AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.5 .0238 83.0 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 286 CVEs published, led by 1Panel-dev (13).
286 CVEs published September 21, 2026: 15 critical, 113 high, 108 medium, 28 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 22 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 261 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 10826 | 45776 | — | — |
| KEV catalog size | 1717 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
2907 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1507 | 5598 | 526 | 2513 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0017 | +241 ▲ |
| microsoft | 1000 | 2899 | 205 | 1985 | 693 | 16 | 289 | 30 | 1.0 | 7.8 | .0044 | +531 ▲ |
| 516 | 2683 | 331 | 1049 | 1182 | 121 | 80 | 9 | 0.3 | 7.5 | .0025 | +445 ▲ | |
| red hat | 168 | 797 | 47 | 331 | 377 | 42 | 2 | 0 | 0.0 | 6.6 | .0028 | -20 ▼ |
| apple | 246 | 563 | 67 | 165 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0020 | +206 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -23 ▼ |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | -14 ▼ |
| suse | 13 | 41 | 7 | 21 | 12 | 1 | 0 | 0 | 0.0 | 7.5 | .0036 | +8 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0039 | +51 ▲ |
| ubiquiti | 0 | 59 | 36 | 22 | 1 | 0 | 3 | 3 | 5.1 | 9.1 | .0049 | 0 |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 10 | 40 | 10 | 10 | 17 | 3 | 29 | 7 | 17.5 | 7.0 | .0038 | +3 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0025 | -7 ▼ |
| f5 | 8 | 25 | 6 | 14 | 4 | 1 | 4 | 1 | 4.0 | 8.7 | .0045 | +8 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0147 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 103 | 615 | 142 | 258 | 198 | 15 | 33 | 2 | 0.3 | 7.5 | .0049 | -28 ▼ |
| mozilla | 113 | 301 | 97 | 122 | 70 | 0 | 9 | 0 | 0.0 | 8.8 | .0026 | +54 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0024 | +26 ▲ |
| gitlab | 17 | 93 | 5 | 23 | 55 | 10 | 5 | 3 | 3.2 | 5.3 | .0032 | +2 ▲ |
| github | 3 | 20 | 1 | 10 | 9 | 0 | 0 | 0 | 0.0 | 7.3 | .0044 | -2 ▼ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0016 | +1 ▲ |
| wordpress | 0 | 5 | 1 | 3 | 1 | 0 | 2 | 2 | 40.0 | 8.8 | .3120 | -2 ▼ |
| go | 4 | 4 | 0 | 2 | 1 | 1 | 0 | 0 | 0.0 | 5.9 | .0029 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0034 | -255 ▼ |
| ibm | 297 | 916 | 183 | 415 | 305 | 13 | 6 | 1 | 0.1 | 7.5 | .0030 | -77 ▼ |
| adobe | 171 | 777 | 57 | 344 | 366 | 10 | 20 | 4 | 0.5 | 7.5 | .0023 | +111 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0035 | -16 ▼ |
| solarwinds | 1 | 24 | 17 | 4 | 3 | 0 | 10 | 4 | 16.7 | 9.1 | .0058 | +1 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0032 | -10 ▼ |
| zohocorp | 7 | 17 | 3 | 8 | 6 | 0 | 0 | 0 | 0.0 | 7.7 | .0106 | +3 ▲ |
| atlassian | 3 | 9 | 1 | 8 | 0 | 0 | 13 | 0 | 0.0 | 7.6 | .0032 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 25 | 70 | 20 | 26 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0154 | +9 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0018 | -4 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0027 | +18 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0068 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0040 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0036 | +3 ▲ |
| abb | 1 | 8 | 1 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 182 | 353 | 31 | 164 | 137 | 21 | 2 | 1 | 0.3 | 7.2 | .0021 | +126 ▲ |
| sourcecodester | 58 | 227 | 0 | 0 | 134 | 93 | 0 | 0 | 0.0 | 5.5 | .0027 | +21 ▲ |
| spring | 0 | 170 | 13 | 60 | 82 | 15 | 0 | 0 | 0.0 | 6.5 | .0024 | -5 ▼ |
| nvidia | 32 | 166 | 20 | 117 | 29 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +8 ▲ |
| mongodb | 64 | 162 | 6 | 94 | 58 | 4 | 1 | 0 | 0.0 | 7.1 | .0026 | +32 ▲ |
| itsourcecode | 36 | 152 | 0 | 0 | 37 | 115 | 0 | 0 | 0.0 | 2.1 | .0026 | +17 ▲ |
| wwbn | 106 | 146 | 23 | 49 | 74 | 0 | 0 | 0 | 0.0 | 6.9 | .0024 | +104 ▲ |
| hewlett packard enterprise (hpe) | 129 | 138 | 15 | 71 | 46 | 6 | 1 | 1 | 0.7 | 7.2 | .0029 | +126 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-60004 | .8678 | 99.7 | 9.8 |
| CVE-2026-85706 | .1456 | 96.5 | 10.0 |
| CVE-2026-83549 | .0851 | 94.9 | 7.8 |
| CVE-2026-82329 | .0767 | 94.4 | 9.8 |
| CVE-2026-86218 | .0749 | 94.3 | 10.0 |
| CVE-2026-79756 | .0515 | 92.1 | 8.7 |
| CVE-2026-83548 | .0467 | 91.4 | 10.0 |
| CVE-2026-76698 | .0411 | 90.3 | 6.5 |
| CVE-2026-47864 | .0408 | 90.3 | 9.8 |
| CVE-2026-17176 | .0359 | 88.9 | 7.7 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .1456 | KEV |
| CVE-2026-86218 | 10.0 | .0749 | KEV |
| CVE-2026-83548 | 10.0 | .0467 | KEV |
| CVE-2026-75650 | 10.0 | .0215 | KEV |
| CVE-2026-86152 | 10.0 | .0186 | |
| CVE-2026-76195 | 10.0 | .0159 | |
| CVE-2026-76197 | 10.0 | .0159 | |
| CVE-2026-82222 | 10.0 | .0155 | |
| CVE-2026-82004 | 10.0 | .0144 | |
| CVE-2026-82456 | 10.0 | .0139 |
| Vendor | CVEs |
|---|---|
| linux | 1735 |
| microsoft | 1008 |
| 847 | |
| oracle | 635 |
| ibm | 313 |
| apple | 250 |
| adobe | 212 |
| red hat | 208 |
| dell | 198 |
| apache | 140 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| ivanti | 5 |
| adobe | 4 |
| berriai | 4 |
| jfrog | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 99 |
| Packagist | 41 |
| npm | 20 |
| PyPI | 14 |
| crates.io | 3 |
| RubyGems | 2 |
| Go | 1 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE-2026-81578 | PaperCut | 3 |
| CVE-2026-82078 | PaperCut | 3 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1769 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1769 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1769 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1769 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1769 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1769 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1769 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1769 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1769 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1769 |
ADDED TO KEV — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). Remediation due September 24, 2026.
