boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 18, 2026 · all times UTC← 2026-09-17 · archive

Security Box Score — September 18, 2026

CISA adds 3 to KEV; 514 CVEs published, led by IBM (90).

514 CVEs published September 18, 2026: 51 critical, 207 high, 207 medium, 42 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 7 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 114 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1033545276——
KEV catalog size1716

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2812 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15075597526251371211560.17.8.0017+245 ▲
microsoft10002899204198469516289301.07.8.0044+556 ▲
google5162682331104811821218090.37.5.0025+452 ▲
red hat1537794432437140200.06.6.0028-8 ▼
apple24656367165317148881.46.5.0020+212 ▲
freebsd04823673000.07.8.00160
canonical0421311135000.07.8.0021-11 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+66 ▲
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0045+8 ▲
ivanti10246162025520.88.8.0146+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache93605140253195153320.37.5.0048-8 ▼
mozilla11330080103640900.08.8.0026+54 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+2 ▲
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+1 ▲
wordpress0513102240.08.8.3120-2 ▼
go440211000.05.9.0029+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0034-255 ▼
ibm29791618341430313610.17.5.0029+105 ▲
adobe17177757344366102040.57.5.0023+111 ▲
progress3641539100611.68.1.0035-16 ▼
solarwinds1241743010416.79.1.0058+1 ▲
veeam01961030100.08.6.0032-10 ▼
zohocorp7173860000.07.7.0106+3 ▲
atlassian3918001300.07.6.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link216619241112300.08.5.0154+5 ▲
siemens1552633103000.07.3.0018-4 ▼
synology1946510256000.05.6.0027+18 ▲
rockwell automation184353260000.08.6.0029+18 ▲
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
abb181430000.07.2.0018+1 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1773482616613323210.37.2.0021+144 ▲
sourcecodester482170012889000.05.5.0028+21 ▲
spring017013608215000.06.5.00240
nvidia3216620117290000.07.8.0029+8 ▲
mongodb64162694584100.07.1.0026+32 ▲
itsourcecode341500037113000.02.1.0026+17 ▲
wwbn1061462349740000.06.9.0024+104 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0029+126 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.145696.510.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-19586.057092.79.3
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
CVE-2026-77806.042090.59.8
CVE-2026-76698.041190.36.5
CVE-2026-47864.040890.29.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1456KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-6983610.0.0155
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8782710.0.0107
Most disclosures (vendor)
VendorCVEs
linux1889
microsoft1031
google854
oracle635
ibm388
apple256
adobe212
red hat209
dell193
apache160
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
ivanti5
adobe4
berriai4
jfrog4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist41
npm20
PyPI17
crates.io3
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-72529TrueConf0
CVE-2026-72530TrueConf0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171766
CVE-2021-27102n/a2021-11-171766
CVE-2021-27101n/a2021-11-171766
CVE-2021-27103n/a2021-11-171766
CVE-2021-21017Adobe2021-11-171766
CVE-2021-28550Adobe2021-11-171766
CVE-2021-42013Apache Software Foundation2021-11-171766
CVE-2021-41773Apache Software Foundation2021-11-171766
CVE-2021-30858Apple2021-11-171766
CVE-2021-30860Apple2021-11-171766

Transactions

ADDED TO KEV — CVE-2025-39682 (Linux). Remediation due September 21, 2026.

ADDED TO KEV — CVE-2025-39964 (Linux). Remediation due September 21, 2026.

ADDED TO KEV — CVE-2026-53266 (Linux). Remediation due September 21, 2026.

EXPLOIT PUBLISHED — open-webui: 11 CVEs (CVE-2026-70479, CVE-2026-70480, CVE-2026-70481, CVE-2026-70482, CVE-2026-70483, CVE-2026-70485, CVE-2026-70486, CVE-2026-70489, CVE-2026-70491, CVE-2026-70492, CVE-2026-70493). Public exploit references added.

EXPLOIT PUBLISHED — netty: 6 CVEs (CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587, CVE-2026-89044). Public exploit references added.

EXPLOIT PUBLISHED — wazuh: 6 CVEs (CVE-2026-41424, CVE-2026-44252, CVE-2026-44254, CVE-2026-44255, CVE-2026-44256, CVE-2026-46343). Public exploit references added.

EXPLOIT PUBLISHED — GNU Binutils: 4 CVEs (CVE-2026-90801, CVE-2026-90802, CVE-2026-90803, CVE-2026-90804). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66046 (libexpat project libexpat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86176 (netbox-community netbox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86426 (librenms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86427 (librenms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86739 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86744 (grokability snipe-it). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87819 (gitpython-developers GitPython). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87928 (MaxSite CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-89034 (TCH QRing). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90489 (Xuxueli xxl-job). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91732 (Google Chrome). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91995 (pig-mesh pig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92381 (PbootCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92399 (GPAC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92413 (Artifex MuPDF). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92458 (guchengwuyue yshop-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92463 (guchengwuyue yshop-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92468 (zlt2000 microservices-platform). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92473 (GPAC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92776 (requarks Wiki.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92800 (suitenumerique Docs). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92812 (decaporg decap-server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92921 (cjbi admin3). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92926 (code-projects Matrimonial System). Public exploit reference added.

DUE DATE PASSED — CVE-2026-76461 (Cisco Secure Email). CISA remediation deadline was September 17, 2026; still in catalog.

REJECTED — CVE-2026-90168 (Linux). Record withdrawn by the CNA.

REJECTED — CVE-2026-90310 (Linux). Record withdrawn by the CNA.

RESCORED — open-webui: 6 CVEs (CVE-2026-70482, CVE-2026-70483, CVE-2026-70484, CVE-2026-70486, CVE-2026-70487, CVE-2026-70492). CVSS rescored — before/after on each CVE page.

RESCORED — Ivanti Neurons for ITSM: 4 CVEs (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, CVE-2026-12650). CVSS rescored — before/after on each CVE page.

RESCORED — Google Chrome: 3 CVEs (CVE-2026-91719, CVE-2026-91723, CVE-2026-91732). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2025-10072 (Portabilis i-Educar). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-84566 (Apple iOS and iPadOS). CVSS 8.4 → 7.8 (NVD).

RESCORED — CVE-2026-85544 (Hikvision DS-KV9503). CVSS 5.2 → 6.1 (NVD).

RESCORED — CVE-2026-93308 (O-RAN-SC SMO OAM). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-93309 (O-RAN-SC SMO OAM). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — CVE-2026-65490 (John-Michael L'Allier Create). Fixed in Create 2.6.1.

ENRICHED — CVE-2018-13410. Received CVSS 9.8 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

514 CVEs published. 25 box scores and 375 table rows below; the remaining 114 continue on page 2 — every CVE is listed, nothing truncated.

