boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 18, 2026 · all times UTC← 2026-09-17 · archive

Security Box Score — September 18, 2026 — page 2

Edition of September 18, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–514 of 514
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-776076.1—SemanticMediaWikiSemanticMediaWikiCWE-79Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
CVE-2026-776086.1—SemanticMediaWikiSemanticMediaWikiCWE-79Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property…
CVE-2026-776096.1—SemanticMediaWikiSemanticMediaWikiCWE-601Semantic MediaWiki has an open redirect in Special:URIResolver
CVE-2026-776106.1—SemanticMediaWikiSemanticMediaWikiCWE-79Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)
CVE-2026-776166.1—SemanticMediaWikiSemanticMediaWikiCWE-79Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cu…
CVE-2026-792946.1—n/an/aCWE-79Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-…
CVE-2026-849926.1—imzbfmd-editor-v3CWE-79md-editor-v3: XSS via fenced-code language rendering bypass
CVE-2026-852716.1—openedxopenedx-platformCWE-79Open edX Platform: Stored CSS Injection in Email Digest Notifications via Uns…
CVE-2026-912026.1—Red HatRed Hat Enterprise Linux 10CWE-61Cockpit-files: cockpit-files: arbitrary file ownership change via symlink fol…
CVE-2026-934326.1—Red HatExploit IntelligenceCWE-79Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection v…
CVE-2026-912036.0—Red HatRed Hat Enterprise Linux 10CWE-363Cockpit-files: cockpit-files: arbitrary file ownership and permission modific…
CVE-2026-912056.0—Red HatRed Hat Enterprise Linux 10CWE-363Cockpit-files: cockpit-files: local attacker can hijack file ownership via sy…
CVE-2024-563445.9—IBMCognos AnalyticsCWE-327IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vuln…
CVE-2025-331475.9—IBMCognos AnalyticsCWE-327IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulne…
CVE-2025-364215.9—IBMControllerCWE-319Multiple vulnerabilities in IBM Controller
CVE-2026-108325.9—Red HatCryostat 4CWE-770Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wil…
CVE-2026-634055.9—anycableanycableCWE-345AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Re…
CVE-2026-634065.9—anycableanycableCWE-312AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Tra…
CVE-2026-634485.9—OISFsuricataCWE-400Suricata smb: some SMB flows can cause resource exhaustion
CVE-2026-718555.9—OISFsuricataCWE-697Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state
CVE-2026-828905.9—IBMGuardium Data ProtectionCWE-79IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-911475.9—Red HatRed Hat Enterprise Linux 10CWE-617Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling …
CVE-2026-935785.9—Red HatRed Hat build of Apache Camel for Spring Boot 4CWE-1035Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) chec…
CVE-2026-936025.9—rustlswebpkiCWE-299rustls-webpki before 0.103.10 CRL Revocation Check Bypass
CVE-2026-769015.8—1Panel-devCordysCRMCWE-639CordysCRM: Broken object-level authorization in lead pool and account pool de…
CVE-2026-768995.7—1Panel-devCordysCRMCWE-89CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool…
CVE-2026-634205.5—AcademySoftwareFoundationOpenImageIOCWE-125OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row`
CVE-2026-636355.5—AcademySoftwareFoundationOpenImageIOCWE-125OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read…
CVE-2026-659695.5—AcademySoftwareFoundationOpenImageIOCWE-125OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV
CVE-2026-927685.5—Red HatRed Hat Enterprise Linux 10CWE-214Cockpit-machines: cockpit-machines: sensitive data exposure via command-line …
CVE-2026-936535.5—Red HatRed Hat Enterprise Linux 10CWE-606Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill vi…
CVE-2025-361785.4—IBMControllerCWE-1284Multiple vulnerabilities in IBM Controller
CVE-2026-10295.4—IBMCommon LicensingCWE-79Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-172625.4—IBMiCWE-78IBM i is Affected By Denial of Service and Security Restriction Bypass Vulner…
CVE-2026-936855.4—Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-200Multicluster-observability-addon: multicluster-observability-addon: possible …
CVE-2025-13505.3—IBMControllerCWE-209Multiple vulnerabilities in IBM Controller
CVE-2025-138825.3—IBMSterling Partner Engagement Manager Essentials EditionCWE-799Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.
