Security Box Score — September 15, 2026 — page 3
Edition of September 15, 2026, continued — page 3 of 3. Back to page 1 · page 2
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-91963 | 7.1 | — | FreeRDP | FreeRDP | CWE-457 | FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc |
| CVE-2026-91968 | 7.1 | — | go-vikunja | vikunja | CWE-674 | vikunja before 2.6.0 Denial of Service via unbounded filter recursion |
| CVE-2026-91969 | 7.1 | — | go-vikunja | vikunja | CWE-400 | vikunja before 2.6.0 Resource Exhaustion via CSV Migration |
| CVE-2026-91970 | 7.1 | — | go-vikunja | vikunja | CWE-770 | Vikunja before 2.6.0 Resource Exhaustion via Planka Migration |
| CVE-2026-91971 | 7.1 | — | go-vikunja | vikunja | CWE-400 | Vikunja before 2.6.0 Denial of Service via Avatar Upload |
| CVE-2026-91979 | 7.1 | — | go-vikunja | vikunja | CWE-400 | Vikunja before 2.6.0 Denial of Service via Decompression Bomb |
| CVE-2026-91987 | 7.1 | — | dep0we | atomic-agents-stack | CWE-770 | atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model |
| CVE-2026-91994 | 7.1 | — | semaphoreui | semaphore | CWE-862 | Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests |
| CVE-2026-92256 | 7.1 | — | Netcore | NR255-V | CWE-522 | Netcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_… |
| CVE-2026-12150 | 7.0 | — | IBM | MQ | CWE-121 | IBM MQ queue manager is vulnerable to denial of service |
| CVE-2026-58701 | 7.0 | — | Android | CWE-362 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds … | |
| CVE-2026-58724 | 7.0 | — | Android | CWE-362 | In multiple locations, there is a possible use-after-free due to a race condi… | |
| CVE-2026-58728 | 7.0 | — | Android | CWE-362 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race c… | |
| CVE-2026-58734 | 7.0 | — | Android | CWE-362 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bound… | |
| CVE-2026-73446 | 7.0 | — | Arista Networks | EOS | CWE-696 | Security Advisory 0160 |
| CVE-2026-73459 | 7.0 | — | Arista Networks | EOS | CWE-354 | Security Advisory 0160 |
| CVE-2026-73460 | 7.0 | — | Arista Networks | EOS | CWE-863 | Security Advisory 0160 |
| CVE-2026-76693 | 7.0 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-400 | Unauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect… |
| CVE-2026-76856 | 7.0 | — | Netcore | NR255-V | CWE-352 | Netcore NR255-V 1.5.130703 Cross-Site Request Forgery in WAN/LAN Configuratio… |
| CVE-2026-83015 | 7.0 | — | Oracle Corporation | PeopleSoft Enterprise PeopleTools | — | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle Peop… |
| CVE-2026-83150 | 7.0 | — | Oracle Corporation | Oracle Application Testing Suite | — | Vulnerability in Oracle Application Testing Suite. The supported version that… |
| CVE-2026-83231 | 7.0 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83239 | 7.0 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83252 | 7.0 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83316 | 7.0 | — | Oracle Corporation | Oracle Business Intelligence Enterprise Edition | — | Vulnerability in the Oracle Business Intelligence Enterprise Edition product … |
| CVE-2026-83368 | 7.0 | — | Oracle Corporation | Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM | — | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Editio… |
| CVE-2026-87240 | 7.0 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-19641 | 6.9 | — | Arista Networks | EOS | CWE-116 | On affected platforms running Arista EOS with password authentication configu… |
| CVE-2026-47780 | 6.9 | — | free5gc | free5gc | CWE-20 | free5GC: UDR Improper ueId validation in free5GC EE subscription handlers all… |
| CVE-2026-53941 | 6.9 | — | inspektor-gadget | inspektor-gadget | CWE-770 | Inspektor Gadget Uprobe gadgets: unprivileged container's ld.so.cache causes … |
| CVE-2026-55617 | 6.9 | — | hydro-dev | Hydro | CWE-613 | Hydro: Insufficient session expiration when recreating sessions |
| CVE-2026-55701 | 6.9 | — | open-telemetry | opentelemetry-collector-contrib | CWE-863 | OpenTelemetry githubreceiver silently ignores configured required_headers aut… |
| CVE-2026-57442 | 6.9 | — | bitbonsai | mcpvault | CWE-22 | MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) onl… |
| CVE-2026-76865 | 6.9 | — | Netcore | NR255-V | CWE-476 | Netcore NR255-V 1.5.130703 NULL Pointer Dereference via Unchecked atoi() in Q… |
| CVE-2026-76868 | 6.9 | — | Netcore | NR255-V | CWE-476 | Netcore NR255-V 1.5.130703 NULL Pointer Dereference in route_policy_add.cgi v… |
| CVE-2026-89027 | 6.9 | — | miniOrange | JWT Authentication for WP REST APIs | CWE-306 | miniOrange JWT Authentication for WP REST APIs < 4.8.0 Authentication Downgrade |
| CVE-2026-90439 | 6.9 | — | F5 | NGINX Plus | CWE-122 | NGINX ngx_http_v3_module vulnerability |
| CVE-2026-91958 | 6.9 | — | FreeRDP | FreeRDP | CWE-125 | FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index |
| CVE-2026-91966 | 6.9 | — | WWBN | AVideo | CWE-918 | AVideo through 29.0 Unauthenticated SSRF via Host Header |
| CVE-2026-91997 | 6.9 | — | evolution-foundation | evolution-api | CWE-697 | evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass |
| CVE-2026-92003 | 6.9 | — | MISP | MISP | CWE-400 | MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion |
| CVE-2026-92114 | 6.9 | — | a2ui-project | a2ui | CWE-400 | a2ui-project a2ui Basic Catalog safe_regex.ts redos |
| CVE-2026-55770 | 6.8 | — | openbao | openbao | CWE-90 | OpenBao: LDAPi ldaputil (wrong escape func) |
| CVE-2026-69214 | 6.8 | — | http4s | http4s | CWE-384 | Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain |
| CVE-2026-69215 | 6.8 | — | http4s | http4s | CWE-565 | Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin |
| CVE-2026-73965 | 6.8 | — | Oracle Corporation | Siebel CRM Deployment | — | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-83076 | 6.8 | — | Oracle Corporation | Oracle HR Intelligence | — | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suit… |
| CVE-2026-83278 | 6.8 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83441 | 6.8 | — | Oracle Corporation | Oracle Product Hub | — | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (c… |
| CVE-2026-83491 | 6.8 | — | Oracle Corporation | Oracle iRecruitment | — | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (… |
| CVE-2026-87252 | 6.8 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-55317 | 6.7 | — | Android | CWE-20 | In printf of printf.c, there is a possible out-of-bounds write due to imprope… | |
