| CVE-2026-1168 | 7.5 | 48.8 | GitLab | GitLab | CWE-770 | Allocation of Resources Without Limits or Throttling in GitLab |
| CVE-2026-78088 | 8.8 | 46.8 | contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | CWE-434 | Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUr… |
| CVE-2026-88263 | 8.7 | 45.2 | XikeStor | SKS8310-8X | CWE-306 | XikeStor Layer3 switches miss authentication for downloading configuration da… |
| CVE-2026-27552 | 8.1 | 45.2 | Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D | CWE-863 | Unauthorized IODD File Upload due to Improper Authorization |
| CVE-2026-27553 | 6.5 | 43.9 | Pepperl+Fuchs | ICE2-8IOL1-G65L-V1D | CWE-497 | Information Disclosure via Schema Path Manipulation |
| CVE-2026-81642 | 9.1 | 43.0 | NLnet Labs | Unbound | CWE-122 | Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY |
| CVE-2026-92220 | 6.9 | 43.0 | vllm-project | vLLM | CWE-400 | vllm-project vLLM MoRIIO Acknowledgement moriio_connector.py MoRIIOWrapper._h… |
| CVE-2026-92091 | 5.9 | 41.4 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-407 | Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded… |
| CVE-2026-8462 | 8.9 | 40.5 | openmeter | openmeter | CWE-89 | OpenMeter SQL Injection in ClickHouse-backed Meter Definitions |
| CVE-2026-73464 | 8.7 | 40.5 | Arista Networks | EOS | CWE-94 | Security Advisory 0166 |
| CVE-2026-73455 | 8.9 | 40.0 | Arista Networks | EOS | CWE-130 | Security Advisory 0173 |
| CVE-2026-86792 | await | 38.4 | Apache Software Foundation | Apache Airflow Apache Kafka provider | CWE-470 | Apache Airflow Apache Kafka provider: Connection-editor remote code execution… |
| CVE-2026-92216 | 5.3 | 37.8 | a2ui-project | a2ui | CWE-601 | a2ui-project a2ui Binder generic-binder.ts openUrl redirect |
| CVE-2026-14349 | 9.8 | 36.1 | themetechmount | TrueBooker – Appointment Booking and Scheduler System | CWE-862 | TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User… |
| CVE-2026-8030 | 4.3 | 35.1 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-19248 | 7.1 | 34.7 | qt | qt | CWE-674 | Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impact… |
| CVE-2026-82717 | 8.4 | 34.0 | NLnet Labs | Unbound | CWE-122 | CNAME synthesis could lead to heap corruption |
| CVE-2026-92081 | 5.9 | 33.3 | fastify | fastify | CWE-248 | fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 tra… |
| CVE-2026-88255 | 6.3 | 33.1 | ZenHive | mpp | CWE-1289 | mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transac… |
| CVE-2026-89186 | 6.3 | 33.1 | ZenHive | mpp | CWE-524 | mpp writes Payment-Receipt and Cache-Control before the wrapped application r… |
| CVE-2026-78252 | 8.2 | 32.9 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-89063 | 7.5 | 32.9 | ladela | Online Scheduling and Appointment Booking System – Bookly | CWE-639 | Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Ob… |
| CVE-2026-12793 | 9.8 | 32.5 | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | CWE-269 | JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engi… |
| CVE-2026-92215 | 6.9 | 31.7 | a2ui-project | a2ui | CWE-918 | a2ui-project a2ui FileResolver file_resolver.py httpx.get server-side request… |
| CVE-2026-81634 | 7.5 | 29.1 | NLnet Labs | Unbound | CWE-122 | Possible heap buffer overflow during DNSSEC canonicalization |
| CVE-2026-92299 | 7.1 | 28.1 | Jitsi | @jitsi/electron-sdk | CWE-862 | @jitsi/electron-sdk before 10.0.5 Unauthorized Screen Capture |
| CVE-2026-79708 | 8.5 | 27.3 | GitLab | GitLab | CWE-863 | Incorrect Authorization in GitLab |
| CVE-2026-89207 | 6.9 | 26.9 | Siemens | WTV676-HB6035 Web Interface | CWE-1287 | A vulnerability has been identified in WTV676-HB6035 Web Interface (All versi… |
| CVE-2026-73439 | 7.7 | 26.4 | Arista Networks | EOS | CWE-842 | Security Advisory 0164 |
| CVE-2026-73445 | 6.9 | 25.7 | Arista Networks | EOS | CWE-20 | Security Advisory 0167 |
| CVE-2026-7514 | 4.3 | 25.6 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-16794 | 4.3 | 25.6 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-92298 | 6.3 | 25.4 | EspoCRM | EspoCRM | CWE-338 | EspoCRM through 10.0.8 Weak Token Generation via rand() |
| CVE-2026-86338 | 6.0 | 25.2 | ash-project | ash | CWE-1220 | Ash field policies do not filter-nil forbidden calculations and aggregates, e… |
| CVE-2026-92217 | 5.3 | 25.0 | a2ui-project | a2ui | CWE-913 | a2ui-project a2ui Message Parsing message-processor.ts processMessages dynami… |
| CVE-2026-86341 | 4.4 | 24.7 | GitLab | GitLab | CWE-1280 | Access Control Check Implemented After Asset is Accessed in GitLab |
| CVE-2026-3855 | 3.1 | 24.5 | GitLab | GitLab | CWE-99 | Improper Control of Resource Identifiers ('Resource Injection') in GitLab |
| CVE-2026-80225 | 5.3 | 24.1 | NLnet Labs | Unbound | CWE-770 | Possible degradation of service from continuous queries on the same TCP/DoT c… |
| CVE-2026-85501 | 5.3 | 24.1 | NLnet Labs | Unbound | CWE-770 | Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC |
| CVE-2026-19619 | 4.7 | 23.0 | GitLab | GitLab | CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… |
| CVE-2026-73461 | 9.4 | 22.5 | Arista Networks | EOS | CWE-266 | Security Advisory 0163 |
| CVE-2026-73454 | 8.6 | 22.3 | Arista Networks | EOS | CWE-77 | Security Advisory 0165 |
| CVE-2026-73469 | 6.9 | 22.0 | Arista Networks | EOS | CWE-863 | Security Advisory 0176 |
| CVE-2026-16588 | 6.5 | 22.1 | wpdirectorykit | WP Directory Kit | CWE-89 | WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'order_… |
| CVE-2026-92247 | 2.0 | 22.1 | synaptikcms | synaptik-cms | CWE-284 | synaptikcms synaptik-cms Admin File Manager file-manager.php rename unrestric… |
| CVE-2026-11984 | 5.3 | 21.2 | spacetime | Ad Inserter – Ad Manager & AdSense Ads | CWE-862 | Ad Inserter <= 2.8.16 - Missing Authorization to Unauthenticated Header/Foote… |
| CVE-2026-82720 | 5.9 | 21.1 | NLnet Labs | Unbound | CWE-416 | Use-after-free in DoH stream cleanup code path |
