AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N N 7.7 .0150 73.1 —
AFFECTED Product Versions Fixed ManageEngine DataSecurity Plus unspecified —
TIMELINE Aug 5 Reserved by CNA Sep 18 Published (CNA: Zohocorp)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 3 to KEV; 514 CVEs published, led by IBM (90).
514 CVEs published September 18, 2026: 51 critical, 207 high, 207 medium, 42 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 7 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 114 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 10335 | 45276 | — | — |
| KEV catalog size | 1716 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2812 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1507 | 5597 | 526 | 2513 | 712 | 1 | 15 | 6 | 0.1 | 7.8 | .0017 | +245 ▲ |
| microsoft | 1000 | 2899 | 204 | 1984 | 695 | 16 | 289 | 30 | 1.0 | 7.8 | .0044 | +556 ▲ |
| 516 | 2682 | 331 | 1048 | 1182 | 121 | 80 | 9 | 0.3 | 7.5 | .0025 | +452 ▲ | |
| red hat | 153 | 779 | 44 | 324 | 371 | 40 | 2 | 0 | 0.0 | 6.6 | .0028 | -8 ▼ |
| apple | 246 | 563 | 67 | 165 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0020 | +212 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | -11 ▼ |
| suse | 13 | 41 | 7 | 21 | 12 | 1 | 0 | 0 | 0.0 | 7.5 | .0036 | +8 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0039 | +66 ▲ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 10 | 40 | 10 | 10 | 17 | 3 | 29 | 7 | 17.5 | 7.0 | .0038 | +3 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0025 | -7 ▼ |
| f5 | 8 | 25 | 6 | 14 | 4 | 1 | 4 | 1 | 4.0 | 8.7 | .0045 | +8 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0146 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 93 | 605 | 140 | 253 | 195 | 15 | 33 | 2 | 0.3 | 7.5 | .0048 | -8 ▼ |
| mozilla | 113 | 300 | 80 | 103 | 64 | 0 | 9 | 0 | 0.0 | 8.8 | .0026 | +54 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0024 | +26 ▲ |
| gitlab | 17 | 93 | 5 | 23 | 55 | 10 | 5 | 3 | 3.2 | 5.3 | .0032 | +2 ▲ |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | -2 ▼ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0016 | +1 ▲ |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -2 ▼ |
| go | 4 | 4 | 0 | 2 | 1 | 1 | 0 | 0 | 0.0 | 5.9 | .0029 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0034 | -255 ▼ |
| ibm | 297 | 916 | 183 | 414 | 303 | 13 | 6 | 1 | 0.1 | 7.5 | .0029 | +105 ▲ |
| adobe | 171 | 777 | 57 | 344 | 366 | 10 | 20 | 4 | 0.5 | 7.5 | .0023 | +111 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0035 | -16 ▼ |
| solarwinds | 1 | 24 | 17 | 4 | 3 | 0 | 10 | 4 | 16.7 | 9.1 | .0058 | +1 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | -10 ▼ |
| zohocorp | 7 | 17 | 3 | 8 | 6 | 0 | 0 | 0 | 0.0 | 7.7 | .0106 | +3 ▲ |
| atlassian | 3 | 9 | 1 | 8 | 0 | 0 | 13 | 0 | 0.0 | 7.6 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 21 | 66 | 19 | 24 | 11 | 12 | 3 | 0 | 0.0 | 8.5 | .0154 | +5 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0018 | -4 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0027 | +18 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +18 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0068 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0040 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0036 | +3 ▲ |
| abb | 1 | 8 | 1 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 177 | 348 | 26 | 166 | 133 | 23 | 2 | 1 | 0.3 | 7.2 | .0021 | +144 ▲ |
| sourcecodester | 48 | 217 | 0 | 0 | 128 | 89 | 0 | 0 | 0.0 | 5.5 | .0028 | +21 ▲ |
| spring | 0 | 170 | 13 | 60 | 82 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | 0 |
| nvidia | 32 | 166 | 20 | 117 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +8 ▲ |
| mongodb | 64 | 162 | 6 | 94 | 58 | 4 | 1 | 0 | 0.0 | 7.1 | .0026 | +32 ▲ |
| itsourcecode | 34 | 150 | 0 | 0 | 37 | 113 | 0 | 0 | 0.0 | 2.1 | .0026 | +17 ▲ |
| wwbn | 106 | 146 | 23 | 49 | 74 | 0 | 0 | 0 | 0.0 | 6.9 | .0024 | +104 ▲ |
| hewlett packard enterprise (hpe) | 129 | 138 | 15 | 71 | 46 | 6 | 1 | 1 | 0.7 | 7.2 | .0029 | +126 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-85706 | .1456 | 96.5 | 10.0 |
| CVE-2026-83549 | .0851 | 94.8 | 7.8 |
| CVE-2026-82329 | .0767 | 94.3 | 9.8 |
| CVE-2026-19586 | .0570 | 92.7 | 9.3 |
| CVE-2026-79756 | .0515 | 92.0 | 8.7 |
| CVE-2026-83548 | .0467 | 91.3 | 10.0 |
| CVE-2026-77806 | .0420 | 90.5 | 9.8 |
| CVE-2026-76698 | .0411 | 90.3 | 6.5 |
| CVE-2026-47864 | .0408 | 90.2 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .1456 | KEV |
| CVE-2026-83548 | 10.0 | .0467 | KEV |
| CVE-2026-75650 | 10.0 | .0215 | KEV |
| CVE-2026-86152 | 10.0 | .0186 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-69836 | 10.0 | .0155 | |
| CVE-2026-82222 | 10.0 | .0155 | |
| CVE-2026-82004 | 10.0 | .0144 | |
| CVE-2026-87827 | 10.0 | .0107 |
| Vendor | CVEs |
|---|---|
| linux | 1889 |
| microsoft | 1031 |
| 854 | |
| oracle | 635 |
| ibm | 388 |
| apple | 256 |
| adobe | 212 |
| red hat | 209 |
| dell | 193 |
| apache | 160 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| ivanti | 5 |
| adobe | 4 |
| berriai | 4 |
| jfrog | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 93 |
| Packagist | 41 |
| npm | 20 |
| PyPI | 17 |
| crates.io | 3 |
| Go | 2 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-72529 | TrueConf | 0 |
| CVE-2026-72530 | TrueConf | 0 |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1766 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1766 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1766 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1766 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1766 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1766 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1766 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1766 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1766 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1766 |
ADDED TO KEV — CVE-2025-39682 (Linux). Remediation due September 21, 2026.
ADDED TO KEV — CVE-2025-39964 (Linux). Remediation due September 21, 2026.
ADDED TO KEV — CVE-2026-53266 (Linux). Remediation due September 21, 2026.
EXPLOIT PUBLISHED — open-webui: 11 CVEs (CVE-2026-70479, CVE-2026-70480, CVE-2026-70481, CVE-2026-70482, CVE-2026-70483, CVE-2026-70485, CVE-2026-70486, CVE-2026-70489, CVE-2026-70491, CVE-2026-70492, CVE-2026-70493). Public exploit references added.
EXPLOIT PUBLISHED — netty: 6 CVEs (CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42587, CVE-2026-89044). Public exploit references added.
EXPLOIT PUBLISHED — wazuh: 6 CVEs (CVE-2026-41424, CVE-2026-44252, CVE-2026-44254, CVE-2026-44255, CVE-2026-44256, CVE-2026-46343). Public exploit references added.
EXPLOIT PUBLISHED — GNU Binutils: 4 CVEs (CVE-2026-90801, CVE-2026-90802, CVE-2026-90803, CVE-2026-90804). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2025-6021 (libxml2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66046 (libexpat project libexpat). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86176 (netbox-community netbox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86426 (librenms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86427 (librenms). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86739 (grokability snipe-it). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86744 (grokability snipe-it). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87819 (gitpython-developers GitPython). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-87928 (MaxSite CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-89034 (TCH QRing). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90489 (Xuxueli xxl-job). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91732 (Google Chrome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91995 (pig-mesh pig). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92381 (PbootCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92399 (GPAC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92413 (Artifex MuPDF). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92458 (guchengwuyue yshop-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92463 (guchengwuyue yshop-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92468 (zlt2000 microservices-platform). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92473 (GPAC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92776 (requarks Wiki.js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92800 (suitenumerique Docs). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92812 (decaporg decap-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92921 (cjbi admin3). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92926 (code-projects Matrimonial System). Public exploit reference added.