| CVE-2026-55332 | 6.7 | — | Android | CWE-20 | In multiple locations, there is a possible out-of-bounds write due to imprope… | |
| CVE-2026-55365 | 6.7 | — | Android | CWE-787 | In multiple functions of remap.c, there is a possible out-of-bounds write due… | |
| CVE-2026-56879 | 6.7 | — | Android | CWE-441 | In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due… | |
| CVE-2026-56922 | 6.7 | — | Android | CWE-441 | In CPM, there is a possible permission bypass due to a confused deputy. This … | |
| CVE-2026-56972 | 6.7 | — | Android | CWE-787 | In multiple locations, there is a possible out-of-bounds write due to an inco… | |
| CVE-2026-56989 | 6.7 | — | Android | CWE-787 | In multiple locations, there is a possible out-of-bounds write due to a missi… | |
| CVE-2026-56992 | 6.7 | — | Android | CWE-441 | In multiple files, there is a possible permission bypass due to a confused de… | |
| CVE-2026-57035 | 6.7 | — | Android | CWE-787 | In multiple locations, there is a possible out-of-bounds write due to a missi… | |
| CVE-2026-58698 | 6.7 | — | Android | CWE-441 | In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission … | |
| CVE-2026-58716 | 6.7 | — | Android | CWE-362 | In multiple locations, there is a possible time-of-check to time-of-use due t… | |
| CVE-2026-58718 | 6.7 | — | Android | CWE-20 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of… | |
| CVE-2026-58726 | 6.7 | — | Android | CWE-693 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a mis… | |
| CVE-2026-58739 | 6.7 | — | Android | CWE-441 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible c… | |
| CVE-2026-58747 | 6.7 | — | Android | CWE-693 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass du… | |
| CVE-2026-58751 | 6.7 | — | Android | CWE-416 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free du… | |
| CVE-2026-58755 | 6.7 | — | Android | CWE-693 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation o… | |
| CVE-2026-58765 | 6.7 | — | Android | CWE-693 | In GPU, there is a possible permission bypass due to a logic error in the cod… | |
| CVE-2026-58767 | 6.7 | — | Android | CWE-693 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of pri… | |
| CVE-2026-58773 | 6.7 | — | Android | CWE-787 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds w… | |
| CVE-2026-87248 | 6.7 | — | Oracle Corporation | Oracle Hyperion Financial Management | — | Vulnerability in the Oracle Hyperion Financial Management product of Oracle H… |
| CVE-2026-88922 | 6.7 | — | HashiCorp | Shared library | CWE-281 | Go-getter vulnerable to a privilege escalation issue in its archive decompres… |
| CVE-2026-76694 | 6.6 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-269 | Authenticated Privilege Escalation Vulnerability in the Command Line Interfac… |
| CVE-2026-1759 | 6.5 | — | Secomea | GateManager | CWE-280 | Improper handling of insufficient permissions or privileges vulnerability in … |
| CVE-2026-11864 | 6.5 | — | IBM | Cloud Pak for Business Automation | CWE-643 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-48987 | 6.5 | — | pyload | pyload | CWE-400 | pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventMan… |
| CVE-2026-54050 | 6.5 | — | sakaiproject | sakai | CWE-639 | Sakai: IDOR in Profile Image Deletion Allows Any Authenticated User to Delete… |
| CVE-2026-54168 | 6.5 | — | tektoncd | pipelines-as-code | CWE-269 | Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized… |
| CVE-2026-54688 | 6.5 | — | ihor-sokoliuk | mcp-searxng | CWE-918 | mcp-searxng: SSRF in web_url_read: the internal-address guard is disabled by … |
| CVE-2026-55306 | 6.5 | — | Android | CWE-20 | In Cellular Modem, there is a possible denial of service due to improper inpu… | |
| CVE-2026-55776 | 6.5 | — | openbao | openbao | CWE-617 | OpenBao: Transit secrets engine crashes on key creation with `derived: true` … |
| CVE-2026-56830 | 6.5 | — | shopperlabs | shopper | CWE-862 | Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still… |
| CVE-2026-56831 | 6.5 | — | shopperlabs | shopper | CWE-20 | Shopper: Negative discount values accepted and propagated through order calcu… |
| CVE-2026-57008 | 6.5 | — | Android | CWE-20 | In Modem, there is a possible information disclosure due to improper input va… | |
| CVE-2026-59157 | 6.5 | — | ncarlier | webhookd | CWE-290 | webhookd: Unrestricted HTTP Header to Shell Variable Injection |
| CVE-2026-62597 | 6.5 | — | Oracle Corporation | Oracle Enterprise Manager Base Platform | — | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-70755 | 6.5 | — | Oracle Corporation | Oracle Web Applications Desktop Integrator | — | Vulnerability in the Oracle Web Applications Desktop Integrator product of Or… |
| CVE-2026-73437 | 6.5 | — | Arista Networks | EOS | CWE-345 | On affected platforms running Arista EOS with Dynamic Host Configuration Prot… |
| CVE-2026-76695 | 6.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-120 | Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect… |
| CVE-2026-76696 | 6.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-400 | Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disrup… |
| CVE-2026-76697 | 6.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-200 | Authenticated Information Disclosure in HPE Networking EdgeConnect Enterprise… |
| CVE-2026-76698 | 6.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Command Injection Vulnerability leads to Denial-of-Service in H… |
| CVE-2026-79409 | 6.5 | — | n/a | n/a | CWE-639 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive… |
| CVE-2026-81237 | 6.5 | — | Dell | Wyse Management Suite | CWE-287 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improp… |
| CVE-2026-83097 | 6.5 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-83140 | 6.5 | — | Oracle Corporation | Oracle Field Service | — | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite … |
| CVE-2026-83175 | 6.5 | — | Oracle Corporation | Oracle Application Object Library | — | Vulnerability in the Oracle Application Object Library product of Oracle E-Bu… |
| CVE-2026-83200 | 6.5 | — | Oracle Corporation | Oracle Process Manufacturing Intelligence | — | Vulnerability in the Oracle Process Manufacturing Intelligence product of Ora… |
| CVE-2026-83250 | 6.5 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83251 | 6.5 | — | Oracle Corporation | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | — | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experien… |