EXPLOIT PUBLISHED — SourceCodester Drug Recommendation System: 4 CVEs (CVE-2026-92927, CVE-2026-93997, CVE-2026-94033, CVE-2026-94034). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2023-43000 (Apple macOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-54399 (Hongjing e-HR). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-58385 (Yonyou U8 CRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-26731. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70640 (ggml-org llama.cpp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85046 (Google Chrome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86861 (pgadmin.org pgAdmin 4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86862 (pgadmin.org pgAdmin 4). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90499 (lenve vhr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90504 (vvbbnn00 WARP-Clash-API). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90828 (GNU Binutils). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92457 (guchengwuyue yshop-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92462 (guchengwuyue yshop-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92467 (zlt2000 microservices-platform). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92770 (goharbor harbor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92775 (requarks Wiki.js). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92796 (manticoresoftware Manticore Search). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92811 (browserless). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92816 (Comfy-Org ComfyUI). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93309 (O-RAN-SC SMO OAM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93314 (Freedesktop Poppler). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93740 (Totolink A3002MU). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93742 (Totolink A3002MU). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93955 (grimmory-tools grimmory). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93956 (olivier-ls PHP-FTS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93958 (D-Link R95). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93963 (itsourcecode Leave Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93973 (SourceCodester Online Reviewer Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93975 (code-projects Assessment Management). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93976 (code-projects Assessment Management). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93978 (code-projects Internship Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93980 (code-projects Internship Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93988 (webkul qloapps). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94028 (mealie-recipes Mealie). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94031 (0-Gaurav-0 nexus-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94036 (D-Link DIR-X1860). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94038 (NonceGeek dim-sum-app). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94039 (vas3k TaxHacker). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94041 (AdithyaYelloju Restaurant-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94044 (03-lovepreetSingh MCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94046 (0215AndrewFeng ACE-MCP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94048 (CodeAstro QR Code Attendance Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94049 (06ketan slideshot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94051 (0717376 cowork_bench). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94091 (piskvorky gensim). Public exploit reference added.
REJECTED — CVE-2026-68914 (mojolicious mojo). Record withdrawn by the CNA.
REJECTED — CVE-2026-77568 (mojolicious mojo). Record withdrawn by the CNA.
REJECTED — CVE-2026-80219 (Red Hat build of Apache Camel - HawtIO 4). Record withdrawn by the CNA.
RESCORED — Dell Update Package Framework: 5 CVEs (CVE-2026-71179, CVE-2026-71180, CVE-2026-71181, CVE-2026-71182, CVE-2026-86358). CVSS rescored — before/after on each CVE page.
RESCORED — Dell Wyse Management Suite: 5 CVEs (CVE-2026-81235, CVE-2026-81236, CVE-2026-81238, CVE-2026-81239, CVE-2026-81240). CVSS rescored — before/after on each CVE page.
RESCORED — Microsoft Windows 10 Version 1607: 4 CVEs (CVE-2026-69619, CVE-2026-72947, CVE-2026-72948, CVE-2026-72950). CVSS rescored — before/after on each CVE page.
RESCORED — Netcore NBR200V2: 3 CVEs (CVE-2026-94095, CVE-2026-94096, CVE-2026-94097). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2024-35768 (Live Composer Team Page Builder: Live Composer). CVSS 5.9 → 4.8 (NVD).
RESCORED — CVE-2024-40766 (SonicWall SonicOS). CVSS 9.3 → 9.8 (NVD).
RESCORED — CVE-2025-39682 (Linux). CVSS 7.1 → 9.8 (NVD).
RESCORED — CVE-2025-43936 (Dell ObjectScale). CVSS 8.1 → 9.1 (NVD).
RESCORED — CVE-2026-26731. CVSS 8 → 8.8 (NVD).
RESCORED — CVE-2026-28367 (Red Hat JBoss Enterprise Application Platform 8.1.7.GA). CVSS 8.7 → 9.1 (NVD).
RESCORED — CVE-2026-28368 (Red Hat JBoss Enterprise Application Platform 8.1.7.GA). CVSS 8.7 → 9.1 (NVD).
RESCORED — CVE-2026-69597 (Microsoft Windows 11 version 23H2). CVSS 7.1 → 7.5 (NVD).
RESCORED — CVE-2026-69602 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD).
RESCORED — CVE-2026-69625 (Microsoft Windows 10 Version 1809). CVSS 8 → 8.8 (NVD).
RESCORED — CVE-2026-70416 (Dell ObjectScale). CVSS 10 → 9.8 (NVD).
RESCORED — CVE-2026-81627 (Red Hat Enterprise Linux 10). CVSS 6.7 → 8.2 (NVD).
PATCH SHIPPED — Red Hat Hardened Images: 4 CVEs (CVE-2026-6862, CVE-2026-76781, CVE-2026-85013, CVE-2026-87876). Fix versions published.
PATCH SHIPPED — CVE-2026-43961 (vim). Fixed in Red Hat Hardened Images 9.2.967-1.1.hum1.
PATCH SHIPPED — CVE-2026-65492 (weDevs Dokan Pro). Fixed in Dokan Pro 5.0.7.
PATCH SHIPPED — CVE-2026-66457 (Pixelite Events Manager). Fixed in Events Manager 7.4.3.
PATCH SHIPPED — CVE-2026-71577 (Red Hat Multicluster Global Hub 1.4.9). Fixed in Multicluster Global Hub 1.4.9 1788355417.
PATCH SHIPPED — CVE-2026-78002 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:8.2510.0-5.el10_2.2.
PATCH SHIPPED — CVE-2026-78376 (WebKit). Fixed in Red Hat Enterprise Linux 9 0:2.54.0-1.el9_8.
