boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 15, 2026 · all times UTC← 2026-09-14 · archive

Security Box Score — September 15, 2026 — page 3

Edition of September 15, 2026, continued — page 3 of 3. Back to page 1 · page 2

Results (continued, ranked) — ranks 1001–1426 of 1426
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-919637.1—FreeRDPFreeRDPCWE-457FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc
CVE-2026-919687.1—go-vikunjavikunjaCWE-674vikunja before 2.6.0 Denial of Service via unbounded filter recursion
CVE-2026-919697.1—go-vikunjavikunjaCWE-400vikunja before 2.6.0 Resource Exhaustion via CSV Migration
CVE-2026-919707.1—go-vikunjavikunjaCWE-770Vikunja before 2.6.0 Resource Exhaustion via Planka Migration
CVE-2026-919717.1—go-vikunjavikunjaCWE-400Vikunja before 2.6.0 Denial of Service via Avatar Upload
CVE-2026-919797.1—go-vikunjavikunjaCWE-400Vikunja before 2.6.0 Denial of Service via Decompression Bomb
CVE-2026-919877.1—dep0weatomic-agents-stackCWE-770atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model
CVE-2026-919947.1—semaphoreuisemaphoreCWE-862Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests
CVE-2026-922567.1—NetcoreNR255-VCWE-522Netcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_…
CVE-2026-121507.0—IBMMQCWE-121IBM MQ queue manager is vulnerable to denial of service
CVE-2026-587017.0—GoogleAndroidCWE-362In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds …
CVE-2026-587247.0—GoogleAndroidCWE-362In multiple locations, there is a possible use-after-free due to a race condi…
CVE-2026-587287.0—GoogleAndroidCWE-362In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race c…
CVE-2026-587347.0—GoogleAndroidCWE-362In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bound…
CVE-2026-734467.0—Arista NetworksEOSCWE-696Security Advisory 0160
CVE-2026-734597.0—Arista NetworksEOSCWE-354Security Advisory 0160
CVE-2026-734607.0—Arista NetworksEOSCWE-863Security Advisory 0160
CVE-2026-766937.0—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-400Unauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect…
CVE-2026-768567.0—NetcoreNR255-VCWE-352Netcore NR255-V 1.5.130703 Cross-Site Request Forgery in WAN/LAN Configuratio…
CVE-2026-830157.0—Oracle CorporationPeopleSoft Enterprise PeopleTools—Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop…
CVE-2026-831507.0—Oracle CorporationOracle Application Testing Suite—Vulnerability in Oracle Application Testing Suite. The supported version that…
CVE-2026-832317.0—Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-832397.0—Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience Manager—Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-832527.0—Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience Manager—Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-833167.0—Oracle CorporationOracle Business Intelligence Enterprise Edition—Vulnerability in the Oracle Business Intelligence Enterprise Edition product …
CVE-2026-833687.0—Oracle CorporationOracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM—Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Editio…
CVE-2026-872407.0—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-196416.9—Arista NetworksEOSCWE-116On affected platforms running Arista EOS with password authentication configu…
CVE-2026-477806.9—free5gcfree5gcCWE-20free5GC: UDR Improper ueId validation in free5GC EE subscription handlers all…
CVE-2026-539416.9—inspektor-gadgetinspektor-gadgetCWE-770Inspektor Gadget Uprobe gadgets: unprivileged container's ld.so.cache causes …
CVE-2026-556176.9—hydro-devHydroCWE-613Hydro: Insufficient session expiration when recreating sessions
CVE-2026-557016.9—open-telemetryopentelemetry-collector-contribCWE-863OpenTelemetry githubreceiver silently ignores configured required_headers aut…
CVE-2026-574426.9—bitbonsaimcpvaultCWE-22MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) onl…
CVE-2026-768656.9—NetcoreNR255-VCWE-476Netcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in Q…
CVE-2026-768686.9—NetcoreNR255-VCWE-476Netcore NR255-V 1.5.130703 NULL Pointer Dereference in route_policy_add.cgi v…
CVE-2026-890276.9—miniOrangeJWT Authentication for WP REST APIsCWE-306miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade
CVE-2026-904396.9—F5NGINX PlusCWE-122NGINX ngx_http_v3_module vulnerability
CVE-2026-919586.9—FreeRDPFreeRDPCWE-125FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index
CVE-2026-919666.9—WWBNAVideoCWE-918AVideo through 29.0 Unauthenticated SSRF via Host Header
CVE-2026-919976.9—evolution-foundationevolution-apiCWE-697evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass
CVE-2026-920036.9—MISPMISPCWE-400MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion
CVE-2026-921146.9—a2ui-projecta2uiCWE-400a2ui-project a2ui Basic Catalog safe_regex.ts redos
CVE-2026-557706.8—openbaoopenbaoCWE-90OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-692146.8—http4shttp4sCWE-384Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
CVE-2026-692156.8—http4shttp4sCWE-565Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
CVE-2026-739656.8—Oracle CorporationSiebel CRM Deployment—Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp…
CVE-2026-830766.8—Oracle CorporationOracle HR Intelligence—Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit…
CVE-2026-832786.8—Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-834416.8—Oracle CorporationOracle Product Hub—Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c…
CVE-2026-834916.8—Oracle CorporationOracle iRecruitment—Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (…