DUE DATE PASSED — CVE-2026-76461 (Cisco Secure Email). CISA remediation deadline was September 17, 2026; still in catalog.
REJECTED — CVE-2026-90168 (Linux). Record withdrawn by the CNA.
REJECTED — CVE-2026-90310 (Linux). Record withdrawn by the CNA.
RESCORED — open-webui: 6 CVEs (CVE-2026-70482, CVE-2026-70483, CVE-2026-70484, CVE-2026-70486, CVE-2026-70487, CVE-2026-70492). CVSS rescored — before/after on each CVE page.
RESCORED — Ivanti Neurons for ITSM: 4 CVEs (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, CVE-2026-12650). CVSS rescored — before/after on each CVE page.
RESCORED — Google Chrome: 3 CVEs (CVE-2026-91719, CVE-2026-91723, CVE-2026-91732). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2025-10072 (Portabilis i-Educar). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-84566 (Apple iOS and iPadOS). CVSS 8.4 → 7.8 (NVD).
RESCORED — CVE-2026-85544 (Hikvision DS-KV9503). CVSS 5.2 → 6.1 (NVD).
RESCORED — CVE-2026-93308 (O-RAN-SC SMO OAM). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-93309 (O-RAN-SC SMO OAM). CVSS 5.3 → 2.1 (NVD).
PATCH SHIPPED — CVE-2026-65490 (John-Michael L'Allier Create). Fixed in Create 2.6.1.
ENRICHED — CVE-2018-13410. Received CVSS 9.8 and CPE data from NVD.
How to read these box scores · glossary
514 CVEs published. 25 box scores and 375 table rows below; the remaining 114 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H N N 7.7 .0150 73.1 —
AFFECTED Product Versions Fixed ManageEngine DataSecurity Plus unspecified —
TIMELINE Aug 5 Reserved by CNA Sep 18 Published (CNA: Zohocorp)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0135 70.3 —
AFFECTED Product Versions Fixed yt-dlp-web-ui v4 – —
TIMELINE Sep 17 Reserved by CNA Sep 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N C H L N 7.5 .0106 63.1 —
AFFECTED Product Versions Fixed ManageEngine DataSecurity Plus unspecified —
TIMELINE Aug 5 Reserved by CNA Sep 18 Published (CNA: Zohocorp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0094 59.3 —
AFFECTED Product Versions Fixed Printcart Store – Web to Print Product Designer for WooCommerce unspecified —
TIMELINE Jul 1 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0089 57.8 —
AFFECTED Product Versions Fixed ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF unspecified —
TIMELINE Jul 24 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0066 50.0 —
AFFECTED Product Versions Fixed Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers unspecified —
TIMELINE Jul 23 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N L H 8.8 .0065 49.8 —
AFFECTED Product Versions Fixed TN-4500B Series 1.0 – 2.1
TIMELINE Jul 13 Reserved by CNA Sep 18 Published (CNA: Moxa)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0056 45.1 —
AFFECTED Product Versions Fixed RESTEasy unspecified — Red Hat build of Apache Camel 4 for Quarkus 3 unspecified — Red Hat build of Apicurio Registry 3 unspecified — Red Hat build of Debezium 3 unspecified — Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat build of Quarkus unspecified — Red Hat Certificate System 10 unspecified — Red Hat Certificate System 11 unspecified — Red Hat Enterprise Linux 10 unspecified — + 13 more
TIMELINE Sep 10 Reserved by CNA Sep 18 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0052 43.1 —
AFFECTED Product Versions Fixed OAKlouds-custom_page-2.0 unspecified — OAKlouds-custom_page-3.0 unspecified — OAKlouds-custom_page-4.0 unspecified —
TIMELINE Sep 18 Reserved by CNA Sep 18 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0050 42.2 —
AFFECTED Product Versions Fixed DiskStation Manager (DSM) 7.4 – —
TIMELINE Jun 29 Reserved by CNA Sep 18 Published (CNA: synology)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0050 41.6 —
AFFECTED Product Versions Fixed WCFM Marketplace – Multivendor Marketplace for WooCommerce unspecified —
TIMELINE Jul 30 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0049 40.9 —
AFFECTED Product Versions Fixed Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress unspecified —
TIMELINE Jul 30 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0047 40.1 —
AFFECTED Product Versions Fixed Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder unspecified —
TIMELINE Sep 9 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0046 39.2 —
AFFECTED Product Versions Fixed OAKlouds-bulletin_v3-2.0 unspecified — OAKlouds-bulletin_v3-3.0 unspecified —
TIMELINE Sep 18 Reserved by CNA Sep 18 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0046 38.9 —
AFFECTED Product Versions Fixed Mapster WP Maps unspecified —
TIMELINE Jun 22 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0046 38.8 —
AFFECTED Product Versions Fixed DiskStation Manager (DSM) 7.4 – —
TIMELINE Jun 29 Reserved by CNA Sep 18 Published (CNA: synology)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L L 6.5 .0043 37.2 —
AFFECTED Product Versions Fixed DiskStation Manager (DSM) 7.3 – —
TIMELINE Apr 14 Reserved by CNA Sep 18 Published (CNA: synology)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L N 6.4 .0043 36.8 —
AFFECTED Product Versions Fixed Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder unspecified —
TIMELINE Jul 14 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0043 36.8 —
AFFECTED Product Versions Fixed Exploit Intelligence unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — OpenShift Serverless unspecified — Red Hat build of Apache Camel 4 for Quarkus 3 unspecified — + 11 more
TIMELINE Sep 9 Reserved by CNA Sep 18 Published (CNA: redhat)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0041 35.0 —
AFFECTED Product Versions Fixed Photo Gallery by 10Web – Mobile-Friendly Image Gallery unspecified —
TIMELINE Sep 4 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0040 34.5 —
AFFECTED Product Versions Fixed SMO OAM 2025-06-10 – —
TIMELINE Sep 17 Reserved by CNA Sep 18 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0038 31.5 —
AFFECTED Product Versions Fixed NEX-Forms – Ultimate Forms Plugin for WordPress unspecified —
TIMELINE Aug 18 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P N N N 5.1 .0037 31.4 —
AFFECTED Product Versions Fixed TAO 2.0 – —
TIMELINE Sep 17 Reserved by CNA Sep 18 Published (CNA: INCIBE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0037 31.3 —
AFFECTED Product Versions Fixed WP Multi Store Locator Pro unspecified —
TIMELINE Jul 9 Reserved by CNA Sep 18 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H H H 7.2 .0037 30.9 —
AFFECTED Product Versions Fixed Booking Calendar unspecified —
TIMELINE Sep 16 Reserved by CNA Sep 18 Published (CNA: Wordfence)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-40536 | 4.3 | 30.8 | Synology | DiskStation Manager (DSM) | CWE-22 | An improper limitation of a pathname to a restricted directory ('path travers… |
| CVE-2026-67100 | 9.8 | 29.0 | HCL Software | HCL BigFix Service Management | CWE-89 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-40530 | 8.0 | 28.4 | Synology | DiskStation Manager (DSM) | CWE-93 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability… |
| CVE-2026-17607 | 6.5 | 28.0 | chuck1982 | WP Inventory Manager | CWE-89 | WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection vi… |
| CVE-2026-4036 | 6.5 | 27.3 | Synology | DiskStation Manager (DSM) | CWE-89 | An improper neutralization of special elements used in an SQL command ('SQL i… |
| CVE-2026-85705 | 7.5 | 27.2 | AyeCode Ltd | Location Manager | CWE-89 | Location Manager <= 2.3.38 - Unauthenticated SQL Injection via 'latitude' and… |
| CVE-2026-12739 | 4.3 | 27.2 | saadiqbal | WP Easy Pay – Payment and Donation Form Builder for Square | CWE-862 | WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) A… |
| CVE-2026-93312 | 2.1 | 27.2 | Freedesktop | Poppler | CWE-404 | Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference |
| CVE-2026-40531 | 4.3 | 26.7 | Synology | DiskStation Manager (DSM) | CWE-190 | An integer overflow or wraparound vulnerability in File Operation in Synology… |
