boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 15, 2026 · all times UTC← 2026-09-14 · archive

Security Box Score — September 15, 2026

1426 CVEs published, led by Oracle Corporation (634).

1426 CVEs published September 15, 2026: 169 critical, 790 high, 274 medium, 60 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 133 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 1026 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published791742837——
KEV catalog size1710

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2667 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux6314722491223071211230.17.8.0016-630 ▼
microsoft9812880189198369216289301.07.8.0044+539 ▲
google4992665323101411571227980.37.5.0025+450 ▲
red hat927184329734038200.06.6.0027-50 ▼
apple2455626012522878881.46.5.0019+243 ▲
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1240721111000.07.6.0037+7 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco181022947260581514.77.5.0041-13 ▼
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0047+8 ▲
ivanti102410122025520.88.8.0146+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache71581134242191133320.37.5.0048-29 ▼
mozilla11330080100630900.08.8.0029+112 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab682519499533.75.3.0029-7 ▼
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+2 ▲
wordpress0513102240.08.8.3120-1 ▼
kubernetes010001000.02.4.00350
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290358116585631012840.17.8.0034+634 ▲
ibm20782616637327111610.17.5.0029+15 ▲
adobe17077657343366102040.57.5.0023+110 ▲
progress3641539100611.68.1.0035-13 ▼
solarwinds0231733010417.49.1.00580
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+1 ▲
atlassian3918001300.07.6.0032+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link216619241112300.08.5.0154+5 ▲
siemens145163393000.07.3.0018-5 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
abb070430000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1423132714512318210.37.2.0020+124 ▲
sourcecodester442130012588000.05.5.0027+25 ▲
spring017012608315000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb50148487534100.07.1.0026+18 ▲
itsourcecode321480037111000.02.1.0026+22 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0026+126 ▲
wwbn921322144670000.06.9.0024+90 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-64849.164196.89.3
CVE-2026-85706.119695.910.0
CVE-2026-83549.085194.77.8
CVE-2026-82329.076794.39.8
CVE-2026-19478.058192.79.1
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.59.3
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1196KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8782710.0.0107
Most disclosures (vendor)
VendorCVEs
oracle1524
microsoft1016
linux1014
google852
ibm405
apple287
adobe211
dell196
red hat178
mozilla172
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco15
apple8
google8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven82
Packagist39
npm20
PyPI15
RubyGems2
Go1
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171763
CVE-2021-27102n/a2021-11-171763
CVE-2021-27101n/a2021-11-171763
CVE-2021-27103n/a2021-11-171763
CVE-2021-21017Adobe2021-11-171763
CVE-2021-28550Adobe2021-11-171763
CVE-2021-42013Apache Software Foundation2021-11-171763
CVE-2021-41773Apache Software Foundation2021-11-171763
CVE-2021-30858Apple2021-11-171763
CVE-2021-30860Apple2021-11-171763

Transactions

EXPLOIT PUBLISHED — curl: 40 CVEs (CVE-2025-10966, CVE-2025-14524, CVE-2025-15079, CVE-2025-15224, CVE-2026-3783, CVE-2026-3784, CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-7168, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8925, CVE-2026-8926, CVE-2026-8927, CVE-2026-8932, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9546, CVE-2026-9547, CVE-2026-10536, CVE-2026-11352, CVE-2026-11564, CVE-2026-11586, CVE-2026-11856, CVE-2026-12064, CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209). Public exploit references added.

EXPLOIT PUBLISHED — wazuh: 11 CVEs (CVE-2026-44901, CVE-2026-45798, CVE-2026-48024, CVE-2026-48162, CVE-2026-49392, CVE-2026-49441, CVE-2026-54083, CVE-2026-54084, CVE-2026-61783, CVE-2026-61800, CVE-2026-61802). Public exploit references added.

EXPLOIT PUBLISHED — GPAC: 10 CVEs (CVE-2026-90577, CVE-2026-90578, CVE-2026-90610, CVE-2026-90611, CVE-2026-90683, CVE-2026-90687, CVE-2026-90791, CVE-2026-90824, CVE-2026-90825, CVE-2026-90827). Public exploit references added.

EXPLOIT PUBLISHED — FlowiseAI Flowise: 7 CVEs (CVE-2026-67621, CVE-2026-67622, CVE-2026-70636, CVE-2026-90533, CVE-2026-90534, CVE-2026-90535, CVE-2026-90580). Public exploit references added.

EXPLOIT PUBLISHED — open-webui: 6 CVEs (CVE-2026-87011, CVE-2026-87012, CVE-2026-87013, CVE-2026-87014, CVE-2026-87015, CVE-2026-87016). Public exploit references added.

EXPLOIT PUBLISHED — GNU Binutils: 4 CVEs (CVE-2026-90804, CVE-2026-90828, CVE-2026-90829, CVE-2026-90830). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-46331 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-52023. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73698 (FileRun). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79513. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79514. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79522. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86137 (xmlsoft libxml2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86143 (xmlsoft libxml2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-89009 (WAVLINK Technology WN535M1). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-89263 (moxi624 MoguBlog). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90488 (Xuxueli xxl-job). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90491 (sanjevirau gsubs). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90498 (lenve vhr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90508 (Chengdu Qilu Technology Ludashi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90514 (SourceCodester School Registration and Fee System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90519 (PHPGurukul Bank Locker Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90524 (jaychouchannel Tourism-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90572 (davenardella snap7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90582 (evanchiu serverless-todo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90595 (wxiaoqi Spring-Cloud-Platform). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90600 (itsourcecode Sales and Inventory System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90605 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90606 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90615 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90617 (GH05TCREW PentestAgent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90621 (ipa-lab HackingBuddyGPT). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90622 (GNU libredwg). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90682 (Matthias-Wandel jhead). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90697 (SourceCodester Inventory Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90698 (memcached). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90702 (D-Link DWR-M921). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90703 (D-Link DWR-M921). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90708 (Yot CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90713 (vllm-project vLLM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90714 (marcobambini Gravity). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90785 (Dvidelabs flatcc). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90786 (Dvidelabs flatcc). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90795 (itsourcecode Loan Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90796 (itsourcecode Leave Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90805 (subhajitkhan online-clinic-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90810 (cosmicstack-labs mercury-agent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90814 (cosmicstack-labs mercury-agent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90815 (FFmpeg). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90835 (michaelliao itranswarp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91143 (snail007 goproxy). Public exploit reference added.