| CVE-2024-11222 | 6.4 | 20.7 | GitLab | GitLab | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab |
| CVE-2026-92358 | 6.4 | 20.6 | Red Hat | Red Hat Build of Keycloak | CWE-613 | Keycloak-services: keycloak-services: residual cross-browser account-link pro… |
| CVE-2026-76550 | await | 19.7 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path T… |
| CVE-2026-76551 | await | 19.7 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function |
| CVE-2026-77860 | 3.7 | 19.7 | NLnet Labs | Unbound | CWE-675 | 'serve-expired' can bypass Unbound 'wait-limit' |
| CVE-2026-92221 | 2.0 | 19.0 | gedelumbung | HospitalManagement | CWE-74 | gedelumbung HospitalManagement app_global_admin_model.php generate_index_pasi… |
| CVE-2026-78227 | 6.5 | 18.9 | NLnet Labs | Unbound | CWE-416 | Use-after-free in DoQ stream output buffer on reset re-transmission |
| CVE-2026-92214 | 5.1 | 17.6 | a2ui-project | a2ui | CWE-79 | a2ui-project a2ui a2a-chat-canvas sanitizer-markdown-renderer-service.ts cros… |
| CVE-2026-86475 | 5.3 | 17.2 | Unknown | Appointment Hour Booking | CWE-20 | Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass v… |
| CVE-2026-73440 | 2.3 | 17.3 | Arista Networks | EOS | CWE-212 | Security Advisory 0178 |
| CVE-2026-76552 | await | 17.1 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remo… |
| CVE-2026-73468 | 7.1 | 16.9 | Arista Networks | EOS | CWE-670 | Security Advisory 0175 |
| CVE-2026-84439 | await | 16.7 | Apache Software Foundation | Apache ZooKeeper | CWE-117 | Apache ZooKeeper: Audit log injection via unsanitized output from multiple so… |
| CVE-2026-18595 | 7.2 | 16.6 | wp-lab | WP-Lister Lite for eBay | CWE-79 | WP-Lister Lite for eBay <= 3.8.9 - Unauthenticated Stored Cross-Site Scriptin… |
| CVE-2026-82310 | await | 16.5 | Apache Software Foundation | Apache Airflow FAB provider | CWE-613 | Apache Airflow FAB provider: FAB auth manager: deactivated users retain and r… |
| CVE-2026-2380 | 5.1 | 16.4 | Arista Networks | EOS | CWE-256 | Security Advisory 0168 |
| CVE-2026-86109 | 7.5 | 15.6 | Arista Networks | VeloCloud Edge | CWE-347 | Security Advisory 0182 |
| CVE-2026-79993 | await | 15.6 | Apache Software Foundation | Apache ZooKeeper | CWE-862 | Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthor… |
| CVE-2026-92213 | 5.1 | 14.7 | a2ui-project | a2ui | CWE-74 | a2ui-project a2ui Angular Renderer server-to-client.ts z.any injection |
| CVE-2026-73436 | 6.0 | 14.5 | Arista Networks | EOS | CWE-125 | Security Advisory 0171 |
| CVE-2026-78472 | await | 14.1 | Unknown | Ni WooCommerce Sales Report | — | Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter |
| CVE-2026-5920 | 6.4 | 13.6 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-18555 | 6.1 | 13.4 | wordplus | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots | CWE-79 | Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plu… |
| CVE-2026-84501 | 5.3 | 13.4 | Apache Software Foundation | Apache ZooKeeper | CWE-117 | Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAu… |
| CVE-2026-78474 | await | 13.4 | Unknown | Ni WooCommerce Sales Report | — | Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data… |
| CVE-2026-84829 | await | 13.4 | Unknown | Optimole | — | Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter |
| CVE-2026-86444 | await | 13.4 | Unknown | LearnPress | — | LearnPress < 4.4.7 - Reflected XSS via 'skin' Parameter |
| CVE-2026-86448 | await | 13.4 | Unknown | LearnPress | — | LearnPress < 4.4.7 - Unauthenticated Order Data Disclosure via lp_download_order |
| CVE-2026-86465 | await | 13.1 | Apache Software Foundation | Apache Airflow Akeyless provider | CWE-639 | Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard … |
| CVE-2026-13407 | 5.4 | 12.3 | Unknown | Royal Addons for Elementor | CWE-116 | Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in … |
| CVE-2026-73438 | 7.0 | 11.9 | Arista Networks | EOS | CWE-617 | Security Advisory 0172 |
| CVE-2026-89783 | 9.8 | 11.4 | Linux | Linux | — | xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
| CVE-2026-89777 | 8.8 | 11.4 | Linux | Linux | — | vfio/pci: clear vdev->msi_perm after freeing it on init failure |
| CVE-2026-89789 | 7.8 | 11.4 | Linux | Linux | — | gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free |
| CVE-2026-89780 | await | 11.4 | Linux | Linux | — | net: qualcomm: rmnet: restore skb->dev on deaggregated frames |
| CVE-2026-89784 | await | 11.4 | Linux | Linux | — | SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 |
| CVE-2026-89793 | 7.8 | 11.2 | Linux | Linux | — | ublk: clear VM_MAYWRITE on read-only ublk char device mmap |
| CVE-2026-76186 | await | 10.9 | Apache Software Foundation | Apache Airflow Keycloak provider | CWE-565 | Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow… |
| CVE-2026-89778 | 9.8 | 10.8 | Linux | Linux | — | isofs: fix out-of-bounds page array access on empty zisofs block |
| CVE-2026-89779 | 9.1 | 10.8 | Linux | Linux | — | fs/ntfs3: validate ef->size covers the record's name and value |
| CVE-2026-89786 | 9.1 | 10.8 | Linux | Linux | — | ext4: fix out-of-bounds read in ext4_read_inline_dir() |
| CVE-2026-89781 | 8.4 | 10.8 | Linux | Linux | — | fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() |
| CVE-2026-89782 | 8.4 | 10.8 | Linux | Linux | — | fs/ntfs3: reject restart table growth beyond U16_MAX entries |
| CVE-2026-11996 | 6.4 | 10.7 | codesupplyco | Advanced Popups | CWE-79 | Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scriptin… |
| CVE-2026-89776 | await | 10.8 | Linux | Linux | — | vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes |
| CVE-2026-89785 | await | 10.8 | Linux | Linux | — | fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init |
| CVE-2026-89787 | await | 10.8 | Linux | Linux | — | ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() |
