| CVE-2026-91011 | 6.8 | 5.4 | Unknown | EWWW Image Optimizer | CWE-79 | EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute B… |
| CVE-2026-24081 | 7.4 | 5.2 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in BT Controller |
| CVE-2026-25281 | 7.4 | 5.2 | Qualcomm, Inc. | Snapdragon | CWE-770 | Allocation of Resources Without Limits or Throttling in OOBM |
| CVE-2026-25294 | 7.4 | 5.2 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in WLAN Firmware |
| CVE-2026-86788 | 6.8 | 4.8 | Unknown | HT Mega Addons for Elementor | CWE-79 | HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag |
| CVE-2026-87829 | 4.3 | 4.7 | Unknown | Checkout Field Manager (Checkout Manager) for WooCommerce | CWE-639 | Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion vi… |
| CVE-2026-87831 | 4.3 | 4.7 | Unknown | Checkout Field Manager (Checkout Manager) for WooCommerce | CWE-862 | Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion vi… |
| CVE-2026-86446 | 3.7 | 4.2 | Unknown | LearnPress | CWE-200 | LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-a… |
| CVE-2026-50604 | 4.9 | 3.8 | Acer | Agent Service | CWE-306 | Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50608 | 1.2 | 3.9 | Acer | System Monitoring | CWE-306 | Authentication Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-92838 | 7.8 | 3.6 | GeoVision Inc. | GV-Remote E-map | CWE-427 | GeoVision GV-Remote E-Map dll hijacking vulnerability |
| CVE-2026-87836 | 2.7 | 3.7 | Unknown | Comments Import & Export | CWE-200 | Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via … |
| CVE-2026-86707 | 9.8 | 3.4 | Unknown | Private Feed Key | CWE-287 | Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey'… |
| CVE-2026-86710 | 9.8 | 3.4 | Unknown | Login with QR | CWE-287 | Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin… |
| CVE-2026-85128 | 7.5 | 3.4 | Unknown | Choose User Role at Registration | CWE-269 | Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Pr… |
| CVE-2026-90923 | 6.5 | 3.4 | Unknown | Autopay | CWE-863 | Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disc… |
| CVE-2026-90922 | 5.3 | 3.4 | Unknown | Paid Membership Subscriptions | CWE-284 | Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass… |
| CVE-2026-91015 | 5.3 | 3.4 | Unknown | Master Addons for Elementor | CWE-862 | Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via … |
| CVE-2026-91016 | 5.3 | 3.4 | Unknown | Motors | CWE-639 | Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure |
| CVE-2026-91008 | 3.7 | 3.4 | Unknown | Event Booking Manager for WooCommerce | CWE-639 | Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII … |
| CVE-2026-44940 | 5.7 | 3.2 | SUSE | SUSE Observability | CWE-200 | Service token exposure and potential privilege escalation in SUSE Observability |
| CVE-2026-88904 | 8.8 | 3.1 | Unknown | PuppyFW | CWE-269 | PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Lea… |
| CVE-2026-91019 | 4.9 | 3.1 | Unknown | Event Booking Manager for WooCommerce | CWE-284 | Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway … |
| CVE-2026-91010 | 4.3 | 3.1 | Unknown | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-862 | Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission… |
| CVE-2026-15688 | 9.2 | 2.0 | Mitsubishi Electric Corporation | GX Works3 | CWE-303 | Password Authentication Bypass Vulnerability in GX Works3 and Motion Control … |
| CVE-2026-25261 | 6.7 | 1.8 | Qualcomm, Inc. | Snapdragon | CWE-822 | Untrusted Pointer Dereference in Camera |
| CVE-2026-25283 | 8.8 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-121 | Stack-based Buffer Overflow in OOBM |
| CVE-2025-59607 | 7.8 | 1.5 | Qualcomm, Inc. | Snapdragon | CWE-822 | Untrusted Pointer Dereference in Windows Compute |
| CVE-2026-24075 | 7.8 | 1.5 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in Qualcomm IPC |
| CVE-2026-25280 | 7.8 | 1.5 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out-of-bounds Write in DSP Service |
| CVE-2026-25290 | 7.8 | 1.4 | Qualcomm, Inc. | Snapdragon | CWE-190 | Integer Overflow or Wraparound in OOBM |
| CVE-2026-81546 | 7.7 | 1.4 | Canva | Affinity | CWE-121 | The Affinity by Canva application before 3.3.0 (September 2026 release) did n… |
| CVE-2026-25284 | 7.3 | 1.3 | Qualcomm, Inc. | Snapdragon | CWE-126 | Buffer Over-read in OOBM |
| CVE-2026-91017 | 3.7 | 1.0 | Unknown | Robokassa payment gateway for Woocommerce | CWE-345 | Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment B… |
| CVE-2026-86824 | 4.8 | 1.0 | Unknown | Newsletter | CWE-326 | Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modificati… |
| CVE-2026-25282 | 7.9 | 0.9 | Qualcomm, Inc. | Snapdragon | CWE-125 | Out-of-bounds Read in OOBM |
| CVE-2026-91009 | 4.3 | 0.8 | Unknown | Active Woot Products Tables for WooCommerce. 100% FREE | CWE-352 | Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post T… |
| CVE-2026-50605 | 7.4 | 0.6 | Acer | Agent Serivce | CWE-284 | Privilege Escalation Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-50609 | 7.4 | 0.6 | Acer | System Monitoring | CWE-284 | Unauthorized Registry Modification Vulnerability in NitroSense and PredatorSe… |
| CVE-2026-50610 | 7.4 | 0.6 | Acer | System Monitoring | CWE-284 | Improper Access control Vulnerability in NitroSense and PredatorSense Software |
| CVE-2026-25278 | 7.8 | 0.4 | Qualcomm, Inc. | Snapdragon | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Software plat… |
| CVE-2026-50603 | 4.9 | 0.1 | Acer | Agent Service | CWE-321 | Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense … |
| CVE-2026-50606 | 1.2 | 0.1 | Acer | System Monitoring | CWE-321 | Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSe… |
| CVE-2026-54734 | 10.0 | — | prebid | prebid-server-java | CWE-918 | Prebid Server Java: Vulnerability to request forgery allows for possible host… |
| CVE-2026-62104 | 10.0 | — | superweby | Migratico Lite | CWE-94 | WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulner… |
| CVE-2026-62874 | 10.0 | — | Microsoft | Azure Billing | CWE-345 | Azure Billing Elevation of Privilege Vulnerability |
| CVE-2026-69399 | 10.0 | — | Microsoft | Azure ARC | CWE-441 | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-69843 | 10.0 | — | Microsoft | Microsoft Fabric | CWE-290 | Microsoft Fabric Elevation of Privilege Vulnerability |
