.7 | — | espocrm | espocrm | CWE-863 | EspoCRM before 10.0.4 Field-level Security Bypass via Attendees |
| CVE-2026-90946 | 8.7 | — | AsyncFuncAI | deepwiki-open | CWE-73 | DeepWiki-Open through commit d92819a Arbitrary File Read via /ws/chat WebSocket |
| CVE-2026-91080 | 8.7 | — | adnanh | webhook | CWE-770 | webhook through 2.8.3 Memory Exhaustion via Oversized Request Body |
| CVE-2026-91144 | 8.7 | — | zfile-dev | zfile | CWE-639 | ZFile through 5.0.5 Share Entry Filter Bypass via Download Endpoint |
| CVE-2026-91200 | 8.7 | — | devspace | devspace | CWE-22 | DevSpace through 6.3.21 Path Traversal via tar extraction |
| CVE-2026-7848 | 8.6 | — | Alior Bank | raty | CWE-89 | SQL Injection in Alior Bank raty PrestaShop module |
| CVE-2026-15600 | 8.6 | — | Alior Bank | raty | CWE-89 | SQL Injection in Alior Bank raty PrestaShop module |
| CVE-2026-54628 | 8.6 | — | julien040 | anyquery | CWE-284 | Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual … |
| CVE-2026-57122 | 8.6 | — | MervinPraison | PraisonAI | CWE-345 | PraisonAI: Webhook signature verification skipped (fail-open) when secret uns… |
| CVE-2026-78375 | 8.6 | — | joomshaper.com | SP Page Builder (Free and Pro) extension for Joomla | CWE-89 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in… |
| CVE-2026-86830 | 8.6 | — | AWS | iam-identity-center-team | CWE-266 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM)… |
| CVE-2026-90932 | 8.6 | — | laradashboard | laradashboard | CWE-73 | LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE |
| CVE-2026-20773 | 8.5 | — | Ping Identity | PingFederate | CWE-863 | Improper Authorization in PingFederate Administrative Expression Evaluation E… |
| CVE-2026-55072 | 8.5 | — | pimcore | pimcore | CWE-20 | Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection vi… |
| CVE-2026-57126 | 8.5 | — | MervinPraison | PraisonAI | CWE-918 | praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS |
| CVE-2026-81301 | 8.5 | — | Ekia | File Manager | CWE-926 | Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file a… |
| CVE-2026-90702 | 8.5 | — | D-Link | DWR-M921 | CWE-77 | D-Link DWR-M921 formDiskFormat system os command injection |
| CVE-2026-90703 | 8.5 | — | D-Link | DWR-M921 | CWE-77 | D-Link DWR-M921 formDiskCreateShare system os command injection |
| CVE-2024-58383 | 8.4 | — | froxlor | froxlor | CWE-732 | Froxlor before 2.2.0 Insecure File Permissions mysql.conf |
| CVE-2026-54447 | 8.4 | — | cyberjunky | python-garminconnect | CWE-732 | garminconnect: Insecure Permission Assignment for Garmin OAuth Token Store |
| CVE-2026-82049 | 8.4 | — | Python Software Foundation | CPython | CWE-59 | tarfile extraction filters allow file modification and content disclosure via… |
| CVE-2026-86836 | 8.4 | — | Eclipse Foundation | Eclipse Ankaios | CWE-276 | In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload f… |
| CVE-2026-90895 | 8.4 | — | MISP | MISP | CWE-150 | MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Te… |
| CVE-2026-55451 | 8.3 | — | locize | gettext-converter | CWE-1321 | gettext-converter: Prototype pollution in js2i18next() via crafted translatio… |
| CVE-2026-17467 | 8.2 | — | IBM | Cloud Pak for Data System (Yosemite 1.0) | CWE-327 | Vulnerabilities exists in IBM Cloud Pak for Data System |
| CVE-2026-34151 | 8.2 | — | xwiki | xwiki-platform | CWE-24 | XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+ |
| CVE-2026-57132 | 8.2 | — | MervinPraison | PraisonAI | CWE-287 | PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally … |
| CVE-2026-57577 | 8.2 | — | riganti | dotvvm | CWE-1333 | DotVVM: ReDOS in routing |
