boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, September 17, 2026 · all times UTC← 2026-09-16 · archive

Security Box Score — September 17, 2026

CISA adds 1 to KEV; 1035 CVEs published, led by Linux (602).

1035 CVEs published September 17, 2026: 71 critical, 177 high, 133 medium, 29 low; 1 in the KEV catalog at press time; 3 with a public exploit reference; 625 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 635 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published982344760——
KEV catalog size1713

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2770 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15095599517235571211230.17.8.0017+247 ▲
microsoft9992898204198369516289301.07.8.0044+556 ▲
google5162682328104211751178090.37.5.0025+467 ▲
red hat1107364330634938200.06.6.0028-37 ▼
apple24656367165317148881.46.5.0019+212 ▲
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+66 ▲
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0045+8 ▲
ivanti102410122025520.88.8.0146+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache92604140252195153320.37.5.0048-8 ▼
mozilla11330080100640900.08.8.0025+112 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+2 ▲
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+2 ▲
wordpress0513102240.08.8.3120-2 ▼
go440211000.05.9.0034+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290358116585631012840.17.8.0034+634 ▲
ibm20782616737027511610.17.5.0029+15 ▲
adobe17177757344366102040.57.5.0023+111 ▲
progress3641539100611.68.1.0035-16 ▼
solarwinds1241743010416.79.1.0058+1 ▲
veeam01961030100.08.6.0032-10 ▼
zohocorp5153660000.08.4.0099+1 ▲
atlassian3918001300.07.6.0032+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link216619241112300.08.5.0154+5 ▲
siemens1552633103000.07.3.0018-4 ▼
rockwell automation184353260000.08.6.0029+18 ▲
synology02736153000.05.6.0025-1 ▼
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
hitachi energy470340000.06.9.0017+4 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1773482616613323210.37.2.0020+151 ▲
sourcecodester482170012889000.05.5.0028+22 ▲
spring017013608215000.06.5.00240
nvidia3216620117290000.07.8.0029+16 ▲
mongodb56154587584100.07.1.0026+24 ▲
itsourcecode341500037113000.02.1.0026+20 ▲
wwbn1061462349740000.06.9.0024+104 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0029+126 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.119695.910.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-19586.057092.69.3
CVE-2026-19490.056092.59.3
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
CVE-2026-77806.042090.59.8
CVE-2026-76698.041190.36.5
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1196KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8782710.0.0107
Most disclosures (vendor)
VendorCVEs
linux1891
microsoft1032
google854
oracle635
ibm405
apple256
dell216
adobe212
red hat177
apache159
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
ivanti5
adobe4
berriai4
jfrog4
oracle4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist40
npm18
PyPI16
Go2
RubyGems2
NuGet1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-64849mlflow1
CVE-2026-84869ConnectWise2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171765
CVE-2021-27102n/a2021-11-171765
CVE-2021-27101n/a2021-11-171765
CVE-2021-27103n/a2021-11-171765
CVE-2021-21017Adobe2021-11-171765
CVE-2021-28550Adobe2021-11-171765
CVE-2021-42013Apache Software Foundation2021-11-171765
CVE-2021-41773Apache Software Foundation2021-11-171765
CVE-2021-30858Apple2021-11-171765
CVE-2021-30860Apple2021-11-171765

Transactions

ADDED TO KEV — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Remediation due September 19, 2026.

EXPLOIT PUBLISHED — Unknown WP Import Export Lite: 9 CVEs (CVE-2026-76550, CVE-2026-76551, CVE-2026-76552, CVE-2026-76553, CVE-2026-76555, CVE-2026-76556, CVE-2026-76557, CVE-2026-76558, CVE-2026-76559). Public exploit references added.

EXPLOIT PUBLISHED — netty: 5 CVEs (CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587). Public exploit references added.

EXPLOIT PUBLISHED — Unknown LearnPress: 5 CVEs (CVE-2026-86444, CVE-2026-86445, CVE-2026-86447, CVE-2026-86448, CVE-2026-86449). Public exploit references added.

EXPLOIT PUBLISHED — Unknown Eventin: 3 CVEs (CVE-2026-77702, CVE-2026-84905, CVE-2026-84907). Public exploit references added.

EXPLOIT PUBLISHED — Unknown FluentBoards: 3 CVEs (CVE-2026-85349, CVE-2026-89327, CVE-2026-89328). Public exploit references added.

EXPLOIT PUBLISHED — Unknown Schema & Structured Data for WP & AMP: 3 CVEs (CVE-2026-82124, CVE-2026-82125, CVE-2026-82126). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2024-11222 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-21626 (opencontainers runc). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56005. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-68624 (N-able Mail Assure). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-71338 (Flowise). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47094 (SIMAC MyPHR). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57147 (MervinPraison PraisonAI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59255 (SpecterOps BloodHound). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59258 (immich-app immich). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-62239 (Dao-AILab flash-attention). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63765 (chatwoot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63768 (calcom cal.diy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66005 (janhq jan). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67278 (Mikrotik RouterOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-69114 (Spacebar Server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-69116 (xpf0000 FlyEnv). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73033 (sucuri-wordpress-plugin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-74926 (Unknown MultiVendorX). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78472 (Unknown Ni WooCommerce Sales Report). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-78474 (Unknown Ni WooCommerce Sales Report). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79418. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79419. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82964 (Gen Digital Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business Security). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84088 (Unknown Xpro Addons — 140+ Widgets for Elementor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84829 (Unknown Optimole). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85131 (Unknown WPLP Cookie Consent). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85530 (Unknown GiveWP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85569 (Unknown Tutor LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85572 (Unknown Tutor LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85641 (Unknown Formidable Forms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86784 (Unknown Visualizer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86823 (Unknown Newsletter). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87828 (Unknown Seraphinite Accelerator). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87854 (Unknown Subscriptions for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87860 (Unknown Subscriptions for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87896 (Unknown Rox Appointment Booking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87907 (Unknown Rox Appointment Booking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87959 (Unknown WPBot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-88910 (Unknown kboard). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90881 (D-Link DIR-882). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91005 (SourceCodester Online Faculty Clearance System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91090 (GPAC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91849 (WuzhiCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91993 (dromara Jpom). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91996 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91998 (casdoor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92455 (guchengwuyue yshop-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92460 (guchengwuyue yshop-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92474 (GPAC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92527 (chatwoot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92774 (requarks Wiki.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92806 (phpList). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92809 (PrestaShop psgdpr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92810 (PrestaShop blockwishlist). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92813 (Metabase). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92814 (dgtlmoon changedetection.io). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92815 (dgtlmoon changedetection.io). Public exploit reference added.

DUE DATE PASSED — CVE-2026-48710 (Kludex starlette). CISA remediation deadline was September 16, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-59822 (BerriAI litellm). CISA remediation deadline was September 16, 2026; still in catalog.

REJECTED — CVE-2026-56395 (SiYuan). Record withdrawn by the CNA.

RESCORED — CVE-2023-4622 (Linux Kernel). CVSS 7.8 → 7 (NVD).