| CVE-2026-69865 | 10.0 | — | Microsoft | Azure Container Registry | CWE-639 | Microsoft Container Registry Elevation of Privilege Vulnerability |
| CVE-2026-70200 | 10.0 | — | Microsoft | Azure Logic Apps | CWE-22 | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-83944 | 10.0 | — | Microsoft | Azure Logic Apps | CWE-284 | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-85889 | 10.0 | — | Microsoft | Azure AI Foundry | CWE-306 | Azure AI Foundry Elevation of Privilege Vulnerability |
| CVE-2026-92937 | 10.0 | — | patriksimek | vm2 | CWE-94 | vm2 3.11.6 Remote Code Execution via Promise call/apply |
| CVE-2026-92940 | 10.0 | — | patriksimek | vm2 | CWE-668 | vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent |
| CVE-2026-92941 | 10.0 | — | patriksimek | vm2 | CWE-732 | vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation |
| CVE-2026-92946 | 10.0 | — | patriksimek | vm2 | CWE-913 | vm2 before 3.11.7 Remote Code Execution via require.external |
| CVE-2026-92947 | 10.0 | — | patriksimek | vm2 | CWE-200 | vm2 before 3.11.7 Memory Disclosure via Buffer Pool |
| CVE-2026-92955 | 10.0 | — | patriksimek | vm2 | CWE-913 | vm2 before 3.11.8 Sandbox Escape via NodeVM |
| CVE-2026-92956 | 10.0 | — | patriksimek | vm2 | CWE-693 | vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming |
| CVE-2026-92960 | 10.0 | — | patriksimek | vm2 | CWE-200 | vm2 before 3.11.6 Process-wide State Exposure via os and dns |
| CVE-2026-85878 | 9.9 | — | Microsoft | Azure HorizonDB | CWE-285 | Azure Database for PostgreSQL Elevation of Privilege Vulnerability |
| CVE-2026-85885 | 9.9 | — | Microsoft | Microsoft 365 Copilot | CWE-77 | Microsoft 365 Copilot Elevation of Privilege Vulnerability |
| CVE-2026-45140 | 9.8 | — | chamilo | chamilo-lms | CWE-22 | Chamilo LMS CStudio upload flow allows unauthenticated remote code execution |
| CVE-2026-54460 | 9.8 | — | open-reception | appointment-booking-software | CWE-306 | OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth… |
| CVE-2026-54617 | 9.8 | — | GravitLauncher | Launcher | CWE-22 | GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler |
| CVE-2026-54626 | 9.8 | — | HappySeaFox | sail | CWE-122 | SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mi… |
| CVE-2026-54627 | 9.8 | — | HappySeaFox | sail | CWE-122 | SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) |
| CVE-2026-62101 | 9.8 | — | Chris Åkerfeldt Wendel | EduAdmin Booking | CWE-288 | WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability |
| CVE-2026-62108 | 9.8 | — | miniOrange | Headless Single Sign On | CWE-290 | WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vul… |
| CVE-2026-90822 | 9.8 | — | FatPipe Networks | MPVPN | CWE-78 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware ve… |
| CVE-2026-90823 | 9.8 | — | FatPipe Networks | MPVPN | CWE-121 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware ve… |
| CVE-2026-54053 | 9.6 | — | brufdev | many-notes | CWE-22 | Many Notes: Path Traversal via ZIP import allows arbitrary file write and sto… |
| CVE-2026-54752 | 9.6 | — | netbox-community | devicetype-library | CWE-502 | NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite All… |
| CVE-2026-87701 | 9.6 | — | Microsoft | Azure Cosmos DB | CWE-74 | Azure Cosmos DB Elevation of Privilege Vulnerability |
| CVE-2026-92934 | 9.5 | — | patriksimek | vm2 | CWE-693 | vm2 before 3.11.8 Sandbox Escape RCE via AggregateError |
| CVE-2026-92935 | 9.5 | — | patriksimek | vm2 | CWE-913 | vm2 NodeVM Remote Code Execution via Array-Shaped Require |
| CVE-2026-54501 | 9.4 | — | webrecorder | browsertrix | CWE-20 | Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization… |
| CVE-2026-54618 | 9.4 | — | jimprosser | obsidian-web-mcp | CWE-306 | Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approve… |
| CVE-2026-92860 | 9.4 | — | rcourtman | Pulse | CWE-20 | rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation |
| CVE-2026-92938 | 9.4 | — | patriksimek | vm2 | CWE-693 | vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite |
| CVE-2026-92939 | 9.4 | — | patriksimek | vm2 | CWE-114 | vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine |
| CVE-2026-92948 | 9.4 | — | patriksimek | vm2 | CWE-693 | vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test |
| CVE-2026-92951 | 9.4 | — | patriksimek | vm2 | CWE-706 | vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver |
| CVE-2026-92957 | 9.4 | — | patriksimek | vm2 | CWE-269 | vm2 before 3.11.7 Authentication Bypass via node: Prefix |
| CVE-2026-54237 | 9.3 | — | wavelog | wavelog | CWE-94 | Wavelog: Unauthenticated Remote Code Execution |
| CVE-2026-70009 | 9.3 | — | Microsoft | Azure ARC | CWE-22 | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-86863 | 9.3 | — | pgadmin.org | pgAdmin 4 | CWE-290 | pgAdmin 4: Authentication bypass via a client-controlled identity header in W… |
| CVE-2026-92944 | 9.3 | — | patriksimek | vm2 | CWE-693 | vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector |
| CVE-2026-92950 | 9.3 | — | patriksimek | vm2 | CWE-453 | vm2 before 3.11.7 Sandbox Escape via CLI require |
| CVE-2026-92953 | 9.3 | — | patriksimek | vm2 | CWE-913 | vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray |
| CVE-2026-76834 | 9.2 | — | b2evolution | b2evolution CMS | CWE-502 | b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Arr… |
| CVE-2026-79752 | 9.2 | — | cakephp | cakephp | CWE-89 | CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection |
| CVE-2026-92943 | 9.2 | — | AWS | AWSIoTPythonSDK | CWE-297 | Improper validation of certificate with host mismatch in AWS IoT Device SDK f… |
| CVE-2026-92954 | 9.2 | — | patriksimek | vm2 | CWE-248 | vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise |
| CVE-2026-93393 | 9.2 | — | MongoDB Inc. | C Driver | CWE-787 | Heap overflow via oversized decrypted TLS record sequence in Windows Secure C… |
| CVE-2026-54670 | 9.1 | — | LabRedesCefetRJ | WeGIA | CWE-22 | WeGIA: Unauthenticated Auth Bypass + Local File Inclusion |
| CVE-2026-54767 | 9.1 | — | LabRedesCefetRJ | WeGIA | CWE-306 | WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_soci… |
