boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, September 21, 2026 · all times UTC← 2026-09-20 · archive

Security Box Score — September 21, 2026

CISA adds 1 to KEV; 286 CVEs published, led by 1Panel-dev (13).

286 CVEs published September 21, 2026: 15 critical, 113 high, 108 medium, 28 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 22 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 261 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1082645776——
KEV catalog size1717

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2907 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15075598526251371311560.17.8.0017+241 ▲
microsoft10002899205198569316289301.07.8.0044+531 ▲
google5162683331104911821218090.37.5.0025+445 ▲
red hat1687974733137742200.06.6.0028-20 ▼
apple24656367165317148881.46.5.0020+206 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0021-14 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+51 ▲
ubiquiti059362210335.19.1.00490
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1040101017329717.57.0.0038+3 ▲
netgear23400277000.04.3.0025-7 ▼
f582561441414.08.7.0045+8 ▲
ivanti10246162025520.88.8.0147+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache103615142258198153320.37.5.0049-28 ▼
mozilla11330197122700900.08.8.0026+54 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+2 ▲
github32011090000.07.3.0044-2 ▼
docker3121830000.08.4.0016+1 ▲
wordpress0513102240.08.8.3120-2 ▼
go440211000.05.9.0029+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0034-255 ▼
ibm29791618341530513610.17.5.0030-77 ▼
adobe17177757344366102040.57.5.0023+111 ▲
progress3641539100611.68.1.0035-16 ▼
solarwinds1241743010416.79.1.0058+1 ▲
veeam01961030100.08.6.0032-10 ▼
zohocorp7173860000.07.7.0106+3 ▲
atlassian3918001300.07.6.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link257020261212300.08.5.0154+9 ▲
siemens1552633103000.07.3.0018-4 ▼
synology1946510256000.05.6.0027+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
abb181430000.07.2.0018+1 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1823533116413721210.37.2.0021+126 ▲
sourcecodester582270013493000.05.5.0027+21 ▲
spring017013608215000.06.5.0024-5 ▼
nvidia3216620117290000.07.8.0029+8 ▲
mongodb64162694584100.07.1.0026+32 ▲
itsourcecode361520037115000.02.1.0026+17 ▲
wwbn1061462349740000.06.9.0024+104 ▲
hewlett packard enterprise (hpe)1291381571466110.77.2.0029+126 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.145696.510.0
CVE-2026-83549.085194.97.8
CVE-2026-82329.076794.49.8
CVE-2026-86218.074994.310.0
CVE-2026-79756.051592.18.7
CVE-2026-83548.046791.410.0
CVE-2026-76698.041190.36.5
CVE-2026-47864.040890.39.8
CVE-2026-17176.035988.97.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.1456KEV
CVE-2026-8621810.0.0749KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8245610.0.0139
Most disclosures (vendor)
VendorCVEs
linux1735
microsoft1008
google847
oracle635
ibm313
apple250
adobe212
red hat208
dell198
apache140
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
ivanti5
adobe4
berriai4
jfrog4
Most-affected ecosystems
EcosystemAdvisories
Maven99
Packagist41
npm20
PyPI14
crates.io3
RubyGems2
Go1
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
CVE-2026-82078PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171769
CVE-2021-27102n/a2021-11-171769
CVE-2021-27101n/a2021-11-171769
CVE-2021-27103n/a2021-11-171769
CVE-2021-21017Adobe2021-11-171769
CVE-2021-28550Adobe2021-11-171769
CVE-2021-42013Apache Software Foundation2021-11-171769
CVE-2021-41773Apache Software Foundation2021-11-171769
CVE-2021-30858Apple2021-11-171769
CVE-2021-30860Apple2021-11-171769

Transactions

ADDED TO KEV — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). Remediation due September 24, 2026.

EXPLOIT PUBLISHED — SourceCodester Drug Recommendation System: 4 CVEs (CVE-2026-92927, CVE-2026-93997, CVE-2026-94033, CVE-2026-94034). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2023-43000 (Apple macOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54399 (Hongjing e-HR). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-58385 (Yonyou U8 CRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-5914 (libarchive). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26731. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-70640 (ggml-org llama.cpp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71225 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71227 (Stephan Muelle libkcapi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85046 (Google Chrome). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86861 (pgadmin.org pgAdmin 4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86862 (pgadmin.org pgAdmin 4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90499 (lenve vhr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90504 (vvbbnn00 WARP-Clash-API). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90828 (GNU Binutils). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92457 (guchengwuyue yshop-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92462 (guchengwuyue yshop-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92467 (zlt2000 microservices-platform). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92770 (goharbor harbor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92775 (requarks Wiki.js). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92796 (manticoresoftware Manticore Search). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92811 (browserless). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92816 (Comfy-Org ComfyUI). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93309 (O-RAN-SC SMO OAM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93314 (Freedesktop Poppler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93740 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93742 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93955 (grimmory-tools grimmory). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93956 (olivier-ls PHP-FTS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93958 (D-Link R95). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93963 (itsourcecode Leave Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93973 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93975 (code-projects Assessment Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93976 (code-projects Assessment Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93978 (code-projects Internship Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93980 (code-projects Internship Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93988 (webkul qloapps). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94028 (mealie-recipes Mealie). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94031 (0-Gaurav-0 nexus-mcp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94036 (D-Link DIR-X1860). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94038 (NonceGeek dim-sum-app). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94039 (vas3k TaxHacker). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94041 (AdithyaYelloju Restaurant-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94044 (03-lovepreetSingh MCP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94046 (0215AndrewFeng ACE-MCP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94048 (CodeAstro QR Code Attendance Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94049 (06ketan slideshot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94051 (0717376 cowork_bench). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94091 (piskvorky gensim). Public exploit reference added.