| CVE-2026-89058 | 7.4 | 26.6 | Red Hat | RESTEasy | — | Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credential… |
| CVE-2026-13471 | 4.3 | 26.4 | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | CWE-639 | LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference… |
| CVE-2026-79954 | 8.7 | 25.5 | NASA | CryptoLib | CWE-306 | NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the… |
| CVE-2026-40532 | 6.5 | 25.3 | Synology | DiskStation Manager (DSM) | CWE-425 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synol… |
| CVE-2026-93311 | 2.1 | 25.1 | Freedesktop | Poppler | CWE-189 | Freedesktop Poppler SampledFunction Function.cc integer overflow |
| CVE-2026-6205 | 8.1 | 24.9 | Synology | DiskStation Manager (DSM) | CWE-73 | An external control of file name or path vulnerability in Upload API in Synol… |
| CVE-2026-75017 | 4.3 | 24.7 | wpblockart | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | CWE-862 | Magazine Blocks <= 1.8.6 - Missing Authorization to Authenticated (Contributo… |
| CVE-2026-93331 | 6.9 | 24.5 | n/a | GPAC | CWE-119 | GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds |
| CVE-2026-85410 | 8.1 | 24.4 | pixarlabs | Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits | CWE-862 | Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated… |
| CVE-2026-12384 | 8.8 | 23.9 | TECHIN2B | TECHIN2B Application | CWE-639 | Broken Access Control in TECHIN2B Application |
| CVE-2026-17586 | 6.4 | 23.6 | kurudrive | VK All in One Expansion Unit | CWE-79 | VK All in One Expansion Unit <= 9.118.0 - Authenticated (Author+) Stored Cros… |
| CVE-2026-13673 | 8.8 | 23.5 | Synology | DiskStation Manager (DSM) | CWE-732 | An incorrect permission assignment for critical resource vulnerability in LDA… |
| CVE-2026-40533 | 5.3 | 22.2 | Synology | DiskStation Manager (DSM) | CWE-202 | An exposure of sensitive information through data queries vulnerability in De… |
| CVE-2026-83561 | 7.2 | 22.1 | complianz | Complianz GDPR/CCPA Cookie Consent Banner | CWE-79 | Complianz GDPR/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored C… |
| CVE-2026-89413 | 8.1 | 21.9 | farazfrank | Filter Gallery | CWE-862 | Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+… |
| CVE-2026-92991 | 5.4 | 21.6 | bdthemes | Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator | CWE-79 | Biggopti Library (Various Versions) - Cross-Site Scripting via display_id fro… |
| CVE-2026-88994 | 6.6 | 20.8 | Unknown | All Bootstrap Blocks | CWE-98 | All Bootstrap Blocks 1.3.20 - 1.3.31 - Contributor+ LFI via lightspeed Block … |
| CVE-2026-17576 | 6.5 | 20.1 | revmakx | InfiniteWP Client | CWE-89 | InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_g… |
| CVE-2026-90981 | 6.1 | 20.0 | satollo | Newsletter – Send awesome emails from WordPress | CWE-79 | Newsletter <= 9.3.8 - Reflected Cross-Site Scripting via 'nn' Parameter |
| CVE-2026-67102 | 8.1 | 19.9 | HCL Software | HCL BigFix Service Management | CWE-285 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-90977 | 5.3 | 19.9 | Unknown | Clean Login | CWE-697 | Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison |
| CVE-2026-67101 | 9.3 | 19.3 | HCL Software | HCL BigFix Service Management | CWE-918 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-13635 | 5.3 | 18.8 | Synology | DiskStation Manager (DSM) | CWE-116 | An improper encoding or escaping of output vulnerability in Auth API in Synol… |
| CVE-2026-92249 | 6.1 | 18.7 | qodeinteractive | Qi Addons For Elementor | CWE-79 | Qi Addons For Elementor <= 1.11 - Reflected DOM-Based Cross-Site Scripting vi… |
| CVE-2026-92554 | 6.1 | 18.7 | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | CWE-79 | ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Paramet… |
| CVE-2026-91707 | 5.3 | 18.6 | Elegant Themes | Divi | CWE-862 | Divi <= 5.11.1 - Missing Authorization to Unauthenticated Arbitrary Registere… |
| CVE-2026-14472 | 6.4 | 18.2 | extendthemes | Kubio AI Page Builder | CWE-79 | Kubio AI Page Builder <= 2.8.4 - Authenticated (Contributor+) Stored Cross-Si… |
| CVE-2026-93455 | 7.1 | 17.8 | batiste | django-page-cms | CWE-862 | django-page-cms through 2.0.13 Unauthorized Content Access via Staff Account |
| CVE-2026-89278 | 5.3 | 17.5 | john-dagelmore | GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI | CWE-200 | GPTranslate <= 2.34.6 - Unauthenticated Sensitive Information Exposure in Pub… |
| CVE-2026-56592 | 6.5 | 17.3 | HCL Software | HCL BigFix Service Management | CWE-307 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-40537 | 4.3 | 17.3 | Synology | DiskStation Manager (DSM) | CWE-918 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synol… |
| CVE-2026-86796 | 5.3 | 16.9 | Unknown | Hide My WP Ghost | CWE-693 | WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detecti… |
| CVE-2026-86800 | 5.3 | 16.9 | Unknown | Hide My WP Ghost | CWE-693 | WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via … |
| CVE-2026-13683 | 2.7 | 16.7 | Synology | DiskStation Manager (DSM) | CWE-89 | An improper neutralization of special elements used in an SQL command ('SQL I… |
| CVE-2026-40538 | 3.7 | 16.6 | Synology | DiskStation Manager (DSM) | CWE-307 | An improper restriction of excessive authentication attempts vulnerability in… |
| CVE-2026-12106 | 6.4 | 16.5 | airani | Auto Upload Images | CWE-918 | Auto Upload Images <= 3.3.2 - Authenticated (Contributor+) Server-Side Reques… |
| CVE-2026-93313 | 2.1 | 16.4 | Freedesktop | Poppler | CWE-189 | Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow |
| CVE-2026-93314 | 2.1 | 16.4 | Freedesktop | Poppler | CWE-189 | Freedesktop Poppler FoFiTrueType.cc mapCodeToGID integer overflow |
| CVE-2024-38639 | 4.8 | 16.1 | QNAP Systems Inc. | QTS | CWE-287 | QTS |
| CVE-2026-92622 | 6.4 | 15.8 | wpchill | Strong Testimonials | CWE-79 | Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site… |
| CVE-2026-15004 | 5.4 | 15.8 | ninjateam | FileBird – WordPress Media Library Folders & File Manager | CWE-79 | FileBird – WordPress Media Library Folders & File Manager <= 6.5.6 - Authenti… |
| CVE-2026-77169 | 6.5 | 15.7 | Nextcloud | Team Folders | CWE-284 | A vulnerability in the team folders (formerly group folders) app when used in… |
| CVE-2026-92714 | 6.5 | 15.2 | codename065 | Download Manager | CWE-639 | Download Manager <= 3.3.68 - Insecure Direct Object Reference to Authenticate… |
| CVE-2026-84909 | 6.4 | 14.7 | smub | Custom Twitter Feeds – A Tweets Widget or X Feed Widget | CWE-79 | Custom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Sit… |
| CVE-2026-92561 | 6.1 | 14.2 | wpdevelop | Booking Calendar | CWE-79 | Booking Calendar <= 11.8.2 - Reflected Cross-Site Scripting via 'options' Par… |
| CVE-2026-89138 | 4.3 | 13.7 | farazfrank | Filter Gallery | CWE-862 | Filter Gallery <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+… |
| CVE-2026-84738 | 9.1 | 13.3 | Unknown | AF Companion | CWE-94 | AF Companion < 2.2.0 - Shop Manager+ Arbitrary File Upload to RCE |
| CVE-2026-67103 | 7.6 | 13.3 | HCL Software | HCL BigFix Service Management | CWE-79 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-90884 | 5.4 | 12.9 | brechtvds | WP Recipe Maker | CWE-79 | WP Recipe Maker <= 10.8.1 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-90976 | 5.3 | 12.9 | Unknown | Clean Login | CWE-284 | Clean Login < 1.19 - Unauthenticated Account Creation with Registration Disabled |
| CVE-2026-79713 | 6.5 | 12.0 | Unknown | Breeze Cache | CWE-444 | Breeze Cache 1.2.5 - 2.5.14 - Unauthenticated Cache Poisoning via Unkeyed Tra… |
| CVE-2026-18317 | 4.3 | 12.0 | foxtheme | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images | CWE-862 | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images … |
| CVE-2026-15650 | 6.4 | 11.8 | themewant | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | CWE-79 | RT Mega Menu <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Script… |