| CVE-2026-63472 | 9.1 | — | vendurehq | vendure | CWE-287 | Vendure: External-authentication account takeover: external login linked to a… |
| CVE-2026-76949 | 9.1 | — | team-alembic | ash_authentication | CWE-290 | Remember-me sign-in guard reads a session key that is never written in ash_au… |
| CVE-2026-82761 | 9.1 | — | team-alembic | ash_authentication | CWE-367 | Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
| CVE-2026-85500 | 9.1 | — | team-alembic | ash_authentication | CWE-305 | `require_confirmed_with` is not enforced on the action and fails open on an u… |
| CVE-2026-86533 | 9.1 | — | team-alembic | ash_authentication | CWE-613 | Revoked session accepted because the session jti is never checked in AshAuthe… |
| CVE-2026-88952 | 9.1 | — | team-alembic | ash_authentication | CWE-287 | OAuth2 sign-in attached to an existing account without an email comparison in… |
| CVE-2026-91039 | 9.1 | — | team-alembic | ash_authentication | CWE-290 | dynamic_oidc identities are not namespaced by connection in ash_authenticatio… |
| CVE-2026-92913 | 9.1 | — | WWBN | AVideo | CWE-330 | AVideo Weak PRNG Activation Code Authentication Bypass |
| CVE-2026-45143 | 9.0 | — | chamilo | chamilo-lms | CWE-79 | Chamilo LMS: Student-to-admin stored XSS in private messages via v-html |
| CVE-2026-47252 | 9.0 | — | julien040 | anyquery | CWE-94 | Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (… |
| CVE-2026-77903 | 9.0 | — | Microsoft | Microsoft Dataverse | CWE-290 | Microsoft Dataverse Elevation of Privilege Vulnerability |
| CVE-2026-92952 | 8.9 | — | patriksimek | vm2 | CWE-669 | vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass |
| CVE-2026-14850 | 8.8 | — | MobiAPParc | MobiAPParc | CWE-640 | Weak password recovery mechanism for forgotten password in MobiAPParc |
| CVE-2026-15815 | 8.8 | — | Grafana | Grafana OSS | CWE-22 | CVE-2026-15815 CVE Record |
| CVE-2026-28326 | 8.8 | — | SolarWinds | Access Rights Manager | CWE-321 | SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulner… |
| CVE-2026-54239 | 8.8 | — | wpengine | faustjs | CWE-345 | FaustWP — Authentication Bypass via Initialization Vector Modification in Tok… |
| CVE-2026-54504 | 8.8 | — | andrea9293 | mcp-documentation-server | CWE-306 | MCP Documentation Server: Web UI API binds to all interfaces without authenti… |
| CVE-2026-54519 | 8.8 | — | vmDeshpande | ai-agent-automation | CWE-862 | AI Agent Automation: Missing ownership checks in memory APIs allow cross-user… |
| CVE-2026-54612 | 8.8 | — | givanz | Vvveb | CWE-22 | Vvveb: Authenticated editor path traversal to PHP file write/RCE via data-v-s… |
| CVE-2026-54671 | 8.8 | — | LabRedesCefetRJ | WeGIA | CWE-639 | WeGIA: Authorization Bypass via Empty Resource Array in InternoControle |
| CVE-2026-54916 | 8.8 | — | netbox-community | devicetype-library | CWE-427 | NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE… |
| CVE-2026-77614 | 8.8 | — | opencast | opencast | CWE-384 | Opencast: Session fixation in login enables account takeover via crafted link |
| CVE-2026-78295 | 8.8 | — | Xagio SEO | Xagio SEO | CWE-352 | WordPress Xagio SEO plugin <= 7.1.0.43 - Cross Site Request Forgery (CSRF) vu… |
| CVE-2026-92972 | 8.8 | — | sgl-project | sglang | CWE-306 | SGLang through 0.5.19 Unauthenticated Route Poisoning via PUT endpoint |
| CVE-2026-52836 | 8.7 | — | OpenDDS | OpenDDS | CWE-125 | OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` — tri… |
| CVE-2026-54343 | 8.7 | — | frappe | lms | CWE-22 | Frappe LMS: Path Traversal in SCORM File Serving |
| CVE-2026-54571 | 8.7 | — | ESP32Async | ESPAsyncWebServer | CWE-190 | ESPAsyncWebServer: Integer overflow in multipart boundary parser causes denia… |
| CVE-2026-63459 | 8.7 | — | vendurehq | vendure | CWE-79 | Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHT… |
| CVE-2026-69197 | 8.7 | — | umbraco | Umbraco-CMS | CWE-200 | Umbraco: Delivery API leaks protected (Public Access) content through Content… |
| CVE-2026-77615 | 8.7 | — | opencast | opencast | CWE-79 | Paella Player: Stored XSS via caption cue text |
| CVE-2026-86864 | 8.7 | — | pgadmin.org | pgAdmin 4 | CWE-22 | pgAdmin 4: Argument and connection-string injection via the database field in… |
| CVE-2026-89036 | 8.7 | — | appwrite | appwrite | CWE-88 | Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter |
| CVE-2026-89418 | 8.7 | — | Google | protobuf-javascript (aka google-protobuf npm package) | CWE-674 | Uncontrolled Recursion leading to Denial of Service in protobuf-javascript (g… |
| CVE-2026-92916 | 8.7 | — | getgrav | grav | CWE-200 | Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork |
| CVE-2026-92917 | 8.7 | — | getgrav | grav | CWE-200 | Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r |
| CVE-2026-92918 | 8.7 | — | cjbi | admin3 | CWE-532 | admin3 through 3.0.0 Session Token Disclosure via Audit Log |
| CVE-2026-92942 | 8.7 | — | patriksimek | vm2 | CWE-400 | vm2 before 3.11.7 Timeout Bypass via FinalizationRegistry |
| CVE-2026-92961 | 8.7 | — | patriksimek | vm2 | CWE-770 | vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass |
| CVE-2026-92970 | 8.7 | — | hubzero | hubzero-cms | CWE-22 | HUBzero CMS through 2.2.32 Path Traversal via File Upload |
| CVE-2026-92971 | 8.7 | — | InternLM | lmdeploy | CWE-617 | InternLM LMDeploy through 0.17.0 Assertion Denial of Service |
| CVE-2026-92983 | 8.7 | — | InternLM | lmdeploy | CWE-772 | InternLM LMDeploy through 0.17.0 Memory Exhaustion via Session ID Mismatch |
| CVE-2026-92987 | 8.7 | — | RazrFalcon | roxmltree | CWE-407 | roxmltree through 0.21.1 Denial of Service via Quadratic Parsing |
| CVE-2026-93435 | 8.7 | — | NodeRedis | redis-parser | CWE-674 | redis-parser through 3.0.0 Denial of Service via Unbounded Recursion |
| CVE-2026-93436 | 8.7 | — | vllm-project | vllm | CWE-401 | vLLM through 0.29.0 Memory Exhaustion via Rejected Requests |
| CVE-2026-93450 | 8.7 | — | go-openapi | swag | CWE-674 | go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSO… |
| CVE-2026-93452 | 8.7 | — | xerial | snappy-java | CWE-787 | snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress |
| CVE-2026-93453 | 8.7 | — | Alinto | SOGo | CWE-640 | SOGo before 5.12.11 Password Reset Token Interception via Origin Header |
| CVE-2026-19477 | 8.6 | — | MCC | Universal Library for Linux (uldaq) | CWE-121 | Stack-based Buffer Overflow Vulnerability in Linux (uldaq) |
| CVE-2026-68791 | 8.6 | — | Microsoft | Azure Machine Learning | CWE-863 | Azure Machine Learning Information Disclosure Vulnerability |
| CVE-2026-92914 | 8.6 | — | WWBN | AVideo | CWE-287 | AVideo LoginControl PGP Second Factor Authentication Bypass |
| CVE-2026-92980 | 8.6 | — | danielbrendel | hortusfox-web | CWE-434 | HortusFox-Web < 6.1 Remote Code Execution via Import/Export |
| CVE-2026-92985 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels |
| CVE-2026-92986 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan before 3.8.4 Cross-Site Scripting via Document Title |
| CVE-2026-66580 | 8.5 | — | RexTheme | Product Feed Manager | CWE-89 | WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability |
| CVE-2026-71538 | 8.5 | — | CycloneDX | cyclonedx-node-npm | CWE-78 | @cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argumen… |
| CVE-2026-92984 | 8.5 | — | hubzero | hubzero-cms | CWE-384 | HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier |
| CVE-2026-93337 | 8.5 | — | nm-l2tp | NetworkManager-l2tp | CWE-88 | NetworkManager-l2tp Privilege Escalation via pppd Plugin Injection |
| CVE-2026-54507 | 8.4 | — | givanz | Vvveb | CWE-918 | Vvveb oEmbedProxy vulnerable to server-side request forgery |
| CVE-2026-55062 | 8.4 | — | uniget-org | cli | CWE-22 | uniget: Path Traversal in Hook Files - Directory Escape Vulnerability |
| CVE-2026-92958 | 8.4 | — | patriksimek | vm2 | CWE-269 | vm2 before 3.11.7 Denylist Bypass via fs/promises |
| CVE-2026-93292 | 8.4 | — | SigNoz | signoz | CWE-89 | SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query … |
| CVE-2026-93426 | 8.4 | — | SigNoz | signoz | CWE-89 | SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names |
| CVE-2026-54580 | 8.3 | — | MidnightBSD | mport | CWE-354 | mport index decompression can leave partial or corrupt index data after zstd … |
| CVE-2026-54581 | 8.3 | — | MidnightBSD | mport | CWE-345 | mport bootstrap index fetch can continue after hash verification failure |
| CVE-2026-54583 | 8.3 | — | MidnightBSD | mport | CWE-22 | mport package bundle downloads allow unsafe destination filenames |
| CVE-2026-54597 | 8.3 | — | itflow-org | itflow | CWE-89 | ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Pa… |
| CVE-2026-92912 | 8.3 | — | WWBN | AVideo | CWE-330 | AVideo Cryptographically Weak PRNG via uniqid Stream Key |
| CVE-2026-54253 | 8.2 | — | joni1802 | ts3-manager | CWE-79 | TS3 Manager: Reflected XSS via /api/download port parameter steals operator s… |
| CVE-2026-54354 | 8.2 | — | MapServer | MapServer | CWE-89 | MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Qu… |
| CVE-2026-54451 | 8.2 | — | elixir-protobuf | protobuf | CWE-674 | Elixir protobuf: Unbounded recursion depth in embedded-message decoding |
| CVE-2026-56795 | 8.2 | — | Dell | Driver Pack For Windows OS | CWE-427 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrol… |
| CVE-2026-82760 | 8.2 | — | team-alembic | ash_authentication | CWE-407 | Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API … |
| CVE-2026-83946 | 8.2 | — | Microsoft | Azure Portal | CWE-79 | Azure Portal Spoofing Vulnerability |
| CVE-2026-85077 | 8.2 | — | sanic-org | sanic | CWE-113 | Sanic: HTTP response header injection via missing CR/LF validation in Sanic H… |
| CVE-2026-86039 | 8.2 | — | libp2p | js-libp2p | CWE-290 | libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID an… |
| CVE-2026-92903 | 8.2 | — | Snowflake | Snowflake CLI | CWE-89 | Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Co… |
| CVE-2026-26950 | 8.1 | — | Dell | SmartFabric Manager | CWE-345 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient V… |
| CVE-2026-54446 | 8.1 | — | Labs64 | NetLicensing-MCP | CWE-306 | NetLicensing MCP Server: Unauthenticated Use of Server-Side NetLicensing API … |
| CVE-2026-54520 | 8.1 | — | vmDeshpande | ai-agent-automation | CWE-22 | AI Agent Automation: Workflow file step path traversal allows read and write … |
| CVE-2026-54596 | 8.1 | — | itflow-org | itflow | CWE-89 | ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter… |
| CVE-2026-81442 | 8.1 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-269 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-81475 | 8.1 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-306 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-81476 | 8.1 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-78 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-81478 | 8.1 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-321 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-54692 | 7.8 | — | HappySeaFox | sail | CWE-131 | SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal bu… |
| CVE-2026-81474 | 7.8 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-122 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-48977 | 7.7 | — | openslide | openslide | CWE-123 | OpenSlide: Arbitrary memory write with crafted Ventana BIF file |
| CVE-2026-50158 | 7.7 | — | eat-pray-ai | yutu | CWE-73 | yutu: Arbitrary File Write via MCP `caption-download` Tool |
| CVE-2026-53557 | 7.7 | — | dataease | SQLBot | CWE-89 | SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Com… |
| CVE-2026-54339 | 7.7 | — | LeslieLeung | glean | CWE-918 | Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via M… |
| CVE-2026-85887 | 7.7 | — | Microsoft | Microsoft 365 Copilot | CWE-732 | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-45726 | 7.6 | — | siderolabs | omni | CWE-200 | Omni: Reader-level users can retrieve imported cluster CA keys via ResourceSe… |
| CVE-2026-54506 | 7.6 | — | givanz | Vvveb | CWE-79 | Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field |
| CVE-2026-66618 | 7.6 | — | Flipper Code | WP Maps | CWE-89 | WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability |
| CVE-2026-66619 | 7.6 | — | Tribulant Software | Newsletters | CWE-89 | WordPress Newsletters plugin <= 4.18 - SQL Injection vulnerability |