DUE DATE PASSED — CVE-2026-81578 (PaperCut MF/NG). CISA remediation deadline was September 14, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-82078 (PaperCut MF/NG). CISA remediation deadline was September 14, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-84869 (ConnectWise ScreenConnect). CISA remediation deadline was September 14, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-85706 (GitLab). CISA remediation deadline was September 14, 2026; still in catalog.

REJECTED — CVE-2026-71269 (node-red). Record withdrawn by the CNA.

REJECTED — CVE-2026-75501 (Calix GS7 XGS (GS5239XG)). Record withdrawn by the CNA.

RESCORED — xmlsoft libxml2: 8 CVEs (CVE-2026-86137, CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86141, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144). CVSS rescored — before/after on each CVE page.

RESCORED — Portabilis i-Educar: 7 CVEs (CVE-2025-8538, CVE-2025-8539, CVE-2025-9236, CVE-2025-9531, CVE-2025-9606, CVE-2025-10012, CVE-2026-2015). CVSS rescored — before/after on each CVE page.

RESCORED — undici: 5 CVEs (CVE-2026-84933, CVE-2026-84947, CVE-2026-84961, CVE-2026-85008, CVE-2026-85014). CVSS rescored — before/after on each CVE page.

RESCORED — PHPGurukul Blood Donor Management System: 3 CVEs (CVE-2026-90840, CVE-2026-90841, CVE-2026-90842). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-5578 (Portábilis i-Educar). CVSS 5.1 → 2 (NVD).

RESCORED — CVE-2026-14199 (Grafana Enterprise). CVSS 7.1 → 8.1 (NVD).

RESCORED — CVE-2026-3416 (WSO2 API Manager). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2026-66014 (jfrog artifactory). CVSS 9.8 → 8.8 (NVD).

RESCORED — CVE-2026-75050 (JetBrains YouTrack). CVSS 7.1 → 6.5 (NVD).

RESCORED — CVE-2026-77822 (IBM ContextForge MCP Gateway). CVSS 8.2 → 9.6 (NVD).

RESCORED — CVE-2026-79418. CVSS 5.4 → 8.7 (NVD).

RESCORED — CVE-2026-81381 (Microsoft Visual Studio Code). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-9176 (IBM WebSphere Application Server). CVSS 6.7 → 7.1 (NVD).

RESCORED — CVE-2026-9327 (IBM WebSphere Application Server). CVSS 6.3 → 8.1 (NVD).

PATCH SHIPPED — CVE-2026-75092 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:0.24.0-1.el9_8.1.

Yesterday's Results

How to read these box scores · glossary

1426 CVEs published. 25 box scores and 375 table rows below; the remaining 1026 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

