| CVE-2026-94491 | 5.5 | 17.2 | Yonyou | KSOA | CWE-74 | Yonyou KSOA search_list.jsp sql injection |
| CVE-2026-65634 | 8.2 | 16.7 | Erlang | OTP | CWE-407 | Superlinear CPU denial of service in Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder |
| CVE-2026-18439 | 4.3 | 16.7 | themeum | Tutor LMS – eLearning and online course solution | CWE-639 | Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference… |
| CVE-2026-93778 | 7.2 | 16.3 | jgwhite33 | WP Yelp Review Slider | CWE-79 | WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting vi… |
| CVE-2026-91092 | 4.3 | 15.4 | tomdever | wpForo Forum | CWE-862 | wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) … |
| CVE-2026-93836 | 7.2 | 14.0 | wpclever | WPC Product Bundles for WooCommerce | CWE-79 | WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-S… |
| CVE-2025-14484 | 5.3 | 14.0 | kamleshyadav | Image Buzz | CWE-862 | Image Buzz <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary API … |
| CVE-2025-14486 | 5.3 | 14.0 | kamleshyadav | PixelPlay | CWE-862 | PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API K… |
| CVE-2025-14487 | 5.3 | 14.0 | kamleshyadav | Handily | CWE-862 | Handily <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Stripe … |
| CVE-2026-16778 | 6.4 | 12.9 | livecomposer | Live Composer – Free WordPress Website Builder | CWE-79 | Live Composer <= 2.1.21 - Authenticated (Contributor+) Stored Cross-Site Scri… |
| CVE-2026-9004 | 4.3 | 12.4 | nofearinc | WP-CRM System – Manage Clients and Projects | CWE-200 | WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive I… |
| CVE-2026-93655 | 6.1 | 12.2 | wpdevelop | Booking Calendar | CWE-79 | Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fi… |
| CVE-2026-76974 | 5.3 | 12.1 | SAP_SE | SAP Fiori Launchpad | CWE-95 | Information Disclosure vulnerability in SAP Fiori Launchpad |
| CVE-2026-12995 | 4.3 | 11.9 | hiroaki-miyashita | Custom Field Template | CWE-639 | Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct… |
| CVE-2026-4123 | 4.3 | 10.6 | rwelephant01 | RW Elephant Rental Inventory | CWE-862 | RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticat… |
| CVE-2026-7622 | 4.3 | 10.6 | codexpert | ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & More | CWE-862 | ThumbPress <= 6.2.1 - Missing Authorization to Authenticated (Subscriber+) Pl… |
| CVE-2026-18345 | 4.3 | 9.6 | wpusermanager | WP User Manager – User Profile Builder & Membership | CWE-862 | WP User Manager <= 2.9.18 - Missing Authorization to Authenticated (Subscribe… |
| CVE-2026-1645 | 4.4 | 9.5 | prasunsen | Hostel | CWE-79 | Hostel <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting … |
| CVE-2026-88788 | 6.8 | 9.4 | Unknown | Text Styler | CWE-79 | Text Styler <= 1.1.1 - Contributor+ Stored XSS |
| CVE-2026-94492 | 2.1 | 9.2 | Yonyou | U8cloud | CWE-74 | Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection |
| CVE-2026-93711 | 6.5 | 8.7 | — | Dancer2 | CWE-113 | Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response h… |
| CVE-2026-93712 | 7.5 | 8.5 | — | Dancer2 | CWE-22 | Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside pu… |
| CVE-2026-93709 | await | 8.5 | — | Dancer2 | CWE-41 | Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equiv… |
| CVE-2026-93710 | 7.5 | 6.9 | — | Dancer2 | CWE-460 | Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dyi… |
| CVE-2016-15059 | 9.8 | 6.8 | — | Net-IDN-Encode | CWE-122 | Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflo… |
| CVE-2026-87082 | 7.5 | 5.6 | — | Net-IDN-Encode | CWE-835 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wro… |
| CVE-2026-74765 | 6.5 | 5.3 | — | Net-IDN-Encode | CWE-125 | Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read… |
| CVE-2026-74766 | 8.4 | 5.2 | — | Net-IDN-Encode | CWE-416 | Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use… |
| CVE-2026-87079 | 7.5 | 5.0 | — | Net-IDN-Encode | CWE-407 | Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via qu… |
| CVE-2026-87081 | 7.5 | 5.0 | — | Net-IDN-Encode | CWE-407 | Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadr… |
| CVE-2026-87078 | 9.1 | 5.0 | — | Net-IDN-Encode | CWE-401 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output … |
| CVE-2026-87080 | 9.1 | 4.4 | — | Net-IDN-Encode | CWE-1286 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated labe… |
| CVE-2026-95503 | 6.8 | 3.0 | Red Hat | Red Hat Build of Keycloak | CWE-347 | Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerb… |
| CVE-2026-7866 | 10.0 | — | RTI | Connext Professional | CWE-121 | Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core L… |
| CVE-2026-73369 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-75699 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-75703 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-75721 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-75723 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-75745 | 10.0 | — | Adobe | AEM 6.5 Forms JEE | CWE-863 | Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863) |
| CVE-2026-77244 | 10.0 | — | sooperset | mcp-atlassian | CWE-287 | [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueToken… |
| CVE-2026-80155 | 10.0 | — | LANTRONIX | SLC8000 | CWE-22 | Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypas… |
| CVE-2026-84412 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-89275 | 10.0 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-16346 | 9.9 | — | IBM | DataStage on Cloud Pak for Data | CWE-285 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-18169 | 9.9 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-22 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-57149 | 9.9 | — | plone | plone.app.portlets | CWE-95 | plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection |
| CVE-2026-75682 | 9.9 | — | Adobe | Adobe Connect | CWE-89 | Adobe Connect | Improper Neutralization of Special Elements used in an SQL Co… |
| CVE-2026-82008 | 9.9 | — | Adobe | Adobe Campaign Classic | CWE-20 | Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20) |
| CVE-2026-82010 | 9.9 | — | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-82013 | 9.9 | — | Adobe | Adobe Campaign Classic | CWE-918 | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-83660 | 9.9 | — | Adobe | Adobe Campaign Classic | CWE-918 | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-89276 | 9.9 | — | Adobe | Adobe Campaign Classic | CWE-94 | Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code … |
| CVE-2026-12718 | 9.8 | — | Karel Electronic Industry and Trade Inc. | KarelIPS | CWE-89 | SQLi in Karel Electronics' KarelIPS |
| CVE-2026-18162 | 9.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-94 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18163 | 9.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-502 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-25254 | 9.8 | — | Qualcomm, Inc. | Snapdragon | CWE-285 | Improper authorization in Qualcomm Software Center |
| CVE-2026-28324 | 9.8 | — | SolarWinds | Observability Self-Hosted | CWE-345 | SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability |
| CVE-2026-65113 | 9.8 | — | NVIDIA | Infrastructure Controller | CWE-798 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-74849 | 9.8 | — | Zohocorp | ManageEngine ADSelfService Plus | CWE-78 | Remote code execution vulnerability |
| CVE-2026-76708 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ALE | — | Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking An… |
| CVE-2026-76709 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ALE | — | Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking A… |
| CVE-2026-79313 | 9.8 | — | n/a | n/a | CWE-613 | webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The appli… |
| CVE-2026-93088 | 9.8 | — | SGLang | SGLang | CWE-502 | CVE-2026-93088 |
| CVE-2026-17472 | 9.6 | — | IBM | Concert | CWE-269 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-82000 | 9.6 | — | Adobe | AEM 6.5 Forms JEE | CWE-918 | Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-… |
| CVE-2026-82443 | 9.6 | — | Adobe | Adobe Campaign Classic | CWE-918 | Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-84388 | 9.6 | — | Fortinet | FortiPAM Chrome Extension | CWE-1021 | A improper restriction of rendered ui layers or frames vulnerability in Forti… |
| CVE-2026-86059 | 9.6 | — | Dokploy | dokploy | CWE-200 | Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and … |
| CVE-2026-80143 | 9.4 | — | LANTRONIX | SLC8000 | CWE-78 | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom… |
| CVE-2026-80144 | 9.4 | — | LANTRONIX | SLC8000 | CWE-78 | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom… |
| CVE-2026-80145 | 9.4 | — | LANTRONIX | SLC8000 | CWE-78 | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs p… |
| CVE-2026-80146 | 9.4 | — | LANTRONIX | SLC8000 | CWE-121 | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc … |
| CVE-2026-80147 | 9.4 | — | LANTRONIX | SLC8000 | CWE-121 | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc … |
| CVE-2026-80151 | 9.4 | — | LANTRONIX | SLC8000 | CWE-78 | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs dow… |
| CVE-2026-80152 | 9.4 | — | LANTRONIX | SLC8000 | CWE-78 | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script … |
| CVE-2026-80156 | 9.4 | — | LANTRONIX | SLC8000 | CWE-22 | Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload File… |
| CVE-2026-43641 | 9.3 | — | Softaculous | Virtualizor | CWE-78 | Softaculous Virtualizor OS Command Injection via Billing Module Handler |
| CVE-2026-47116 | 9.3 | — | LTSecurity | LTK3500SF | CWE-798 | LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH |
| CVE-2026-63374 | 9.3 | — | agronholm | anyio | CWE-295 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certifica… |
| CVE-2026-75684 | 9.3 | — | Adobe | Adobe Connect | CWE-79 | Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75686 | 9.3 | — | Adobe | Adobe Connect | CWE-20 | Adobe Connect | Improper Input Validation (CWE-20) |
| CVE-2026-75689 | 9.3 | — | Adobe | Adobe Connect | CWE-79 | Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75697 | 9.3 | — | Adobe | Adobe Connect | CWE-79 | Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-75698 | 9.3 | — | Adobe | Adobe Connect | CWE-79 | Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) |
| CVE-2026-77621 | 9.3 | — | vectordotdev | vector | CWE-22 | Vector: Arbitrary file write in the file sink via templated path (path traver… |
| CVE-2026-77987 | 9.3 | — | GitHub | Enterprise Server | CWE-208 | GitHub Enterprise Server notebook viewer vulnerable to Server-side request fo… |
| CVE-2026-87121 | 9.3 | — | lwIP | TCP/IP Stack MQTT | CWE-787 | Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application |
| CVE-2026-91130 | 9.3 | — | home-assistant | core | CWE-80 | Home Assistant: XSS in Statistics Graph Card |
| CVE-2026-95675 | 9.3 | — | D-LINK | DAP-1360 | CWE-78 | D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface |
| CVE-2026-18461 | 9.2 | — | RTI | Connext Professional | CWE-134 | Use of Externally-Controlled Format String vulnerability in RTI Connext Profe… |
| CVE-2026-43642 | 9.2 | — | Softaculous | Virtualizor | CWE-502 | Softaculous Virtualizor PHP Object Injection via Billing Module Handler |
| CVE-2026-17635 | 9.1 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-306 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-17645 | 9.1 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-269 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-19202 | 9.1 | — | Google | mcp-toolbox-sdk-python | CWE-524 | Token Cache Reuse in mcp-toolbox-sdk-python |