| CVE-2026-66624 | 7.6 | — | Ludwig You | WPMasterToolKit | CWE-89 | WordPress WPMasterToolKit plugin <= 2.22.0 - SQL Injection vulnerability |
| CVE-2026-66625 | 7.6 | — | WCVendors | WC Vendors Marketplace | CWE-89 | WordPress WC Vendors Marketplace plugin <= 2.7.2.1 - SQL Injection vulnerability |
| CVE-2026-66626 | 7.6 | — | Sonal S Sinha | SKT Addons for Elementor | CWE-89 | WordPress SKT Addons for Elementor plugin <= 4.0 - SQL Injection vulnerability |
| CVE-2026-66628 | 7.6 | — | WP Lab | WP-Lister Lite for eBay | CWE-89 | WordPress WP-Lister Lite for eBay plugin <= 3.8.11 - SQL Injection vulnerability |
| CVE-2026-66630 | 7.6 | — | PublishPress | PublishPress Series | CWE-89 | WordPress PublishPress Series plugin <= 3.1.3 - SQL Injection vulnerability |
| CVE-2026-66631 | 7.6 | — | Moreconvert Team | MC Woocommerce Wishlist | CWE-89 | WordPress MC Woocommerce Wishlist plugin <= 1.9.21 - SQL Injection vulnerability |
| CVE-2026-80218 | 7.6 | — | team-alembic | ash_authentication | CWE-287 | Sign-in token minted for one resource accepted by another in AshAuthentication |
| CVE-2026-82685 | 7.6 | — | team-alembic | ash_authentication | CWE-639 | Confirmation token accepted on any record in AshAuthentication |
| CVE-2026-50125 | 7.5 | — | StacklokLabs | mkp | CWE-400 | MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` … |
| CVE-2026-50275 | 7.5 | — | DataDog | dd-trace-php | CWE-770 | Datadog PHP Tracer: Improper parsing of W3C baggage headers may lead to DoS |
| CVE-2026-50277 | 7.5 | — | DataDog | dd-trace-cpp | CWE-770 | dd-trace-cpp: Improper parsing of W3C baggage headers may lead to DoS |
| CVE-2026-50285 | 7.5 | — | pomerium | pomerium | CWE-770 | Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE… |
| CVE-2026-53534 | 7.5 | — | JabRef | jabref | CWE-78 | JabRef CAYW Sublime Text integration permits operating-system command injection |
| CVE-2026-54716 | 7.5 | — | valhalla | valhalla | CWE-770 | Valhalla: Degenerate exclude_polygons (collinear points, zero area) causes OO… |
| CVE-2026-63460 | 7.5 | — | vendurehq | vendure | CWE-1333 | Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends |
| CVE-2026-68523 | 7.5 | — | fulgur-rs | fulgur | CWE-400 | Fulgur: Unbounded page slicing from attacker-controlled CSS height causes den… |
| CVE-2026-68537 | 7.5 | — | fulgur-rs | fulgur | CWE-400 | Fulgur: Unbounded page slicing from attacker-controlled CSS height causes den… |
| CVE-2026-81481 | 7.5 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-22 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-81515 | 7.5 | — | SteeltoeOSS | security-advisories | CWE-755 | Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire … |
| CVE-2026-81516 | 7.5 | — | SteeltoeOSS | security-advisories | CWE-755 | Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instanc… |
| CVE-2026-85715 | 7.5 | — | mattiasw | ExifReader | CWE-789 | ExifReader: DoS via Crafted HEIC/AVIF iloc Box - Memory Exhaustion |
| CVE-2026-85719 | 7.5 | — | AsyncHttpClient | async-http-client | CWE-319 | AsyncHttpClient: SOCKS proxy credentials sent to the origin server over plain… |
| CVE-2026-85721 | 7.5 | — | AsyncHttpClient | async-http-client | CWE-400 | AsyncHttpClient: Unbounded HTTP/1.1 response decompression enables a decompre… |
| CVE-2026-85917 | 7.5 | — | Microsoft | Azure AI Foundry | CWE-918 | Azure AI Foundry Elevation of Privilege Vulnerability |
| CVE-2026-86038 | 7.5 | — | libp2p | js-libp2p | CWE-345 | libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA… |
| CVE-2026-86040 | 7.5 | — | libp2p | js-libp2p | CWE-400 | libp2p: Unbounded RPC decode + synchronous subscription processing in @libp2p… |
| CVE-2026-87742 | 7.5 | — | Red Hat | Exploit Intelligence | CWE-770 | Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next v… |
| CVE-2026-78501 | 7.4 | — | Microsoft | Microsoft 365 Copilot's Business Chat | CWE-77 | Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability |
| CVE-2026-81446 | 7.4 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-918 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-86688 | 7.4 | — | team-alembic | ash_authentication | CWE-384 | Session id is not renewed on authentication in ash_authentication, allowing s… |
| CVE-2026-90997 | 7.4 | — | Keycloak | Keycloak | CWE-294 | Keycloak: Replay protection bypass leads to unauthorized access via database … |
| CVE-2026-53554 | 7.3 | — | dataease | SQLBot | CWE-22 | SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through… |
| CVE-2026-54634 | 7.3 | — | Hamlib | Hamlib | CWE-787 | Hamlib: rigctld `send_raw` Stack Out-of-Bounds Write and Uninitialized Memory… |
| CVE-2026-66269 | 7.3 | — | Dell | Dell OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-470 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-76154 | 7.3 | — | Grafana | Grafana OSS | CWE-79 | CVE-2026-76154 CVE Record |
| CVE-2026-80356 | 7.3 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-200 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-81440 | 7.3 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-798 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-52727 | 7.2 | — | lxc | lxc-ci | CWE-321 | lxc-ci: Pacman keyring stored in archlinux image with a private key |
| CVE-2026-54646 | 7.2 | — | cubecart | v6 | CWE-89 | CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.i… |
| CVE-2026-54647 | 7.2 | — | cubecart | v6 | CWE-89 | CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php |
| CVE-2026-81445 | 7.2 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-269 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-81477 | 7.2 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-122 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-81480 | 7.2 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-121 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-81632 | 7.2 | — | team-alembic | ash_authentication_phoenix | CWE-598 | Single-use sign-in token placed in a redirect query string in AshAuthenticati… |
| CVE-2026-92919 | 7.2 | — | cjbi | admin3 | CWE-22 | admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Uploa… |
| CVE-2026-44236 | 7.1 | — | alanxz | rabbitmq-c | CWE-122 | rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized conne… |