| CVE-2026-76556 | await | 10.6 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Authenticated SQLi via Export Filter Rules |
| CVE-2026-76557 | await | 10.6 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options |
| CVE-2026-73463 | 6.0 | 9.9 | Arista Networks | EOS | CWE-362 | Security Advisory 0169 |
| CVE-2026-84088 | await | 9.9 | Unknown | Xpro Addons — 140+ Widgets for Elementor | — | Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circl… |
| CVE-2026-86784 | await | 9.9 | Unknown | Visualizer | — | Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source |
| CVE-2026-89790 | await | 9.8 | Linux | Linux | — | ipv6: avoid divide by zero in rt6_multipath_rebalance |
| CVE-2026-59739 | await | 9.6 | Apache Software Foundation | Apache ZooKeeper | CWE-862 | Apache ZooKeeper: Information disclosure via SetWatches reconnect replay |
| CVE-2026-76558 | await | 9.5 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Contributor+ Stored DOM XSS via Custom Field… |
| CVE-2026-76187 | await | 9.5 | Apache Software Foundation | Apache Airflow Keycloak provider | CWE-287 | Apache Airflow Keycloak provider: Any realm client's credentials mint an Airf… |
| CVE-2026-76555 | await | 9.5 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via … |
| CVE-2026-82311 | await | 9.5 | Apache Software Foundation | Apache Airflow FAB provider | CWE-613 | Apache Airflow FAB provider: FAB password reset never invalidates sessions: s… |
| CVE-2026-86462 | await | 9.5 | Apache Software Foundation | Apache Airflow FAB provider | CWE-613 | Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate dat… |
| CVE-2026-19640 | 2.3 | 9.1 | Arista Networks | EOS | CWE-863 | Security Advisory 0170 |
| CVE-2026-89774 | 8.8 | 9.0 | Linux | Linux | — | Bluetooth: SCO: hold sk properly in sco_conn_ready |
| CVE-2026-82124 | await | 8.9 | Unknown | Schema & Structured Data for WP & AMP | — | Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Prote… |
| CVE-2026-86445 | await | 8.9 | Unknown | LearnPress | — | LearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_conten… |
| CVE-2026-86447 | await | 8.9 | Unknown | LearnPress | — | LearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_c… |
| CVE-2026-86449 | await | 8.9 | Unknown | LearnPress | — | LearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST API |
| CVE-2026-89788 | 9.8 | 8.8 | Linux | Linux | — | ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
| CVE-2026-89791 | 7.8 | 8.7 | Linux | Linux | — | perf: Fix use-after-free when perf mmap() revival races with the last munmap() |
| CVE-2026-89792 | 7.1 | 8.8 | Linux | Linux | — | ksmbd: prevent out-of-bounds reads in share config responses |
| CVE-2026-19857 | 4.8 | 8.7 | Unknown | Formidable Forms | CWE-74 | Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [… |
| CVE-2026-89775 | 9.3 | 8.2 | Linux | Linux | — | KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
| CVE-2026-76553 | await | 8.0 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion v… |
| CVE-2026-85349 | await | 8.0 | Unknown | FluentBoards | — | FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR |
| CVE-2026-85572 | await | 8.0 | Unknown | Tutor LMS | — | Tutor LMS 4.0.0 - < 4.0.8 - Subscriber+ Cross-Course Lesson Comment Disclosure |
| CVE-2026-77702 | await | 7.6 | Unknown | Eventin | — | Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token |
| CVE-2026-82125 | await | 7.6 | Unknown | Schema & Structured Data for WP & AMP | — | Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Publi… |
| CVE-2026-84907 | await | 7.6 | Unknown | Eventin | — | Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Paymen… |
| CVE-2026-85530 | await | 7.6 | Unknown | GiveWP | — | GiveWP < 4.16.8.1 - Unauthenticated Account Takeover via Donor Email Sanitiza… |
| CVE-2026-87854 | await | 7.5 | Unknown | Subscriptions for WooCommerce | — | Subscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Dis… |
| CVE-2026-87896 | await | 7.5 | Unknown | Rox Appointment Booking | — | Rox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Ag… |
| CVE-2026-87907 | await | 7.5 | Unknown | Rox Appointment Booking | — | Rox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure v… |
| CVE-2026-74926 | await | 7.0 | Unknown | MultiVendorX | — | MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership … |
| CVE-2026-76559 | await | 7.0 | Unknown | WP Import Export Lite | — | WP Import Export Lite < 3.9.33 - Admin+ SSRF via Import URL Handling |
| CVE-2026-82126 | await | 7.0 | Unknown | Schema & Structured Data for WP & AMP | — | Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public P… |
| CVE-2026-84905 | await | 7.0 | Unknown | Eventin | — | Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation |
| CVE-2026-85569 | await | 7.0 | Unknown | Tutor LMS | — | Tutor LMS 2.7.1 - < 4.0.8 - Read-Only API Key Privilege Escalation via REST R… |
| CVE-2026-87828 | await | 6.7 | Unknown | Seraphinite Accelerator | — | Seraphinite Accelerator < 2.29.24 - Subscriber+ DoS via seraph_accel_State Up… |
| CVE-2026-89327 | await | 6.5 | Unknown | FluentBoards | — | FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by… |
| CVE-2026-89328 | await | 6.5 | Unknown | FluentBoards | — | FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modi… |
| CVE-2026-86823 | await | 6.2 | Unknown | Newsletter | — | Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Discl… |
| CVE-2026-88910 | await | 6.2 | Unknown | kboard | — | KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR |
| CVE-2026-73435 | 7.0 | 5.9 | Arista Networks | EOS | CWE-345 | Security Advisory 0171 |
| CVE-2026-87959 | await | 5.7 | Unknown | WPBot | — | WPBot 8.7.2 - 8.7.5 - Subscriber+ Claude AI Settings Update |
| CVE-2026-85131 | await | 4.1 | Unknown | WPLP Cookie Consent | — | WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF |
| CVE-2026-84906 | 5.3 | 4.1 | Unknown | Eventin | CWE-345 | Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross… |
| CVE-2026-86466 | await | 3.6 | Apache Software Foundation | Apache Airflow FAB provider | CWE-346 | Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience… |
| CVE-2026-87860 | await | 3.5 | Unknown | Subscriptions for WooCommerce | — | Subscriptions for WooCommerce < 2.0.3 - Subscription Cancellation via CSRF |
| CVE-2026-73450 | 7.0 | 3.1 | Arista Networks | EOS | CWE-345 | Security Advisory 0161 |
| CVE-2026-77955 | 4.4 | 2.8 | NLnet Labs | Unbound | CWE-345 | Possible ZONEMD verification bypass window |
| CVE-2026-81326 | 6.8 | 2.4 | QualitySoft Corporation | QND Premium | CWE-321 | QND uses a hard-coded cryptographic key, which may allow a local attacker who… |
| CVE-2026-85641 | await | 2.3 | Unknown | Formidable Forms | — | Formidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated… |
| CVE-2026-59969 | await | 2.2 | Apache Software Foundation | Apache ZooKeeper | CWE-297 | Apache ZooKeeper: Improper validation of certificate with host mismatch in FI… |
| CVE-2026-86443 | 6.9 | 0.9 | Fermax Electronica S.A.U. | DuoxMe | CWE-312 | Cleartext Storage of Sensitive Information Vulnerability |
| CVE-2026-85628 | 7.0 | 0.1 | Fermax Electronica S.A.U. | DuoxMe | CWE-319 | Cleartext Transmission of Sensitive Information in the Pairing Process vulner… |
| CVE-2026-20130 | 10.0 | — | Cisco | Cisco Identity Services Engine Software | CWE-74 | Cisco Identity Services Engine Hardening Release - Improper Neutralization Vu… |
| CVE-2026-20192 | 10.0 | — | Cisco | Cisco Identity Services Engine Software | CWE-284 | Cisco Identity Services Engine Hardening Release - Access Control Vulnerabili… |
| CVE-2026-70416 | 10.0 | — | Dell | ObjectScale | CWE-502 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Un… |
| CVE-2026-76423 | 10.0 | — | Cisco | Cisco Identity Services Engine Software | CWE-290 | Cisco ISE API Authentication Bypass Vulnerability |
| CVE-2026-92808 | 10.0 | — | Altium | Altium Enterprise Server | CWE-306 | Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service … |
| CVE-2026-20234 | 9.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-522 | Cisco Identity Services Engine Hardening Release - Insuffiencently Protected … |
| CVE-2026-20307 | 9.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-502 | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20322 | 9.9 | — | Cisco | Cisco Nexus Dashboard | CWE-284 | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Im… |
| CVE-2026-20324 | 9.9 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-862 | Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectuti… |
| CVE-2026-20325 | 9.9 | — | Cisco | Cisco Nexus Dashboard | CWE-77 | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Im… |
| CVE-2026-20329 | 9.9 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-703 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-20330 | 9.9 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-707 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-20332 | 9.9 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-284 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2025-59953 | 9.8 | — | InternLM | lmdeploy | CWE-502 | LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call… |
| CVE-2026-20242 | 9.8 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-502 | Cisco Secure Firewall Management Center Software Java Deserialization Remote … |
| CVE-2026-20326 | 9.8 | — | Cisco | Cisco Nexus Dashboard | CWE-306 | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Mi… |
| CVE-2026-89847 | 9.8 | — | Linux | Linux | — | scsi: qla2xxx: Avoid double completion in async IOCB timeout |
| CVE-2026-89857 | 9.8 | — | Linux | Linux | — | scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
| CVE-2026-89969 | 9.8 | — | Linux | Linux | — | nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
| CVE-2026-89970 | 9.8 | — | Linux | Linux | — | nvmet-auth: Synchronize timeout work during SQ teardown |
| CVE-2026-89972 | 9.8 | — | Linux | Linux | — | nvme: add missing SRCU grace period in error path |
| CVE-2026-89990 | 9.8 | — | Linux | Linux | — | ceph: lock mutex in ceph_mds_check_access() |
| CVE-2026-90012 | 9.8 | — | Linux | Linux | — | spi: Fix DMA mapping ownership on partial map failure |
| CVE-2026-90036 | 9.8 | — | Linux | Linux | — | NFSD: Prevent client use-after-free during blocked-lock reaping |
| CVE-2026-90037 | 9.8 | — | Linux | Linux | — | NFSD: Prevent client use-after-free during close_lru reaping |
| CVE-2026-90038 | 9.8 | — | Linux | Linux | — | NFSD: Prevent client use-after-free during export state revocation |
| CVE-2026-90042 | 9.8 | — | Linux | Linux | — | ceph: properly decrypt filenames in vmalloc() buffers |
| CVE-2026-90048 | 9.8 | — | Linux | Linux | — | fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
| CVE-2026-91843 | 9.8 | — | checkpoint | Quantum Security Management | CWE-121 | Stack overflow in login process to the Security Management and Log Servers |
| CVE-2026-20331 | 9.6 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-693 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-77411 | 9.5 | — | rabbitmq | amqp091-go | CWE-754 | RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integ… |
| CVE-2026-58146 | 9.4 | — | WNC | T-Mobile 5G Box IDU | CWE-78 | Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
| CVE-2026-77405 | 9.4 | — | rabbitmq | amqp091-go | CWE-326 | RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In UR… |
| CVE-2026-40855 | 9.3 | — | WNC | T-Mobile 5G Box IDU | CWE-78 | Command Injection in T-Mobile 5G Box IDU router via ping functionality |
| CVE-2026-58147 | 9.3 | — | WNC | T-Mobile 5G Box IDU | CWE-78 | Authorized remote code execution via password change functionality in T-Mobil… |