CVE-2026-872526.8—Oracle CorporationOracle Agile PLM—Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-553176.7—GoogleAndroidCWE-20In printf of printf.c, there is a possible out-of-bounds write due to imprope…
CVE-2026-553326.7—GoogleAndroidCWE-20In multiple locations, there is a possible out-of-bounds write due to imprope…
CVE-2026-553656.7—GoogleAndroidCWE-787In multiple functions of remap.c, there is a possible out-of-bounds write due…
CVE-2026-568796.7—GoogleAndroidCWE-441In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due…
CVE-2026-569226.7—GoogleAndroidCWE-441In CPM, there is a possible permission bypass due to a confused deputy. This …
CVE-2026-569726.7—GoogleAndroidCWE-787In multiple locations, there is a possible out-of-bounds write due to an inco…
CVE-2026-569896.7—GoogleAndroidCWE-787In multiple locations, there is a possible out-of-bounds write due to a missi…
CVE-2026-569926.7—GoogleAndroidCWE-441In multiple files, there is a possible permission bypass due to a confused de…
CVE-2026-570356.7—GoogleAndroidCWE-787In multiple locations, there is a possible out-of-bounds write due to a missi…
CVE-2026-586986.7—GoogleAndroidCWE-441In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission …
CVE-2026-587166.7—GoogleAndroidCWE-362In multiple locations, there is a possible time-of-check to time-of-use due t…
CVE-2026-587186.7—GoogleAndroidCWE-20In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of…
CVE-2026-587266.7—GoogleAndroidCWE-693In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a mis…
CVE-2026-587396.7—GoogleAndroidCWE-441In platform_msg_handler_init of default_msg_handlers.c, there is a possible c…
CVE-2026-587476.7—GoogleAndroidCWE-693In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass du…
CVE-2026-587516.7—GoogleAndroidCWE-416In multiple functions of arm-smmu-v3.c, there is a possible use-after-free du…
CVE-2026-587556.7—GoogleAndroidCWE-693In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation o…
CVE-2026-587656.7—GoogleAndroidCWE-693In GPU, there is a possible permission bypass due to a logic error in the cod…
CVE-2026-587676.7—GoogleAndroidCWE-693In multiple functions of arm-smmu-v3.c, there is a possible escalation of pri…
CVE-2026-587736.7—GoogleAndroidCWE-787In link_load_gnss_image of link_device.c, there is a possible out-of-bounds w…
CVE-2026-872486.7—Oracle CorporationOracle Hyperion Financial Management—Vulnerability in the Oracle Hyperion Financial Management product of Oracle H…
CVE-2026-889226.7—HashiCorpShared libraryCWE-281Go-getter vulnerable to a privilege escalation issue in its archive decompres…
CVE-2026-766946.6—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-269Authenticated Privilege Escalation Vulnerability in the Command Line Interfac…
CVE-2026-17596.5—SecomeaGateManagerCWE-280Improper handling of insufficient permissions or privileges vulnerability in …
CVE-2026-118646.5—IBMCloud Pak for Business AutomationCWE-643Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine…
CVE-2026-489876.5—pyloadpyloadCWE-400pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventMan…
CVE-2026-540506.5—sakaiprojectsakaiCWE-639Sakai: IDOR in Profile Image Deletion Allows Any Authenticated User to Delete…
CVE-2026-541686.5—tektoncdpipelines-as-codeCWE-269Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized…
CVE-2026-546886.5—ihor-sokoliukmcp-searxngCWE-918mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by …
CVE-2026-553066.5—GoogleAndroidCWE-20In Cellular Modem, there is a possible denial of service due to improper inpu…
CVE-2026-557766.5—openbaoopenbaoCWE-617OpenBao: Transit secrets engine crashes on key creation with `derived: true` …
CVE-2026-568306.5—shopperlabsshopperCWE-862Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still…
CVE-2026-568316.5—shopperlabsshopperCWE-20Shopper: Negative discount values accepted and propagated through order calcu…
CVE-2026-570086.5—GoogleAndroidCWE-20In Modem, there is a possible information disclosure due to improper input va…
CVE-2026-591576.5—ncarlierwebhookdCWE-290webhookd: Unrestricted HTTP Header to Shell Variable Injection
CVE-2026-625976.5—Oracle CorporationOracle Enterprise Manager Base Platform—Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl…
CVE-2026-707556.5—Oracle CorporationOracle Web Applications Desktop Integrator—Vulnerability in the Oracle Web Applications Desktop Integrator product of Or…
CVE-2026-734376.5—Arista NetworksEOSCWE-345On affected platforms running Arista EOS with Dynamic Host Configuration Prot…
CVE-2026-766956.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-120Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect…
CVE-2026-766966.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-400Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disrup…
CVE-2026-766976.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-200Authenticated Information Disclosure in HPE Networking EdgeConnect Enterprise…
CVE-2026-766986.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authenticated Command Injection Vulnerability leads to Denial-of-Service in H…
CVE-2026-794096.5—n/an/aCWE-639An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive…
CVE-2026-812376.5—DellWyse Management SuiteCWE-287Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improp…
CVE-2026-830976.5—Oracle CorporationOracle Forms—Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-831406.5—Oracle CorporationOracle Field Service—Vulnerability in the Oracle Field Service product of Oracle E-Business Suite …
CVE-2026-831756.5—Oracle CorporationOracle Application Object Library—Vulnerability in the Oracle Application Object Library product of Oracle E-Bu…