| CVE-2026-75728 | 9.1 | — | Adobe | Adobe Campaign Classic | CWE-863 | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
| CVE-2026-77254 | 9.1 | — | sooperset | mcp-atlassian | CWE-306 | MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured … |
| CVE-2026-81995 | 9.1 | — | Adobe | AEM 6.5 Forms JEE | CWE-20 | Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20) |
| CVE-2026-82009 | 9.1 | — | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-82011 | 9.1 | — | Adobe | Adobe Campaign Classic | CWE-89 | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements us… |
| CVE-2026-85734 | 9.1 | — | HKUDS | LightRAG | CWE-307 | LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks |
| CVE-2026-94456 | 9.1 | — | GitroomHQ | postiz-app | CWE-330 | Unauthenticated recovery of the Math.random() state behind OAuth tokens, auth… |
| CVE-2026-95654 | 9.1 | — | David-Crty | Databasement | CWE-863 | Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token |
| CVE-2026-80154 | 8.9 | — | LANTRONIX | SLC8000 | CWE-330 | Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Valid… |
| CVE-2026-13087 | 8.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server rep… |
| CVE-2026-16468 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-16469 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-16672 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | — | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-17102 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-17636 | 8.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-787 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-17637 | 8.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-502 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-17643 | 8.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-522 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-17644 | 8.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-798 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-17647 | 8.8 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-829 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-25255 | 8.8 | — | Qualcomm, Inc. | Snapdragon | CWE-749 | Exposed function in Qualcomm Package Manager and Qualcomm Software Center. |
| CVE-2026-25264 | 8.8 | — | Qualcomm, Inc. | Snapdragon | CWE-427 | Uncontrolled Search Path Element in Qualcomm Software Center |
| CVE-2026-25265 | 8.8 | — | Qualcomm, Inc. | Snapdragon | CWE-378 | Creation of Temporary File with Insecure Permissions in Qualcomm Software Center |
| CVE-2026-28325 | 8.8 | — | SolarWinds | Observability Self-Hosted | CWE-502 | SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vu… |
| CVE-2026-65128 | 8.8 | — | NVIDIA | Infrastructure Controller | CWE-89 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-65179 | 8.8 | — | NVIDIA | NeMo Speech | CWE-502 | NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it d… |
| CVE-2026-70410 | 8.8 | — | Apache Software Foundation | Apache Calcite Avatica | CWE-470 | Apache Calcite Avatica: Unrestricted class initialization when instantiating … |
| CVE-2026-77243 | 8.8 | — | sooperset | mcp-atlassian | CWE-862 | MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass |
| CVE-2026-77274 | 8.8 | — | sooperset | mcp-atlassian | CWE-918 | MCP Atlassian: SSRF Protection Bypass |
| CVE-2026-88419 | 8.8 | — | n/a | n/a | CWE-434 | An unrestricted upload of files with a dangerous type in the thumbnail-upload… |
| CVE-2026-18459 | 8.7 | — | RTI | Connext Professional | CWE-682 | Incorrect Calculation vulnerability in RTI Connext Professional (Core Librari… |
| CVE-2026-43643 | 8.7 | — | Softaculous | Virtualizor | CWE-862 | Softaculous Virtualizor Authorization Bypass via Billing Module Handler |
| CVE-2026-67615 | 8.7 | — | Apereo Foundation | openEQUELLA | CWE-184 | openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Inv… |
| CVE-2026-77619 | 8.7 | — | vectordotdev | vector | CWE-130 | Vector: Unauthenticated denial of service in the `logstash` source via unboun… |
| CVE-2026-77620 | 8.7 | — | vectordotdev | vector | CWE-409 | Vector: Unauthenticated denial of service in the `logstash` source via nested… |
| CVE-2026-81999 | 8.7 | — | Adobe | AEM 6.5 Forms JEE | CWE-918 | Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-… |
| CVE-2026-90882 | 8.7 | — | Eclipse Foundation | open-vsx.org | CWE-942 | Reflected arbitrary origins with credentials, allowing cross-origin reads of … |
| CVE-2026-91018 | 8.7 | — | lwIP | lwIP API | CWE-415 | Double Free in lwIP (lightweight IP) |
| CVE-2026-93345 | 8.7 | — | MikroTik | RouterOS | CWE-1284 | MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-… |
| CVE-2026-94450 | 8.7 | — | AWS | s2n-quic | CWE-1284 | Potential denial of service when configured to send Retry packets in s2n-quic |
| CVE-2026-95653 | 8.7 | — | concretecms-community-store | community_store | CWE-340 | Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token |
| CVE-2026-34689 | 8.6 | — | Adobe | Adobe Connect | CWE-22 | Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory (… |
| CVE-2026-75791 | 8.6 | — | Zohocorp | ManageEngine ADSelfService Plus | CWE-306 | Authentication bypass vulnerability |
| CVE-2026-77248 | 8.6 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachmen… |
| CVE-2026-77255 | 8.6 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA u… |
| CVE-2026-77262 | 8.6 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_atta… |
| CVE-2026-85279 | 8.6 | — | notepad-plus-plus | notepad-plus-plus | CWE-121 | Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLex… |
| CVE-2026-95655 | 8.6 | — | aureuserp | aureuserp | CWE-639 | Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel |
| CVE-2026-95814 | 8.6 | — | dani-garcia | vaultwarden | CWE-863 | Vaultwarden through 1.37.3 Authorization Bypass via Missing Status Check |
