boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 22, 2026 · all times UTC← 2026-09-21 · archive

Security Box Score — September 22, 2026

CISA adds 4 to KEV; 455 CVEs published, led by Adobe (53).

455 CVEs published September 22, 2026: 81 critical, 170 high, 162 medium, 22 low; 3 in the KEV catalog at press time; 2 with a public exploit reference; 20 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 55 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1128146235——
KEV catalog size1721

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

2944 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15075598526251371311560.17.8.0017+91 ▲
microsoft10002899205198669216289301.07.8.0044+531 ▲
google5172684332104911821218090.37.5.0025+446 ▲
red hat1758044733737842200.06.7.0028-13 ▼
apple24656367165317148881.46.5.0020+206 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0021-14 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+51 ▲
ubiquiti665362810334.69.1.0049+6 ▲
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0038+4 ▲
netgear23400277000.04.3.0025-7 ▼
f592671441527.78.7.0045+9 ▲
ivanti10246162025520.88.8.0147+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache104616142260198153320.37.5.0049-27 ▼
mozilla113301102126730900.08.8.0028+54 ▲
drupal2694119668411.15.7.0024+26 ▲
gitlab17935235510533.25.3.0032+2 ▲
github623211100000.07.4.0044+1 ▲
docker3121830000.08.4.0016+1 ▲
wordpress1614102233.38.7.3120-1 ▼
go440211000.05.9.0029+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0034-255 ▼
ibm34196019043731914610.17.5.0030-33 ▼
adobe22483082362376102040.57.5.0023+164 ▲
progress3641539100611.68.1.0035-16 ▼
solarwinds3261853010415.49.1.0058+3 ▲
zohocorp9194960000.08.4.0106+5 ▲
veeam01961030100.08.6.0032-10 ▼
atlassian3918001300.07.6.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link267121261212300.08.5.0154+10 ▲
siemens1552633103000.07.3.0018-4 ▼
synology1946510256000.05.6.0027+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
abb181430000.07.2.0018+1 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1823533116413721210.37.2.0020+126 ▲
sourcecodester582270013493000.05.5.0027+21 ▲
nvidia5118521127370000.07.8.0029+27 ▲
spring017013608215000.06.5.0024-5 ▼
mongodb64162694584100.07.1.0026+32 ▲
itsourcecode371530038115000.02.1.0026+18 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0029+136 ▲
wwbn1061462349740000.06.9.0024+97 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.092995.110.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-86218.074994.210.0
CVE-2026-79756.051592.08.7
CVE-2026-83548.046791.310.0
CVE-2026-76698.041190.36.5
CVE-2026-47864.040890.29.8
CVE-2026-17176.035988.97.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.0929KEV
CVE-2026-8621810.0.0749KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
CVE-2026-8245610.0.0139
Most disclosures (vendor)
VendorCVEs
linux1735
microsoft1008
google848
oracle635
ibm357
adobe265
apple250
red hat215
dell198
apache141
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
ivanti5
adobe4
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven100
Packagist41
npm20
PyPI14
crates.io5
RubyGems2
Go1
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171770
CVE-2021-27102n/a2021-11-171770
CVE-2021-27101n/a2021-11-171770
CVE-2021-27103n/a2021-11-171770
CVE-2021-21017Adobe2021-11-171770
CVE-2021-28550Adobe2021-11-171770
CVE-2021-42013Apache Software Foundation2021-11-171770
CVE-2021-41773Apache Software Foundation2021-11-171770
CVE-2021-30858Apple2021-11-171770
CVE-2021-30860Apple2021-11-171770

Transactions

ADDED TO KEV — CVE-2026-85102 (checkpoint Quantum Security Gateway). Remediation due September 25, 2026.

ADDED TO KEV — CVE-2026-93616 (checkpoint Quantum Security Management). Remediation due September 25, 2026.

ADDED TO KEV — CVE-2026-93952 (Arista Networks VeloCloud Orchestrator (VCO) On-Prem). Remediation due September 25, 2026.

ADDED TO KEV — CVE-2026-94127 (F5 BIG-IP). Remediation due September 25, 2026.

EXPLOIT PUBLISHED — FreeRDP: 4 CVEs (CVE-2026-55191, CVE-2026-55192, CVE-2026-55564, CVE-2026-63652). Public exploit references added.

EXPLOIT PUBLISHED — dromara lamp-cloud: 3 CVEs (CVE-2026-94533, CVE-2026-94534, CVE-2026-94535). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2019-25776 (Weaver Network Co., Ltd. E-cology). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-6851. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-6134 (Red Hat build of Keycloak 22). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-6563 (Red Hat Single Sign-On 7.6 for RHEL 7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44253 (wazuh). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-5704 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91854 (code-projects Record Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92221 (gedelumbung HospitalManagement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92385 (SourceCodester Online Food Ordering System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92475 (GPAC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92526 (itsourcecode Leave Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92993 (Dromara mayfly-go). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93311 (Freedesktop Poppler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93312 (Freedesktop Poppler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93532 (gedelumbung HospitalManagement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93738 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93741 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93954 (grimmory-tools grimmory). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93957 (olivier-ls PHP-FTS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93959 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93960 (Pixelfed). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93962 (Kamailio). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93964 (NginxProxyManager nginx-proxy-manager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93974 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93979 (code-projects Internship Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93984 (Openpanel-dev openpanel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94015 (SourceCodester Drug Recommendation System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94016 (SourceCodester Drug Recommendation System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94032 (itsourcecode Leave Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94037 (00Kisumi00 mcp-file-analyzer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94042 (AdithyaYelloju Restaurant Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94047 (samanhappy MCPHub). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94089 (D-Link DIR-868L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94094 (OpenClaw). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94099 (Netcore NBR200V2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94110 (QCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94139 (Chengdu Feiyuxing Technology Feiyu Star Router). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94152 (Omega Solution FBP Fulfillment by People). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94413 (jishenghua jshERP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94497 (jishenghua jshERP). Public exploit reference added.

DUE DATE PASSED — CVE-2025-39682 (Linux). CISA remediation deadline was September 21, 2026; still in catalog.

DUE DATE PASSED — CVE-2025-39964 (Linux). CISA remediation deadline was September 21, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-53266 (Linux). CISA remediation deadline was September 21, 2026; still in catalog.

REJECTED — CVE-2026-95511 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA.

RESCORED — Microsoft Windows 10 Version 1607: 8 CVEs (CVE-2026-69681, CVE-2026-69688, CVE-2026-69706, CVE-2026-69714, CVE-2026-69717, CVE-2026-69761, CVE-2026-72931, CVE-2026-72978). CVSS rescored — before/after on each CVE page.