Zohocorp ManageEngine DataSecurity Plus — ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulner…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  N  N    7.7   .0150   73.1     —
AFFECTED
  Product                         Versions     Fixed
  ManageEngine DataSecurity Plus  unspecified  —
TIMELINE
  Aug 5   Reserved by CNA
  Sep 18  Published (CNA: Zohocorp)
CWE-89 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
marcopiovanello yt-dlp-web-ui generic.go NewGenericDownload command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0135   70.3     —
AFFECTED
  Product        Versions  Fixed
  yt-dlp-web-ui  v4 –      —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 18  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Zohocorp ManageEngine DataSecurity Plus — ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allow…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  L  N    7.5   .0106   63.1     —
AFFECTED
  Product                         Versions     Fixed
  ManageEngine DataSecurity Plus  unspecified  —
TIMELINE
  Aug 5   Reserved by CNA
  Sep 18  Published (CNA: Zohocorp)
CWE-20 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Printcart Web to Print Product Designer for WooCommerce <= 2.8.5 - Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0094   59.3     —
AFFECTED
  Product                                                          Versions     Fixed
  Printcart Store – Web to Print Product Designer for WooCommerce  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
ShortPixel Image Optimizer <= 6.5.5 - Authenticated (Author+) PHP Object Injection via Nested JSON Post Content
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0089   57.8     —
AFFECTED
  Product                                                            Versions     Fixed
  ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF  unspecified  —
TIMELINE
  Jul 24  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
jkohlbach Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers — Store Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0066   50.0     —
AFFECTED
  Product                                                                         Versions     Fixed
  Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers  unspecified  —
TIMELINE
  Jul 23  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Moxa TN-4500B Series — An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   H    8.8   .0065   49.8     —
AFFECTED
  Product          Versions  Fixed
  TN-4500B Series  1.0 –     2.1
TIMELINE
  Jul 13  Reserved by CNA
  Sep 18  Published (CNA: Moxa)
CWE-787 · CNA: Moxa · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Red Hat RESTEasy — Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0056   45.1     —
AFFECTED
  Product                                        Versions     Fixed
  RESTEasy                                       unspecified  —
  Red Hat build of Apache Camel 4 for Quarkus 3  unspecified  —
  Red Hat build of Apicurio Registry 3           unspecified  —
  Red Hat build of Debezium 3                    unspecified  —
  Red Hat Build of Keycloak                      unspecified  —
  Red Hat Build of Keycloak                      unspecified  —
  Red Hat build of Quarkus                       unspecified  —
  Red Hat Certificate System 10                  unspecified  —
  Red Hat Certificate System 11                  unspecified  —
  Red Hat Enterprise Linux 10                    unspecified  —
  + 13 more
TIMELINE
  Sep 10  Reserved by CNA
  Sep 18  Published (CNA: redhat)
CWE-409 · CNA: redhat · CVSS v3.1 · 4 references · NVD status: Awaiting Analysis
HGiga|OAKlouds - Insecure Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0052   43.1     —
AFFECTED
  Product                   Versions     Fixed
  OAKlouds-custom_page-2.0  unspecified  —
  OAKlouds-custom_page-3.0  unspecified  —
  OAKlouds-custom_page-4.0  unspecified  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 18  Published (CNA: twcert)
CWE-502 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Synology DiskStation Manager (DSM) — An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-690…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0050   42.2     —
AFFECTED
  Product                    Versions  Fixed
  DiskStation Manager (DSM)  7.4 –     —
TIMELINE
  Jun 29  Reserved by CNA
  Sep 18  Published (CNA: synology)
CWE-331 · CNA: synology · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
wclovers WCFM Marketplace – Multivendor Marketplace for WooCommerce — WCFM Marketplace <= 3.8.2 - Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0050   41.6     —
AFFECTED
  Product                                                     Versions     Fixed
  WCFM Marketplace – Multivendor Marketplace for WooCommerce  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
jegtheme Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress — Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0049   40.9     —
AFFECTED
  Product                                                                                   Versions     Fixed
  Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder — Popup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0047   40.1     —
AFFECTED
  Product                                                                                         Versions     Fixed
  Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
HGiga|OAKlouds - Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0046   39.2     —
AFFECTED
  Product                   Versions     Fixed
  OAKlouds-bulletin_v3-2.0  unspecified  —
  OAKlouds-bulletin_v3-3.0  unspecified  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 18  Published (CNA: twcert)
CWE-23 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Mapster WP Maps <= 1.23.0 - Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0046   38.9     —
AFFECTED
  Product          Versions     Fixed
  Mapster WP Maps  unspecified  —
TIMELINE
  Jun 22  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-20 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Synology DiskStation Manager (DSM) — An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) befo…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0046   38.8     —
AFFECTED
  Product                    Versions  Fixed
  DiskStation Manager (DSM)  7.4 –     —
TIMELINE
  Jun 29  Reserved by CNA
  Sep 18  Published (CNA: synology)
CWE-116 · CNA: synology · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Synology DiskStation Manager (DSM) — An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  L    6.5   .0043   37.2     —
AFFECTED
  Product                    Versions  Fixed
  DiskStation Manager (DSM)  7.3 –     —
TIMELINE
  Apr 14  Reserved by CNA
  Sep 18  Published (CNA: synology)
CWE-22 · CNA: synology · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder — Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_title
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0043   36.8     —
AFFECTED
  Product                                                                                         Versions     Fixed
  Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder  unspecified  —
TIMELINE
  Jul 14  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 11 references · NVD status: Deferred