REJECTED — CVE-2026-68914 (mojolicious mojo). Record withdrawn by the CNA.

REJECTED — CVE-2026-77568 (mojolicious mojo). Record withdrawn by the CNA.

REJECTED — CVE-2026-80219 (Red Hat build of Apache Camel - HawtIO 4). Record withdrawn by the CNA.

RESCORED — Dell Update Package Framework: 5 CVEs (CVE-2026-71179, CVE-2026-71180, CVE-2026-71181, CVE-2026-71182, CVE-2026-86358). CVSS rescored — before/after on each CVE page.

RESCORED — Dell Wyse Management Suite: 5 CVEs (CVE-2026-81235, CVE-2026-81236, CVE-2026-81238, CVE-2026-81239, CVE-2026-81240). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 10 Version 1607: 4 CVEs (CVE-2026-69619, CVE-2026-72947, CVE-2026-72948, CVE-2026-72950). CVSS rescored — before/after on each CVE page.

RESCORED — Netcore NBR200V2: 3 CVEs (CVE-2026-94095, CVE-2026-94096, CVE-2026-94097). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2024-35768 (Live Composer Team Page Builder: Live Composer). CVSS 5.9 → 4.8 (NVD).

RESCORED — CVE-2024-40766 (SonicWall SonicOS). CVSS 9.3 → 9.8 (NVD).

RESCORED — CVE-2025-39682 (Linux). CVSS 7.1 → 9.8 (NVD).

RESCORED — CVE-2025-43936 (Dell ObjectScale). CVSS 8.1 → 9.1 (NVD).

RESCORED — CVE-2026-26731. CVSS 8 → 8.8 (NVD).

RESCORED — CVE-2026-28367 (Red Hat JBoss Enterprise Application Platform 8.1.7.GA). CVSS 8.7 → 9.1 (NVD).

RESCORED — CVE-2026-28368 (Red Hat JBoss Enterprise Application Platform 8.1.7.GA). CVSS 8.7 → 9.1 (NVD).

RESCORED — CVE-2026-69597 (Microsoft Windows 11 version 23H2). CVSS 7.1 → 7.5 (NVD).

RESCORED — CVE-2026-69602 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD).

RESCORED — CVE-2026-69625 (Microsoft Windows 10 Version 1809). CVSS 8 → 8.8 (NVD).

RESCORED — CVE-2026-70416 (Dell ObjectScale). CVSS 10 → 9.8 (NVD).

RESCORED — CVE-2026-81627 (Red Hat Enterprise Linux 10). CVSS 6.7 → 8.2 (NVD).

PATCH SHIPPED — Red Hat Hardened Images: 4 CVEs (CVE-2026-6862, CVE-2026-76781, CVE-2026-85013, CVE-2026-87876). Fix versions published.

PATCH SHIPPED — CVE-2026-43961 (vim). Fixed in Red Hat Hardened Images 9.2.967-1.1.hum1.

PATCH SHIPPED — CVE-2026-65492 (weDevs Dokan Pro). Fixed in Dokan Pro 5.0.7.

PATCH SHIPPED — CVE-2026-66457 (Pixelite Events Manager). Fixed in Events Manager 7.4.3.

PATCH SHIPPED — CVE-2026-71577 (Red Hat Multicluster Global Hub 1.4.9). Fixed in Multicluster Global Hub 1.4.9 1788355417.

PATCH SHIPPED — CVE-2026-78002 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:8.2510.0-5.el10_2.2.

PATCH SHIPPED — CVE-2026-78376 (WebKit). Fixed in Red Hat Enterprise Linux 9 0:2.54.0-1.el9_8.

PATCH SHIPPED — CVE-2026-83596 (WebKit). Fixed in Red Hat Enterprise Linux 9 0:2.54.0-1.el9_8.

PATCH SHIPPED — CVE-2026-92925 (Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions). Fixed in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 9040020260917140622.9.

ENRICHED — CVE-2026-31710 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHED — CVE-2026-92126 (Jenkins Project Jenkins Script Security Plugin). Received CVSS 8.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