PATCH SHIPPED — CVE-2026-83596 (WebKit). Fixed in Red Hat Enterprise Linux 9 0:2.54.0-1.el9_8.
PATCH SHIPPED — CVE-2026-92925 (Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions). Fixed in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 9040020260917140622.9.
ENRICHED — CVE-2026-31710 (Linux). Received CVSS 5.5 and CPE data from NVD.
ENRICHED — CVE-2026-92126 (Jenkins Project Jenkins Script Security Plugin). Received CVSS 8.5 and CPE data from NVD.
How to read these box scores · glossary
286 CVEs published. 25 box scores, 261 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.5 .0238 83.0 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0205 80.2 —
AFFECTED Product Versions Fixed Feiyu Star Router B-MB5E202-210322-r11656 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0169 75.6 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 65.2 —
AFFECTED Product Versions Fixed Feiyu Star Router B-MB5E202-210322-r11656 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0046 38.7 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0044 38.0 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N H L 9.1 .0040 34.5 —
AFFECTED Product Versions Fixed Eclipse Open VSX 0.6.0 – —
TIMELINE Nov 11 Reserved by CNA Sep 21 Published (CNA: eclipse)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0039 33.4 —
AFFECTED Product Versions Fixed HRM OS 20260717 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N C H H H 8.0 .0031 24.4 —
AFFECTED Product Versions Fixed Red Hat OpenShift Container Platform 4 unspecified —
TIMELINE Jul 15 Reserved by CNA Sep 21 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0031 24.5 —
AFFECTED Product Versions Fixed ScadaBR 1.0 – 1.2.0
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N A H N N 6.7 .0029 22.2 —
AFFECTED Product Versions Fixed nvm unspecified 0.40.8
TIMELINE Sep 21 Reserved by CNA Sep 21 Published (CNA: harborist)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0029 21.8 —
AFFECTED Product Versions Fixed Apache MINA 2.2.0 – —
TIMELINE May 19 Reserved by CNA Sep 21 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0026 17.9 —
AFFECTED Product Versions Fixed QCMS 6.0.0 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0025 17.2 —
AFFECTED Product Versions Fixed drogon 1.9.0 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0025 17.2 —
AFFECTED Product Versions Fixed drogon 1.9.0 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N L N 2.1 .0025 16.6 —
AFFECTED Product Versions Fixed WuzhiCMS 4.0 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0024 15.2 —
AFFECTED Product Versions Fixed RooCMS 1.2.0 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L H N U H N N 4.9 .0023 14.2 —
AFFECTED Product Versions Fixed Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Single Sign-On 7 unspecified —
TIMELINE Sep 21 Reserved by CNA Sep 21 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L N N 2.1 .0022 12.9 —
AFFECTED Product Versions Fixed HRM OS 20260717 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L N N 2.1 .0022 12.5 —
AFFECTED Product Versions Fixed FBP Fulfillment by People 2025 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U N L N 3.1 .0020 10.5 —
AFFECTED Product Versions Fixed Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Single Sign-On 7 unspecified —
TIMELINE Sep 21 Reserved by CNA Sep 21 Published (CNA: redhat)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P N L N 1.9 .0020 10.4 —
AFFECTED Product Versions Fixed HRM OS 20260717 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0019 9.4 —
AFFECTED Product Versions Fixed RestroPress unspecified —
TIMELINE Sep 2 Reserved by CNA Sep 21 Published (CNA: WPScan)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P N L N 2.0 .0019 9.0 —
AFFECTED Product Versions Fixed xxl-job 3.0 – —
TIMELINE Sep 20 Reserved by CNA Sep 21 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H H N U L H L 5.5 .0018 8.3 —
AFFECTED Product Versions Fixed Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Build of Keycloak unspecified — Red Hat Single Sign-On 7 unspecified —
TIMELINE Sep 21 Reserved by CNA Sep 21 Published (CNA: redhat)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-85113 | 6.5 | 8.1 | Unknown | GiveWP | CWE-74 | GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name |
| CVE-2026-90860 | 7.1 | 7.2 | Canva | Canva | CWE-212 | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the header… |
| CVE-2026-86802 | 3.7 | 5.4 | Unknown | To Do List Member | CWE-862 | To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import |
| CVE-2026-82187 | 9.8 | 4.2 | Unknown | Web to Print Online Designer | CWE-434 | WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitr… |
| CVE-2026-94217 | 3.5 | 3.7 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: uma scope merge across resource owners … |
| CVE-2026-94142 | 8.5 | 2.7 | BioStar | Temperature Monitor Utility | CWE-119 | BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-… |
| CVE-2026-94128 | 8.5 | 2.5 | BioStar | VIVID LED DJ | CWE-119 | BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where |
| CVE-2026-94129 | 8.5 | 2.5 | BioStar | VALKYRIE AURORA | CWE-119 | BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where |
| CVE-2026-94146 | 8.5 | 2.5 | BioStar | BIOS Update Utility | CWE-119 | BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where |
| CVE-2026-92400 | 5.3 | 1.7 | Unknown | Payment Gateway for PayPal on WooCommerce | CWE-345 | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment B… |
| CVE-2026-94137 | 1.9 | 1.5 | Hangzhou Shunwang Technology | shzh | CWE-404 | Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180… |
| CVE-2026-77521 | 10.0 | — | 1Panel-dev | MaxKB | CWE-78 | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-79920 | 9.9 | — | ajenti | ajenti | CWE-862 | Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin … |
| CVE-2026-85751 | 9.8 | — | Mailu | Mailu | CWE-290 | Mailu: Authentication bypass in header-based proxy authentication via spoofab… |
| CVE-2026-94301 | 9.8 | — | Apache Software Foundation | Apache MINA | CWE-502 | Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.… |
| CVE-2026-94571 | 9.4 | — | OpenStack | Octavia | CWE-94 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not rejec… |