Red Hat Exploit Intelligence — Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus http security
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0043   36.8     —
AFFECTED
  Product                                        Versions     Fixed
  Exploit Intelligence                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  OpenShift Serverless                           unspecified  —
  Red Hat build of Apache Camel 4 for Quarkus 3  unspecified  —
  + 11 more
TIMELINE
  Sep 9   Reserved by CNA
  Sep 18  Published (CNA: redhat)
CWE-551 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
10web Photo Gallery by 10Web – Mobile-Friendly Image Gallery — Photo Gallery by 10Web <= 1.8.44 - Authenticated (Author+) SQL Injection via 'album_id' Shortcode Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0041   35.0     —
AFFECTED
  Product                                                 Versions     Fixed
  Photo Gallery by 10Web – Mobile-Friendly Image Gallery  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
O-RAN-SC SMO OAM VES Collector allocation of resources
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0040   34.5     —
AFFECTED
  Product  Versions      Fixed
  SMO OAM  2025-06-10 –  —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 18  Published (CNA: VulDB)
CWE-400, CWE-770 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
webaways NEX-Forms – Ultimate Forms Plugin for WordPress — NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0038   31.5     —
AFFECTED
  Product                                          Versions     Fixed
  NEX-Forms – Ultimate Forms Plugin for WordPress  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
T-Systems TAO — Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   N   N   N    5.1   .0037   31.4     —
AFFECTED
  Product  Versions  Fixed
  TAO      2.0 –     —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 18  Published (CNA: INCIBE)
CWE-613 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
wpexpertsio WP Multi Store Locator Pro — WP Multi Store Locator Pro <= 4.5.1 - Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0037   31.3     —
AFFECTED
  Product                     Versions     Fixed
  WP Multi Store Locator Pro  unspecified  —
TIMELINE
  Jul 9   Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
wpdevelop Booking Calendar — Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0037   30.9     —
AFFECTED
  Product           Versions     Fixed
  Booking Calendar  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Sep 18  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-405364.330.8SynologyDiskStation Manager (DSM)CWE-22An improper limitation of a pathname to a restricted directory ('path travers…
CVE-2026-671009.829.0HCL SoftwareHCL BigFix Service ManagementCWE-89HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-405308.028.4SynologyDiskStation Manager (DSM)CWE-93An improper neutralization of CRLF sequences ('CRLF injection') vulnerability…
CVE-2026-176076.528.0chuck1982WP Inventory ManagerCWE-89WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection vi…
CVE-2026-40366.527.3SynologyDiskStation Manager (DSM)CWE-89An improper neutralization of special elements used in an SQL command ('SQL i…
CVE-2026-857057.527.2AyeCode LtdLocation ManagerCWE-89Location Manager <= 2.3.38 - Unauthenticated SQL Injection via 'latitude' and…
CVE-2026-127394.327.2saadiqbalWP Easy Pay – Payment and Donation Form Builder for SquareCWE-862WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A…
CVE-2026-933122.127.2FreedesktopPopplerCWE-404Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference
CVE-2026-405314.326.7SynologyDiskStation Manager (DSM)CWE-190An integer overflow or wraparound vulnerability in File Operation in Synology…
CVE-2026-890587.426.6Red HatRESTEasy—Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credential…
CVE-2026-134714.326.4latepointAppointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressCWE-639LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference…
CVE-2026-799548.725.5NASACryptoLibCWE-306NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the…
CVE-2026-405326.525.3SynologyDiskStation Manager (DSM)CWE-425A direct request ('forced browsing') vulnerability in Wallpaper Path in Synol…
CVE-2026-933112.125.1FreedesktopPopplerCWE-189Freedesktop Poppler SampledFunction Function.cc integer overflow
CVE-2026-62058.124.9SynologyDiskStation Manager (DSM)CWE-73An external control of file name or path vulnerability in Upload API in Synol…
CVE-2026-750174.324.7wpblockartMagazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post GridCWE-862Magazine Blocks <= 1.8.6 - Missing Authorization to Authenticated (Contributo…
CVE-2026-933316.924.5n/aGPACCWE-119GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds
CVE-2026-854108.124.4pixarlabsMaster Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template KitsCWE-862Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated…
CVE-2026-123848.823.9TECHIN2BTECHIN2B ApplicationCWE-639Broken Access Control in TECHIN2B Application
CVE-2026-175866.423.6kurudriveVK All in One Expansion UnitCWE-79VK All in One Expansion Unit <= 9.118.0 - Authenticated (Author+) Stored Cros…
CVE-2026-136738.823.5SynologyDiskStation Manager (DSM)CWE-732An incorrect permission assignment for critical resource vulnerability in LDA…
CVE-2026-405335.322.2SynologyDiskStation Manager (DSM)CWE-202An exposure of sensitive information through data queries vulnerability in De…
CVE-2026-835617.222.1complianzComplianz GDPR/CCPA Cookie Consent BannerCWE-79Complianz GDPR/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored C…
CVE-2026-894138.121.9farazfrankFilter GalleryCWE-862Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-929915.421.6bdthemesLive Copy Paste for Elementor – Cross Domain Copy Paste & Page DuplicatorCWE-79Biggopti Library (Various Versions) - Cross-Site Scripting via display_id fro…
CVE-2026-889946.620.8UnknownAll Bootstrap BlocksCWE-98All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block …
CVE-2026-175766.520.1revmakxInfiniteWP ClientCWE-89InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_g…
CVE-2026-909816.120.0satolloNewsletter – Send awesome emails from WordPressCWE-79Newsletter <= 9.3.8 - Reflected Cross-Site Scripting via 'nn' Parameter
CVE-2026-671028.119.9HCL SoftwareHCL BigFix Service ManagementCWE-285HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-909775.319.9UnknownClean LoginCWE-697Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison
CVE-2026-671019.319.3HCL SoftwareHCL BigFix Service ManagementCWE-918HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-136355.318.8SynologyDiskStation Manager (DSM)CWE-116An improper encoding or escaping of output vulnerability in Auth API in Synol…
CVE-2026-922496.118.7qodeinteractiveQi Addons For ElementorCWE-79Qi Addons For Elementor <= 1.11 - Reflected DOM-Based Cross-Site Scripting vi…
CVE-2026-925546.118.7devitemsllcShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCWE-79ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Paramet…
CVE-2026-917075.318.6Elegant ThemesDiviCWE-862Divi <= 5.11.1 - Missing Authorization to Unauthenticated Arbitrary Registere…
CVE-2026-144726.418.2extendthemesKubio AI Page BuilderCWE-79Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Si…