286 CVEs published. 25 box scores, 261 table rows — nothing truncated.

Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0238   83.0     —
AFFECTED
  Product   Versions             Fixed
  NBR200V2  1.3.241127.071246 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Chengdu Feiyuxing Technology Feiyu Star Router send_order.cgi command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0205   80.2     —
AFFECTED
  Product            Versions                   Fixed
  Feiyu Star Router  B-MB5E202-210322-r11656 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Netcore NBR200V2 Backup Restore restore.cgi command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0169   75.6     —
AFFECTED
  Product   Versions             Fixed
  NBR200V2  1.3.241127.071246 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   65.2     —
AFFECTED
  Product            Versions                   Fixed
  Feiyu Star Router  B-MB5E202-210322-r11656 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0046   38.7     —
AFFECTED
  Product   Versions             Fixed
  NBR200V2  1.3.241127.071246 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0044   38.0     —
AFFECTED
  Product   Versions             Fixed
  NBR200V2  1.3.241127.071246 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-119, CWE-120 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Eclipse Foundation Eclipse Open VSX — UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — fro…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   H   L    9.1   .0040   34.5     —
AFFECTED
  Product           Versions  Fixed
  Eclipse Open VSX  0.6.0 –   —
TIMELINE
  Nov 11  Reserved by CNA
  Sep 21  Published (CNA: eclipse)
CNA: eclipse · CVSS v4.0 · 3 references · NVD status: Deferred
Omega Solution HRM OS Role Permission API permission missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0039   33.4     —
AFFECTED
  Product  Versions    Fixed
  HRM OS   20260717 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Red Hat Red Hat OpenShift Container Platform 4 — Cri-o: cri-o: insufficient validation during container checkpoint restore
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  C  H  H  H    8.0   .0031   24.4     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Sep 21  Published (CNA: redhat)
CWE-22 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Received
n/a ScadaBR — ScadaBR Export Project Endpoint export_project.htm EmportDwr.createExportJSON information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0031   24.5     —
AFFECTED
  Product  Versions  Fixed
  ScadaBR  1.0 –     1.2.0
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
nvm-sh nvm — nvm alias resolution follows `..` and discloses files outside $NVM_DIR/alias
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   A   H   N   N    6.7   .0029   22.2     —
AFFECTED
  Product  Versions     Fixed
  nvm      unspecified  0.40.8
TIMELINE
  Sep 21  Reserved by CNA
  Sep 21  Published (CNA: harborist)
CWE-22, CWE-200 · CNA: harborist · CVSS v4.0 · 1 reference · NVD status: Received
Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0029   21.8     —
AFFECTED
  Product      Versions  Fixed
  Apache MINA  2.2.0 –   —
TIMELINE
  May 19  Reserved by CNA
  Sep 21  Published (CNA: apache)
CWE-409, CWE-789 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
n/a QCMS — QCMS Content Detail Controllers.php self_Tmp sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0026   17.9     —
AFFECTED
  Product  Versions  Fixed
  QCMS     6.0.0 –   —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
drogonframework drogon ORM Mapper Mapper.h orderBy sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0025   17.2     —
AFFECTED
  Product  Versions  Fixed
  drogon   1.9.0 –   —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
drogonframework drogon ORM Criteria.cc makeCriteria sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0025   17.2     —
AFFECTED
  Product  Versions  Fixed
  drogon   1.9.0 –   —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
n/a WuzhiCMS — WuzhiCMS Login index.php redirect
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0025   16.6     —
AFFECTED
  Product   Versions  Fixed
  WuzhiCMS  4.0 –     —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-601 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
n/a RooCMS — RooCMS Frontend Rendering site_pagePHP.php eval code injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0024   15.2     —
AFFECTED
  Product  Versions  Fixed
  RooCMS   1.2.0 –   —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-74, CWE-94 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Red Hat Red Hat Build of Keycloak — Keycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identity
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0023   14.2     —
AFFECTED
  Product                    Versions     Fixed
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Single Sign-On 7   unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 21  Published (CNA: redhat)
CWE-862 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Received
Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0022   12.9     —
AFFECTED
  Product  Versions    Fixed
  HRM OS   20260717 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-99 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Omega Solution FBP Fulfillment by People User Profile API user authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0022   12.5     —
AFFECTED
  Product                    Versions  Fixed
  FBP Fulfillment by People  2025 –    —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Red Hat Red Hat Build of Keycloak — Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  N  L  N    3.1   .0020   10.5     —
AFFECTED
  Product                    Versions     Fixed
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Single Sign-On 7   unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 21  Published (CNA: redhat)