| CVE-2026-73172 | 9.3 | — | Advantech | EKI-1242IEIMS | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-89082 | 9.3 | — | HP Inc | HP AC Print & Scan | CWE-94 | HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitr… |
| CVE-2026-89083 | 9.3 | — | HP Inc | HP AC Print & Scan | CWE-94 | HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitr… |
| CVE-2026-89914 | 9.3 | — | Linux | Linux | — | KVM: arm64: Sign-extend VA for range-based TLBI invalidation |
| CVE-2026-89915 | 9.3 | — | Linux | Linux | — | KVM: arm64: Remove VM-wide VNCR mapping counter |
| CVE-2026-89916 | 9.3 | — | Linux | Linux | — | KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry |
| CVE-2026-89918 | 9.3 | — | Linux | Linux | — | KVM: arm64: Correctly handle end of VA space TLBI invalidation |
| CVE-2026-89930 | 9.3 | — | Linux | Linux | — | KVM: nVMX: Service local TLB flushes on failed nested VM-Enter |
| CVE-2026-90049 | 9.3 | — | Linux | Linux | — | net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() |
| CVE-2026-91104 | 9.3 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-122 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-91106 | 9.3 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-122 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-92717 | 9.3 | — | cobbr | Covenant | CWE-306 | Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub |
| CVE-2026-92720 | 9.3 | — | kubero-dev | kubero | CWE-306 | Kubero through 3.1.1 Unauthenticated Notifications API Access |
| CVE-2026-92787 | 9.3 | — | feast-dev | feast | CWE-798 | Feast through 0.66.0 Authentication Bypass via Unverified Token |
| CVE-2026-92805 | 9.3 | — | uvdesk | community-skeleton | CWE-306 | UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Install… |
| CVE-2026-73456 | 9.2 | — | Arista Networks | EOS | CWE-94 | Under certain circumstances, an unauthenticated gNPSI client can craft a mali… |
| CVE-2026-92576 | 9.2 | — | HKUDS | nanobot | CWE-918 | HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool |
| CVE-2026-92578 | 9.2 | — | WWBN | AVideo | CWE-287 | WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash |
| CVE-2026-92749 | 9.2 | — | chaitin | SafeLine | CWE-338 | SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret |
| CVE-2026-92785 | 9.2 | — | Angel-ML | angel | CWE-502 | Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes |
| CVE-2026-20176 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-77 | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20194 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-669 | Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfe… |
| CVE-2026-20211 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-502 | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20237 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-20 | Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabi… |
| CVE-2026-20284 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-943 | Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability |
| CVE-2026-20305 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-78 | Cisco Identity Services Engine Command Injection Vulnerability |
| CVE-2026-20306 | 9.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-78 | Cisco Identity Services Engine Command Injection Vulnerability |
| CVE-2026-20341 | 9.1 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-502 | Cisco Secure Firewall Management Center Software sftunnel Deserialization Roo… |
| CVE-2026-61594 | 9.1 | — | djust-org | djust | CWE-306 | djust has an authorization bypass on the WebSocket/SSE mount path |
| CVE-2026-75513 | 9.1 | — | JasperFx | marten | CWE-89 | Marten: SQL injection in Marten's LINQ provider via unescaped string literals |
| CVE-2026-77408 | 9.1 | — | rabbitmq | amqp091-go | CWE-190 | RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr… |
| CVE-2026-89846 | 9.1 | — | Linux | Linux | — | scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read |
| CVE-2026-90011 | 9.1 | — | Linux | Linux | — | scsi: target: iscsi: Reserve a terminator byte for the login payload |
| CVE-2026-92395 | 9.1 | — | @fastify/proxy-addr | @fastify/proxy-addr | CWE-290 | @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
| CVE-2026-76420 | 9.0 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-285 | Cisco Secure Firewall Management Center Software Impersonated sftunnel Connec… |
| CVE-2026-77403 | 8.9 | — | rabbitmq | amqp091-go | CWE-770 | RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation |
| CVE-2026-77410 | 8.9 | — | rabbitmq | amqp091-go | CWE-789 | RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allo… |
| CVE-2026-77412 | 8.9 | — | rabbitmq | amqp091-go | CWE-681 | RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client |
| CVE-2026-20333 | 8.8 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-697 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-20336 | 8.8 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-664 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-20340 | 8.8 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-502 | Cisco Secure Firewall Management Center Software Deserialization Arbitrary Ro… |
| CVE-2026-20344 | 8.8 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-89 | Cisco Secure Firewall Management Center Software SQL Injection Vulnerability |
| CVE-2026-20360 | 8.8 | — | Cisco | Cisco Nexus Dashboard | CWE-200 | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - In… |
| CVE-2026-20361 | 8.8 | — | Cisco | Cisco Nexus Dashboard | CWE-89 | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQ… |
| CVE-2026-61599 | 8.8 | — | djust-org | djust | CWE-470 | djust has an unauthenticated arbitrary module import via the WebSocket/SSE vi… |
| CVE-2026-63506 | 8.8 | — | tinacms | tinacms | CWE-639 | Tina: [Broken Access Control] letting any TinaCloud user authorize against an… |
| CVE-2026-73173 | 8.8 | — | Advantech | EKI-1242IEIMS | CWE-306 | Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critica… |