| CVE-2026-17646 | 8.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-611 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18095 | 8.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-787 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-82003 | 8.5 | — | Adobe | Adobe Campaign Classic | CWE-20 | Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20) |
| CVE-2026-83603 | 8.4 | — | netdata | netdata | CWE-73 | Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle… |
| CVE-2026-18457 | 8.3 | — | RTI | Connext Professional | CWE-122 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Li… |
| CVE-2026-65114 | 8.3 | — | NVIDIA | Infrastructure Controller | CWE-306 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-77247 | 8.3 | — | sooperset | mcp-atlassian | CWE-73 | MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachme… |
| CVE-2026-77251 | 8.3 | — | sooperset | mcp-atlassian | CWE-1276 | MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidde… |
| CVE-2026-77256 | 8.3 | — | sooperset | mcp-atlassian | CWE-732 | MCP Atlassian: OAuth refresh-token backup file is world-readable under defaul… |
| CVE-2026-77257 | 8.3 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths |
| CVE-2026-77260 | 8.3 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Arbitrary local file READ via unconstrained file_path in uploa… |
| CVE-2026-77267 | 8.3 | — | sooperset | mcp-atlassian | CWE-918 | mcp-atlassian has an incomplete SSRF remediation |
| CVE-2026-77271 | 8.3 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrit… |
| CVE-2026-18074 | 8.2 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-287 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18131 | 8.2 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-79 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-65121 | 8.2 | — | NVIDIA | Infrastructure Controller | CWE-287 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-87119 | 8.2 | — | ZenHive | mpp | CWE-294 | mpp Tempo subscription key authorization is not bound to the issuing challeng… |
| CVE-2026-18137 | 8.1 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-89 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-75607 | 8.1 | — | blakeblackshear | frigate | CWE-862 | Frigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only Oper… |
| CVE-2026-75744 | 8.1 | — | Adobe | AEM 6.5 Forms JEE | CWE-79 | Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-87902 | 8.1 | — | WordPress | WordPress | CWE-98 | An unauthenticated attacker can make `get_page_template()` page-template reso… |
| CVE-2026-18154 | 8.0 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-321 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-65130 | 8.0 | — | NVIDIA | Infrastructure Controller | CWE-78 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-18066 | 7.9 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-918 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-24239 | 7.8 | — | NVIDIA | NeMo Speech | CWE-502 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious… |
| CVE-2026-24267 | 7.8 | — | NVIDIA | NeMo Speech | CWE-502 | NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech d… |
| CVE-2026-65111 | 7.8 | — | NVIDIA | NeMo Speech | CWE-77 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious… |
| CVE-2026-65178 | 7.8 | — | NVIDIA | NeMo Speech | CWE-502 | NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a … |
| CVE-2026-75649 | 7.8 | — | Adobe | Adobe Bridge | CWE-122 | Bridge | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-75655 | 7.8 | — | Adobe | Adobe Bridge | CWE-674 | Bridge | Uncontrolled Recursion (CWE-674) |
| CVE-2026-75658 | 7.8 | — | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-75663 | 7.8 | — | Adobe | Adobe Bridge | CWE-787 | Bridge | Out-of-bounds Write (CWE-787) |
| CVE-2026-75665 | 7.8 | — | Adobe | Adobe Bridge | CWE-122 | Bridge | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-75676 | 7.8 | — | Adobe | Adobe Bridge | CWE-121 | Bridge | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-77605 | 7.8 | — | notepad-plus-plus | notepad-plus-plus | CWE-20 | Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target… |
| CVE-2026-79906 | 7.8 | — | Adobe | Substance3D - Modeler | CWE-787 | Substance3D - Modeler | Out-of-bounds Write (CWE-787) |
| CVE-2026-81998 | 7.8 | — | Adobe | Substance3D - Modeler | CWE-787 | Substance3D - Modeler | Out-of-bounds Write (CWE-787) |
| CVE-2026-83598 | 7.8 | — | netdata | netdata | CWE-269 | Netdata: Local Privilege Escalation in Netdata Agent Windows installer via Po… |
| CVE-2026-83962 | 7.8 | — | Adobe | Substance3D - Modeler | CWE-121 | Substance3D - Modeler | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-83963 | 7.8 | — | Adobe | Substance3D - Modeler | CWE-787 | Substance3D - Modeler | Out-of-bounds Write (CWE-787) |
| CVE-2026-86054 | 7.8 | — | notepad-plus-plus | notepad-plus-plus | CWE-121 | Notepad++: Stack Buffer Overflow in `NppParameters::writeSession` via overlon… |
| CVE-2026-95831 | 7.8 | — | — | Crypt-SelfCertificate | CWE-506 | Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malw… |
| CVE-2026-8849 | 7.7 | — | RTI | Connext Professional | CWE-416 | Use After Free vulnerability in RTI Connext Professional (Security Plugins) a… |
| CVE-2026-75608 | 7.7 | — | blakeblackshear | frigate | CWE-863 | Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive … |
| CVE-2026-77258 | 7.7 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing… |
| CVE-2026-77259 | 7.7 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows ex… |
| CVE-2026-80148 | 7.7 | — | LANTRONIX | SLC8000 | CWE-918 | Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation |
| CVE-2026-80149 | 7.7 | — | LANTRONIX | SLC8000 | CWE-918 | Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter |
| CVE-2026-80150 | 7.7 | — | LANTRONIX | SLC8000 | CWE-918 | Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter |
| CVE-2026-83803 | 7.7 | — | getsentry | sentry | CWE-502 | Sentry: Unsafe pickle deserialization in Relocation Feature |
| CVE-2026-95619 | 7.7 | — | Red Hat | Red Hat Hardened Images | CWE-190 | Gcc: libstdc++ integer overflow in `new` operator |
| CVE-2026-95806 | 7.7 | — | MISP | MISP | CWE-74 | MISP: PHP phar stream wrapper enables deserialization and code execution via … |
| CVE-2026-18123 | 7.6 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-470 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-94117 | 7.6 | — | DevItems | HashBar – WordPress Notification Bar | CWE-89 | WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injectio… |
| CVE-2026-18134 | 7.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-319 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-19480 | 7.5 | — | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-58268 | 7.5 | — | emiago | sipgo | CWE-789 | SIPGO: DoS via unvalidated Content-Length in the stream parser |
| CVE-2026-59991 | 7.5 | — | psd-tools | psd-tools | CWE-789 | psd-tools: Uncontrolled memory allocation in psd-tools composite/numpy via cr… |
| CVE-2026-61570 | 7.5 | — | joniles | mpxj | CWE-611 | MPXJ: XXE Vulnerability in MerlinReader |
| CVE-2026-61685 | 7.5 | — | fecommunity | reactpress | CWE-89 | ReactPress has SQL injection via dynamic column names in TypeORM query builders |
| CVE-2026-62985 | 7.5 | — | azu | request-filtering-agent | CWE-248 | request-filtering-agent: Synchronous throw from createConnection() for litera… |
| CVE-2026-65118 | 7.5 | — | NVIDIA | Infrastructure Controller | CWE-295 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-75632 | 7.5 | — | Adobe | Content Credentials Rust SDK | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-76710 | 7.5 | — | Hewlett Packard Enterprise (HPE) | ALE | — | Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE … |
| CVE-2026-76711 | 7.5 | — | Hewlett Packard Enterprise (HPE) | ALE | — | Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analyti… |
| CVE-2026-77242 | 7.5 | — | sooperset | mcp-atlassian | CWE-367 | MCP Atlassian: Incomplete fix for CVE-2026-27826: DNS rebinding bypasses SSRF… |
| CVE-2026-77322 | 7.5 | — | emiago | sipgo | CWE-789 | SIPGO: DoS via unvalidated WebSocket frame length |
| CVE-2026-77544 | 7.5 | — | Ubiquiti Inc | Dream Machines | CWE-787 | A malicious actor with access to the network could exploit an Out-of-bounds W… |
| CVE-2026-77555 | 7.5 | — | Ubiquiti Inc | Dream Machines | CWE-787 | A malicious actor with access to the network could exploit an Out-of-bounds W… |
| CVE-2026-77556 | 7.5 | — | Ubiquiti Inc | Dream Machines | CWE-125 | A malicious actor with access to the network could exploit an Out-of-bounds R… |
| CVE-2026-77558 | 7.5 | — | Ubiquiti Inc | Dream Machines | CWE-125 | A malicious actor with access to the network could exploit an Out-of-bounds R… |
| CVE-2026-83599 | 7.5 | — | netdata | netdata | CWE-409 | Netdata: WebSocket Decompression Bomb |
| CVE-2026-89407 | 7.5 | — | FasterXML | jackson-core | CWE-400 | jackson-core: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLi… |
| CVE-2026-94640 | 7.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-400 | Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows un… |
| CVE-2026-95861 | 7.5 | — | Ubiquiti Inc | Dream Machines | CWE-674 | A malicious actor with access to the network could exploit an Uncontrolled Re… |
| CVE-2026-95862 | 7.5 | — | Ubiquiti Inc | Dream Machines | CWE-787 | A malicious actor with access to the network could exploit an Out-of-bounds W… |
| CVE-2026-96269 | 7.5 | — | GNU | Emacs | CWE-829 | GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a fi… |
| CVE-2026-18152 | 7.4 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-347 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18172 | 7.4 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-611 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18176 | 7.4 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-319 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-77246 | 7.4 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated… |
| CVE-2026-77912 | 7.4 | — | GitHub | Enterprise Server | CWE-79 | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed… |
| CVE-2026-17618 | 7.3 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-862 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18462 | 7.3 | — | RTI | Connext Professional | CWE-190 | Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI … |
| CVE-2026-19915 | 7.3 | — | HP Inc | HP Support Assistant | CWE-269 | HP Support Assistant - Local Escalation of Privilege |
| CVE-2026-56681 | 7.3 | — | decolua | 9router | CWE-807 | 9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip H… |
| CVE-2026-76712 | 7.3 | — | Hewlett Packard Enterprise (HPE) | ALE | CWE-200 | Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denia… |
| CVE-2026-85995 | 7.3 | — | notepad-plus-plus | notepad-plus-plus | CWE-347 | Notepad++: Authenticode verification bypass allows modified updater execution |
| CVE-2026-63104 | 7.2 | — | usekaneo | kaneo | CWE-862 | Kaneo 2.3.12 < 2.12.2 Missing Authorization via Bulk Task Endpoint |
| CVE-2026-76713 | 7.2 | — | Hewlett Packard Enterprise (HPE) | ALE | CWE-269 | Authenticated Remote File System Access Vulnerability in HPE Networking Analy… |
| CVE-2026-76714 | 7.2 | — | Hewlett Packard Enterprise (HPE) | ALE | CWE-78 | Authenticated Remote Code Execution with Elevated Privileges Vulnerability in… |
| CVE-2026-94367 | 7.2 | — | OpenEye | Apex Network Video Recorder (NVR) | CWE-78 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS c… |
| CVE-2026-95815 | 7.2 | — | OpenClaw | OpenClaw iOS | CWE-532 | OpenClaw iOS before 2026.8.11 Credential Exposure via Deep-Link URL Logging |