RESCORED — CVE-2026-43697 (Apple macOS). CVSS 4.3 → 7.1 (NVD).

RESCORED — CVE-2026-58704 (Google Android). CVSS 8 → 8.8 (NVD).

RESCORED — CVE-2026-67378 (Microsoft SQL Server 2019 (CU 32)). CVSS 8.5 → 9 (NVD).

RESCORED — CVE-2026-67631 (Microsoft SQL Server 2017 (CU 31)). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2026-67636 (Microsoft SQL Server 2019 (CU 32)). CVSS 8.5 → 9 (NVD).

RESCORED — CVE-2026-67643 (Microsoft SQL Server 2022 (CU 26)). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2026-72980 (Microsoft Windows 10 Version 1607). CVSS 4.4 → 5.5 (NVD).

RESCORED — CVE-2026-79419. CVSS 6.1 → 8.7 (NVD).

RESCORED — CVE-2026-82874 (ToolJet). CVSS 2.4 → 9.4 (NVD).

RESCORED — CVE-2026-86865 (Tanium Asset). CVSS 8.8 → 7.2 (NVD).

PATCH SHIPPED — CVE-2026-15565 (Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7). Fixed in Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap.

PATCH SHIPPED — CVE-2026-15567 (Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7). Fixed in Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap.

Yesterday's Results

How to read these box scores · glossary

1035 CVEs published. 25 box scores and 375 table rows below; the remaining 635 continue on page 2 · page 3 — every CVE is listed, nothing truncated.