CVE-2026-934557.117.8batistedjango-page-cmsCWE-862django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account
CVE-2026-892785.317.5john-dagelmoreGPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AICWE-200GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Pub…
CVE-2026-565926.517.3HCL SoftwareHCL BigFix Service ManagementCWE-307HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-405374.317.3SynologyDiskStation Manager (DSM)CWE-918A server-side request forgery (SSRF) vulnerability in PersonMail API in Synol…
CVE-2026-867965.316.9UnknownHide My WP GhostCWE-693WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detecti…
CVE-2026-868005.316.9UnknownHide My WP GhostCWE-693WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via …
CVE-2026-136832.716.7SynologyDiskStation Manager (DSM)CWE-89An improper neutralization of special elements used in an SQL command ('SQL I…
CVE-2026-405383.716.6SynologyDiskStation Manager (DSM)CWE-307An improper restriction of excessive authentication attempts vulnerability in…
CVE-2026-121066.416.5airaniAuto Upload ImagesCWE-918Auto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Reques…
CVE-2026-933132.116.4FreedesktopPopplerCWE-189Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow
CVE-2026-933142.116.4FreedesktopPopplerCWE-189Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow
CVE-2024-386394.816.1QNAP Systems Inc.QTSCWE-287QTS
CVE-2026-926226.415.8wpchillStrong TestimonialsCWE-79Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site…
CVE-2026-150045.415.8ninjateamFileBird – WordPress Media Library Folders & File ManagerCWE-79FileBird – WordPress Media Library Folders & File Manager <= 6.5.6 - Authenti…
CVE-2026-771696.515.7NextcloudTeam FoldersCWE-284A vulnerability in the team folders (formerly group folders) app when used in…
CVE-2026-927146.515.2codename065Download ManagerCWE-639Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticate…
CVE-2026-849096.414.7smubCustom Twitter Feeds – A Tweets Widget or X Feed WidgetCWE-79Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Sit…
CVE-2026-925616.114.2wpdevelopBooking CalendarCWE-79Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Par…
CVE-2026-891384.313.7farazfrankFilter GalleryCWE-862Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+…
CVE-2026-847389.113.3UnknownAF CompanionCWE-94AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE
CVE-2026-671037.613.3HCL SoftwareHCL BigFix Service ManagementCWE-79HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-908845.412.9brechtvdsWP Recipe MakerCWE-79WP Recipe Maker <= 10.8.1 - Authenticated (Contributor+) Stored Cross-Site Sc…
CVE-2026-909765.312.9UnknownClean LoginCWE-284Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled
CVE-2026-797136.512.0UnknownBreeze CacheCWE-444Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tra…
CVE-2026-183174.312.0foxthemeFoxtool All-in-One: Contact chat button, Custom login, Media optimize imagesCWE-862Foxtool All-in-One: Contact chat button, Custom login, Media optimize images …
CVE-2026-156506.411.8themewantRT Mega Menu – Mega Menu Builder for Elementor & GutenbergCWE-79RT Mega Menu <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Script…
CVE-2026-893306.111.7wpdevteamEmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documentsCWE-79EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' …
CVE-2026-218226.311.6HCL SoftwareHCL AppScan 360°CWE-22A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2…
CVE-2026-829806.311.3NextcloudFiles LockCWE-287Any authenticated user can lock or unlock files they do not own by targeting …
CVE-2026-934947.510.7Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-1035Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when …
CVE-2026-405345.410.8SynologyDiskStation Manager (DSM)CWE-79An improper neutralization of input during web page generation ('cross-site s…
CVE-2026-829856.510.4NextcloudServerCWE-284The Photos app's filter-based "smart albums" build their file listing using t…
CVE-2026-148556.410.3themewantRT Mega Menu – Mega Menu Builder for Elementor & GutenbergCWE-79RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripti…
CVE-2026-750166.410.3wpblockartMagazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post GridCWE-79Magazine Blocks <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scr…
CVE-2026-218485.09.7HCL SoftwareHCL BigFix Service ManagementCWE-284HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2025-135334.49.6wipeoutmediaCSS & JavaScript ToolboxCWE-79CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Administrator+) Stored Cr…
CVE-2026-136234.89.3SynologyDiskStation Manager (DSM)CWE-79An improper neutralization of input during web page generation ('Cross-site S…
CVE-2026-136663.59.3SynologyDiskStation Manager (DSM)CWE-93An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability…
CVE-2026-877678.68.9Unknownwp shortcut link and advertisement banerCWE-89WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url
CVE-2026-877708.68.9UnknownPrice Drop Alert for Woo CommerceCWE-89Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via p…
CVE-2026-877718.68.9UnknownProduct Question and AnswerCWE-89Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id…
CVE-2026-877748.68.9UnknownTz Weekly Radio ScheduleCWE-89Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week
CVE-2026-877758.68.9UnknownTz Weekly Radio ScheduleCWE-89Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell
CVE-2026-829824.38.5NextcloudApprovalCWE-840The Approval app's approve/reject endpoint is meant to require the file's cur…
CVE-2026-851228.88.1UnknownEasy Form Builder by WhiteStudioCWE-79Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Co…
CVE-2026-117576.18.0KA Informatics Technologies Ltd. Co.Bar Association WebsiteCWE-79Reflected XSS in KA Informatics' Bar Association Website
CVE-2026-888258.87.0UnknowniGMS Direct BookingCWE-79iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings
CVE-2026-75157await7.0Apache Software FoundationApache AirflowCWE-863Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instea…
CVE-2026-851278.86.7UnknownVikBooking Hotel Booking Engine & PMSCWE-79VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment
CVE-2026-565906.46.8HCL SoftwareHCL BigFix Service ManagementCWE-434HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-849026.86.0UnknownKing Addons for ElementorCWE-79King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Ca…
CVE-2026-934857.15.7AutomatticWordPressCWE-79WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability
CVE-2026-565973.15.5HCL SoftwareHCL BigFix Service ManagementCWE-200HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-771704.34.8NextcloudDeckCWE-284The Deck config API allows authenticated users to set board-scoped configurat…
CVE-2026-889936.84.8UnknownAll Bootstrap BlocksCWE-79All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button typ…
CVE-2026-934568.44.7batistedjango-page-cmsCWE-352django-page-cms through 2.0.13 CSRF via admin mutation views
CVE-2026-934935.94.6Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-299Io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when…
CVE-2026-849032.74.5UnknownKing Addons for ElementorCWE-200King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Discl…