| CVE-2026-83347 | 6.5 | — | Oracle Corporation | Oracle Database Server | — | Vulnerability in the Oracle Net Services component of Oracle Database Server.… |
| CVE-2026-83433 | 6.5 | — | Oracle Corporation | Oracle Depot Repair | — | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (… |
| CVE-2026-83443 | 6.5 | — | Oracle Corporation | Oracle Assets | — | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (compon… |
| CVE-2026-83460 | 6.5 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-88618 | 6.5 | — | n/a | n/a | CWE-79 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerabil… |
| CVE-2026-12749 | 6.4 | — | IBM | Cloud Pak for Business Automation | CWE-79 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-12750 | 6.4 | — | IBM | Cloud Pak for Business Automation | CWE-79 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-15609 | 6.4 | — | QODE | Bridge - Creative Multipurpose WordPress Theme | CWE-79 | Bridge - Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (C… |
| CVE-2026-56915 | 6.4 | — | Android | CWE-362 | In bigo_worker_thread of bigo.c, there is a possible escalation of privilege … | |
| CVE-2026-56923 | 6.4 | — | Android | CWE-362 | In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corrupti… | |
| CVE-2026-56964 | 6.4 | — | Android | CWE-362 | In multiple locations, there is a possible use-after-free due to a race condi… | |
| CVE-2026-56988 | 6.4 | — | Android | CWE-362 | In multiple functions of bluetooth_cco.cc, there is a possible use-after-free… | |
| CVE-2026-76699 | 6.4 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in H… |
| CVE-2026-83077 | 6.4 | — | Oracle Corporation | Siebel CRM Cloud Applications | — | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2024-58384 | 6.3 | — | tornadoweb | tornado | CWE-113 | Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient |
| CVE-2026-53658 | 6.3 | — | hyperledger | fabric-ca | CWE-90 | Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter |
| CVE-2026-54689 | 6.3 | — | ihor-sokoliuk | mcp-searxng | CWE-200 | mcp-searxng hardened-mode SSRF bypasses permit internal URL access |
| CVE-2026-73451 | 6.3 | — | Arista Networks | EOS | CWE-1419 | On affected platforms running Arista EOS with dual switch cards and with ingr… |
| CVE-2026-82190 | 6.3 | — | j2commerce.com | J2Store extension for Joomla | CWE-1241 | Joomla Extension - j2commerce.com - Predictable/forgeable order access token … |
| CVE-2026-83354 | 6.3 | — | Oracle Corporation | Oracle Coherence | — | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-84048 | 6.3 | — | joomgalleryfriends.net | JoomGallery extension for Joomla | CWE-284 | Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file up… |
| CVE-2026-91991 | 6.3 | — | tornadoweb | tornado | CWE-113 | Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs |
| CVE-2026-92082 | 6.3 | — | Payara | Payara Server | CWE-307 | Payara Server is vulnerable to brute-force login attacks due to the absence o… |
| CVE-2026-54561 | 6.2 | — | mkreyman | mcp-memory-keeper | CWE-22 | MCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_imp… |
| CVE-2026-49446 | 6.1 | — | azukaar | Cosmos-Server | CWE-285 | Cosmos: Authentication bypass via forward-auth header smuggling on Constellat… |
| CVE-2026-54724 | 6.1 | — | kiwitcms | Kiwi | CWE-601 | Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmati… |
| CVE-2026-87169 | 6.1 | — | Oracle Corporation | Oracle Contract Lifecycle Management for Public Sector | — | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector p… |
| CVE-2026-87253 | 6.1 | — | Oracle Corporation | Oracle Agile PLM | — | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (compone… |
| CVE-2026-87278 | 6.1 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87279 | 6.1 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-91786 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering … |
| CVE-2026-55828 | 6.0 | — | qbee-io | transport | CWE-22 | qbee transport: Symlink-chain path traversal in tar extraction (one level out… |
| CVE-2026-73465 | 6.0 | — | Arista Networks | EOS | CWE-532 | On affected platforms running Arista EOS, under certain circumstances plainte… |
| CVE-2026-73466 | 6.0 | — | Arista Networks | EOS | CWE-532 | On affected platforms running Arista EOS, under certain circumstances plainte… |
| CVE-2026-73467 | 6.0 | — | Arista Networks | EOS | CWE-532 | On affected platforms running Arista EOS, under certain circumstances plainte… |
| CVE-2026-87282 | 6.0 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87283 | 6.0 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87285 | 6.0 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-54254 | 5.9 | — | Cyberdrop-DL | cyberdrop-dl | CWE-20 | Cyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sites |
| CVE-2026-69201 | 5.9 | — | http4s | http4s | CWE-22 | Http4s: ResourceService and Webjar Service path escape via percent-encoded se… |
| CVE-2026-69206 | 5.9 | — | http4s | http4s | CWE-294 | Http4s: DigestAuth allows replay of captured requests |
| CVE-2026-69212 | 5.9 | — | http4s | http4s | CWE-200 | Http4s: FollowRedirect middleware leaks credentials over https->http same-aut… |
| CVE-2026-76700 | 5.9 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConne… |
| CVE-2026-76701 | 5.9 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnec… |
| CVE-2026-77117 | 5.9 | — | The GNU C Library | glibc | CWE-835 | SHIFT_JISX0213 decoding may hang on crafted input |
| CVE-2026-80489 | 5.9 | — | The GNU C Library | glibc | CWE-835 | EUC_JISX0213 decoding may hang on crafted input |
| CVE-2026-52724 | 5.8 | — | kumahq | kuma | CWE-295 | kuma-dp connects to control plane without verifying TLS certificate when no C… |
| CVE-2026-55591 | 5.8 | — | SignalK | signalk-server | CWE-918 | Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints |
| CVE-2026-76702 | 5.8 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeCon… |
| CVE-2026-55636 | 5.7 | — | projectcapsule | capsule | CWE-863 | Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namesp… |
| CVE-2026-56975 | 5.7 | — | Android | CWE-20 | In Cellular Modem, there is a possible denial of service due to improper inpu… | |
| CVE-2025-11395 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-277 | Podman: arbitrary file write when importing oci archive |
| CVE-2026-48722 | 5.5 | — | nextflow-io | nextflow | CWE-276 | Nextflow: Incorrect default permissions in the nextflow auth login command |