| CVE-2026-76409 | 8.8 | — | Cisco | Cisco Nexus Dashboard | CWE-22 | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Im… |
| CVE-2026-82964 | 8.8 | — | Gen Digital | Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security | CWE-281 | Avast sandbox privilege escalation via unpreserved DACLs on virtualized files… |
| CVE-2026-84858 | 8.8 | — | Scada-LTS | Scada-LTS | — | Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass |
| CVE-2026-84860 | 8.8 | — | Scada-LTS | Scada-LTS | — | Scada-LTS DWR Authorization Bypass - Systemic |
| CVE-2026-85731 | 8.8 | — | oras-project | oras-go | CWE-22 | oras-go: Arbitrary file write outside file.Store root via symlink-chain bypas… |
| CVE-2026-86865 | 8.8 | — | Tanium | Asset | CWE-89 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2026-87105 | 8.8 | — | Tanium | Threat Response | CWE-89 | Tanium addressed a SQL injection vulnerability in Threat Response. |
| CVE-2026-88064 | 8.8 | — | backstage | backstage | CWE-20 | Backstage: Improper input validation in TechDocs MkDocs configuration |
| CVE-2026-89084 | 8.8 | — | HP Inc | HP AC Print & Scan | CWE-22 | HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitr… |
| CVE-2026-89804 | 8.8 | — | Linux | Linux | — | drm/nouveau/dmem: fix mismatched DMA unmap size for large folios |
| CVE-2026-89811 | 8.8 | — | Linux | Linux | — | drm/amdkfd: Add TLB flush after MES queue eviction/suspension |
| CVE-2026-89844 | 8.8 | — | Linux | Linux | — | scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition |
| CVE-2026-89849 | 8.8 | — | Linux | Linux | — | scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path |
| CVE-2026-89860 | 8.8 | — | Linux | Linux | — | scsi: qla2xxx: Initialize NVMe abort_work once at submission |
| CVE-2026-89898 | 8.8 | — | Linux | Linux | — | media: cec: extron-da-hd-4k-plus: add sanity check |
| CVE-2026-89907 | 8.8 | — | Linux | Linux | — | LoongArch: KVM: Validate MSI data before routing it to EIOINTC |
| CVE-2026-89908 | 8.8 | — | Linux | Linux | — | LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY |
| CVE-2026-89913 | 8.8 | — | Linux | Linux | — | KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables |
| CVE-2026-89928 | 8.8 | — | Linux | Linux | — | KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk |
| CVE-2026-89929 | 8.8 | — | Linux | Linux | — | KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU |
| CVE-2026-89932 | 8.8 | — | Linux | Linux | — | KVM: nVMX: Always flush vpid02 on first use |
| CVE-2026-89951 | 8.8 | — | Linux | Linux | — | batman-adv: fix stale receive device on merged fragments |
| CVE-2026-89957 | 8.8 | — | Linux | Linux | — | s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed |
| CVE-2026-89959 | 8.8 | — | Linux | Linux | — | s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove |
| CVE-2026-89960 | 8.8 | — | Linux | Linux | — | s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() |
| CVE-2026-89995 | 8.8 | — | Linux | Linux | — | dma-direct: return struct page from dma_direct_alloc_from_pool() |
| CVE-2026-90000 | 8.8 | — | Linux | Linux | — | HID: rmi: fix OOB access with undersized RMI reports |
| CVE-2026-90018 | 8.8 | — | Linux | Linux | — | staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() |
| CVE-2026-90041 | 8.8 | — | Linux | Linux | — | HID: sony: clean up device list on probe failure |
| CVE-2026-92122 | 8.8 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-693 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not che… |
| CVE-2026-92123 | 8.8 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-693 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not int… |
| CVE-2026-92124 | 8.8 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-693 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the o… |
| CVE-2026-92125 | 8.8 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-94 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not rej… |
| CVE-2026-92137 | 8.8 | — | Jenkins Project | Jenkins Robot Framework Plugin | CWE-22 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the arch… |
| CVE-2026-92566 | 8.8 | — | datageartech | datagear | CWE-918 | DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview |
| CVE-2026-92729 | 8.8 | — | SigNoz | signoz | CWE-306 | SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analyt… |
| CVE-2026-40854 | 8.7 | — | WNC | T-Mobile 5G Box IDU | CWE-290 | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
| CVE-2026-47094 | 8.7 | — | SIMAC | MyPHR | CWE-639 | SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id} |
| CVE-2026-73174 | 8.7 | — | Advantech | EKI-1242IEIMS | CWE-319 | Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitiv… |
| CVE-2026-75516 | 8.7 | — | rabbitmq | rabbitmq-java-client | CWE-770 | RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0)… |
| CVE-2026-77404 | 8.7 | — | rabbitmq | amqp091-go | CWE-116 | RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS P… |
| CVE-2026-82410 | 8.7 | — | pocketbase | pocketbase | CWE-248 | Pocketbase: Unhandled panic in worker goroutines |
| CVE-2026-86106 | 8.7 | — | Arista Networks | VeloCloud Edge | CWE-306 | Security Advisory 0179 |
| CVE-2026-86831 | 8.7 | — | AWS | aws-network-policy-agent | CWE-1289 | Improper validation of pod identifier uniqueness in aws-network-policy-agent … |
| CVE-2026-88817 | 8.7 | — | Curiosity GmbH | Curiosity Workspace | CWE-269 | Privilege escalation via legacy access group creation endpoint |
| CVE-2026-92466 | 8.7 | — | zlt2000 | microservices-platform | CWE-862 | microservices-platform through 6.0.0 Missing Authorization via Disabled URL P… |
| CVE-2026-92467 | 8.7 | — | zlt2000 | microservices-platform | CWE-620 | microservices-platform through 6.0.0 Unverified Password Change via /users/pa… |
| CVE-2026-92577 | 8.7 | — | WWBN | AVideo | CWE-639 | AVideo through 29.0 API get_api_video Broken Access Control via clean_title |