| CVE-2026-89330 | 6.1 | 11.7 | wpdevteam | EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents | CWE-79 | EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' … |
| CVE-2026-21822 | 6.3 | 11.6 | HCL Software | HCL AppScan 360° | CWE-22 | A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2… |
| CVE-2026-82980 | 6.3 | 11.3 | Nextcloud | Files Lock | CWE-287 | Any authenticated user can lock or unlock files they do not own by targeting … |
| CVE-2026-93494 | 7.5 | 10.7 | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-1035 | Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when … |
| CVE-2026-40534 | 5.4 | 10.8 | Synology | DiskStation Manager (DSM) | CWE-79 | An improper neutralization of input during web page generation ('cross-site s… |
| CVE-2026-82985 | 6.5 | 10.4 | Nextcloud | Server | CWE-284 | The Photos app's filter-based "smart albums" build their file listing using t… |
| CVE-2026-14855 | 6.4 | 10.3 | themewant | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | CWE-79 | RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripti… |
| CVE-2026-75016 | 6.4 | 10.3 | wpblockart | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | CWE-79 | Magazine Blocks <= 1.8.6 - Authenticated (Contributor+) Stored Cross-Site Scr… |
| CVE-2026-21848 | 5.0 | 9.7 | HCL Software | HCL BigFix Service Management | CWE-284 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2025-13533 | 4.4 | 9.6 | wipeoutmedia | CSS & JavaScript Toolbox | CWE-79 | CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Administrator+) Stored Cr… |
| CVE-2026-13623 | 4.8 | 9.3 | Synology | DiskStation Manager (DSM) | CWE-79 | An improper neutralization of input during web page generation ('Cross-site S… |
| CVE-2026-13666 | 3.5 | 9.3 | Synology | DiskStation Manager (DSM) | CWE-93 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability… |
| CVE-2026-87767 | 8.6 | 8.9 | Unknown | wp shortcut link and advertisement baner | CWE-89 | WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url |
| CVE-2026-87770 | 8.6 | 8.9 | Unknown | Price Drop Alert for Woo Commerce | CWE-89 | Price Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via p… |
| CVE-2026-87771 | 8.6 | 8.9 | Unknown | Product Question and Answer | CWE-89 | Product Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id… |
| CVE-2026-87774 | 8.6 | 8.9 | Unknown | Tz Weekly Radio Schedule | CWE-89 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via week |
| CVE-2026-87775 | 8.6 | 8.9 | Unknown | Tz Weekly Radio Schedule | CWE-89 | Tz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cell |
| CVE-2026-82982 | 4.3 | 8.5 | Nextcloud | Approval | CWE-840 | The Approval app's approve/reject endpoint is meant to require the file's cur… |
| CVE-2026-85122 | 8.8 | 8.1 | Unknown | Easy Form Builder by WhiteStudio | CWE-79 | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type Co… |
| CVE-2026-11757 | 6.1 | 8.0 | KA Informatics Technologies Ltd. Co. | Bar Association Website | CWE-79 | Reflected XSS in KA Informatics' Bar Association Website |
| CVE-2026-88825 | 8.8 | 7.0 | Unknown | iGMS Direct Booking | CWE-79 | iGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget Settings |
| CVE-2026-75157 | await | 7.0 | Apache Software Foundation | Apache Airflow | CWE-863 | Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instea… |
| CVE-2026-85127 | 8.8 | 6.7 | Unknown | VikBooking Hotel Booking Engine & PMS | CWE-79 | VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment |
| CVE-2026-56590 | 6.4 | 6.8 | HCL Software | HCL BigFix Service Management | CWE-434 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-84902 | 6.8 | 6.0 | Unknown | King Addons for Elementor | CWE-79 | King Addons for Elementor < 51.1.81 - Contributor+ Stored XSS via Template Ca… |
| CVE-2026-93485 | 7.1 | 5.7 | Automattic | WordPress | CWE-79 | WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability |
| CVE-2026-56597 | 3.1 | 5.5 | HCL Software | HCL BigFix Service Management | CWE-200 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-77170 | 4.3 | 4.8 | Nextcloud | Deck | CWE-284 | The Deck config API allows authenticated users to set board-scoped configurat… |
| CVE-2026-88993 | 6.8 | 4.8 | Unknown | All Bootstrap Blocks | CWE-79 | All Bootstrap Blocks <= 1.3.31 - Contributor+ Stored XSS via areoi/button typ… |
| CVE-2026-93456 | 8.4 | 4.7 | batiste | django-page-cms | CWE-352 | django-page-cms through 2.0.13 CSRF via admin mutation views |
| CVE-2026-93493 | 5.9 | 4.6 | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-299 | Io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when… |
| CVE-2026-84903 | 2.7 | 4.5 | Unknown | King Addons for Elementor | CWE-200 | King Addons for Elementor < 51.1.81 - Contributor+ Private Post Content Discl… |
| CVE-2026-56595 | 3.1 | 4.4 | HCL Software | HCL BigFix Service Management | CWE-942 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-85009 | 6.5 | 4.3 | Unknown | RestroPress | CWE-639 | RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modif… |
| CVE-2026-85123 | 5.3 | 4.3 | Unknown | Easy Form Builder by WhiteStudio | CWE-284 | Easy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass … |
| CVE-2026-85350 | 5.3 | 4.3 | Unknown | UpsellWP | CWE-287 | UpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought … |
| CVE-2026-87966 | 5.3 | 4.3 | Unknown | Easy Appointments | CWE-639 | Easy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modif… |
| CVE-2026-87965 | 4.8 | 4.3 | Unknown | Easy Appointments | CWE-284 | Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confir… |
| CVE-2026-88798 | 5.3 | 4.2 | Unknown | Really Simple Security | CWE-400 | Really Simple Security (Free) < 9.8.3 - Unauthenticated Unbounded Option Grow… |
| CVE-2026-81810 | 7.2 | 3.9 | Unknown | All-in-One WP Migration and Backup | CWE-269 | All-in-One WP Migration and Backup < 7.111 - Authenticated Privilege Escalati… |
| CVE-2026-81340 | 3.8 | 3.9 | Unknown | MasterStudy LMS WordPress Plugin | CWE-639 | MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR |
| CVE-2026-84904 | 3.8 | 3.9 | Unknown | King Addons for Elementor | CWE-862 | King Addons for Elementor 51.1.56 - 51.1.80 - Author+ Missing Authorization v… |
| CVE-2026-68493 | 3.1 | 3.7 | Nextcloud | Server | CWE-639 | After guessing a 62^15 complex unique identifier, a malicious logged in user … |
| CVE-2026-89008 | 2.7 | 3.7 | Unknown | Bookit — Booking & Appointment Calendar | CWE-200 | Bookit < 2.6.0.5 - Bookit Staff+ Appointment PII Disclosure |
| CVE-2026-90984 | 5.8 | 3.4 | Unknown | Generate PDF using Contact Form 7 | CWE-918 | Generate PDF using Contact Form 7 < 4.2.2 - Unauthenticated Server-Side Reque… |
| CVE-2026-90978 | 7.1 | 3.2 | Unknown | Filter Gallery | CWE-284 | Filter Gallery < 1.1.5 - Subscriber+ Arbitrary Post Overwrite and Plugin Opti… |
| CVE-2026-88844 | 2.7 | 3.2 | Unknown | MasterStudy LMS WordPress Plugin | CWE-639 | MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR |
| CVE-2026-89007 | 2.7 | 3.2 | Unknown | Bookit — Booking & Appointment Calendar | CWE-862 | Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing A… |
| CVE-2024-27123 | 5.2 | 3.0 | QNAP Systems Inc. | QcalAgent | CWE-79 | QcalAgent |
| CVE-2026-77164 | 6.2 | 2.7 | Nextcloud | Server | CWE-918 | Circles' remote-instance signature verification fetches the attacker-supplied… |
| CVE-2026-40539 | 7.1 | 0.1 | Synology | DiskStation Manager (DSM) | CWE-295 | An improper certificate validation vulnerability in Email API in Synology Dis… |
| CVE-2025-15399 | 10.0 | — | IBM | Common Licensing | CWE-352 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-10747 | 10.0 | — | IBM | MQ Appliance | CWE-122 | IBM MQ Appliance is affected by a heap buffer overflow vulnerability in proto… |
| CVE-2026-93603 | 10.0 | — | patriksimek | vm2 | CWE-94 | vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function |