| CVE-2026-50166 | 5.5 | — | kumahq | kuma | CWE-295 | Kuma: kumactl connects to control plane without verifying TLS certificate whe… |
| CVE-2026-54637 | 5.5 | — | dragonflyoss | dragonfly | CWE-918 | Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled Peer… |
| CVE-2026-56888 | 5.5 | — | Android | CWE-203 | In multiple locations, there is a possible permission bypass due to side chan… | |
| CVE-2026-56892 | 5.5 | — | Android | CWE-120 | In ReadDataElement of common.c, there is a possible information disclosure du… | |
| CVE-2026-56958 | 5.5 | — | Android | CWE-125 | In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-boun… | |
| CVE-2026-58731 | 5.5 | — | Android | CWE-125 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-b… | |
| CVE-2026-76703 | 5.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Authenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-… |
| CVE-2026-76704 | 5.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-79 | Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect … |
| CVE-2026-76705 | 5.5 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-120 | Authenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remot… |
| CVE-2026-83274 | 5.5 | — | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-83279 | 5.5 | — | Oracle Corporation | Oracle Agile PLM MCAD Connector | — | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply… |
| CVE-2026-91848 | 5.5 | — | n/a | WuzhiCMS | CWE-74 | WuzhiCMS index.php getDataOfJson sql injection |
| CVE-2026-91855 | 5.5 | — | n/a | Open5GS | CWE-404 | Open5GS PFCP Message handler.c denial of service |
| CVE-2026-92259 | 5.5 | — | Samsung Opensource | Escargot | CWE-190 | Integer overflow or wraparound vulnerability in Samsung Opensource Escargot a… |
| CVE-2026-11918 | 5.4 | — | IBM | ContextForge MCP Gateway | CWE-184 | IBM ContextForge MCP Gateway is affected by security filter bypass via nested… |
| CVE-2026-12742 | 5.4 | — | IBM | Business Automation Workflow containers and traditional | CWE-862 | Multiple secuirty vulnerabilies addressed with IBM Business Automation Workfl… |
| CVE-2026-12751 | 5.4 | — | IBM | Cloud Pak for Business Automation | CWE-80 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Busine… |
| CVE-2026-12910 | 5.4 | — | GitLab | GitLab | CWE-306 | Missing Authentication for Critical Function in GitLab |
| CVE-2026-55226 | 5.4 | — | strimzi | strimzi-kafka-operator | CWE-269 | Strimzi: Unrestricted access to all Secrets within namespace watched by the T… |
| CVE-2026-69216 | 5.4 | — | http4s | http4s | CWE-444 | Http4s: Ember chunk parser lenience (TE.TE request smuggling) |
| CVE-2026-83198 | 5.4 | — | Oracle Corporation | Oracle Field Service | — | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite … |
| CVE-2026-83346 | 5.4 | — | Oracle Corporation | Oracle Fusion Middleware Control | — | Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusio… |
| CVE-2026-83419 | 5.4 | — | Oracle Corporation | Oracle Communications Cloud Native Core Security Edge Protection Proxy | — | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Pr… |
| CVE-2026-83431 | 5.4 | — | Oracle Corporation | Oracle Product Workbench | — | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Su… |
| CVE-2026-83488 | 5.4 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-32599 | 5.3 | — | gravitl | netmaker | CWE-89 | Netmaker has a boolean‑based SQL Injection |
| CVE-2026-44163 | 5.3 | — | fluent-plugins-nursery | fluent-plugin-opentelemetry | CWE-409 | fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and D… |
| CVE-2026-50024 | 5.3 | — | WangYihang | GitHacker | CWE-22 | GitHacker: Path traversal in ref/hash parsing enables existence oracle and he… |
| CVE-2026-55375 | 5.3 | — | jleehr | canto-saas-api | CWE-209 | canto-saas-api: OAuth credentials exposed in URL query string and exception m… |
| CVE-2026-55863 | 5.3 | — | motioneye-project | motioneye | CWE-862 | motionEye: Missing authentication on ActionHandler allows unauthenticated cam… |
| CVE-2026-73444 | 5.3 | — | Arista Networks | EOS | CWE-303 | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header… |
| CVE-2026-76706 | 5.3 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | CWE-200 | Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API… |
| CVE-2026-76863 | 5.3 | — | Netcore | NR255-V | CWE-863 | Netcore NR255-V 1.5.130703 Sensitive Information Disclosure via QoS Bandwidth… |
| CVE-2026-82191 | 5.3 | — | j2commerce.com | J2Store extension for Joomla | CWE-1241 | Joomla Extension - j2commerce.com - Unescaped request data reflected into Pay… |
| CVE-2026-82567 | 5.3 | — | mySCADA Technologies | mySCADA myPRO | CWE-862 | mySCADA myPRO Manager Missing Authorization |
| CVE-2026-82837 | 5.3 | — | GitLab | GitLab | CWE-201 | Insertion of Sensitive Information Into Sent Data in GitLab |
| CVE-2026-83109 | 5.3 | — | Oracle Corporation | Oracle Forms | — | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (compon… |
| CVE-2026-83458 | 5.3 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83459 | 5.3 | — | Oracle Corporation | Helidon | CWE-400 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-83480 | 5.3 | — | Oracle Corporation | Helidon | — | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: … |
| CVE-2026-87267 | 5.3 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-91744 | 5.3 | — | Chrome | CWE-367 | Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153… | |
| CVE-2026-91922 | 5.3 | — | steedos | steedos-platform | CWE-79 | Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render |
| CVE-2026-91962 | 5.3 | — | FreeRDP | FreeRDP | CWE-131 | FreeRDP before 3.31.0 Integer Overflow via audin Apple backends |
| CVE-2026-91967 | 5.3 | — | WWBN | AVideo | CWE-918 | AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL |
| CVE-2026-91980 | 5.3 | — | go-vikunja | vikunja | CWE-200 | vikunja before 2.6.0 Team Enumeration via Project Share |
| CVE-2026-91981 | 5.3 | — | go-vikunja | vikunja | CWE-200 | Vikunja before 2.6.0 User Enumeration via v2 API |
| CVE-2026-91982 | 5.3 | — | go-vikunja | vikunja | CWE-522 | Vikunja before 2.6.0 TOTP Secret Disclosure via API |
| CVE-2026-91983 | 5.3 | — | go-vikunja | vikunja | CWE-863 | Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter |
| CVE-2026-91984 | 5.3 | — | go-vikunja | vikunja | CWE-639 | Vikunja before 2.6.0 Broken Object-Level Authorization via task-position |
| CVE-2026-91986 | 5.3 | — | GitoxideLabs | gitoxide | CWE-74 | gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection |
| CVE-2026-91993 | 5.3 | — | dromara | Jpom | CWE-639 | Jpom through 2.11.12 Workspace Isolation Bypass via /build/branch-list |
| CVE-2026-92184 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-918 | ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen serve… |
| CVE-2026-92255 | 5.3 | — | Netcore | NR255-V | CWE-125 | Netcore NR255-V 1.5.130703 Out-of-Bounds Read in filter_arp_put_file.cgi via … |
| CVE-2026-76796 | 5.1 | — | Newell Brands | DYMO Connect Desktop | CWE-73 | Newell Brands DYMO Connect Desktop improper file path validation |
| CVE-2026-76867 | 5.1 | — | Netcore | NR255-V | CWE-79 | Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in Route/NAT Configura… |
| CVE-2026-76872 | 5.1 | — | Netcore | NR255-V | CWE-79 | Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP/ACL Managemen… |
| CVE-2026-76873 | 5.1 | — | Netcore | NR255-V | CWE-79 | Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DHCP and ARP Hostn… |
| CVE-2026-87793 | 5.1 | — | Developers Italia | design-scuole-wordpress-theme | CWE-79 | Reflected XSS in WordPress theme design-scuole-wordpress-theme |
| CVE-2026-89307 | 5.1 | — | Developers Italia | design-scuole-wordpress-theme | CWE-601 | HTML injection allows open redirection in WordPress theme design-scuole-wordp… |
| CVE-2026-91717 | 5.1 | — | Chrome | CWE-862 | Missing authorization in Android in Google Chrome on on Android prior to 153.… | |
| CVE-2026-91942 | 5.1 | — | unclecode | crawl4ai | CWE-79 | crawl4ai before 0.9.3 Cross-Site Scripting via innerHTML |
| CVE-2026-91944 | 5.1 | — | unclecode | crawl4ai | CWE-79 | crawl4ai before 0.9.3 DOM-based XSS via Playground UI |
| CVE-2026-92002 | 5.1 | — | MISP | MISP | CWE-778 | MISP: Authentication failure logging suppressed during Redis unavailability |
| CVE-2026-92234 | 5.1 | — | Webkul | QloApps | CWE-79 | QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors |
| CVE-2026-92257 | 5.1 | — | Netcore | NR255-V | CWE-79 | Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting in L7 Content Manageme… |
| CVE-2026-48737 | 4.9 | — | pyload | pyload | CWE-918 | pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal… |
| CVE-2026-44282 | 4.8 | — | decidim | decidim | CWE-79 | Election question titles allow stored script execution |
| CVE-2026-47215 | 4.8 | — | sylabs | singularity | CWE-22 | Singularity: Incorrect path matching for 'limit container paths' directive |
| CVE-2026-48785 | 4.8 | — | apptainer | apptainer | CWE-22 | Apptainer: Incorrect path matching for 'limit container paths' directive |
| CVE-2026-55374 | 4.8 | — | jleehr | canto-saas-api | CWE-74 | canto-saas-api: Authenticated API requests can be redirected via unencoded pa… |
| CVE-2026-69211 | 4.8 | — | http4s | http4s | CWE-113 | Http4s: Set-Cookie rendering does not escape attribute delimiters |
| CVE-2026-76858 | 4.8 | — | Netcore | NR255-V | CWE-79 | Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via DDNS eval() in ddn… |
| CVE-2026-76864 | 4.8 | — | Netcore | NR255-V | CWE-79 | Netcore NR255-V 1.5.130703 Stored Cross-Site Scripting via Unescaped QoS Rule… |
| CVE-2026-86472 | 4.8 | — | fast-uri | fast-uri | CWE-178 | fast-uri vulnerable to inconsistent host case normalization via percent-encod… |
| CVE-2026-86818 | 4.8 | — | fast-uri | fast-uri | CWE-172 | fast-uri vulnerable to mailto header injection via percent-encoded field-name… |
| CVE-2026-58196 | 4.7 | — | stacklok | toolhive | CWE-918 | ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypa… |
| CVE-2026-91720 | 4.7 | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allow… | |
| CVE-2026-91726 | 4.7 | — | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.801… | |
| CVE-2026-87275 | 4.6 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-79705 | 4.5 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-22 | Podman: buildah: buildah/copier: directory escape via crafted tar symlinks wh… |
| CVE-2026-0177 | 4.4 | — | Android | CWE-120 | In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds r… | |
| CVE-2026-0183 | 4.4 | — | Android | CWE-441 | In CPM, there is a possible information disclosure due to a confused deputy. … | |
| CVE-2026-0197 | 4.4 | — | Android | CWE-200 | In VPU, there is a possible information dislclosure due to a logic error in t… | |
| CVE-2026-55650 | 4.4 | — | outerbase | studio | CWE-79 | Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exp… |
| CVE-2026-56950 | 4.4 | — | Android | CWE-20 | In validate_ns_buf of mbu_class.rs, there is a possible information disclosur… | |
| CVE-2026-57006 | 4.4 | — | Android | CWE-693 | In acfw_ffa.c, there is a possible secret read due to a logic error in the co… | |
| CVE-2026-58721 | 4.4 | — | Android | CWE-457 | In multiple locations, there is a possible information disclosure due to unin… | |
| CVE-2026-79699 | 4.4 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-59 | Podman: buildah: skopeo: containers/storage: malicious tar whiteout header al… |
| CVE-2026-87274 | 4.4 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-53954 | 4.3 | — | bugsink | bugsink | CWE-400 | Bugsink: DOS using large numbers of event tags |
| CVE-2026-54503 | 4.3 | — | plone | plone.app.textfield | CWE-80 | plone.app.textfield: Stored XSS by spoofing mime type |
| CVE-2026-76707 | 4.3 | — | Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | — | Unauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN G… |
| CVE-2026-83416 | 4.3 | — | Oracle Corporation | Oracle Coherence | — | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-91740 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowe… | |
| CVE-2026-91746 | 4.3 | — | Chrome | CWE-190 | Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allow… | |
| CVE-2026-87280 | 4.2 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-19504 | 4.0 | — | Fabric.js | Fabric.js | CWE-918 | Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability |
| CVE-2026-91926 | 3.7 | — | Red Hat | Red Hat Enterprise Linux 8 | CWE-401 | Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicat… |
| CVE-2026-87281 | 3.2 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-87284 | 3.2 | — | Oracle Corporation | Oracle VM VirtualBox | — | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-83369 | 3.1 | — | Oracle Corporation | Oracle Access Manager | — | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middlewar… |
| CVE-2026-91708 | 3.1 | — | Chrome | CWE-367 | Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a r… | |