RESCORED — Microsoft Windows 10 Version 1809: 3 CVEs (CVE-2026-69689, CVE-2026-69757, CVE-2026-69762). CVSS rescored — before/after on each CVE page.

RESCORED — Okta Access Gateway: 3 CVEs (CVE-2026-78620, CVE-2026-78623, CVE-2026-78626). CVSS rescored — before/after on each CVE page.

RESCORED — Qualcomm, Inc. Snapdragon: 3 CVEs (CVE-2026-24075, CVE-2026-25261, CVE-2026-25278). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2023-4547 (SPA-Cart eCommerce CMS). CVSS 5.1 → 2 (NVD).

RESCORED — CVE-2023-4548 (SPA-Cart eCommerce CMS). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2023-6134 (Red Hat build of Keycloak 22). CVSS 4.6 → 5.4 (NVD).

RESCORED — CVE-2023-6927 (Red Hat build of Keycloak 22). CVSS 4.6 → 6.1 (NVD).

RESCORED — CVE-2026-55564 (FreeRDP). CVSS 5.4 → 7.1 (NVD).

RESCORED — CVE-2026-55748 (OpenStack Horizon). CVSS 6 → 6.8 (NVD).

RESCORED — CVE-2026-58381 (Red Hat Enterprise Linux 6). CVSS 6.1 → 7.3 (NVD).

RESCORED — CVE-2026-69775 (Microsoft Windows 11 version 23H2). CVSS 7.1 → 7.5 (NVD).

RESCORED — CVE-2026-71222 (Red Hat Enterprise Linux 7). CVSS 5.3 → 6.3 (NVD).

RESCORED — CVE-2026-78627 (Okta Hyperdrive Integration Plugin). CVSS 7.3 → 5.5 (NVD).

RESCORED — CVE-2026-78629 (Okta Hyperdrive Agent). CVSS 5.6 → 5.5 (NVD).

RESCORED — CVE-2026-78631 (Okta Hyperdrive Agent). CVSS 5.3 → 5.5 (NVD).

RESCORED — CVE-2026-93295 (misp). CVSS 5.1 → 8.7 (NVD).

RESCORED — CVE-2026-93296 (misp). CVSS 5.1 → 8.5 (NVD).

RESCORED — CVE-2026-94109 (openEQUELLA). CVSS 8.7 → 8.6 (NVD).

RESCORED — CVE-2026-94489 (OctoPrint). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10: 4 CVEs (CVE-2026-5680, CVE-2026-10832, CVE-2026-14180, CVE-2026-85511). Fix versions published.

PATCH SHIPPED — CVE-2026-19730 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 7:5.8.2-9.el10_2.

PATCH SHIPPED — CVE-2026-84217 (Mamunur Rashid Classified Listing). Fixed in Classified Listing 6.1.5.

ENRICHED — CVE-2020-6851. Received CVSS 7.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

455 CVEs published. 25 box scores and 375 table rows below; the remaining 55 continue on page 2 — every CVE is listed, nothing truncated.