EFM ipTIME C200E System Setup iux_set.cgi os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0218   81.4     —
AFFECTED
  Product       Versions  Fixed
  ipTIME C200E  1.094 –   —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 15  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SabyasachiRana WebMap New Nmap Scan functions_nmap.py nmap_newscan os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0137   70.4     —
AFFECTED
  Product  Versions                                    Fixed
  WebMap   8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25 –  —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 15  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
OpenIdentityPlatform OpenAM — OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0109   63.5     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.2 –  —
TIMELINE
  Jul 13  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-94, CWE-470 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Received
D-Link DSL-3782 Diagnostics Diagnostics.asp system command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0104   62.3     —
AFFECTED
  Product   Versions      Fixed
  DSL-3782  2016-07-28 –  —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 15  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
LITE-ON Technology Corporation FF-RFI079I4 — Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0103   61.8     —
AFFECTED
  Product      Versions     Fixed
  FF-RFI079I4  unspecified  —
  FF-RFI078I4  unspecified  —
TIMELINE
  Sep 7   Reserved by CNA
  Sep 15  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM Authentication Bypass via MSISDN LDAP Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0099   60.7     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 15  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-90 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0089   57.5     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.2 –  —
TIMELINE
  Jul 13  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
MervinPraison PraisonAI — PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.7     —
AFFECTED
  Product    Versions   Fixed
  PraisonAI  < 1.7.2 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-94 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0076   53.5     —
AFFECTED
  Product    Versions             Fixed
  PraisonAI  >= 1.2.3, < 1.7.2 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-78, CWE-693, CWE-863 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
wandb wandb — Weights & Biases wandb before 0.29.0 Path Traversal via File Download
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0073   52.4     —
AFFECTED
  Product  Versions     Fixed
  wandb    unspecified  —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 15  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0069   50.8     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 8   Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   H   H   N    7.4   .0067   50.1     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 15  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-620, CWE-1391 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
MervinPraison PraisonAI — PraisonAI codeMode sandbox escape via Function constructor
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0065   49.5     —
AFFECTED
  Product    Versions             Fixed
  PraisonAI  >= 1.4.0, < 1.7.2 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-184, CWE-693 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
MervinPraison PraisonAI — PraisonAI MCPServer exposes unauthenticated HTTP tools/call
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   48.9     —
AFFECTED
  Product    Versions             Fixed
  PraisonAI  >= 1.5.0, < 1.7.2 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-306, CWE-862, CWE-1188 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
OpenIdentityPlatform OpenAM — OpenAM Unsafe Java Deserialization via SNS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0063   48.2     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 13  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-502 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   L   H   N    8.3   .0059   46.6     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 5   Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-79 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM: Pre-authentication Reflected XSS in SAML2 Cluster Cookie-Hash-Redirect Path via `FSUtils.postToTarget`
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   A   L   H   N    7.0   .0059   46.6     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 7   Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-79 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
MervinPraison PraisonAI — PraisonAI AgentOS exposes unauthenticated agent listing and invocation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0056   45.2     —
AFFECTED
  Product    Versions             Fixed
  PraisonAI  >= 1.6.0, < 1.7.2 –  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-306 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
OpenIdentityPlatform OpenAM — OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   L    9.3   .0055   44.7     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 8   Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-285 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM OAuth Client Impersonation via JWKS Resolver Cache
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   N    7.6   .0055   44.7     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 19  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-287 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
OpenIdentityPlatform OpenAM — OpenAM OAuth Authorization Bypass via PKCE Challenge
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   N    9.1   .0053   43.3     —
AFFECTED
  Product  Versions    Fixed
  OpenAM   < 16.1.1 –  —
TIMELINE
  May 22  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-285 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Received
MervinPraison PraisonAI — praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   43.2     —
AFFECTED
  Product             Versions    Fixed
  PraisonAI           < 4.6.51 –  —
  praisonai-platform  < 0.1.6 –   —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-287, CWE-798, CWE-1188 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
Kimai: Two-factor authentication bypass on the Kimai API
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   L   N    7.1   .0052   42.8     —
AFFECTED
  Product  Versions    Fixed
  kimai    < 2.59.0 –  —
TIMELINE
  Jun 8   Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-287 · CNA: GitHub_M · CVSS v4.0 · 5 references · NVD status: Received
MervinPraison PraisonAI — praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   42.2     —
AFFECTED
  Product             Versions    Fixed
  PraisonAI           < 4.6.51 –  —
  praisonai-platform  < 0.1.6 –   —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 15  Published (CNA: GitHub_M)
CWE-798, CWE-1188 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0051   42.2     —
AFFECTED
  Product  Versions  Fixed
  DI-8300  16.07 –   —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 15  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-571338.841.9MervinPraisonPraisonAICWE-78PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
CVE-2026-415737.141.2OpenIdentityPlatformOpenAMCWE-90OpenAM LDAP Injection via `_queryId` Parameter
CVE-2026-910018.640.4D-LinkDI-8400CWE-119D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow
CVE-2026-474247.540.3OpenIdentityPlatformOpenAMCWE-693OpenAM Authenticated RCE via Groovy Sandbox Escape
CVE-2026-918595.339.7MISPMISPCWE-223MISP Access Log Entry Overwritten by Error Controller's Second beforeFilter Pass
