boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, September 20, 2026 · all times UTC← 2026-09-19 · archive

Security Box Score — September 20, 2026

105 CVEs published, led by SourceCodester (10).

105 CVEs published September 20, 2026: 12 critical, 17 high, 43 medium, 33 low; 0 in the KEV catalog at press time; 3 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 80 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1054345485——
KEV catalog size1716

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2863 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15075597526251371211560.17.8.0017+245 ▲
microsoft10002899204198469516289301.07.8.0044+533 ▲
google5162682331104811821218090.37.5.0025+445 ▲
red hat1567824432437440200.06.6.0028-31 ▼
apple24656367165317148881.46.5.0020+208 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0021-14 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+51 ▲
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0045+8 ▲
ivanti10246162025520.88.8.0147+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache93605140253195153320.37.5.0049-17 ▼
mozilla11330081118670900.08.8.0026+54 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+2 ▲
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+1 ▲
wordpress0513102240.08.8.3120-2 ▼
go440211000.05.9.0029+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0034-255 ▼
ibm29791618341530513610.17.5.0030-77 ▼
adobe17177757344366102040.57.5.0023+111 ▲
progress3641539100611.68.1.0035-16 ▼
solarwinds1241743010416.79.1.0058+1 ▲
veeam01961030100.08.6.0032-10 ▼
zohocorp7173860000.07.7.0106+3 ▲
atlassian3918001300.07.6.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link257020261212300.08.5.0154+9 ▲
siemens1552633103000.07.3.0018-4 ▼
synology1946510256000.05.6.0027+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
abb181430000.07.2.0018+1 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1773482616613323210.37.2.0021+121 ▲
sourcecodester582270013493000.05.5.0028+23 ▲
spring017013608215000.06.5.00240
nvidia3216620117290000.07.8.0029+8 ▲
mongodb64162694584100.07.1.0026+32 ▲
itsourcecode361520037115000.02.1.0026+17 ▲
wwbn1061462349740000.06.9.0024+104 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0029+126 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.145696.510.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-86218.074994.210.0
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
CVE-2026-76698.041190.36.5
CVE-2026-47864.040890.29.8
CVE-2026-17176.035988.97.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1456KEV
CVE-2026-8621810.0.0749KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8245610.0.0139
Most disclosures (vendor)
VendorCVEs
linux1885
microsoft1008
google847
oracle635
ibm313
apple250
adobe212
red hat196
dell193
apache130
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
ivanti5
adobe4
berriai4
jfrog4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist41
npm20
PyPI13
crates.io3
RubyGems2
Go1
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
CVE-2026-82078PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171768
CVE-2021-27102n/a2021-11-171768
CVE-2021-27101n/a2021-11-171768
CVE-2021-27103n/a2021-11-171768
CVE-2021-21017Adobe2021-11-171768
CVE-2021-28550Adobe2021-11-171768
CVE-2021-42013Apache Software Foundation2021-11-171768
CVE-2021-41773Apache Software Foundation2021-11-171768
CVE-2021-30858Apple2021-11-171768
CVE-2021-30860Apple2021-11-171768

Transactions

EXPLOIT PUBLISHED — grokability snipe-it: 5 CVEs (CVE-2026-86754, CVE-2026-86759, CVE-2026-86764, CVE-2026-86769, CVE-2026-86774). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-87963 (Unknown Yo). Public exploit reference added.

DUE DATE PASSED — CVE-2026-58704 (Google Android). CISA remediation deadline was September 19, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-76460 (Cisco Identity Services Engine Software). CISA remediation deadline was September 19, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-87886 (Acronis Backup plugin for cPanel & WHM). CISA remediation deadline was September 19, 2026; still in catalog.

PATCH SHIPPED — CVE-2026-12564 (Red Hat Ansible Automation Platform 2.7). Fixed in Red Hat Ansible Automation Platform 2.7 1788918363.

PATCH SHIPPED — CVE-2026-32551 (DiviNext Woo Essential). Fixed in Woo Essential 4.3.1.

PATCH SHIPPED — CVE-2026-42784 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 0.3.2-4.hum1.

PATCH SHIPPED — CVE-2026-71576 (Red Hat Multicluster Global Hub 1.4.9). Fixed in Multicluster Global Hub 1.4.9 1788355599.

PATCH SHIPPED — CVE-2026-81796 (WEN Solutions WP Travel). Fixed in WP Travel 12.0.4.