| CVE-2026-94572 | 9.4 | — | OpenStack | Octavia | CWE-94 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not valid… |
| CVE-2026-58491 | 9.3 | — | warp-tech | warpgate | CWE-79 | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next p… |
| CVE-2026-94424 | 9.3 | — | Moore Threads | MTT S80 Driver Package | CWE-119 | Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-… |
| CVE-2026-94425 | 9.3 | — | Moore Threads | MTT S80 Driver Package | CWE-266 | Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privi… |
| CVE-2026-61674 | 9.2 | — | fluent | fluent-bit | CWE-121 | Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-F… |
| CVE-2026-46649 | 9.1 | — | laurent22 | joplin | CWE-307 | Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brut… |
| CVE-2026-79916 | 9.1 | — | 1Panel-dev | MaxKB | CWE-78 | MaxKB AWS Bedrock model credential injection leads to remote code execution |
| CVE-2026-86473 | 9.1 | — | Apache Software Foundation | Apache Airflow | CWE-613 | Apache Airflow: Logout ignores a presented Authorization bearer token, leavin… |
| CVE-2026-55563 | 8.9 | — | feast-dev | feast | CWE-863 | Feast: `pull_request_target` integration tests run untrusted fork code with p… |
| CVE-2026-88807 | 8.9 | — | X.org | libXrender | CWE-122 | libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow |
| CVE-2026-53940 | 8.8 | — | conda | conda | CWE-22 | Conda: Entry-point path traversal in noarch:python install (arbitrary file wr… |
| CVE-2026-55159 | 8.8 | — | openwrt | luci-app-adblock-fast | CWE-93 | luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root… |
| CVE-2026-55897 | 8.8 | — | openwrt | luci | CWE-78 | luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing… |
| CVE-2026-62182 | 8.8 | — | kubeedge | kubeedge | CWE-78 | KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and cod… |
| CVE-2026-62371 | 8.8 | — | kubeedge | kubeedge | CWE-78 | KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha… |
| CVE-2026-63116 | 8.8 | — | deepstreamIO | deepstream.io | CWE-862 | deepstream: PATCH_MULTI action bypasses Valve permission system allowing unau… |
| CVE-2026-82412 | 8.8 | — | ntop | ntopng | CWE-78 | ntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan … |
| CVE-2026-84285 | 8.8 | — | Dassault Systèmes | Tuleap Enterprise Edition | CWE-78 | OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 1… |
| CVE-2026-84990 | 8.8 | — | ntop | ntopng | CWE-200 | ntopng: Missing Authorization on System Configuration Backup Download and Lis… |
| CVE-2026-88409 | 8.8 | — | n/a | n/a | — | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer… |
| CVE-2026-92574 | 8.8 | — | Red Hat | Confidential Compute Attestation | CWE-250 | Cri-o: cri-o checkpoint restore bypasses destination security context |
| CVE-2026-16651 | 8.7 | — | Temporal Technologies, Inc. | temporalio/sqlparser | CWE-129 | temporalio/sqlparser malformed MySQL version comments can cause a panic |
| CVE-2026-61652 | 8.7 | — | kap-sh | zapros | CWE-770 | Zapros: Streaming decoders ignored the requested chunk size, allowing a singl… |
| CVE-2026-65651 | 8.7 | — | Temporal Technologies, Inc. | temporalio/sqlparser | CWE-674 | temporalio/sqlparser deeply nested unary expressions can cause a fatal stack … |
| CVE-2026-65652 | 8.7 | — | Temporal Technologies, Inc. | temporalio/tchannel-go | CWE-129 | temporalio/tchannel-go malformed checksum type causes process termination |
| CVE-2026-65653 | 8.7 | — | Temporal Technologies, Inc. | temporalio/tchannel-go | CWE-129 | temporalio/tchannel-go zero-chunk call fragment causes process termination |
| CVE-2026-65654 | 8.7 | — | Temporal Technologies, Inc. | temporalio/ringpop-go | CWE-770 | temporalio/ringpop-go fails to enforce configured label limits on inbound mem… |
| CVE-2026-89139 | 8.7 | — | Temporal Technologies, Inc. | Temporal Server | CWE-78 | Temporal Server worker deployment compute provider executes a caller-supplied… |
| CVE-2026-94381 | 8.7 | — | MISP | MISP | CWE-269 | MISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via up… |
| CVE-2026-94411 | 8.7 | — | jishenghua | jshERP | CWE-862 | jshERP 3.6 Privilege Escalation via updateOneValueByKeyIdAndType |
| CVE-2026-94412 | 8.7 | — | jishenghua | jshERP | CWE-862 | jshERP through 3.6 Authorization Bypass via resetPwd |
| CVE-2026-94496 | 8.7 | — | jishenghua | jshERP | CWE-862 | jshERP through 3.6 Privilege Escalation via Role Management |
| CVE-2026-94497 | 8.7 | — | jishenghua | jshERP | CWE-639 | jshERP through 3.6 Unauthorized Access via by-id Endpoints |
| CVE-2026-94501 | 8.7 | — | jishenghua | jshERP | CWE-862 | jshERP through 3.6 Privilege Escalation via userBusiness CRUD |
| CVE-2026-94622 | 8.7 | — | vllm-project | vllm | CWE-248 | vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata |
| CVE-2026-94623 | 8.7 | — | vllm-project | vllm | CWE-617 | vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure |
| CVE-2026-94624 | 8.7 | — | vllm-project | vllm | CWE-770 | vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions |
| CVE-2026-94626 | 8.7 | — | vllm-project | vllm | CWE-789 | vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size |
| CVE-2026-94627 | 8.7 | — | vllm-project | vllm | CWE-401 | vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision |
| CVE-2025-71421 | 8.6 | — | uvdesk | core-framework | CWE-269 | UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent |
| CVE-2026-94383 | 8.6 | — | MISP | MISP | CWE-20 | MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted F… |
| CVE-2026-94403 | 8.5 | — | ColorFul | iGameCenter | CWE-822 | ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference |
| CVE-2026-49811 | 8.4 | — | Dell | Command | Monitor (DCM) | CWE-732 | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect… |
| CVE-2026-55071 | 8.4 | — | SepineTam | mcp-for-stata | CWE-94 | MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_pack… |
| CVE-2026-94374 | 8.3 | — | MISP | MISP | CWE-472 | MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows … |
| CVE-2026-94401 | 8.3 | — | MISP | MISP | CWE-73 | MISP Arbitrary Local File Read and SSRF via MISP Export Upload |
| CVE-2026-94488 | 8.3 | — | Telegram | Telegram Desktop | CWE-79 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fix… |