Acronis Acronis Backup plugin for cPanel & WHM — Local privilege escalation due to insecure file permissions. The following products are affected: Acronis B…
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8      —      —   YES
AFFECTED
  Product                                 Versions       Fixed
  Acronis Backup plugin for cPanel & WHM  unspecified –  —
  Acronis Backup extension for Plesk      unspecified –  —
  Acronis Backup plugin for DirectAdmin   unspecified –  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 17  Added to CISA KEV, due Sep 19
  Sep 17  Published (CNA: Acronis)
CWE-276 · CNA: Acronis · CVSS v3.0 · 1 reference · NVD status: Received · KEV due September 19, 2026
sh1zen Multi Uploader for Gravity Forms — Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0061   47.7     —
AFFECTED
  Product                           Versions     Fixed
  Multi Uploader for Gravity Forms  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 17  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
ichurakov Paid Downloads — Paid Downloads <= 3.15 - Unauthenticated Arbitrary File Upload via 'paiddownloads_update_file' Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0053   43.8     —
AFFECTED
  Product         Versions     Fixed
  Paid Downloads  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 17  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
@fastify/static vulnerable to route guard bypass via path case-folding
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0036   29.4     —
AFFECTED
  Product          Versions     Fixed
  @fastify/static  unspecified  10.1.4
TIMELINE
  Sep 14  Reserved by CNA
  Sep 17  Published (CNA: openjs)
CWE-178, CWE-284 · CNA: openjs · CVSS v3.1 · 2 references · NVD status: Received
go github.com/neuvector/neuvector — Admission Control Bypass via Hardcoded Sidecar Image Exemption
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  L    4.3   .0036   29.4     —
AFFECTED
  Product                         Versions     Fixed
  github.com/neuvector/neuvector  unspecified  5.6.2
TIMELINE
  Aug 24  Reserved by CNA
  Sep 17  Published (CNA: suse)
CWE-807 · CNA: suse · CVSS v3.1 · 2 references · NVD status: Received
go github.com/neuvector/neuvector — SAML Audience Confusion Allows Cross-SP Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   N    7.6   .0035   28.4     —
AFFECTED
  Product                         Versions     Fixed
  github.com/neuvector/neuvector  unspecified  5.6.2
TIMELINE
  Aug 24  Reserved by CNA
  Sep 17  Published (CNA: suse)
CWE-287 · CNA: suse · CVSS v4.0 · 2 references · NVD status: Received
servmask All-in-One WP Migration and Backup — All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Insufficient Credential Protection via Authorization Basic Header
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0034   27.9     —
AFFECTED
  Product                             Versions     Fixed
  All-in-One WP Migration and Backup  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 17  Published (CNA: Wordfence)
CWE-522 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
go neuvector — Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  N    8.0   .0034   27.2     —
AFFECTED
  Product    Versions  Fixed
  neuvector  <5.6.1 –  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 17  Published (CNA: suse)
CWE-384 · CNA: suse · CVSS v3.1 · 2 references · NVD status: Received
Unknown To Do List Member — To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0034   26.9     —
AFFECTED
  Product            Versions  Fixed
  To Do List Member  1.4 –     —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-306 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Yo — Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0032   25.5     —
AFFECTED
  Product  Versions  Fixed
  Yo       1.1 –     —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Qualcomm, Inc. Snapdragon — Buffer Over-read in WLAN Firmware
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0030   22.7     —
AFFECTED
  Product     Versions                               Fixed
  Snapdragon  Snapdragon G1 Gen 2 Gaming Platform –  —
TIMELINE
  Feb 2   Reserved by CNA
  Sep 17  Published (CNA: qualcomm)
CWE-126 · CNA: qualcomm · CVSS v3.1 · 1 reference · NVD status: Received
Unknown wpShopGermany IT-RECHT KANZLEI — wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .0029   21.9     —
AFFECTED
  Product                         Versions  Fixed
  wpShopGermany IT-RECHT KANZLEI  1.6 –     —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-94 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Acer System Monitoring — WebSocket Exposure Vulnerability in NitroSense and PredatorSense Software
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    2.7   .0025   17.0     —
AFFECTED
  Product            Versions     Fixed
  System Monitoring  unspecified  —
TIMELINE
  Jun 5   Reserved by CNA
  Sep 17  Published (CNA: Acer)
CWE-668 · CNA: Acer · CVSS v4.0 · 1 reference · NVD status: Received
Red Hat Red Hat Enterprise Linux 10 — Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0022   12.5     —
AFFECTED
  Product                      Versions     Fixed
  Red Hat Enterprise Linux 10  unspecified  —
  Red Hat Enterprise Linux 8   unspecified  —
  Red Hat Enterprise Linux 9   unspecified  —
TIMELINE
  Sep 7   Reserved by CNA
  Sep 17  Published (CNA: redhat)
CWE-94 · CNA: redhat · CVSS v3.1 · 3 references · NVD status: Received
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  N  L  N    4.3   .0021   11.9     —
AFFECTED
  Product  Versions     Fixed
  Canva    unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 17  Published (CNA: Canva)
CWE-174 · CNA: Canva · CVSS v3.1 · 1 reference · NVD status: Received
10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0019    9.5     —
AFFECTED
  Product                                                 Versions     Fixed
  Photo Gallery by 10Web – Mobile-Friendly Image Gallery  unspecified  —
TIMELINE
  Sep 6   Reserved by CNA
  Sep 17  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
go neuvector — Logout bypass via alternate JWT spelling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   R  U  L  L  N    3.7   .0019    8.5     —
AFFECTED
  Product    Versions     Fixed
  neuvector  unspecified  5.6.2
TIMELINE
  Aug 24  Reserved by CNA
  Sep 17  Published (CNA: suse)
CWE-863 · CNA: suse · CVSS v3.1 · 2 references · NVD status: Received
Unknown The Pressengine — The Pressengine <= 1.0 - Unauthenticated Authentication Bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0018    7.5     —
AFFECTED
  Product          Versions     Fixed
  The Pressengine  unspecified  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-287 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown WPLP Cookie Consent — WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0017    7.0     —
AFFECTED
  Product              Versions     Fixed
  WPLP Cookie Consent  unspecified  —
TIMELINE
  Sep 3   Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Dewa Kirim — Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0017    7.0     —
AFFECTED
  Product     Versions     Fixed
  Dewa Kirim  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Dictionary — Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0017    7.0     —
AFFECTED
  Product     Versions     Fixed
  Dictionary  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Dictionary — Dictionary <= 1.0 - Reflected XSS via Multiple Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  L    7.1   .0017    7.0     —
AFFECTED
  Product     Versions     Fixed
  Dictionary  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Unknown Realtyna Organic IDX plugin + WPL Real Estate — Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  L    7.1   .0017    6.7     —
AFFECTED
  Product                                        Versions     Fixed
  Realtyna Organic IDX plugin + WPL Real Estate  unspecified  —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 17  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Qualcomm, Inc. Snapdragon — Out-of-bounds Write in Video
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0016    5.8     —
AFFECTED
  Product     Versions   Fixed
  Snapdragon  Cologne –  —
TIMELINE
  Jan 21  Reserved by CNA
  Sep 17  Published (CNA: qualcomm)
CWE-787 · CNA: qualcomm · CVSS v3.1 · 1 reference · NVD status: Received