| CVE-2026-52851 | 7.1 | — | traccar | traccar | CWE-89 | Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions |
| CVE-2026-54510 | 7.1 | — | murtaza-nasir | speakr | CWE-287 | Speakr: CSRF bypass via unauthenticated API token parameter in csrf_exempt_fo… |
| CVE-2026-54524 | 7.1 | — | frappe | hrms | CWE-89 | Frappe HR: SQL Injection in HRMS Salary Payments Based on Payment Mode Report |
| CVE-2026-54608 | 7.1 | — | MythicalLTD | MythicalDash | CWE-345 | MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpo… |
| CVE-2026-66571 | 7.1 | — | Gabe Livan | Asset CleanUp: Page Speed Booster | CWE-352 | WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Re… |
| CVE-2026-86049 | 7.1 | — | jupyter-server | jupyter_server | CWE-532 | Jupyter Server: 5xx request logging leaks token-bearing Referer header values |
| CVE-2026-86862 | 7.1 | — | pgadmin.org | pgAdmin 4 | CWE-88 | pgAdmin 4: Connection-string injection via the database field in the Restore … |
| CVE-2026-90887 | 7.1 | — | WP Inventory | WP Inventory Manager | CWE-79 | WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) v… |
| CVE-2026-90986 | 7.1 | — | CODEPRESS IT Solutions LLC | Visitor Traffic Real Time Statistics Pro | CWE-79 | WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Si… |
| CVE-2026-92925 | 7.1 | — | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-125 | Redis: redis: out-of-bounds read via crafted cluster bus packets |
| CVE-2026-92959 | 7.1 | — | patriksimek | vm2 | CWE-693 | vm2 before 3.11.8 allowAsync Bypass via Promise Thenable |
| CVE-2026-93014 | 7.1 | — | RosarioSIS | RosarioSIS | CWE-22 | RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter |
| CVE-2026-45720 | 7.0 | — | siderolabs | omni | CWE-294 | Omni: TOCTOU race condition allows multiple concurrent uses of a single-use S… |
| CVE-2026-93015 | 7.0 | — | BlueKitchen GmbH | BTstack | CWE-787 | BlueKitchen BTstack through 1.8.2 A2DP SEP Discovery Out-of-Bounds Write |
| CVE-2026-54633 | 6.9 | — | podofo | podofo | CWE-125 | PoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchS… |
| CVE-2026-61793 | 6.9 | — | nuxt-modules | og-image | CWE-20 | Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter |
| CVE-2026-78223 | 6.9 | — | team-alembic | ash_authentication | CWE-347 | Token revocation record built from unverified JWT claims in AshAuthentication |
| CVE-2026-89038 | 6.9 | — | Verizon | Verizon Cloud for Android | CWE-22 | Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity |
| CVE-2026-92915 | 6.9 | — | WWBN | AVideo | CWE-770 | WWBN AVideo userVerifyEmail.php Unauthenticated Access Control |
| CVE-2026-92921 | 6.9 | — | cjbi | admin3 | CWE-916 | admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5 |
| CVE-2026-92933 | 6.9 | — | patriksimek | vm2 | CWE-200 | vm2 before 3.11.8 Information Disclosure via util.getCallSites |
| CVE-2026-92936 | 6.9 | — | patriksimek | vm2 | CWE-209 | vm2 3.11.0 before 3.11.7 Information Disclosure via Error Stack |
| CVE-2026-92963 | 6.9 | — | patriksimek | vm2 | CWE-227 | vm2 before 3.11.2 Information Disclosure via Internal State |
| CVE-2026-93395 | 6.9 | — | MongoDB Inc. | C Driver | CWE-191 | Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer() |
| CVE-2026-93451 | 6.9 | — | xerial | snappy-java | CWE-787 | snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods |
| CVE-2026-81447 | 6.8 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-295 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-85717 | 6.8 | — | AsyncHttpClient | async-http-client | CWE-200 | AsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redi… |
| CVE-2026-92756 | 6.8 | — | MongoDB Inc. | MongoDB Entity Framework Core Provider | CWE-311 | Combining encryption settings may disable encryption |
| CVE-2026-92757 | 6.8 | — | MongoDB Inc. | MongoDB Entity Framework Core Provider | CWE-311 | Malformed connection string may disable field level encryption |
| CVE-2026-44235 | 6.5 | — | alanxz | rabbitmq-c | CWE-125 | rabbitmq-c: size_t underflow in AMQP frame length computation leads to out-of… |
| CVE-2026-52852 | 6.5 | — | traccar | traccar | CWE-674 | Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle |
| CVE-2026-54648 | 6.5 | — | cubecart | v6 | CWE-862 | CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unau… |
| CVE-2026-54676 | 6.5 | — | Erudika | scoold | CWE-862 | Scoold: GET /api/posts/{id}/answers leaks private-space replies when personal… |
| CVE-2026-54677 | 6.5 | — | Erudika | scoold | CWE-862 | Scoold: Authenticated user can post replies and comments to private-space que… |
| CVE-2026-66572 | 6.5 | — | Crocoblock. Jetimpex Inc. | JetBlog | CWE-79 | WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66573 | 6.5 | — | Crocoblock. Jetimpex Inc. | JetTabs | CWE-79 | WordPress JetTabs plugin <= 2.3.3.1 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66574 | 6.5 | — | bdthemes | Element Pack Elementor Addons | CWE-79 | WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scriptin… |
| CVE-2026-66576 | 6.5 | — | Crocoblock. Jetimpex Inc. | JetBlocks For Elementor | CWE-79 | WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS… |
| CVE-2026-66577 | 6.5 | — | Crocoblock. Jetimpex Inc. | JetSearch | CWE-79 | WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-66578 | 6.5 | — | Property Hive | PropertyHive | CWE-79 | WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-66579 | 6.5 | — | Crocoblock. Jetimpex Inc. | JetElements For Elementor | CWE-79 | WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting … |
| CVE-2026-66617 | 6.5 | — | PublishPress | PublishPress Series | CWE-79 | WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Scripting (XSS) vu… |
| CVE-2026-67071 | 6.5 | — | HCLSoftware | HCL DevOps Deploy / HCL Launch | CWE-212 | HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensi… |
| CVE-2026-77281 | 6.5 | — | caddyserver | caddy | CWE-94 | Caddy: rewrite placeholder re-expansion |
| CVE-2026-78294 | 6.5 | — | Dylan Kuhn | Geo Mashup | CWE-79 | WordPress Geo Mashup plugin <= 1.13.21 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-81453 | 6.5 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-22 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-81868 | 6.5 | — | SteeltoeOSS | security-advisories | CWE-288 | Steeltoe: Header-forwarded client cert lacks proof of private-key possession |