Arista Networks VeloCloud Orchestrator (VCO) On-Prem — Security Advisory 0183
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   H   H   H    9.5   .0042   36.3   YES
AFFECTED
  Product                               Versions  Fixed
  VeloCloud Orchestrator (VCO) On-Prem  5.2.0 –   —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 22  Added to CISA KEV, due Sep 25
  Sep 22  Published (CNA: Arista)
CWE-20 · CNA: Arista · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis · KEV due September 25, 2026
checkpoint Quantum Security Management — Directory Traversal and File upload allows execution of arbitrary script on the Management Server
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —   YES
AFFECTED
  Product                      Versions                       Fixed
  Quantum Security Management  R82.20 with no Jumbo Hotfix –  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 22  Added to CISA KEV, due Sep 25
  Sep 22  Published (CNA: checkpoint)
CWE-22 · CNA: checkpoint · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis · KEV due September 25, 2026
F5 BIG-IP — BIG-IP APM OAuth vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3      —      —   YES
AFFECTED
  Product  Versions  Fixed
  BIG-IP   21.1.0 –  —
TIMELINE
  Sep 20  Reserved by CNA
  Sep 22  Added to CISA KEV, due Sep 25
  Sep 22  Published (CNA: f5)
CWE-122 · CNA: f5 · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis · KEV due September 25, 2026
n/a OctoPrint — OctoPrint Command API system.py executeSystemCommand os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0210   80.9     —
AFFECTED
  Product    Versions  Fixed
  OctoPrint  1.0.0 –   —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 22  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
wahid0003 Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels — Product Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0117   66.1     —
AFFECTED
  Product                                                                                        Versions     Fixed
  Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social Channels  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Gigatech PDV5701 WebSocket Service index.html missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0073   52.8     —
AFFECTED
  Product  Versions                Fixed
  PDV5701  1.0.31_240305_112640 –  —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 22  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
realmag777 HUSKY – Products Filter for WooCommerce Professional — HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0065   49.8     —
AFFECTED
  Product                                               Versions     Fixed
  HUSKY – Products Filter for WooCommerce Professional  unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
wptravelengine WP Travel Engine – Tour Booking Plugin – Tour Operator Software — WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0058   46.3     —
AFFECTED
  Product                                                          Versions     Fixed
  WP Travel Engine – Tour Booking Plugin – Tour Operator Software  unspecified  —
TIMELINE
  May 21  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
SeaTheme BM Content Builder — BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Deletion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0057   45.7     —
AFFECTED
  Product             Versions     Fixed
  BM Content Builder  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
SeaTheme BM Content Builder — BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0053   43.9     —
AFFECTED
  Product             Versions     Fixed
  BM Content Builder  unspecified  —
TIMELINE
  Feb 13  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Erlang OTP — SSH daemon allocates unbounded idle session channels, bypassing max_channels
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   H    7.1   .0047   40.3     —
AFFECTED
  Product  Versions                                    Fixed
  OTP      18.1.2 –                                    27.3.4.18
  OTP      4.1.1 –                                     5.2.11.13
  OTP      84df3d4d0278e21a36a453bfee94799f0df67c2a –  79c2d2be17d902c5f53969b5806b725efda831be
TIMELINE
  Aug 17  Reserved by CNA
  Sep 22  Published (CNA: EEF)
CWE-770 · CNA: EEF · CVSS v4.0 · 8 references · NVD status: Deferred
Red Hat Red Hat Enterprise Linux 10 — Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  N  H  H    7.4   .0042   36.3     —
AFFECTED
  Product                                 Versions     Fixed
  Red Hat Enterprise Linux 10             unspecified  —
  Red Hat Enterprise Linux 8              unspecified  —
  Red Hat Enterprise Linux 9              unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
  Red Hat OpenShift Container Platform 4  unspecified  —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 22  Published (CNA: redhat)
CWE-787 · CNA: redhat · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
LiquidWeb Give Tributes — Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0041   34.9     —
AFFECTED
  Product        Versions     Fixed
  Give Tributes  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Erlang OTP — TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   N    9.3   .0037   30.7     —
AFFECTED
  Product  Versions                                    Fixed
  OTP      22.2 –                                      27.3.4.18
  OTP      9.5 –                                       11.2.12.13
  OTP      21b8a1b0ad0adf200682b3854bc50114ab2b8c62 –  afec5156361bb50d3607c7c1a453c19b9149b324
TIMELINE
  Sep 11  Reserved by CNA
  Sep 22  Published (CNA: EEF)
CWE-322 · CNA: EEF · CVSS v4.0 · 8 references · NVD status: Deferred
roxnor WP Ultimate Review — WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0036   29.9     —
AFFECTED
  Product             Versions     Fixed
  WP Ultimate Review  unspecified  —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Unknown Ninja Forms — Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0035   28.4     —
AFFECTED
  Product      Versions  Fixed
  Ninja Forms  3.15.3 –  —
TIMELINE
  Sep 16  Reserved by CNA
  Sep 22  Published (CNA: WPScan)
CWE-79 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0034   28.1     —
AFFECTED
  Product                       Versions     Fixed
  Meta Box Frontend Submission  unspecified  —
TIMELINE
  Jun 25  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 3 references · NVD status: Deferred
niteo CMP – Coming Soon & Maintenance Plugin by NiteoThemes — CMP <= 4.1.17 - Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0033   26.6     —
AFFECTED
  Product                                                Versions     Fixed
  CMP – Coming Soon & Maintenance Plugin by NiteoThemes  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
wptb WP Table Builder – Drag & Drop Table Builder — WP Table Builder <= 2.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  H    7.1   .0031   23.5     —
AFFECTED
  Product                                       Versions     Fixed
  WP Table Builder – Drag & Drop Table Builder  unspecified  —
TIMELINE
  Apr 23  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-863 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
Kompini Tankuam Places — Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0031   23.4     —
AFFECTED
  Product         Versions     Fixed
  Tankuam Places  unspecified  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 22  Published (CNA: INCIBE)
CWE-639 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Unknown Ninja Forms — Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  U  H  H  H    7.5   .0030   23.4     —
AFFECTED
  Product      Versions  Fixed
  Ninja Forms  3.15.3 –  —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 22  Published (CNA: WPScan)
CWE-502 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
cozmoslabs TranslatePress – Translate Multilingual sites with AI Translation — TranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0030   23.3     —
AFFECTED
  Product                                                            Versions     Fixed
  TranslatePress – Translate Multilingual sites with AI Translation  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 13 references · NVD status: Deferred
kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder — Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0029   22.1     —
AFFECTED
  Product                                                                                     Versions     Fixed
  Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder  unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Magepeople inc. Taxi Booking Manager for WooCommerce — WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0028   21.2     —
AFFECTED
  Product                               Versions  Fixed
  Taxi Booking Manager for WooCommerce  n/a –     2.0.8
TIMELINE
  Sep 19  Reserved by CNA
  Sep 22  Published (CNA: Patchstack)
CWE-288 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
ajay Contextual Related Posts — Contextual Related Posts <= 4.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0026   17.4     —
AFFECTED
  Product                   Versions     Fixed
  Contextual Related Posts  unspecified  —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 22  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-944915.517.2YonyouKSOACWE-74Yonyou KSOA search_list.jsp sql injection
CVE-2026-656348.216.7ErlangOTPCWE-407Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder
CVE-2026-184394.316.7themeumTutor LMS – eLearning and online course solutionCWE-639Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference…
CVE-2026-937787.216.3jgwhite33WP Yelp Review SliderCWE-79WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting vi…
CVE-2026-910924.315.4tomdeverwpForo ForumCWE-862wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) …
CVE-2026-938367.214.0wpcleverWPC Product Bundles for WooCommerceCWE-79WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-S…
CVE-2025-144845.314.0kamleshyadavImage BuzzCWE-862Image Buzz <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary API …
CVE-2025-144865.314.0kamleshyadavPixelPlayCWE-862PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API K…
CVE-2025-144875.314.0kamleshyadavHandilyCWE-862Handily <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Stripe …
CVE-2026-167786.412.9livecomposerLive Composer – Free WordPress Website BuilderCWE-79Live Composer <= 2.1.21 - Authenticated (Contributor+) Stored Cross-Site Scri…
CVE-2026-90044.312.4nofearincWP-CRM System – Manage Clients and ProjectsCWE-200WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive I…
CVE-2026-936556.112.2wpdevelopBooking CalendarCWE-79Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fi…
CVE-2026-769745.312.1SAP_SESAP Fiori LaunchpadCWE-95Information Disclosure vulnerability in SAP Fiori Launchpad
CVE-2026-129954.311.9hiroaki-miyashitaCustom Field TemplateCWE-639Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct…
CVE-2026-41234.310.6rwelephant01RW Elephant Rental InventoryCWE-862RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticat…
CVE-2026-76224.310.6codexpertThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & MoreCWE-862ThumbPress <= 6.2.1 - Missing Authorization to Authenticated (Subscriber+) Pl…
CVE-2026-183454.39.6wpusermanagerWP User Manager – User Profile Builder & MembershipCWE-862WP User Manager <= 2.9.18 - Missing Authorization to Authenticated (Subscribe…
CVE-2026-16454.49.5prasunsenHostelCWE-79Hostel <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting …
CVE-2026-887886.89.4UnknownText StylerCWE-79Text Styler <= 1.1.1 - Contributor+ Stored XSS
CVE-2026-944922.19.2YonyouU8cloudCWE-74Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection
CVE-2026-937116.58.7—Dancer2CWE-113Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response h…
CVE-2026-937127.58.5—Dancer2CWE-22Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside pu…
CVE-2026-93709await8.5—Dancer2CWE-41Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equiv…
CVE-2026-937107.56.9—Dancer2CWE-460Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dyi…
CVE-2016-150599.86.8—Net-IDN-EncodeCWE-122Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflo…
CVE-2026-870827.55.6—Net-IDN-EncodeCWE-835Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wro…
CVE-2026-747656.55.3—Net-IDN-EncodeCWE-125Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read…
CVE-2026-747668.45.2—Net-IDN-EncodeCWE-416Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use…
CVE-2026-870797.55.0—Net-IDN-EncodeCWE-407Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via qu…
CVE-2026-870817.55.0—Net-IDN-EncodeCWE-407Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadr…
CVE-2026-870789.15.0—Net-IDN-EncodeCWE-401Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output …
CVE-2026-870809.14.4—Net-IDN-EncodeCWE-1286Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated labe…
CVE-2026-955036.83.0Red HatRed Hat Build of KeycloakCWE-347Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerb…
CVE-2026-786610.0—RTIConnext ProfessionalCWE-121Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core L…
CVE-2026-7336910.0—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-7569910.0—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-7570310.0—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-7572110.0—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-7572310.0—AdobeAdobe Campaign ClassicCWE-863Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVE-2026-7574510.0—AdobeAEM 6.5 Forms JEECWE-863Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)
CVE-2026-7724410.0—soopersetmcp-atlassianCWE-287[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueToken…
CVE-2026-8015510.0—LANTRONIXSLC8000CWE-22Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypas…
CVE-2026-8441210.0—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-8927510.0—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-163469.9—IBMDataStage on Cloud Pak for DataCWE-285DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-181699.9—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-22IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-571499.9—ploneplone.app.portletsCWE-95plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
CVE-2026-756829.9—AdobeAdobe ConnectCWE-89Adobe Connect | Improper Neutralization of Special Elements used in an SQL Co…
CVE-2026-820089.9—AdobeAdobe Campaign ClassicCWE-20Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
CVE-2026-820109.9—AdobeAdobe Campaign ClassicCWE-89Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us…
CVE-2026-820139.9—AdobeAdobe Campaign ClassicCWE-918Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-836609.9—AdobeAdobe Campaign ClassicCWE-918Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-892769.9—AdobeAdobe Campaign ClassicCWE-94Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code …
CVE-2026-127189.8—Karel Electronic Industry and Trade Inc.KarelIPSCWE-89SQLi in Karel Electronics' KarelIPS
CVE-2026-181629.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-94IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181639.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-502IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-252549.8—Qualcomm, Inc.SnapdragonCWE-285Improper authorization in Qualcomm Software Center
CVE-2026-283249.8—SolarWindsObservability Self-HostedCWE-345SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
CVE-2026-651139.8—NVIDIAInfrastructure ControllerCWE-798NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-748499.8—ZohocorpManageEngine ADSelfService PlusCWE-78Remote code execution vulnerability
CVE-2026-767089.8—Hewlett Packard Enterprise (HPE)ALE—Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking An…
CVE-2026-767099.8—Hewlett Packard Enterprise (HPE)ALE—Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking A…
CVE-2026-793139.8—n/an/aCWE-613webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The appli…
CVE-2026-930889.8—SGLangSGLangCWE-502CVE-2026-93088
CVE-2026-174729.6—IBMConcertCWE-269Multiple Vulnerabilities in IBM Concert Software
CVE-2026-820009.6—AdobeAEM 6.5 Forms JEECWE-918Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-…
CVE-2026-824439.6—AdobeAdobe Campaign ClassicCWE-918Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-843889.6—FortinetFortiPAM Chrome ExtensionCWE-1021A improper restriction of rendered ui layers or frames vulnerability in Forti…