Qualcomm, Inc. Snapdragon — Out-of-bounds Write in Video
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0016    5.8     —
AFFECTED
  Product     Versions   Fixed
  Snapdragon  Cologne –  —
TIMELINE
  Jan 21  Reserved by CNA
  Sep 17  Published (CNA: qualcomm)
CWE-787 · CNA: qualcomm · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-910116.85.4UnknownEWWW Image OptimizerCWE-79EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute B…
CVE-2026-240817.45.2Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in BT Controller
CVE-2026-252817.45.2Qualcomm, Inc.SnapdragonCWE-770Allocation of Resources Without Limits or Throttling in OOBM
CVE-2026-252947.45.2Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in WLAN Firmware
CVE-2026-867886.84.8UnknownHT Mega Addons for ElementorCWE-79HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag
CVE-2026-878294.34.7UnknownCheckout Field Manager (Checkout Manager) for WooCommerceCWE-639Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion vi…
CVE-2026-878314.34.7UnknownCheckout Field Manager (Checkout Manager) for WooCommerceCWE-862Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion vi…
CVE-2026-864463.74.2UnknownLearnPressCWE-200LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-a…
CVE-2026-506044.93.8AcerAgent ServiceCWE-306Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software
CVE-2026-506081.23.9AcerSystem MonitoringCWE-306Authentication Vulnerability in NitroSense and PredatorSense Software
CVE-2026-928387.83.6GeoVision Inc.GV-Remote E-mapCWE-427GeoVision GV-Remote E-Map dll hijacking vulnerability
CVE-2026-878362.73.7UnknownComments Import & ExportCWE-200Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via …
CVE-2026-867079.83.4UnknownPrivate Feed KeyCWE-287Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey'…
CVE-2026-867109.83.4UnknownLogin with QRCWE-287Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin…
CVE-2026-851287.53.4UnknownChoose User Role at RegistrationCWE-269Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Pr…
CVE-2026-909236.53.4UnknownAutopayCWE-863Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disc…
CVE-2026-909225.33.4UnknownPaid Membership SubscriptionsCWE-284Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass…
CVE-2026-910155.33.4UnknownMaster Addons for ElementorCWE-862Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via …
CVE-2026-910165.33.4UnknownMotorsCWE-639Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure
CVE-2026-910083.73.4UnknownEvent Booking Manager for WooCommerceCWE-639Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII …
CVE-2026-449405.73.2SUSESUSE ObservabilityCWE-200Service token exposure and potential privilege escalation in SUSE Observability
CVE-2026-889048.83.1UnknownPuppyFWCWE-269PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Lea…
CVE-2026-910194.93.1UnknownEvent Booking Manager for WooCommerceCWE-284Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway …
CVE-2026-910104.33.1UnknownInvisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All FormsCWE-862Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission…
CVE-2026-156889.22.0Mitsubishi Electric CorporationGX Works3CWE-303Password Authentication Bypass Vulnerability in GX Works3 and Motion Control …
CVE-2026-252616.71.8Qualcomm, Inc.SnapdragonCWE-822Untrusted Pointer Dereference in Camera
CVE-2026-252838.81.4Qualcomm, Inc.SnapdragonCWE-121Stack-based Buffer Overflow in OOBM
CVE-2025-596077.81.5Qualcomm, Inc.SnapdragonCWE-822Untrusted Pointer Dereference in Windows Compute
CVE-2026-240757.81.5Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in Qualcomm IPC
CVE-2026-252807.81.5Qualcomm, Inc.SnapdragonCWE-787Out-of-bounds Write in DSP Service
CVE-2026-252907.81.4Qualcomm, Inc.SnapdragonCWE-190Integer Overflow or Wraparound in OOBM
CVE-2026-815467.71.4CanvaAffinityCWE-121The Affinity by Canva application before 3.3.0 (September 2026 release) did n…
CVE-2026-252847.31.3Qualcomm, Inc.SnapdragonCWE-126Buffer Over-read in OOBM
CVE-2026-910173.71.0UnknownRobokassa payment gateway for WoocommerceCWE-345Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment B…
CVE-2026-868244.81.0UnknownNewsletterCWE-326Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modificati…
CVE-2026-252827.90.9Qualcomm, Inc.SnapdragonCWE-125Out-of-bounds Read in OOBM
CVE-2026-910094.30.8UnknownActive Woot Products Tables for WooCommerce. 100% FREECWE-352Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post T…
CVE-2026-506057.40.6AcerAgent SerivceCWE-284Privilege Escalation Vulnerability in NitroSense and PredatorSense Software
CVE-2026-506097.40.6AcerSystem MonitoringCWE-284Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSe…
CVE-2026-506107.40.6AcerSystem MonitoringCWE-284Improper Access control Vulnerability in NitroSense and PredatorSense Software
CVE-2026-252787.80.4Qualcomm, Inc.SnapdragonCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Software plat…
CVE-2026-506034.90.1AcerAgent ServiceCWE-321Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense …
CVE-2026-506061.20.1AcerSystem MonitoringCWE-321Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSe…
CVE-2026-5473410.0—prebidprebid-server-javaCWE-918Prebid Server Java: Vulnerability to request forgery allows for possible host…
CVE-2026-6210410.0—superwebyMigratico LiteCWE-94WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulner…
CVE-2026-6287410.0—MicrosoftAzure BillingCWE-345Azure Billing Elevation of Privilege Vulnerability
CVE-2026-6939910.0—MicrosoftAzure ARCCWE-441Azure Arc Elevation of Privilege Vulnerability
CVE-2026-6984310.0—MicrosoftMicrosoft FabricCWE-290Microsoft Fabric Elevation of Privilege Vulnerability
CVE-2026-6986510.0—MicrosoftAzure Container RegistryCWE-639Microsoft Container Registry Elevation of Privilege Vulnerability
CVE-2026-7020010.0—MicrosoftAzure Logic AppsCWE-22Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-8394410.0—MicrosoftAzure Logic AppsCWE-284Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-8588910.0—MicrosoftAzure AI FoundryCWE-306Azure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-9293710.0—patriksimekvm2CWE-94vm2 3.11.6 Remote Code Execution via Promise call/apply
CVE-2026-9294010.0—patriksimekvm2CWE-668vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent
CVE-2026-9294110.0—patriksimekvm2CWE-732vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation
CVE-2026-9294610.0—patriksimekvm2CWE-913vm2 before 3.11.7 Remote Code Execution via require.external
CVE-2026-9294710.0—patriksimekvm2CWE-200vm2 before 3.11.7 Memory Disclosure via Buffer Pool
CVE-2026-9295510.0—patriksimekvm2CWE-913vm2 before 3.11.8 Sandbox Escape via NodeVM
CVE-2026-9295610.0—patriksimekvm2CWE-693vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming
CVE-2026-9296010.0—patriksimekvm2CWE-200vm2 before 3.11.6 Process-wide State Exposure via os and dns
CVE-2026-858789.9—MicrosoftAzure HorizonDBCWE-285Azure Database for PostgreSQL Elevation of Privilege Vulnerability
CVE-2026-858859.9—MicrosoftMicrosoft 365 CopilotCWE-77Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-451409.8—chamilochamilo-lmsCWE-22Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
CVE-2026-544609.8—open-receptionappointment-booking-softwareCWE-306OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth…
CVE-2026-546179.8—GravitLauncherLauncherCWE-22GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
CVE-2026-546269.8—HappySeaFoxsailCWE-122SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mi…
CVE-2026-546279.8—HappySeaFoxsailCWE-122SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)
CVE-2026-621019.8—Chris Åkerfeldt WendelEduAdmin BookingCWE-288WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability
CVE-2026-621089.8—miniOrangeHeadless Single Sign OnCWE-290WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vul…
CVE-2026-908229.8—FatPipe NetworksMPVPNCWE-78FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware ve…
CVE-2026-908239.8—FatPipe NetworksMPVPNCWE-121FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware ve…
CVE-2026-540539.6—brufdevmany-notesCWE-22Many Notes: Path Traversal via ZIP import allows arbitrary file write and sto…
CVE-2026-547529.6—netbox-communitydevicetype-libraryCWE-502NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite All…
CVE-2026-877019.6—MicrosoftAzure Cosmos DBCWE-74Azure Cosmos DB Elevation of Privilege Vulnerability