| CVE-2026-91747 | 3.1 | — | Chrome | CWE-416 | Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remo… | |
| CVE-2026-44778 | 2.9 | — | inspektor-gadget | inspektor-gadget | CWE-20 | Inspektor Gadget: Unprivileged container can crash USDT note parser via craft… |
| CVE-2026-49254 | 2.9 | — | dragonflyoss | dragonfly | CWE-200 | Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated… |
| CVE-2026-54450 | 2.9 | — | stacklok | toolhive | CWE-918 | ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48),… |
| CVE-2026-83414 | 2.5 | — | Oracle Corporation | Oracle Coherence | — | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-55775 | 2.3 | — | openbao | openbao | CWE-285 | OpenBao's System Backend allows Unauthorized Management of the containing Nam… |
| CVE-2026-68532 | 2.3 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS 9.0.0 to 9.5.2 is vunerable to CSRF in Concrete CMS Group Type D… |
| CVE-2026-68533 | 2.3 | — | Concrete CMS | Concrete CMS | CWE-862 | Missing Authorization in Concrete CMS versions below 9.5.3 Conversation File … |
| CVE-2026-68534 | 2.3 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express en… |
| CVE-2026-81919 | 2.3 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) i… |
| CVE-2026-81920 | 2.3 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) i… |
| CVE-2026-81921 | 2.3 | — | Concrete CMS | Concrete CMS | CWE-862 | In Concrete CMS 8.5.3 to 9,5,2, OAuth 2.0 Refresh-Token Grant Bypasses Accoun… |
| CVE-2026-91957 | 2.3 | — | FreeRDP | FreeRDP | CWE-416 | FreeRDP before 3.31.0 Use-After-Free via smartcard worker |
| CVE-2026-18421 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.0.0-9.5.2 Boards data source dashboard is missing an authoriza… |
| CVE-2026-18422 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS below 9.5.3 Multilingual Page Assign Action Lacks Destination Au… |
| CVE-2026-18423 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-639 | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object refe… |
| CVE-2026-18424 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-918 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to SSRF protection bypass in remote… |
| CVE-2026-18425 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-352 | IDOR in Concrete CMS 9.0.0 through 9.5.2 dashboard sitemap reorder (SitemapUp… |
| CVE-2026-55774 | 2.1 | — | openbao | openbao | CWE-863 | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{r… |
| CVE-2026-68529 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.0.0 through 9.5.2 us missing authorization in the Express entr… |
| CVE-2026-68530 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.0.0 through 9.5.2 is Missing Authorization on Board Instance A… |
| CVE-2026-68531 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-405 | Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via… |
| CVE-2026-81922 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | "In Concrete CMS below 9.5.3, there is Missing authorization in the sitemap p… |
| CVE-2026-81923 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS below 9.5.3 is missing authorization in the SEO Bulk Update Meta… |
| CVE-2026-81924 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-352 | Concrete CMS below 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) i… |
| CVE-2026-81925 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below 9.5.3 is vulnerable to Reflected Cross-Site Scripting (XSS… |
| CVE-2026-91849 | 2.1 | — | n/a | WuzhiCMS | CWE-284 | WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload |
| CVE-2026-91853 | 2.1 | — | TOTOLINK | X5000R | CWE-77 | TOTOLINK X5000R Export Ovpn cstecgi.cgi exportOvpn os command injection |
| CVE-2026-91854 | 2.1 | — | code-projects | Record Management System | CWE-79 | code-projects Record Management System reg.php cross site scripting |
| CVE-2026-18426 | 2.0 | — | Concrete CMS | Concrete CMS | CWE-862 | Concrete CMS 9.0.0 to 9.5.2 Express Form block missing authorization allows a… |
| CVE-2026-81926 | 2.0 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS 9.4.0 through 9.5.2 is vulnerable to Cross-site scripting in the… |
| CVE-2026-83413 | 1.9 | — | Oracle Corporation | Oracle Coherence | — | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (co… |
| CVE-2026-81927 | 1.8 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS before 9.5.3 is vulnerable to Stored XSS via SVG upload in "Reje… |
| CVE-2026-91842 | 1.2 | — | OpenBankProject | OBP-API | CWE-20 | OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization |
| CVE-2026-91835 | 0.9 | — | OpenClaw | ClawScan | CWE-436 | OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretati… |
| CVE-2026-91836 | 0.9 | — | OpenClaw | ClawScan | CWE-1023 | OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with… |
| CVE-2026-55630 | 0.0 | — | kiwitcms | Kiwi | CWE-79 | Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & Tes… |
| CVE-2026-0179 | await | — | Android | — | In Bootloader, there is a possible permission bypass due to a missing permiss… | |
| CVE-2026-0186 | await | — | Android | — | In ac_init_one_sswrp of init.c, there is a possible escalation of privilege d… | |
| CVE-2026-0187 | await | — | Android | — | In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation… | |
| CVE-2026-0189 | await | — | Android | — | In ac_init_policy of init.c, there is a possible permission bypass due to a l… | |
| CVE-2026-0192 | await | — | Android | — | In Bootloader, there is a possible escalation of privilege due to a missing p… | |
| CVE-2026-0194 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to an intege… | |
| CVE-2026-11921 | await | — | IBM | Verify Identity Access | CWE-522 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-11927 | await | — | IBM | Verify Identity Access | CWE-74 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-11928 | await | — | IBM | Verify Identity Access | CWE-787 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-12101 | await | — | IBM | Verify Identity Access | CWE-289 | Security vulnerabilities have been addressed in IBM Verify Identity Access an… |
| CVE-2026-13327 | await | — | Devolutions | Server | CWE-295 | Improper certificate validation on LDAPS connections to Active Directory in D… |
| CVE-2026-25825 | await | — | n/a | n/a | — | An issue was discovered in Keyfactor SignServer before 7.6.0. The output file… |
| CVE-2026-25826 | await | — | n/a | n/a | — | An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute A… |