CVE-2026-115395.3—IBMWebSphere Application ServerCWE-306IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-115405.3—IBMWebSphere Application ServerCWE-863IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-527455.3—1Panel-devCordysCRMCWE-89CordysCRM: Customer Public Pool Sorting Field SQL Injection
CVE-2026-572225.3—OISFsuricataCWE-697Suricata ippair: hash collision can cause incorrect state reuse across IPv4 a…
CVE-2026-572295.3—OISFsuricataCWE-665Suricata smtp/mime: incomplete state reset allows detection bypass
CVE-2026-659705.3—AcademySoftwareFoundationOpenImageIOCWE-825OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::…
CVE-2026-691865.3—c-aresc-aresCWE-400c-ares: Memory-amplification denial of service via unvalidated DNS header rec…
CVE-2026-775285.3—crossbarioautobahn-pythonCWE-409Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after infla…
CVE-2026-934925.3—Red HatRed Hat AMQ Broker 7CWE-1035Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size
CVE-2026-935045.3—n/aSveltyCMSCWE-266SveltyCMS User Attribute Update Endpoint +server.ts access control
CVE-2026-935065.3—n/aSveltyCMSCWE-918SveltyCMS File Upload Endpoint upload-media server-side request forgery
CVE-2026-935335.3—spatieScottyCWE-77spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection
CVE-2026-935345.3—spatieScottyCWE-494spatie Scotty Self Update SelfUpdater.php update code download
CVE-2026-935965.3—ArcadeDataarcadedbCWE-862ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect
CVE-2026-935975.3—ArcadeDataarcadedbCWE-918ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses
CVE-2026-937365.3—mealie-recipesmealieCWE-639Mealie before 3.21.0 Information Disclosure via Ratings Endpoint
CVE-2026-938695.3—CotontiCotontiCWE-601Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex
CVE-2026-938705.3—CotontiCotontiCWE-352Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX H…
CVE-2026-938735.3—CotontiCotontiCWE-352Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin
CVE-2026-939215.3—siyuan-notesiyuanCWE-862SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint
CVE-2026-773395.1—F1bonacc1process-composeCWE-306Process Compose: Browser DNS rebinding lets websites control local process-co…
CVE-2026-935055.1—n/aSveltyCMSCWE-79SveltyCMS SVG Media Upload media-service.server.ts cross site scripting
CVE-2026-938715.1—CotontiCotontiCWE-601Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix
CVE-2026-769025.0—1Panel-devCordysCRMCWE-306CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview…
CVE-2026-927455.0—Red HatRed Hat Enterprise Linux 10CWE-214Cockpit-machines: cockpit-machines: information disclosure of rhsm offline to…
CVE-2026-927475.0—Red HatRed Hat Enterprise Linux 10CWE-214Cockpit-machines: cockpit-machines: sensitive data exposure of guest credenti…
CVE-2026-115484.8—IBMCICS TX AdvancedCWE-444Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh…
CVE-2026-117224.8—IBMCICS TX AdvancedCWE-444Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh…
CVE-2026-281994.8—CohesityNetBackup Flex OSCWE-347Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell
CVE-2026-935874.8—ImageMagickImageMagickCWE-400ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder
CVE-2026-165154.7—zephyrprojectzephyrCWE-406ICMPv6 error messages sent for multicast-destined packets and non-unique sour…
CVE-2026-256844.4—ZscalerZIA File Type ControlCWE-20File Type Control rule bypass
CVE-2025-360454.3—IBMTS4300CWE-799TS4300 Tape Library addresses security vulnerability
CVE-2025-360764.3—IBMCognos AnalyticsCWE-540IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulne…
CVE-2026-10304.3—IBMCommon LicensingCWE-209Multiple vulnerabilities affect IBM License Key Server Administration and Rep…
CVE-2026-115374.3—IBMWebSphere Application ServerCWE-650IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-165144.3—zephyrprojectzephyrCWE-125Out-of-bounds read in gPTP Announce path-trace validation via unvalidated ste…
CVE-2026-773854.3—zoriyaKyooCWE-639Kyoo: Transcoder serves uncataloged files from the media directory
CVE-2026-844504.3—strukturaglibheifCWE-617libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction…