CVE-2026-832006.5—Oracle CorporationOracle Process Manufacturing Intelligence—Vulnerability in the Oracle Process Manufacturing Intelligence product of Ora…
CVE-2026-832506.5—Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience Manager—Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-832516.5—Oracle CorporationOracle Commerce Guided Search / Oracle Commerce Experience Manager—Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien…
CVE-2026-833476.5—Oracle CorporationOracle Database Server—Vulnerability in the Oracle Net Services component of Oracle Database Server.…
CVE-2026-834336.5—Oracle CorporationOracle Depot Repair—Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (…
CVE-2026-834436.5—Oracle CorporationOracle Assets—Vulnerability in the Oracle Assets product of Oracle E-Business Suite (compon…
CVE-2026-834606.5—Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-886186.5—n/an/aCWE-791024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerabil…
CVE-2026-127496.4—IBMCloud Pak for Business AutomationCWE-79Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine…
CVE-2026-127506.4—IBMCloud Pak for Business AutomationCWE-79Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine…
CVE-2026-156096.4—QODEBridge - Creative Multipurpose WordPress ThemeCWE-79Bridge - Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (C…
CVE-2026-569156.4—GoogleAndroidCWE-362In bigo_worker_thread of bigo.c, there is a possible escalation of privilege …
CVE-2026-569236.4—GoogleAndroidCWE-362In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corrupti…
CVE-2026-569646.4—GoogleAndroidCWE-362In multiple locations, there is a possible use-after-free due to a race condi…
CVE-2026-569886.4—GoogleAndroidCWE-362In multiple functions of bluetooth_cco.cc, there is a possible use-after-free…
CVE-2026-766996.4—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Unauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in H…
CVE-2026-830776.4—Oracle CorporationSiebel CRM Cloud Applications—Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C…
CVE-2024-583846.3—tornadowebtornadoCWE-113Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient
CVE-2026-536586.3—hyperledgerfabric-caCWE-90Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter
CVE-2026-546896.3—ihor-sokoliukmcp-searxngCWE-200mcp-searxng hardened-mode SSRF bypasses permit internal URL access
CVE-2026-734516.3—Arista NetworksEOSCWE-1419On affected platforms running Arista EOS with dual switch cards and with ingr…
CVE-2026-821906.3—j2commerce.comJ2Store extension for JoomlaCWE-1241Joomla Extension - j2commerce.com - Predictable/forgeable order access token …
CVE-2026-833546.3—Oracle CorporationOracle Coherence—Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-840486.3—joomgalleryfriends.netJoomGallery extension for JoomlaCWE-284Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file up…
CVE-2026-919916.3—tornadowebtornadoCWE-113Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs
CVE-2026-920826.3—PayaraPayara ServerCWE-307Payara Server is vulnerable to brute-force login attacks due to the absence o…
CVE-2026-545616.2—mkreymanmcp-memory-keeperCWE-22MCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_imp…
CVE-2026-494466.1—azukaarCosmos-ServerCWE-285Cosmos: Authentication bypass via forward-auth header smuggling on Constellat…
CVE-2026-547246.1—kiwitcmsKiwiCWE-601Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmati…
CVE-2026-871696.1—Oracle CorporationOracle Contract Lifecycle Management for Public Sector—Vulnerability in the Oracle Contract Lifecycle Management for Public Sector p…
CVE-2026-872536.1—Oracle CorporationOracle Agile PLM—Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone…
CVE-2026-872786.1—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-872796.1—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-917866.1—Red HatRed Hat Enterprise Linux 10CWE-125Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering …
CVE-2026-558286.0—qbee-iotransportCWE-22qbee transport: Symlink-chain path traversal in tar extraction (one level out…
CVE-2026-734656.0—Arista NetworksEOSCWE-532On affected platforms running Arista EOS, under certain circumstances plainte…
CVE-2026-734666.0—Arista NetworksEOSCWE-532On affected platforms running Arista EOS, under certain circumstances plainte…
CVE-2026-734676.0—Arista NetworksEOSCWE-532On affected platforms running Arista EOS, under certain circumstances plainte…
CVE-2026-872826.0—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-872836.0—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-872856.0—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-542545.9—Cyberdrop-DLcyberdrop-dlCWE-20Cyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sites
CVE-2026-692015.9—http4shttp4sCWE-22Http4s: ResourceService and Webjar Service path escape via percent-encoded se…
CVE-2026-692065.9—http4shttp4sCWE-294Http4s: DigestAuth allows replay of captured requests
CVE-2026-692125.9—http4shttp4sCWE-200Http4s: FollowRedirect middleware leaks credentials over https->http same-aut…
CVE-2026-767005.9—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConne…
CVE-2026-767015.9—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnec…
CVE-2026-771175.9—The GNU C LibraryglibcCWE-835SHIFT_JISX0213 decoding may hang on crafted input
CVE-2026-804895.9—The GNU C LibraryglibcCWE-835EUC_JISX0213 decoding may hang on crafted input
CVE-2026-527245.8—kumahqkumaCWE-295kuma-dp connects to control plane without verifying TLS certificate when no C…
CVE-2026-555915.8—SignalKsignalk-serverCWE-918Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