CVE-2026-910025.537.6stamparmmaltrailCWE-287stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication
CVE-2026-571378.837.4MervinPraisonPraisonAICWE-693PraisonAI AgentLoop onToolCall approval runs after tool execution
CVE-2026-571348.236.3MervinPraisonPraisonAICWE-287PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid cred…
CVE-2026-450488.536.3OpenIdentityPlatformOpenAMCWE-200OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
CVE-2026-528196.335.7kimaikimaiCWE-863Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading ot…
CVE-2026-464987.634.9OpenIdentityPlatformOpenAMCWE-639OpenAM Arbitrary OAuth Token Minting via Push Registration
CVE-2026-442025.334.9OpenIdentityPlatformOpenAMCWE-918OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`
CVE-2026-528215.334.9kimaikimaiCWE-639Kimai: Improper Authorization in Kimai Activity Creation with Preset Project …
CVE-2026-571357.634.7MervinPraisonPraisonAICWE-653PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-awar…
CVE-2026-759837.534.7arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCWE-269Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1…
CVE-2026-908815.534.5D-LinkDIR-882CWE-200D-Link DIR-882 CGI Binary dllog.cgi main information disclosure
CVE-2026-536607.434.1OpenIdentityPlatformOpenAMCWE-1004OpenAM Insecure SSO Cookie Initialization
CVE-2026-593414.233.9Bitnamisealed-secrets—Sealed Secrets: decryption oracle via Go template injection in unauthenticate…
CVE-2026-528265.333.2kimaikimaiCWE-285Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate E…
CVE-2026-528285.333.2kimaikimaiCWE-862Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TE…
CVE-2026-910912.132.7n/aGPACCWE-119GPAC Node Insertion base_scenegraph.c gf_node_list_insert_child memory corrup…
CVE-2026-917528.732.3GNUlibextractorCWE-789GNU libextractor before 1.15 Stack Overflow via OLE2
CVE-2026-528225.332.2kimaikimaiCWE-285Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows…
CVE-2026-528249.131.4kimaikimaiCWE-1188Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account …
CVE-2026-910875.530.7n/aGPACCWE-119GPAC Compositor media_object.c gf_mo_get_od_id use after free
CVE-2026-528205.329.9kimaikimaiCWE-639Kimai: Timesheet PATCH/POST allows assigning to project outside user's team v…
CVE-2026-528255.329.9kimaikimaiCWE-285Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignme…
CVE-2026-174955.929.1momentmomentCWE-27moment vulnerable to Path Traversal via crafted non-string locale name
CVE-2026-917517.227.9flextypeflextypeCWE-22Flextype CMS through 1.0.0-alpha.3 Path Traversal via Entries REST API
CVE-2026-882628.726.0bizwellxClickCWE-613Insufficient session expiration vulnerability in bizwell xClick allows Authen…
CVE-2025-58025.326.0WSO2WSO2 API ManagerCWE-203Username Enumeration via Self Registration Flow in Multiple WSO2 Products All…
CVE-2026-622806.125.7OpenIdentityPlatformOpenAMCWE-79OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
CVE-2026-910862.125.3n/aGPACCWE-119GPAC MPEG Video Reframer reframe_mpgvid.c mpgviddmx_process heap-based overflow
CVE-2026-908525.524.3lubenzstd-jniCWE-119luben zstd-jni Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDi…
CVE-2026-908585.523.6subhajitkhanonline-clinic-management-systemCWE-285subhajitkhan online-clinic-management-system adminappview.php session_start a…
CVE-2026-908782.122.9vllm-projectvLLMCWE-400vllm-project vLLM Jinja Template Rendering completions resource consumption
CVE-2026-910892.121.8n/aGPACCWE-119GPAC base_scenegraph.c gf_node_get_name_and_id use after free
CVE-2026-908565.521.4SourceCodesterCollege Notes Gallery Management SystemCWE-266SourceCodester College Notes Gallery Management System Registration Flow sign…
CVE-2026-802178.720.9LITE-ON Technology CorporationFF-RFI079I4CWE-912Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may a…
CVE-2026-157585.319.8iberezansky3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image GalleryCWE-2003D FlipBook <= 1.16.20 - Unauthenticated Sensitive Information Exposure in 'i…
CVE-2026-813036.319.7Red HatRed Hat build of Apache Camel - HawtIO 4CWE-441Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec…
CVE-2026-891416.519.6tigroumeowAI Engine – The Chatbot, AI Framework & MCP for WordPressCWE-639AI Engine <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Subsc…
CVE-2026-908765.519.0SourceCodesterOnline Faculty Clearance SystemCWE-74SourceCodester Online Faculty Clearance System delete_requirement.php sql inj…
CVE-2025-131663.719.1WSO2WSO2 Identity ServerCWE-203Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Acc…
CVE-2026-908495.518.5SourceCodesterCollege Notes Gallery Management SystemCWE-74SourceCodester College Notes Gallery Management System login.php sql injection
CVE-2026-917507.118.4TencentWeKnoraCWE-918WeKnora before 0.7.0 SSRF via Unvalidated HTTP Redirects
CVE-2026-908445.518.2PHPGurukulDaily Expense Tracker SystemCWE-74PHPGurukul Daily Expense Tracker System Login index.php sql injection
CVE-2026-908465.518.2PHPGurukulDaily Expense Tracker SystemCWE-74PHPGurukul Daily Expense Tracker System forgot-password.php sql injection
CVE-2026-908775.518.2SourceCodesterOnline Faculty Clearance SystemCWE-74SourceCodester Online Faculty Clearance System update_requirement_status.php …
CVE-2026-908795.518.2zyx0814FilePressCWE-74zyx0814 FilePress Publish search.php sql injection
CVE-2026-910045.518.3SourceCodesterOnline Faculty Clearance SystemCWE-74SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection
CVE-2026-908485.318.3GovernikusAusweisAppCWE-79Governikus AusweisApp StartPAOSResponse cross site scripting
CVE-2026-918515.317.9MISPMISPCWE-697MISP Dashboard Template ACL Bypass Due to VARCHAR-to-Integer Type Coercion in…
CVE-2026-908545.517.7SourceCodesterOnline Food Ordering SystemCWE-74SourceCodester/katojkalemba Online Food Ordering System category-foods.php sq…
CVE-2026-908555.517.7SourceCodesterOnline Food Ordering SystemCWE-74SourceCodester/katojkalemba Online Food Ordering System order.php sql injection
CVE-2026-917787.217.5Octopus DeployOctopus ServerCWE-863In affected versions of Octopus Server, users with certain scoped permission …
CVE-2026-917707.117.5gamonoidicehrmCWE-639IceHRM before 36.0.0 Broken Access Control via Employee ID
CVE-2026-154026.416.5arrayticsEventin – Event Calendar, Tickets, Registration, Booking & WooCommerceCWE-79Eventin <= 4.1.23 - Authenticated (Custom+) Stored Cross-Site Scripting via '…
CVE-2026-918257.115.6MISPMISPCWE-862MISP: Missing Authorization Check for Event Sharing Group When Distribution F…
CVE-2026-882615.112.9bizwellxClickCWE-20Improper input validation vulnerability in bizwell xClick allows Stored XSS. …
CVE-2026-918575.311.9MISPMISPCWE-352MISP: State-changing actions accessible via GET request enabling CSRF
CVE-2026-908501.911.4PHPGurukulHostel Management SystemCWE-79PHPGurukul Hostel Management System manage-students.php cross site scripting
CVE-2026-908512.111.3PHPGurukulHostel Management SystemCWE-266PHPGurukul Hostel Management System checklogin.php access control
CVE-2026-908572.111.3SourceCodesterCollege Notes Gallery Management SystemCWE-284SourceCodester College Notes Gallery Management System Profile Upload userpro…
CVE-2026-910052.111.3SourceCodesterOnline Faculty Clearance SystemCWE-284SourceCodester Online Faculty Clearance System Profile Picture Upload edit_pi…
CVE-2026-918467.111.0MISPMISPCWE-639MISP Collection Element Add Missing Authorization on Referenced Object UUID
CVE-2026-528235.310.9kimaikimaiCWE-352Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Un…
CVE-2026-917735.39.9charmbraceletsoft-serveCWE-639Soft Serve 0.7.1 through 0.11.6 Information Disclosure via LFS Locks
CVE-2026-917745.39.9YaoAppyaoCWE-862Yao through v1.0.0-rc22 Missing Authorization via OpenAPI team endpoint
CVE-2026-908452.09.8PHPGurukulDaily Expense Tracker SystemCWE-79PHPGurukul Daily Expense Tracker System sidebar.php cross site scripting