CWE-862 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Received
Omega Solution HRM OS SVG File Upload view cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   N   L   N    1.9   .0020   10.4     —
AFFECTED
  Product  Versions    Fixed
  HRM OS   20260717 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Unknown RestroPress — RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0019    9.4     —
AFFECTED
  Product      Versions     Fixed
  RestroPress  unspecified  —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 21  Published (CNA: WPScan)
CWE-472 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
xuxueli xxl-job Task Management JobInfoController.java cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   N   L   N    2.0   .0019    9.0     —
AFFECTED
  Product  Versions  Fixed
  xxl-job  3.0 –     —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 21  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Red Hat Red Hat Build of Keycloak — Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  L  H  L    5.5   .0018    8.3     —
AFFECTED
  Product                    Versions     Fixed
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Build of Keycloak  unspecified  —
  Red Hat Single Sign-On 7   unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 21  Published (CNA: redhat)
CWE-862 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-851136.58.1UnknownGiveWPCWE-74GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name
CVE-2026-908607.17.2CanvaCanvaCWE-212The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the header…
CVE-2026-868023.75.4UnknownTo Do List MemberCWE-862To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import
CVE-2026-821879.84.2UnknownWeb to Print Online DesignerCWE-434WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitr…
CVE-2026-942173.53.7Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: uma scope merge across resource owners …
CVE-2026-941428.52.7BioStarTemperature Monitor UtilityCWE-119BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-…
CVE-2026-941288.52.5BioStarVIVID LED DJCWE-119BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where
CVE-2026-941298.52.5BioStarVALKYRIE AURORACWE-119BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where
CVE-2026-941468.52.5BioStarBIOS Update UtilityCWE-119BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where
CVE-2026-924005.31.7UnknownPayment Gateway for PayPal on WooCommerceCWE-345Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment B…
CVE-2026-941371.91.5Hangzhou Shunwang TechnologyshzhCWE-404Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180…
CVE-2026-7752110.0—1Panel-devMaxKBCWE-78MaxKB: Prompt-injectable agent can lead to command execution
CVE-2026-799209.9—ajentiajentiCWE-862Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin …
CVE-2026-857519.8—MailuMailuCWE-290Mailu: Authentication bypass in header-based proxy authentication via spoofab…
CVE-2026-943019.8—Apache Software FoundationApache MINACWE-502Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.…
CVE-2026-945719.4—OpenStackOctaviaCWE-94In OpenStack Octavia before 18.0.1, the Amphora provider driver did not rejec…
CVE-2026-945729.4—OpenStackOctaviaCWE-94In OpenStack Octavia before 18.0.1, the Amphora provider driver did not valid…
CVE-2026-584919.3—warp-techwarpgateCWE-79Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next p…
CVE-2026-944249.3—Moore ThreadsMTT S80 Driver PackageCWE-119Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-…
CVE-2026-944259.3—Moore ThreadsMTT S80 Driver PackageCWE-266Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privi…
CVE-2026-616749.2—fluentfluent-bitCWE-121Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-F…
CVE-2026-466499.1—laurent22joplinCWE-307Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brut…
CVE-2026-799169.1—1Panel-devMaxKBCWE-78MaxKB AWS Bedrock model credential injection leads to remote code execution
CVE-2026-864739.1—Apache Software FoundationApache AirflowCWE-613Apache Airflow: Logout ignores a presented Authorization bearer token, leavin…
CVE-2026-555638.9—feast-devfeastCWE-863Feast: `pull_request_target` integration tests run untrusted fork code with p…
CVE-2026-888078.9—X.orglibXrenderCWE-122libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow
CVE-2026-539408.8—condacondaCWE-22Conda: Entry-point path traversal in noarch:python install (arbitrary file wr…
CVE-2026-551598.8—openwrtluci-app-adblock-fastCWE-93luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root…
CVE-2026-558978.8—openwrtluciCWE-78luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing…
CVE-2026-621828.8—kubeedgekubeedgeCWE-78KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and cod…
CVE-2026-623718.8—kubeedgekubeedgeCWE-78KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha…
CVE-2026-631168.8—deepstreamIOdeepstream.ioCWE-862deepstream: PATCH_MULTI action bypasses Valve permission system allowing unau…
CVE-2026-824128.8—ntopntopngCWE-78ntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan …
CVE-2026-842858.8—Dassault SystèmesTuleap Enterprise EditionCWE-78OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 1…
CVE-2026-849908.8—ntopntopngCWE-200ntopng: Missing Authorization on System Configuration Backup Download and Lis…
CVE-2026-884098.8—n/an/a—FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer…
CVE-2026-925748.8—Red HatConfidential Compute AttestationCWE-250Cri-o: cri-o checkpoint restore bypasses destination security context
CVE-2026-166518.7—Temporal Technologies, Inc.temporalio/sqlparserCWE-129temporalio/sqlparser malformed MySQL version comments can cause a panic
CVE-2026-616528.7—kap-shzaprosCWE-770Zapros: Streaming decoders ignored the requested chunk size, allowing a singl…
CVE-2026-656518.7—Temporal Technologies, Inc.temporalio/sqlparserCWE-674temporalio/sqlparser deeply nested unary expressions can cause a fatal stack …