| CVE-2026-65838 | 8.2 | — | zalando | skipper | CWE-754 | Skipper: an oversized declared-`Content-Length` body still hands OPA an empty… |
| CVE-2026-85921 | 8.2 | — | Microsoft | Windows 11 version 26H1 | CWE-415 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
| CVE-2026-90896 | 8.2 | — | MarcosCamara01 | Ecommerce Template | CWE-306 | Missing authentication in Ecommerce Template checkout session endpoint allows… |
| CVE-2026-16335 | 8.1 | — | IBM | DataStage on Cloud Pak for Data | CWE-22 | DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc… |
| CVE-2026-25687 | 8.1 | — | Zscaler | Client Connector | CWE-366 | ZCC race condition in ZPA tunnel handler |
| CVE-2026-54178 | 8.1 | — | Laravel-Backpack | CRUD | CWE-22 | backpack/crud: Arbitrary file deletion via attacker-controlled clear_<attr>[]… |
| CVE-2026-54182 | 8.1 | — | Laravel-Backpack | CRUD | CWE-20 | backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-co… |
| CVE-2026-57130 | 8.1 | — | MervinPraison | praisonaiagents | CWE-20 | PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters |
| CVE-2026-59569 | 8.1 | — | Zscaler | Client Connector | CWE-20 | Android ZCC VPN API method privilege escalation |
| CVE-2026-82432 | 8.1 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-863 | Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configurati… |
| CVE-2026-82438 | 8.1 | — | Apache Software Foundation | Apache Storm Webapp | CWE-346 | Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Ori… |
| CVE-2026-17133 | 7.8 | — | IBM | App Connect Enterprise | CWE-78 | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution … |
| CVE-2026-17156 | 7.8 | — | IBM | App Connect Enterprise | CWE-502 | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution … |
| CVE-2026-17416 | 7.8 | — | IBM | App Connect Enterprise | CWE-502 | IBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution … |
| CVE-2026-19624 | 7.8 | — | — | NetworkManager-l2tp | CWE-88 | NetworkManager-l2tp: local privilege escalation via ipsec.conf injection |
| CVE-2026-43689 | 7.8 | — | Apple | iOS and iPadOS | CWE-862 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-43691 | 7.8 | — | Apple | macOS | CWE-22 | A path handling issue was addressed with improved validation. This issue is f… |
| CVE-2026-43783 | 7.8 | — | Apple | macOS | CWE-362 | A race condition was addressed with improved locking. This issue is fixed in … |
| CVE-2026-43786 | 7.8 | — | Apple | macOS | CWE-280 | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-64701 | 7.8 | — | Apple | macOS | CWE-280 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-64712 | 7.8 | — | Apple | macOS | CWE-284 | This issue was addressed with improved checks. This issue is fixed in macOS G… |
| CVE-2026-65362 | 7.8 | — | Apple | macOS | CWE-284 | This issue was addressed with improved checks. This issue is fixed in macOS G… |
| CVE-2026-82427 | 7.8 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-22 | Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Bl… |
| CVE-2026-82429 | 7.8 | — | Apache Software Foundation | Apache Storm Worker Launcher | CWE-367 | Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-o… |
| CVE-2026-82430 | 7.8 | — | Apache Software Foundation | Apache Storm Worker Launcher | CWE-367 | Apache Storm Worker Launcher: Local Privilege Escalation to Root via Containe… |
| CVE-2026-84505 | 7.8 | — | Apple | macOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-84568 | 7.8 | — | Apple | macOS | CWE-22 | A path traversal issue was addressed with improved path validation. This issu… |
| CVE-2026-84631 | 7.8 | — | Apple | macOS | CWE-280 | This issue was addressed with additional entitlement checks. This issue is fi… |
| CVE-2026-85892 | 7.8 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-362 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2026-86917 | 7.8 | — | Apple | macOS | CWE-280 | A permissions issue was addressed with additional restrictions. This issue is… |
| CVE-2026-90894 | 7.8 | — | Parallels | Parallels Desktop for Mac | CWE-78 | Parallels Desktop local privilege escalation via appliance extract argument i… |
| CVE-2026-90947 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-787 | Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset… |
| CVE-2026-90948 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-787 | Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in … |
| CVE-2026-90949 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 6 | CWE-787 | Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel… |
| CVE-2026-16432 | 7.7 | — | IBM | DataStage on Cloud Pak for Data | CWE-611 | DataStage on Cloud Pak for Data has several vulnerabilities due to open sourc… |
| CVE-2026-19499 | 7.7 | — | The GNU C Library | glibc | CWE-122 | Buffer overflow in strfmon and strfmon_l right-justification padding |
| CVE-2026-47701 | 7.7 | — | open-telemetry | opentelemetry-operator | CWE-200 | OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local … |
| CVE-2026-54155 | 7.7 | — | node-opcua | node-opcua | CWE-347 | node-opcua: Missing nonce verification in UserNameIdentityToken authentication |
| CVE-2026-55253 | 7.7 | — | langchain-ai | langchain-mongodb | CWE-943 | LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to… |
| CVE-2026-73496 | 7.7 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Arbitrary server-side file read via attachment upload |
| CVE-2026-54087 | 7.6 | — | EasyCorp | EasyAdminBundle | CWE-79 | EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline… |
| CVE-2026-54175 | 7.6 | — | Laravel-Backpack | CRUD | CWE-620 | backpack/crud: Unverified password change in MyAccountController via mass ass… |
| CVE-2026-54180 | 7.6 | — | Laravel-Backpack | CRUD | CWE-639 | backpack/crud: CRUD panel query scopes are not enforced on Update, Delete, an… |
| CVE-2026-90930 | 7.6 | — | filebrowser | filebrowser | CWE-59 | File Browser through 2.63.23 Path Traversal via Symlink Alias |
| CVE-2026-15955 | 7.5 | — | IBM | Db2 | CWE-22 | IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to pe… |
| CVE-2026-19290 | 7.5 | — | IBM | Sterling File Gateway | CWE-284 | IBM Sterling File Gateway is Vulnerable to Improper Access Control |
| CVE-2026-28960 | 7.5 | — | Apple | iOS and iPadOS | CWE-20 | A denial-of-service issue was addressed with improved validation. This issue … |
| CVE-2026-50270 | 7.5 | — | DataDog | dd-trace-java | CWE-770 | dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS |
| CVE-2026-50276 | 7.5 | — | DataDog | dd-trace-rb | CWE-770 | dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS |
| CVE-2026-53659 | 7.5 | — | http4k | http4k | CWE-409 | http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilter… |
| CVE-2026-53752 | 7.5 | — | plutext | docx4j | CWE-674 | docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of … |
| CVE-2026-54156 | 7.5 | — | node-opcua | node-opcua | CWE-770 | node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS |
| CVE-2026-54567 | 7.5 | — | jugmac00 | flask-reuploaded | CWE-178 | Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in nam… |
| CVE-2026-54629 | 7.5 | — | julien040 | anyquery | CWE-22 | Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules… |
| CVE-2026-54632 | 7.5 | — | sipsorcery-org | sipsorcery | CWE-20 | SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate… |
| CVE-2026-55091 | 7.5 | — | joaonuno | flat-to-nested-js | CWE-915 | flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__… |
| CVE-2026-57119 | 7.5 | — | MervinPraison | PraisonAI | CWE-22 | PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jo… |
| CVE-2026-57129 | 7.5 | — | MervinPraison | praisonaiagents | CWE-22 | PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal |
| CVE-2026-57579 | 7.5 | — | AlchemyCMS | alchemy_cms | CWE-862 | Alchemy: Unauthenticated nested page API leaks restricted & unpublished content |
| CVE-2026-59570 | 7.5 | — | Zscaler | Client Connector | CWE-20 | Android ZCC denial of service |
| CVE-2026-59960 | 7.5 | — | argos-ci | argos-javascript | CWE-78 | Argos JavaScript: CI Branch Name OS Command Injection in @argos-ci/core |
| CVE-2026-65364 | 7.5 | — | Apple | macOS | CWE-125 | An out-of-bounds read was addressed with improved bounds checking. This issue… |
| CVE-2026-73178 | 7.5 | — | Apache Software Foundation | Apache Syncope | CWE-200 | Apache Syncope: JWT Access Token takeover |
| CVE-2026-73236 | 7.5 | — | Apache Software Foundation | Apache Syncope | CWE-863 | Apache Syncope: Cross-Realm authorization bypass in delegated administration |
| CVE-2026-76442 | 7.5 | — | Cisco | Cisco Secure Email | CWE-1284 | Cisco Secure Email Gateway Security Hardening Release |
| CVE-2026-78336 | 7.5 | — | Apache Software Foundation | Apache Syncope | CWE-201 | Apache Syncope: OIDCC4UI provider list discloses client secrets to any authen… |
| CVE-2026-84553 | 7.5 | — | Apple | macOS | CWE-400 | A resource exhaustion issue was addressed with improved input validation. Thi… |
| CVE-2026-87779 | 7.5 | — | Apache Software Foundation | Apache Syncope | CWE-532 | Apache Syncope: AES Secret Key disclosure via log output |
| CVE-2026-53714 | 7.4 | — | envoyproxy | gateway | CWE-306 | Envoy Gateway: xDS Control Plane Information Disclosure when Envoy Gateway op… |
| CVE-2026-70658 | 7.4 | — | pay-rails | pay | CWE-208 | pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook si… |
| CVE-2026-73494 | 7.4 | — | http4s | blaze | CWE-444 | blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire pa… |
| CVE-2026-18116 | 7.3 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 8.3.0 to 9.5.2 is vulnerable to Stored XSS in Calendar Event Nam… |
| CVE-2026-18117 | 7.3 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Custom Page Alias … |
| CVE-2026-47253 | 7.3 | — | julien040 | anyquery | CWE-22 | Anyquery: Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory D… |
| CVE-2026-56839 | 7.3 | — | MervinPraison | PraisonAI | CWE-22 | PraisonAI Code agent tools fail open without a workspace boundary |
| CVE-2026-73195 | 7.3 | — | Apache Software Foundation | Apache Syncope | CWE-116 | Apache Syncope: CSV export spreadsheet formula injection |
| CVE-2026-81900 | 7.3 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS before 9.5.3 is vulnerable to Stored XSS in the YouTube block (v… |
| CVE-2026-81901 | 7.2 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.2.0 to 9.5.2 is vulnerable to stored XSS due to missing author… |
| CVE-2026-90929 | 7.2 | — | filebrowser | filebrowser | CWE-863 | File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup |
| CVE-2026-8821 | 7.1 | — | Mattermost | Mattermost | CWE-862 | Playbooks run owner channel membership permission bypass |
| CVE-2026-12756 | 7.1 | — | IBM | Business Automation Workflow containers and traditional | CWE-611 | Multiple secuirty vulnerabilies addressed with IBM Business Automation Workfl… |
| CVE-2026-13107 | 7.1 | — | IBM | Business Automation Workflow containers and traditional | CWE-611 | Multiple secuirty vulnerabilies addressed with IBM Business Automation Workfl… |
| CVE-2026-13275 | 7.1 | — | IBM | MQ | CWE-611 | IBM MQ Managed File Transfer is vulnerable to XML external entity injection |
| CVE-2026-13285 | 7.1 | — | IBM | MQ | CWE-611 | IBM MQ Managed File Transfer is vulnerable to XML external entity injection |
| CVE-2026-13287 | 7.1 | — | IBM | MQ | CWE-611 | IBM MQ Managed File Transfer is vulnerable to XML external entity injection |
| CVE-2026-19816 | 7.1 | — | — | PackageKit | CWE-863 | PackageKit: dnf5 backend ignores SIMULATE on RepoRemove |
| CVE-2026-77884 | 7.1 | — | Brain Trust | Gallery - Private Photo Vault | CWE-552 | Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP fil… |
| CVE-2026-81902 | 7.1 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to CSRF on Orphan Block Cleanup |
| CVE-2026-82035 | 7.1 | — | PyMuPDF | PyMuPDF | CWE-22 | PyMuPDF 1.28.2 Path Traversal via extract_objects() Font Branch |
| CVE-2026-90927 | 7.1 | — | filebrowser | filebrowser | CWE-400 | filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message |
| CVE-2026-90928 | 7.1 | — | filebrowser | filebrowser | CWE-400 | File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint |
| CVE-2026-90933 | 7.1 | — | laradashboard | laradashboard | CWE-862 | laradashboard through 1.2.2 Missing Authorization via License API |
| CVE-2026-90939 | 7.1 | — | 201206030 | novel-plus | CWE-862 | novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list En… |
| CVE-2026-91145 | 7.1 | — | Activiti | Activiti | CWE-917 | Activiti through 7.1.0.M6 Expression Injection via Mail Task |
| CVE-2026-91197 | 7.1 | — | flowable | flowable-engine | CWE-611 | Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory |
| CVE-2026-18119 | 7.0 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via unsanitized inline b… |
| CVE-2026-81564 | 7.0 | — | joomshaper.com | SP Page Builder (Free and Pro) extension for Joomla | CWE-22 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Re… |
| CVE-2026-81903 | 7.0 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Stored XSS via Page Container icon |
| CVE-2026-54150 | 6.9 | — | muxinc | next-video | CWE-22 | next-video: Unauthenticated arbitrary file read via /api/video request handler |
| CVE-2026-54559 | 6.9 | — | cmusphinx | pocketsphinx | CWE-119 | PocketSphinx: Buffer overflows in language and acoustic model loading code |
| CVE-2026-55795 | 6.9 | — | craftcms | commerce | CWE-307 | Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass |
| CVE-2026-79700 | 6.9 | — | joomshaper.com | SP Page Builder (Pro) extension for Joomla | CWE-807 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Reques… |
| CVE-2026-79701 | 6.9 | — | joomshaper.com | SP Page Builder (Pro) extension for Joomla | CWE-807 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module … |
| CVE-2026-81565 | 6.9 | — | joomshaper.com | SP Page Builder (Free and Pro) extension for Joomla | CWE-22 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Up… |
| CVE-2026-89021 | 6.9 | — | MikroTik | RouterOS | CWE-22 | MikroTik RouterOS Path Traversal via Container OCI/tar Image Extraction |
| CVE-2026-90707 | 6.9 | — | n/a | Open5GS | CWE-119 | Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discov… |
| CVE-2026-90809 | 6.9 | — | HKUDS | nanobot | CWE-74 | HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection |
| CVE-2026-90819 | 6.9 | — | a2aproject | a2a-java | CWE-93 | a2aproject a2a-java Authorization Header Construction BasePushNotificationSen… |
| CVE-2026-90840 | 6.9 | — | PHPGurukul | Blood Donor Management System | CWE-287 | PHPGurukul Blood Donor Management System Admin Controllers Dashboard.php __co… |
| CVE-2026-90841 | 6.9 | — | PHPGurukul | Blood Donor Management System | CWE-89 | PHPGurukul Blood Donor Management System Report Endpoint Report.php sql injec… |
| CVE-2026-90940 | 6.9 | — | 201206030 | novel-plus | CWE-1392 | novel-plus through 5.3.3 Default Cache Management Password in the Front Portal |
| CVE-2026-91081 | 6.9 | — | suitenumerique | docs | CWE-918 | Docs through 5.6.1 SSRF via Unauthenticated cors-proxy Endpoint |
| CVE-2026-91143 | 6.9 | — | snail007 | goproxy | CWE-288 | goproxy through 15.3 Authentication Bypass via CONNECT |
| CVE-2026-91198 | 6.9 | — | growthbook | growthbook | CWE-201 | GrowthBook through 5.0.1 Information Disclosure via Public Endpoints |
| CVE-2025-24890 | 6.8 | — | GitoxideLabs | gitoxide | CWE-283 | gix-sec safe.directory protections absent for elevated administrators |
| CVE-2026-12985 | 6.8 | — | Mattermost | Mattermost | CWE-601 | Mattermost DCR redirect URI allowlist bypass via improper URL component valid… |
| CVE-2026-13265 | 6.8 | — | IBM | MQ | CWE-611 | IBM MQ Managed File Transfer REST API is vulnerable to XML external entity in… |
| CVE-2026-14986 | 6.8 | — | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transac… |
| CVE-2026-16147 | 6.8 | — | zephyrproject | zephyr | CWE-416 | it82xx2 USB device controller submits incomplete OUT transfer buffers, causin… |
| CVE-2026-53495 | 6.8 | — | containerd | containerd | CWE-400 | containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service |
| CVE-2026-55837 | 6.8 | — | dbt-labs | dbt-mcp | CWE-200 | dbt-mcp: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens |
| CVE-2026-90890 | 6.8 | — | ASRock | ASRock Polychrome SYNC/RGB for MB | CWE-822 | ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Derefe… |
| CVE-2026-90891 | 6.8 | — | ASRock | ASRock Polychrome SYNC/RGB for MB | CWE-1256 | ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control |
| CVE-2026-53708 | 6.6 | — | IBM | mcp-context-forge | CWE-350 | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admi… |
| CVE-2026-54177 | 6.6 | — | Laravel-Backpack | CRUD | CWE-434 | backpack/crud: HasUploadFields keeps the attacker-supplied file extension — p… |
| CVE-2026-5132 | 6.5 | — | Mattermost | Mattermost | CWE-409 | Unbounded zlib decompression in Calls SDP WebSocket messages |
| CVE-2026-9812 | 6.5 | — | Mattermost | Mattermost | CWE-639 | Missing property field ownership validation in Playbooks run property update … |
| CVE-2026-12759 | 6.5 | — | IBM | Cloud Pak for Business Automation | CWE-400 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-12765 | 6.5 | — | IBM | Langflow OSS | CWE-918 | Langflow OSS is affected by server-side request forgery due to missing URL va… |
| CVE-2026-12767 | 6.5 | — | IBM | Langflow OSS | CWE-918 | Langflow is vulnerable to server-side request forgery due to missing egress v… |
| CVE-2026-15396 | 6.5 | — | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-15412 | 6.5 | — | IBM | WebSphere Application Server | CWE-601 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-15634 | 6.5 | — | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-15814 | 6.5 | — | Mattermost | Mattermost | CWE-409 | Uploading a crafted image causes excessive memory allocation in the Mattermos… |
| CVE-2026-15893 | 6.5 | — | zephyrproject | zephyr | CWE-617 | Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advert… |
| CVE-2026-16187 | 6.5 | — | IBM | WebSphere Application Server | CWE-862 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-16702 | 6.5 | — | IBM | Db2 | CWE-476 | IBM® Db2® federated server could allow a remote authenticated attacker to cau… |
| CVE-2026-17463 | 6.5 | — | IBM | Db2 | CWE-400 | IBM® Db2® could allow a remote authenticated attacker to cause a denial of se… |
| CVE-2026-50157 | 6.5 | — | auth0 | symfony | CWE-598 | Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony… |
| CVE-2026-53716 | 6.5 | — | envoyproxy | gateway | CWE-789 | Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit |
| CVE-2026-53717 | 6.5 | — | envoyproxy | gateway | CWE-789 | Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untru… |
| CVE-2026-53719 | 6.5 | — | envoyproxy | gateway | CWE-476 | Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without s… |
| CVE-2026-54176 | 6.5 | — | Laravel-Backpack | CRUD | CWE-287 | backpack/crud: MyAccountController allows changing the login email without a … |
| CVE-2026-54723 | 6.5 | — | devpi | devpi | CWE-304 | devpi: Database contents leak |
| CVE-2026-57115 | 6.5 | — | MervinPraison | PraisonAI | CWE-918 | PraisonAI: SpiderTools redirect-target SSRF protection bypass |
| CVE-2026-57120 | 6.5 | — | MervinPraison | praisonaiagents | CWE-693 | PraisonAI: execute_code sandbox bypass: str.format C-level attribute access r… |
| CVE-2026-57570 | 6.5 | — | Laravel-Backpack | CRUD | CWE-862 | backpack/crud: HasMany/MorphMany relation fields allow cross-tenant record re… |
| CVE-2026-68570 | 6.5 | — | Apache Software Foundation | Apache Doris | CWE-863 | Apache Doris: Authorization bypass leading to unauthorized data access |
| CVE-2026-73497 | 6.5 | — | sooperset | mcp-atlassian | CWE-918 | MCP Atlassian is a Model Context Protocol (MCP): DNS-rebinding TOCTOU bypass … |
| CVE-2026-77147 | 6.5 | — | Apache Software Foundation | Apache Syncope | CWE-94 | Apache Syncope: Groovy Sandbox escape for empty CommandArgs |
| CVE-2026-82426 | 6.5 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-22 | Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded J… |
| CVE-2026-82433 | 6.5 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-522 | Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configu… |
| CVE-2026-84179 | 6.5 | — | Apache Software Foundation | Apache Storm Nimbus | CWE-200 | Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon … |
| CVE-2026-84538 | 6.5 | — | Apple | macOS | CWE-20 | A denial-of-service issue was addressed with improved input validation. This … |
| CVE-2026-86879 | 6.5 | — | Apple | iOS and iPadOS | CWE-20 | A denial-of-service issue was addressed with improved input validation. This … |
| CVE-2026-91181 | 6.5 | — | Mattermost | Mattermost | CWE-863 | Data Retention Teams Endpoint Leaks Private Team Invite ID |
| CVE-2026-4103 | 6.4 | — | WSO2 | WSO2 API Control Plane | CWE-79 | Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Po… |
| CVE-2026-16185 | 6.4 | — | IBM | WebSphere Application Server | CWE-862 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-53718 | 6.4 | — | envoyproxy | gateway | CWE-862 | Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass |
| CVE-2026-14275 | 6.3 | — | IBM | i Access Family | CWE-78 | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-14276 | 6.3 | — | IBM | i Access Family | CWE-78 | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-14277 | 6.3 | — | IBM | i Access Family | CWE-78 | IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities |
| CVE-2026-54452 | 6.3 | — | doyensec | safeurl | CWE-918 | safeurl: Missing IPv6 CIDR Ranges in Blocklist |
| CVE-2026-88819 | 6.3 | — | Eclipse Foundation | Eclipse Data Plane Core | CWE-290 | In Siglet current and past versions the refresh token handler do not enforce … |
| CVE-2026-90842 | 6.3 | — | PHPGurukul | Blood Donor Management System | CWE-313 | PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in… |
Results continue: ranks 401–777.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-14 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.