CVE-2026-860599.6—DokploydokployCWE-200Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and …
CVE-2026-801439.4—LANTRONIXSLC8000CWE-78Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom…
CVE-2026-801449.4—LANTRONIXSLC8000CWE-78Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom…
CVE-2026-801459.4—LANTRONIXSLC8000CWE-78Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs p…
CVE-2026-801469.4—LANTRONIXSLC8000CWE-121Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc …
CVE-2026-801479.4—LANTRONIXSLC8000CWE-121Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc …
CVE-2026-801519.4—LANTRONIXSLC8000CWE-78Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs dow…
CVE-2026-801529.4—LANTRONIXSLC8000CWE-78Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script …
CVE-2026-801569.4—LANTRONIXSLC8000CWE-22Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload File…
CVE-2026-436419.3—SoftaculousVirtualizorCWE-78Softaculous Virtualizor OS Command Injection via Billing Module Handler
CVE-2026-471169.3—LTSecurityLTK3500SFCWE-798LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH
CVE-2026-633749.3—agronholmanyioCWE-295AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certifica…
CVE-2026-756849.3—AdobeAdobe ConnectCWE-79Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-756869.3—AdobeAdobe ConnectCWE-20Adobe Connect | Improper Input Validation (CWE-20)
CVE-2026-756899.3—AdobeAdobe ConnectCWE-79Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-756979.3—AdobeAdobe ConnectCWE-79Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-756989.3—AdobeAdobe ConnectCWE-79Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
CVE-2026-776219.3—vectordotdevvectorCWE-22Vector: Arbitrary file write in the file sink via templated path (path traver…
CVE-2026-779879.3—GitHubEnterprise ServerCWE-208GitHub Enterprise Server notebook viewer vulnerable to Server-side request fo…
CVE-2026-871219.3—lwIPTCP/IP Stack MQTTCWE-787Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application
CVE-2026-911309.3—home-assistantcoreCWE-80Home Assistant: XSS in Statistics Graph Card
CVE-2026-956759.3—D-LINKDAP-1360CWE-78D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface
CVE-2026-184619.2—RTIConnext ProfessionalCWE-134Use of Externally-Controlled Format String vulnerability in RTI Connext Profe…
CVE-2026-436429.2—SoftaculousVirtualizorCWE-502Softaculous Virtualizor PHP Object Injection via Billing Module Handler
CVE-2026-176359.1—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-306IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-176459.1—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-269IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-192029.1—Googlemcp-toolbox-sdk-pythonCWE-524Token Cache Reuse in mcp-toolbox-sdk-python
CVE-2026-757289.1—AdobeAdobe Campaign ClassicCWE-863Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVE-2026-772549.1—soopersetmcp-atlassianCWE-306MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured …
CVE-2026-819959.1—AdobeAEM 6.5 Forms JEECWE-20Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20)
CVE-2026-820099.1—AdobeAdobe Campaign ClassicCWE-89Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us…
CVE-2026-820119.1—AdobeAdobe Campaign ClassicCWE-89Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us…
CVE-2026-857349.1—HKUDSLightRAGCWE-307LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CVE-2026-944569.1—GitroomHQpostiz-appCWE-330Unauthenticated recovery of the Math.random() state behind OAuth tokens, auth…
CVE-2026-956549.1—David-CrtyDatabasementCWE-863Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token
CVE-2026-801548.9—LANTRONIXSLC8000CWE-330Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Valid…
CVE-2026-130878.8—Red HatRed Hat Enterprise Linux 10CWE-787Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server rep…
CVE-2026-164688.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-164698.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-166728.8—IBMDataStage on Cloud Pak for Data—DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-171028.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-176368.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-787IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-176378.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-502IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-176438.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-522IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-176448.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-798IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-176478.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-829IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-252558.8—Qualcomm, Inc.SnapdragonCWE-749Exposed function in Qualcomm Package Manager and Qualcomm Software Center.
CVE-2026-252648.8—Qualcomm, Inc.SnapdragonCWE-427Uncontrolled Search Path Element in Qualcomm Software Center
CVE-2026-252658.8—Qualcomm, Inc.SnapdragonCWE-378Creation of Temporary File with Insecure Permissions in Qualcomm Software Center
CVE-2026-283258.8—SolarWindsObservability Self-HostedCWE-502SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vu…
CVE-2026-651288.8—NVIDIAInfrastructure ControllerCWE-89NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-651798.8—NVIDIANeMo SpeechCWE-502NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it d…
CVE-2026-704108.8—Apache Software FoundationApache Calcite AvaticaCWE-470Apache Calcite Avatica: Unrestricted class initialization when instantiating …
CVE-2026-772438.8—soopersetmcp-atlassianCWE-862MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
CVE-2026-772748.8—soopersetmcp-atlassianCWE-918MCP Atlassian: SSRF Protection Bypass
CVE-2026-884198.8—n/an/aCWE-434An unrestricted upload of files with a dangerous type in the thumbnail-upload…
CVE-2026-184598.7—RTIConnext ProfessionalCWE-682Incorrect Calculation vulnerability in RTI Connext Professional (Core Librari…
CVE-2026-436438.7—SoftaculousVirtualizorCWE-862Softaculous Virtualizor Authorization Bypass via Billing Module Handler
CVE-2026-676158.7—Apereo FoundationopenEQUELLACWE-184openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Inv…
CVE-2026-776198.7—vectordotdevvectorCWE-130Vector: Unauthenticated denial of service in the `logstash` source via unboun…
CVE-2026-776208.7—vectordotdevvectorCWE-409Vector: Unauthenticated denial of service in the `logstash` source via nested…
CVE-2026-819998.7—AdobeAEM 6.5 Forms JEECWE-918Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-…
CVE-2026-908828.7—Eclipse Foundationopen-vsx.orgCWE-942Reflected arbitrary origins with credentials, allowing cross-origin reads of …
CVE-2026-910188.7—lwIPlwIP APICWE-415Double Free in lwIP (lightweight IP)
CVE-2026-933458.7—MikroTikRouterOSCWE-1284MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-…
CVE-2026-944508.7—AWSs2n-quicCWE-1284Potential denial of service when configured to send Retry packets in s2n-quic
CVE-2026-956538.7—concretecms-community-storecommunity_storeCWE-340Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token
CVE-2026-346898.6—AdobeAdobe ConnectCWE-22Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory (…
CVE-2026-757918.6—ZohocorpManageEngine ADSelfService PlusCWE-306Authentication bypass vulnerability
CVE-2026-772488.6—soopersetmcp-atlassianCWE-22MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachmen…
CVE-2026-772558.6—soopersetmcp-atlassianCWE-22MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA u…
CVE-2026-772628.6—soopersetmcp-atlassianCWE-22MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_atta…
CVE-2026-852798.6—notepad-plus-plusnotepad-plus-plusCWE-121Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLex…
CVE-2026-956558.6—aureuserpaureuserpCWE-639Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel
CVE-2026-958148.6—dani-garciavaultwardenCWE-863Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check
CVE-2026-176468.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-611IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-180958.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-787IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-820038.5—AdobeAdobe Campaign ClassicCWE-20Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