| CVE-2026-25827 | await | — | n/a | n/a | — | An issue was discovered in Keyfactor SignServer before 7.6.0. A number of pro… |
| CVE-2026-37152 | await | — | n/a | n/a | — | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded… |
| CVE-2026-39038 | await | — | n/a | n/a | — | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scriptin… |
| CVE-2026-39039 | await | — | n/a | n/a | — | In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT aut… |
| CVE-2026-39040 | await | — | n/a | n/a | — | BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting… |
| CVE-2026-51133 | await | — | n/a | n/a | — | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillan… |
| CVE-2026-51134 | await | — | n/a | n/a | — | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerab… |
| CVE-2026-55301 | await | — | Android | — | In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due t… | |
| CVE-2026-55302 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to a logic e… | |
| CVE-2026-55304 | await | — | Android | — | In addr_remap_address_map of remap.c, there is a possible escalation of privi… | |
| CVE-2026-55359 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to a logic e… | |
| CVE-2026-55366 | await | — | Android | — | In IP Multimedia Subsystem, there is a possible authentication bypass due to … | |
| CVE-2026-56881 | await | — | Android | — | In enable_segment of remap.c, there is a possible permission bypass due to a … | |
| CVE-2026-56889 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to an intege… | |
| CVE-2026-56907 | await | — | Android | — | In VPU, there is a possible shared memory overwrite due to improper input val… | |
| CVE-2026-56914 | await | — | Android | — | In multiple locations, there is a possible use-after-free due to improper loc… | |
| CVE-2026-56932 | await | — | Android | — | In Trusted Execution Environment, there is a possible memory corruption due t… | |
| CVE-2026-56941 | await | — | Android | — | In multiple functions of fpc_tee_hal.c, there is a possible use-after-free du… | |
| CVE-2026-56960 | await | — | Android | — | In multiple locations, there is a possible use-after-free due to a logic erro… | |
| CVE-2026-56970 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to a missing… | |
| CVE-2026-56973 | await | — | Android | — | In multiple locations, there is a possible escalation of privilege due to a l… | |
| CVE-2026-56978 | await | — | Android | — | In get_global_config_item_addr of gc.c, there is a possible out-of-bounds rea… | |
| CVE-2026-56979 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to a logic e… | |
| CVE-2026-56982 | await | — | Android | — | In VPU, there is a possible permission bypass due to a missing permission che… | |
| CVE-2026-56985 | await | — | Android | — | In multiple files, there is a possible way to obtain signatures due to type c… | |
| CVE-2026-56986 | await | — | Android | — | In multiple files, there is a possible out-of-bounds read due to type confusi… | |
| CVE-2026-57012 | await | — | Android | — | In the Setup Wizard, there is a possible remote package install due to a miss… | |
| CVE-2026-57042 | await | — | Android | — | In multiple functions of DreamPickerReceiver.kt, there is a possible permissi… | |
| CVE-2026-58678 | await | — | Android | — | In Bootloader, there is a possible permission bypass due to a logic error in … | |
| CVE-2026-58679 | await | — | Android | — | In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer ove… | |
| CVE-2026-58691 | await | — | Android | — | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to impro… | |
| CVE-2026-58695 | await | — | Android | — | In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible esc… | |
| CVE-2026-58699 | await | — | Android | — | In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds r… | |
| CVE-2026-79303 | await | — | n/a | n/a | — | kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dyn… |
| CVE-2026-79411 | await | — | n/a | n/a | — | Incorrect privilege assignment in the admin user-management component of Webk… |
| CVE-2026-79551 | await | — | n/a | n/a | — | Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contai… |
| CVE-2026-84850 | await | — | Devolutions | Server | CWE-295 | Improper certificate validation in the shared HTTP client used by synchroniza… |
| CVE-2026-88617 | await | — | n/a | n/a | — | SmartAdmin v3.30.0 contains an authorization flaw in the configuration query … |
| CVE-2026-88620 | await | — | n/a | n/a | — | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authori… |
| CVE-2026-88621 | await | — | n/a | n/a | — | OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability… |
| CVE-2026-88742 | await | — | n/a | n/a | — | Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in… |
| CVE-2026-88743 | await | — | n/a | n/a | — | Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in… |
| CVE-2026-90969 | await | — | Devolutions | Server | CWE-284 | Improper access control in the vault entry listing feature in Devolutions Ser… |
| CVE-2026-90971 | await | — | Devolutions | Server | CWE-863 | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in D… |
| CVE-2026-91711 | await | — | Chrome | CWE-787 | Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 … | |
| CVE-2026-91713 | await | — | Chrome | CWE-862 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allo… | |
| CVE-2026-91714 | await | — | Chrome | CWE-203 | Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allow… | |
| CVE-2026-91715 | await | — | Chrome | CWE-843 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allow… | |
| CVE-2026-91716 | await | — | Chrome | CWE-416 | Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remo… | |
| CVE-2026-91719 | await | — | Chrome | CWE-94 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remot… | |
| CVE-2026-91722 | await | — | Chrome | CWE-416 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a rem… | |
| CVE-2026-91723 | await | — | Chrome | CWE-362 | Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allo… | |
| CVE-2026-91725 | await | — | Chrome | CWE-203 | Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed… | |
| CVE-2026-91729 | await | — | Chrome | CWE-416 | Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 … | |
| CVE-2026-91730 | await | — | Chrome | CWE-459 | Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 al… | |
| CVE-2026-91732 | await | — | Chrome | CWE-862 | Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 … | |