CVE-2026-656528.7—Temporal Technologies, Inc.temporalio/tchannel-goCWE-129temporalio/tchannel-go malformed checksum type causes process termination
CVE-2026-656538.7—Temporal Technologies, Inc.temporalio/tchannel-goCWE-129temporalio/tchannel-go zero-chunk call fragment causes process termination
CVE-2026-656548.7—Temporal Technologies, Inc.temporalio/ringpop-goCWE-770temporalio/ringpop-go fails to enforce configured label limits on inbound mem…
CVE-2026-891398.7—Temporal Technologies, Inc.Temporal ServerCWE-78Temporal Server worker deployment compute provider executes a caller-supplied…
CVE-2026-943818.7—MISPMISPCWE-269MISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via up…
CVE-2026-944118.7—jishenghuajshERPCWE-862jshERP 3.6 Privilege Escalation via updateOneValueByKeyIdAndType
CVE-2026-944128.7—jishenghuajshERPCWE-862jshERP through 3.6 Authorization Bypass via resetPwd
CVE-2026-944968.7—jishenghuajshERPCWE-862jshERP through 3.6 Privilege Escalation via Role Management
CVE-2026-944978.7—jishenghuajshERPCWE-639jshERP through 3.6 Unauthorized Access via by-id Endpoints
CVE-2026-945018.7—jishenghuajshERPCWE-862jshERP through 3.6 Privilege Escalation via userBusiness CRUD
CVE-2026-946228.7—vllm-projectvllmCWE-248vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata
CVE-2026-946238.7—vllm-projectvllmCWE-617vLLM through 0.29.0 Denial of Service via NIXL Multi-Prompt Assertion Failure
CVE-2026-946248.7—vllm-projectvllmCWE-770vLLM through 0.29.0 Denial of Service via Unbounded P2P KV Offloading Sessions
CVE-2026-946268.7—vllm-projectvllmCWE-789vLLM through 0.29.0 Memory Exhaustion via Unvalidated NIXL tp_size
CVE-2026-946278.7—vllm-projectvllmCWE-401vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision
CVE-2025-714218.6—uvdeskcore-frameworkCWE-269UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent
CVE-2026-943838.6—MISPMISPCWE-20MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted F…
CVE-2026-944038.5—ColorFuliGameCenterCWE-822ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference
CVE-2026-498118.4—DellCommand | Monitor (DCM)CWE-732Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect…
CVE-2026-550718.4—SepineTammcp-for-stataCWE-94MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_pack…
CVE-2026-943748.3—MISPMISPCWE-472MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows …
CVE-2026-944018.3—MISPMISPCWE-73MISP Arbitrary Local File Read and SSRF via MISP Export Upload
CVE-2026-944888.3—TelegramTelegram DesktopCWE-79Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fix…
CVE-2026-550748.2—chofstedeansible_jailexecCWE-59Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in …
CVE-2026-488268.1—sysadminsmediahomeboxCWE-269HomeBox: Cross-Group Inventory Wipe in Homebox via Global Owner Role and X-Te…
CVE-2026-489758.1—sysadminsmediahomeboxCWE-639HomeBox: Cross-Tenant IDOR in MaintenanceEntry Update and Delete Allows Tampe…
CVE-2026-489768.1—sysadminsmediahomeboxCWE-522HomeBox: Cross-Tenant IDOR in Notifier Update Leaks Shoutrrr Credentials and …
CVE-2026-582698.1—Sync-inserverCWE-288Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
CVE-2026-616288.1—lucasdillmannnginx-ignitionCWE-362nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race…
CVE-2026-623698.1—kubeedgekubeedgeCWE-22KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write o…
CVE-2026-775608.1—tinyauthapptinyauthCWE-178Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (c…
CVE-2026-801108.1—Red HatRed Hat Certificate System 9CWE-863Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break let…
CVE-2026-836218.1—ntopntopngCWE-862ntopng: Missing Authorization Check in REST API Allows Non-Admin Users to Tam…
CVE-2026-941848.1—Red HatRed Hat Enterprise Linux 10CWE-121Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fet…
CVE-2026-659807.9—chartbrewchartbrewCWE-89Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variabl…
CVE-2026-170527.8—zephyrprojectzephyrCWE-787Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allow…
CVE-2026-498107.8—DellCommand Powershell Provider (DCPP)CWE-532Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an …
CVE-2026-555677.8—bleachbitbleachbitCWE-367BleachBit: Exploit File Delete to Escalate Privilege
CVE-2026-814697.8—DellInventory Collector ClientCWE-428Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquote…
CVE-2026-551057.7—laurent22joplinCWE-79Joplin: Fountain embeds allow arbitrary script execution in published notes a…
CVE-2026-633307.7—warp-techwarpgateCWE-285Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allo…
CVE-2026-768987.7—jgraphdrawioCWE-918draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js
CVE-2026-598147.6—laurent22joplinCWE-79Joplin: Stored XSS via inline-served note attachment on published shares
CVE-2026-527417.5—gocdgocdCWE-80GoCD has stored XSS possible via tracking tool link highlighting on Compare P…
CVE-2026-616297.5—lucasdillmannnginx-ignitionCWE-770nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x…
CVE-2026-715437.5—openbaoopenbaoCWE-863OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
CVE-2026-735127.5—envoyproxyenvoyCWE-416Envoy: use-after-free in QUIC on internal redirects
CVE-2026-735137.5—envoyproxyenvoyCWE-20Envoy: oghttp2 upstream trailers incorrect handling
CVE-2026-735477.5—envoyproxyenvoyCWE-20Envoy ext_authz: request `:path` pseudoheader dereferenced w/o null check
CVE-2026-735487.5—envoyproxyenvoyCWE-444Envoy: Cross-user response poisoning via a generic (non-WebSocket) HTTP upgra…
CVE-2026-735507.5—envoyproxyenvoyCWE-401Envoy: HTTP/2 Discarded Host Header 200 GB Header-Copy OOM in Envoy
CVE-2026-735527.5—envoyproxyenvoyCWE-20Envoy: HTTP RBAC safe_regex can fail open on RFC-valid obs-text header values
CVE-2026-735537.5—envoyproxyenvoyCWE-436Envoy: RBAC Authorization Bypass via Path Parameters
CVE-2026-884067.5—n/an/a—FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack …
CVE-2026-884077.5—n/an/a—An out-of-bounds read in the node_token_count/relation_token_count component …
