Security Box Score — September 16, 2026 — page 2
Edition of September 16, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-89803 | 7.8 | — | Linux | Linux | — | drm/nouveau: unsubscribe the channel-kill event before the fence context |
| CVE-2026-89805 | 7.8 | — | Linux | Linux | — | drm/pagemap: Fix folio allocation fallback and use-after-put |
| CVE-2026-89808 | 7.8 | — | Linux | Linux | — | drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram |
| CVE-2026-89810 | 7.8 | — | Linux | Linux | — | drm/amdkfd: Fix error path at svm_migrate_copy_to_ram |
| CVE-2026-89814 | 7.8 | — | Linux | Linux | — | drm/amdgpu: clamp the isolation index for rings outside a partition |
| CVE-2026-89815 | 7.8 | — | Linux | Linux | — | drm/ttm: Drop tt->restore after successful restore |
| CVE-2026-89819 | 7.8 | — | Linux | Linux | — | drm/amd/display: validate plane degamma LUT size for private color prop |
| CVE-2026-89823 | 7.8 | — | Linux | Linux | — | drm: fix race between partial drm_dev_register() failure and ioctl |
| CVE-2026-89825 | 7.8 | — | Linux | Linux | — | drm/panthor: fix firmware control interface bounds checks |
| CVE-2026-89829 | 7.8 | — | Linux | Linux | — | f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() |
| CVE-2026-89832 | 7.8 | — | Linux | Linux | — | f2fs: fix to clear dirty flag on folio in error path |
| CVE-2026-89836 | 7.8 | — | Linux | Linux | — | f2fs: fix folio_nr_pages() race after put in large folio invalidate |
| CVE-2026-89841 | 7.8 | — | Linux | Linux | — | f2fs: only redirty pinned folios in redirty_blocks |
| CVE-2026-89854 | 7.8 | — | Linux | Linux | — | scsi: qla2xxx: Fix cs84xx use-after-free on host teardown |
| CVE-2026-89870 | 7.8 | — | Linux | Linux | — | media: zoran: Avoid freeing a registered video_device twice |
| CVE-2026-89873 | 7.8 | — | Linux | Linux | — | media: v4l2-ctrls: validate HEVC EXT SPS RPS counts |
| CVE-2026-89875 | 7.8 | — | Linux | Linux | — | media: ti: vpe: quiesce overflow recovery before freeing streams |
| CVE-2026-89880 | 7.8 | — | Linux | Linux | — | media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure |
| CVE-2026-89882 | 7.8 | — | Linux | Linux | — | media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow |
| CVE-2026-89883 | 7.8 | — | Linux | Linux | — | media: rc: sunxi-cir: Unregister rc device on probe failure |
| CVE-2026-89887 | 7.8 | — | Linux | Linux | — | media: i2c: ov7740: fix use-after-destroy in remove |
| CVE-2026-89888 | 7.8 | — | Linux | Linux | — | media: i2c: ov02a10: fix endpoint parsing use-after-free |
| CVE-2026-89890 | 7.8 | — | Linux | Linux | — | media: go7007: defer the ALSA v4l2 put until card release |
| CVE-2026-89893 | 7.8 | — | Linux | Linux | — | media: cx23885: cancel NetUP CI work before teardown |
| CVE-2026-89894 | 7.8 | — | Linux | Linux | — | media: cx231xx: reject geometry changes while the VBI queue is busy |
| CVE-2026-89899 | 7.8 | — | Linux | Linux | — | media: cec: disable delayed work before freeing an interrupted transmit |
| CVE-2026-89902 | 7.8 | — | Linux | Linux | — | LoongArch: Avoid preempt count underflow without probe |
| CVE-2026-89903 | 7.8 | — | Linux | Linux | — | LoongArch: Do not save/restore percpu base register in rethook trampoline |
| CVE-2026-89906 | 7.8 | — | Linux | Linux | — | LoongArch: BPF: Refactor jump offset calculation in tail call |
| CVE-2026-89919 | 7.8 | — | Linux | Linux | — | KVM: s390: keyop: use mmu_lock to read gmap->asce |
| CVE-2026-89920 | 7.8 | — | Linux | Linux | — | KVM: s390: Fix memory corruption by not reinjecting CK machine checks |
| CVE-2026-89922 | 7.8 | — | Linux | Linux | — | KVM: s390: Take srcu when importing watchpoint data |
| CVE-2026-89938 | 7.8 | — | Linux | Linux | — | iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF |
| CVE-2026-89940 | 7.8 | — | Linux | Linux | — | iio: buffer: Tie IIO dma fence lock lifetime to the fence |
| CVE-2026-89941 | 7.8 | — | Linux | Linux | — | iio: buffer: Make IIO DMA fence release RCU-safe |
| CVE-2026-89942 | 7.8 | — | Linux | Linux | — | iio: buffer: Fix potential use-after-free in anonymous buffer release |
| CVE-2026-89961 | 7.8 | — | Linux | Linux | — | powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population |
| CVE-2026-89965 | 7.8 | — | Linux | Linux | — | nvdimm/btt: reject an arena whose nfree is below the lane count |
| CVE-2026-89967 | 7.8 | — | Linux | Linux | — | mm/migrate_device: avoid out-of-bounds writes for compound folios |
| CVE-2026-89979 | 7.8 | — | Linux | Linux | — | ALSA: pcm: Fix race between non-atomic ops and trigger-start |
| CVE-2026-89985 | 7.8 | — | Linux | Linux | — | memcg: keep folio's objcg same as its node |
| CVE-2026-89986 | 7.8 | — | Linux | Linux | — | mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() |
| CVE-2026-89988 | 7.8 | — | Linux | Linux | — | kprobes: Protect kprobe_blacklist with RCU |
| CVE-2026-89994 | 7.8 | — | Linux | Linux | — | dmaengine: fsl-edma: tracing: no ptr dereference during log output |
| CVE-2026-89997 | 7.8 | — | Linux | Linux | — | dm: fix resume-vs-remove race |
| CVE-2026-89998 | 7.8 | — | Linux | Linux | — | dm: fix race when loading and unloading a table |
| CVE-2026-90001 | 7.8 | — | Linux | Linux | — | HID: bpf: serialize device reference release in struct_ops destroy path |
| CVE-2026-90002 | 7.8 | — | Linux | Linux | — | ftrace: Take trace_array reference before accessing its ftrace_ops |
| CVE-2026-90003 | 7.8 | — | Linux | Linux | — | futex: Prevent rcuwait use-after-free during requeue PI |
| CVE-2026-90007 | 7.8 | — | Linux | Linux | — | scsi: pm8001: Use rollback index when freeing MSI-X vectors |
| CVE-2026-90008 | 7.8 | — | Linux | Linux | — | scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame |
| CVE-2026-90009 | 7.8 | — | Linux | Linux | — | scsi: bsg: Fix TOCTOU in io_uring passthrough command setup |
| CVE-2026-90010 | 7.8 | — | Linux | Linux | — | scsi: bsg: Cap io_uring sense copy to max_response_len |
| CVE-2026-90013 | 7.8 | — | Linux | Linux | — | tracing: Take trace_array reference when opening options file |
| CVE-2026-90014 | 7.8 | — | Linux | Linux | — | tracing: Have show_event_filters/triggers files take trace array ref |
| CVE-2026-90022 | 7.8 | — | Linux | Linux | — | usb: gadget: f_midi2: fix use-after-free in string attribute show path |
| CVE-2026-90026 | 7.8 | — | Linux | Linux | — | usb: typec: qcom-pmic: cancel reset_work on stop |
| CVE-2026-90027 | 7.8 | — | Linux | Linux | — | usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop |
| CVE-2026-90030 | 7.8 | — | Linux | Linux | — | usb: dwc3: clear forceRM when issuing EndTransfer |
| CVE-2026-90032 | 7.8 | — | Linux | Linux | — | media: usbtv: keep device alive while ALSA card exists |
| CVE-2026-90043 | 7.8 | — | Linux | Linux | — | zram: fix slot lock bit position on big-endian 64-bit |
| CVE-2026-90044 | 7.8 | — | Linux | Linux | — | usb: gadget: f_fs: Fix Use-After-Free in AIO error path |
| CVE-2026-90045 | 7.8 | — | Linux | Linux | — | USB: gadget: ffs: fix mm lifetime handling |
| CVE-2026-90046 | 7.8 | — | Linux | Linux | — | mm/page_alloc: don't spin_trylock() in NMI on UP |
| CVE-2026-90047 | 7.8 | — | Linux | Linux | — | drm/xe: Don't hand out the flat CCS storage as usable VRAM |