CVE-2026-929349.5—patriksimekvm2CWE-693vm2 before 3.11.8 Sandbox Escape RCE via AggregateError
CVE-2026-929359.5—patriksimekvm2CWE-913vm2 NodeVM Remote Code Execution via Array-Shaped Require
CVE-2026-545019.4—webrecorderbrowsertrixCWE-20Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization…
CVE-2026-546189.4—jimprosserobsidian-web-mcpCWE-306Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approve…
CVE-2026-928609.4—rcourtmanPulseCWE-20rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation
CVE-2026-929389.4—patriksimekvm2CWE-693vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite
CVE-2026-929399.4—patriksimekvm2CWE-114vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine
CVE-2026-929489.4—patriksimekvm2CWE-693vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test
CVE-2026-929519.4—patriksimekvm2CWE-706vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver
CVE-2026-929579.4—patriksimekvm2CWE-269vm2 before 3.11.7 Authentication Bypass via node: Prefix
CVE-2026-542379.3—wavelogwavelogCWE-94Wavelog: Unauthenticated Remote Code Execution
CVE-2026-700099.3—MicrosoftAzure ARCCWE-22Azure Arc Elevation of Privilege Vulnerability
CVE-2026-868639.3—pgadmin.orgpgAdmin 4CWE-290pgAdmin 4: Authentication bypass via a client-controlled identity header in W…
CVE-2026-929449.3—patriksimekvm2CWE-693vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector
CVE-2026-929509.3—patriksimekvm2CWE-453vm2 before 3.11.7 Sandbox Escape via CLI require
CVE-2026-929539.3—patriksimekvm2CWE-913vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray
CVE-2026-768349.2—b2evolutionb2evolution CMSCWE-502b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Arr…
CVE-2026-797529.2—cakephpcakephpCWE-89CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
CVE-2026-929439.2—AWSAWSIoTPythonSDKCWE-297Improper validation of certificate with host mismatch in AWS IoT Device SDK f…
CVE-2026-929549.2—patriksimekvm2CWE-248vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise
CVE-2026-933939.2—MongoDB Inc.C DriverCWE-787Heap overflow via oversized decrypted TLS record sequence in Windows Secure C…
CVE-2026-546709.1—LabRedesCefetRJWeGIACWE-22WeGIA: Unauthenticated Auth Bypass + Local File Inclusion
CVE-2026-547679.1—LabRedesCefetRJWeGIACWE-306WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_soci…
CVE-2026-634729.1—vendurehqvendureCWE-287Vendure: External-authentication account takeover: external login linked to a…
CVE-2026-769499.1—team-alembicash_authenticationCWE-290Remember-me sign-in guard reads a session key that is never written in ash_au…
CVE-2026-827619.1—team-alembicash_authenticationCWE-367Magic link single-use tokens replayable via TOCTOU race in AshAuthentication
CVE-2026-855009.1—team-alembicash_authenticationCWE-305`require_confirmed_with` is not enforced on the action and fails open on an u…
CVE-2026-865339.1—team-alembicash_authenticationCWE-613Revoked session accepted because the session jti is never checked in AshAuthe…
CVE-2026-889529.1—team-alembicash_authenticationCWE-287OAuth2 sign-in attached to an existing account without an email comparison in…
CVE-2026-910399.1—team-alembicash_authenticationCWE-290dynamic_oidc identities are not namespaced by connection in ash_authenticatio…
CVE-2026-929139.1—WWBNAVideoCWE-330AVideo Weak PRNG Activation Code Authentication Bypass
CVE-2026-451439.0—chamilochamilo-lmsCWE-79Chamilo LMS: Student-to-admin stored XSS in private messages via v-html
CVE-2026-472529.0—julien040anyqueryCWE-94Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (…
CVE-2026-779039.0—MicrosoftMicrosoft DataverseCWE-290Microsoft Dataverse Elevation of Privilege Vulnerability
CVE-2026-929528.9—patriksimekvm2CWE-669vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass
CVE-2026-148508.8—MobiAPParcMobiAPParcCWE-640Weak password recovery mechanism for forgotten password in MobiAPParc
CVE-2026-158158.8—GrafanaGrafana OSSCWE-22CVE-2026-15815 CVE Record
CVE-2026-283268.8—SolarWindsAccess Rights ManagerCWE-321SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulner…
CVE-2026-542398.8—wpenginefaustjsCWE-345FaustWP — Authentication Bypass via Initialization Vector Modification in Tok…
CVE-2026-545048.8—andrea9293mcp-documentation-serverCWE-306MCP Documentation Server: Web UI API binds to all interfaces without authenti…
CVE-2026-545198.8—vmDeshpandeai-agent-automationCWE-862AI Agent Automation: Missing ownership checks in memory APIs allow cross-user…
CVE-2026-546128.8—givanzVvvebCWE-22Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-s…
CVE-2026-546718.8—LabRedesCefetRJWeGIACWE-639WeGIA: Authorization Bypass via Empty Resource Array in InternoControle
CVE-2026-549168.8—netbox-communitydevicetype-libraryCWE-427NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE…
CVE-2026-776148.8—opencastopencastCWE-384Opencast: Session fixation in login enables account takeover via crafted link
CVE-2026-782958.8—Xagio SEOXagio SEOCWE-352WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vu…
CVE-2026-929728.8—sgl-projectsglangCWE-306SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint
CVE-2026-528368.7—OpenDDSOpenDDSCWE-125OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` — tri…
CVE-2026-543438.7—frappelmsCWE-22Frappe LMS: Path Traversal in SCORM File Serving
CVE-2026-545718.7—ESP32AsyncESPAsyncWebServerCWE-190ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denia…
CVE-2026-634598.7—vendurehqvendureCWE-79Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHT…
CVE-2026-691978.7—umbracoUmbraco-CMSCWE-200Umbraco: Delivery API leaks protected (Public Access) content through Content…
CVE-2026-776158.7—opencastopencastCWE-79Paella Player: Stored XSS via caption cue text
CVE-2026-868648.7—pgadmin.orgpgAdmin 4CWE-22pgAdmin 4: Argument and connection-string injection via the database field in…
CVE-2026-890368.7—appwriteappwriteCWE-88Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter
CVE-2026-894188.7—Googleprotobuf-javascript (aka google-protobuf npm package)CWE-674Uncontrolled Recursion leading to Denial of Service in protobuf-javascript (g…
CVE-2026-929168.7—getgravgravCWE-200Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork
CVE-2026-929178.7—getgravgravCWE-200Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r
CVE-2026-929188.7—cjbiadmin3CWE-532admin3 through 3.0.0 Session Token Disclosure via Audit Log
CVE-2026-929428.7—patriksimekvm2CWE-400vm2 before 3.11.7 Timeout Bypass via FinalizationRegistry
CVE-2026-929618.7—patriksimekvm2CWE-770vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass
CVE-2026-929708.7—hubzerohubzero-cmsCWE-22HUBzero CMS through 2.2.32 Path Traversal via File Upload
CVE-2026-929718.7—InternLMlmdeployCWE-617InternLM LMDeploy through 0.17.0 Assertion Denial of Service
CVE-2026-929838.7—InternLMlmdeployCWE-772InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch
CVE-2026-929878.7—RazrFalconroxmltreeCWE-407roxmltree through 0.21.1 Denial of Service via Quadratic Parsing
CVE-2026-934358.7—NodeRedisredis-parserCWE-674redis-parser through 3.0.0 Denial of Service via Unbounded Recursion
CVE-2026-934368.7—vllm-projectvllmCWE-401vLLM through 0.29.0 Memory Exhaustion via Rejected Requests
CVE-2026-934508.7—go-openapiswagCWE-674go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSO…
CVE-2026-934528.7—xerialsnappy-javaCWE-787snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress
CVE-2026-934538.7—AlintoSOGoCWE-640SOGo before 5.12.11 Password Reset Token Interception via Origin Header
CVE-2026-194778.6—MCCUniversal Library for Linux (uldaq)CWE-121Stack-based Buffer Overflow Vulnerability in Linux (uldaq)
CVE-2026-687918.6—MicrosoftAzure Machine LearningCWE-863Azure Machine Learning Information Disclosure Vulnerability
CVE-2026-929148.6—WWBNAVideoCWE-287AVideo LoginControl PGP Second Factor Authentication Bypass
CVE-2026-929808.6—danielbrendelhortusfox-webCWE-434HortusFox-Web < 6.1 Remote Code Execution via Import/Export
CVE-2026-929858.6—siyuan-notesiyuanCWE-79SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels
CVE-2026-929868.6—siyuan-notesiyuanCWE-79SiYuan before 3.8.4 Cross-Site Scripting via Document Title
CVE-2026-665808.5—RexThemeProduct Feed ManagerCWE-89WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability
CVE-2026-715388.5—CycloneDXcyclonedx-node-npmCWE-78@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argumen…