Yesterday's Results

How to read these box scores · glossary

105 CVEs published. 25 box scores, 80 table rows — nothing truncated.

D-Link R95 DHMAPI ssi system os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0217   81.5     —
AFFECTED
  Product  Versions          Fixed
  R95      BE9500_1.00.16 –  —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    5.1   .0157   74.3     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
aiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    5.1   .0157   74.3     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
aiyiyi121 SxDevOps Command services.py generate_host_task command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   L   L   L    5.1   .0073   52.6     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
n/a Kamailio — Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0053   43.7     —
AFFECTED
  Product   Versions  Fixed
  Kamailio  5.8.0 –   6.0.8
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-119, CWE-122 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
ZTE SmartLife — A password reset vulnerability in ZTE SmartLife APP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0045   38.1     —
AFFECTED
  Product    Versions                                   Fixed
  SmartLife  ZTE_SL_V2.8.2_ABROAD and prior versions –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 20  Published (CNA: zte)
CWE-269 · CNA: zte · CVSS v3.1 · 1 reference · NVD status: Received
Dromara UJCMS UserController UserController.java usernameExist improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0042   35.9     —
AFFECTED
  Product  Versions  Fixed
  UJCMS    12.3.0 –  —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
OISF Suricata — Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0040   34.2     —
AFFECTED
  Product   Versions  Fixed
  Suricata  8.0.0 –   —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 20  Published (CNA: mitre)
CWE-843 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
OISF Suricata — Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules th…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  L    9.4   .0040   34.2     —
AFFECTED
  Product   Versions     Fixed
  Suricata  unspecified  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 20  Published (CNA: mitre)
CWE-416 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Received
code-projects Assessment Management User Editing edit-user.php cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   N   L   N    1.9   .0037   30.6     —
AFFECTED
  Product                Versions  Fixed
  Assessment Management  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
n/a Pixelfed — Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   N    2.1   .0037   30.4     —
AFFECTED
  Product   Versions  Fixed
  Pixelfed  0.12.0 –  0.12.10
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
SourceCodester Online Reviewer Management System btn_functions.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0036   29.3     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
SourceCodester Online Reviewer Management System btn_functions.php remove sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0033   26.2     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
aiyiyi121 SxDevOps settings.py information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0031   24.6     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
olivier-ls PHP-FTS Filter Matching SearchEngine.php matchesSingleFilter comparison
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0030   22.8     —
AFFECTED
  Product  Versions  Fixed
  PHP-FTS  1.1.0 –   1.1.4
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-697 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Received
aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0029   21.9     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-259, CWE-798 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
aiyiyi121 SxDevOps Settings settings.py hard-coded credentials
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .0029   21.9     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-259, CWE-798 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0027   19.9     —
AFFECTED
  Product              Versions  Fixed
  nginx-proxy-manager  2.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
SourceCodester Online Reviewer Management System btn_functions.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0027   18.8     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
ZTE SmartLife — A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  L    5.4   .0026   18.7     —
AFFECTED
  Product    Versions                                   Fixed
  SmartLife  ZTE_SL_V2.8.2_ABROAD and prior versions –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 20  Published (CNA: zte)
CWE-269 · CNA: zte · CVSS v3.1 · 1 reference · NVD status: Received
SourceCodester Online Reviewer Management System btn_functions.php remove sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0026   18.5     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   L   L    5.1   .0026   17.7     —
AFFECTED
  Product   Versions  Fixed
  SxDevOps  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-266, CWE-269 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