CVE-2026-565953.14.4HCL SoftwareHCL BigFix Service ManagementCWE-942HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-850096.54.3UnknownRestroPressCWE-639RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modif…
CVE-2026-851235.34.3UnknownEasy Form Builder by WhiteStudioCWE-284Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass …
CVE-2026-853505.34.3UnknownUpsellWPCWE-287UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought …
CVE-2026-879665.34.3UnknownEasy AppointmentsCWE-639Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modif…
CVE-2026-879654.84.3UnknownEasy AppointmentsCWE-284Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confir…
CVE-2026-887985.34.2UnknownReally Simple SecurityCWE-400Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Grow…
CVE-2026-818107.23.9UnknownAll-in-One WP Migration and BackupCWE-269All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalati…
CVE-2026-813403.83.9UnknownMasterStudy LMS WordPress PluginCWE-639MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR
CVE-2026-849043.83.9UnknownKing Addons for ElementorCWE-862King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization v…
CVE-2026-684933.13.7NextcloudServerCWE-639After guessing a 62^15 complex unique identifier, a malicious logged in user …
CVE-2026-890082.73.7UnknownBookit — Booking & Appointment CalendarCWE-200Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure
CVE-2026-909845.83.4UnknownGenerate PDF using Contact Form 7CWE-918Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Reque…
CVE-2026-909787.13.2UnknownFilter GalleryCWE-284Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Opti…
CVE-2026-888442.73.2UnknownMasterStudy LMS WordPress PluginCWE-639MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR
CVE-2026-890072.73.2UnknownBookit — Booking & Appointment CalendarCWE-862Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing A…
CVE-2024-271235.23.0QNAP Systems Inc.QcalAgentCWE-79QcalAgent
CVE-2026-771646.22.7NextcloudServerCWE-918Circles' remote-instance signature verification fetches the attacker-supplied…
CVE-2026-405397.10.1SynologyDiskStation Manager (DSM)CWE-295An improper certificate validation vulnerability in Email API in Synology Dis…
CVE-2025-1539910.0—IBMCommon LicensingCWE-352Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-1074710.0—IBMMQ ApplianceCWE-122IBM MQ Appliance is affected by a heap buffer overflow vulnerability in proto…
CVE-2026-9360310.0—patriksimekvm2CWE-94vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function
CVE-2026-9360510.0—patriksimekvm2CWE-693vm2 NodeVM before 3.12.1 Remote Code Execution via child_process
CVE-2026-9360610.0—patriksimekvm2CWE-693vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species
CVE-2025-538379.9—xwikixwiki-renderingCWE-95org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
CVE-2026-108589.9—IBMMQ for HPE NonStopCWE-122IBM MQ for HPE NonStop is vulnerable to a denial of service attack
CVE-2026-616829.9—kcp-devkcpCWE-290kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing …
CVE-2026-617819.9—pgpartmanpg_partmanCWE-89pg_partman has privilege escalation through SQL injection in create_partition…
CVE-2026-772409.9—ArnasDonwacrmCWE-639WACRM: Database-layer authorization bypasses
CVE-2026-804429.9—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840649.9—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840759.9—IBMGuardium Data ProtectionCWE-306IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840789.9—IBMGuardium Data ProtectionCWE-306IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2025-664559.8—InternLMlmdeployCWE-502LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_r…
CVE-2026-582649.8—FluidSynthfluidsynthCWE-122FluidSynth: Heap-based buffer overrun
CVE-2026-615509.8—Icingaicinga2CWE-862Icinga 2: Improper access control for JSON-RPC update certificate messages
CVE-2026-750319.8—InterchangeInterchangeCWE-94In the interchange/interchange project, a critical remote code execution (RCE…
CVE-2026-804419.8—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-816579.8—IBMGuardium Data ProtectionCWE-502IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-823409.8—IBMGuardium Data ProtectionCWE-94IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-829679.8—IBMGuardium Data ProtectionCWE-306IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840829.8—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-843839.8—strukturaglibheifCWE-787libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alp…
CVE-2026-828329.6—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-281979.4—CohesityNetBackup Flex OSCWE-88Privilege Escalation via Argument Injection in NetBackup Flex OS Shell
CVE-2026-281989.4—CohesityNetBackup Flex OSCWE-347Privilege Escalation via Cryptographic Signature Verification Bypass in NetBa…
CVE-2023-543999.3—Hongjinge-HRCWE-89Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree
CVE-2026-636479.3—1Panel-devCordysCRMCWE-306CordysCRM SSE Notification Stream Hijack via `/sse/subscribe`
CVE-2026-758859.3—Red HatRed Hat OpenShift Container Platform 4CWE-918Openshift/console: openshift/console: unauthenticated ssrf and resource exhau…
CVE-2026-813219.3—CareCamHMT.CM2507 FirmwareCWE-312CareCam CM2507 Cleartext Storage of Sensitive Information
CVE-2026-854979.3—CareCamHMT.CM2507 FirmwareCWE-916CareCam CM2507 Use of Password Hash With Insufficient Computational Effort
CVE-2026-936599.3—concretecms-community-storecommunity_storeCWE-79Concrete CMS Community Store before 2.7.8 Stored XSS
CVE-2026-937409.3—TotolinkA3002MUCWE-119Totolink A3002MU formWlEncrypt buffer overflow
CVE-2026-938399.3—ModelTCLightLLMCWE-306LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSo…
CVE-2023-57789.2—ABBFreelance Controller DCPCWE-130Missing Length Check
CVE-2026-937629.2—MongoDB Inc.MongoidCWE-470Data deletion and attribute disclosure via field-name method injection in in-…
CVE-2026-938689.2—CotontiCotontiCWE-338Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG
CVE-2026-591639.1—AxDSanmnemosyneCWE-347Mnemosyne has JWT signature verification bypass sync server that allows authe…
CVE-2026-758789.1—IBMSterling File GatewayCWE-287IBM Sterling File Gateway is Vulnerable to Authentication Bypass
CVE-2026-840739.1—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-927019.1—ultravioletrscocosCWE-346Cocos AI: Intra-handshake attested TLS implementation is vulnerable to sessio…
CVE-2026-927029.1—ultravioletrscocosCWE-346Cocos AI: Intra-handshake attested TLS implementation can accept Evidence wit…
CVE-2026-930199.1——ImagerCWE-196Imager versions before 1.036 for Perl exit the process reading a TGA with a c…
CVE-2026-840319.0—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840708.9—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840748.9—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-841068.9—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2025-147548.8—IBMCloud Pak for DataCWE-78IBM Cloud Pak for Data is vulnerable to OS command injection
CVE-2026-105758.8—IBMMQCWE-122IBM MQ queue manager is vulnerable to remote code execution
CVE-2026-113758.8—IBMMQCWE-122IBM MQ queue manager is vulnerable to remote code execution
CVE-2026-113788.8—IBMMQCWE-190IBM MQ queue manager is vulnerable to remote code execution
CVE-2026-113818.8—IBMMQ for HPE NonStopCWE-122IBM MQ for HPE NonStop is vulnerable to a denial of service issue