| CVE-2026-92580 | 8.7 | — | WWBN | AVideo | CWE-78 | AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF |
| CVE-2026-92592 | 8.7 | — | craftcms | cms | CWE-1336 | Craft CMS before 4.18.6 Remote Code Execution via signed cookie |
| CVE-2026-92593 | 8.7 | — | craftcms | cms | CWE-94 | Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
| CVE-2026-92594 | 8.7 | — | craftcms | cms | CWE-200 | Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL |
| CVE-2026-92596 | 8.7 | — | nodemailer | nodemailer | CWE-400 | Nodemailer before 9.1.0 Denial of Service via addressparser |
| CVE-2026-92599 | 8.7 | — | hapijs | joi | CWE-1333 | Joi before 17.13.7 and 18.2.6 ReDoS via isoDate |
| CVE-2026-92719 | 8.7 | — | quickwit-oss | quickwit | CWE-918 | Quickwit through 0.9.0 SSRF via SQS queue_url Parameter |
| CVE-2026-92748 | 8.7 | — | BC-SECURITY | Empire | CWE-22 | BC Security Empire before 6.7.1 Path Traversal File Upload RCE |
| CVE-2026-92752 | 8.7 | — | metasfresh | metasfresh | CWE-639 | metasfresh Unauthorized Access via Document Attachments and Comments Endpoints |
| CVE-2026-92761 | 8.7 | — | retspen | webvirtcloud | CWE-862 | WebVirtCloud Missing Authorization on Instance Control Actions |
| CVE-2026-92762 | 8.7 | — | pelican | panel | CWE-862 | Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup |
| CVE-2026-92780 | 8.7 | — | didi | KnowStreaming | CWE-862 | KnowStreaming through 3.4.1 Missing Authorization on the REST API |
| CVE-2026-92788 | 8.7 | — | coze-dev | coze-studio | CWE-863 | Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node |
| CVE-2026-92791 | 8.7 | — | uber | kraken | CWE-22 | Uber Kraken through 0.1.29 Path Traversal via tag parameter |
| CVE-2026-92792 | 8.7 | — | OpenNHP | opennhp | CWE-287 | OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier |
| CVE-2026-92794 | 8.7 | — | OpenSignLabs | OpenSign | CWE-862 | OpenSign through 2.41.3 Information Disclosure via getDocument |
| CVE-2026-92796 | 8.7 | — | manticoresoftware | Manticore Search | CWE-863 | Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass |
| CVE-2026-92801 | 8.7 | — | chenhg5 | cc-connect | CWE-863 | cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions |
| CVE-2026-92815 | 8.7 | — | dgtlmoon | changedetection.io | CWE-918 | changedetection.io through 0.60.6 SSRF via browser-step Goto URL |
| CVE-2026-19535 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-352 | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) … |
| CVE-2026-20135 | 8.6 | — | Cisco | Cisco Secure Firewall Threat Defense (FTD) Software | CWE-415 | Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulne… |
| CVE-2026-20154 | 8.6 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-835 | Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewal… |
| CVE-2026-20249 | 8.6 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-704 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat … |
| CVE-2026-20250 | 8.6 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-772 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat … |
| CVE-2026-20295 | 8.6 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-789 | Cisco Secure Firewall Management Center and Secure Firewall Threat Defense So… |
| CVE-2026-20352 | 8.6 | — | Cisco | Cisco Identity Services Engine Software | CWE-119 | Cisco Identity Services Engine RADIUS Denial of Service Vulnerability |
| CVE-2026-73163 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-73164 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-73165 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-73166 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-94 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of C… |
| CVE-2026-73167 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-73170 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-94 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of C… |
| CVE-2026-73171 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-73 | Nozomi Networks Labs identified a CWE-73: External Control of File Name or Pa… |
| CVE-2026-73176 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-78 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special … |
| CVE-2026-73177 | 8.6 | — | Advantech | EKI-1242IEIMS | CWE-345 | Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data … |
| CVE-2026-91098 | 8.6 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-122 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-91105 | 8.6 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-122 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-92716 | 8.6 | — | Shuffle | Shuffle | CWE-639 | Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation |
| CVE-2026-92763 | 8.6 | — | rundeck | rundeck | CWE-862 | Rundeck through 6.2.1 Authorization Bypass via Project Import |
| CVE-2026-92776 | 8.6 | — | requarks | Wiki.js | CWE-863 | Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass |
| CVE-2026-92782 | 8.6 | — | chroma-core | chroma | CWE-863 | Chroma through 1.5.9 Authorization Bypass via Collection Identifier |
| CVE-2026-92793 | 8.6 | — | GoAdminGroup | go-admin | CWE-863 | GoAdmin through 1.2.26 Authorization Bypass via Query Parameter |
| CVE-2026-76412 | 8.5 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-264 | Cisco Secure Firewall Management Center Software Authenticated Privilege Esca… |
| CVE-2026-86359 | 8.5 | — | Dell | Repository Manager | CWE-276 | Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Defau… |
| CVE-2026-92397 | 8.5 | — | Ruijie | RG-EW3000GX | CWE-77 | Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection |
| CVE-2026-92398 | 8.5 | — | Ruijie | RG-EW3000GX | CWE-77 | Ruijie RG-EW3000GX user_list_note admin os command injection |
| CVE-2026-92786 | 8.5 | — | lightgbm-org | LightGBM | CWE-787 | LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model |