| CVE-2026-85078 | 6.5 | — | sanic-org | sanic | CWE-444 | sanic chunked trailer request smuggling allows hidden second request execution |
| CVE-2026-2585 | 6.4 | — | themefusecom | Brizy – Page Builder | CWE-79 | Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Si… |
| CVE-2026-66608 | 6.4 | — | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-918 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-81443 | 6.4 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-918 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-86522 | 6.3 | — | team-alembic | ash_authentication | CWE-117 | Log injection via an unescaped password reset identity in AshAuthentication |
| CVE-2026-92949 | 6.3 | — | patriksimek | vm2 | CWE-471 | vm2 3.9.6 before 3.11.7 Sandbox Bypass via Accessor Descriptor |
| CVE-2026-93394 | 6.3 | — | MongoDB Inc. | C Driver | CWE-303 | libmongoc SCRAM client nonce-validation bypass |
| CVE-2026-54521 | 6.1 | — | M66B | FairEmail | CWE-79 | FairEmail: Cross-site scripting (XSS) in AMP message rendering (ActivityAMP) |
| CVE-2026-54644 | 6.1 | — | cubecart | v6 | CWE-79 | CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System |
| CVE-2026-55946 | 6.1 | — | Microsoft | Microsoft Copilot | CWE-77 | Microsoft Copilot Information Disclosure Vulnerability |
| CVE-2026-53556 | 6.0 | — | dataease | SQLBot | CWE-89 | SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary Fil… |
| CVE-2026-54582 | 6.0 | — | MidnightBSD | mport | CWE-73 | mport package installation can overwrite existing unmanaged or differently ow… |
| CVE-2026-54585 | 6.0 | — | MidnightBSD | mport | CWE-22 | mport sample file handling can write outside the configured root |
| CVE-2026-54586 | 6.0 | — | MidnightBSD | mport | CWE-319 | mport permits repository and package mirror fetches over insecure transport |
| CVE-2026-86861 | 6.0 | — | pgadmin.org | pgAdmin 4 | CWE-59 | pgAdmin 4: File Manager save_file writes through a symbolic link planted afte… |
| CVE-2026-75523 | 5.9 | — | SteeltoeOSS | security-advisories | CWE-200 | Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string se… |
| CVE-2026-85718 | 5.9 | — | AsyncHttpClient | async-http-client | CWE-400 | AsyncHttpClient: Connection permit leak on TLS handshake failure causes per-h… |
| CVE-2026-85720 | 5.9 | — | AsyncHttpClient | async-http-client | CWE-319 | AsyncHttpClient: Origin credentials sent to the proxy on the plaintext CONNEC… |
| CVE-2026-50022 | 5.8 | — | NCEAS | metacat | CWE-441 | Metacat acts as unintended proxy to backend Apache SOLR engine |
| CVE-2026-54575 | 5.8 | — | MidnightBSD | mport | CWE-78 | mport package fetch and clean paths are vulnerable to TOCTOU filesystem races |
| CVE-2026-54576 | 5.8 | — | MidnightBSD | mport | CWE-59 | mport package installation has symlink TOCTOU in chown and chmod handling |
| CVE-2026-54587 | 5.8 | — | MidnightBSD | mport | CWE-59 | mport directory asset installation is vulnerable to symlink and path traversa… |
| CVE-2026-81479 | 5.8 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-187 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-92758 | 5.7 | — | MongoDB Inc. | MongoDB Entity Framework Core Provider | CWE-532 | Logs may collect sensitive information |
| CVE-2026-50291 | 5.5 | — | AcademySoftwareFoundation | OpenImageIO | CWE-125 | OpenImageIO: Segmentation Fault in BmpInput::read_native_scanline (bmpinput.c… |
| CVE-2026-76781 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-476 | Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalo… |
| CVE-2026-92926 | 5.5 | — | code-projects | Matrimonial System | CWE-74 | code-projects Matrimonial System partner_preference.php writepartnerprefs sql… |
| CVE-2026-92927 | 5.5 | — | SourceCodester | Drug Recommendation System | CWE-200 | SourceCodester Drug Recommendation System drug_recommendor.sql information di… |
| CVE-2026-14311 | 5.4 | — | melograno | Booking for Appointments and Events Calendar – Amelia | CWE-862 | Booking for Appointments and Events Calendar – Amelia (Premium) <= 2.4.4 - Au… |
| CVE-2026-54613 | 5.4 | — | givanz | Vvveb | CWE-22 | Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme… |
| CVE-2026-54643 | 5.4 | — | cubecart | v6 | CWE-862 | CubeCart: Missing Authorization Check for Order Note Deletion in orders.index… |
| CVE-2026-73999 | 5.4 | — | Gora Tech | Cooked | CWE-639 | WordPress Cooked plugin <= 1.16.0 - Insecure Direct Object References (IDOR) … |
| CVE-2026-74005 | 5.4 | — | PublishPress | PublishPress Series | CWE-352 | WordPress PublishPress Series plugin <= 3.1.3 - Cross Site Request Forgery (C… |
| CVE-2026-80355 | 5.4 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-352 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-8674 | 5.3 | — | The GNU C Library | glibc | CWE-617 | Assertion failure in the DNS stub resolver with a long search domain |
| CVE-2026-16582 | 5.3 | — | melograno | Booking for Appointments and Events Calendar – Amelia | CWE-862 | Booking for Appointments and Events Calendar - Amelia <= 2.4.5 - Missing Auth… |
| CVE-2026-16750 | 5.3 | — | stylemix | Motors – Car Dealership & Classified Listings Plugin | CWE-862 | Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorizat… |
| CVE-2026-54355 | 5.3 | — | MapServer | MapServer | CWE-79 | MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST` |
| CVE-2026-54594 | 5.3 | — | OmniBlocks | monorepo | CWE-799 | OmniBlocks: Spamming in Discussions tab possible via disc.yml |
| CVE-2026-54604 | 5.3 | — | openslide | openslide | CWE-758 | OpenSlide: openslide_read_region() returns uninitialized memory with libtiff … |
| CVE-2026-54642 | 5.3 | — | cubecart | v6 | CWE-352 | CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in o… |
| CVE-2026-54907 | 5.3 | — | fuomag9 | caddy-proxy-manager | CWE-1188 | Caddy Proxy Manager: Registrations enabled by default allows creating users w… |
| CVE-2026-54918 | 5.3 | — | netbox-community | devicetype-library | CWE-15 | NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIB… |
| CVE-2026-63461 | 5.3 | — | vendurehq | vendure | CWE-200 | Vendure: Shop API list queries can return non-public entities when filterOper… |