CVE-2026-929848.5—hubzerohubzero-cmsCWE-384HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier
CVE-2026-933378.5—nm-l2tpNetworkManager-l2tpCWE-88NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection
CVE-2026-545078.4—givanzVvvebCWE-918Vvveb oEmbedProxy vulnerable to server-side request forgery
CVE-2026-550628.4—uniget-orgcliCWE-22uniget: Path Traversal in Hook Files - Directory Escape Vulnerability
CVE-2026-929588.4—patriksimekvm2CWE-269vm2 before 3.11.7 Denylist Bypass via fs/promises
CVE-2026-932928.4—SigNozsignozCWE-89SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query …
CVE-2026-934268.4—SigNozsignozCWE-89SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names
CVE-2026-545808.3—MidnightBSDmportCWE-354mport index decompression can leave partial or corrupt index data after zstd …
CVE-2026-545818.3—MidnightBSDmportCWE-345mport bootstrap index fetch can continue after hash verification failure
CVE-2026-545838.3—MidnightBSDmportCWE-22mport package bundle downloads allow unsafe destination filenames
CVE-2026-545978.3—itflow-orgitflowCWE-89ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Pa…
CVE-2026-929128.3—WWBNAVideoCWE-330AVideo Cryptographically Weak PRNG via uniqid Stream Key
CVE-2026-542538.2—joni1802ts3-managerCWE-79TS3 Manager: Reflected XSS via /api/download port parameter steals operator s…
CVE-2026-543548.2—MapServerMapServerCWE-89MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Qu…
CVE-2026-544518.2—elixir-protobufprotobufCWE-674Elixir protobuf: Unbounded recursion depth in embedded-message decoding
CVE-2026-567958.2—DellDriver Pack For Windows OSCWE-427Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrol…
CVE-2026-827608.2—team-alembicash_authenticationCWE-407Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API …
CVE-2026-839468.2—MicrosoftAzure PortalCWE-79Azure Portal Spoofing Vulnerability
CVE-2026-850778.2—sanic-orgsanicCWE-113Sanic: HTTP response header injection via missing CR/LF validation in Sanic H…
CVE-2026-860398.2—libp2pjs-libp2pCWE-290libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID an…
CVE-2026-929038.2—SnowflakeSnowflake CLICWE-89Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Co…
CVE-2026-269508.1—DellSmartFabric ManagerCWE-345Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient V…
CVE-2026-544468.1—Labs64NetLicensing-MCPCWE-306NetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API …
CVE-2026-545208.1—vmDeshpandeai-agent-automationCWE-22AI Agent Automation: Workflow file step path traversal allows read and write …
CVE-2026-545968.1—itflow-orgitflowCWE-89ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter…
CVE-2026-814428.1—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-269Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-814758.1—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-306Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-814768.1—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-78Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-814788.1—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-321Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-546927.8—HappySeaFoxsailCWE-131SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal bu…
CVE-2026-814747.8—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-122Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-489777.7—openslideopenslideCWE-123OpenSlide: Arbitrary memory write with crafted Ventana BIF file
CVE-2026-501587.7—eat-pray-aiyutuCWE-73yutu: Arbitrary File Write via MCP `caption-download` Tool
CVE-2026-535577.7—dataeaseSQLBotCWE-89SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Com…
CVE-2026-543397.7—LeslieLeunggleanCWE-918Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via M…
CVE-2026-858877.7—MicrosoftMicrosoft 365 CopilotCWE-732M365 Copilot Information Disclosure Vulnerability
CVE-2026-457267.6—siderolabsomniCWE-200Omni: Reader-level users can retrieve imported cluster CA keys via ResourceSe…
CVE-2026-545067.6—givanzVvvebCWE-79Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field
CVE-2026-666187.6—Flipper CodeWP MapsCWE-89WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability
CVE-2026-666197.6—Tribulant SoftwareNewslettersCWE-89WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability
CVE-2026-666247.6—Ludwig YouWPMasterToolKitCWE-89WordPress WPMasterToolKit plugin <= 2.22.0 - SQL Injection vulnerability
CVE-2026-666257.6—WCVendorsWC Vendors MarketplaceCWE-89WordPress WC Vendors Marketplace plugin <= 2.7.2.1 - SQL Injection vulnerability
CVE-2026-666267.6—Sonal S SinhaSKT Addons for ElementorCWE-89WordPress SKT Addons for Elementor plugin <= 4.0 - SQL Injection vulnerability
CVE-2026-666287.6—WP LabWP-Lister Lite for eBayCWE-89WordPress WP-Lister Lite for eBay plugin <= 3.8.11 - SQL Injection vulnerability
CVE-2026-666307.6—PublishPressPublishPress SeriesCWE-89WordPress PublishPress Series plugin <= 3.1.3 - SQL Injection vulnerability
CVE-2026-666317.6—Moreconvert TeamMC Woocommerce WishlistCWE-89WordPress MC Woocommerce Wishlist plugin <= 1.9.21 - SQL Injection vulnerability
CVE-2026-802187.6—team-alembicash_authenticationCWE-287Sign-in token minted for one resource accepted by another in AshAuthentication
CVE-2026-826857.6—team-alembicash_authenticationCWE-639Confirmation token accepted on any record in AshAuthentication
CVE-2026-501257.5—StacklokLabsmkpCWE-400MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` …
CVE-2026-502757.5—DataDogdd-trace-phpCWE-770Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-502777.5—DataDogdd-trace-cppCWE-770dd-trace-cpp: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-502857.5—pomeriumpomeriumCWE-770Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE…
CVE-2026-535347.5—JabRefjabrefCWE-78JabRef CAYW Sublime Text integration permits operating-system command injection
CVE-2026-547167.5—valhallavalhallaCWE-770Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OO…
CVE-2026-634607.5—vendurehqvendureCWE-1333Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
CVE-2026-685237.5—fulgur-rsfulgurCWE-400Fulgur: Unbounded page slicing from attacker-controlled CSS height causes den…
CVE-2026-685377.5—fulgur-rsfulgurCWE-400Fulgur: Unbounded page slicing from attacker-controlled CSS height causes den…
CVE-2026-814817.5—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-22Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-815157.5—SteeltoeOSSsecurity-advisoriesCWE-755Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire …
CVE-2026-815167.5—SteeltoeOSSsecurity-advisoriesCWE-755Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instanc…
CVE-2026-857157.5—mattiaswExifReaderCWE-789ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion
CVE-2026-857197.5—AsyncHttpClientasync-http-clientCWE-319AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plain…
CVE-2026-857217.5—AsyncHttpClientasync-http-clientCWE-400AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompre…
CVE-2026-859177.5—MicrosoftAzure AI FoundryCWE-918Azure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-860387.5—libp2pjs-libp2pCWE-345libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA…
CVE-2026-860407.5—libp2pjs-libp2pCWE-400libp2p: Unbounded RPC decode + synchronous subscription processing in @libp2p…
CVE-2026-877427.5—Red HatExploit IntelligenceCWE-770Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next v…
CVE-2026-785017.4—MicrosoftMicrosoft 365 Copilot's Business ChatCWE-77Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
CVE-2026-814467.4—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-918Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-866887.4—team-alembicash_authenticationCWE-384Session id is not renewed on authentication in ash_authentication, allowing s…
CVE-2026-909977.4—KeycloakKeycloakCWE-294Keycloak: Replay protection bypass leads to unauthorized access via database …
CVE-2026-535547.3—dataeaseSQLBotCWE-22SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through…
CVE-2026-546347.3—HamlibHamlibCWE-787Hamlib: rigctld `send_raw` Stack Out-of-Bounds Write and Uninitialized Memory…
CVE-2026-662697.3—DellDell OpenManage Server Administrator Managed Node (Patch) for WindowsCWE-470Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-761547.3—GrafanaGrafana OSSCWE-79CVE-2026-76154 CVE Record