| CVE-2026-14916 | 7.7 | — | Kong | Kong Enteprise Gateway | CWE-241 | Kong API Gateway Enterprise: JWT Algorithm-Confusion |
| CVE-2026-14917 | 7.7 | — | Kong | Kong Enterprise Gateway | CWE-288 | Kong API Gateway Enterprise: SAML Authentication bypass |
| CVE-2026-20342 | 7.7 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-639 | Cisco Secure Firewall Management Center Software Low Privileged Arbitrary Fil… |
| CVE-2026-61595 | 7.7 | — | djust-org | djust | CWE-636 | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosin… |
| CVE-2026-62997 | 7.7 | — | kedro-org | kedro-plugins | CWE-502 | Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via un… |
| CVE-2026-85385 | 7.7 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field |
| CVE-2026-86474 | 7.7 | — | Fermax Electronica S.A.U. | DUOX PLUS monitor firmware (VEO Wi-Fi range) | CWE-295 | Improper Certificate Validation in the Firmware Download vulnerability |
| CVE-2026-86585 | 7.7 | — | Fermax Electronica S.A.U. | DUOX PLUS monitor firmware (VEO Wi-Fi range) | CWE-347 | Improper Verification of the Firmware Signature vulnerability |
| CVE-2026-90025 | 7.7 | — | Linux | Linux | — | usb: typec: ucsi: displayport: Fix OOB altmode array index |
| CVE-2026-92784 | 7.7 | — | refinedev | @refinedev/inferencer | CWE-94 | @refinedev/inferencer through 7.0.0 Code Injection via API Field Names |
| CVE-2026-76425 | 7.6 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco ISE SQL Injection Vulnerability |
| CVE-2026-92465 | 7.6 | — | Themeum | WP Mega Menu | CWE-89 | WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability |
| CVE-2026-92616 | 7.6 | — | error311 | FileRise | CWE-613 | FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance |
| CVE-2026-92800 | 7.6 | — | suitenumerique | Docs | CWE-613 | Docs before 5.4.1 Stale Collaboration Session After Access Revocation |
| CVE-2026-92812 | 7.6 | — | decaporg | decap-server | CWE-22 | decap-server Path Traversal via Sibling Directory Prefix Matching |
| CVE-2026-18212 | 7.5 | — | Red Hat | Red Hat build of Keycloak 26.4 | CWE-401 | Keycloak-services: keycloak-services: saml redirect deflate helpers leak nati… |
| CVE-2026-19666 | 7.5 | — | ISC | BIND 9 | CWE-416 | Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path |
| CVE-2026-19667 | 7.5 | — | ISC | BIND 9 | CWE-197 | Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` |
| CVE-2026-20247 | 7.5 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco Identity Services Engine Unauthenticated SQL Injection Vulnerability |
| CVE-2026-20343 | 7.5 | — | Cisco | Cisco Secure Firewall Management Center (FMC) | CWE-306 | Cisco Secure Firewall Management Center Software Information Disclosure and D… |
| CVE-2026-46352 | 7.5 | — | OISF | suricata | CWE-833 | Suricata defrag: fragmented encapsulated traffic with fragments can lead to d… |
| CVE-2026-63126 | 7.5 | — | square | wire | CWE-190 | Wire: Unauthenticated decoder crash via 32-bit length integer overflow in Byt… |
| CVE-2026-63128 | 7.5 | — | modelcontextprotocol | rust-sdk | CWE-400 | RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP se… |
| CVE-2026-76163 | 7.5 | — | ISC | BIND 9 | CWE-617 | named aborts on a TKEY query when the user configuration has no global option… |
| CVE-2026-77692 | 7.5 | — | ISC | BIND 9 | CWE-476 | Unauthenticated remote crash of named via a single DoH SIG(0) request |
| CVE-2026-79651 | 7.5 | — | Red Hat | Red Hat build of Keycloak 26.4 | CWE-400 | Keycloak-services: keycloak-services: unauthenticated dos via unbounded local… |
| CVE-2026-80274 | 7.5 | — | ISC | BIND 9 | CWE-617 | Validating resolver can abort while caching a mismatched NOQNAME proof |
| CVE-2026-81563 | 7.5 | — | ISC | BIND 9 | CWE-401 | SVCB AliasMode additional-data error leaks qpcache references |
| CVE-2026-81736 | 7.5 | — | ISC | BIND 9 | CWE-1050 | Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees |
| CVE-2026-81875 | 7.5 | — | hapifhir | org.hl7.fhir.core | CWE-20 | HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service |
| CVE-2026-81876 | 7.5 | — | hapifhir | org.hl7.fhir.core | CWE-20 | HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service |
| CVE-2026-82399 | 7.5 | — | coredns | coredns | CWE-770 | CoreDNS: Unauthenticated memory exhaustion in custom transports |
| CVE-2026-84997 | 7.5 | — | reactphp | http | CWE-835 | react/http: A malformed HTTP chunked body can lead to a denial-of-service and… |
| CVE-2026-85756 | 7.5 | — | sshnet | SSH.NET | CWE-78 | SSH.NET: ScpClient allows server-side RCE via default SCP path handling |
| CVE-2026-86003 | 7.5 | — | coredns | coredns | CWE-441 | CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP |
| CVE-2026-86043 | 7.5 | — | zalando | skipper | CWE-863 | Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunk… |
| CVE-2026-89863 | 7.5 | — | Linux | Linux | — | scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check |
| CVE-2026-89897 | 7.5 | — | Linux | Linux | — | media: cec: Serialize exclusive follower delivery |
| CVE-2026-89968 | 7.5 | — | Linux | Linux | — | nvmet-tcp: reject unsolicited H2CData PDUs |
| CVE-2026-89971 | 7.5 | — | Linux | Linux | — | nvme: skip the zoned limits update if the zone info query failed |
| CVE-2026-89974 | 7.5 | — | Linux | Linux | — | nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails |
| CVE-2026-92128 | 7.5 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-494 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a … |
| CVE-2026-92129 | 7.5 | — | Jenkins Project | Jenkins Script Security Plugin | CWE-693 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not che… |
| CVE-2026-92625 | 7.5 | — | Control iD | iDSecure | CWE-306 | Control iD iDSecure Unauthenticated Denial of Service |
| CVE-2026-92626 | 7.5 | — | Control iD | iDSecure | CWE-476 | Control iD iDSecure Unauthenticated Denial of Service |
| CVE-2026-20222 | 7.4 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-401 | Cisco Secure Adaptive Security Appliance Software and Secure Firewall Threat … |
| CVE-2026-42784 | 7.4 | — | Red Hat | Confidential Compute Attestation | CWE-347 | Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key … |
| CVE-2026-61590 | 7.4 | — | djust-org | djust | CWE-306 | djust's observability endpoints are network-exposed: the localhost gate is an… |
| CVE-2026-61592 | 7.4 | — | djust-org | djust | CWE-384 | djust: SSE sessions are not bound to the authenticated user; the client-chose… |
| CVE-2026-71179 | 7.3 | — | Dell | Update Package Framework | CWE-78 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improp… |
| CVE-2026-85386 | 7.3 | — | Concrete CMS | Concrete CMS | CWE-79 | Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via u… |
| CVE-2026-89910 | 7.3 | — | Linux | Linux | — | LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc |
| CVE-2026-17526 | 7.2 | — | Red Hat | Red Hat build of Keycloak 26.4 | CWE-862 | Keycloak-services: keycloak-services: privilege escalation via impersonation … |
| CVE-2026-76424 | 7.2 | — | Cisco | Cisco Identity Services Engine Software | CWE-23 | Cisco ISE Arbitrary File Access Vulnerability |