CVE-2026-767025.8—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeCon…
CVE-2026-556365.7—projectcapsulecapsuleCWE-863Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namesp…
CVE-2026-569755.7—GoogleAndroidCWE-20In Cellular Modem, there is a possible denial of service due to improper inpu…
CVE-2025-113955.5—Red HatRed Hat Enterprise Linux 10CWE-277Podman: arbitrary file write when importing oci archive
CVE-2026-487225.5—nextflow-ionextflowCWE-276Nextflow: Incorrect default permissions in the nextflow auth login command
CVE-2026-501665.5—kumahqkumaCWE-295Kuma: kumactl connects to control plane without verifying TLS certificate whe…
CVE-2026-546375.5—dragonflyossdragonflyCWE-918Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled Peer…
CVE-2026-568885.5—GoogleAndroidCWE-203In multiple locations, there is a possible permission bypass due to side chan…
CVE-2026-568925.5—GoogleAndroidCWE-120In ReadDataElement of common.c, there is a possible information disclosure du…
CVE-2026-569585.5—GoogleAndroidCWE-125In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-boun…
CVE-2026-587315.5—GoogleAndroidCWE-125In multiple functions of physmem_extmem_linux.c, there is a possible out-of-b…
CVE-2026-767035.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Authenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-…
CVE-2026-767045.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-79Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect …
CVE-2026-767055.5—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-120Authenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remot…
CVE-2026-832745.5—Oracle CorporationOracle Agile PLM MCAD Connector—Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-832795.5—Oracle CorporationOracle Agile PLM MCAD Connector—Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply…
CVE-2026-918485.5—n/aWuzhiCMSCWE-74WuzhiCMS index.php getDataOfJson sql injection
CVE-2026-918555.5—n/aOpen5GSCWE-404Open5GS PFCP Message handler.c denial of service
CVE-2026-922595.5—Samsung OpensourceEscargotCWE-190Integer overflow or wraparound vulnerability in Samsung Opensource Escargot a…
CVE-2026-119185.4—IBMContextForge MCP GatewayCWE-184IBM ContextForge MCP Gateway is affected by security filter bypass via nested…
CVE-2026-127425.4—IBMBusiness Automation Workflow containers and traditionalCWE-862Multiple secuirty vulnerabilies addressed with IBM Business Automation Workfl…
CVE-2026-127515.4—IBMCloud Pak for Business AutomationCWE-80Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine…
CVE-2026-129105.4—GitLabGitLabCWE-306Missing Authentication for Critical Function in GitLab
CVE-2026-552265.4—strimzistrimzi-kafka-operatorCWE-269Strimzi: Unrestricted access to all Secrets within namespace watched by the T…
CVE-2026-692165.4—http4shttp4sCWE-444Http4s: Ember chunk parser lenience (TE.TE request smuggling)
CVE-2026-831985.4—Oracle CorporationOracle Field Service—Vulnerability in the Oracle Field Service product of Oracle E-Business Suite …
CVE-2026-833465.4—Oracle CorporationOracle Fusion Middleware Control—Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusio…
CVE-2026-834195.4—Oracle CorporationOracle Communications Cloud Native Core Security Edge Protection Proxy—Vulnerability in the Oracle Communications Cloud Native Core Security Edge Pr…
CVE-2026-834315.4—Oracle CorporationOracle Product Workbench—Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su…
CVE-2026-834885.4—Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-325995.3—gravitlnetmakerCWE-89Netmaker has a boolean‑based SQL Injection
CVE-2026-441635.3—fluent-plugins-nurseryfluent-plugin-opentelemetryCWE-409fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and D…
CVE-2026-500245.3—WangYihangGitHackerCWE-22GitHacker: Path traversal in ref/hash parsing enables existence oracle and he…
CVE-2026-553755.3—jleehrcanto-saas-apiCWE-209canto-saas-api: OAuth credentials exposed in URL query string and exception m…
CVE-2026-558635.3—motioneye-projectmotioneyeCWE-862motionEye: Missing authentication on ActionHandler allows unauthenticated cam…
CVE-2026-734445.3—Arista NetworksEOSCWE-303On affected platforms running Arista EOS with VRRPv2 IP Authentication Header…
CVE-2026-767065.3—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN GatewaysCWE-200Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API…
CVE-2026-768635.3—NetcoreNR255-VCWE-863Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via QoS Bandwidth…
CVE-2026-821915.3—j2commerce.comJ2Store extension for JoomlaCWE-1241Joomla Extension - j2commerce.com - Unescaped request data reflected into Pay…
CVE-2026-825675.3—mySCADA TechnologiesmySCADA myPROCWE-862mySCADA myPRO Manager Missing Authorization
CVE-2026-828375.3—GitLabGitLabCWE-201Insertion of Sensitive Information Into Sent Data in GitLab
CVE-2026-831095.3—Oracle CorporationOracle Forms—Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon…
CVE-2026-834585.3—Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-834595.3—Oracle CorporationHelidonCWE-400Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-834805.3—Oracle CorporationHelidon—Vulnerability in the Helidon product of Oracle Fusion Middleware (component: …
CVE-2026-872675.3—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-917445.3—GoogleChromeCWE-367Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153…
CVE-2026-919225.3—steedossteedos-platformCWE-79Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render
CVE-2026-919625.3—FreeRDPFreeRDPCWE-131FreeRDP before 3.31.0 Integer Overflow via audin Apple backends
CVE-2026-919675.3—WWBNAVideoCWE-918AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL
CVE-2026-919805.3—go-vikunjavikunjaCWE-200vikunja before 2.6.0 Team Enumeration via Project Share
CVE-2026-919815.3—go-vikunjavikunjaCWE-200Vikunja before 2.6.0 User Enumeration via v2 API
CVE-2026-919825.3—go-vikunjavikunjaCWE-522Vikunja before 2.6.0 TOTP Secret Disclosure via API
CVE-2026-919835.3—go-vikunjavikunjaCWE-863Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter
CVE-2026-919845.3—go-vikunjavikunjaCWE-639Vikunja before 2.6.0 Broken Object-Level Authorization via task-position
CVE-2026-919865.3—GitoxideLabsgitoxideCWE-74gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection
CVE-2026-919935.3—dromaraJpomCWE-639Jpom through 2.11.12 Workspace Isolation Bypass via /build/branch-list
CVE-2026-921845.3—ag-ui-protocolag-uiCWE-918ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen serve…
CVE-2026-922555.3—NetcoreNR255-VCWE-125Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via …
CVE-2026-767965.1—Newell BrandsDYMO Connect DesktopCWE-73Newell Brands DYMO Connect Desktop improper file path validation
CVE-2026-768675.1—NetcoreNR255-VCWE-79Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in Route/NAT Configura…
CVE-2026-768725.1—NetcoreNR255-VCWE-79Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Managemen…
CVE-2026-768735.1—NetcoreNR255-VCWE-79Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP and ARP Hostn…
CVE-2026-877935.1—Developers Italiadesign-scuole-wordpress-themeCWE-79Reflected XSS in WordPress theme design-scuole-wordpress-theme
CVE-2026-893075.1—Developers Italiadesign-scuole-wordpress-themeCWE-601HTML injection allows open redirection in WordPress theme design-scuole-wordp…
CVE-2026-917175.1—GoogleChromeCWE-862Missing authorization in Android in Google Chrome on on Android prior to 153.…
CVE-2026-919425.1—unclecodecrawl4aiCWE-79crawl4ai before 0.9.3 Cross-Site Scripting via innerHTML
CVE-2026-919445.1—unclecodecrawl4aiCWE-79crawl4ai before 0.9.3 DOM-based XSS via Playground UI
CVE-2026-920025.1—MISPMISPCWE-778MISP: Authentication failure logging suppressed during Redis unavailability
CVE-2026-922345.1—WebkulQloAppsCWE-79QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors
CVE-2026-922575.1—NetcoreNR255-VCWE-79Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in L7 Content Manageme…
CVE-2026-487374.9—pyloadpyloadCWE-918pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal…
CVE-2026-442824.8—decidimdecidimCWE-79Election question titles allow stored script execution
CVE-2026-472154.8—sylabssingularityCWE-22Singularity: Incorrect path matching for 'limit container paths' directive
CVE-2026-487854.8—apptainerapptainerCWE-22Apptainer: Incorrect path matching for 'limit container paths' directive
CVE-2026-553744.8—jleehrcanto-saas-apiCWE-74canto-saas-api: Authenticated API requests can be redirected via unencoded pa…
CVE-2026-692114.8—http4shttp4sCWE-113Http4s: Set-Cookie rendering does not escape attribute delimiters
CVE-2026-768584.8—NetcoreNR255-VCWE-79Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DDNS eval() in ddn…
CVE-2026-768644.8—NetcoreNR255-VCWE-79Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via Unescaped QoS Rule…
CVE-2026-864724.8—fast-urifast-uriCWE-178fast-uri vulnerable to inconsistent host case normalization via percent-encod…
CVE-2026-868184.8—fast-urifast-uriCWE-172fast-uri vulnerable to mailto header injection via percent-encoded field-name…
CVE-2026-581964.7—stackloktoolhiveCWE-918ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypa…
CVE-2026-917204.7—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allow…
CVE-2026-917264.7—GoogleChromeCWE-125Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.801…
CVE-2026-872754.6—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-797054.5—Red HatRed Hat Ansible Automation Platform 2CWE-22Podman: buildah: buildah/copier: directory escape via crafted tar symlinks wh…
CVE-2026-01774.4—GoogleAndroidCWE-120In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds r…
CVE-2026-01834.4—GoogleAndroidCWE-441In CPM, there is a possible information disclosure due to a confused deputy. …
CVE-2026-01974.4—GoogleAndroidCWE-200In VPU, there is a possible information dislclosure due to a logic error in t…
CVE-2026-556504.4—outerbasestudioCWE-79Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exp…
CVE-2026-569504.4—GoogleAndroidCWE-20In validate_ns_buf of mbu_class.rs, there is a possible information disclosur…
CVE-2026-570064.4—GoogleAndroidCWE-693In acfw_ffa.c, there is a possible secret read due to a logic error in the co…
CVE-2026-587214.4—GoogleAndroidCWE-457In multiple locations, there is a possible information disclosure due to unin…
CVE-2026-796994.4—Red HatRed Hat Ansible Automation Platform 2CWE-59Podman: buildah: skopeo: containers/storage: malicious tar whiteout header al…
CVE-2026-872744.4—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-539544.3—bugsinkbugsinkCWE-400Bugsink: DOS using large numbers of event tags
CVE-2026-545034.3—ploneplone.app.textfieldCWE-80plone.app.textfield: Stored XSS by spoofing mime type
CVE-2026-767074.3—Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways—Unauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN G…
CVE-2026-834164.3—Oracle CorporationOracle Coherence—Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-917404.3—GoogleChromeCWE-908Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowe…
CVE-2026-917464.3—GoogleChromeCWE-190Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allow…
CVE-2026-872804.2—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-195044.0—Fabric.jsFabric.jsCWE-918Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability
CVE-2026-919263.7—Red HatRed Hat Enterprise Linux 8CWE-401Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicat…
CVE-2026-872813.2—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-872843.2—Oracle CorporationOracle VM VirtualBox—Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c…
CVE-2026-833693.1—Oracle CorporationOracle Access Manager—Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar…
CVE-2026-917083.1—GoogleChromeCWE-367Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a r…
CVE-2026-917473.1—GoogleChromeCWE-416Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remo…
CVE-2026-447782.9—inspektor-gadgetinspektor-gadgetCWE-20Inspektor Gadget: Unprivileged container can crash USDT note parser via craft…
CVE-2026-492542.9—dragonflyossdragonflyCWE-200Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated…
CVE-2026-544502.9—stackloktoolhiveCWE-918ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48),…
CVE-2026-834142.5—Oracle CorporationOracle Coherence—Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-557752.3—openbaoopenbaoCWE-285OpenBao's System Backend allows Unauthorized Management of the containing Nam…
CVE-2026-685322.3—Concrete CMSConcrete CMSCWE-352Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type D…
CVE-2026-685332.3—Concrete CMSConcrete CMSCWE-862Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File …
CVE-2026-685342.3—Concrete CMSConcrete CMSCWE-79Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express en…
CVE-2026-819192.3—Concrete CMSConcrete CMSCWE-352Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) i…
CVE-2026-819202.3—Concrete CMSConcrete CMSCWE-352Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) i…
CVE-2026-819212.3—Concrete CMSConcrete CMSCWE-862In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Accoun…
CVE-2026-919572.3—FreeRDPFreeRDPCWE-416FreeRDP before 3.31.0 Use-After-Free via smartcard worker
CVE-2026-184212.1—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authoriza…
CVE-2026-184222.1—Concrete CMSConcrete CMSCWE-862Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Au…
CVE-2026-184232.1—Concrete CMSConcrete CMSCWE-639Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object refe…
CVE-2026-184242.1—Concrete CMSConcrete CMSCWE-918Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote…
CVE-2026-184252.1—Concrete CMSConcrete CMSCWE-352IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUp…
CVE-2026-557742.1—openbaoopenbaoCWE-863OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{r…
CVE-2026-685292.1—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entr…
CVE-2026-685302.1—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance A…
CVE-2026-685312.1—Concrete CMSConcrete CMSCWE-405Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via…
CVE-2026-819222.1—Concrete CMSConcrete CMSCWE-862"In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap p…
CVE-2026-819232.1—Concrete CMSConcrete CMSCWE-862Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta…
CVE-2026-819242.1—Concrete CMSConcrete CMSCWE-352Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) i…
CVE-2026-819252.1—Concrete CMSConcrete CMSCWE-79Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS…
CVE-2026-918492.1—n/aWuzhiCMSCWE-284WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload
CVE-2026-918532.1—TOTOLINKX5000RCWE-77TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection
CVE-2026-918542.1—code-projectsRecord Management SystemCWE-79code-projects Record Management System reg.php cross site scripting
CVE-2026-184262.0—Concrete CMSConcrete CMSCWE-862Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows a…
CVE-2026-819262.0—Concrete CMSConcrete CMSCWE-79Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the…
CVE-2026-834131.9—Oracle CorporationOracle Coherence—Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co…
CVE-2026-819271.8—Concrete CMSConcrete CMSCWE-79Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reje…
CVE-2026-918421.2—OpenBankProjectOBP-APICWE-20OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization
CVE-2026-918350.9—OpenClawClawScanCWE-436OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretati…
CVE-2026-918360.9—OpenClawClawScanCWE-1023OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with…
CVE-2026-556300.0—kiwitcmsKiwiCWE-79Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & Tes…
CVE-2026-0179await—GoogleAndroid—In Bootloader, there is a possible permission bypass due to a missing permiss…
CVE-2026-0186await—GoogleAndroid—In ac_init_one_sswrp of init.c, there is a possible escalation of privilege d…
CVE-2026-0187await—GoogleAndroid—In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation…
CVE-2026-0189await—GoogleAndroid—In ac_init_policy of init.c, there is a possible permission bypass due to a l…
CVE-2026-0192await—GoogleAndroid—In Bootloader, there is a possible escalation of privilege due to a missing p…
CVE-2026-0194await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to an intege…
CVE-2026-11921await—IBMVerify Identity AccessCWE-522Security vulnerabilities have been addressed in IBM Verify Identity Access an…
CVE-2026-11927await—IBMVerify Identity AccessCWE-74Security vulnerabilities have been addressed in IBM Verify Identity Access an…
CVE-2026-11928await—IBMVerify Identity AccessCWE-787Security vulnerabilities have been addressed in IBM Verify Identity Access an…
CVE-2026-12101await—IBMVerify Identity AccessCWE-289Security vulnerabilities have been addressed in IBM Verify Identity Access an…
CVE-2026-13327await—DevolutionsServerCWE-295Improper certificate validation on LDAPS connections to Active Directory in D…