| CVE-2026-55074 | 8.2 | — | chofstede | ansible_jailexec | CWE-59 | Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in … |
| CVE-2026-48826 | 8.1 | — | sysadminsmedia | homebox | CWE-269 | HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Te… |
| CVE-2026-48975 | 8.1 | — | sysadminsmedia | homebox | CWE-639 | HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampe… |
| CVE-2026-48976 | 8.1 | — | sysadminsmedia | homebox | CWE-522 | HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and … |
| CVE-2026-58269 | 8.1 | — | Sync-in | server | CWE-288 | Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` |
| CVE-2026-61628 | 8.1 | — | lucasdillmann | nginx-ignition | CWE-362 | nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race… |
| CVE-2026-62369 | 8.1 | — | kubeedge | kubeedge | CWE-22 | KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write o… |
| CVE-2026-77560 | 8.1 | — | tinyauthapp | tinyauth | CWE-178 | Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (c… |
| CVE-2026-80110 | 8.1 | — | Red Hat | Red Hat Certificate System 9 | CWE-863 | Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break let… |
| CVE-2026-83621 | 8.1 | — | ntop | ntopng | CWE-862 | ntopng: Missing Authorization Check in REST API Allows Non-Admin Users to Tam… |
| CVE-2026-94184 | 8.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fet… |
| CVE-2026-65980 | 7.9 | — | chartbrew | chartbrew | CWE-89 | Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variabl… |
| CVE-2026-17052 | 7.8 | — | zephyrproject | zephyr | CWE-787 | Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allow… |
| CVE-2026-49810 | 7.8 | — | Dell | Command Powershell Provider (DCPP) | CWE-532 | Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an … |
| CVE-2026-55567 | 7.8 | — | bleachbit | bleachbit | CWE-367 | BleachBit: Exploit File Delete to Escalate Privilege |
| CVE-2026-81469 | 7.8 | — | Dell | Inventory Collector Client | CWE-428 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquote… |
| CVE-2026-55105 | 7.7 | — | laurent22 | joplin | CWE-79 | Joplin: Fountain embeds allow arbitrary script execution in published notes a… |
| CVE-2026-63330 | 7.7 | — | warp-tech | warpgate | CWE-285 | Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allo… |
| CVE-2026-76898 | 7.7 | — | jgraph | drawio | CWE-918 | draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js |
| CVE-2026-59814 | 7.6 | — | laurent22 | joplin | CWE-79 | Joplin: Stored XSS via inline-served note attachment on published shares |
| CVE-2026-52741 | 7.5 | — | gocd | gocd | CWE-80 | GoCD has stored XSS possible via tracking tool link highlighting on Compare P… |
| CVE-2026-61629 | 7.5 | — | lucasdillmann | nginx-ignition | CWE-770 | nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x… |
| CVE-2026-71543 | 7.5 | — | openbao | openbao | CWE-863 | OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters |
| CVE-2026-73512 | 7.5 | — | envoyproxy | envoy | CWE-416 | Envoy: use-after-free in QUIC on internal redirects |
| CVE-2026-73513 | 7.5 | — | envoyproxy | envoy | CWE-20 | Envoy: oghttp2 upstream trailers incorrect handling |
| CVE-2026-73547 | 7.5 | — | envoyproxy | envoy | CWE-20 | Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check |
| CVE-2026-73548 | 7.5 | — | envoyproxy | envoy | CWE-444 | Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgra… |
| CVE-2026-73550 | 7.5 | — | envoyproxy | envoy | CWE-401 | Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy |
| CVE-2026-73552 | 7.5 | — | envoyproxy | envoy | CWE-20 | Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values |
| CVE-2026-73553 | 7.5 | — | envoyproxy | envoy | CWE-436 | Envoy: RBAC Authorization Bypass via Path Parameters |
| CVE-2026-88406 | 7.5 | — | n/a | n/a | — | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack … |
| CVE-2026-88407 | 7.5 | — | n/a | n/a | — | An out-of-bounds read in the node_token_count/relation_token_count component … |
| CVE-2026-88411 | 7.5 | — | n/a | n/a | — | Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply… |
| CVE-2026-88806 | 7.5 | — | x.org | libX11 | CWE-122 | libX11 XkbGetMap Reply Heap-based Buffer Overflow |
| CVE-2026-91863 | 7.5 | — | Apache Software Foundation | Apache Neethi | CWE-674 | Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documen… |
| CVE-2026-91864 | 7.5 | — | Apache Software Foundation | Apache Neethi | CWE-770 | Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits ca… |
| CVE-2026-91865 | 7.5 | — | Apache Software Foundation | Apache Neethi | CWE-770 | Apache Neethi: Crafted policy references cause exponential expansion during n… |
| CVE-2026-91866 | 7.5 | — | Apache Software Foundation | Apache Neethi | CWE-770 | Apache Neethi: Crafted policies cause unbounded work during intersection lead… |
| CVE-2026-94449 | 7.5 | — | Red Hat | Exploit Intelligence | CWE-400 | Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory le… |
| CVE-2026-55210 | 7.4 | — | laurent22 | joplin | CWE-290 | Joplin: SAML SSO account takeover via email-based account linking (missing is… |
| CVE-2026-73546 | 7.4 | — | envoyproxy | envoy | CWE-79 | Envoy: Stored XSS in Admin Stats Interface (/stats?format=html) |
| CVE-2026-75939 | 7.4 | — | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-347 | Openshift/oc-mirror: release signature verification: openpgp signatureerror c… |
| CVE-2026-77523 | 7.4 | — | 1Panel-dev | MaxKB | CWE-639 | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-93340 | 7.4 | — | Gladys Assistant | Gladys Assistant | CWE-640 | Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password En… |
| CVE-2026-94540 | 7.4 | — | MrPear | DesktopSMS | CWE-306 | DesktopSMS 1.11.0 Unauthorized Access via Local Service |
| CVE-2026-36467 | 7.2 | — | n/a | n/a | CWE-434 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in … |
| CVE-2026-87858 | 7.2 | — | Temporal Technologies, Inc. | Temporal Server | CWE-807 | Temporal Server completion callback source header can direct attacker-chosen … |
| CVE-2026-16652 | 7.1 | — | Temporal Technologies, Inc. | Temporal Server | CWE-606 | Temporal Server Schedule exclusion search can cause excessive CPU consumption |