| CVE-2026-92816 | 8.5 | — | Comfy-Org | ComfyUI | CWE-22 | ComfyUI before 0.30.0 Path Traversal via dataset save nodes |
| CVE-2026-20334 | 8.4 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-710 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-40857 | 8.4 | — | WNC | T-Mobile 5G Box IDU | CWE-352 | CSRF token bypass in T-Mobile 5G Box IDU routers |
| CVE-2026-76825 | 8.4 | — | zopefoundation | RestrictedPython | CWE-200 | RestrictedPython: Sandbox escape via string.Formatter field resolution |
| CVE-2026-89795 | 8.4 | — | Linux | Linux | — | PCI: Allow per function PCI slots to fix slot reset on s390 |
| CVE-2026-89806 | 8.4 | — | Linux | Linux | — | drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation |
| CVE-2026-89856 | 8.4 | — | Linux | Linux | — | scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation |
| CVE-2026-89877 | 8.4 | — | Linux | Linux | — | media: saa7164: fix cleanup on resource allocation failure |
| CVE-2026-89885 | 8.4 | — | Linux | Linux | — | media: platform: mtk-mdp3: Fix SCP device refcounting |
| CVE-2026-89904 | 8.4 | — | Linux | Linux | — | LoongArch: Fix acpi_package_ids[] array overflow |
| CVE-2026-89943 | 8.4 | — | Linux | Linux | — | ASoC: loongson: Fix error handling in ACPI property parsing |
| CVE-2026-89980 | 8.4 | — | Linux | Linux | — | ALSA: harmony: initialize locks before requesting IRQ |
| CVE-2026-89992 | 8.4 | — | Linux | Linux | — | cpuidle: dt_idle_genpd: kfree() the original name allocation |
| CVE-2026-91102 | 8.4 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-78 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-20323 | 8.3 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-295 | Cisco Secure Firewall Management Center and Secure Firewall Threat Defense So… |
| CVE-2026-92597 | 8.3 | — | nodemailer | nodemailer | CWE-436 | Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment |
| CVE-2026-92598 | 8.3 | — | nodemailer | nodemailer | CWE-436 | Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass |
| CVE-2026-63127 | 8.2 | — | modelcontextprotocol | rust-sdk | CWE-345 | RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata … |
| CVE-2026-71180 | 8.2 | — | Dell | Update Package Framework | CWE-252 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchec… |
| CVE-2026-76413 | 8.2 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-1259 | Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery… |
| CVE-2026-77406 | 8.2 | — | rabbitmq | amqp091-go | CWE-195 | RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer… |
| CVE-2026-77409 | 8.2 | — | rabbitmq | amqp091-go | CWE-770 | RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking |
| CVE-2026-86107 | 8.2 | — | Arista Networks | VeloCloud | CWE-787 | Security Advisory 0180 |
| CVE-2026-89028 | 8.2 | — | MikroTik | RouterOS | CWE-122 | MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX |
| CVE-2026-89973 | 8.2 | — | Linux | Linux | — | nvme-tcp: check the data direction of a C2HData PDU |
| CVE-2026-92591 | 8.2 | — | craftcms | cms | CWE-636 | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
| CVE-2025-43936 | 8.1 | — | Dell | ObjectScale | CWE-287 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper… |
| CVE-2026-20335 | 8.1 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-682 | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Def… |
| CVE-2026-61591 | 8.1 | — | djust-org | djust | CWE-345 | djust: Unsigned client state snapshot is restored as trusted view state (priv… |
| CVE-2026-61593 | 8.1 | — | djust-org | djust | CWE-352 | djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a c… |
| CVE-2026-63671 | 8.1 | — | nuxt-content | mdc | CWE-79 | @nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allo… |
| CVE-2026-74909 | 8.1 | — | Red Hat | Red Hat build of Keycloak 26.4 | CWE-862 | Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allow… |
| CVE-2026-89848 | 8.1 | — | Linux | Linux | — | scsi: qla2xxx: Quiesce response IRQ before freeing request queue |
| CVE-2026-89861 | 8.1 | — | Linux | Linux | — | scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() |
| CVE-2026-89999 | 8.1 | — | Linux | Linux | — | HID: wacom: validate report length in wacom_intuos_pro2_bt_irq |
| CVE-2026-92087 | 8.1 | — | @fastify/auth | @fastify/auth | CWE-285 | @fastify/auth vulnerable to Authorization Bypass via order-dependent evaluati… |
| CVE-2026-85469 | 8.0 | — | Red Hat | Red Hat Quay 3 | CWE-1357 | Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party actio… |
| CVE-2026-89947 | 8.0 | — | Linux | Linux | — | clk: meson: align gxbb_32k_clk_sel number of parents with actual count |
| CVE-2026-89954 | 8.0 | — | Linux | Linux | — | mtd: afs: validate v2 image info bounds |
| CVE-2026-92127 | 8.0 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-94 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automaticall… |
| CVE-2026-92134 | 8.0 | — | Jenkins Project | Jenkins Warnings Plugin | CWE-79 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not valida… |
| CVE-2026-92135 | 8.0 | — | Jenkins Project | Jenkins Coverage Plugin | CWE-79 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate th… |
| CVE-2026-92136 | 8.0 | — | Jenkins Project | Jenkins OWASP Dependency-Check Plugin | CWE-79 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE v… |
| CVE-2026-89911 | 7.9 | — | Linux | Linux | — | KVM: arm64: Correctly cap TLBI Range to the architural limit |
| CVE-2026-59974 | 7.8 | — | stanfordnlp | stanza | CWE-22 | Stanza: Zip Slip Path Traversal in Model/Resource Extraction |
| CVE-2026-63325 | 7.8 | — | Redocly | redocly-cli | CWE-94 | Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `r… |
| CVE-2026-89799 | 7.8 | — | Linux | Linux | — | bpf: Disable preemption in bpf_get_stackid |
| CVE-2026-89801 | 7.8 | — | Linux | Linux | — | drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE |