Security Box Score — September 18, 2026 — page 2
Edition of September 18, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-77607 | 6.1 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-79 | Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS |
| CVE-2026-77608 | 6.1 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-79 | Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property… |
| CVE-2026-77609 | 6.1 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-601 | Semantic MediaWiki has an open redirect in Special:URIResolver |
| CVE-2026-77610 | 6.1 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-79 | Semantic MediaWiki has a query debug output XSS (`DebugFormatter`) |
| CVE-2026-77616 | 6.1 | — | SemanticMediaWiki | SemanticMediaWiki | CWE-79 | Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cu… |
| CVE-2026-79294 | 6.1 | — | n/a | n/a | CWE-79 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-… |
| CVE-2026-84992 | 6.1 | — | imzbf | md-editor-v3 | CWE-79 | md-editor-v3: XSS via fenced-code language rendering bypass |
| CVE-2026-85271 | 6.1 | — | openedx | openedx-platform | CWE-79 | Open edX Platform: Stored CSS Injection in Email Digest Notifications via Uns… |
| CVE-2026-91202 | 6.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-61 | Cockpit-files: cockpit-files: arbitrary file ownership change via symlink fol… |
| CVE-2026-93432 | 6.1 | — | Red Hat | Exploit Intelligence | CWE-79 | Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection v… |
| CVE-2026-91203 | 6.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-363 | Cockpit-files: cockpit-files: arbitrary file ownership and permission modific… |
| CVE-2026-91205 | 6.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-363 | Cockpit-files: cockpit-files: local attacker can hijack file ownership via sy… |
| CVE-2024-56344 | 5.9 | — | IBM | Cognos Analytics | CWE-327 | IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vuln… |
| CVE-2025-33147 | 5.9 | — | IBM | Cognos Analytics | CWE-327 | IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulne… |
| CVE-2025-36421 | 5.9 | — | IBM | Controller | CWE-319 | Multiple vulnerabilities in IBM Controller |
| CVE-2026-10832 | 5.9 | — | Red Hat | Cryostat 4 | CWE-770 | Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wil… |
| CVE-2026-63405 | 5.9 | — | anycable | anycable | CWE-345 | AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Re… |
| CVE-2026-63406 | 5.9 | — | anycable | anycable | CWE-312 | AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Tra… |
| CVE-2026-63448 | 5.9 | — | OISF | suricata | CWE-400 | Suricata smb: some SMB flows can cause resource exhaustion |
| CVE-2026-71855 | 5.9 | — | OISF | suricata | CWE-697 | Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state |
| CVE-2026-82890 | 5.9 | — | IBM | Guardium Data Protection | CWE-79 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-91147 | 5.9 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-617 | Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling … |
| CVE-2026-93578 | 5.9 | — | Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | CWE-1035 | Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) chec… |
| CVE-2026-93602 | 5.9 | — | rustls | webpki | CWE-299 | rustls-webpki before 0.103.10 CRL Revocation Check Bypass |
| CVE-2026-76901 | 5.8 | — | 1Panel-dev | CordysCRM | CWE-639 | CordysCRM: Broken object-level authorization in lead pool and account pool de… |
| CVE-2026-76899 | 5.7 | — | 1Panel-dev | CordysCRM | CWE-89 | CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool… |
| CVE-2026-63420 | 5.5 | — | AcademySoftwareFoundation | OpenImageIO | CWE-125 | OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row` |
| CVE-2026-63635 | 5.5 | — | AcademySoftwareFoundation | OpenImageIO | CWE-125 | OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read… |
| CVE-2026-65969 | 5.5 | — | AcademySoftwareFoundation | OpenImageIO | CWE-125 | OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV |
| CVE-2026-92768 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-214 | Cockpit-machines: cockpit-machines: sensitive data exposure via command-line … |
| CVE-2026-93653 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-606 | Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill vi… |
| CVE-2025-36178 | 5.4 | — | IBM | Controller | CWE-1284 | Multiple vulnerabilities in IBM Controller |
| CVE-2026-1029 | 5.4 | — | IBM | Common Licensing | CWE-79 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-17262 | 5.4 | — | IBM | i | CWE-78 | IBM i is Affected By Denial of Service and Security Restriction Bypass Vulner… |
| CVE-2026-93685 | 5.4 | — | Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | CWE-200 | Multicluster-observability-addon: multicluster-observability-addon: possible … |
| CVE-2025-1350 | 5.3 | — | IBM | Controller | CWE-209 | Multiple vulnerabilities in IBM Controller |
| CVE-2025-13882 | 5.3 | — | IBM | Sterling Partner Engagement Manager Essentials Edition | CWE-799 | Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager. |
| CVE-2026-11539 | 5.3 | — | IBM | WebSphere Application Server | CWE-306 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-11540 | 5.3 | — | IBM | WebSphere Application Server | CWE-863 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-52745 | 5.3 | — | 1Panel-dev | CordysCRM | CWE-89 | CordysCRM: Customer Public Pool Sorting Field SQL Injection |
| CVE-2026-57222 | 5.3 | — | OISF | suricata | CWE-697 | Suricata ippair: hash collision can cause incorrect state reuse across IPv4 a… |
| CVE-2026-57229 | 5.3 | — | OISF | suricata | CWE-665 | Suricata smtp/mime: incomplete state reset allows detection bypass |
| CVE-2026-65970 | 5.3 | — | AcademySoftwareFoundation | OpenImageIO | CWE-825 | OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::… |
| CVE-2026-69186 | 5.3 | — | c-ares | c-ares | CWE-400 | c-ares: Memory-amplification denial of service via unvalidated DNS header rec… |
| CVE-2026-77528 | 5.3 | — | crossbario | autobahn-python | CWE-409 | Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after infla… |
| CVE-2026-93492 | 5.3 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-1035 | Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size |
| CVE-2026-93504 | 5.3 | — | n/a | SveltyCMS | CWE-266 | SveltyCMS User Attribute Update Endpoint +server.ts access control |
| CVE-2026-93506 | 5.3 | — | n/a | SveltyCMS | CWE-918 | SveltyCMS File Upload Endpoint upload-media server-side request forgery |
| CVE-2026-93533 | 5.3 | — | spatie | Scotty | CWE-77 | spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection |
| CVE-2026-93534 | 5.3 | — | spatie | Scotty | CWE-494 | spatie Scotty Self Update SelfUpdater.php update code download |
| CVE-2026-93596 | 5.3 | — | ArcadeData | arcadedb | CWE-862 | ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect |
| CVE-2026-93597 | 5.3 | — | ArcadeData | arcadedb | CWE-918 | ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses |
| CVE-2026-93736 | 5.3 | — | mealie-recipes | mealie | CWE-639 | Mealie before 3.21.0 Information Disclosure via Ratings Endpoint |
| CVE-2026-93869 | 5.3 | — | Cotonti | Cotonti | CWE-601 | Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex |
| CVE-2026-93870 | 5.3 | — | Cotonti | Cotonti | CWE-352 | Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX H… |
| CVE-2026-93873 | 5.3 | — | Cotonti | Cotonti | CWE-352 | Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin |
| CVE-2026-93921 | 5.3 | — | siyuan-note | siyuan | CWE-862 | SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint |
| CVE-2026-77339 | 5.1 | — | F1bonacc1 | process-compose | CWE-306 | Process Compose: Browser DNS rebinding lets websites control local process-co… |
| CVE-2026-93505 | 5.1 | — | n/a | SveltyCMS | CWE-79 | SveltyCMS SVG Media Upload media-service.server.ts cross site scripting |
| CVE-2026-93871 | 5.1 | — | Cotonti | Cotonti | CWE-601 | Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix |
| CVE-2026-76902 | 5.0 | — | 1Panel-dev | CordysCRM | CWE-306 | CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview… |
| CVE-2026-92745 | 5.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-214 | Cockpit-machines: cockpit-machines: information disclosure of rhsm offline to… |
| CVE-2026-92747 | 5.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-214 | Cockpit-machines: cockpit-machines: sensitive data exposure of guest credenti… |
| CVE-2026-11548 | 4.8 | — | IBM | CICS TX Advanced | CWE-444 | Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh… |
| CVE-2026-11722 | 4.8 | — | IBM | CICS TX Advanced | CWE-444 | Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh… |
| CVE-2026-28199 | 4.8 | — | Cohesity | NetBackup Flex OS | CWE-347 | Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell |
| CVE-2026-93587 | 4.8 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder |
| CVE-2026-16515 | 4.7 | — | zephyrproject | zephyr | CWE-406 | ICMPv6 error messages sent for multicast-destined packets and non-unique sour… |
| CVE-2026-25684 | 4.4 | — | Zscaler | ZIA File Type Control | CWE-20 | File Type Control rule bypass |
| CVE-2025-36045 | 4.3 | — | IBM | TS4300 | CWE-799 | TS4300 Tape Library addresses security vulnerability |
| CVE-2025-36076 | 4.3 | — | IBM | Cognos Analytics | CWE-540 | IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulne… |
| CVE-2026-1030 | 4.3 | — | IBM | Common Licensing | CWE-209 | Multiple vulnerabilities affect IBM License Key Server Administration and Rep… |
| CVE-2026-11537 | 4.3 | — | IBM | WebSphere Application Server | CWE-650 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-16514 | 4.3 | — | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in gPTP Announce path-trace validation via unvalidated ste… |
| CVE-2026-77385 | 4.3 | — | zoriya | Kyoo | CWE-639 | Kyoo: Transcoder serves uncataloged files from the media directory |