CVE-2026-803567.3—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-200Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-814407.3—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-798Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-527277.2—lxclxc-ciCWE-321lxc-ci: Pacman keyring stored in archlinux image with a private key
CVE-2026-546467.2—cubecartv6CWE-89CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.i…
CVE-2026-546477.2—cubecartv6CWE-89CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php
CVE-2026-814457.2—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-269Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-814777.2—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-122Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-814807.2—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-121Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-816327.2—team-alembicash_authentication_phoenixCWE-598Single-use sign-in token placed in a redirect query string in AshAuthenticati…
CVE-2026-929197.2—cjbiadmin3CWE-22admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Uploa…
CVE-2026-442367.1—alanxzrabbitmq-cCWE-122rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized conne…
CVE-2026-528517.1—traccartraccarCWE-89Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions
CVE-2026-545107.1—murtaza-nasirspeakrCWE-287Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_fo…
CVE-2026-545247.1—frappehrmsCWE-89Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report
CVE-2026-546087.1—MythicalLTDMythicalDashCWE-345MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpo…
CVE-2026-665717.1—Gabe LivanAsset CleanUp: Page Speed BoosterCWE-352WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Re…
CVE-2026-860497.1—jupyter-serverjupyter_serverCWE-532Jupyter Server: 5xx request logging leaks token-bearing Referer header values
CVE-2026-868627.1—pgadmin.orgpgAdmin 4CWE-88pgAdmin 4: Connection-string injection via the database field in the Restore …
CVE-2026-908877.1—WP InventoryWP Inventory ManagerCWE-79WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) v…
CVE-2026-909867.1—CODEPRESS IT Solutions LLCVisitor Traffic Real Time Statistics ProCWE-79WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Si…
CVE-2026-929257.1—Red HatPen Drive Powered by Red Hat LightspeedCWE-125Redis: redis: out-of-bounds read via crafted cluster bus packets
CVE-2026-929597.1—patriksimekvm2CWE-693vm2 before 3.11.8 allowAsync Bypass via Promise Thenable
CVE-2026-930147.1—RosarioSISRosarioSISCWE-22RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter
CVE-2026-457207.0—siderolabsomniCWE-294Omni: TOCTOU race condition allows multiple concurrent uses of a single-use S…
CVE-2026-930157.0—BlueKitchen GmbHBTstackCWE-787BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write
CVE-2026-546336.9—podofopodofoCWE-125PoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchS…
CVE-2026-617936.9—nuxt-modulesog-imageCWE-20Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
CVE-2026-782236.9—team-alembicash_authenticationCWE-347Token revocation record built from unverified JWT claims in AshAuthentication
CVE-2026-890386.9—VerizonVerizon Cloud for AndroidCWE-22Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity
CVE-2026-929156.9—WWBNAVideoCWE-770WWBN AVideo userVerifyEmail.php Unauthenticated Access Control
CVE-2026-929216.9—cjbiadmin3CWE-916admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5
CVE-2026-929336.9—patriksimekvm2CWE-200vm2 before 3.11.8 Information Disclosure via util.getCallSites
CVE-2026-929366.9—patriksimekvm2CWE-209vm2 3.11.0 before 3.11.7 Information Disclosure via Error Stack
CVE-2026-929636.9—patriksimekvm2CWE-227vm2 before 3.11.2 Information Disclosure via Internal State
CVE-2026-933956.9—MongoDB Inc.C DriverCWE-191Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()
CVE-2026-934516.9—xerialsnappy-javaCWE-787snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods
CVE-2026-814476.8—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-295Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-857176.8—AsyncHttpClientasync-http-clientCWE-200AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redi…
CVE-2026-927566.8—MongoDB Inc.MongoDB Entity Framework Core ProviderCWE-311Combining encryption settings may disable encryption
CVE-2026-927576.8—MongoDB Inc.MongoDB Entity Framework Core ProviderCWE-311Malformed connection string may disable field level encryption
CVE-2026-442356.5—alanxzrabbitmq-cCWE-125rabbitmq-c: size_t underflow in AMQP frame length computation leads to out-of…
CVE-2026-528526.5—traccartraccarCWE-674Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle
CVE-2026-546486.5—cubecartv6CWE-862CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unau…
CVE-2026-546766.5—ErudikascooldCWE-862Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal…
CVE-2026-546776.5—ErudikascooldCWE-862Scoold: Authenticated user can post replies and comments to private-space que…
CVE-2026-665726.5—Crocoblock. Jetimpex Inc.JetBlogCWE-79WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability
CVE-2026-665736.5—Crocoblock. Jetimpex Inc.JetTabsCWE-79WordPress JetTabs plugin <= 2.3.3.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-665746.5—bdthemesElement Pack Elementor AddonsCWE-79WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scriptin…
CVE-2026-665766.5—Crocoblock. Jetimpex Inc.JetBlocks For ElementorCWE-79WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS…
CVE-2026-665776.5—Crocoblock. Jetimpex Inc.JetSearchCWE-79WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-665786.5—Property HivePropertyHiveCWE-79WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-665796.5—Crocoblock. Jetimpex Inc.JetElements For ElementorCWE-79WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting …
CVE-2026-666176.5—PublishPressPublishPress SeriesCWE-79WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Scripting (XSS) vu…
CVE-2026-670716.5—HCLSoftwareHCL DevOps Deploy / HCL LaunchCWE-212HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensi…
CVE-2026-772816.5—caddyservercaddyCWE-94Caddy: rewrite placeholder re-expansion
CVE-2026-782946.5—Dylan KuhnGeo MashupCWE-79WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-814536.5—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-22Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-818686.5—SteeltoeOSSsecurity-advisoriesCWE-288Steeltoe: Header-forwarded client cert lacks proof of private-key possession
CVE-2026-850786.5—sanic-orgsanicCWE-444sanic chunked trailer request smuggling allows hidden second request execution
CVE-2026-25856.4—themefusecomBrizy – Page BuilderCWE-79Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-666086.4—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-918WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-814436.4—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-918Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-865226.3—team-alembicash_authenticationCWE-117Log injection via an unescaped password reset identity in AshAuthentication
CVE-2026-929496.3—patriksimekvm2CWE-471vm2 3.9.6 before 3.11.7 Sandbox Bypass via Accessor Descriptor
CVE-2026-933946.3—MongoDB Inc.C DriverCWE-303libmongoc SCRAM client nonce-validation bypass
CVE-2026-545216.1—M66BFairEmailCWE-79FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP)
CVE-2026-546446.1—cubecartv6CWE-79CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System
CVE-2026-559466.1—MicrosoftMicrosoft CopilotCWE-77Microsoft Copilot Information Disclosure Vulnerability
CVE-2026-535566.0—dataeaseSQLBotCWE-89SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary Fil…
CVE-2026-545826.0—MidnightBSDmportCWE-73mport package installation can overwrite existing unmanaged or differently ow…
CVE-2026-545856.0—MidnightBSDmportCWE-22mport sample file handling can write outside the configured root
CVE-2026-545866.0—MidnightBSDmportCWE-319mport permits repository and package mirror fetches over insecure transport
CVE-2026-868616.0—pgadmin.orgpgAdmin 4CWE-59pgAdmin 4: File Manager save_file writes through a symbolic link planted afte…
CVE-2026-755235.9—SteeltoeOSSsecurity-advisoriesCWE-200Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string se…
CVE-2026-857185.9—AsyncHttpClientasync-http-clientCWE-400AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-h…
CVE-2026-857205.9—AsyncHttpClientasync-http-clientCWE-319AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNEC…