CVE-2026-25825await—n/an/a—An issue was discovered in Keyfactor SignServer before 7.6.0. The output file…
CVE-2026-25826await—n/an/a—An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute A…
CVE-2026-25827await—n/an/a—An issue was discovered in Keyfactor SignServer before 7.6.0. A number of pro…
CVE-2026-37152await—n/an/a—TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded…
CVE-2026-39038await—n/an/a—BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scriptin…
CVE-2026-39039await—n/an/a—In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT aut…
CVE-2026-39040await—n/an/a—BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting…
CVE-2026-51133await—n/an/a—Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillan…
CVE-2026-51134await—n/an/a—The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerab…
CVE-2026-55301await—GoogleAndroid—In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due t…
CVE-2026-55302await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to a logic e…
CVE-2026-55304await—GoogleAndroid—In addr_remap_address_map of remap.c, there is a possible escalation of privi…
CVE-2026-55359await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to a logic e…
CVE-2026-55366await—GoogleAndroid—In IP Multimedia Subsystem, there is a possible authentication bypass due to …
CVE-2026-56881await—GoogleAndroid—In enable_segment of remap.c, there is a possible permission bypass due to a …
CVE-2026-56889await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to an intege…
CVE-2026-56907await—GoogleAndroid—In VPU, there is a possible shared memory overwrite due to improper input val…
CVE-2026-56914await—GoogleAndroid—In multiple locations, there is a possible use-after-free due to improper loc…
CVE-2026-56932await—GoogleAndroid—In Trusted Execution Environment, there is a possible memory corruption due t…
CVE-2026-56941await—GoogleAndroid—In multiple functions of fpc_tee_hal.c, there is a possible use-after-free du…
CVE-2026-56960await—GoogleAndroid—In multiple locations, there is a possible use-after-free due to a logic erro…
CVE-2026-56970await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to a missing…
CVE-2026-56973await—GoogleAndroid—In multiple locations, there is a possible escalation of privilege due to a l…
CVE-2026-56978await—GoogleAndroid—In get_global_config_item_addr of gc.c, there is a possible out-of-bounds rea…
CVE-2026-56979await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to a logic e…
CVE-2026-56982await—GoogleAndroid—In VPU, there is a possible permission bypass due to a missing permission che…
CVE-2026-56985await—GoogleAndroid—In multiple files, there is a possible way to obtain signatures due to type c…
CVE-2026-56986await—GoogleAndroid—In multiple files, there is a possible out-of-bounds read due to type confusi…
CVE-2026-57012await—GoogleAndroid—In the Setup Wizard, there is a possible remote package install due to a miss…
CVE-2026-57042await—GoogleAndroid—In multiple functions of DreamPickerReceiver.kt, there is a possible permissi…
CVE-2026-58678await—GoogleAndroid—In Bootloader, there is a possible permission bypass due to a logic error in …
CVE-2026-58679await—GoogleAndroid—In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer ove…
CVE-2026-58691await—GoogleAndroid—In FsmReleaseKey of fsm.c, there is a possible permission bypass due to impro…
CVE-2026-58695await—GoogleAndroid—In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible esc…
CVE-2026-58699await—GoogleAndroid—In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds r…
CVE-2026-79303await—n/an/a—kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dyn…
CVE-2026-79411await—n/an/a—Incorrect privilege assignment in the admin user-management component of Webk…
CVE-2026-79551await—n/an/a—Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contai…
CVE-2026-84850await—DevolutionsServerCWE-295Improper certificate validation in the shared HTTP client used by synchroniza…
CVE-2026-88617await—n/an/a—SmartAdmin v3.30.0 contains an authorization flaw in the configuration query …
CVE-2026-88620await—n/an/a—SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authori…
CVE-2026-88621await—n/an/a—OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability…
CVE-2026-88742await—n/an/a—Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in…
CVE-2026-88743await—n/an/a—Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in…
CVE-2026-90969await—DevolutionsServerCWE-284Improper access control in the vault entry listing feature in Devolutions Ser…
CVE-2026-90971await—DevolutionsServerCWE-863Server-Side Request Forgery (SSRF) in the VMware synchronization feature in D…
CVE-2026-91711await—GoogleChromeCWE-787Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 …
CVE-2026-91713await—GoogleChromeCWE-862Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allo…
CVE-2026-91714await—GoogleChromeCWE-203Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allow…
CVE-2026-91715await—GoogleChromeCWE-843Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allow…
CVE-2026-91716await—GoogleChromeCWE-416Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remo…
CVE-2026-91719await—GoogleChromeCWE-94Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remot…
CVE-2026-91722await—GoogleChromeCWE-416Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a rem…
CVE-2026-91723await—GoogleChromeCWE-362Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allo…
CVE-2026-91725await—GoogleChromeCWE-203Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed…
CVE-2026-91729await—GoogleChromeCWE-416Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 …