CVE-2026-852724.3—openedxopenedx-platformCWE-22Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path V…
CVE-2026-108414.2—IBMCICS TX AdvancedCWE-444Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh…
CVE-2026-775684.2—mojoliciousmojoCWE-200Mojolicious: CSRF tokens are vulnerable to BREACH attacks
CVE-2026-811824.2—SyslifterssysreptorCWE-639SysReptor: Unauthorized file disclosure by broken access control in writable …
CVE-2026-855114.2—Red HatRed Hat JBoss Enterprise Application Platform 7CWE-290Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2
CVE-2026-844484.0—strukturaglibheifCWE-125libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_regi…
CVE-2026-115383.7—IBMWebSphere Application ServerCWE-117IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected …
CVE-2026-115453.7—IBMWebSphere Application ServerCWE-862IBM WebSphere Application Server is affected by a privilege escalation
CVE-2026-446393.7—nanomqnanomqCWE-407NanoMQ: O(N²) Denial of Service in MQTT v5 Property Parsing
CVE-2026-572263.7—OISFsuricataCWE-122Suricata swf: heap buffer overflow in SWF decompression depth handling
CVE-2026-634493.7—OISFsuricataCWE-197Suricata sip: large SIP message bodies can evade detection with frame keyword
CVE-2026-634503.7—OISFsuricataCWE-755Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer de…
CVE-2026-811813.7—SyslifterssysreptorCWE-384SysReptor: Session Fixation in Password-Protected Shared Notes
CVE-2026-844493.7—strukturaglibheifCWE-125libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV
CVE-2026-911423.6—Red HatRed Hat Enterprise Linux 10CWE-787Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress…
CVE-2026-811783.5—SyslifterssysreptorCWE-863SysReptor: Anonymous note-share link discloses project member identities and …
CVE-2026-572253.3—OISFsuricataCWE-476Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading
CVE-2026-634513.3—OISFsuricataCWE-122Suricata detect: frame rules without content and with transform can cause hea…
CVE-2026-936763.2—Red HatRed Hat Enterprise Linux 10CWE-284Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses pat…
CVE-2026-165123.1—zephyrprojectzephyrCWE-125Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethern…
CVE-2026-218063.1—HCL SoftwareHCL BigFix Service ManagementCWE-557HCL BigFix Service Management was affected with Admin Session Concurrency vul…
CVE-2026-936502.9—n/aSaleorCWE-307Saleor throttling.py get_client_ip excessive authentication
CVE-2026-854782.4—CareCamHMT.CM2507 FirmwareCWE-306CareCam CM2507 Missing Authentication for Critical Function
CVE-2026-844002.3—CareCamHMT.CM2507 FirmwareCWE-306CareCam CM2507 Missing Authentication for Critical Function
CVE-2026-935882.3—ImageMagickImageMagickCWE-476ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM
CVE-2026-938942.3—Vinyl-CacheVinyl CacheCWE-787In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was foun…
CVE-2026-935312.1—gedelumbungHospitalManagementCWE-352gedelumbung HospitalManagement cross-site request forgery
CVE-2026-935322.1—gedelumbungHospitalManagementCWE-287gedelumbung HospitalManagement Password Change password.php simpan improper a…
CVE-2026-935862.1—ImageMagickImageMagickCWE-416ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob
CVE-2026-936002.1—rustlswebpkiCWE-295rustls webpki Name Constraints URI Validation Bypass
CVE-2026-936012.1—rustlswebpkiCWE-295rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass
CVE-2026-616332.0—nanomqnanomqCWE-835NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS
CVE-2026-75892await—Osmocomosmo-ggsnCWE-787Out of bounds write in PDP ctx GSN-Address decode
CVE-2026-75893await—Osmocomosmo-bscCWE-122Heap based buffer overflow at ipaccess_proxy_read_msg()
CVE-2026-75894await—Osmocomosmo-iuhCWE-617Reachable assertion at ranap_handle_co_dt()
CVE-2026-75895await—Osmocomlibsmpp34CWE-125Out of bounds read at smpp34_unpack()
CVE-2026-88623await—n/an/a—NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up…
CVE-2026-93018await——ImagerCWE-193Imager versions before 1.036 for Perl disclose uninitialised heap memory read…