ZTE SmartLife — Hardcoded Key Vulnerability in ZTE SmartLife APP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   N  U  H  N  N    6.2   .0020   10.7     —
AFFECTED
  Product    Versions                                     Fixed
  SmartLife  ZTE_SL_V2.8.2_ABROAD and earlier versions –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 20  Published (CNA: zte)
CWE-798 · CNA: zte · CVSS v3.1 · 1 reference · NVD status: Received
itsourcecode Leave Management System controller.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0020   10.2     —
AFFECTED
  Product                  Versions  Fixed
  Leave Management System  1.0 –     —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 20  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
ZTE SmartLife — Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0020    9.7     —
AFFECTED
  Product    Versions                                   Fixed
  SmartLife  ZTE_SL_V2.8.2_ABROAD and prior versions –  —
TIMELINE
  Sep 8   Reserved by CNA
  Sep 20  Published (CNA: zte)
CWE-269 · CNA: zte · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-865513.36.8ZTENX741JCWE-668Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z…
CVE-2026-870678.56.7UnknownForminator FormsCWE-94Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection
CVE-2026-148446.84.8UnknownMaster SliderCWE-79Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Att…
CVE-2026-842236.84.8UnknownKirkiCWE-79Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload
CVE-2026-850177.54.6UnknownUnlimited Elements For ElementorCWE-502Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection
CVE-2026-816507.23.7UnknownPhoto Gallery, Sliders, Proofing and ThemesCWE-434NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import
CVE-2026-924232.73.7UnknownMeow GalleryCWE-200Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts
CVE-2026-878397.53.4UnknownTripzzyCWE-284Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion
CVE-2026-878405.33.4UnknownTripzzyCWE-284Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering
CVE-2026-828428.13.2UnknownSAML Single Sign OnCWE-269SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Accoun…
CVE-2026-925407.23.2UnknownImport and export users and customersCWE-269Import and export users and customers < 2.5.2 - Custom Role Privilege Escalat…
CVE-2026-925417.23.2UnknownImport and export users and customersCWE-269Import and export users and customers < 2.5.2 - Custom Role Privilege Escalat…
CVE-2026-870686.63.2UnknownForminator FormsCWE-269Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lea…
CVE-2026-816534.23.2UnknownPhoto Gallery, Sliders, Proofing and ThemesCWE-639NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via …
CVE-2026-165424.13.2UnknownImport and export users and customersCWE-918Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar
CVE-2026-929653.73.2UnknownTikTokCWE-862TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption
CVE-2026-816513.13.2UnknownPhoto Gallery, Sliders, Proofing and ThemesCWE-639NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification v…
CVE-2026-816543.13.2UnknownPhoto Gallery, Sliders, Proofing and ThemesCWE-639NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update
CVE-2026-816522.73.2UnknownPhoto Gallery, Sliders, Proofing and ThemesCWE-639NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR
CVE-2026-924226.51.0UnknownMeow GalleryCWE-345Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load…
CVE-2026-924104.30.8UnknownSign-up SheetsCWE-352Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF
CVE-2026-9409710.0—NetcoreNBR200V2CWE-77Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection
CVE-2026-908179.8—Vanderbilt UniversityREDCapCWE-73An unauthenticated Remote Code Execution vulnerability was found in the surve…
CVE-2026-888569.4—OrdaSoft.comOrdaSoft Joomla Gallery free extension for JoomlaCWE-94Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execu…
CVE-2026-888579.4—OrdaSoft.comOrdaSoft Joomla Gallery free extension for JoomlaCWE-434Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execu…
CVE-2026-940959.4—NetcoreNBR200V2CWE-77Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection
CVE-2026-940969.4—NetcoreNBR200V2CWE-77Netcore NBR200V2 LAN IP Configuration network_tools command injection
CVE-2026-888549.3—OrdaSoft.comOrdaSoft Joomla Gallery free extension for JoomlaCWE-89Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft J…
CVE-2026-940039.3—ComfastCF-N1-SCWE-119Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based …
CVE-2026-940899.3—D-LinkDIR-868LCWE-119D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based ov…
CVE-2026-941079.2—nivocartnivocartCWE-338NivoCart through 2.4.0 Predictable Administrator Password Reset Token
CVE-2026-941048.7—nivocartnivocartCWE-434NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager
CVE-2026-941068.7—james-heinrichgetid3CWE-78getID3 before 1.9.26 OS Command Injection via Unescaped Filenames
CVE-2026-941098.7—openequellaopenEQUELLACWE-1336openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Inj…
CVE-2026-888558.6—OrdaSoft.comOrdaSoft Joomla Gallery free extension for JoomlaCWE-89Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in …
CVE-2026-941088.3—james-heinrichgetid3CWE-611getID3 through 1.9.26 XML External Entity Injection via XML2array