CVE-2026-91730await—GoogleChromeCWE-459Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 al…
CVE-2026-91732await—GoogleChromeCWE-862Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 …
CVE-2026-91737await—GoogleChromeCWE-416Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remot…
CVE-2026-91738await—GoogleChromeCWE-20Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 al…
CVE-2026-91739await—GoogleChromeCWE-862Missing authorization in Transactions Platform in Google Chrome prior to 153.…
CVE-2026-91742await—GoogleChromeCWE-441Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.80…
CVE-2026-91745await—GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote…
CVE-2026-92005await—MozillaFirefox—Use-after-free in the Audio/Video: Web Codecs component
CVE-2026-92016await—MozillaFirefox—Use-after-free in the Disability Access APIs component
CVE-2026-92018await—MozillaFirefox—Sandbox escape in the DOM: Core & HTML component
CVE-2026-92019await—MozillaFirefox—Mitigation bypass in the Remote Settings Client component
CVE-2026-92021await—MozillaFirefox—Use-after-free in the JavaScript Engine: JIT component
CVE-2026-92022await—MozillaFirefox—Use-after-free in the DOM: HTML Parser component
CVE-2026-92023await—MozillaFirefox—Use-after-free in the XML component
CVE-2026-92024await—MozillaFirefox—Use-after-free in the SVG component
CVE-2026-92025await—MozillaFirefox—Use-after-free in the DOM: Navigation component
CVE-2026-92026await—MozillaFirefox—Use-after-free in the Networking component
CVE-2026-92027await—MozillaFirefox—Use-after-free in the DOM: Streams component
CVE-2026-92028await—MozillaFirefox—Use-after-free in the DOM: Core & HTML component
CVE-2026-92029await—MozillaFirefox—Use-after-free in the SVG component
CVE-2026-92030await—MozillaFirefox—Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
CVE-2026-92031await—MozillaFirefox—Information disclosure in the Graphics: ImageLib component
CVE-2026-92032await—MozillaFirefox—Sandbox escape due to invalid pointer in the Graphics component
CVE-2026-92034await—MozillaFirefox—Site isolation issue in the Graphics component
CVE-2026-92035await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Graphics component
CVE-2026-92036await—MozillaFirefox—Incorrect boundary conditions in the Networking: HTTP component
CVE-2026-92037await—MozillaFirefox—Incorrect boundary conditions in the DOM: Animation component
CVE-2026-92038await—MozillaFirefox—Mitigation bypass in the Remote Settings Client component
CVE-2026-92039await—MozillaFirefox—Mitigation bypass in the DOM: Notifications component
CVE-2026-92040await—MozillaFirefox—Use-after-free in the JavaScript: WebAssembly component
CVE-2026-92041await—MozillaFirefox—Mitigation bypass in the DOM: Networking component
CVE-2026-92042await—MozillaFirefox—Race condition in the DOM: Content Processes component
CVE-2026-92044await—MozillaFirefox—Information disclosure in the Networking: HTTP component
CVE-2026-92045await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVE-2026-92046await—MozillaFirefox—Use-after-free in the Graphics component
CVE-2026-92048await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp…
CVE-2026-92049await—MozillaFirefox—Use-after-free in the Widget: Win32 component
CVE-2026-92050await—MozillaFirefox—Sandbox escape due to race condition in the XPConnect component
CVE-2026-92051await—MozillaFirefox—Spoofing issue due to invalid pointer in the Graphics component
CVE-2026-92056await—MozillaFirefox—Use-after-free in the Graphics: Text component
CVE-2026-92057await—MozillaFirefox—Mitigation bypass in the Enterprise Policies component
CVE-2026-92058await—MozillaFirefox—Use-after-free in the Graphics component
CVE-2026-92059await—MozillaFirefox—Incorrect boundary conditions in the DOM: Editor component
CVE-2026-92060await—MozillaFirefox—Use-after-free in the Internationalization component
CVE-2026-92061await—MozillaFirefox—Incorrect boundary conditions in the Security: Process Sandboxing component
CVE-2026-92063await—MozillaFirefox—Denial-of-service in the Audio/Video component
CVE-2026-92064await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp…
CVE-2026-92065await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp…
CVE-2026-92066await—MozillaFirefox—Sandbox escape in the Profile Backup component
CVE-2026-92067await—MozillaFirefox—Use-after-free in the Widget: Gtk component
CVE-2026-92068await—MozillaFirefox—Site isolation issue in the Reader Mode component
CVE-2026-92069await—MozillaFirefox—Spoofing issue in the DOM: Navigation component
CVE-2026-92070await—MozillaFirefox—Information disclosure in the Networking component
CVE-2026-92071await—MozillaFirefox—Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp…
CVE-2026-92072await—MozillaFirefox—Incorrect boundary conditions in the Safe Browsing component
CVE-2026-92074await—MozillaFirefox—Mitigation bypass in the Popup Blocker component
CVE-2026-92075await—MozillaFirefox—Mitigation bypass in the Networking component
CVE-2026-92076await—MozillaFirefox—Incorrect boundary conditions in the Networking component
CVE-2026-92077await—MozillaFirefox—Denial-of-service in the SVG component
CVE-2026-92078await—MozillaFirefox—Denial-of-service in the Security component
CVE-2026-92079await—MozillaFirefox—Mitigation bypass in the Widget: Win32 component
CVE-2026-92237await—DevolutionsPowerShell UniversalCWE-532Insertion of sensitive information into log file in the slow query logging fe…
CVE-2026-92238await—MozillaThunderbird—Ambiguous parsing of mail headers
CVE-2026-92239await—MozillaThunderbird—Buffer overrun in IMAP
CVE-2026-92240await—MozillaThunderbird—Out-of-bounds read in IMAP response parser