| CVE-2026-87024 | 7.2 | — | Tanium | Asset | CWE-89 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2026-87976 | 7.2 | — | Apache Software Foundation | Apache NiFi Registry | CWE-22 | Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension … |
| CVE-2026-92469 | 7.2 | — | zlt2000 | microservices-platform | CWE-639 | microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Owne… |
| CVE-2026-92604 | 7.2 | — | StamusNetworks | scirius | CWE-22 | Scirius through 3.8.0 Arbitrary File Write via PCAP Upload |
| CVE-2026-92751 | 7.2 | — | yahoo | CMAK | CWE-352 | CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter |
| CVE-2026-92779 | 7.2 | — | BuilderIO | @builder.io/sdk-react | CWE-1321 | Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings |
| CVE-2026-92783 | 7.2 | — | yeti-platform | yeti | CWE-862 | Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion |
| CVE-2026-92806 | 7.2 | — | phpList | phpList | CWE-352 | phpList before 3.6.17 Cross-Site Request Forgery via massremove.php |
| CVE-2026-20300 | 7.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco Identity Services Engine SQL Injection Vulnerability |
| CVE-2026-40856 | 7.1 | — | WNC | T-Mobile 5G Box IDU | CWE-306 | Config disclosure in T-Mobile 5G Box IDU routers |
| CVE-2026-61596 | 7.1 | — | djust-org | djust | CWE-639 | djust has broken object-level access control (IDOR) |
| CVE-2026-61598 | 7.1 | — | djust-org | djust | CWE-915 | Client mass-assignment of arbitrary view attributes via the default dj-model … |
| CVE-2026-73175 | 7.1 | — | Advantech | EKI-1242IEIMS | CWE-400 | Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption … |
| CVE-2026-73462 | 7.1 | — | Arista Networks | EOS | CWE-125 | On affected platforms running Arista EOS with IGMP (Internet Group Management… |
| CVE-2026-89034 | 7.1 | — | TCH | QRing | CWE-306 | TCH QRing R20_B006 Unauthenticated BLE Access |
| CVE-2026-89818 | 7.1 | — | Linux | Linux | — | drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check |
| CVE-2026-89826 | 7.1 | — | Linux | Linux | — | drm/panthor: harden firmware build-info bounds checks |
| CVE-2026-89838 | 7.1 | — | Linux | Linux | — | f2fs: limit recovery filename logging to stored length |
| CVE-2026-89840 | 7.1 | — | Linux | Linux | — | f2fs: validate MOVE_RANGE destination size |
| CVE-2026-89912 | 7.1 | — | Linux | Linux | — | KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save |
| CVE-2026-89927 | 7.1 | — | Linux | Linux | — | KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock |
| CVE-2026-90016 | 7.1 | — | Linux | Linux | — | staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() |
| CVE-2026-90017 | 7.1 | — | Linux | Linux | — | staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() |
| CVE-2026-92417 | 7.1 | — | n/a | Open5GS | CWE-404 | Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference |
| CVE-2026-92456 | 7.1 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configura… |
| CVE-2026-92457 | 7.1 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueI… |
| CVE-2026-92459 | 7.1 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint |
| CVE-2026-92460 | 7.1 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing |
| CVE-2026-92462 | 7.1 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlo… |
| CVE-2026-92463 | 7.1 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on Syst… |
| CVE-2026-92468 | 7.1 | — | zlt2000 | microservices-platform | CWE-639 | microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via s… |
| CVE-2026-92567 | 7.1 | — | TDuckCloud | tduck-survey-form | CWE-639 | TDuck survey form through 5.0 Unauthorized Data Modification |
| CVE-2026-92570 | 7.1 | — | yogeshojha | rengine | CWE-862 | reNgine through 2.2.0 Unauthorized Configuration File Read |
| CVE-2026-92582 | 7.1 | — | WWBN | AVideo | CWE-352 | AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass |
| CVE-2026-92600 | 7.1 | — | stylefeng | Guns | CWE-862 | Guns through 8.3.5 Information Disclosure via Missing Permission Check |
| CVE-2026-92601 | 7.1 | — | stylefeng | Guns | CWE-862 | Guns through 8.3.5 Improper Access Control via SysNoticeController |
| CVE-2026-92602 | 7.1 | — | TDuckCloud | tduck-survey-form | CWE-918 | TDuck survey form through 5.3 Server-Side Request Forgery via Unvalidated Web… |
| CVE-2026-92603 | 7.1 | — | continew-org | continew-admin | CWE-639 | ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageCon… |
| CVE-2026-92605 | 7.1 | — | dfir-iris | iris-web | CWE-639 | IRIS through 2.4.29 Unauthorized Comment Access via Object ID |
| CVE-2026-92750 | 7.1 | — | harness | harness | CWE-862 | Harness through 3.3.0 Missing Access Control via infraproviders endpoint |
| CVE-2026-92753 | 7.1 | — | Patrowl | PatrowlManager | CWE-862 | PatrowlManager through 1.8.4 Authorization Bypass via Events API |
| CVE-2026-92759 | 7.1 | — | SecObserve | SecObserve | CWE-522 | SecObserve before 1.59.1 Information Disclosure via API Configuration |
| CVE-2026-92760 | 7.1 | — | shlinkio | shlink | CWE-863 | Shlink through 5.1.6 Mercure Token Authorization Bypass |
| CVE-2026-92765 | 7.1 | — | archerysec | archerysec | CWE-639 | ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList |
| CVE-2026-92770 | 7.1 | — | goharbor | harbor | CWE-200 | Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter |
| CVE-2026-92771 | 7.1 | — | twentyhq | twenty | CWE-863 | Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query |
| CVE-2026-92772 | 7.1 | — | Leantime | leantime | CWE-862 | Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX |
| CVE-2026-92773 | 7.1 | — | triggerdotdev | trigger.dev | CWE-639 | Trigger.dev before 4.6.0 GitHub App Installation Takeover |
| CVE-2026-92775 | 7.1 | — | requarks | Wiki.js | CWE-918 | Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch |
| CVE-2026-92789 | 7.1 | — | Graylog2 | graylog2-server | CWE-918 | Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect |
| CVE-2026-92795 | 7.1 | — | coze-dev | coze-studio | CWE-918 | Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin |
| CVE-2026-92804 | 7.1 | — | NangoHQ | Nango | CWE-918 | Nango through 0.70.4 Server-Side Request Forgery via Configuration |
| CVE-2026-92811 | 7.1 | — | browserless | browserless | CWE-200 | browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass |
| CVE-2026-68904 | 7.0 | — | node-opcua | node-opcua | CWE-400 | node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - R… |
| CVE-2026-77407 | 7.0 | — | rabbitmq | amqp091-go | CWE-316 | RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authent… |
| CVE-2026-91097 | 7.0 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-787 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-92718 | 7.0 | — | projectdiscovery | nuclei | CWE-347 | Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Ti… |
| CVE-2026-92362 | 6.9 | — | ag-ui-protocol | ag-ui | CWE-400 | ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption |
| CVE-2026-92401 | 6.9 | — | ChangeWeDer | crm | CWE-287 | ChangeWeDer crm improper authentication |
| CVE-2026-92565 | 6.9 | — | lukevella | rallly | CWE-359 | Rallly before 4.15.0 Information Disclosure via polls.get |
| CVE-2026-92583 | 6.9 | — | WWBN | AVideo | CWE-307 | AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment |
| CVE-2026-92790 | 6.9 | — | higress-group | higress | CWE-703 | Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header |
| CVE-2026-92803 | 6.9 | — | LibreTranslate | LibreTranslate | CWE-862 | LibreTranslate through 1.9.6 Missing Access Check on the download_file Route |
| CVE-2026-92813 | 6.9 | — | metabase | Metabase | CWE-918 | Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass |
| CVE-2026-20248 | 6.8 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-195 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat … |
| CVE-2026-64684 | 6.8 | — | modelcontextprotocol | rust-sdk | CWE-200 | RMCP: Custom HTTP headers leak to cross-origin redirect targets |
| CVE-2026-77401 | 6.8 | — | zopefoundation | AccessControl | CWE-693 | Zope AccessControl: Information disclosure through Python string `format` and… |
| CVE-2026-91100 | 6.8 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-78 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-92140 | 6.8 | — | Jenkins Project | Jenkins Gitee Plugin | CWE-79 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sende… |
| CVE-2026-26947 | 6.7 | — | Dell | ECS | CWE-269 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prio… |
| CVE-2026-92615 | 6.6 | — | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-413 | Flightctl: flightctl: package-global go-git https transport mutated per-repo … |
| CVE-2026-19033 | 6.5 | — | ISC | BIND 9 | CWE-349 | Unauthenticated IXFR deltas are applied to the live zone before TSIG verifica… |
| CVE-2026-20283 | 6.5 | — | Cisco | Cisco Identity Services Engine Software | CWE-78 | Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability |
| CVE-2026-20287 | 6.5 | — | Cisco | Cisco Identity Services Engine Software | CWE-269 | Cisco Identity Services Engine Hardening Release - Improper Privlege Manageme… |
| CVE-2026-57173 | 6.5 | — | vllm-project | vllm | CWE-770 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions |
| CVE-2026-61588 | 6.5 | — | djust-org | djust | CWE-200 | djust's Django model serialization has no sensitive-field denylist: password … |
| CVE-2026-62949 | 6.5 | — | ronf | asyncssh | CWE-835 | AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MS… |
| CVE-2026-69147 | 6.5 | — | vllm-project | vllm | CWE-400 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reserva… |
| CVE-2026-76438 | 6.5 | — | Cisco | Cisco BroadWorks | CWE-863 | Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerab… |
| CVE-2026-84859 | 6.5 | — | Scada-LTS | Scada-LTS | — | Scada-LTS Authenticated Blind SQL Injection |
| CVE-2026-84993 | 6.5 | — | mikro-orm | mikro-orm | CWE-89 | MikroORM: SQL injection via unvalidated order direction in orderBy |
| CVE-2026-86358 | 6.5 | — | Dell | Update Package Framework | CWE-121 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-b… |
| CVE-2026-87076 | 6.5 | — | Tanium | Discover | CWE-200 | Tanium addressed an information disclosure vulnerability in Discover. |
| CVE-2026-87116 | 6.5 | — | Tanium | Threat Response | CWE-918 | Tanium addressed a server-side request forgery vulnerability in Threat Response. |
| CVE-2026-92139 | 6.5 | — | Jenkins Project | Jenkins Bitbucket Push and Pull Request Plugin | CWE-918 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts value… |
| CVE-2026-18120 | 6.3 | — | Concrete CMS | Concrete CMS | CWE-862 | Missing Authorization in legacy Express entries search endpoint allows disclo… |
| CVE-2026-56719 | 6.3 | — | MikroTik | RouterOS | CWE-125 | MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX |
| CVE-2026-61589 | 6.3 | — | djust-org | djust | CWE-348 | djust: WebSocket/runtime reconstructed request omits the client Host, causing… |
| CVE-2026-73169 | 6.3 | — | Advantech | EKI-1242IEIMS | CWE-79 | Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input Du… |
| CVE-2026-77360 | 6.3 | — | middleapi | orpc | CWE-113 | oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS By… |
| CVE-2026-81871 | 6.3 | — | open-telemetry | opentelemetry-go | CWE-295 | OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pin… |
| CVE-2026-81872 | 6.3 | — | open-telemetry | opentelemetry-go | CWE-400 | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| CVE-2026-87113 | 6.3 | — | Tanium | Threat Response | CWE-639 | Tanium addressed an improper access controls vulnerability in Threat Response. |
| CVE-2026-20309 | 6.1 | — | Cisco | Cisco Identity Services Engine Software | CWE-79 | Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
| CVE-2026-59944 | 6.1 | — | composer | composer | CWE-22 | Composer: CVE-2026-59946 fix bypass via symlinked package bin path |
| CVE-2026-88976 | 6.1 | — | udecode | plate | CWE-79 | @platejs/core HTML deserialization can trigger browser behavior during parsing |
| CVE-2026-73457 | 6.0 | — | Arista Networks | EOS | CWE-532 | Under certain circumstances, the gNPSI client credentials might be logged in … |
| CVE-2026-77190 | 6.0 | — | Arista Networks | EOS | CWE-20 | Security Advisory 0177 |
| CVE-2026-92595 | 6.0 | — | nodemailer | nodemailer | CWE-73 | Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent |
| CVE-2026-19662 | 5.9 | — | ISC | BIND 9 | CWE-416 | qpcache NOQNAME proof use-after-free crashes recursive resolver |
| CVE-2026-19941 | 5.9 | — | ISC | BIND 9 | CWE-345 | checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof |
| CVE-2026-77119 | 5.9 | — | ISC | BIND 9 | CWE-346 | NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets |
| CVE-2026-82561 | 5.9 | — | Apache Software Foundation | Apache NiFi | CWE-862 | Apache NiFi: Missing Authorization for Components Referenced in Flow Update M… |
| CVE-2026-92588 | 5.9 | — | n8n-io | n8n | CWE-639 | n8n before 1.123.76 Improper Authorization via Source Control Push |
| CVE-2026-20120 | 5.8 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-284 | Cisco FTD ACL bypass vulnerability |
| CVE-2026-20290 | 5.8 | — | Cisco | Cisco Secure Firewall Threat Defense (FTD) Software | CWE-805 | Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Servi… |
| CVE-2026-78301 | 5.8 | — | ISC | BIND 9 | CWE-349 | Out-of-zone database nodes can become authoritative zone cuts |
| CVE-2026-76104 | 5.5 | — | Dell | ObjectScale | CWE-732 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission… |
| CVE-2026-92366 | 5.5 | — | code-projects | Matrimonial System | CWE-74 | code-projects Matrimonial System Regular Search search.php sql injection |
| CVE-2026-92380 | 5.5 | — | n/a | WuzhiCMS | CWE-918 | WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery |
| CVE-2026-92399 | 5.5 | — | n/a | GPAC | CWE-119 | GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow |
| CVE-2026-92405 | 5.5 | — | SourceCodester | Inventory and Monitoring System | CWE-74 | SourceCodester Inventory and Monitoring System index.php sql injection |
| CVE-2026-92406 | 5.5 | — | SourceCodester | Inventory and Monitoring System | CWE-74 | SourceCodester Inventory and Monitoring System btn_functions.php add sql inje… |
| CVE-2026-84397 | 5.4 | — | Adobe | Adobe Experience Manager as a Cloud Service | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-92132 | 5.4 | — | Jenkins Project | Jenkins Gradle Plugin | CWE-74 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build sc… |