CVE-2026-500225.8—NCEASmetacatCWE-441Metacat acts as unintended proxy to backend Apache SOLR engine
CVE-2026-545755.8—MidnightBSDmportCWE-78mport package fetch and clean paths are vulnerable to TOCTOU filesystem races
CVE-2026-545765.8—MidnightBSDmportCWE-59mport package installation has symlink TOCTOU in chown and chmod handling
CVE-2026-545875.8—MidnightBSDmportCWE-59mport directory asset installation is vulnerable to symlink and path traversa…
CVE-2026-814795.8—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-187Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-927585.7—MongoDB Inc.MongoDB Entity Framework Core ProviderCWE-532Logs may collect sensitive information
CVE-2026-502915.5—AcademySoftwareFoundationOpenImageIOCWE-125OpenImageIO: Segmentation Fault in BmpInput::read_native_scanline (bmpinput.c…
CVE-2026-767815.5—Red HatRed Hat Enterprise Linux 10CWE-476Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalo…
CVE-2026-929265.5—code-projectsMatrimonial SystemCWE-74code-projects Matrimonial System partner_preference.php writepartnerprefs sql…
CVE-2026-929275.5—SourceCodesterDrug Recommendation SystemCWE-200SourceCodester Drug Recommendation System drug_recommendor.sql information di…
CVE-2026-143115.4—melogranoBooking for Appointments and Events Calendar – AmeliaCWE-862Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Au…
CVE-2026-546135.4—givanzVvvebCWE-22Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme…
CVE-2026-546435.4—cubecartv6CWE-862CubeCart: Missing Authorization Check for Order Note Deletion in orders.index…
CVE-2026-739995.4—Gora TechCookedCWE-639WordPress Cooked plugin <= 1.16.0 - Insecure Direct Object References (IDOR) …
CVE-2026-740055.4—PublishPressPublishPress SeriesCWE-352WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (C…
CVE-2026-803555.4—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-352Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-86745.3—The GNU C LibraryglibcCWE-617Assertion failure in the DNS stub resolver with a long search domain
CVE-2026-165825.3—melogranoBooking for Appointments and Events Calendar – AmeliaCWE-862Booking for Appointments and Events Calendar - Amelia <= 2.4.5 - Missing Auth…
CVE-2026-167505.3—stylemixMotors – Car Dealership & Classified Listings PluginCWE-862Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorizat…
CVE-2026-543555.3—MapServerMapServerCWE-79MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST`
CVE-2026-545945.3—OmniBlocksmonorepoCWE-799OmniBlocks: Spamming in Discussions tab possible via disc.yml
CVE-2026-546045.3—openslideopenslideCWE-758OpenSlide: openslide_read_region() returns uninitialized memory with libtiff …
CVE-2026-546425.3—cubecartv6CWE-352CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in o…
CVE-2026-549075.3—fuomag9caddy-proxy-managerCWE-1188Caddy Proxy Manager: Registrations enabled by default allows creating users w…
CVE-2026-549185.3—netbox-communitydevicetype-libraryCWE-15NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIB…
CVE-2026-634615.3—vendurehqvendureCWE-200Vendure: Shop API list queries can return non-public entities when filterOper…
CVE-2026-665755.3—KingAddons.comKing Addons for ElementorCWE-639WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Objec…
CVE-2026-666765.3—MatrixAddonsEasy InvoiceCWE-862WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability
CVE-2026-715685.3—openshift-metal3bmctestCWE-306BMCtest exposes Ironic without authentication and TLS during the test
CVE-2026-740005.3—wp.insiderSimple MembershipCWE-862WordPress Simple Membership plugin <= 4.8.2 - Broken Access Control vulnerabi…
CVE-2026-740025.3—wpdevelopBooking CalendarCWE-862WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability
CVE-2026-740175.3—wpeverestUser RegistrationCWE-862WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerabi…
CVE-2026-782965.3—WP ManageNinja LLCFluentAuthCWE-345WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability
CVE-2026-785285.3—BerqWPBerqWPCWE-862WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability
CVE-2026-818295.3—Red HatExploit IntelligenceCWE-22Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin…
CVE-2026-859995.3—facelessusersoupsieveCWE-400Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming …
CVE-2026-860005.3—facelessusersoupsieveCWE-400Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selec…
CVE-2026-928795.3—n/avgmstreamCWE-400vgmstream mus_acm.c parse_mus resource consumption
CVE-2026-928805.3—n/avgmstreamCWE-119vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds …
CVE-2026-928815.3—n/avgmstreamCWE-369vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero
CVE-2026-929205.3—cjbiadmin3CWE-613admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled
CVE-2026-929735.3—pycontribsansi2htmlCWE-79ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8
CVE-2026-930135.3—infiniflowragflowCWE-22RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal
CVE-2026-933085.3—O-RAN-SCSMO OAMCWE-770O-RAN-SC SMO OAM VES Collector allocation of resources
CVE-2026-933095.3—O-RAN-SCSMO OAMCWE-770O-RAN-SC SMO OAM VES Collector allocation of resources
CVE-2026-535555.1—dataeaseSQLBotCWE-79Stored XSS via SVG Upload
CVE-2026-929325.1—mispsachertortephpCWE-670MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended…
CVE-2026-932955.1—mispmispCWE-20MISP Background Job Argument Injection via Console Path Switches Enables Remo…
CVE-2026-932965.1—mispmispCWE-79MISP Overmind: Stored Cross-Site Scripting via Unescaped Object Names in Stat…
CVE-2026-934545.1—WebkulAureus ERPCWE-79Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
CVE-2026-545465.0—dfpc-coeCloudTAKCWE-918CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/b…
CVE-2026-546454.8—cubecartv6CWE-79CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass
CVE-2026-926114.8—Eclipse FoundationEclipse AnkaiosCWE-863In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the …
CVE-2026-545654.7—edwardkimrhwpCWE-200rhwp browser extension performs SSRF / private-network requests and leaks HWP…
CVE-2026-184414.3—latepointAppointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressCWE-639LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insec…
CVE-2026-544954.3—open-featureopen-feature-operatorCWE-668Cross-namespace FeatureFlagSource and InProcessConfiguration resolution expos…
CVE-2026-545514.3—h44zwg-portalCWE-285WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' an…
CVE-2026-928934.3—Red HatRed Hat Satellite 6CWE-863Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission …
CVE-2026-928944.3—Red HatRed Hat Satellite 6CWE-863Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model ove…
CVE-2026-929044.3—Red HatRed Hat Satellite 6CWE-863Rubygem-foreman_remote_execution: job output readable without object-level vi…
CVE-2026-814414.0—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-306Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a …
CVE-2026-122843.7—MattermostMattermostCWE-346Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler
CVE-2026-617003.7—mariadb-corporationmariadb-connector-jCWE-284MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiat…
CVE-2026-814383.7—DellDell OpenManage Server Administrator Managed Node (Patch) for WindowsCWE-327Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Us…
CVE-2026-814393.7—DellOpenManage Server Administrator Managed Node (Patch) for WindowsCWE-863Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an…
CVE-2026-857163.7—AsyncHttpClientasync-http-clientCWE-287AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not ver…
CVE-2026-544713.5—DellSmartFabric ManagerCWE-280Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handl…
CVE-2026-457232.7—siderolabsomniCWE-20Omni: Operator can traverse image-factory API paths via unsanitized `talos_ve…
CVE-2026-755882.6—MattermostMattermostCWE-1287Mattermost Desktop App plugin popout scheme validation bypass
CVE-2026-545792.3—MidnightBSDmportCWE-125mport mirror-selection ping accepts insufficiently validated ICMP replies
CVE-2026-816372.3—team-alembicash_authenticationCWE-613Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentic…
CVE-2026-929452.3—patriksimekvm2CWE-22vm2 before 3.11.7 Module Allowlist Bypass via Prefix Matching

Results continue: ranks 401–1035.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-17 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.