| CVE-2026-49450 | 7.1 | — | laurent22 | joplin | CWE-345 | Joplin desktop Windows auto-updater accepts signed installer from any publish… |
| CVE-2026-61647 | 7.1 | — | roomi-fields | notebooklm-mcp | CWE-22 | @roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allo… |
| CVE-2026-61687 | 7.1 | — | hatchet-dev | hatchet | CWE-287 | hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state colli… |
| CVE-2026-88410 | 7.1 | — | n/a | n/a | — | The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered… |
| CVE-2026-94368 | 7.1 | — | Red Hat | Red Hat Openshift Data Foundation 4 | CWE-347 | Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsi… |
| CVE-2026-94404 | 7.1 | — | MISP | MISP | CWE-352 | MISP CSRF vulnerability allows unauthorized attribute modification |
| CVE-2026-94413 | 7.1 | — | jishenghua | jshERP | CWE-200 | jshERP through 3.6 Password Hash Disclosure via /user/info |
| CVE-2026-94495 | 7.1 | — | jishenghua | jshERP | CWE-862 | jshERP through 3.6 Missing Authorization via systemConfig |
| CVE-2026-94532 | 7.1 | — | dromara | lamp-cloud | CWE-639 | lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById |
| CVE-2026-94533 | 7.1 | — | dromara | lamp-cloud | CWE-639 | lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file |
| CVE-2026-94534 | 7.1 | — | dromara | lamp-cloud | CWE-639 | lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints |
| CVE-2026-94535 | 7.1 | — | dromara | lamp-cloud | CWE-639 | lamp-cloud through 5.10.0 Unauthorized Notification Deletion |
| CVE-2026-49453 | 7.0 | — | laurent22 | joplin | CWE-20 | Joplin: Path traversal in resource sync — silent arbitrary file write outside… |
| CVE-2026-52835 | 7.0 | — | Tautulli | Tautulli | CWE-22 | Tautulli: Path traversal / arbitrary file write via unsanitized upload filena… |
| CVE-2026-68919 | 7.0 | — | gocd | gocd | CWE-80 | GoCD has stored XSS possible via forged package material comments on Stage/Jo… |
| CVE-2026-61541 | 6.9 | — | kap-sh | zapros | CWE-770 | Zapros has an Unbounded Content-Encoding decompression chain that allows deni… |
| CVE-2026-77582 | 6.9 | — | tinyauthapp | tinyauth | CWE-208 | Tinyauth: User enumeration attack by timing oracle |
| CVE-2026-94379 | 6.9 | — | MISP | MISP | CWE-20 | MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection an… |
| CVE-2026-94625 | 6.9 | — | vllm-project | vllm | CWE-772 | vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Place… |
| CVE-2026-58271 | 6.8 | — | Sync-in | server | CWE-307 | @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` |
| CVE-2026-63334 | 6.8 | — | jgraph | drawio | CWE-367 | draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist |
| CVE-2026-55179 | 6.5 | — | laurent22 | joplin | CWE-639 | Joplin: Logic error in Joplin Server allows a signed-in user to read any note… |
| CVE-2026-58270 | 6.5 | — | Sync-in | server | CWE-1333 | Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` |
| CVE-2026-61744 | 6.5 | — | inventree | InvenTree | CWE-639 | InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized ob… |
| CVE-2026-61749 | 6.5 | — | inventree | InvenTree | CWE-200 | InvenTree: Administrative staff users can trigger Arbitrary File Read leading… |
| CVE-2026-61851 | 6.5 | — | chartbrew | chartbrew | CWE-184 | Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool |
| CVE-2026-62247 | 6.5 | — | supabase | realtime | CWE-863 | Supabase Realtime: Incorrect Authorization |
| CVE-2026-62370 | 6.5 | — | kubeedge | kubeedge | CWE-789 | KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote… |
| CVE-2026-77165 | 6.5 | — | Nextcloud | Server | CWE-284 | File owners were unable to unlock TYPE_TOKEN locks placed by other users, lea… |
| CVE-2026-79917 | 6.5 | — | 1Panel-dev | MaxKB | CWE-285 | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish… |
| CVE-2026-88408 | 6.5 | — | n/a | n/a | — | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack … |
| CVE-2026-94393 | 6.4 | — | MISP | MISP | CWE-284 | MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in edi… |
| CVE-2026-61743 | 6.3 | — | chartbrew | chartbrew | CWE-350 | Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation |
| CVE-2026-63342 | 6.3 | — | hatchet-dev | hatchet | CWE-863 | Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authoriza… |
| CVE-2026-69190 | 6.3 | — | Graylog2 | graylog2-server | CWE-639 | Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards |
| CVE-2026-79918 | 6.3 | — | 1Panel-dev | MaxKB | CWE-693 | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-79919 | 6.3 | — | 1Panel-dev | MaxKB | CWE-693 | MaxKB function-library sandbox escape: dlopen stack-check bypass via importli… |
| CVE-2026-94277 | 6.3 | — | MISP | MISP | CWE-79 | Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Ga… |
| CVE-2026-94372 | 6.3 | — | MISP | MISP | CWE-79 | Stored Cross-Site Scripting via Unescaped Galaxy Cluster Tag Names in MISP De… |
| CVE-2026-94373 | 6.3 | — | MISP | MISP | CWE-79 | MISP DOM-based Cross-Site Scripting via innerHTML in Contextual Menu |
| CVE-2026-94394 | 6.3 | — | MISP | MISP | CWE-862 | MISP ObjectReferencesController: Granular Distribution and Sharing Group Rest… |
| CVE-2026-59168 | 6.2 | — | TomWright | dasel | CWE-674 | Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack… |
| CVE-2026-62866 | 6.2 | — | TomWright | dasel | CWE-129 | Dasel: Selector lexer panics on trailing whitespace in `parseCurRune` |
| CVE-2026-36468 | 6.1 | — | n/a | n/a | CWE-79 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote una… |
| CVE-2026-58504 | 6.1 | — | jgraph | drawio | CWE-79 | draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass o… |
| CVE-2026-17051 | 6.0 | — | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound … |
| CVE-2026-55473 | 6.0 | — | sysadminsmedia | homebox | CWE-918 | HomeBox: Notifier SSRF guard misses NAT64 prefixes (64:ff9b::/96, 64:ff9b:1::… |
| CVE-2026-91167 | 6.0 | — | warp-tech | warpgate | CWE-862 | Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allo… |
| CVE-2026-48521 | 5.9 | — | envoyproxy | envoy | CWE-476 | Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFact… |
| CVE-2026-50572 | 5.9 | — | envoyproxy | envoy | CWE-416 | Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault |
| CVE-2026-61852 | 5.8 | — | chartbrew | chartbrew | CWE-89 | Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool |
| CVE-2026-62987 | 5.8 | — | fabiolb | fabio | CWE-290 | Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers … |
| CVE-2026-17050 | 5.7 | — | zephyrproject | zephyr | CWE-415 | Double free of the USB host configuration descriptor when device enumeration … |
| CVE-2026-61612 | 5.7 | — | ondata | ckan-mcp-server | CWE-918 | @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fi… |
| CVE-2026-91166 | 5.7 | — | warp-tech | warpgate | CWE-297 | Warpgate: Web SSH stores a jump host's key against the target's address, so i… |
| CVE-2026-82163 | 5.5 | — | Dell | Command | Intel vPro Out of Band | CWE-276 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an In… |
| CVE-2026-82165 | 5.5 | — | Dell | Command | Integration Suite for System Center | CWE-276 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, … |
| CVE-2026-93433 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-121 | Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow i… |
| CVE-2026-48974 | 5.4 | — | sysadminsmedia | homebox | CWE-841 | HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler |
| CVE-2026-54915 | 5.4 | — | Tautulli | Tautulli | CWE-601 | Tautulli: Open redirect via whitespace bypass in /auth/redirect |
| CVE-2026-59830 | 5.4 | — | discourse | discourse | CWE-79 | Discourse: Stored XSS via unescaped actor name in post actions |
| CVE-2026-77516 | 5.4 | — | 1Panel-dev | MaxKB | CWE-639 | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch… |
| CVE-2026-77517 | 5.4 | — | 1Panel-dev | MaxKB | CWE-639 | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and p… |
| CVE-2026-77519 | 5.4 | — | 1Panel-dev | MaxKB | CWE-613 | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-77520 | 5.4 | — | 1Panel-dev | MaxKB | CWE-862 | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes… |
| CVE-2025-71420 | 5.3 | — | uvdesk | core-framework | CWE-639 | UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply |
| CVE-2026-15890 | 5.3 | — | zephyrproject | zephyr | CWE-323 | AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to m… |
| CVE-2026-17054 | 5.3 | — | zephyrproject | zephyr | CWE-125 | Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SP… |
| CVE-2026-52740 | 5.3 | — | gocd | gocd | CWE-863 | GoCD is vulnerable to pipeline template view API authorization bypass |
| CVE-2026-54584 | 5.3 | — | MidnightBSD | mport | CWE-73 | mport trusts environment-controlled temporary directories in privileged metad… |
| CVE-2026-58272 | 5.3 | — | Sync-in | server | CWE-208 | Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST… |
| CVE-2026-61746 | 5.3 | — | inventree | InvenTree | CWE-200 | InvenTree: Plugin-settings GET endpoints are readable without authentication |
| CVE-2026-73511 | 5.3 | — | envoyproxy | envoy | CWE-289 | Envoy: Potential path-matching/authentication bypass when using Envoy in comb… |
| CVE-2026-73549 | 5.3 | — | envoyproxy | envoy | CWE-754 | Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes… |
| CVE-2026-73551 | 5.3 | — | envoyproxy | envoy | CWE-647 | Envoy: Path normalization does not handle dot and dotdot segments with parame… |
| CVE-2026-77021 | 5.3 | — | Checkmk GmbH | Checkmk | CWE-409 | Missing decompression size limit in agent receiver allows memory exhaustion v… |
| CVE-2026-77561 | 5.3 | — | tinyauthapp | tinyauth | CWE-307 | Tinyauth: Unauthenticated login attempts can trigger global login lockdown de… |
| CVE-2026-88412 | 5.3 | — | n/a | n/a | — | An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c… |
| CVE-2026-94414 | 5.3 | — | jishenghua | jshERP | CWE-862 | jshERP through 3.6 Missing Authorization via updateBtnStr |
| CVE-2026-94489 | 5.3 | — | n/a | OctoPrint | CWE-22 | OctoPrint File Download API files.py _validate path traversal |
| CVE-2026-94494 | 5.3 | — | jishenghua | jshERP | CWE-639 | jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info |
| CVE-2026-94536 | 5.3 | — | dromara | lamp-cloud | CWE-639 | lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/vis… |
| CVE-2026-36472 | 5.2 | — | n/a | n/a | CWE-79 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutra… |
| CVE-2025-71419 | 5.1 | — | uvdesk | core-framework | CWE-79 | UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer |
| CVE-2026-45381 | 5.1 | — | Tautulli | Tautulli | CWE-79 | Tautulli: Reflected XSS in `/search` endpoint |
| CVE-2026-52742 | 5.1 | — | gocd | gocd | CWE-863 | GoCD is vulnerable to historical server configuration API authorization bypass |
| CVE-2026-91921 | 5.1 | — | 1millionbot | AI Chatbot Platform (SaaS) de 1millionbot. | CWE-79 | Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform |
| CVE-2026-93339 | 5.1 | — | Metaphor Creations | Ditty | CWE-79 | Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute |
| CVE-2026-94387 | 5.1 | — | aureuserp | aureuserp | CWE-79 | Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log |
| CVE-2026-77518 | 5.0 | — | 1Panel-dev | MaxKB | CWE-862 | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by att… |
| CVE-2026-55625 | 4.9 | — | gocd | gocd | CWE-639 | GoCD is vulnerable to authorization bypass via material connection test APIs |
| CVE-2026-63329 | 4.9 | — | warp-tech | warpgate | CWE-116 | Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enable… |
| CVE-2026-49995 | 4.8 | — | Tautulli | Tautulli | CWE-79 | Tautulli: Stored Cross-Site Scripting (XSS) in the newsletter |
| CVE-2026-46650 | 4.4 | — | laurent22 | joplin | CWE-79 | Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcc… |
| CVE-2026-94588 | 4.4 | — | Proxmox | pmg-api | CWE-88 | In Proxmox pmg-api, an argument injection vulnerability exists in the package… |
| CVE-2026-52743 | 4.3 | — | gocd | gocd | CWE-639 | GoCD before 26.1.0 is vulnerable to authorization bypass via job status API |
| CVE-2026-59815 | 4.3 | — | laurent22 | joplin | CWE-863 | Joplin: Pending share recipients can write items into shared folders before a… |
| CVE-2026-59816 | 4.3 | — | laurent22 | joplin | CWE-22 | Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash |
| CVE-2026-61745 | 4.3 | — | inventree | InvenTree | CWE-862 | InvenTree: Missing authorization on machine restart endpoint allows any authe… |
| CVE-2026-61747 | 4.3 | — | inventree | InvenTree | CWE-639 | InvenTree: Authenticated IDOR in the data-import API exposes other users' imp… |