| CVE-2026-92133 | 5.4 | — | Jenkins Project | Jenkins GitLab Plugin | CWE-522 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API… |
| CVE-2026-19607 | 5.3 | — | Red Hat | Red Hat build of Keycloak 26.4 | CWE-287 | Keycloak-services: keycloak-services: broker-originated username collision ca… |
| CVE-2026-19668 | 5.3 | — | ISC | BIND 9 | CWE-407 | Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching |
| CVE-2026-20121 | 5.3 | — | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | CWE-284 | CIsco FTD Bypass Access List |
| CVE-2026-59823 | 5.3 | — | BerriAI | litellm | CWE-918 | LiteLLM: Server-side request forgery via the `user_config` request parameter … |
| CVE-2026-61709 | 5.3 | — | openfga | openfga | CWE-281 | OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decisi… |
| CVE-2026-73443 | 5.3 | — | Arista Networks | EOS | CWE-294 | On affected platforms running Arista EOS with VRRPv2 IP-AH authentication con… |
| CVE-2026-75029 | 5.3 | — | ISC | BIND 9 | CWE-405 | Message parser retains every identical singleton RDATA, enabling wire-to-work… |
| CVE-2026-76433 | 5.3 | — | Cisco | Cisco Identity Services Engine Software | CWE-22 | Cisco Identity Services Engine Information Disclosure Vulnerability |
| CVE-2026-76439 | 5.3 | — | Cisco | Cisco Identity Services Engine Software | CWE-306 | Cisco Identity Services Engine Event Injection Vulnerability |
| CVE-2026-76444 | 5.3 | — | Cisco | Cisco Identity Services Engine Software | CWE-306 | Cisco Identity Services Engine Information Disclosure Vulnerability |
| CVE-2026-76447 | 5.3 | — | Cisco | Cisco Identity Services Engine Software | CWE-306 | Cisco Identity Services Engine Certificate Reload Vulnerability |
| CVE-2026-81176 | 5.3 | — | sveltejs | devalue | CWE-770 | Svelte devalue: DoS via malformed input |
| CVE-2026-85104 | 5.3 | — | Sooma | Sooma tDCS Home Therapy | CWE-924 | Brain stimulation parameters can be modified via Bluetooth in Sooma |
| CVE-2026-87028 | 5.3 | — | Concrete CMS | Concrete CMS | CWE-862 | Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 throu… |
| CVE-2026-89029 | 5.3 | — | Adenion | Blog2Social | CWE-639 | Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler |
| CVE-2026-89030 | 5.3 | — | Adenion | Blog2Social | CWE-862 | Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user |
| CVE-2026-89031 | 5.3 | — | Adenion | Blog2Social | CWE-639 | Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_m… |
| CVE-2026-92356 | 5.3 | — | a2ui-project | a2ui | CWE-400 | a2ui-project a2ui Update Components basic_functions.ts updateComponents resou… |
| CVE-2026-92357 | 5.3 | — | a2ui-project | a2ui | CWE-200 | a2ui-project a2ui Model Processor model-processor.ts information disclosure |
| CVE-2026-92360 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-345 | ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput or… |
| CVE-2026-92361 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-400 | ag-ui-protocol ag-ui SSE Client client.go resource consumption |
| CVE-2026-92363 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-400 | ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption |
| CVE-2026-92365 | 5.3 | — | vllm-project | vllm | CWE-404 | vllm-project vllm thinking_budget_state.py algorithmic complexity |
| CVE-2026-92402 | 5.3 | — | ChangeWeDer | crm | CWE-862 | ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java… |
| CVE-2026-92416 | 5.3 | — | n/a | Open5GS | CWE-617 | Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report… |
| CVE-2026-92455 | 5.3 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endp… |
| CVE-2026-92458 | 5.3 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale |
| CVE-2026-92461 | 5.3 | — | guchengwuyue | yshop-crm | CWE-862 | yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint |
| CVE-2026-92568 | 5.3 | — | mlrun | mlrun | CWE-918 | MLRun through 1.11.0 Server-Side Request Forgery via Webhook |
| CVE-2026-92569 | 5.3 | — | opengoofy | hippo4j | CWE-918 | Hippo4j through 1.5.0 SSRF via clientAddress Parameter |
| CVE-2026-92579 | 5.3 | — | WWBN | AVideo | CWE-289 | AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision |
| CVE-2026-92581 | 5.3 | — | WWBN | AVideo | CWE-20 | AVideo through 29.0 Like Counter Desynchronization via Array Parameter |
| CVE-2026-92584 | 5.3 | — | WWBN | AVideo | CWE-79 | AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header |
| CVE-2026-92585 | 5.3 | — | WWBN | AVideo | CWE-862 | AVideo through 29.0 Missing Authorization Check via API Like Endpoint |
| CVE-2026-92586 | 5.3 | — | WWBN | AVideo | CWE-862 | AVideo through 29.0 Missing Authorization via comment API endpoint |
| CVE-2026-92587 | 5.3 | — | n8n-io | n8n | CWE-426 | n8n before 1.123.76 Sandbox Escape via Git Relative URL |
| CVE-2026-92589 | 5.3 | — | craftcms | cms | CWE-862 | Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder |
| CVE-2026-92754 | 5.3 | — | Patrowl | PatrowlManager | CWE-862 | PatrowlManager through 1.8.4 Improper Access Control via users API |
| CVE-2026-92764 | 5.3 | — | opencve | opencve | CWE-863 | OpenCVE before 3.1.0 Organization API Ignores Token Scope |
| CVE-2026-92774 | 5.3 | — | requarks | Wiki.js | CWE-863 | Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission |
| CVE-2026-92778 | 5.3 | — | yahoo | CMAK | CWE-693 | CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes |
| CVE-2026-92781 | 5.3 | — | BuilderIO | @builder.io/sdk-react | CWE-1321 | Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttri… |
| CVE-2026-92802 | 5.3 | — | kanbn | kan | CWE-862 | kan through 0.6.0 Authorization Bypass via GitHub Project Import |
| CVE-2026-92809 | 5.3 | — | PrestaShop | psgdpr | CWE-639 | PrestaShop psgdpr through 1.4.3 GDPR Log Forgery |
| CVE-2026-92810 | 5.3 | — | PrestaShop | blockwishlist | CWE-639 | PrestaShop blockwishlist through 3.0.2 Information Disclosure |
| CVE-2026-61597 | 5.1 | — | djust-org | djust | CWE-79 | djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in … |
| CVE-2026-81869 | 5.1 | — | open-telemetry | opentelemetry-go | CWE-176 | OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation |
| CVE-2026-91099 | 5.1 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-61 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-91101 | 5.1 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-129 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-91103 | 5.1 | — | HP Inc. | HP Linux Imaging and Printing Software (HPLIP) | CWE-191 | HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
| CVE-2026-92590 | 5.1 | — | craftcms | cms | CWE-79 | Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields |
| CVE-2026-20072 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-863 | ISE information disclosure |
| CVE-2026-20235 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco Identity Services Engine Information Disclosure Vulnerability |
| CVE-2026-20282 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-641 | Cisco Identity Services Engine Authenticated Write Vulnerability |
| CVE-2026-76426 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco ISE REST API SQL Injection Vulnerability |
| CVE-2026-76427 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-611 | Cisco ISE XML External Entity Injection Vulnerability |
| CVE-2026-76428 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco ISE Profiler SQL Injection Vulnerability |
| CVE-2026-76431 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-22 | Cisco Identity Services Engine Arbitrary File Deletion Vulnerability |
| CVE-2026-76432 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-22 | Cisco Identity Services Engine Arbitrary File Write Vulnerability |
| CVE-2026-76434 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-22 | Cisco Identity Services Engine Arbitrary File Read Vulnerability |
| CVE-2026-76446 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-611 | Cisco Identity Services Engine External Entity Injection Vulnerability |
| CVE-2026-76448 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco Identity Services Engine SQL Injection Vulnerability |
| CVE-2026-76449 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-89 | Cisco Identity Services Engine SQL Injection Vulnerability |
| CVE-2026-76450 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-564 | Cisco Identity Services Engine SQL Injection Vulnerability |
| CVE-2026-76451 | 4.9 | — | Cisco | Cisco Identity Services Engine Software | CWE-564 | Cisco Identity Services Engine Certificate Management SQL Injection Vulnerabi… |
| CVE-2026-20350 | 4.7 | — | Cisco | Cisco ThousandEyes Enterprise Agent | CWE-78 | Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Inje… |
| CVE-2026-75025 | 4.7 | — | Mattermost | Mattermost | CWE-346 | Mattermost Desktop local network access from server-rendered content |
| CVE-2026-85732 | 4.7 | — | oras-project | oras-go | CWE-918 | oras-go: Blind SSRF via unvalidated Link header URL in pagination allows inte… |
| CVE-2026-76151 | 4.6 | — | qt | qt | CWE-125 | Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control res… |
| CVE-2026-92627 | 4.6 | — | The HDF Group | HDF5 | CWE-416 | Heap Use-After-Free in H5T__conv_f_f |
| CVE-2025-36591 | 4.4 | — | Dell | Elastic Cloud Storage (ECS) | CWE-327 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prio… |
| CVE-2026-63225 | 4.4 | — | Redocly | redocly-cli | CWE-22 | Redocly CLI: Path traversal when using `split` command |
| CVE-2026-20285 | 4.3 | — | Cisco | Cisco Identity Services Engine Software | CWE-285 | Cisco Identity Services Engine Authorization Bypass Vulnerability |
| CVE-2026-20286 | 4.3 | — | Cisco | Cisco Identity Services Engine Software | CWE-285 | Cisco Identity Services Engine Authorization Bypass Vulnerability |
| CVE-2026-92141 | 4.3 | — | Jenkins Project | Jenkins Keycloak Authentication Plugin | CWE-601 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict th… |
| CVE-2026-92131 | 4.2 | — | Jenkins Project | Jenkins Pipeline: Groovy Libraries Plugin | CWE-22 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does… |
| CVE-2026-92138 | 4.2 | — | Jenkins Project | Jenkins Bitbucket Server Integration Plugin | CWE-345 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plug… |
| CVE-2026-20071 | 3.8 | — | Cisco | Cisco Identity Services Engine Software | CWE-290 | ISE 802.1x Session Hijack Vulnerability |
| CVE-2026-87026 | 3.8 | — | Tanium | Threat Response | CWE-862 | Tanium addressed an improper access controls vulnerability in Threat Response. |
| CVE-2026-69200 | 3.7 | — | node-opcua | node-opcua | CWE-1321 | node-opcua: Prototype Pollution via internal `fieldsToJson()` implementation … |
| CVE-2026-86071 | 3.7 | — | junrar | junrar | CWE-22 | Junrar: LocalFolderExtractor mkdir escape allows directory creation outside e… |
| CVE-2026-92130 | 3.1 | — | Jenkins Project | Jenkins Pipeline: Multibranch Plugin | CWE-863 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not … |
| CVE-2026-71181 | 3.0 | — | Dell | Update Package Framework | CWE-59 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improp… |
| CVE-2026-71182 | 3.0 | — | Dell | Update Package Framework | CWE-59 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improp… |
| CVE-2026-86089 | 2.3 | — | Apache Software Foundation | Apache NiFi | CWE-862 | Apache NiFi: Missing Process Group Authorization for Connector Migration |
| CVE-2026-92359 | 2.3 | — | ag-ui-protocol | ag-ui | CWE-346 | ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain … |
| CVE-2026-92814 | 2.3 | — | dgtlmoon | changedetection.io | CWE-79 | changedetection.io through 0.60.6 Cross-Site Scripting via watch_title |
| CVE-2026-73442 | 2.1 | — | Arista Networks | EOS | CWE-532 | On affected platforms running Arista EOS with VRRP enabled, the peer device V… |
| CVE-2026-87031 | 2.1 | — | Concrete CMS | Concrete CMS | CWE-862 | Missing authorization in the REST API user creation endpoint in Concrete CMS … |
| CVE-2026-92364 | 2.1 | — | itsourcecode | Leave Management System | CWE-74 | itsourcecode Leave Management System index.php sql injection |
| CVE-2026-92383 | 2.1 | — | n/a | PbootCMS | CWE-352 | PbootCMS User Management UserController.php mod cross-site request forgery |
| CVE-2026-92413 | 2.1 | — | Artifex | MuPDF | CWE-404 | Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dere… |
| CVE-2026-92526 | 2.1 | — | itsourcecode | Leave Management System | CWE-74 | itsourcecode Leave Management System index.php sql injection |
| CVE-2026-92527 | 2.1 | — | n/a | chatwoot | CWE-918 | chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery |
| CVE-2026-81870 | 2.0 | — | open-telemetry | opentelemetry-go | CWE-200 | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
| CVE-2026-85387 | 2.0 | — | Concrete CMS | Concrete CMS | CWE-613 | Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authentic… |
| CVE-2026-92381 | 2.0 | — | n/a | PbootCMS | CWE-79 | PbootCMS Template Rendering ContentController.php decode_string cross site sc… |
| CVE-2026-92418 | 2.0 | — | ChangeWeDer | crm | CWE-79 | ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting |
| CVE-2026-92385 | 1.9 | — | SourceCodester | Online Food Ordering System | CWE-79 | SourceCodester Online Food Ordering System Category Update update_category.ph… |
| CVE-2026-92472 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free |
| CVE-2026-92473 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC BIFS commands.c gf_sg_command_del use after free |
| CVE-2026-92474 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free |
| CVE-2026-92475 | 1.9 | — | n/a | GPAC | CWE-119 | GPAC downloader.c wait_for_header_and_parse out-of-bounds |
| CVE-2026-81866 | 0.5 | — | Apache Software Foundation | Apache NiFi | CWE-862 | Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Conne… |
| CVE-2025-56563 | await | — | n/a | n/a | — | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith… |
| CVE-2025-56565 | await | — | n/a | n/a | — | DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, sto… |
| CVE-2025-56566 | await | — | n/a | n/a | — | MikroTik firmware 7.19.4 stores sensitive authentication credentials and netw… |
| CVE-2026-38999 | await | — | n/a | n/a | — | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk… |
| CVE-2026-51990 | await | — | n/a | n/a | — | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) all… |
| CVE-2026-65388 | await | — | Apple | containerization | — | A remote attacker who controls a container registry may be able to direct a c… |
| CVE-2026-68536 | await | — | Apache Software Foundation | Apache MyFaces | CWE-918 | Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability |
| CVE-2026-70469 | await | — | Apache Software Foundation | Apache NiFi | CWE-409 | Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HT… |
| CVE-2026-76646 | await | — | Apache Software Foundation | Apache MyFaces | CWE-400 | Apache MyFaces: Denial of Service via Unbounded Request Parsing |
| CVE-2026-79298 | await | — | n/a | n/a | — | An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and … |
| CVE-2026-88592 | await | — | n/a | n/a | — | kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The … |
| CVE-2026-88593 | await | — | n/a | n/a | — | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview en… |
| CVE-2026-89794 | await | — | Linux | Linux | — | ksmbd: zero pipe read compound padding |
| CVE-2026-89796 | await | — | Linux | Linux | — | mm/damon/core: avoid infinite kdamond_merge_regions() internal loop |
| CVE-2026-89797 | await | — | Linux | Linux | — | power: supply: ab8500_fg: fix use-after-free on remove |
| CVE-2026-89798 | await | — | Linux | Linux | — | rpcrdma: arm rn_done before publishing the notification |
| CVE-2026-89800 | await | — | Linux | Linux | — | drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE |
| CVE-2026-89802 | await | — | Linux | Linux | — | drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op |
| CVE-2026-89807 | await | — | Linux | Linux | — | drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore |
| CVE-2026-89809 | await | — | Linux | Linux | — | drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds |
| CVE-2026-89812 | await | — | Linux | Linux | — | drm/amdgpu: force complete the MES ring fences on reset |
| CVE-2026-89813 | await | — | Linux | Linux | — | drm/amdgpu: force complete the KIQ ring fences on reset |
| CVE-2026-89816 | await | — | Linux | Linux | — | drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used |
| CVE-2026-89817 | await | — | Linux | Linux | — | drm/gud: NUL-terminate TV mode names read from the device |
| CVE-2026-89820 | await | — | Linux | Linux | — | drm/amd/display: fix dc_lock leak on GPU reset error paths |
| CVE-2026-89821 | await | — | Linux | Linux | — | drm/amd/display: avoid divide-by-zero in __is_lut_linear() |
| CVE-2026-89822 | await | — | Linux | Linux | — | drm/i915: Guard against NULL driver_data in i915_pci_probe() |
| CVE-2026-89824 | await | — | Linux | Linux | — | drm/panel-edp: fix i2c adapter leak on probe failure |
| CVE-2026-89827 | await | — | Linux | Linux | — | drm/amdgpu: avoid force-completing uninitialized UVD rings |
| CVE-2026-89828 | await | — | Linux | Linux | — | drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() |
| CVE-2026-89830 | await | — | Linux | Linux | — | f2fs: fix valid block count leak on data block allocation failure |
| CVE-2026-89831 | await | — | Linux | Linux | — | f2fs: protect critical_task_priority updates with s_umount |
| CVE-2026-89833 | await | — | Linux | Linux | — | f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() |
| CVE-2026-89834 | await | — | Linux | Linux | — | f2fs: fix to migrate all curseg types during free_segment_range |
| CVE-2026-89835 | await | — | Linux | Linux | — | f2fs: avoid NULL checkpoint thread access in sysfs |
| CVE-2026-89837 | await | — | Linux | Linux | — | f2fs: fix dentry folio leak in find_in_level |
| CVE-2026-89839 | await | — | Linux | Linux | — | f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() |
| CVE-2026-89842 | await | — | Linux | Linux | — | scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started |
| CVE-2026-89843 | await | — | Linux | Linux | — | scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak |
| CVE-2026-89845 | await | — | Linux | Linux | — | scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() |
| CVE-2026-89850 | await | — | Linux | Linux | — | scsi: qla2xxx: Don't query firmware state while chip is down |
| CVE-2026-89851 | await | — | Linux | Linux | — | scsi: qla2xxx: Fix FCE trace enable parsing in debugfs |
| CVE-2026-89852 | await | — | Linux | Linux | — | scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() |
| CVE-2026-89853 | await | — | Linux | Linux | — | scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump |
| CVE-2026-89855 | await | — | Linux | Linux | — | scsi: qla2xxx: Serialize flash version read in reset handler |
| CVE-2026-89858 | await | — | Linux | Linux | — | scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() |
| CVE-2026-89859 | await | — | Linux | Linux | — | scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak |
| CVE-2026-89862 | await | — | Linux | Linux | — | scsi: qla2xxx: Fix BSG job leak on validate flash image error path |
| CVE-2026-89864 | await | — | Linux | Linux | — | scsi: qla2xxx: Bound i2c->length in I2C bsg handlers |
| CVE-2026-89865 | await | — | Linux | Linux | — | scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers |
| CVE-2026-89866 | await | — | Linux | Linux | — | media: chips-media: wave5: Resume device before setting EOS flag |
| CVE-2026-89867 | await | — | Linux | Linux | — | media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued |
| CVE-2026-89868 | await | — | Linux | Linux | — | media: chips-media: wave5: Add timeout while stop_streaming |
| CVE-2026-89869 | await | — | Linux | Linux | — | media: qcom: iris: use disable_irq() during power-off |
| CVE-2026-89871 | await | — | Linux | Linux | — | media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure |
| CVE-2026-89872 | await | — | Linux | Linux | — | media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link |
| CVE-2026-89874 | await | — | Linux | Linux | — | media: v4l2-async: avoid deleting unlinked ASC entry on link error |
| CVE-2026-89876 | await | — | Linux | Linux | — | media: tda18250: fix possible integer overflow |
| CVE-2026-89878 | await | — | Linux | Linux | — | media: s2255: check firmware size before reading trailing marker |
| CVE-2026-89879 | await | — | Linux | Linux | — | media: s2255: bound JPEG frame size before copying into the buffer |
| CVE-2026-89881 | await | — | Linux | Linux | — | media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak |
| CVE-2026-89884 | await | — | Linux | Linux | — | media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup |
| CVE-2026-89886 | await | — | Linux | Linux | — | media: intel/ipu6: fix async notifier cleanup leak on parse error |
| CVE-2026-89889 | await | — | Linux | Linux | — | media: i2c: imx415: Release runtime PM reference on VBLANK error |
| CVE-2026-89891 | await | — | Linux | Linux | — | media: em28xx: fix use-after-free of dev_next->devlist on disconnect |
| CVE-2026-89892 | await | — | Linux | Linux | — | media: em28xx: defer audio-only extension registration |
| CVE-2026-89895 | await | — | Linux | Linux | — | media: cobalt: Avoid freeing ALSA private data twice |
| CVE-2026-89896 | await | — | Linux | Linux | — | media: cedrus: fix memory leak in cedrus_init_ctrls() |
| CVE-2026-89900 | await | — | Linux | Linux | — | media: cec: core: Fix kmemleak due to missed rc_free_device() call |
| CVE-2026-89901 | await | — | Linux | Linux | — | media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref |
| CVE-2026-89905 | await | — | Linux | Linux | — | LoongArch: BPF: Move arena register slot below TCC context |
| CVE-2026-89909 | await | — | Linux | Linux | — | LoongArch: KVM: Free init resources if kvm_init() fails |
| CVE-2026-89917 | await | — | Linux | Linux | — | KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping |
| CVE-2026-89921 | await | — | Linux | Linux | — | KVM: s390: Zero initialize data structures for inject_pfault_token |
| CVE-2026-89923 | await | — | Linux | Linux | — | KVM: s390: Free guest debug data on vcpu destroy |
| CVE-2026-89924 | await | — | Linux | Linux | — | KVM: s390: Fix old_data leak in guest debug error path |
| CVE-2026-89925 | await | — | Linux | Linux | — | KVM: s390: Fix memory leak in guest debug handling |
| CVE-2026-89926 | await | — | Linux | Linux | — | KVM: s390: Fix length check __import_wp_info() |
| CVE-2026-89931 | await | — | Linux | Linux | — | KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit |
| CVE-2026-89933 | await | — | Linux | Linux | — | iio: pressure: dps310: fix NULL pointer dereference on ACPI probe |
| CVE-2026-89934 | await | — | Linux | Linux | — | iio: light: ltrf216a: fix runtime PM reference leak in error path |
| CVE-2026-89935 | await | — | Linux | Linux | — | iio: light: apds9306: fix PM reference leak in apds9306_read_data() |
| CVE-2026-89936 | await | — | Linux | Linux | — | iio: dac: m62332: Fix regulator reference count imbalance |
| CVE-2026-89937 | await | — | Linux | Linux | — | iio: chemical: sgp30: Handle IAQ thread creation failure |
| CVE-2026-89939 | await | — | Linux | Linux | — | iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable |
| CVE-2026-89944 | await | — | Linux | Linux | — | ASoC: hdac_hda: Fix hlink refcount leak on component registration failure |
| CVE-2026-89945 | await | — | Linux | Linux | — | ASoC: cs35l34: drain threaded IRQ before runtime suspend |
| CVE-2026-89946 | await | — | Linux | Linux | — | ASoC: cs35l33: drain threaded IRQ before runtime suspend |
| CVE-2026-89948 | await | — | Linux | Linux | — | batman-adv: bla: fix freeing of claims on meshif deletion |
| CVE-2026-89949 | await | — | Linux | Linux | — | batman-adv: dat: avoid unaligned fault in IP extraction |
| CVE-2026-89950 | await | — | Linux | Linux | — | batman-adv: mcast: linearize skbuff for packet generation |
| CVE-2026-89952 | await | — | Linux | Linux | — | mtd: rawnand: validate ONFI extended parameter page sections |
| CVE-2026-89953 | await | — | Linux | Linux | — | mtd: mtdoops: free page bitmap when the backing MTD is removed |
| CVE-2026-89955 | await | — | Linux | Linux | — | s390/vfio-ap: Fix NULL deref in status_show() during queue probe |
| CVE-2026-89956 | await | — | Linux | Linux | — | s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects |
| CVE-2026-89958 | await | — | Linux | Linux | — | s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL |
| CVE-2026-89962 | await | — | Linux | Linux | — | powerpc/kexec_file: Prevent kexec range truncation |
| CVE-2026-89963 | await | — | Linux | Linux | — | powerpc/kexec_file: Fix null-ptr-def in extra size calculation |
| CVE-2026-89964 | await | — | Linux | Linux | — | parisc: eisa: Fix infinite loop when parsing invalid IRQ value |
| CVE-2026-89966 | await | — | Linux | Linux | — | mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio |
| CVE-2026-89975 | await | — | Linux | Linux | — | nvme-fabrics: fix DHCHAP secret leak on parse failure |
| CVE-2026-89976 | await | — | Linux | Linux | — | accel/ethosu: fix job completion fence cleanup |
| CVE-2026-89977 | await | — | Linux | Linux | — | accel/ethosu: check MMIO mapping errors in probe |
| CVE-2026-89978 | await | — | Linux | Linux | — | accel/amdxdna: return early from a zero-length flush |
| CVE-2026-89981 | await | — | Linux | Linux | — | arm64: Don't read GMID_EL1 when MTE is disabled |
| CVE-2026-89982 | await | — | Linux | Linux | — | i2c: mux: Fix channel node leak on adapter add failure |
| CVE-2026-89983 | await | — | Linux | Linux | — | i2c: core: fix debugfs UAF on adapter removal |
| CVE-2026-89984 | await | — | Linux | Linux | — | perf/x86/intel: Fix kernel address leakages in LBR stack |
| CVE-2026-89987 | await | — | Linux | Linux | — | mm/huge_memory: transfer the pmd dirty bit to the folio on zap |
| CVE-2026-89989 | await | — | Linux | Linux | — | ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() |
| CVE-2026-89991 | await | — | Linux | Linux | — | bpf: Fix infinite loop in pcpu_freelist push with one possible CPU |
| CVE-2026-89993 | await | — | Linux | Linux | — | dmaengine: dw-edma: Initialize IRQ data before requesting IRQs |
| CVE-2026-89996 | await | — | Linux | Linux | — | dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds |
| CVE-2026-90004 | await | — | Linux | Linux | — | mm/damon/core: handle region split failure in apply_min_nr_regions() |
| CVE-2026-90005 | await | — | Linux | Linux | — | samples/damon/wsse: handle damon_start() failure |
| CVE-2026-90006 | await | — | Linux | Linux | — | samples/damon/mtier: handle damon_stop() failure |
| CVE-2026-90015 | await | — | Linux | Linux | — | xhci: fix lost bounce buffers on TDs spanning several ring segments |
| CVE-2026-90019 | await | — | Linux | Linux | — | usb: gadget: fix null pointer dereference in usb_put_function_instance() |
| CVE-2026-90020 | await | — | Linux | Linux | — | USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() |
| CVE-2026-90021 | await | — | Linux | Linux | — | usb: gadget: f_midi: initialize work in f_midi_alloc() |
| CVE-2026-90023 | await | — | Linux | Linux | — | usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_n… |
| CVE-2026-90024 | await | — | Linux | Linux | — | usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs |
| CVE-2026-90028 | await | — | Linux | Linux | — | usb: typec: hd3ss3220: track VBUS enable state per consumer |
| CVE-2026-90029 | await | — | Linux | Linux | — | usb: storage: realtek_cr: fix use-after-free on disconnect |
| CVE-2026-90031 | await | — | Linux | Linux | — | usb-storage: ene_ub6250: fix race between scan work and probe |
| CVE-2026-90033 | await | — | Linux | Linux | — | ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() |
| CVE-2026-90034 | await | — | Linux | Linux | — | usb: image: mdc800: change kmalloc() to kzalloc() |
| CVE-2026-90035 | await | — | Linux | Linux | — | drm/amd/display: fix division by zero in get_estimated_bw() |
| CVE-2026-90039 | await | — | Linux | Linux | — | NFSD: Guard admin state-revocation walks with NFSD_NET_UP |
| CVE-2026-90040 | await | — | Linux | Linux | — | KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped |
| CVE-2026-90999 | await | — | Functional Software, Inc. | Sentry Seer | — | Sentry Seer vulnerability allows attacker-controlled input to be executed in … |
| CVE-2026-92126 | await | — | Jenkins Project | Jenkins Script Security Plugin | — | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not rej… |