CVE-2026-180636.49.7blueglasschJob PostingsCWE-79Job Postings <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-571128.38.6MervinPraisonPraisonAICWE-306PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin an…
CVE-2026-907119.18.5proxy-addrproxy-addrCWE-290proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
CVE-2026-917725.38.1halo-devhaloCWE-601Halo through 2.26.1 Open Redirect via Unvalidated URI Parameter
CVE-2026-195157.06.5WSO2WSO2 Integrator: MI for Visual Studio CodeCWE-78OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Ex…
CVE-2026-855756.46.1roxnorShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgetsCWE-79The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce S…
CVE-2026-165936.85.8UnknownWP Directory KitCWE-89WP Directory Kit <= 1.5.7 - Editor+ SQL Injection via Elementor Category and …
CVE-2026-918196.95.3MISPMISPCWE-20MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurit…
CVE-2026-182325.34.2UnknownWP Directory KitCWE-200WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure vi…
CVE-2026-165922.73.6UnknownWP Directory KitCWE-200WP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure …
CVE-2026-856575.43.5publishpressCo-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress AuthorsCWE-79Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishP…
CVE-2026-813205.53.3Red HatRed Hat build of Apache Camel - HawtIO 4CWE-532Hawtio-operator: hawtio-operator: tls private key written to operator log at …
CVE-2026-750927.32.8Red HatRed Hat Enterprise Linux 9CWE-250Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysq…
CVE-2026-910900.92.4n/aGPACCWE-119GPAC base_scenegraph.c gf_node_activate_ex stack-based overflow
CVE-2026-917821.92.2GNUBinutilsCWE-404GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynre…
CVE-2026-917811.92.1GNUBinutilsCWE-404GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null …
CVE-2026-910882.41.8n/aGPACCWE-119GPAC URL url.c gf_url_concatenate_ex heap-based overflow
CVE-2026-917791.91.6GNUBinutilsCWE-404GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null po…
CVE-2026-917801.91.6GNUBinutilsCWE-404GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference
CVE-2026-918264.41.5Samsung OpensourcerLottieCWE-121Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allow…
CVE-2026-761597.00.9DuplicatiDuplicatiCWE-732Duplicati for Windows - Incorrect Permission Assignment for Critical Resource
CVE-2026-867011.80.8NTT DOCOMO BUSINESS, Inc.ManabiPocket for ParentsCWE-926Android application "ManabiPocket for Parents" contains an improper access co…
CVE-2026-5371010.0—IBMmcp-context-forgeCWE-94MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in pyt…
CVE-2026-5997110.0—designcomputermysql_mcp_serverCWE-306MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Una…
CVE-2026-7113310.0—Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-8302010.0—Oracle CorporationOracle Platform Security for JavaCWE-287Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-8302110.0—Oracle CorporationOracle WebLogic ServerCWE-287Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-8305910.0—Oracle CorporationOracle Internet DirectoryCWE-287Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-8309910.0—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-8723010.0—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-455799.9—DIRACGridDIRACCWE-95DIRAC: RCE in RequestManager due to eval on untrusted input
CVE-2026-616679.9—DIRACGridDIRACCWE-89DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
CVE-2026-711639.9—Oracle CorporationOracle Access Manager—Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739459.9—Oracle CorporationOracle Access Manager—Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739489.9—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-766699.9—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Or…
CVE-2026-766709.9—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Or…
CVE-2026-766729.9—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect …
CVE-2026-829979.9—Oracle CorporationService Delivery Platform—Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-829989.9—Oracle CorporationService Delivery Platform—Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-829999.9—Oracle CorporationService Delivery Platform—Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-830319.9—Oracle CorporationOracle WebCenter Sites—Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-830389.9—Oracle CorporationOracle WebLogic Server—Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-830399.9—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-830559.9—Oracle CorporationOracle Internet Directory—Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830569.9—Oracle CorporationOracle Internet Directory—Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830579.9—Oracle CorporationOracle Internet Directory—Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830589.9—Oracle CorporationOracle Internet Directory—Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-832829.9—Oracle CorporationOracle Business Intelligence Enterprise Edition—Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-871729.9—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-123519.8—IBMMQCWE-74IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection
CVE-2026-197739.8—libwebsocketslibwebsocketsCWE-787libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Cod…
CVE-2026-543379.8—ShaneIsraelfireshareCWE-88Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Over…
CVE-2026-552119.8—equinorsurfioCWE-125surfio IRAP header size fields cause out-of-bounds reads
CVE-2026-615609.8—zereightgitlab-mcpCWE-22@zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdo…
CVE-2026-636959.8—DellSmartFabric OS10 SoftwareCWE-284Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Sessio…
CVE-2026-707489.8—Oracle CorporationOracle WebLogic ServerCWE-287Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-707569.8—Oracle CorporationOracle WebLogic ServerCWE-287Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-707579.8—Oracle CorporationOracle WebLogic ServerCWE-287Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middlewa…
CVE-2026-709139.8—Oracle CorporationOracle Identity ManagerCWE-287Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-739409.8—Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739479.8—Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739509.8—Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739539.8—Oracle CorporationOracle WebCenter PortalCWE-287Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-739569.8—Oracle CorporationOracle WebCenter PortalCWE-287Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-739619.8—Oracle CorporationOracle JDeveloperCWE-287Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c…
CVE-2026-739639.8—Oracle CorporationOracle WebCenter PortalCWE-287Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-766739.8—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator
CVE-2026-766749.8—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution…
CVE-2026-829949.8—Oracle CorporationOracle Platform Security for JavaCWE-287Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-829959.8—Oracle CorporationOracle Platform Security for JavaCWE-287Vulnerability in the Oracle Platform Security for Java product of Oracle Fusi…
CVE-2026-830009.8—Oracle CorporationService Delivery PlatformCWE-287Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-830359.8—Oracle CorporationOracle WebCenter SitesCWE-287Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-830369.8—Oracle CorporationOracle WebCenter SitesCWE-287Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-830379.8—Oracle CorporationOracle WebCenter SitesCWE-287Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-830429.8—Oracle CorporationOracle Identity ManagerCWE-287Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-830549.8—Oracle CorporationOracle Internet DirectoryCWE-287Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830609.8—Oracle CorporationOracle Internet DirectoryCWE-287Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830619.8—Oracle CorporationOracle Internet DirectoryCWE-287Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830629.8—Oracle CorporationOracle Internet DirectoryCWE-287Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830669.8—Oracle CorporationOracle Internet DirectoryCWE-287Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middl…
CVE-2026-830949.8—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-830959.8—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-830989.8—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831009.8—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831089.8—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831519.8—Oracle CorporationService Delivery PlatformCWE-287Vulnerability in the Service Delivery Platform product of Oracle Fusion Middl…
CVE-2026-832329.8—Oracle CorporationOracle Data IntegratorCWE-287Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middlewa…
CVE-2026-832619.8—Oracle CorporationOracle Product Lifecycle AnalyticsCWE-287Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Sup…
CVE-2026-832699.8—Oracle CorporationOracle BI PublisherCWE-287Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-832839.8—Oracle CorporationOracle Business Intelligence Enterprise EditionCWE-287Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-833279.8—Oracle CorporationOracle Applications FrameworkCWE-287Vulnerability in the Oracle Applications Framework product of Oracle E-Busine…
CVE-2026-833399.8—Oracle CorporationOracle WebCenter Enterprise CaptureCWE-287Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-833559.8—Oracle CorporationOracle Enterprise Manager for Fusion MiddlewareCWE-287Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product …
CVE-2026-834529.8—Oracle CorporationOracle Document Management and CollaborationCWE-287Vulnerability in the Oracle Document Management and Collaboration product of …
CVE-2026-834629.8—Oracle CorporationOracle Mobile Application ServerCWE-287Vulnerability in the Oracle Mobile Application Server product of Oracle E-Bus…
CVE-2026-871849.8—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871889.8—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-615599.6—zereightgitlab-mcpCWE-918@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
CVE-2026-615689.6—zereightgitlab-mcpCWE-350@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
CVE-2026-739629.6—Oracle CorporationOracle Access Manager—Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-830299.6—Oracle CorporationOracle Managed File Transfer—Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Mi…
CVE-2026-830409.6—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-830439.6—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-871869.6—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-917109.6—GoogleChromeCWE-416Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allo…
CVE-2026-917189.6—GoogleChromeCWE-416Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remo…
CVE-2026-917289.6—GoogleChromeCWE-190Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remo…
CVE-2026-917499.6—GoogleChromeCWE-416Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a r…
CVE-2026-156409.5—DelineaSecret Server (On-Prem)CWE-290Authentication Bypass via SAML Response Manipulation
CVE-2026-782259.5—WärtsiläFOS-OnboardCWE-321Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
CVE-2026-668879.4—Digital WatchdogVMAX A1 G4 DVRCWE-862Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups
CVE-2026-668909.4—Digital WatchdogVMAX A1 G4 DVRCWE-798Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Li…
CVE-2026-684919.4—WebprosSolusVMCWE-59An insufficient check allowed for the overwrite of arbitrary files via a syml…
CVE-2026-771799.4—DockerDocker SandboxesCWE-59Docker Sandboxes guest can write arbitrary macOS host files via a symlink in …
CVE-2026-919989.4—casdoorcasdoorCWE-863Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp
CVE-2023-543989.3—YonyouU8 CloudCWE-502Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet
CVE-2024-583859.3—YonyouU8 CRMCWE-89Yonyou U8 CRM SQL Injection via fillbacksettingedit.php
CVE-2026-156399.3—DelineaSecret Server (On-Prem)CWE-79Reflected Cross-Site Scripting
CVE-2026-399199.3—Artifex SoftwareGhostscriptCWE-122Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter
CVE-2026-534599.3—maziggybambuddyCWE-636Bambuddy's authentication fails open on database errors, allowing unauthentic…
CVE-2026-738079.3—mySCADA TechnologiesmySCADA myPROCWE-862mySCADA myPRO Manager Missing Authorization
CVE-2026-739579.3—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-818559.3—WärtsiläFOS-OnboardCWE-321Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
CVE-2026-830279.3—Oracle CorporationOracle Identity Manager Connector—Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusi…
CVE-2026-890269.3—Issabel FoundationIssabel FrameworkCWE-321Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate
CVE-2026-890409.3—TencentMass Service Engine in Cluster (MSEC)CWE-22Tencent Mass Service Engine in Cluster (MSEC) path traversal
CVE-2026-893089.3—TREXOMTrxTimeATTENDANCECWE-78Arbitrary command execution in TrxTimeATTENDANCE
CVE-2026-919399.3—CotontiCotontiCWE-502Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter
CVE-2026-919959.3—pig-meshpigCWE-620pig before 4.1.0 Unverified Password Change via /register/password
CVE-2026-464959.2—OpenIdentityPlatformOpenDJCWE-502OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
CVE-2026-692049.2—http4shttp4sCWE-444Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE r…
CVE-2026-734589.2—Arista NetworksEOSCWE-303On affected platforms running Arista EOS with authenticated Bidirectional For…
CVE-2026-919499.2—FreeRDPFreeRDPCWE-693FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
CVE-2026-919889.2—dep0weatomic-agents-stackCWE-319atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP
CVE-2026-156389.1—DelineaSecret Server (On-Prem)CWE-327Cryptographic Padding Oracle
CVE-2026-464889.1—motioneye-projectmotioneyeCWE-256motionEye: Authentication possible via password hash
CVE-2026-551589.1—wktkconflibotCWE-78Conflibot: Command injection via crafted pull request branch names under pull…
CVE-2026-636969.1—DellSmartFabric OS10 SoftwareCWE-494Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Downlo…
CVE-2026-739449.1—Oracle CorporationOracle Access ManagerCWE-287Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739469.1—Oracle CorporationOracle Access Manager—Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-739529.1—Oracle CorporationOracle WebCenter PortalCWE-287Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-766759.1—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authenticated Command Injection Vulnerability Leads to Privilege Escalation i…
CVE-2026-830019.1—Oracle CorporationOracle Access Manager—Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-830069.1—Oracle CorporationOracle WebCenter Enterprise Capture—Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-830649.1—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-831039.1—Oracle CorporationOracle Forms—Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831049.1—Oracle CorporationOracle FormsCWE-287Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831079.1—Oracle CorporationOracle Forms—Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831499.1—Oracle CorporationOracle Application Testing Suite—Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-831549.1—Oracle CorporationSiebel CRM End UserCWE-287Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (compon…