CVE-2026-836038.4—netdatanetdataCWE-73Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle…
CVE-2026-184578.3—RTIConnext ProfessionalCWE-122Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Li…
CVE-2026-651148.3—NVIDIAInfrastructure ControllerCWE-306NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-772478.3—soopersetmcp-atlassianCWE-73MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachme…
CVE-2026-772518.3—soopersetmcp-atlassianCWE-1276MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidde…
CVE-2026-772568.3—soopersetmcp-atlassianCWE-732MCP Atlassian: OAuth refresh-token backup file is world-readable under defaul…
CVE-2026-772578.3—soopersetmcp-atlassianCWE-22MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
CVE-2026-772608.3—soopersetmcp-atlassianCWE-22MCP Atlassian: Arbitrary local file READ via unconstrained file_path in uploa…
CVE-2026-772678.3—soopersetmcp-atlassianCWE-918mcp-atlassian has an incomplete SSRF remediation
CVE-2026-772718.3—soopersetmcp-atlassianCWE-22MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrit…
CVE-2026-180748.2—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-287IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181318.2—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-79IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-651218.2—NVIDIAInfrastructure ControllerCWE-287NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-871198.2—ZenHivemppCWE-294mpp Tempo subscription key authorization is not bound to the issuing challeng…
CVE-2026-181378.1—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-89IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-756078.1—blakeblackshearfrigateCWE-862Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Oper…
CVE-2026-757448.1—AdobeAEM 6.5 Forms JEECWE-79Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-879028.1—WordPressWordPressCWE-98An unauthenticated attacker can make `get_page_template()` page-template reso…
CVE-2026-181548.0—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-321IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-651308.0—NVIDIAInfrastructure ControllerCWE-78NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-180667.9—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-918IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-242397.8—NVIDIANeMo SpeechCWE-502NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious…
CVE-2026-242677.8—NVIDIANeMo SpeechCWE-502NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech d…
CVE-2026-651117.8—NVIDIANeMo SpeechCWE-77NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious…
CVE-2026-651787.8—NVIDIANeMo SpeechCWE-502NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a …
CVE-2026-756497.8—AdobeAdobe BridgeCWE-122Bridge | Heap-based Buffer Overflow (CWE-122)
CVE-2026-756557.8—AdobeAdobe BridgeCWE-674Bridge | Uncontrolled Recursion (CWE-674)
CVE-2026-756587.8—AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-756637.8—AdobeAdobe BridgeCWE-787Bridge | Out-of-bounds Write (CWE-787)
CVE-2026-756657.8—AdobeAdobe BridgeCWE-122Bridge | Heap-based Buffer Overflow (CWE-122)
CVE-2026-756767.8—AdobeAdobe BridgeCWE-121Bridge | Stack-based Buffer Overflow (CWE-121)
CVE-2026-776057.8—notepad-plus-plusnotepad-plus-plusCWE-20Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target…
CVE-2026-799067.8—AdobeSubstance3D - ModelerCWE-787Substance3D - Modeler | Out-of-bounds Write (CWE-787)
CVE-2026-819987.8—AdobeSubstance3D - ModelerCWE-787Substance3D - Modeler | Out-of-bounds Write (CWE-787)
CVE-2026-835987.8—netdatanetdataCWE-269Netdata: Local Privilege Escalation in Netdata Agent Windows installer via Po…
CVE-2026-839627.8—AdobeSubstance3D - ModelerCWE-121Substance3D - Modeler | Stack-based Buffer Overflow (CWE-121)
CVE-2026-839637.8—AdobeSubstance3D - ModelerCWE-787Substance3D - Modeler | Out-of-bounds Write (CWE-787)
CVE-2026-860547.8—notepad-plus-plusnotepad-plus-plusCWE-121Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlon…
CVE-2026-958317.8——Crypt-SelfCertificateCWE-506Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malw…
CVE-2026-88497.7—RTIConnext ProfessionalCWE-416Use After Free vulnerability in RTI Connext Professional (Security Plugins) a…
CVE-2026-756087.7—blakeblackshearfrigateCWE-863Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive …
CVE-2026-772587.7—soopersetmcp-atlassianCWE-22MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing…
CVE-2026-772597.7—soopersetmcp-atlassianCWE-22MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows ex…
CVE-2026-801487.7—LANTRONIXSLC8000CWE-918Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation
CVE-2026-801497.7—LANTRONIXSLC8000CWE-918Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter
CVE-2026-801507.7—LANTRONIXSLC8000CWE-918Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter
CVE-2026-838037.7—getsentrysentryCWE-502Sentry: Unsafe pickle deserialization in Relocation Feature
CVE-2026-956197.7—Red HatRed Hat Hardened ImagesCWE-190Gcc: libstdc++ integer overflow in `new` operator
CVE-2026-958067.7—MISPMISPCWE-74MISP: PHP phar stream wrapper enables deserialization and code execution via …
CVE-2026-181237.6—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-470IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-941177.6—DevItemsHashBar – WordPress Notification BarCWE-89WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injectio…
CVE-2026-181347.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-319IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-194807.5—AdobeContent Credentials Rust SDKCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-582687.5—emiagosipgoCWE-789SIPGO: DoS via unvalidated Content-Length in the stream parser
CVE-2026-599917.5—psd-toolspsd-toolsCWE-789psd-tools: Uncontrolled memory allocation in psd-tools composite/numpy via cr…
CVE-2026-615707.5—jonilesmpxjCWE-611MPXJ: XXE Vulnerability in MerlinReader
CVE-2026-616857.5—fecommunityreactpressCWE-89ReactPress has SQL injection via dynamic column names in TypeORM query builders
CVE-2026-629857.5—azurequest-filtering-agentCWE-248request-filtering-agent: Synchronous throw from createConnection() for litera…
CVE-2026-651187.5—NVIDIAInfrastructure ControllerCWE-295NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-756327.5—AdobeContent Credentials Rust SDKCWE-400CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
CVE-2026-767107.5—Hewlett Packard Enterprise (HPE)ALE—Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE …
CVE-2026-767117.5—Hewlett Packard Enterprise (HPE)ALE—Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analyti…
CVE-2026-772427.5—soopersetmcp-atlassianCWE-367MCP Atlassian: Incomplete fix for CVE-2026-27826: DNS rebinding bypasses SSRF…
CVE-2026-773227.5—emiagosipgoCWE-789SIPGO: DoS via unvalidated WebSocket frame length
CVE-2026-775447.5—Ubiquiti IncDream MachinesCWE-787A malicious actor with access to the network could exploit an Out-of-bounds W…
CVE-2026-775557.5—Ubiquiti IncDream MachinesCWE-787A malicious actor with access to the network could exploit an Out-of-bounds W…
CVE-2026-775567.5—Ubiquiti IncDream MachinesCWE-125A malicious actor with access to the network could exploit an Out-of-bounds R…
CVE-2026-775587.5—Ubiquiti IncDream MachinesCWE-125A malicious actor with access to the network could exploit an Out-of-bounds R…
CVE-2026-835997.5—netdatanetdataCWE-409Netdata: WebSocket Decompression Bomb
CVE-2026-894077.5—FasterXMLjackson-coreCWE-400jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLi…
CVE-2026-946407.5—Red HatRed Hat Enterprise Linux 10CWE-400Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows un…
CVE-2026-958617.5—Ubiquiti IncDream MachinesCWE-674A malicious actor with access to the network could exploit an Uncontrolled Re…
CVE-2026-958627.5—Ubiquiti IncDream MachinesCWE-787A malicious actor with access to the network could exploit an Out-of-bounds W…
CVE-2026-962697.5—GNUEmacsCWE-829GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a fi…