CVE-2026-884117.5—n/an/a—Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply…
CVE-2026-888067.5—x.orglibX11CWE-122libX11 XkbGetMap Reply Heap-based Buffer Overflow
CVE-2026-918637.5—Apache Software FoundationApache NeethiCWE-674Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documen…
CVE-2026-918647.5—Apache Software FoundationApache NeethiCWE-770Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits ca…
CVE-2026-918657.5—Apache Software FoundationApache NeethiCWE-770Apache Neethi: Crafted policy references cause exponential expansion during n…
CVE-2026-918667.5—Apache Software FoundationApache NeethiCWE-770Apache Neethi: Crafted policies cause unbounded work during intersection lead…
CVE-2026-944497.5—Red HatExploit IntelligenceCWE-400Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory le…
CVE-2026-552107.4—laurent22joplinCWE-290Joplin: SAML SSO account takeover via email-based account linking (missing is…
CVE-2026-735467.4—envoyproxyenvoyCWE-79Envoy: Stored XSS in Admin Stats Interface (/stats?format=html)
CVE-2026-759397.4—Red HatRed Hat OpenShift Container Platform 4CWE-347Openshift/oc-mirror: release signature verification: openpgp signatureerror c…
CVE-2026-775237.4—1Panel-devMaxKBCWE-639MaxKB: Cross-workspace model parameter form write
CVE-2026-933407.4—Gladys AssistantGladys AssistantCWE-640Gladys Assistant < 5.1.0 Password Reset Link Poisoning via forgot_password En…
CVE-2026-945407.4—MrPearDesktopSMSCWE-306DesktopSMS 1.11.0 Unauthorized Access via Local Service
CVE-2026-364677.2—n/an/aCWE-434Unrestricted Upload of File with Dangerous Type in core/modules/media.php in …
CVE-2026-878587.2—Temporal Technologies, Inc.Temporal ServerCWE-807Temporal Server completion callback source header can direct attacker-chosen …
CVE-2026-166527.1—Temporal Technologies, Inc.Temporal ServerCWE-606Temporal Server Schedule exclusion search can cause excessive CPU consumption
CVE-2026-494507.1—laurent22joplinCWE-345Joplin desktop Windows auto-updater accepts signed installer from any publish…
CVE-2026-616477.1—roomi-fieldsnotebooklm-mcpCWE-22@roomi-fields/notebooklm-mcp has path traversal in vault.batch tool that allo…
CVE-2026-616877.1—hatchet-devhatchetCWE-287hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state colli…
CVE-2026-884107.1—n/an/a—The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered…
CVE-2026-943687.1—Red HatRed Hat Openshift Data Foundation 4CWE-347Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsi…
CVE-2026-944047.1—MISPMISPCWE-352MISP CSRF vulnerability allows unauthorized attribute modification
CVE-2026-944137.1—jishenghuajshERPCWE-200jshERP through 3.6 Password Hash Disclosure via /user/info
CVE-2026-944957.1—jishenghuajshERPCWE-862jshERP through 3.6 Missing Authorization via systemConfig
CVE-2026-945327.1—dromaralamp-cloudCWE-639lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById
CVE-2026-945337.1—dromaralamp-cloudCWE-639lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file
CVE-2026-945347.1—dromaralamp-cloudCWE-639lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints
CVE-2026-945357.1—dromaralamp-cloudCWE-639lamp-cloud through 5.10.0 Unauthorized Notification Deletion
CVE-2026-494537.0—laurent22joplinCWE-20Joplin: Path traversal in resource sync — silent arbitrary file write outside…
CVE-2026-528357.0—TautulliTautulliCWE-22Tautulli: Path traversal / arbitrary file write via unsanitized upload filena…
CVE-2026-689197.0—gocdgocdCWE-80GoCD has stored XSS possible via forged package material comments on Stage/Jo…
CVE-2026-615416.9—kap-shzaprosCWE-770Zapros has an Unbounded Content-Encoding decompression chain that allows deni…
CVE-2026-775826.9—tinyauthapptinyauthCWE-208Tinyauth: User enumeration attack by timing oracle
CVE-2026-943796.9—MISPMISPCWE-20MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection an…
CVE-2026-946256.9—vllm-projectvllmCWE-772vLLM through 0.29.0 Resource Exhaustion via Ownerless Mooncake Transfer Place…
CVE-2026-582716.8—Sync-inserverCWE-307@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
CVE-2026-633346.8—jgraphdrawioCWE-367draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist
CVE-2026-551796.5—laurent22joplinCWE-639Joplin: Logic error in Joplin Server allows a signed-in user to read any note…
CVE-2026-582706.5—Sync-inserverCWE-1333Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
CVE-2026-617446.5—inventreeInvenTreeCWE-639InvenTree: Barcode-scan API (`POST /api/barcode/`) returns full serialized ob…
CVE-2026-617496.5—inventreeInvenTreeCWE-200InvenTree: Administrative staff users can trigger Arbitrary File Read leading…
CVE-2026-618516.5—chartbrewchartbrewCWE-184Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool
CVE-2026-622476.5—supabaserealtimeCWE-863Supabase Realtime: Incorrect Authorization
CVE-2026-623706.5—kubeedgekubeedgeCWE-789KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote…
CVE-2026-771656.5—NextcloudServerCWE-284File owners were unable to unlock TYPE_TOKEN locks placed by other users, lea…
CVE-2026-799176.5—1Panel-devMaxKBCWE-285MaxKB: Chat share-link endpoint missing owner check: a chat token can publish…
CVE-2026-884086.5—n/an/a—FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack …
CVE-2026-943936.4—MISPMISPCWE-284MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in edi…
CVE-2026-617436.3—chartbrewchartbrewCWE-350Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation
CVE-2026-633426.3—hatchet-devhatchetCWE-863Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authoriza…
CVE-2026-691906.3—Graylog2graylog2-serverCWE-639Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
CVE-2026-799186.3—1Panel-devMaxKBCWE-693MaxKB: Sandbox escape via unhooked fexecve
CVE-2026-799196.3—1Panel-devMaxKBCWE-693MaxKB function-library sandbox escape: dlopen stack-check bypass via importli…
CVE-2026-942776.3—MISPMISPCWE-79Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Ga…
CVE-2026-943726.3—MISPMISPCWE-79Stored Cross-Site Scripting via Unescaped Galaxy Cluster Tag Names in MISP De…