| CVE-2026-75743 | 7.1 | — | Adobe | AEM 6.5 Forms JEE | CWE-352 | Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352) |
| CVE-2026-76715 | 7.1 | — | Hewlett Packard Enterprise (HPE) | ALE | CWE-300 | Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulne… |
| CVE-2026-77253 | 7.1 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary… |
| CVE-2026-77261 | 7.1 | — | sooperset | mcp-atlassian | CWE-918 | MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth auth… |
| CVE-2026-77426 | 7.1 | — | Unleash | unleash | CWE-639 | Unleash: Missing await on permission check + cross-project IDOR in admin API |
| CVE-2026-77633 | 7.1 | — | cloudreve | cloudreve | CWE-362 | Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based de… |
| CVE-2026-84395 | 7.1 | — | Adobe | Premiere | CWE-918 | Premiere Pro | Server-Side Request Forgery (SSRF) (CWE-918) |
| CVE-2026-85055 | 7.1 | — | twentyhq | twenty | CWE-200 | Twenty: Field-level read bypass |
| CVE-2026-85740 | 7.1 | — | HKUDS | LightRAG | CWE-918 | LightRAG: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6t… |
| CVE-2026-89420 | 7.1 | — | ZenHive | mpp | CWE-1284 | Session voucher adding no new funds is accepted without a charge in mpp, serv… |
| CVE-2026-93343 | 7.1 | — | WebWizards | MarketKing | CWE-862 | MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax |
| CVE-2026-93344 | 7.1 | — | WebWizards | MarketKing | CWE-862 | MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX |
| CVE-2026-94455 | 7.1 | — | GitroomHQ | postiz-app | CWE-306 | Unauthenticated /enterprise/create-user mints lifetime top-tier organizations… |
| CVE-2026-94462 | 7.1 | — | spree | spree | CWE-639 | Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) |
| CVE-2026-83597 | 7.0 | — | netdata | netdata | CWE-269 | Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MS… |
| CVE-2026-11388 | 6.9 | — | RTI | Connext Professional | CWE-415 | Double Free vulnerability in RTI Connext Professional (Core Libraries) allows… |
| CVE-2026-18460 | 6.9 | — | RTI | Connext Professional | CWE-193 | Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Profession… |
| CVE-2026-25262 | 6.9 | — | Qualcomm, Inc. | Snapdragon | CWE-123 | Write-what-where Condition in Primary Bootloader |
| CVE-2026-63627 | 6.9 | — | wevm | mppx | CWE-20 | mppx: Gas Draining with padding |
| CVE-2026-63628 | 6.9 | — | wevm | mppx | CWE-20 | mppx: Gas Draining with access list |
| CVE-2026-95499 | 6.9 | — | JosephChuks | php-file-manager-with-code-editor | CWE-284 | JosephChuks php-file-manager-with-code-editor filemanager.php move_uploaded_f… |
| CVE-2026-95658 | 6.9 | — | MISP | MISP | CWE-352 | MISP CSRF vulnerability in workflow moduleStatelessExecution allows cross-sit… |
| CVE-2026-95667 | 6.9 | — | MISP | MISP | CWE-22 | MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Creden… |
| CVE-2026-95679 | 6.9 | — | MISP | MISP | CWE-20 | MISP Unauthenticated Blind SSRF via XML Body Processing |
| CVE-2026-95754 | 6.9 | — | MISP | MISP | CWE-285 | MISP: Disabled-user check ineffective in pre-authentication TOTP login branch |
| CVE-2026-11389 | 6.8 | — | RTI | Connext Professional | CWE-125 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access … |
| CVE-2026-18458 | 6.8 | — | RTI | Connext Professional | CWE-125 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access … |
| CVE-2026-18626 | 6.8 | — | RTI | Connext Professional | CWE-125 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries)… |
| CVE-2026-79312 | 6.8 | — | n/a | n/a | CWE-384 | webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._l… |
| CVE-2026-95624 | 6.8 | — | Tauri | tauri-plugin-updater | CWE-284 | Tauri framework v2 malicious downgrade via allow_downgrades from frontend code |
| CVE-2026-63278 | 6.7 | — | The Document Foundation | LibreOffice | CWE-200 | Package URLs can be used to exfiltrate arbitrary INI file values and environm… |
| CVE-2026-65129 | 6.7 | — | NVIDIA | Infrastructure Controller | CWE-295 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-85288 | 6.7 | — | notepad-plus-plus | notepad-plus-plus | CWE-78 | Notepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Mac… |
| CVE-2026-65125 | 6.6 | — | NVIDIA | Infrastructure Controller | CWE-73 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-16426 | 6.5 | — | IBM | Concert | CWE-918 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-17465 | 6.5 | — | IBM | Concert | CWE-400 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-18114 | 6.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-22 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18124 | 6.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-522 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18132 | 6.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-862 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18156 | 6.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-862 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18170 | 6.5 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-770 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-57576 | 6.5 | — | plone | plone.app.dexterity | CWE-400 | plone.app.dexterity and plone.app.contenttypes have a Denial of Service due t… |
| CVE-2026-65112 | 6.5 | — | NVIDIA | Infrastructure Controller | CWE-400 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-65115 | 6.5 | — | NVIDIA | Infrastructure Controller | CWE-400 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-75517 | 6.5 | — | novuhq | novu | CWE-639 | Novu: Cross-Environment Integration Manipulation (IDOR) |
| CVE-2026-75638 | 6.5 | — | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-77252 | 6.5 | — | sooperset | mcp-atlassian | CWE-284 | MCP Atlassian: JIRA_PROJECTS_FILTER and CONFLUENCE_SPACES_FILTER can be bypas… |