| CVE-2026-66575 | 5.3 | — | KingAddons.com | King Addons for Elementor | CWE-639 | WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Objec… |
| CVE-2026-66676 | 5.3 | — | MatrixAddons | Easy Invoice | CWE-862 | WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability |
| CVE-2026-71568 | 5.3 | — | openshift-metal3 | bmctest | CWE-306 | BMCtest exposes Ironic without authentication and TLS during the test |
| CVE-2026-74000 | 5.3 | — | wp.insider | Simple Membership | CWE-862 | WordPress Simple Membership plugin <= 4.8.2 - Broken Access Control vulnerabi… |
| CVE-2026-74002 | 5.3 | — | wpdevelop | Booking Calendar | CWE-862 | WordPress Booking Calendar plugin <= 11.7 - Broken Access Control vulnerability |
| CVE-2026-74017 | 5.3 | — | wpeverest | User Registration | CWE-862 | WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerabi… |
| CVE-2026-78296 | 5.3 | — | WP ManageNinja LLC | FluentAuth | CWE-345 | WordPress FluentAuth plugin <= 2.1.2 - Email Verification Bypass vulnerability |
| CVE-2026-78528 | 5.3 | — | BerqWP | BerqWP | CWE-862 | WordPress BerqWP plugin <= 4.1.15 - Broken Access Control vulnerability |
| CVE-2026-81829 | 5.3 | — | Red Hat | Exploit Intelligence | CWE-22 | Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin… |
| CVE-2026-85999 | 5.3 | — | facelessuser | soupsieve | CWE-400 | Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming … |
| CVE-2026-86000 | 5.3 | — | facelessuser | soupsieve | CWE-400 | Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selec… |
| CVE-2026-92879 | 5.3 | — | n/a | vgmstream | CWE-400 | vgmstream mus_acm.c parse_mus resource consumption |
| CVE-2026-92880 | 5.3 | — | n/a | vgmstream | CWE-119 | vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds … |
| CVE-2026-92881 | 5.3 | — | n/a | vgmstream | CWE-369 | vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero |
| CVE-2026-92920 | 5.3 | — | cjbi | admin3 | CWE-613 | admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled |
| CVE-2026-92973 | 5.3 | — | pycontribs | ansi2html | CWE-79 | ansi2html 1.7.0a0 through 1.9.3 Cross-Site Scripting via OSC 8 |
| CVE-2026-93013 | 5.3 | — | infiniflow | ragflow | CWE-22 | RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal |
| CVE-2026-93308 | 5.3 | — | O-RAN-SC | SMO OAM | CWE-770 | O-RAN-SC SMO OAM VES Collector allocation of resources |
| CVE-2026-93309 | 5.3 | — | O-RAN-SC | SMO OAM | CWE-770 | O-RAN-SC SMO OAM VES Collector allocation of resources |
| CVE-2026-53555 | 5.1 | — | dataease | SQLBot | CWE-79 | Stored XSS via SVG Upload |
| CVE-2026-92932 | 5.1 | — | misp | sachertortephp | CWE-670 | MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended… |
| CVE-2026-93295 | 5.1 | — | misp | misp | CWE-20 | MISP Background Job Argument Injection via Console Path Switches Enables Remo… |
| CVE-2026-93296 | 5.1 | — | misp | misp | CWE-79 | MISP Overmind: Stored Cross-Site Scripting via Unescaped Object Names in Stat… |
| CVE-2026-93454 | 5.1 | — | Webkul | Aureus ERP | CWE-79 | Aureus ERP through 1.6.0 Stored XSS via Payment Term Note |
| CVE-2026-54546 | 5.0 | — | dfpc-coe | CloudTAK | CWE-918 | CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/b… |
| CVE-2026-54645 | 4.8 | — | cubecart | v6 | CWE-79 | CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass |
| CVE-2026-92611 | 4.8 | — | Eclipse Foundation | Eclipse Ankaios | CWE-863 | In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the … |
| CVE-2026-54565 | 4.7 | — | edwardkim | rhwp | CWE-200 | rhwp browser extension performs SSRF / private-network requests and leaks HWP… |
| CVE-2026-18441 | 4.3 | — | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | CWE-639 | LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insec… |
| CVE-2026-54495 | 4.3 | — | open-feature | open-feature-operator | CWE-668 | Cross-namespace FeatureFlagSource and InProcessConfiguration resolution expos… |
| CVE-2026-54551 | 4.3 | — | h44z | wg-portal | CWE-285 | WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' an… |
| CVE-2026-92893 | 4.3 | — | Red Hat | Red Hat Satellite 6 | CWE-863 | Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission … |
| CVE-2026-92894 | 4.3 | — | Red Hat | Red Hat Satellite 6 | CWE-863 | Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model ove… |
| CVE-2026-92904 | 4.3 | — | Red Hat | Red Hat Satellite 6 | CWE-863 | Rubygem-foreman_remote_execution: job output readable without object-level vi… |
| CVE-2026-81441 | 4.0 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-306 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a … |
| CVE-2026-12284 | 3.7 | — | Mattermost | Mattermost | CWE-346 | Mattermost Desktop App Missing IPC Sender Validation in Calls Leave Handler |
| CVE-2026-61700 | 3.7 | — | mariadb-corporation | mariadb-connector-j | CWE-284 | MariaDB Connector/J does not enforce allowLocalInfile=false on server-initiat… |
| CVE-2026-81438 | 3.7 | — | Dell | Dell OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-327 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Us… |
| CVE-2026-81439 | 3.7 | — | Dell | OpenManage Server Administrator Managed Node (Patch) for Windows | CWE-863 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an… |
| CVE-2026-85716 | 3.7 | — | AsyncHttpClient | async-http-client | CWE-287 | AsyncHttpClient: SCRAM and Digest mutual-authentication responses are not ver… |
| CVE-2026-54471 | 3.5 | — | Dell | SmartFabric Manager | CWE-280 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handl… |
| CVE-2026-45723 | 2.7 | — | siderolabs | omni | CWE-20 | Omni: Operator can traverse image-factory API paths via unsanitized `talos_ve… |
| CVE-2026-75588 | 2.6 | — | Mattermost | Mattermost | CWE-1287 | Mattermost Desktop App plugin popout scheme validation bypass |
| CVE-2026-54579 | 2.3 | — | MidnightBSD | mport | CWE-125 | mport mirror-selection ping accepts insufficiently validated ICMP replies |
| CVE-2026-81637 | 2.3 | — | team-alembic | ash_authentication | CWE-613 | Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentic… |
| CVE-2026-92945 | 2.3 | — | patriksimek | vm2 | CWE-22 | vm2 before 3.11.7 Module Allowlist Bypass via Prefix Matching |