| CVE-2026-91737 | await | — | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remot… | |
| CVE-2026-91738 | await | — | Chrome | CWE-20 | Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 al… | |
| CVE-2026-91739 | await | — | Chrome | CWE-862 | Missing authorization in Transactions Platform in Google Chrome prior to 153.… | |
| CVE-2026-91742 | await | — | Chrome | CWE-441 | Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.80… | |
| CVE-2026-91745 | await | — | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote… | |
| CVE-2026-92005 | await | — | Mozilla | Firefox | — | Use-after-free in the Audio/Video: Web Codecs component |
| CVE-2026-92016 | await | — | Mozilla | Firefox | — | Use-after-free in the Disability Access APIs component |
| CVE-2026-92018 | await | — | Mozilla | Firefox | — | Sandbox escape in the DOM: Core & HTML component |
| CVE-2026-92019 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Remote Settings Client component |
| CVE-2026-92021 | await | — | Mozilla | Firefox | — | Use-after-free in the JavaScript Engine: JIT component |
| CVE-2026-92022 | await | — | Mozilla | Firefox | — | Use-after-free in the DOM: HTML Parser component |
| CVE-2026-92023 | await | — | Mozilla | Firefox | — | Use-after-free in the XML component |
| CVE-2026-92024 | await | — | Mozilla | Firefox | — | Use-after-free in the SVG component |
| CVE-2026-92025 | await | — | Mozilla | Firefox | — | Use-after-free in the DOM: Navigation component |
| CVE-2026-92026 | await | — | Mozilla | Firefox | — | Use-after-free in the Networking component |
| CVE-2026-92027 | await | — | Mozilla | Firefox | — | Use-after-free in the DOM: Streams component |
| CVE-2026-92028 | await | — | Mozilla | Firefox | — | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-92029 | await | — | Mozilla | Firefox | — | Use-after-free in the SVG component |
| CVE-2026-92030 | await | — | Mozilla | Firefox | — | Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component |
| CVE-2026-92031 | await | — | Mozilla | Firefox | — | Information disclosure in the Graphics: ImageLib component |
| CVE-2026-92032 | await | — | Mozilla | Firefox | — | Sandbox escape due to invalid pointer in the Graphics component |
| CVE-2026-92034 | await | — | Mozilla | Firefox | — | Site isolation issue in the Graphics component |
| CVE-2026-92035 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Graphics component |
| CVE-2026-92036 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the Networking: HTTP component |
| CVE-2026-92037 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the DOM: Animation component |
| CVE-2026-92038 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Remote Settings Client component |
| CVE-2026-92039 | await | — | Mozilla | Firefox | — | Mitigation bypass in the DOM: Notifications component |
| CVE-2026-92040 | await | — | Mozilla | Firefox | — | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-92041 | await | — | Mozilla | Firefox | — | Mitigation bypass in the DOM: Networking component |
| CVE-2026-92042 | await | — | Mozilla | Firefox | — | Race condition in the DOM: Content Processes component |
| CVE-2026-92044 | await | — | Mozilla | Firefox | — | Information disclosure in the Networking: HTTP component |
| CVE-2026-92045 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the WebRTC component |
| CVE-2026-92046 | await | — | Mozilla | Firefox | — | Use-after-free in the Graphics component |
| CVE-2026-92048 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp… |
| CVE-2026-92049 | await | — | Mozilla | Firefox | — | Use-after-free in the Widget: Win32 component |
| CVE-2026-92050 | await | — | Mozilla | Firefox | — | Sandbox escape due to race condition in the XPConnect component |
| CVE-2026-92051 | await | — | Mozilla | Firefox | — | Spoofing issue due to invalid pointer in the Graphics component |
| CVE-2026-92056 | await | — | Mozilla | Firefox | — | Use-after-free in the Graphics: Text component |
| CVE-2026-92057 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Enterprise Policies component |
| CVE-2026-92058 | await | — | Mozilla | Firefox | — | Use-after-free in the Graphics component |
| CVE-2026-92059 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the DOM: Editor component |
| CVE-2026-92060 | await | — | Mozilla | Firefox | — | Use-after-free in the Internationalization component |
| CVE-2026-92061 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the Security: Process Sandboxing component |
| CVE-2026-92063 | await | — | Mozilla | Firefox | — | Denial-of-service in the Audio/Video component |
| CVE-2026-92064 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp… |
| CVE-2026-92065 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp… |
| CVE-2026-92066 | await | — | Mozilla | Firefox | — | Sandbox escape in the Profile Backup component |
| CVE-2026-92067 | await | — | Mozilla | Firefox | — | Use-after-free in the Widget: Gtk component |
| CVE-2026-92068 | await | — | Mozilla | Firefox | — | Site isolation issue in the Reader Mode component |
| CVE-2026-92069 | await | — | Mozilla | Firefox | — | Spoofing issue in the DOM: Navigation component |
| CVE-2026-92070 | await | — | Mozilla | Firefox | — | Information disclosure in the Networking component |
| CVE-2026-92071 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 comp… |
| CVE-2026-92072 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the Safe Browsing component |
| CVE-2026-92074 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Popup Blocker component |
| CVE-2026-92075 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Networking component |
| CVE-2026-92076 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the Networking component |
| CVE-2026-92077 | await | — | Mozilla | Firefox | — | Denial-of-service in the SVG component |
| CVE-2026-92078 | await | — | Mozilla | Firefox | — | Denial-of-service in the Security component |
| CVE-2026-92079 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Widget: Win32 component |
| CVE-2026-92237 | await | — | Devolutions | PowerShell Universal | CWE-532 | Insertion of sensitive information into log file in the slow query logging fe… |
| CVE-2026-92238 | await | — | Mozilla | Thunderbird | — | Ambiguous parsing of mail headers |
| CVE-2026-92239 | await | — | Mozilla | Thunderbird | — | Buffer overrun in IMAP |
| CVE-2026-92240 | await | — | Mozilla | Thunderbird | — | Out-of-bounds read in IMAP response parser |