| CVE-2026-93605 | 10.0 | — | patriksimek | vm2 | CWE-693 | vm2 NodeVM before 3.12.1 Remote Code Execution via child_process |
| CVE-2026-93606 | 10.0 | — | patriksimek | vm2 | CWE-693 | vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species |
| CVE-2025-53837 | 9.9 | — | xwiki | xwiki-rendering | CWE-95 | org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue |
| CVE-2026-10858 | 9.9 | — | IBM | MQ for HPE NonStop | CWE-122 | IBM MQ for HPE NonStop is vulnerable to a denial of service attack |
| CVE-2026-61682 | 9.9 | — | kcp-dev | kcp | CWE-290 | kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing … |
| CVE-2026-61781 | 9.9 | — | pgpartman | pg_partman | CWE-89 | pg_partman has privilege escalation through SQL injection in create_partition… |
| CVE-2026-77240 | 9.9 | — | ArnasDon | wacrm | CWE-639 | WACRM: Database-layer authorization bypasses |
| CVE-2026-80442 | 9.9 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84064 | 9.9 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84075 | 9.9 | — | IBM | Guardium Data Protection | CWE-306 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84078 | 9.9 | — | IBM | Guardium Data Protection | CWE-306 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2025-66455 | 9.8 | — | InternLM | lmdeploy | CWE-502 | LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_r… |
| CVE-2026-58264 | 9.8 | — | FluidSynth | fluidsynth | CWE-122 | FluidSynth: Heap-based buffer overrun |
| CVE-2026-61550 | 9.8 | — | Icinga | icinga2 | CWE-862 | Icinga 2: Improper access control for JSON-RPC update certificate messages |
| CVE-2026-75031 | 9.8 | — | Interchange | Interchange | CWE-94 | In the interchange/interchange project, a critical remote code execution (RCE… |
| CVE-2026-80441 | 9.8 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-81657 | 9.8 | — | IBM | Guardium Data Protection | CWE-502 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-82340 | 9.8 | — | IBM | Guardium Data Protection | CWE-94 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-82967 | 9.8 | — | IBM | Guardium Data Protection | CWE-306 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84082 | 9.8 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84383 | 9.8 | — | strukturag | libheif | CWE-787 | libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alp… |
| CVE-2026-82832 | 9.6 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-28197 | 9.4 | — | Cohesity | NetBackup Flex OS | CWE-88 | Privilege Escalation via Argument Injection in NetBackup Flex OS Shell |
| CVE-2026-28198 | 9.4 | — | Cohesity | NetBackup Flex OS | CWE-347 | Privilege Escalation via Cryptographic Signature Verification Bypass in NetBa… |
| CVE-2023-54399 | 9.3 | — | Hongjing | e-HR | CWE-89 | Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree |
| CVE-2026-63647 | 9.3 | — | 1Panel-dev | CordysCRM | CWE-306 | CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` |
| CVE-2026-75885 | 9.3 | — | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-918 | Openshift/console: openshift/console: unauthenticated ssrf and resource exhau… |
| CVE-2026-81321 | 9.3 | — | CareCam | HMT.CM2507 Firmware | CWE-312 | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-85497 | 9.3 | — | CareCam | HMT.CM2507 Firmware | CWE-916 | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-93659 | 9.3 | — | concretecms-community-store | community_store | CWE-79 | Concrete CMS Community Store before 2.7.8 Stored XSS |
| CVE-2026-93740 | 9.3 | — | Totolink | A3002MU | CWE-119 | Totolink A3002MU formWlEncrypt buffer overflow |
| CVE-2026-93839 | 9.3 | — | ModelTC | LightLLM | CWE-306 | LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSo… |
| CVE-2023-5778 | 9.2 | — | ABB | Freelance Controller DCP | CWE-130 | Missing Length Check |
| CVE-2026-93762 | 9.2 | — | MongoDB Inc. | Mongoid | CWE-470 | Data deletion and attribute disclosure via field-name method injection in in-… |
| CVE-2026-93868 | 9.2 | — | Cotonti | Cotonti | CWE-338 | Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
| CVE-2026-59163 | 9.1 | — | AxDSan | mnemosyne | CWE-347 | Mnemosyne has JWT signature verification bypass sync server that allows authe… |
| CVE-2026-75878 | 9.1 | — | IBM | Sterling File Gateway | CWE-287 | IBM Sterling File Gateway is Vulnerable to Authentication Bypass |
| CVE-2026-84073 | 9.1 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-92701 | 9.1 | — | ultravioletrs | cocos | CWE-346 | Cocos AI: Intra-handshake attested TLS implementation is vulnerable to sessio… |
| CVE-2026-92702 | 9.1 | — | ultravioletrs | cocos | CWE-346 | Cocos AI: Intra-handshake attested TLS implementation can accept Evidence wit… |
| CVE-2026-93019 | 9.1 | — | — | Imager | CWE-196 | Imager versions before 1.036 for Perl exit the process reading a TGA with a c… |
| CVE-2026-84031 | 9.0 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84070 | 8.9 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84074 | 8.9 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84106 | 8.9 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2025-14754 | 8.8 | — | IBM | Cloud Pak for Data | CWE-78 | IBM Cloud Pak for Data is vulnerable to OS command injection |
| CVE-2026-10575 | 8.8 | — | IBM | MQ | CWE-122 | IBM MQ queue manager is vulnerable to remote code execution |
| CVE-2026-11375 | 8.8 | — | IBM | MQ | CWE-122 | IBM MQ queue manager is vulnerable to remote code execution |
| CVE-2026-11378 | 8.8 | — | IBM | MQ | CWE-190 | IBM MQ queue manager is vulnerable to remote code execution |
| CVE-2026-11381 | 8.8 | — | IBM | MQ for HPE NonStop | CWE-122 | IBM MQ for HPE NonStop is vulnerable to a denial of service issue |
| CVE-2026-11725 | 8.8 | — | IBM | MQ | CWE-190 | IBM MQ queue manager is vulnerable to privilege escalation |
| CVE-2026-33625 | 8.8 | — | InternLM | lmdeploy | CWE-400 | LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant… |
| CVE-2026-58197 | 8.8 | — | stacklok | toolhive | CWE-284 | ToolHive: containerized MCP servers can reach host services via host.docker.i… |
| CVE-2026-81180 | 8.8 | — | Syslifters | sysreptor | CWE-20 | SysReptor: Authenticated RCE by insecure image processing |
| CVE-2026-81656 | 8.8 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-81933 | 8.8 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-82885 | 8.8 | — | IBM | Guardium Data Protection | CWE-862 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-82887 | 8.8 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84034 | 8.8 | — | IBM | Guardium Data Protection | CWE-798 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84084 | 8.8 | — | IBM | Guardium Data Protection | CWE-352 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-88622 | 8.8 | — | n/a | n/a | CWE-77 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handl… |
| CVE-2026-93031 | 8.8 | — | WP Cloud Plugins/_deleeuw_ | Use-your-Drive | Google Drive plugin for WordPress | CWE-434 | WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Bo… |
| CVE-2026-93759 | 8.8 | — | MongoDB Inc. | Mongoid | CWE-94 | Server-side JavaScript injection via string query criteria bypassing the stri… |
| CVE-2017-20284 | 8.7 | — | Caucho Technology, Inc. | Resin | CWE-22 | Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet |
| CVE-2019-25776 | 8.7 | — | Weaver Network Co., Ltd. | E-cology | CWE-89 | Weaver E-cology SQL Injection via SyncUserInfo.jsp |
| CVE-2021-48008 | 8.7 | — | Chanjet Information Technology Co., Ltd. | CRM | CWE-89 | Chanjet CRM SQL Injection via get_usedspace.php |
| CVE-2026-62943 | 8.7 | — | digint | btrbk | CWE-78 | btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh |
| CVE-2026-68914 | 8.7 | — | mojolicious | mojo | CWE-400 | Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply … |
| CVE-2026-77929 | 8.7 | — | MacWarrior | clipbucket-v5 | CWE-434 | ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint |
| CVE-2026-81942 | 8.7 | — | PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V1 | CWE-78 | PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server |
| CVE-2026-84398 | 8.7 | — | CareCam | HMT.CM2507 Firmware | CWE-258 | CareCam CM2507 Empty Password in Configuration File |
| CVE-2026-86520 | 8.7 | — | Bransys | ELD | CWE-798 | Use of Hard-coded Credentials in Bransys ELD |
| CVE-2026-88259 | 8.7 | — | CareCam | HMT.CM2507 Firmware | CWE-306 | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-93592 | 8.7 | — | vllm-project | vllm | CWE-129 | vLLM before 0.28.0 Denial of Service via negative token ID |
| CVE-2026-93599 | 8.7 | — | rustls | webpki | CWE-191 | rustls-webpki before 0.103.13 Panic via empty BIT STRING |
| CVE-2026-93657 | 8.7 | — | hickory-dns | hickory-resolver | CWE-347 | hickory-resolver before 0.26.2 DNSSEC Validation Bypass |
| CVE-2026-93687 | 8.7 | — | micromatch | braces | CWE-674 | braces through 3.0.3 Stack Overflow via Deeply Nested Patterns |
| CVE-2026-93688 | 8.7 | — | sgl-project | sglang | CWE-770 | SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room |
| CVE-2026-93690 | 8.7 | — | garycourt | uri-js | CWE-835 | uri-js through 4.4.1 Denial of Service via removeDotSegments |
| CVE-2026-93748 | 8.7 | — | kornelski | http-cache-semantics | CWE-524 | http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale |
| CVE-2026-93749 | 8.7 | — | 7rulnik | source-map-js | CWE-1284 | source-map-js through 1.2.1 Event Loop Denial of Service |
| CVE-2026-93752 | 8.7 | — | NV | CSSOM | CWE-915 | CSSOM through 0.5.0 Denial of Service via length Property |
| CVE-2026-93753 | 8.7 | — | TehShrike | deepmerge | CWE-1321 | deepmerge through 4.3.1 Prototype Poisoning via mergeObject |
| CVE-2026-93761 | 8.7 | — | MongoDB Inc. | Mongoid | CWE-1333 | Denial of service via unbounded regex matching in Mongoid's in-memory query m… |
| CVE-2025-61682 | 8.6 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-79 | Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use… |
| CVE-2026-17619 | 8.6 | — | IBM | spectrum-lsf : IBM Platform RTM | CWE-89 | The IBM Platform RTM is affected by an SQL injection vulnerability |
| CVE-2026-61551 | 8.6 | — | Icinga | icinga2 | CWE-674 | Icinga 2: Stack overflow via deeply nested JSON objects |
| CVE-2026-68928 | 8.6 | — | Acode-Foundation | Acode | CWE-749 | Acode: Exported TerminalService (bundled terminal plugin) lets any installed … |
| CVE-2026-81626 | 8.6 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-93593 | 8.6 | — | ArcadeData | arcadedb | CWE-863 | ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission |
| CVE-2026-93738 | 8.6 | — | Totolink | A3002MU | CWE-119 | Totolink A3002MU formSchedule buffer overflow |
| CVE-2026-93739 | 8.6 | — | Totolink | A3002MU | CWE-119 | Totolink A3002MU formWlAc buffer overflow |
| CVE-2026-93758 | 8.6 | — | MongoDB Inc. | Mongoid | CWE-639 | Cross-principal document update, theft, and deletion via unvalidated id in ne… |
| CVE-2026-93922 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan through 3.8.4 Stored XSS via notebook names |
| CVE-2026-93923 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan through 3.8.4 Stored XSS via Heading Style Attribute |
| CVE-2026-61817 | 8.5 | — | pgpartman | pg_partman | CWE-89 | pg_partman privilege escalation via SQL injection in several functions via ti… |
| CVE-2026-61818 | 8.5 | — | pgpartman | pg_partman | CWE-89 | pg_partman SQL injection in undo partition time encoder |
| CVE-2026-61819 | 8.5 | — | pgpartman | pg_partman | CWE-89 | pg_partman privilege escalation via SQL injection in when using pg_jobmon and… |
| CVE-2026-61820 | 8.5 | — | pgpartman | pg_partman | CWE-89 | pg_partman privilege escalation via SQL injection when inheriting template pr… |
| CVE-2026-61821 | 8.5 | — | pgpartman | pg_partman | CWE-862 | pg_partman authorization bypass to move child tables between schemas during r… |
| CVE-2026-81943 | 8.4 | — | PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V1 | CWE-489 | PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCE |
| CVE-2026-63199 | 8.3 | — | perses | perses | CWE-862 | Perses: Missing authorization in datasource proxy allows cross-scope secret d… |
| CVE-2026-63638 | 8.3 | — | AcademySoftwareFoundation | OpenImageIO | CWE-787 | OpenImageIO: Cineon invalid bit depth heap out-of-bounds write |
| CVE-2026-93760 | 8.3 | — | MongoDB Inc. | Mongoid | CWE-943 | NoSQL injection of JavaScript-executing query operators via unsafe-by-default… |
| CVE-2026-93765 | 8.3 | — | MongoDB Inc. | Mongoid | CWE-470 | Document deletion and process crash via unvalidated method-name dispatch in a… |
| CVE-2026-55556 | 8.2 | — | rsyslog | rsyslog | CWE-122 | Rsyslog: Heap buffer overflow in imhttp plugin Basic Authentication handling |
| CVE-2026-57228 | 8.2 | — | OISF | suricata | CWE-125 | Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder |
| CVE-2026-86689 | 8.2 | — | Bransys | ELD | CWE-319 | Cleartext Transmission of Sensitive Information in Bransys ELD |
| CVE-2026-91127 | 8.2 | — | flyfish-dev | file-viewer | CWE-79 | File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer |
| CVE-2026-93569 | 8.2 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-444 | Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated … |
| CVE-2026-93750 | 8.2 | — | kornelski | http-cache-semantics | CWE-436 | http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wil… |
| CVE-2026-93838 | 8.2 | — | sgl-project | sglang | CWE-770 | SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx |
| CVE-2026-10027 | 8.1 | — | IBM | MQ | CWE-787 | IBM MQ queue manager is vulnerable to unauthenticated remote code execution |
| CVE-2026-11726 | 8.1 | — | IBM | MQ for HPE NonStop | CWE-125 | IBM MQ for HPE NonStop is vulnerable to a denial of service issue |
| CVE-2026-11727 | 8.1 | — | IBM | MQ for HPE NonStop | CWE-122 | IBM MQ for HPE NonStop is vulnerable to a denial of service issue |
| CVE-2026-54148 | 8.1 | — | http4k | http4k | CWE-294 | http4k: `DigestAuthProvider.verify` did not bind to request URI |
| CVE-2026-61548 | 8.1 | — | rsyslog | rsyslog | CWE-121 | Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured… |
| CVE-2026-61833 | 8.1 | — | project-zot | zot | CWE-285 | zot: Bearer authentication maps DELETE to push scope, allowing unauthorized d… |
| CVE-2026-62278 | 8.1 | — | hargata | lubelog | CWE-22 | LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticate… |
| CVE-2026-77239 | 8.1 | — | ArnasDon | wacrm | CWE-285 | WACRM: Service-role routes missing a role check |
| CVE-2026-81179 | 8.1 | — | Syslifters | sysreptor | CWE-807 | SysReptor: Host header injection might allow account takeover |
| CVE-2026-82892 | 8.1 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84077 | 8.1 | — | IBM | Guardium Data Protection | CWE-352 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84081 | 8.1 | — | IBM | Guardium Data Protection | CWE-295 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84085 | 8.1 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84108 | 8.1 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84241 | 8.1 | — | IBM | Guardium Data Protection | CWE-285 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-88097 | 8.1 | — | Microsoft | Microsoft Edge (Chromium-based) | CWE-416 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2026-61721 | 8.0 | — | FluidSynth | fluidsynth | CWE-122 | FluidSynth: Heap-based buffer overrun for DLS samples |
| CVE-2026-46655 | 7.8 | — | virtio-win | kvm-guest-drivers-windows | CWE-122 | virtio-win: Integer overflow causing a heap overflow in Viosock driver |
| CVE-2026-61714 | 7.8 | — | FluidSynth | fluidsynth | CWE-122 | FluidSynth: Heap Buffer Overflow in MIDI Player |
| CVE-2026-63419 | 7.8 | — | AcademySoftwareFoundation | OpenImageIO | CWE-787 | OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer |
| CVE-2026-63422 | 7.8 | — | AcademySoftwareFoundation | OpenImageIO | CWE-122 | OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write |