| CVE-2026-61748 | 4.3 | — | inventree | InvenTree | CWE-639 | InvenTree: Report/Label print endpoints ignore per-model permissions |
| CVE-2026-75158 | 4.3 | — | Apache Software Foundation | Apache Airflow | CWE-200 | Apache Airflow: Assets events API returns asset events for every Dag with no … |
| CVE-2026-77522 | 4.3 | — | 1Panel-dev | MaxKB | CWE-918 | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/syn… |
| CVE-2026-88978 | 4.3 | — | hatchet-dev | hatchet | CWE-639 | Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task U… |
| CVE-2026-91164 | 4.3 | — | warp-tech | warpgate | CWE-284 | Warpgate: API tokens bypass the user's allowed_ip_ranges restriction |
| CVE-2026-91867 | 4.3 | — | Apache Software Foundation | Apache Neethi | CWE-400 | Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow ser… |
| CVE-2026-61630 | 4.2 | — | lucasdillmann | nginx-ignition | CWE-287 | nginx ignition has TOTP Reuse During Validity Window |
| CVE-2026-63373 | 4.2 | — | jgraph | drawio | CWE-352 | draw.io: OAuth CSRF via missing state validation on self-hosted deployments a… |
| CVE-2026-77525 | 4.2 | — | 1Panel-dev | MaxKB | CWE-862 | MaxKB: Management chat-record routes trust path application_id but load ChatR… |
| CVE-2026-82355 | 4.2 | — | Apache Software Foundation | Apache Airflow | CWE-384 | Apache Airflow: Session cookie silently overrides explicit Authorization bear… |
| CVE-2026-61681 | 4.1 | — | hatchet-dev | hatchet | CWE-918 | Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler |
| CVE-2026-92382 | 4.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_pac… |
| CVE-2026-55060 | 3.7 | — | gocd | gocd | CWE-863 | GoCD is vulnerable to authorization bypass via support process list API |
| CVE-2026-63416 | 3.7 | — | jgraph | drawio | CWE-22 | draw.io: Path traversal in ExportProxyServlet allows access to arbitrary back… |
| CVE-2026-85219 | 3.7 | — | Thinkst Applied Research | OpenCanary | CWE-770 | Denial-of-Service in the OpenCanary Redis service |
| CVE-2026-85220 | 3.7 | — | Thinkst Applied Research | Canary | CWE-770 | Denial-of-Service in the Thinkst Canary Redis service |
| CVE-2026-84298 | 3.1 | — | hatchet-dev | hatchet | CWE-639 | Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispa… |
| CVE-2026-49449 | 2.5 | — | laurent22 | joplin | CWE-200 | Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 cre… |
| CVE-2026-77166 | 2.4 | — | Nextcloud | Collectives | CWE-840 | The emoji field in the page emoji update endpoint does not properly validate … |
| CVE-2026-91165 | 2.4 | — | warp-tech | warpgate | CWE-79 | Warpgate: Markup injection in SSO form_post return page via unencoded redirec… |
| CVE-2026-55870 | 2.3 | — | gocd | gocd | CWE-200 | GoCD is vulnerable to credential exposure when admins insecurely configure ma… |
| CVE-2026-94382 | 2.3 | — | henrygd | beszel | CWE-639 | Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts |
| CVE-2026-94214 | 2.1 | — | ST Engineering iDirect | Evolution | CWE-601 | ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Serv… |
| CVE-2026-94216 | 2.1 | — | ST Engineering iDirect | Evolution | CWE-601 | ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header web… |
| CVE-2026-94210 | 2.0 | — | Hyve5 | Leantime | CWE-79 | Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting |
| CVE-2026-94426 | 2.0 | — | xuxueli | xxl-job | CWE-79 | xuxueli xxl-job insert cross site scripting |
| CVE-2026-94211 | 1.9 | — | Hyve5 | Leantime | CWE-79 | Hyve5 Leantime Project Dashboard show.blade.php cross site scripting |
| CVE-2026-92612 | 1.0 | — | Eclipse Foundation | Eclipse iceoryx™ | CWE-749 | In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes it… |
| CVE-2026-36469 | await | — | n/a | n/a | — | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/… |
| CVE-2026-36470 | await | — | n/a | n/a | — | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. Th… |
| CVE-2026-36471 | await | — | n/a | n/a | — | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_ur… |
| CVE-2026-67827 | await | — | n/a | n/a | — | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 … |
| CVE-2026-78806 | await | — | n/a | n/a | — | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Pr… |
| CVE-2026-78847 | await | — | n/a | n/a | — | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScrip… |
| CVE-2026-79079 | await | — | n/a | n/a | — | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbi… |
| CVE-2026-79316 | await | — | n/a | n/a | — | An improper access control vulnerability exists in x-ui 0.3.2. Any authentica… |
| CVE-2026-79317 | await | — | n/a | n/a | — | A session invalidation flaw exists in x-ui 0.3.2. The full user object is sto… |
| CVE-2026-79318 | await | — | n/a | n/a | — | web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vuln… |
| CVE-2026-79319 | await | — | n/a | n/a | — | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. |
| CVE-2026-79320 | await | — | n/a | n/a | — | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerabi… |
| CVE-2026-88402 | await | — | n/a | n/a | — | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 al… |
| CVE-2026-88403 | await | — | n/a | n/a | — | A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobas… |
| CVE-2026-88404 | await | — | n/a | n/a | — | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.… |
| CVE-2026-88405 | await | — | n/a | n/a | — | A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionServ… |
| CVE-2026-88467 | await | — | n/a | n/a | — | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification… |
| CVE-2026-88738 | await | — | n/a | n/a | — | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vul… |
| CVE-2026-88745 | await | — | n/a | n/a | — | EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to uploa… |
| CVE-2026-88746 | await | — | n/a | n/a | — | idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_de… |
| CVE-2026-88756 | await | — | n/a | n/a | — | Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injec… |
| CVE-2026-93012 | await | — | — | Email-Sender | CWE-78 | Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbit… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-21 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.