CVE-2026-943736.3—MISPMISPCWE-79MISP DOM-based Cross-Site Scripting via innerHTML in Contextual Menu
CVE-2026-943946.3—MISPMISPCWE-862MISP ObjectReferencesController: Granular Distribution and Sharing Group Rest…
CVE-2026-591686.2—TomWrightdaselCWE-674Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack…
CVE-2026-628666.2—TomWrightdaselCWE-129Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
CVE-2026-364686.1—n/an/aCWE-79Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote una…
CVE-2026-585046.1—jgraphdrawioCWE-79draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass o…
CVE-2026-170516.0—zephyrprojectzephyrCWE-787Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound …
CVE-2026-554736.0—sysadminsmediahomeboxCWE-918HomeBox: Notifier SSRF guard misses NAT64 prefixes (64:ff9b::/96, 64:ff9b:1::…
CVE-2026-911676.0—warp-techwarpgateCWE-862Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allo…
CVE-2026-485215.9—envoyproxyenvoyCWE-476Envoy: HTTP/3 connection pool selection null-derefs in ProdClusterManagerFact…
CVE-2026-505725.9—envoyproxyenvoyCWE-416Envoy: ext_authz - RawHttpClientImpl onSuccess 0x0 segfault
CVE-2026-618525.8—chartbrewchartbrewCWE-89Chartbrew: SQL Injection via row_limit Parameter in AI runQuery Tool
CVE-2026-629875.8—fabiolbfabioCWE-290Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers …
CVE-2026-170505.7—zephyrprojectzephyrCWE-415Double free of the USB host configuration descriptor when device enumeration …
CVE-2026-616125.7—ondatackan-mcp-serverCWE-918@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fi…
CVE-2026-911665.7—warp-techwarpgateCWE-297Warpgate: Web SSH stores a jump host's key against the target's address, so i…
CVE-2026-821635.5—DellCommand | Intel vPro Out of BandCWE-276Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an In…
CVE-2026-821655.5—DellCommand | Integration Suite for System CenterCWE-276Dell Command | Integration Suite for System Center, versions prior to 6.7.2, …
CVE-2026-934335.5—Red HatRed Hat Enterprise Linux 10CWE-121Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow i…
CVE-2026-489745.4—sysadminsmediahomeboxCWE-841HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler
CVE-2026-549155.4—TautulliTautulliCWE-601Tautulli: Open redirect via whitespace bypass in /auth/redirect
CVE-2026-598305.4—discoursediscourseCWE-79Discourse: Stored XSS via unescaped actor name in post actions
CVE-2026-775165.4—1Panel-devMaxKBCWE-639MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch…
CVE-2026-775175.4—1Panel-devMaxKBCWE-639MaxKB cross-knowledge IDOR lets a normal user read and modify documents and p…
CVE-2026-775195.4—1Panel-devMaxKBCWE-613MaxKB: Expired application API keys remain usable on `/chat/api/mcp`
CVE-2026-775205.4—1Panel-devMaxKBCWE-862MaxKB: Homepage ranking leaks application IDs that workflow application-nodes…
CVE-2025-714205.3—uvdeskcore-frameworkCWE-639UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply
CVE-2026-158905.3—zephyrprojectzephyrCWE-323AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to m…
CVE-2026-170545.3—zephyrprojectzephyrCWE-125Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SP…
CVE-2026-527405.3—gocdgocdCWE-863GoCD is vulnerable to pipeline template view API authorization bypass
CVE-2026-545845.3—MidnightBSDmportCWE-73mport trusts environment-controlled temporary directories in privileged metad…
CVE-2026-582725.3—Sync-inserverCWE-208Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST…
CVE-2026-617465.3—inventreeInvenTreeCWE-200InvenTree: Plugin-settings GET endpoints are readable without authentication
CVE-2026-735115.3—envoyproxyenvoyCWE-289Envoy: Potential path-matching/authentication bypass when using Envoy in comb…
CVE-2026-735495.3—envoyproxyenvoyCWE-754Envoy - Incomplete fix for CVE-2026-26310: copyInternetAddressAndPort crashes…
CVE-2026-735515.3—envoyproxyenvoyCWE-647Envoy: Path normalization does not handle dot and dotdot segments with parame…
CVE-2026-770215.3—Checkmk GmbHCheckmkCWE-409Missing decompression size limit in agent receiver allows memory exhaustion v…
CVE-2026-775615.3—tinyauthapptinyauthCWE-307Tinyauth: Unauthenticated login attempts can trigger global login lockdown de…
CVE-2026-884125.3—n/an/a—An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c…
CVE-2026-944145.3—jishenghuajshERPCWE-862jshERP through 3.6 Missing Authorization via updateBtnStr
CVE-2026-944895.3—n/aOctoPrintCWE-22OctoPrint File Download API files.py _validate path traversal
CVE-2026-944945.3—jishenghuajshERPCWE-639jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info
CVE-2026-945365.3—dromaralamp-cloudCWE-639lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/vis…
CVE-2026-364725.2—n/an/aCWE-79CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutra…
CVE-2025-714195.1—uvdeskcore-frameworkCWE-79UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer
CVE-2026-453815.1—TautulliTautulliCWE-79Tautulli: Reflected XSS in `/search` endpoint
CVE-2026-527425.1—gocdgocdCWE-863GoCD is vulnerable to historical server configuration API authorization bypass
CVE-2026-919215.1—1millionbotAI Chatbot Platform (SaaS) de 1millionbot.CWE-79Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform
CVE-2026-933395.1—Metaphor CreationsDittyCWE-79Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute
CVE-2026-943875.1—aureuserpaureuserpCWE-79Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log
CVE-2026-775185.0—1Panel-devMaxKBCWE-862MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by att…
CVE-2026-556254.9—gocdgocdCWE-639GoCD is vulnerable to authorization bypass via material connection test APIs
CVE-2026-633294.9—warp-techwarpgateCWE-116Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enable…
CVE-2026-499954.8—TautulliTautulliCWE-79Tautulli: Stored Cross-Site Scripting (XSS) in the newsletter
CVE-2026-466504.4—laurent22joplinCWE-79Joplin: Stored XSS in public share viewer via javascript: URL bypass in isAcc…