CVE-2026-831969.1—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-831979.1—Oracle CorporationSiebel Apps - Financial Services—Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebe…
CVE-2026-832019.1—Oracle CorporationSiebel CRM DeploymentCWE-287Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-832029.1—Oracle CorporationSiebel CRM DeploymentCWE-287Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-832299.1—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-832609.1—Oracle CorporationOracle Agile PLM—Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-832689.1—Oracle CorporationOracle BI Publisher—Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-871289.1—Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-287Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-871299.1—Oracle CorporationOracle Hyperion Data Relationship ManagementCWE-287Vulnerability in the Oracle Hyperion Data Relationship Management product of …
CVE-2026-871709.1—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871739.1—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871759.1—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871769.1—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871899.1—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872149.1—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872179.1—Oracle CorporationOracle Hyperion Financial ManagementCWE-287Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872239.1—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-890229.1—bookstackappbookstackCWE-290BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion
CVE-2023-543979.0—tornadowebtornadoCWE-444Tornado before 6.3.3 HTTP Request Smuggling via Content-Length
CVE-2024-140299.0—tornadowebtornadoCWE-444Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding
CVE-2026-615499.0—woodpecker-ciwoodpeckerCWE-269Woodpecker: Privilege escalation via unrestricted serviceAccountName in the K…
CVE-2026-778669.0—SlabsafeurlCWE-636SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts
CVE-2026-779729.0—SlabsafeurlCWE-367safeurl validated address is not bound to the request, allowing DNS rebinding
CVE-2026-831059.0—Oracle CorporationOracle Forms—Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-919319.0—FlowiseAIFlowiseCWE-78Flowise before 3.1.4 Remote Code Execution via Custom MCP npx
CVE-2026-919329.0—FlowiseAIFlowiseCWE-20Flowise before 3.1.4 Remote Code Execution via cwd Parameter
CVE-2026-833048.9—Oracle CorporationOracle Business Intelligence Enterprise Edition—Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-01598.8—GoogleAndroidCWE-787In Cellular Modem, there is a possible out-of-bounds write due to a missing b…
CVE-2026-01708.8—GoogleAndroidCWE-787In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds …
CVE-2026-01718.8—GoogleAndroidCWE-787In multiple locations, there is a possible out-of-bounds write due to a logic…
CVE-2026-02008.8—GoogleAndroidCWE-122In Cellular Modem, there is a possible out-of-bounds write due to a heap buff…
CVE-2026-127288.8—IBMMQ—IBM MQ Java messaging is vulnerable to remote code execution
CVE-2026-148058.8—StylemixThemesConsulting - Business, Finance WordPress ThemeCWE-269Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Sub…
CVE-2026-161408.8—OpenBMCphosphor-net-ipmidCWE-863OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1
CVE-2026-197808.8—KohaKohaCWE-95Koha Eval Code Injection Remote Code Execution Vulnerability
CVE-2026-400588.8—CrowdStrikeFalcon sensor for WindowsCWE-367Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for…
CVE-2026-443008.8—opencostopencostCWE-20OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
CVE-2026-524848.8—n/an/aCWE-78An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authe…
CVE-2026-553188.8—GoogleAndroidCWE-362In multiple locations, there is a possible use-after-free due to a race condi…
CVE-2026-553318.8—GoogleAndroidCWE-120In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an…
CVE-2026-568828.8—GoogleAndroidCWE-200In Cellular Modem, there is a possible information disclosure due to a logic …
CVE-2026-569208.8—GoogleAndroidCWE-787In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bou…
CVE-2026-569428.8—GoogleAndroidCWE-787In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write…
CVE-2026-569748.8—GoogleAndroidCWE-20In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds…
CVE-2026-569978.8—GoogleAndroidCWE-787In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds …
CVE-2026-586838.8—GoogleAndroidCWE-20In IP Multimedia Subsystem, there is a possible out-of-bounds write due to im…
CVE-2026-587108.8—GoogleAndroidCWE-120In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bou…
CVE-2026-591608.8—DerYegeryegerCWE-306Yeger: Unauthenticated Network-Exposed Turborepo Task Execution via /api/run
CVE-2026-694868.8—MicrosoftMicrosoft Edge (Chromium-based)CWE-122Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-709158.8—Oracle CorporationOracle Identity Manager—Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-710478.8—Oracle CorporationOracle Identity Manager—Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-739428.8—Oracle CorporationOracle Identity Manager—Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-739498.8—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-739598.8—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-766768.8—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution…
CVE-2026-766778.8—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authorization Bypass Leading to Privilege Escalation in HPE Networking EdgeCo…
CVE-2026-766788.8—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authenticated Command Injection Vulnerability leads to Remote Code Execution …
CVE-2026-830058.8—Oracle CorporationOracle WebCenter Enterprise Capture—Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-830088.8—Oracle CorporationOracle WebCenter Enterprise Capture—Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-830098.8—Oracle CorporationOracle WebCenter Enterprise Capture—Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-830138.8—Oracle CorporationOracle WebCenter Enterprise Capture—Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fu…
CVE-2026-830178.8—Oracle CorporationPeopleSoft Enterprise PeopleTools—Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-830328.8—Oracle CorporationOracle WebCenter Sites—Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-830338.8—Oracle CorporationOracle WebCenter Sites—Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middlewa…
CVE-2026-830538.8—Oracle CorporationOracle WebCenter Portal—Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middlew…
CVE-2026-830698.8—Oracle CorporationOracle Fusion Middleware Control—Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusio…
CVE-2026-830868.8—Oracle CorporationSiebel CRM Cloud Applications—Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2026-830908.8—Oracle CorporationOracle Spares Management—Vulnerability in the Oracle Spares Management product of Oracle E-Business Su…
CVE-2026-831198.8—Oracle CorporationOracle User Management—Vulnerability in the Oracle User Management product of Oracle E-Business Suit…
CVE-2026-831208.8—Oracle CorporationOracle Alert—Vulnerability in the Oracle Alert product of Oracle E-Business Suite (compone…
CVE-2026-831218.8—Oracle CorporationOracle Marketing—Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (com…
CVE-2026-831228.8—Oracle CorporationOracle Report Manager—Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite…
CVE-2026-831248.8—Oracle CorporationOracle Sales Online—Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (…
CVE-2026-831258.8—Oracle CorporationOracle Report Manager—Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite…
CVE-2026-831368.8—Oracle CorporationOracle Spares Management—Vulnerability in the Oracle Spares Management product of Oracle E-Business Su…