CVE-2026-181527.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-347IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181727.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-611IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181767.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-319IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-772467.4—soopersetmcp-atlassianCWE-22MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated…
CVE-2026-779127.4—GitHubEnterprise ServerCWE-79Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed…
CVE-2026-176187.3—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-862IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-184627.3—RTIConnext ProfessionalCWE-190Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI …
CVE-2026-199157.3—HP IncHP Support AssistantCWE-269HP Support Assistant - Local Escalation of Privilege
CVE-2026-566817.3—decolua9routerCWE-8079Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip H…
CVE-2026-767127.3—Hewlett Packard Enterprise (HPE)ALECWE-200Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denia…
CVE-2026-859957.3—notepad-plus-plusnotepad-plus-plusCWE-347Notepad++: Authenticode verification bypass allows modified updater execution
CVE-2026-631047.2—usekaneokaneoCWE-862Kaneo 2.3.12 < 2.12.2 Missing Authorization via Bulk Task Endpoint
CVE-2026-767137.2—Hewlett Packard Enterprise (HPE)ALECWE-269Authenticated Remote File System Access Vulnerability in HPE Networking Analy…
CVE-2026-767147.2—Hewlett Packard Enterprise (HPE)ALECWE-78Authenticated Remote Code Execution with Elevated Privileges Vulnerability in…
CVE-2026-943677.2—OpenEyeApex Network Video Recorder (NVR)CWE-78OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS c…
CVE-2026-958157.2—OpenClawOpenClaw iOSCWE-532OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging
CVE-2026-757437.1—AdobeAEM 6.5 Forms JEECWE-352Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352)
CVE-2026-767157.1—Hewlett Packard Enterprise (HPE)ALECWE-300Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulne…
CVE-2026-772537.1—soopersetmcp-atlassianCWE-22MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary…
CVE-2026-772617.1—soopersetmcp-atlassianCWE-918MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth auth…
CVE-2026-774267.1—UnleashunleashCWE-639Unleash: Missing await on permission check + cross-project IDOR in admin API
CVE-2026-776337.1—cloudrevecloudreveCWE-362Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based de…
CVE-2026-843957.1—AdobePremiereCWE-918Premiere Pro | Server-Side Request Forgery (SSRF) (CWE-918)
CVE-2026-850557.1—twentyhqtwentyCWE-200Twenty: Field-level read bypass
CVE-2026-857407.1—HKUDSLightRAGCWE-918LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6t…
CVE-2026-894207.1—ZenHivemppCWE-1284Session voucher adding no new funds is accepted without a charge in mpp, serv…
CVE-2026-933437.1—WebWizardsMarketKingCWE-862MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax
CVE-2026-933447.1—WebWizardsMarketKingCWE-862MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX
CVE-2026-944557.1—GitroomHQpostiz-appCWE-306Unauthenticated /enterprise/create-user mints lifetime top-tier organizations…
CVE-2026-944627.1—spreespreeCWE-639Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
CVE-2026-835977.0—netdatanetdataCWE-269Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MS…
CVE-2026-113886.9—RTIConnext ProfessionalCWE-415Double Free vulnerability in RTI Connext Professional (Core Libraries) allows…
CVE-2026-184606.9—RTIConnext ProfessionalCWE-193Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Profession…
CVE-2026-252626.9—Qualcomm, Inc.SnapdragonCWE-123Write-what-where Condition in Primary Bootloader
CVE-2026-636276.9—wevmmppxCWE-20mppx: Gas Draining with padding
CVE-2026-636286.9—wevmmppxCWE-20mppx: Gas Draining with access list
CVE-2026-954996.9—JosephChuksphp-file-manager-with-code-editorCWE-284JosephChuks php-file-manager-with-code-editor filemanager.php move_uploaded_f…
CVE-2026-956586.9—MISPMISPCWE-352MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-sit…
CVE-2026-956676.9—MISPMISPCWE-22MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Creden…
CVE-2026-956796.9—MISPMISPCWE-20MISP Unauthenticated Blind SSRF via XML Body Processing
CVE-2026-957546.9—MISPMISPCWE-285MISP: Disabled-user check ineffective in pre-authentication TOTP login branch
CVE-2026-113896.8—RTIConnext ProfessionalCWE-125Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access …
CVE-2026-184586.8—RTIConnext ProfessionalCWE-125Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access …
CVE-2026-186266.8—RTIConnext ProfessionalCWE-125Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries)…
CVE-2026-793126.8—n/an/aCWE-384webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._l…
CVE-2026-956246.8—Tauritauri-plugin-updaterCWE-284Tauri framework v2 malicious downgrade via allow_downgrades from frontend code
CVE-2026-632786.7—The Document FoundationLibreOfficeCWE-200Package URLs can be used to exfiltrate arbitrary INI file values and environm…
CVE-2026-651296.7—NVIDIAInfrastructure ControllerCWE-295NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-852886.7—notepad-plus-plusnotepad-plus-plusCWE-78Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Mac…
CVE-2026-651256.6—NVIDIAInfrastructure ControllerCWE-73NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-164266.5—IBMConcertCWE-918Multiple Vulnerabilities in IBM Concert Software
CVE-2026-174656.5—IBMConcertCWE-400Multiple Vulnerabilities in IBM Concert Software
CVE-2026-181146.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-22IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181246.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-522IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181326.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-862IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181566.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-862IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181706.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-770IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-575766.5—ploneplone.app.dexterityCWE-400plone.app.dexterity and plone.app.contenttypes have a Denial of Service due t…
CVE-2026-651126.5—NVIDIAInfrastructure ControllerCWE-400NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-651156.5—NVIDIAInfrastructure ControllerCWE-400NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-755176.5—novuhqnovuCWE-639Novu: Cross-Environment Integration Manipulation (IDOR)
CVE-2026-756386.5—AdobeContent Credentials Rust SDKCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-772526.5—soopersetmcp-atlassianCWE-284MCP Atlassian: JIRA_PROJECTS_FILTER and CONFLUENCE_SPACES_FILTER can be bypas…
CVE-2026-772666.5—soopersetmcp-atlassianCWE-22MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read…
CVE-2026-772696.5—soopersetmcp-atlassianCWE-22MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read…
CVE-2026-772706.5—soopersetmcp-atlassianCWE-22MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
CVE-2026-773996.5—collectiveicalendarCWE-400icalendar: Denial of service via unbounded VALARM REPEAT expansion
CVE-2026-799136.5—cloudrevecloudreveCWE-697Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrapper…
CVE-2026-836006.5—netdatanetdataCWE-193Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB alloca…
CVE-2026-836016.5—netdatanetdataCWE-190Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing…
CVE-2026-836026.5—netdatanetdataCWE-284Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist…
CVE-2026-929286.5—OpenEyeApex Network Video Recorder (NVR)CWE-798OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardc…
CVE-2026-962606.5—MattermostMattermostCWE-789Mattermost server missing request body size limit on plugin routes allows den…
CVE-2026-838056.4—nautobotnautobotCWE-285Nautobot: Authorization bypass in approval workflow REST API allows self-appr…
CVE-2026-943846.4—Amazonamazon-connect-salesforce-lambdaCWE-862Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Conn…
CVE-2026-843016.3—labringFastGPTCWE-918FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected …
CVE-2026-868056.3—The GNU C LibraryglibcCWE-367AT_SECURE programs may load attacker-controlled code via $ORIGIN
CVE-2026-880106.3—traefiktraefikCWE-208Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated us…
CVE-2026-159156.2—IBMConcertCWE-552Multiple Vulnerabilities in IBM Concert Software