| CVE-2026-82893 | 7.8 | — | IBM | Guardium Data Protection | CWE-269 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84083 | 7.8 | — | IBM | Guardium Data Protection | CWE-269 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84089 | 7.8 | — | IBM | Guardium Data Protection | CWE-269 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-81944 | 7.7 | — | PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V1 | CWE-121 | PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server |
| CVE-2026-84105 | 7.7 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-93872 | 7.7 | — | Cotonti | Cotonti | CWE-502 | Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter |
| CVE-2026-67549 | 7.6 | — | AcademySoftwareFoundation | OpenImageIO | CWE-122 | OpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds write |
| CVE-2026-82896 | 7.6 | — | IBM | Guardium Data Protection | CWE-22 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84076 | 7.6 | — | IBM | Guardium Data Protection | CWE-285 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84239 | 7.6 | — | IBM | Guardium Data Protection | CWE-89 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2025-14753 | 7.5 | — | IBM | Cloud Pak for Data | CWE-22 | IBM Cloud Pak for Data is vulnerable to path traversal |
| CVE-2026-10744 | 7.5 | — | IBM | MQ for HPE NonStop | CWE-122 | IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation |
| CVE-2026-10751 | 7.5 | — | IBM | MQ | CWE-502 | IBM MQ Java messaging is vulnerable to remote code execution |
| CVE-2026-10853 | 7.5 | — | IBM | MQ | CWE-470 | IBM MQ queue manager is vulnerable to remote code execution |
| CVE-2026-11716 | 7.5 | — | IBM | MQ for HPE NonStop | CWE-122 | IBM MQ for HPE NonStop is vulnerable to a denial of service attack |
| CVE-2026-32641 | 7.5 | — | parseablehq | parseable | CWE-248 | Parseable: Unauthenticated Denial of Service via panic in Kinesis header pars… |
| CVE-2026-57227 | 7.5 | — | OISF | suricata | CWE-400 | Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel… |
| CVE-2026-63446 | 7.5 | — | OISF | suricata | CWE-401 | Suricata app-layer: passed flows can retain transactions, causing resource ex… |
| CVE-2026-63447 | 7.5 | — | OISF | suricata | CWE-407 | Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption |
| CVE-2026-63452 | 7.5 | — | OISF | suricata | CWE-400 | Suricata http1: repeated brotli compression bombs can cause excessive CPU con… |
| CVE-2026-69184 | 7.5 | — | c-ares | c-ares | CWE-407 | c-ares: CPU-exhaustion denial of service via unbounded DNS name compression p… |
| CVE-2026-71418 | 7.5 | — | OISF | suricata | CWE-407 | Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption |
| CVE-2026-77301 | 7.5 | — | cthackers | adm-zip | CWE-789 | adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
| CVE-2026-81945 | 7.5 | — | PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V1 | CWE-121 | PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server |
| CVE-2026-84384 | 7.5 | — | strukturag | libheif | CWE-409 | libheif: brotli/zlib decompression paths lack output-size limits, allowing de… |
| CVE-2026-84446 | 7.5 | — | strukturag | libheif | CWE-835 | libheif: Sequence decode timing-table initialization allows non-terminating l… |
| CVE-2026-84447 | 7.5 | — | strukturag | libheif | CWE-770 | libheif: Derived-image indirect reference chains and tiled offsets bypass dec… |
| CVE-2026-85058 | 7.5 | — | moquette-io | moquette | CWE-862 | Moquette: Missing Authorization in io.moquette:moquette-broker |
| CVE-2026-91149 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Cockpit: cockpit: denial of service via unbounded connection thread spawning |
| CVE-2026-92708 | 7.5 | — | sveltejs | devalue | CWE-200 | devalue: Cross-request process memory disclosure in devalue when `stringify` … |
| CVE-2026-93488 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-770 | Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent … |
| CVE-2026-93491 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-770 | Io.netty/netty-codec-http: netty: denial of service via unbounded httpserverc… |
| CVE-2026-93558 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in we… |
| CVE-2026-93560 | 7.5 | — | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-1035 | Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int tru… |
| CVE-2026-93563 | 7.5 | — | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-1035 | Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation … |
| CVE-2026-93564 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild b… |
| CVE-2026-93565 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trail… |
| CVE-2026-93567 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-20 | Io.netty/netty-codec-http2: http/1 authority-form connect is translated to ma… |
| CVE-2026-93568 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-20 | Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and htt… |
| CVE-2026-93572 | 7.5 | — | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-770 | Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers m… |
| CVE-2026-93575 | 7.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder |
| CVE-2026-93576 | 7.5 | — | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-93 | Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field i… |
| CVE-2026-93652 | 7.5 | — | D3TN GmbH | µD3TN | CWE-190 | Integer Overflow or Wraparound in µD3TN |
| CVE-2026-84036 | 7.4 | — | IBM | Guardium Data Protection | CWE-285 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84444 | 7.4 | — | strukturag | libheif | CWE-787 | libheif uncompressed tiled image encoding allows out-of-bounds write |
| CVE-2026-84975 | 7.4 | — | pjsip | pjproject | CWE-295 | PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in… |
| CVE-2026-93658 | 7.3 | — | uutils | coreutils | CWE-281 | uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid |
| CVE-2026-61552 | 7.2 | — | Icinga | icinga2 | CWE-94 | Icinga 2 DSL Injection via Unescaped Import Template Name |
| CVE-2026-81669 | 7.2 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-81937 | 7.2 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84071 | 7.2 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84086 | 7.2 | — | IBM | Guardium Data Protection | CWE-22 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-93591 | 7.2 | — | siyuan-note | siyuan | CWE-89 | SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go |
| CVE-2026-93854 | 7.2 | — | OpenStack | Blazar | CWE-1025 | In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-l… |
| CVE-2026-10030 | 7.1 | — | IBM | MQ | CWE-285 | IBM MQ Console is vulnerable to privilege escalation |
| CVE-2026-61672 | 7.1 | — | projectcapsule | capsule | CWE-697 | Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node lab… |
| CVE-2026-62279 | 7.1 | — | hargata | lubelog | CWE-639 | LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records fr… |
| CVE-2026-63445 | 7.1 | — | perses | perses | CWE-22 | Perses: Unvalidated project parameter enables filesystem path traversal |
| CVE-2026-63458 | 7.1 | — | perses | perses | CWE-639 | Perses project query parameter authorization bypass exposes cross-project res… |
| CVE-2026-77927 | 7.1 | — | MacWarrior | clipbucket-v5 | CWE-89 | ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint |
| CVE-2026-77928 | 7.1 | — | MacWarrior | clipbucket-v5 | CWE-89 | ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endp… |
| CVE-2026-81505 | 7.1 | — | frain-dev | convoy | CWE-639 | Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials |
| CVE-2026-93594 | 7.1 | — | ArcadeData | arcadedb | CWE-863 | ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries |
| CVE-2026-93595 | 7.1 | — | ArcadeData | arcadedb | CWE-862 | ArcadeDB before 26.9.1 ACL Bypass via query_database Tool |
| CVE-2026-93598 | 7.1 | — | ArcadeData | arcadedb | CWE-184 | ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle |
| CVE-2026-93660 | 7.1 | — | dataease | SQLBot | CWE-639 | SQLBot through 1.10.1 Improper Access Control via Dashboard Update |
| CVE-2026-93737 | 7.1 | — | azkaban | azkaban | CWE-862 | Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet |
| CVE-2026-93763 | 7.1 | — | MongoDB Inc. | Mongoid | CWE-312 | Silent plaintext persistence via unresolved callable database name in encrypt… |
| CVE-2026-93764 | 7.1 | — | MongoDB Inc. | Mongoid | CWE-312 | Plaintext storage of encrypted fields via skipped embedded models in encrypti… |
| CVE-2026-93852 | 7.1 | — | OpenStack | Blazar | CWE-862 | In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/le… |
| CVE-2026-7006 | 7.0 | — | Sublime HQ Pty Ltd | Sublime Text 4 | CWE-494 | Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism |
| CVE-2026-57223 | 7.0 | — | OISF | suricata | CWE-428 | Suricata windows: unquoted LocalSystem service ImagePath can allow local priv… |
| CVE-2026-63349 | 7.0 | — | agronholm | anyio | CWE-266 | AnyIO run_process/open_process ignores extra_groups and can retain parent sup… |
| CVE-2026-73863 | 7.0 | — | nanomq | nanomq | CWE-125 | NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRI… |
| CVE-2026-81305 | 7.0 | — | CareCam | HMT.CM2507 Firmware | CWE-829 | CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere |
| CVE-2026-63646 | 6.9 | — | 1Panel-dev | CordysCRM | CWE-200 | CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users |
| CVE-2026-77396 | 6.9 | — | pjsip | pjproject | CWE-122 | PJSIP: Heap buffer overflow in the AVI parser |
| CVE-2026-77960 | 6.9 | — | Bransys | ELD | CWE-798 | Use of Hard-coded Credentials in Bransys ELD |
| CVE-2026-93338 | 6.9 | — | Grandstream Networks | GWN7660ELR | CWE-1188 | Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Com… |
| CVE-2026-93559 | 6.9 | — | Forget-C | Jellyfish AI Short Drama Studio | CWE-287 | Forget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing auth… |
| CVE-2026-93604 | 6.9 | — | patriksimek | vm2 | CWE-284 | vm2 3.11.8 Sandbox Escape via crypto.setFips |
| CVE-2026-93751 | 6.9 | — | garycourt | uri-js | CWE-176 | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars |
| CVE-2026-61722 | 6.8 | — | FluidSynth | fluidsynth | CWE-190 | FluidSynth: DLS Articulation Chunk Integer Overflow |
| CVE-2026-61723 | 6.8 | — | FluidSynth | fluidsynth | CWE-190 | FluidSynth: DLS ptbl Chunk Integer Overflow |
| CVE-2026-61794 | 6.8 | — | projectcapsule | capsule | CWE-20 | Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation an… |
| CVE-2026-61795 | 6.8 | — | projectcapsule | capsule | CWE-697 | Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, al… |
| CVE-2026-64847 | 6.8 | — | agronholm | anyio | CWE-770 | AnyIO process-pool workers can block indefinitely on undrained stderr |
| CVE-2026-75883 | 6.8 | — | PPP Project | ppp | CWE-122 | PPPD buffer overflow in PEAP response code |
| CVE-2026-76900 | 6.8 | — | 1Panel-dev | CordysCRM | CWE-918 | CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Valid… |
| CVE-2026-77875 | 6.8 | — | QUANTUMTECH LTD | Hide Photos - Secure vault | CWE-922 | Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet… |
| CVE-2026-93689 | 6.8 | — | winfsp | winfsp | CWE-476 | WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O |
| CVE-2026-81627 | 6.7 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Qemu-kvm: vapic writable rom alias can escape the option-rom window and expos… |
| CVE-2026-81946 | 6.7 | — | PLANET Technology Corp. | PLANET IGS-5225-8P2T4S V1 | CWE-121 | PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm |
| CVE-2025-33141 | 6.5 | — | IBM | QRadar | CWE-497 | IBM QRadar SIEM could allow an authenticated user to obtain sensitive informa… |
| CVE-2026-11549 | 6.5 | — | IBM | CICS TX Advanced | CWE-284 | Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh… |
| CVE-2026-11710 | 6.5 | — | IBM | WebSphere Application Server | CWE-444 | IBM WebSphere Application Server is affected by an HTTP request smuggling vul… |
| CVE-2026-11711 | 6.5 | — | IBM | WebSphere Application Server | CWE-502 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-54147 | 6.5 | — | http4k | http4k | CWE-327 | http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not … |
| CVE-2026-57224 | 6.5 | — | OISF | suricata | CWE-400 | Suricata dhcp: unbounded transactions in unidirectional traffic can lead to r… |
| CVE-2026-59156 | 6.5 | — | AcademySoftwareFoundation | OpenImageIO | CWE-674 | OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow |
| CVE-2026-61670 | 6.5 | — | superradcompany | microsandbox | CWE-214 | microsandbox: Secret values exposed in world-readable process arguments |
| CVE-2026-61822 | 6.5 | — | pgpartman | pg_partman | CWE-703 | pg_partman disable maintenance for all partition sets |
| CVE-2026-62282 | 6.5 | — | opencve | opencve | CWE-918 | OpenCVE: Server-Side Request Forgery (SSRF) in notifications |
| CVE-2026-71537 | 6.5 | — | Paymenter | Paymenter | CWE-362 | Paymenter: Credit-refund double-spend race condition in service downgrade (do… |
| CVE-2026-77386 | 6.5 | — | zoriya | Kyoo | CWE-601 | Kyoo: OIDC login token can be redirected to an attacker-controlled URL |
| CVE-2026-84451 | 6.5 | — | strukturag | libheif | CWE-125 | libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an ou… |
| CVE-2026-93561 | 6.5 | — | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-1035 | Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned t… |
| CVE-2026-93562 | 6.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer… |
| CVE-2026-93566 | 6.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-http: netty: http request smuggling due to control chara… |
| CVE-2026-93573 | 6.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-444 | Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-… |
| CVE-2026-93574 | 6.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-444 | Io.netty/netty-codec-http: netty: http request smuggling via post-digit white… |
| CVE-2026-93579 | 6.5 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-http2: netty: http/2 header field values are not validat… |
| CVE-2026-18869 | 6.4 | — | IBM | i | CWE-918 | IBM i is Affected By Denial of Service and Security Restriction Bypass Vulner… |
| CVE-2026-81623 | 6.3 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-93589 | 6.3 | — | ImageMagick | ImageMagick | CWE-369 | ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder |
| CVE-2026-93590 | 6.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder |
| CVE-2026-93840 | 6.3 | — | vllm-project | vllm | CWE-129 | vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids |
| CVE-2026-93841 | 6.3 | — | vllm-project | vllm | CWE-129 | vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated… |
| CVE-2026-61720 | 6.2 | — | FluidSynth | fluidsynth | CWE-191 | FluidSynth: SF2 DMOD Chunk Unsigned Underflow |
| CVE-2025-36147 | 6.1 | — | IBM | Financial Transaction Manager for SWIFT Services for Multiplatforms | CWE-79 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vu… |
| CVE-2026-1025 | 6.1 | — | IBM | Common Licensing | CWE-79 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-1031 | 6.1 | — | IBM | Common Licensing | CWE-79 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-1037 | 6.1 | — | IBM | Common Licensing | CWE-79 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-59181 | 6.1 | — | AcademySoftwareFoundation | OpenImageIO | CWE-121 | OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked… |
| CVE-2026-59956 | 6.1 | — | AcademySoftwareFoundation | OpenImageIO | CWE-125 | OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is… |
| CVE-2026-77606 | 6.1 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-79 | Semantic MediaWiki has reflected XSS in Special:Ask plain table headers |
Results continue: ranks 401–514.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-18 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.