CVE-2026-831378.8—Oracle CorporationOracle Spares Management—Vulnerability in the Oracle Spares Management product of Oracle E-Business Su…
CVE-2026-831488.8—Oracle CorporationOracle Application Testing Suite—Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-831538.8—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-831608.8—Oracle CorporationOracle Database Server—Vulnerability in the RDBMS component of Oracle Database Server. Supported ver…
CVE-2026-831638.8—Oracle CorporationOracle Application Object Library—Vulnerability in the Oracle Application Object Library product of Oracle E-Bu…
CVE-2026-831648.8—Oracle CorporationOracle Customer Interaction History—Vulnerability in the Oracle Customer Interaction History product of Oracle E-…
CVE-2026-831658.8—Oracle CorporationOracle Customer Interaction History—Vulnerability in the Oracle Customer Interaction History product of Oracle E-…
CVE-2026-831688.8—Oracle CorporationOracle Applications Manager—Vulnerability in the Oracle Applications Manager product of Oracle E-Business…
CVE-2026-831808.8—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-831898.8—Oracle CorporationOracle User Management—Vulnerability in the Oracle User Management product of Oracle E-Business Suit…
CVE-2026-831948.8—Oracle CorporationOracle Depot Repair—Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (…
CVE-2026-831998.8—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-832058.8—Oracle CorporationOracle Applications Framework—Vulnerability in the Oracle Applications Framework product of Oracle E-Busine…
CVE-2026-832088.8—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-832098.8—Oracle CorporationSiebel CRM Development—Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (com…
CVE-2026-832108.8—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-832128.8—Oracle CorporationSiebel Apps - Self Service—Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM …
CVE-2026-832718.8—Oracle CorporationOracle Database Server—Vulnerability in the RDBMS component of Oracle Database Server. Supported ver…
CVE-2026-833018.8—Oracle CorporationOracle Business Intelligence Enterprise Edition—Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-833068.8—Oracle CorporationOracle JDeveloper—Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c…
CVE-2026-833158.8—Oracle CorporationOracle BI Publisher—Vulnerability in the Oracle BI Publisher product of Oracle Analytics (compone…
CVE-2026-833298.8—Oracle CorporationOracle Applications Framework—Vulnerability in the Oracle Applications Framework product of Oracle E-Busine…
CVE-2026-833318.8—Oracle CorporationOracle Applications Framework—Vulnerability in the Oracle Applications Framework product of Oracle E-Busine…
CVE-2026-833358.8—Oracle CorporationOracle Business Intelligence Enterprise Edition—Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-833388.8—Oracle CorporationOracle Applications Manager—Vulnerability in the Oracle Applications Manager product of Oracle E-Business…
CVE-2026-833408.8—Oracle CorporationOracle Identity Manager—Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middlew…
CVE-2026-833488.8—Oracle CorporationOracle Database Server—Vulnerability in the RDBMS component of Oracle Database Server. Supported ver…
CVE-2026-834108.8—Oracle CorporationOracle Coherence—Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-834118.8—Oracle CorporationOracle Coherence—Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-834238.8—Oracle CorporationOracle JDeveloper—Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (c…
CVE-2026-834448.8—Oracle CorporationOracle Product Hub—Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c…
CVE-2026-834458.8—Oracle CorporationOracle Complex Maintenance, Repair and Overhaul—Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product …
CVE-2026-834548.8—Oracle CorporationOracle Document Management and Collaboration—Vulnerability in the Oracle Document Management and Collaboration product of …
CVE-2026-834568.8—Oracle CorporationOracle Demand Signal Repository—Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Busi…
CVE-2026-834798.8—Oracle CorporationOracle Contracts—Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (com…
CVE-2026-858938.8—MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-871508.8—Oracle CorporationOracle Bills of Material—Vulnerability in the Oracle Bills of Material product of Oracle E-Business Su…
CVE-2026-871558.8—Oracle CorporationOracle Product Hub—Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c…
CVE-2026-871628.8—Oracle CorporationOracle Contract Lifecycle Management for Public Sector—Vulnerability in the Oracle Contract Lifecycle Management for Public Sector p…
CVE-2026-871638.8—Oracle CorporationOracle Purchasing—Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (co…
CVE-2026-871658.8—Oracle CorporationOracle Contract Lifecycle Management for Public Sector—Vulnerability in the Oracle Contract Lifecycle Management for Public Sector p…
CVE-2026-871798.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871808.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871818.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871828.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871858.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-871878.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872018.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872028.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872048.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872248.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872268.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872278.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-872388.8—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-886168.8—n/an/aCWE-863An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrar…
CVE-2026-917098.8—GoogleChromeCWE-843Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allow…
CVE-2026-917218.8—GoogleChromeCWE-416Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a…
CVE-2026-917318.8—GoogleChromeCWE-843Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed…
CVE-2026-917368.8—GoogleChromeCWE-416Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remot…
CVE-2026-917418.8—GoogleChromeCWE-843Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowe…
CVE-2026-920068.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920078.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920088.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920098.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920108.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920118.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920128.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920138.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: Ca…
CVE-2026-920148.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics com…
CVE-2026-920158.8—MozillaFirefoxCWE-269Privilege escalation in the WebExtensions component
CVE-2026-920178.8—MozillaFirefoxCWE-269Privilege escalation in the DOM: Service Workers component
CVE-2026-920208.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Graphics: We…
CVE-2026-920338.8—MozillaFirefoxCWE-269Privilege escalation in Firefox for Android
CVE-2026-920438.8—MozillaFirefoxCWE-120Privilege escalation due to incorrect boundary conditions in the Audio/Video …
CVE-2026-920478.8—MozillaFirefoxCWE-269Privilege escalation in the Crash Reporting component
CVE-2026-920528.8—MozillaFirefoxCWE-457Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL…
CVE-2026-920538.8—MozillaFirefoxCWE-269Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-920548.8—MozillaFirefoxCWE-119Privilege escalation in the Memory component
CVE-2026-920558.8—MozillaFirefoxCWE-269Privilege escalation in the DevTools component

Results continue: ranks 401–1426.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-15 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.