CVE-2026-839646.2—AdobeAdobe ConnectCWE-295Adobe Connect | Improper Certificate Validation (CWE-295)
CVE-2026-929306.2—OpenEyeApex Network Video Recorder (NVR)CWE-330OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administ…
CVE-2026-483616.1—AdobeAdobe ConnectCWE-79Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-772506.1—soopersetmcp-atlassianCWE-312MCP Atlassian: OAuth fallback token storage writes plaintext access and refre…
CVE-2026-860626.1—HKUDSLightRAGCWE-79LightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer…
CVE-2026-751016.0—GitHubEnterprise ServerCWE-639Authorization bypass vulnerability in GitHub Enterprise Server allowed readin…
CVE-2025-360845.9—IBMConcertCWE-327Multiple Vulnerabilities in IBM Concert Software
CVE-2026-651245.9—NVIDIAInfrastructure ControllerCWE-91NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-772655.9—soopersetmcp-atlassianCWE-918MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
CVE-2026-857255.9—HKUDSLightRAGCWE-208LightRAG: Plaintext Passwords Compared Without Constant-Time Function
CVE-2026-945705.9—SGLangSGLangCWE-1287CVE-2026-94570
CVE-2026-956235.6—Tauritauri-plugin-httpCWE-918Tauri framework v2 SSRF Protection Bypass via HTTP Redirects
CVE-2026-756335.5—AdobeContent Credentials Rust SDKCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-756565.5—AdobeAdobe BridgeCWE-125Bridge | Out-of-bounds Read (CWE-125)
CVE-2026-761925.5—AdobeInDesign DesktopCWE-476InDesign Desktop | NULL Pointer Dereference (CWE-476)
CVE-2026-768045.5—projectdiscoverynucleiCWE-284Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
CVE-2026-772685.5—soopersetmcp-atlassianCWE-732MCP Atlassian: Insecure File Permissions on OAuth Token Storage
CVE-2026-797675.5—gardenergardenerCWE-863Gardener: Authorization Bypass via Group Subject Injection
CVE-2026-818785.5—radareorgradare2CWE-190radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser
CVE-2026-818795.5—radareorgradare2CWE-125radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling
CVE-2026-818805.5—radareorgradare2CWE-400radare2: Uncontrolled resource consumption in radare2 PEF loader
CVE-2026-818855.5—radareorgradare2CWE-770radare2: Infinite relocation-chain loop causes denial of service in radare2 N…
CVE-2026-818865.5—radareorgradare2CWE-770radare2: Uncontrolled memory allocation in radare2 dmp64 parser
CVE-2026-843965.5—AdobeInDesign DesktopCWE-476InDesign Desktop | NULL Pointer Dereference (CWE-476)
CVE-2026-860565.5—notepad-plus-plusnotepad-plus-plusCWE-476Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler cause…
CVE-2026-892775.5—AdobeContent Credentials Rust SDKCWE-190CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
CVE-2026-952715.5—dgtlmoonchangedetection.ioCWE-287dgtlmoon changedetection.io Authentication Hook flask_app.py check_authentica…
CVE-2026-955005.5—JosephChuksphp-file-manager-with-code-editorCWE-284JosephChuks php-file-manager-with-code-editor Save codeEditor.php file_put_co…
CVE-2026-956565.5—dgtlmoonchangedetection.ioCWE-918dgtlmoon changedetection.io Preview Endpoint __init__.py add_watch_ui_snapsho…
CVE-2026-958195.5—anirbandutta9College-Notes-GalleryCWE-74anirbandutta9 College-Notes-Gallery login.php sql injection
CVE-2026-962595.5—MattermostMattermostCWE-918Mattermost server-side request forgery via OAuth endpoints configurable by a …
CVE-2026-181335.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-22IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181535.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-327IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-632725.4—The Document FoundationLibreOfficeCWE-125Heap buffer overflow in WMF text record import
CVE-2026-632735.4—The Document FoundationLibreOfficeCWE-787Heap buffer overflow in PDF import encryption handling
CVE-2026-632745.4—The Document FoundationLibreOfficeCWE-125Heap buffer overflow in PDF import stream handling
CVE-2026-632755.4—The Document FoundationLibreOfficeCWE-787Stack buffer overflow in CFF font hint handling
CVE-2026-632765.4—The Document FoundationLibreOfficeCWE-787Stack buffer overflow in CFF to Type 1 font conversion
CVE-2026-632795.4—The Document FoundationLibreOfficeCWE-125Out of bounds read in PICT image import
CVE-2026-772725.4—soopersetmcp-atlassianCWE-79MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
CVE-2026-838015.4—nautobotnautobotCWE-79Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
CVE-2026-904625.4—Red HatRed Hat Enterprise Linux 10CWE-280Sssd: sssd: fail-open in ldap ppolicy access check allows continued authoriza…
CVE-2026-911295.4—home-assistantcoreCWE-918Home Assistant: mDNS Server-Side Request Forgery
CVE-2025-127675.3—IBMConcertCWE-770Multiple Vulnerabilities in IBM Concert Software
CVE-2026-176205.3—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-523IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-566825.3—decolua9routerCWE-3079Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
CVE-2026-633865.3—sunnyadnjs-tomlCWE-674js-toml: Uncontrolled recursion in `load()` causes `RangeError` (stack exhaus…
CVE-2026-658295.3—jonilesmpxjCWE-22MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak…
CVE-2026-755115.3—novuhqnovuCWE-918Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs
CVE-2026-767165.3—Hewlett Packard Enterprise (HPE)ALECWE-770Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilit…
CVE-2026-767175.3—Hewlett Packard Enterprise (HPE)ALECWE-200Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE …
CVE-2026-768035.3—projectdiscoverynucleiCWE-284Nuclei: Local File Read via MySQL Client Sandbox Bypass
CVE-2026-768055.3—projectdiscoverynucleiCWE-200Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuz…
CVE-2026-769105.3—UnleashunleashCWE-639Unleash: Clone-feature lets a user copy a feature from a project they cannot …
CVE-2026-772495.3—soopersetmcp-atlassianCWE-918MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unh…
CVE-2026-857095.3—HKUDSLightRAGCWE-209LightRAG: Sensitive Information Exposure Through Raw Exception Messages in AP…
CVE-2026-880205.3—Autonomy LogicOpenPLC RuntimeCWE-79Improper Neutralization of Input During Web Page Generation in OpenPLC Runtim…
CVE-2026-909905.3—Checkmk GmbHCheckmkCWE-93Livestatus injection via monitoring filter values
CVE-2026-928825.3—Checkmk GmbHCheckmkCWE-522Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config …
CVE-2026-929295.3—OpenEyeApex Network Video Recorder (NVR)CWE-290OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forw…
CVE-2026-933415.3—WebWizardsMarketKingCWE-862MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX
CVE-2026-933425.3—WebWizardsMarketKingCWE-862MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX
CVE-2026-956715.3—MISPMISPCWE-285MISP Collections: Missing Authorization Check for Sharing Group on PUT Reques…
CVE-2026-956745.3—MISPMISPCWE-20MISP EventsController queryEnrichment allows querying unavailable or legacy m…
CVE-2026-956835.3—MISPMISPCWE-639MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL
CVE-2026-956855.3—MISPMISPCWE-862MISP Missing Authorization on replaceSuggestionInReport Event Report Action
CVE-2026-956935.3—MISPMISPCWE-22MISP Information Disclosure via Forged Upload Path
CVE-2026-956975.3—MISPMISPCWE-862MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Or…
CVE-2026-956985.3—MISPMISPCWE-22MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name
CVE-2026-958055.3—MISPMISPCWE-285MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended a…
CVE-2026-958125.3—MacWarriorclipbucket-v5CWE-79ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters
CVE-2026-958135.3—e621nge621ngCWE-601e621ng before 26.09.16 Open Redirect via URL Parameters
CVE-2026-958295.3—TDuckCloudtduck-platformCWE-89TDuckCloud tduck-platform Pagination Inner Interceptor MybatisPlusConfig.java…
CVE-2026-958305.3—theRealSainPixtreamCWE-434theRealSain Pixtream post_upload.php unrestricted upload
CVE-2026-958335.3—itsourcecodeLeave Management SystemCWE-89itsourcecode Leave Management System index.php sql injection
CVE-2026-755105.1—novuhqnovuCWE-79Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: sc…

Results continue: ranks 401–455.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-22 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.