| CVE-2026-84450 | 4.3 | — | strukturag | libheif | CWE-617 | libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction… |
| CVE-2026-85272 | 4.3 | — | openedx | openedx-platform | CWE-22 | Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path V… |
| CVE-2026-10841 | 4.2 | — | IBM | CICS TX Advanced | CWE-444 | Multiple security vulnerabilities may affect IBM WebSphere Liberty that is sh… |
| CVE-2026-77568 | 4.2 | — | mojolicious | mojo | CWE-200 | Mojolicious: CSRF tokens are vulnerable to BREACH attacks |
| CVE-2026-81182 | 4.2 | — | Syslifters | sysreptor | CWE-639 | SysReptor: Unauthorized file disclosure by broken access control in writable … |
| CVE-2026-85511 | 4.2 | — | Red Hat | Red Hat JBoss Enterprise Application Platform 7 | CWE-290 | Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2 |
| CVE-2026-84448 | 4.0 | — | strukturag | libheif | CWE-125 | libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_regi… |
| CVE-2026-11538 | 3.7 | — | IBM | WebSphere Application Server | CWE-117 | IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected … |
| CVE-2026-11545 | 3.7 | — | IBM | WebSphere Application Server | CWE-862 | IBM WebSphere Application Server is affected by a privilege escalation |
| CVE-2026-44639 | 3.7 | — | nanomq | nanomq | CWE-407 | NanoMQ: O(N²) Denial of Service in MQTT v5 Property Parsing |
| CVE-2026-57226 | 3.7 | — | OISF | suricata | CWE-122 | Suricata swf: heap buffer overflow in SWF decompression depth handling |
| CVE-2026-63449 | 3.7 | — | OISF | suricata | CWE-197 | Suricata sip: large SIP message bodies can evade detection with frame keyword |
| CVE-2026-63450 | 3.7 | — | OISF | suricata | CWE-755 | Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer de… |
| CVE-2026-81181 | 3.7 | — | Syslifters | sysreptor | CWE-384 | SysReptor: Session Fixation in Password-Protected Shared Notes |
| CVE-2026-84449 | 3.7 | — | strukturag | libheif | CWE-125 | libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV |
| CVE-2026-91142 | 3.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress… |
| CVE-2026-81178 | 3.5 | — | Syslifters | sysreptor | CWE-863 | SysReptor: Anonymous note-share link discloses project member identities and … |
| CVE-2026-57225 | 3.3 | — | OISF | suricata | CWE-476 | Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading |
| CVE-2026-63451 | 3.3 | — | OISF | suricata | CWE-122 | Suricata detect: frame rules without content and with transform can cause hea… |
| CVE-2026-93676 | 3.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-284 | Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses pat… |
| CVE-2026-16512 | 3.1 | — | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethern… |
| CVE-2026-21806 | 3.1 | — | HCL Software | HCL BigFix Service Management | CWE-557 | HCL BigFix Service Management was affected with Admin Session Concurrency vul… |
| CVE-2026-93650 | 2.9 | — | n/a | Saleor | CWE-307 | Saleor throttling.py get_client_ip excessive authentication |
| CVE-2026-85478 | 2.4 | — | CareCam | HMT.CM2507 Firmware | CWE-306 | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-84400 | 2.3 | — | CareCam | HMT.CM2507 Firmware | CWE-306 | CareCam CM2507 Missing Authentication for Critical Function |
| CVE-2026-93588 | 2.3 | — | ImageMagick | ImageMagick | CWE-476 | ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM |
| CVE-2026-93894 | 2.3 | — | Vinyl-Cache | Vinyl Cache | CWE-787 | In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was foun… |
| CVE-2026-93531 | 2.1 | — | gedelumbung | HospitalManagement | CWE-352 | gedelumbung HospitalManagement cross-site request forgery |
| CVE-2026-93532 | 2.1 | — | gedelumbung | HospitalManagement | CWE-287 | gedelumbung HospitalManagement Password Change password.php simpan improper a… |
| CVE-2026-93586 | 2.1 | — | ImageMagick | ImageMagick | CWE-416 | ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob |
| CVE-2026-93600 | 2.1 | — | rustls | webpki | CWE-295 | rustls webpki Name Constraints URI Validation Bypass |
| CVE-2026-93601 | 2.1 | — | rustls | webpki | CWE-295 | rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass |
| CVE-2026-61633 | 2.0 | — | nanomq | nanomq | CWE-835 | NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS |
| CVE-2026-75892 | await | — | Osmocom | osmo-ggsn | CWE-787 | Out of bounds write in PDP ctx GSN-Address decode |
| CVE-2026-75893 | await | — | Osmocom | osmo-bsc | CWE-122 | Heap based buffer overflow at ipaccess_proxy_read_msg() |
| CVE-2026-75894 | await | — | Osmocom | osmo-iuh | CWE-617 | Reachable assertion at ranap_handle_co_dt() |
| CVE-2026-75895 | await | — | Osmocom | libsmpp34 | CWE-125 | Out of bounds read at smpp34_unpack() |
| CVE-2026-88623 | await | — | n/a | n/a | — | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up… |
| CVE-2026-93018 | await | — | — | Imager | CWE-193 | Imager versions before 1.036 for Perl disclose uninitialised heap memory read… |