CVE-2026-117258.8—IBMMQCWE-190IBM MQ queue manager is vulnerable to privilege escalation
CVE-2026-336258.8—InternLMlmdeployCWE-400LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant…
CVE-2026-581978.8—stackloktoolhiveCWE-284ToolHive: containerized MCP servers can reach host services via host.docker.i…
CVE-2026-811808.8—SyslifterssysreptorCWE-20SysReptor: Authenticated RCE by insecure image processing
CVE-2026-816568.8—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-819338.8—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-828858.8—IBMGuardium Data ProtectionCWE-862IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-828878.8—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840348.8—IBMGuardium Data ProtectionCWE-798IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840848.8—IBMGuardium Data ProtectionCWE-352IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-886228.8—n/an/aCWE-77NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handl…
CVE-2026-930318.8—WP Cloud Plugins/_deleeuw_Use-your-Drive | Google Drive plugin for WordPressCWE-434WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Bo…
CVE-2026-937598.8—MongoDB Inc.MongoidCWE-94Server-side JavaScript injection via string query criteria bypassing the stri…
CVE-2017-202848.7—Caucho Technology, Inc.ResinCWE-22Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet
CVE-2019-257768.7—Weaver Network Co., Ltd.E-cologyCWE-89Weaver E-cology SQL Injection via SyncUserInfo.jsp
CVE-2021-480088.7—Chanjet Information Technology Co., Ltd.CRMCWE-89Chanjet CRM SQL Injection via get_usedspace.php
CVE-2026-629438.7—digintbtrbkCWE-78btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh
CVE-2026-689148.7—mojoliciousmojoCWE-400Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply …
CVE-2026-779298.7—MacWarriorclipbucket-v5CWE-434ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint
CVE-2026-819428.7—PLANET Technology Corp.PLANET IGS-5225-8P2T4S V1CWE-78PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server
CVE-2026-843988.7—CareCamHMT.CM2507 FirmwareCWE-258CareCam CM2507 Empty Password in Configuration File
CVE-2026-865208.7—BransysELDCWE-798Use of Hard-coded Credentials in Bransys ELD
CVE-2026-882598.7—CareCamHMT.CM2507 FirmwareCWE-306CareCam CM2507 Missing Authentication for Critical Function
CVE-2026-935928.7—vllm-projectvllmCWE-129vLLM before 0.28.0 Denial of Service via negative token ID
CVE-2026-935998.7—rustlswebpkiCWE-191rustls-webpki before 0.103.13 Panic via empty BIT STRING
CVE-2026-936578.7—hickory-dnshickory-resolverCWE-347hickory-resolver before 0.26.2 DNSSEC Validation Bypass
CVE-2026-936878.7—micromatchbracesCWE-674braces through 3.0.3 Stack Overflow via Deeply Nested Patterns
CVE-2026-936888.7—sgl-projectsglangCWE-770SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room
CVE-2026-936908.7—garycourturi-jsCWE-835uri-js through 4.4.1 Denial of Service via removeDotSegments
CVE-2026-937488.7—kornelskihttp-cache-semanticsCWE-524http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale
CVE-2026-937498.7—7rulniksource-map-jsCWE-1284source-map-js through 1.2.1 Event Loop Denial of Service
CVE-2026-937528.7—NVCSSOMCWE-915CSSOM through 0.5.0 Denial of Service via length Property
CVE-2026-937538.7—TehShrikedeepmergeCWE-1321deepmerge through 4.3.1 Prototype Poisoning via mergeObject
CVE-2026-937618.7—MongoDB Inc.MongoidCWE-1333Denial of service via unbounded regex matching in Mongoid's in-memory query m…
CVE-2025-616828.6—SemanticMediaWikiSemanticMediaWikiCWE-79Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use…
CVE-2026-176198.6—IBMspectrum-lsf : IBM Platform RTMCWE-89The IBM Platform RTM is affected by an SQL injection vulnerability
CVE-2026-615518.6—Icingaicinga2CWE-674Icinga 2: Stack overflow via deeply nested JSON objects
CVE-2026-689288.6—Acode-FoundationAcodeCWE-749Acode: Exported TerminalService (bundled terminal plugin) lets any installed …
CVE-2026-816268.6—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-935938.6—ArcadeDataarcadedbCWE-863ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission
CVE-2026-937388.6—TotolinkA3002MUCWE-119Totolink A3002MU formSchedule buffer overflow
CVE-2026-937398.6—TotolinkA3002MUCWE-119Totolink A3002MU formWlAc buffer overflow
CVE-2026-937588.6—MongoDB Inc.MongoidCWE-639Cross-principal document update, theft, and deletion via unvalidated id in ne…
CVE-2026-939228.6—siyuan-notesiyuanCWE-79SiYuan through 3.8.4 Stored XSS via notebook names
CVE-2026-939238.6—siyuan-notesiyuanCWE-79SiYuan through 3.8.4 Stored XSS via Heading Style Attribute
CVE-2026-618178.5—pgpartmanpg_partmanCWE-89pg_partman privilege escalation via SQL injection in several functions via ti…
CVE-2026-618188.5—pgpartmanpg_partmanCWE-89pg_partman SQL injection in undo partition time encoder
CVE-2026-618198.5—pgpartmanpg_partmanCWE-89pg_partman privilege escalation via SQL injection in when using pg_jobmon and…
CVE-2026-618208.5—pgpartmanpg_partmanCWE-89pg_partman privilege escalation via SQL injection when inheriting template pr…
CVE-2026-618218.5—pgpartmanpg_partmanCWE-862pg_partman authorization bypass to move child tables between schemas during r…
CVE-2026-819438.4—PLANET Technology Corp.PLANET IGS-5225-8P2T4S V1CWE-489PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCE
CVE-2026-631998.3—persespersesCWE-862Perses: Missing authorization in datasource proxy allows cross-scope secret d…
CVE-2026-636388.3—AcademySoftwareFoundationOpenImageIOCWE-787OpenImageIO: Cineon invalid bit depth heap out-of-bounds write
CVE-2026-937608.3—MongoDB Inc.MongoidCWE-943NoSQL injection of JavaScript-executing query operators via unsafe-by-default…
CVE-2026-937658.3—MongoDB Inc.MongoidCWE-470Document deletion and process crash via unvalidated method-name dispatch in a…
CVE-2026-555568.2—rsyslogrsyslogCWE-122Rsyslog: Heap buffer overflow in imhttp plugin Basic Authentication handling
CVE-2026-572288.2—OISFsuricataCWE-125Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder
CVE-2026-866898.2—BransysELDCWE-319Cleartext Transmission of Sensitive Information in Bransys ELD
CVE-2026-911278.2—flyfish-devfile-viewerCWE-79File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
CVE-2026-935698.2—Red HatRed Hat AMQ Broker 7CWE-444Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated …
CVE-2026-937508.2—kornelskihttp-cache-semanticsCWE-436http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wil…
CVE-2026-938388.2—sgl-projectsglangCWE-770SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx
CVE-2026-100278.1—IBMMQCWE-787IBM MQ queue manager is vulnerable to unauthenticated remote code execution
CVE-2026-117268.1—IBMMQ for HPE NonStopCWE-125IBM MQ for HPE NonStop is vulnerable to a denial of service issue
CVE-2026-117278.1—IBMMQ for HPE NonStopCWE-122IBM MQ for HPE NonStop is vulnerable to a denial of service issue
CVE-2026-541488.1—http4khttp4kCWE-294http4k: `DigestAuthProvider.verify` did not bind to request URI
CVE-2026-615488.1—rsyslogrsyslogCWE-121Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured…
CVE-2026-618338.1—project-zotzotCWE-285zot: Bearer authentication maps DELETE to push scope, allowing unauthorized d…
CVE-2026-622788.1—hargatalubelogCWE-22LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticate…
CVE-2026-772398.1—ArnasDonwacrmCWE-285WACRM: Service-role routes missing a role check