| CVE-2026-77266 | 6.5 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read… |
| CVE-2026-77269 | 6.5 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read… |
| CVE-2026-77270 | 6.5 | — | sooperset | mcp-atlassian | CWE-22 | MCP Atlassian: Arbitrary File Read via Upload Attachment Tools |
| CVE-2026-77399 | 6.5 | — | collective | icalendar | CWE-400 | icalendar: Denial of service via unbounded VALARM REPEAT expansion |
| CVE-2026-79913 | 6.5 | — | cloudreve | cloudreve | CWE-697 | Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrapper… |
| CVE-2026-83600 | 6.5 | — | netdata | netdata | CWE-193 | Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB alloca… |
| CVE-2026-83601 | 6.5 | — | netdata | netdata | CWE-190 | Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing… |
| CVE-2026-83602 | 6.5 | — | netdata | netdata | CWE-284 | Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist… |
| CVE-2026-92928 | 6.5 | — | OpenEye | Apex Network Video Recorder (NVR) | CWE-798 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardc… |
| CVE-2026-96260 | 6.5 | — | Mattermost | Mattermost | CWE-789 | Mattermost server missing request body size limit on plugin routes allows den… |
| CVE-2026-83805 | 6.4 | — | nautobot | nautobot | CWE-285 | Nautobot: Authorization bypass in approval workflow REST API allows self-appr… |
| CVE-2026-94384 | 6.4 | — | Amazon | amazon-connect-salesforce-lambda | CWE-862 | Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Conn… |
| CVE-2026-84301 | 6.3 | — | labring | FastGPT | CWE-918 | FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected … |
| CVE-2026-86805 | 6.3 | — | The GNU C Library | glibc | CWE-367 | AT_SECURE programs may load attacker-controlled code via $ORIGIN |
| CVE-2026-88010 | 6.3 | — | traefik | traefik | CWE-208 | Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated us… |
| CVE-2026-15915 | 6.2 | — | IBM | Concert | CWE-552 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-83964 | 6.2 | — | Adobe | Adobe Connect | CWE-295 | Adobe Connect | Improper Certificate Validation (CWE-295) |
| CVE-2026-92930 | 6.2 | — | OpenEye | Apex Network Video Recorder (NVR) | CWE-330 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administ… |
| CVE-2026-48361 | 6.1 | — | Adobe | Adobe Connect | CWE-79 | Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-77250 | 6.1 | — | sooperset | mcp-atlassian | CWE-312 | MCP Atlassian: OAuth fallback token storage writes plaintext access and refre… |
| CVE-2026-86062 | 6.1 | — | HKUDS | LightRAG | CWE-79 | LightRAG: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer… |
| CVE-2026-75101 | 6.0 | — | GitHub | Enterprise Server | CWE-639 | Authorization bypass vulnerability in GitHub Enterprise Server allowed readin… |
| CVE-2025-36084 | 5.9 | — | IBM | Concert | CWE-327 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-65124 | 5.9 | — | NVIDIA | Infrastructure Controller | CWE-91 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-77265 | 5.9 | — | sooperset | mcp-atlassian | CWE-918 | MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow |
| CVE-2026-85725 | 5.9 | — | HKUDS | LightRAG | CWE-208 | LightRAG: Plaintext Passwords Compared Without Constant-Time Function |
| CVE-2026-94570 | 5.9 | — | SGLang | SGLang | CWE-1287 | CVE-2026-94570 |
| CVE-2026-95623 | 5.6 | — | Tauri | tauri-plugin-http | CWE-918 | Tauri framework v2 SSRF Protection Bypass via HTTP Redirects |
| CVE-2026-75633 | 5.5 | — | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-75656 | 5.5 | — | Adobe | Adobe Bridge | CWE-125 | Bridge | Out-of-bounds Read (CWE-125) |
| CVE-2026-76192 | 5.5 | — | Adobe | InDesign Desktop | CWE-476 | InDesign Desktop | NULL Pointer Dereference (CWE-476) |
| CVE-2026-76804 | 5.5 | — | projectdiscovery | nuclei | CWE-284 | Nuclei: Local File Read via Workflow File-Protocol Gate Bypass |
| CVE-2026-77268 | 5.5 | — | sooperset | mcp-atlassian | CWE-732 | MCP Atlassian: Insecure File Permissions on OAuth Token Storage |
| CVE-2026-79767 | 5.5 | — | gardener | gardener | CWE-863 | Gardener: Authorization Bypass via Group Subject Injection |
| CVE-2026-81878 | 5.5 | — | radareorg | radare2 | CWE-190 | radare2: Integer overflow causes heap out-of-bounds write in radare2 PYC parser |
| CVE-2026-81879 | 5.5 | — | radareorg | radare2 | CWE-125 | radare2: Heap out-of-bounds read in radare2 ELF PN_XNUM handling |
| CVE-2026-81880 | 5.5 | — | radareorg | radare2 | CWE-400 | radare2: Uncontrolled resource consumption in radare2 PEF loader |
| CVE-2026-81885 | 5.5 | — | radareorg | radare2 | CWE-770 | radare2: Infinite relocation-chain loop causes denial of service in radare2 N… |
| CVE-2026-81886 | 5.5 | — | radareorg | radare2 | CWE-770 | radare2: Uncontrolled memory allocation in radare2 dmp64 parser |
| CVE-2026-84396 | 5.5 | — | Adobe | InDesign Desktop | CWE-476 | InDesign Desktop | NULL Pointer Dereference (CWE-476) |
| CVE-2026-86056 | 5.5 | — | notepad-plus-plus | notepad-plus-plus | CWE-476 | Notepad++: Null pointer dereference in NPPM_SAVESESSION message handler cause… |
| CVE-2026-89277 | 5.5 | — | Adobe | Content Credentials Rust SDK | CWE-190 | CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-95271 | 5.5 | — | dgtlmoon | changedetection.io | CWE-287 | dgtlmoon changedetection.io Authentication Hook flask_app.py check_authentica… |
| CVE-2026-95500 | 5.5 | — | JosephChuks | php-file-manager-with-code-editor | CWE-284 | JosephChuks php-file-manager-with-code-editor Save codeEditor.php file_put_co… |
| CVE-2026-95656 | 5.5 | — | dgtlmoon | changedetection.io | CWE-918 | dgtlmoon changedetection.io Preview Endpoint __init__.py add_watch_ui_snapsho… |
| CVE-2026-95819 | 5.5 | — | anirbandutta9 | College-Notes-Gallery | CWE-74 | anirbandutta9 College-Notes-Gallery login.php sql injection |