CVE-2026-941127.6—mayswindezBookkeepingCWE-294mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack
CVE-2026-940367.4—D-LinkDIR-X1860CWE-266D-Link DIR-X1860/DIR-X1860Z routerd ubus access control
CVE-2026-941137.1—FrappeERPNextCWE-862Frappe ERPNext before 15.121.0 and 16.34.0 Missing Authorization in Timesheet…
CVE-2026-922546.9—WatchdogAnti-VirusCWE-20WatchDog Antivirus kernel driver arbitrary file deletion via unauthenticated …
CVE-2026-941056.9—nivocartnivocartCWE-754NivoCart through 2.4.0 Destructive Configuration Write via the Password Reset…
CVE-2026-941116.9—TencentBrowserSkillCWE-346Tencent BrowserSkill through 0.3.0 Origin Validation Error in Local WebSocket…
CVE-2026-922525.9—WatchDogAnti-VirusCWE-276Incorrect Default Permissions in WatchDog Anti-Virus Installation Directory
CVE-2026-939785.5—code-projectsInternship Management SystemCWE-74code-projects Internship Management System login.php sql injection
CVE-2026-939795.5—code-projectsInternship Management SystemCWE-74code-projects Internship Management System login.php sql injection
CVE-2026-939805.5—code-projectsInternship Management SystemCWE-74code-projects Internship Management System Admin Login Form login.php sql inj…
CVE-2026-939975.5—SourceCodesterDrug Recommendation SystemCWE-74SourceCodester Drug Recommendation System edit_symptom.php sql injection
CVE-2026-940045.5—n/aDedeCMSCWE-74DedeCMS mytag_js.php code injection
CVE-2026-940155.5—SourceCodesterDrug Recommendation SystemCWE-74SourceCodester Drug Recommendation System edit_user.php sql injection
CVE-2026-940385.5—NonceGeekdim-sum-appCWE-918NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side r…
CVE-2026-940395.5—vas3kTaxHackerCWE-918vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-sid…
CVE-2026-940405.5—vas3kTaxHackerCWE-918vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery
CVE-2026-940435.5—n/aFree5GCCWE-362Free5GC Gmm handler.go race condition
CVE-2026-940445.5—03-lovepreetSinghMCPCWE-2203-lovepreetSingh MCP route.ts create_file path traversal
CVE-2026-940505.3—D-LinkDIR-X1860ZCWE-200D-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information di…
CVE-2026-940905.3—JusticeRageManalyzeCWE-189JusticeRage Manalyze PE Parser pe.cpp _parse_debug integer underflow
CVE-2026-922535.2—WatchDogAnti-VirusCWE-59Arbitrary File Write via Directory Junction in WatchDog Anti-Virus Quarantine…
CVE-2026-940282.1—mealie-recipesMealieCWE-918mealie-recipes Mealie Recipe Action Trigger controller_group_recipe_actions.p…
CVE-2026-940312.1—0-Gaurav-0nexus-mcpCWE-740-Gaurav-0 nexus-mcp nexus_reauth MCP tool browser.ts child_process.exec comm…
CVE-2026-940322.1—itsourcecodeLeave Management SystemCWE-74itsourcecode Leave Management System index.php sql injection
CVE-2026-940352.1—SourceCodesterDrug Recommendation SystemCWE-79SourceCodester Drug Recommendation System index.php cross site scripting
CVE-2026-940372.1—00Kisumi00mcp-file-analyzerCWE-2200Kisumi00 mcp-file-analyzer analyze_csv_data MCP tool main.py ControlFlowNod…
CVE-2026-940412.1—AdithyaYellojuRestaurant-Management-SystemCWE-74AdithyaYelloju Restaurant-Management-System add_menu.php sql injection
CVE-2026-940422.1—AdithyaYellojuRestaurant Management SystemCWE-74AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql in…
CVE-2026-940462.1—0215AndrewFengACE-MCPCWE-220215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path trave…
CVE-2026-940472.1—samanhappyMCPHubCWE-266samanhappy MCPHub Template Import Endpoint templateService.ts importTemplate …
CVE-2026-940492.1—06ketanslideshotCWE-2206ketan slideshot renderer.ts render_slides path traversal
CVE-2026-940512.1—0717376cowork_benchCWE-9180717376 cowork_bench pdf-tools-mcp server.py ControlFlowNode server-side requ…
CVE-2026-940932.1—DLR-RMstable-baselines3CWE-20DLR-RM stable-baselines3 save_util.py VecNormalize.load deserialization
CVE-2026-940942.1—n/aOpenClawCWE-404OpenClaw Canvas Host Route server.ts createCanvasHostHandler denial of service
CVE-2026-939772.0—code-projectsAssessment ManagementCWE-79code-projects Assessment Management add-single-mark.php cross site scripting
CVE-2026-940332.0—SourceCodesterDrug Recommendation SystemCWE-79SourceCodester Drug Recommendation System User Management add_user cross site…
CVE-2026-940342.0—SourceCodesterDrug Recommendation SystemCWE-79SourceCodester Drug Recommendation System Password Change change_password cro…
CVE-2026-940452.0—newbee-ltdnewbee-mallCWE-79newbee-ltd newbee-mall Goods Save Endpoint UploadController.java cross site s…
CVE-2026-940482.0—CodeAstroQR Code Attendance Management SystemCWE-266CodeAstro QR Code Attendance Management System UserController.php save privil…
CVE-2026-940912.0—piskvorkygensimCWE-20piskvorky gensim Model Loader utils.py load deserialization
CVE-2026-940922.0—dmlcdglCWE-20dmlc dgl utils.py _read_torch_data deserialization
CVE-2026-939761.9—code-projectsAssessment ManagementCWE-79code-projects Assessment Management add-user.php cross site scripting
CVE-2026-940161.9—SourceCodesterDrug Recommendation SystemCWE-79SourceCodester Drug Recommendation System add_symptom cross site scripting
CVE-2026-940301.3—n/aSerenityOSCWE-189SerenityOS LibGfx BMPLoader.cpp decode_bmp_pixel_data integer overflow

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-20 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.