CVE-2026-811798.1—SyslifterssysreptorCWE-807SysReptor: Host header injection might allow account takeover
CVE-2026-828928.1—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840778.1—IBMGuardium Data ProtectionCWE-352IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840818.1—IBMGuardium Data ProtectionCWE-295IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840858.1—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-841088.1—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-842418.1—IBMGuardium Data ProtectionCWE-285IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-880978.1—MicrosoftMicrosoft Edge (Chromium-based)CWE-416Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-617218.0—FluidSynthfluidsynthCWE-122FluidSynth: Heap-based buffer overrun for DLS samples
CVE-2026-466557.8—virtio-winkvm-guest-drivers-windowsCWE-122virtio-win: Integer overflow causing a heap overflow in Viosock driver
CVE-2026-617147.8—FluidSynthfluidsynthCWE-122FluidSynth: Heap Buffer Overflow in MIDI Player
CVE-2026-634197.8—AcademySoftwareFoundationOpenImageIOCWE-787OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer
CVE-2026-634227.8—AcademySoftwareFoundationOpenImageIOCWE-122OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write
CVE-2026-828937.8—IBMGuardium Data ProtectionCWE-269IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840837.8—IBMGuardium Data ProtectionCWE-269IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840897.8—IBMGuardium Data ProtectionCWE-269IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-819447.7—PLANET Technology Corp.PLANET IGS-5225-8P2T4S V1CWE-121PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server
CVE-2026-841057.7—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-938727.7—CotontiCotontiCWE-502Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter
CVE-2026-675497.6—AcademySoftwareFoundationOpenImageIOCWE-122OpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds write
CVE-2026-828967.6—IBMGuardium Data ProtectionCWE-22IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840767.6—IBMGuardium Data ProtectionCWE-285IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-842397.6—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2025-147537.5—IBMCloud Pak for DataCWE-22IBM Cloud Pak for Data is vulnerable to path traversal
CVE-2026-107447.5—IBMMQ for HPE NonStopCWE-122IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation
CVE-2026-107517.5—IBMMQCWE-502IBM MQ Java messaging is vulnerable to remote code execution
CVE-2026-108537.5—IBMMQCWE-470IBM MQ queue manager is vulnerable to remote code execution
CVE-2026-117167.5—IBMMQ for HPE NonStopCWE-122IBM MQ for HPE NonStop is vulnerable to a denial of service attack
CVE-2026-326417.5—parseablehqparseableCWE-248Parseable: Unauthenticated Denial of Service via panic in Kinesis header pars…
CVE-2026-572277.5—OISFsuricataCWE-400Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel…
CVE-2026-634467.5—OISFsuricataCWE-401Suricata app-layer: passed flows can retain transactions, causing resource ex…
CVE-2026-634477.5—OISFsuricataCWE-407Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption
CVE-2026-634527.5—OISFsuricataCWE-400Suricata http1: repeated brotli compression bombs can cause excessive CPU con…
CVE-2026-691847.5—c-aresc-aresCWE-407c-ares: CPU-exhaustion denial of service via unbounded DNS name compression p…
CVE-2026-714187.5—OISFsuricataCWE-407Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption
CVE-2026-773017.5—cthackersadm-zipCWE-789adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
CVE-2026-819457.5—PLANET Technology Corp.PLANET IGS-5225-8P2T4S V1CWE-121PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server
CVE-2026-843847.5—strukturaglibheifCWE-409libheif: brotli/zlib decompression paths lack output-size limits, allowing de…
CVE-2026-844467.5—strukturaglibheifCWE-835libheif: Sequence decode timing-table initialization allows non-terminating l…
CVE-2026-844477.5—strukturaglibheifCWE-770libheif: Derived-image indirect reference chains and tiled offsets bypass dec…
CVE-2026-850587.5—moquette-iomoquetteCWE-862Moquette: Missing Authorization in io.moquette:moquette-broker
CVE-2026-911497.5—Red HatRed Hat Enterprise Linux 10CWE-770Cockpit: cockpit: denial of service via unbounded connection thread spawning
CVE-2026-927087.5—sveltejsdevalueCWE-200devalue: Cross-request process memory disclosure in devalue when `stringify` …
CVE-2026-934887.5—Red HatRed Hat AMQ Broker 7CWE-770Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent …
CVE-2026-934917.5—Red HatRed Hat AMQ Broker 7CWE-770Io.netty/netty-codec-http: netty: denial of service via unbounded httpserverc…
CVE-2026-935587.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in we…
CVE-2026-935607.5—Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-1035Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int tru…
CVE-2026-935637.5—Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-1035Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation …
CVE-2026-935647.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild b…
CVE-2026-935657.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trail…
CVE-2026-935677.5—Red HatRed Hat AMQ Broker 7CWE-20Io.netty/netty-codec-http2: http/1 authority-form connect is translated to ma…
CVE-2026-935687.5—Red HatRed Hat AMQ Broker 7CWE-20Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and htt…
CVE-2026-935727.5—Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-770Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers m…
CVE-2026-935757.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder
CVE-2026-935767.5—Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-93Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field i…
CVE-2026-936527.5—D3TN GmbHµD3TNCWE-190Integer Overflow or Wraparound in µD3TN
CVE-2026-840367.4—IBMGuardium Data ProtectionCWE-285IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-844447.4—strukturaglibheifCWE-787libheif uncompressed tiled image encoding allows out-of-bounds write
CVE-2026-849757.4—pjsippjprojectCWE-295PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in…
CVE-2026-936587.3—uutilscoreutilsCWE-281uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid
CVE-2026-615527.2—Icingaicinga2CWE-94Icinga 2 DSL Injection via Unescaped Import Template Name
CVE-2026-816697.2—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-819377.2—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840717.2—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-840867.2—IBMGuardium Data ProtectionCWE-22IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-935917.2—siyuan-notesiyuanCWE-89SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go
CVE-2026-938547.2—OpenStackBlazarCWE-1025In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-l…
CVE-2026-100307.1—IBMMQCWE-285IBM MQ Console is vulnerable to privilege escalation
CVE-2026-616727.1—projectcapsulecapsuleCWE-697Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node lab…
CVE-2026-622797.1—hargatalubelogCWE-639LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records fr…
CVE-2026-634457.1—persespersesCWE-22Perses: Unvalidated project parameter enables filesystem path traversal
CVE-2026-634587.1—persespersesCWE-639Perses project query parameter authorization bypass exposes cross-project res…