| CVE-2026-96259 | 5.5 | — | Mattermost | Mattermost | CWE-918 | Mattermost server-side request forgery via OAuth endpoints configurable by a … |
| CVE-2026-18133 | 5.4 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-22 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-18153 | 5.4 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-327 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-63272 | 5.4 | — | The Document Foundation | LibreOffice | CWE-125 | Heap buffer overflow in WMF text record import |
| CVE-2026-63273 | 5.4 | — | The Document Foundation | LibreOffice | CWE-787 | Heap buffer overflow in PDF import encryption handling |
| CVE-2026-63274 | 5.4 | — | The Document Foundation | LibreOffice | CWE-125 | Heap buffer overflow in PDF import stream handling |
| CVE-2026-63275 | 5.4 | — | The Document Foundation | LibreOffice | CWE-787 | Stack buffer overflow in CFF font hint handling |
| CVE-2026-63276 | 5.4 | — | The Document Foundation | LibreOffice | CWE-787 | Stack buffer overflow in CFF to Type 1 font conversion |
| CVE-2026-63279 | 5.4 | — | The Document Foundation | LibreOffice | CWE-125 | Out of bounds read in PICT image import |
| CVE-2026-77272 | 5.4 | — | sooperset | mcp-atlassian | CWE-79 | MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler |
| CVE-2026-83801 | 5.4 | — | nautobot | nautobot | CWE-79 | Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text |
| CVE-2026-90462 | 5.4 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-280 | Sssd: sssd: fail-open in ldap ppolicy access check allows continued authoriza… |
| CVE-2026-91129 | 5.4 | — | home-assistant | core | CWE-918 | Home Assistant: mDNS Server-Side Request Forgery |
| CVE-2025-12767 | 5.3 | — | IBM | Concert | CWE-770 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-17620 | 5.3 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-523 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-56682 | 5.3 | — | decolua | 9router | CWE-307 | 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header |
| CVE-2026-63386 | 5.3 | — | sunnyadn | js-toml | CWE-674 | js-toml: Uncontrolled recursion in `load()` causes `RangeError` (stack exhaus… |
| CVE-2026-65829 | 5.3 | — | joniles | mpxj | CWE-22 | MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak… |
| CVE-2026-75511 | 5.3 | — | novuhq | novu | CWE-918 | Novu: Server-Side Request Forgery (SSRF) via Chat Provider Webhook URLs |
| CVE-2026-76716 | 5.3 | — | Hewlett Packard Enterprise (HPE) | ALE | CWE-770 | Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilit… |
| CVE-2026-76717 | 5.3 | — | Hewlett Packard Enterprise (HPE) | ALE | CWE-200 | Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE … |
| CVE-2026-76803 | 5.3 | — | projectdiscovery | nuclei | CWE-284 | Nuclei: Local File Read via MySQL Client Sandbox Bypass |
| CVE-2026-76805 | 5.3 | — | projectdiscovery | nuclei | CWE-200 | Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuz… |
| CVE-2026-76910 | 5.3 | — | Unleash | unleash | CWE-639 | Unleash: Clone-feature lets a user copy a feature from a project they cannot … |
| CVE-2026-77249 | 5.3 | — | sooperset | mcp-atlassian | CWE-918 | MCP Atlassian: Incomplete fix for CVE-2026-27826: redirect-based SSRF via unh… |
| CVE-2026-85709 | 5.3 | — | HKUDS | LightRAG | CWE-209 | LightRAG: Sensitive Information Exposure Through Raw Exception Messages in AP… |
| CVE-2026-88020 | 5.3 | — | Autonomy Logic | OpenPLC Runtime | CWE-79 | Improper Neutralization of Input During Web Page Generation in OpenPLC Runtim… |
| CVE-2026-90990 | 5.3 | — | Checkmk GmbH | Checkmk | CWE-93 | Livestatus injection via monitoring filter values |
| CVE-2026-92882 | 5.3 | — | Checkmk GmbH | Checkmk | CWE-522 | Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config … |
| CVE-2026-92929 | 5.3 | — | OpenEye | Apex Network Video Recorder (NVR) | CWE-290 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forw… |
| CVE-2026-93341 | 5.3 | — | WebWizards | MarketKing | CWE-862 | MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX |
| CVE-2026-93342 | 5.3 | — | WebWizards | MarketKing | CWE-862 | MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX |
| CVE-2026-95671 | 5.3 | — | MISP | MISP | CWE-285 | MISP Collections: Missing Authorization Check for Sharing Group on PUT Reques… |
| CVE-2026-95674 | 5.3 | — | MISP | MISP | CWE-20 | MISP EventsController queryEnrichment allows querying unavailable or legacy m… |
| CVE-2026-95683 | 5.3 | — | MISP | MISP | CWE-639 | MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL |
| CVE-2026-95685 | 5.3 | — | MISP | MISP | CWE-862 | MISP Missing Authorization on replaceSuggestionInReport Event Report Action |
| CVE-2026-95693 | 5.3 | — | MISP | MISP | CWE-22 | MISP Information Disclosure via Forged Upload Path |
| CVE-2026-95697 | 5.3 | — | MISP | MISP | CWE-862 | MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Or… |
| CVE-2026-95698 | 5.3 | — | MISP | MISP | CWE-22 | MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name |
| CVE-2026-95805 | 5.3 | — | MISP | MISP | CWE-285 | MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended a… |
| CVE-2026-95812 | 5.3 | — | MacWarrior | clipbucket-v5 | CWE-79 | ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters |
| CVE-2026-95813 | 5.3 | — | e621ng | e621ng | CWE-601 | e621ng before 26.09.16 Open Redirect via URL Parameters |
| CVE-2026-95829 | 5.3 | — | TDuckCloud | tduck-platform | CWE-89 | TDuckCloud tduck-platform Pagination Inner Interceptor MybatisPlusConfig.java… |
| CVE-2026-95830 | 5.3 | — | theRealSain | Pixtream | CWE-434 | theRealSain Pixtream post_upload.php unrestricted upload |
| CVE-2026-95833 | 5.3 | — | itsourcecode | Leave Management System | CWE-89 | itsourcecode Leave Management System index.php sql injection |
| CVE-2026-75510 | 5.1 | — | novuhq | novu | CWE-79 | Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: sc… |