CVE-2026-945884.4—Proxmoxpmg-apiCWE-88In Proxmox pmg-api, an argument injection vulnerability exists in the package…
CVE-2026-527434.3—gocdgocdCWE-639GoCD before 26.1.0 is vulnerable to authorization bypass via job status API
CVE-2026-598154.3—laurent22joplinCWE-863Joplin: Pending share recipients can write items into shared folders before a…
CVE-2026-598164.3—laurent22joplinCWE-22Joplin: Path traversal in transcribe proxy endpoint via URL-encoded slash
CVE-2026-617454.3—inventreeInvenTreeCWE-862InvenTree: Missing authorization on machine restart endpoint allows any authe…
CVE-2026-617474.3—inventreeInvenTreeCWE-639InvenTree: Authenticated IDOR in the data-import API exposes other users' imp…
CVE-2026-617484.3—inventreeInvenTreeCWE-639InvenTree: Report/Label print endpoints ignore per-model permissions
CVE-2026-751584.3—Apache Software FoundationApache AirflowCWE-200Apache Airflow: Assets events API returns asset events for every Dag with no …
CVE-2026-775224.3—1Panel-devMaxKBCWE-918MaxKB: Authenticated full-read SSRF via the knowledge web-document import/syn…
CVE-2026-889784.3—hatchet-devhatchetCWE-639Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task U…
CVE-2026-911644.3—warp-techwarpgateCWE-284Warpgate: API tokens bypass the user's allowed_ip_ranges restriction
CVE-2026-918674.3—Apache Software FoundationApache NeethiCWE-400Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow ser…
CVE-2026-616304.2—lucasdillmannnginx-ignitionCWE-287nginx ignition has TOTP Reuse During Validity Window
CVE-2026-633734.2—jgraphdrawioCWE-352draw.io: OAuth CSRF via missing state validation on self-hosted deployments a…
CVE-2026-775254.2—1Panel-devMaxKBCWE-862MaxKB: Management chat-record routes trust path application_id but load ChatR…
CVE-2026-823554.2—Apache Software FoundationApache AirflowCWE-384Apache Airflow: Session cookie silently overrides explicit Authorization bear…
CVE-2026-616814.1—hatchet-devhatchetCWE-918Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler
CVE-2026-923824.1—Red HatRed Hat Enterprise Linux 10CWE-787Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_pac…
CVE-2026-550603.7—gocdgocdCWE-863GoCD is vulnerable to authorization bypass via support process list API
CVE-2026-634163.7—jgraphdrawioCWE-22draw.io: Path traversal in ExportProxyServlet allows access to arbitrary back…
CVE-2026-852193.7—Thinkst Applied ResearchOpenCanaryCWE-770Denial-of-Service in the OpenCanary Redis service
CVE-2026-852203.7—Thinkst Applied ResearchCanaryCWE-770Denial-of-Service in the Thinkst Canary Redis service
CVE-2026-842983.1—hatchet-devhatchetCWE-639Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispa…
CVE-2026-494492.5—laurent22joplinCWE-200Joplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 cre…
CVE-2026-771662.4—NextcloudCollectivesCWE-840The emoji field in the page emoji update endpoint does not properly validate …
CVE-2026-911652.4—warp-techwarpgateCWE-79Warpgate: Markup injection in SSO form_post return page via unencoded redirec…
CVE-2026-558702.3—gocdgocdCWE-200GoCD is vulnerable to credential exposure when admins insecurely configure ma…
CVE-2026-943822.3—henrygdbeszelCWE-639Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts
CVE-2026-942142.1—ST Engineering iDirectEvolutionCWE-601ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Serv…
CVE-2026-942162.1—ST Engineering iDirectEvolutionCWE-601ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header web…
CVE-2026-942102.0—Hyve5LeantimeCWE-79Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting
CVE-2026-944262.0—xuxuelixxl-jobCWE-79xuxueli xxl-job insert cross site scripting
CVE-2026-942111.9—Hyve5LeantimeCWE-79Hyve5 Leantime Project Dashboard show.blade.php cross site scripting
CVE-2026-926121.0—Eclipse FoundationEclipse iceoryx™CWE-749In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes it…
CVE-2026-36469await—n/an/a—CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/…
CVE-2026-36470await—n/an/a—CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. Th…
CVE-2026-36471await—n/an/a—Deserialization of Untrusted Data of the __post_data parameter in cn_parse_ur…
CVE-2026-67827await—n/an/a—Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 …
CVE-2026-78806await—n/an/a—An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Pr…
CVE-2026-78847await—n/an/a—An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScrip…
CVE-2026-79079await—n/an/a—An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbi…
CVE-2026-79316await—n/an/a—An improper access control vulnerability exists in x-ui 0.3.2. Any authentica…
CVE-2026-79317await—n/an/a—A session invalidation flaw exists in x-ui 0.3.2. The full user object is sto…
CVE-2026-79318await—n/an/a—web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vuln…
CVE-2026-79319await—n/an/a—Stencil core 4.43.5 is vulnerable to Incorrect Access Control.
CVE-2026-79320await—n/an/a—Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerabi…
CVE-2026-88402await—n/an/a—A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 al…
CVE-2026-88403await—n/an/a—A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobas…
CVE-2026-88404await—n/an/a—A remote code execution (RCE) vulnerability in the UniscriptExecutionService.…
CVE-2026-88405await—n/an/a—A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionServ…
CVE-2026-88467await—n/an/a—CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification…
CVE-2026-88738await—n/an/a—Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vul…
CVE-2026-88745await—n/an/a—EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to uploa…
CVE-2026-88746await—n/an/a—idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_de…
CVE-2026-88756await—n/an/a—Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injec…
CVE-2026-93012await——Email-SenderCWE-78Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbit…

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-21 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.