CVE-2026-779277.1—MacWarriorclipbucket-v5CWE-89ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint
CVE-2026-779287.1—MacWarriorclipbucket-v5CWE-89ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endp…
CVE-2026-815057.1—frain-devconvoyCWE-639Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
CVE-2026-935947.1—ArcadeDataarcadedbCWE-863ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries
CVE-2026-935957.1—ArcadeDataarcadedbCWE-862ArcadeDB before 26.9.1 ACL Bypass via query_database Tool
CVE-2026-935987.1—ArcadeDataarcadedbCWE-184ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle
CVE-2026-936607.1—dataeaseSQLBotCWE-639SQLBot through 1.10.1 Improper Access Control via Dashboard Update
CVE-2026-937377.1—azkabanazkabanCWE-862Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet
CVE-2026-937637.1—MongoDB Inc.MongoidCWE-312Silent plaintext persistence via unresolved callable database name in encrypt…
CVE-2026-937647.1—MongoDB Inc.MongoidCWE-312Plaintext storage of encrypted fields via skipped embedded models in encrypti…
CVE-2026-938527.1—OpenStackBlazarCWE-862In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/le…
CVE-2026-70067.0—Sublime HQ Pty LtdSublime Text 4CWE-494Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism
CVE-2026-572237.0—OISFsuricataCWE-428Suricata windows: unquoted LocalSystem service ImagePath can allow local priv…
CVE-2026-633497.0—agronholmanyioCWE-266AnyIO run_process/open_process ignores extra_groups and can retain parent sup…
CVE-2026-738637.0—nanomqnanomqCWE-125NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRI…
CVE-2026-813057.0—CareCamHMT.CM2507 FirmwareCWE-829CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-636466.9—1Panel-devCordysCRMCWE-200CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users
CVE-2026-773966.9—pjsippjprojectCWE-122PJSIP: Heap buffer overflow in the AVI parser
CVE-2026-779606.9—BransysELDCWE-798Use of Hard-coded Credentials in Bransys ELD
CVE-2026-933386.9—Grandstream NetworksGWN7660ELRCWE-1188Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Com…
CVE-2026-935596.9—Forget-CJellyfish AI Short Drama StudioCWE-287Forget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing auth…
CVE-2026-936046.9—patriksimekvm2CWE-284vm2 3.11.8 Sandbox Escape via crypto.setFips
CVE-2026-937516.9—garycourturi-jsCWE-176uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
CVE-2026-617226.8—FluidSynthfluidsynthCWE-190FluidSynth: DLS Articulation Chunk Integer Overflow
CVE-2026-617236.8—FluidSynthfluidsynthCWE-190FluidSynth: DLS ptbl Chunk Integer Overflow
CVE-2026-617946.8—projectcapsulecapsuleCWE-20Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation an…
CVE-2026-617956.8—projectcapsulecapsuleCWE-697Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, al…
CVE-2026-648476.8—agronholmanyioCWE-770AnyIO process-pool workers can block indefinitely on undrained stderr
CVE-2026-758836.8—PPP ProjectpppCWE-122PPPD buffer overflow in PEAP response code
CVE-2026-769006.8—1Panel-devCordysCRMCWE-918CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Valid…
CVE-2026-778756.8—QUANTUMTECH LTDHide Photos - Secure vaultCWE-922Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet…
CVE-2026-936896.8—winfspwinfspCWE-476WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O
CVE-2026-816276.7—Red HatRed Hat Enterprise Linux 10CWE-787Qemu-kvm: vapic writable rom alias can escape the option-rom window and expos…
CVE-2026-819466.7—PLANET Technology Corp.PLANET IGS-5225-8P2T4S V1CWE-121PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm
CVE-2025-331416.5—IBMQRadarCWE-497IBM QRadar SIEM could allow an authenticated user to obtain sensitive informa…
CVE-2026-115496.5—IBMCICS TX AdvancedCWE-284Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh…
CVE-2026-117106.5—IBMWebSphere Application ServerCWE-444IBM WebSphere Application Server is affected by an HTTP request smuggling vul…
CVE-2026-117116.5—IBMWebSphere Application ServerCWE-502IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-541476.5—http4khttp4kCWE-327http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not …
CVE-2026-572246.5—OISFsuricataCWE-400Suricata dhcp: unbounded transactions in unidirectional traffic can lead to r…
CVE-2026-591566.5—AcademySoftwareFoundationOpenImageIOCWE-674OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow
CVE-2026-616706.5—superradcompanymicrosandboxCWE-214microsandbox: Secret values exposed in world-readable process arguments
CVE-2026-618226.5—pgpartmanpg_partmanCWE-703pg_partman disable maintenance for all partition sets
CVE-2026-622826.5—opencveopencveCWE-918OpenCVE: Server-Side Request Forgery (SSRF) in notifications
CVE-2026-715376.5—PaymenterPaymenterCWE-362Paymenter: Credit-refund double-spend race condition in service downgrade (do…
CVE-2026-773866.5—zoriyaKyooCWE-601Kyoo: OIDC login token can be redirected to an attacker-controlled URL
CVE-2026-844516.5—strukturaglibheifCWE-125libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an ou…
CVE-2026-935616.5—Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-1035Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned t…
CVE-2026-935626.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer…
CVE-2026-935666.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-http: netty: http request smuggling due to control chara…
CVE-2026-935736.5—Red HatRed Hat AMQ Broker 7CWE-444Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-…
CVE-2026-935746.5—Red HatRed Hat AMQ Broker 7CWE-444Io.netty/netty-codec-http: netty: http request smuggling via post-digit white…
CVE-2026-935796.5—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-http2: netty: http/2 header field values are not validat…
CVE-2026-188696.4—IBMiCWE-918IBM i is Affected By Denial of Service and Security Restriction Bypass Vulner…
CVE-2026-816236.3—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-935896.3—ImageMagickImageMagickCWE-369ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder
CVE-2026-935906.3—ImageMagickImageMagickCWE-400ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder
CVE-2026-938406.3—vllm-projectvllmCWE-129vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids
CVE-2026-938416.3—vllm-projectvllmCWE-129vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated…
CVE-2026-617206.2—FluidSynthfluidsynthCWE-191FluidSynth: SF2 DMOD Chunk Unsigned Underflow
CVE-2025-361476.1—IBMFinancial Transaction Manager for SWIFT Services for MultiplatformsCWE-79IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vu…
CVE-2026-10256.1—IBMCommon LicensingCWE-79Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-10316.1—IBMCommon LicensingCWE-79Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-10376.1—IBMCommon LicensingCWE-79Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-591816.1—AcademySoftwareFoundationOpenImageIOCWE-121OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked…
CVE-2026-599566.1—AcademySoftwareFoundationOpenImageIOCWE-125OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is…
CVE-2026-776066.1—SemanticMediaWikiSemanticMediaWikiCWE-79Semantic MediaWiki has reflected XSS in Special:Ask plain table headers

Results continue: ranks 401–514.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-18 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.