Security Box Score — September 22, 2026 — page 2
Edition of September 22, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-95661 | 5.1 | — | MISP | MISP | CWE-79 | MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-… |
| CVE-2026-95665 | 5.1 | — | MISP | MISP | CWE-79 | MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Une… |
| CVE-2026-95701 | 5.1 | — | MISP | MISP | CWE-22 | MISP Path Traversal via Organization Name in Org-Statistics Logo Check |
| CVE-2026-95703 | 5.1 | — | MISP | MISP | CWE-20 | MISP OrganisationsController File Existence and Image-Type Oracle via Forged … |
| CVE-2026-65117 | 5.0 | — | NVIDIA | Infrastructure Controller | CWE-259 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-65126 | 5.0 | — | NVIDIA | Infrastructure Controller | CWE-841 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-95659 | 4.8 | — | MISP | MISP | CWE-20 | MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread |
| CVE-2026-95682 | 4.8 | — | MISP | MISP | CWE-79 | MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Ema… |
| CVE-2026-76802 | 4.7 | — | projectdiscovery | nuclei | CWE-78 | Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass |
| CVE-2026-79315 | 4.7 | — | n/a | n/a | CWE-79 | A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The mana… |
| CVE-2026-18161 | 4.3 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-778 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-75634 | 4.3 | — | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-76194 | 4.3 | — | Adobe | Content Credentials Rust SDK | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-77425 | 4.3 | — | Unleash | unleash | CWE-639 | Unleash: A project member can reorder activation strategies belonging to any … |
| CVE-2026-95666 | 4.3 | — | Mattermost | Mattermost | CWE-770 | Unbounded post ID array in the bulk reactions endpoint allows denial of service |
| CVE-2026-65127 | 4.1 | — | NVIDIA | Infrastructure Controller | CWE-1258 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an … |
| CVE-2026-77637 | 3.8 | — | cloudreve | cloudreve | CWE-862 | Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible… |
| CVE-2026-18173 | 3.7 | — | IBM | Financial Transaction Manager (FTM) for RedHat OpenShift | CWE-295 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities |
| CVE-2026-95818 | 3.6 | — | The GNU C Library | glibc | CWE-121 | AT_SECURE program buffer overflow via $ORIGIN processing |
| CVE-2026-92706 | 3.4 | — | darkreader | darkreader | CWE-200 | Dark Reader: Ability to request icon-like bitmap data from certain local web … |
| CVE-2026-81881 | 3.3 | — | radareorg | radare2 | CWE-125 | radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser |
| CVE-2026-81882 | 3.3 | — | radareorg | radare2 | CWE-125 | radare2: Missing string termination causes heap out-of-bounds read in radare2… |
| CVE-2026-81883 | 3.3 | — | radareorg | radare2 | CWE-125 | radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode |
| CVE-2026-95270 | 2.9 | — | dgtlmoon | changedetection.io | CWE-203 | dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timin… |
| CVE-2026-95272 | 2.9 | — | dgtlmoon | changedetection.io | CWE-22 | dgtlmoon changedetection.io Screenshot flask_app.py static_content path trave… |
| CVE-2026-81884 | 2.5 | — | radareorg | radare2 | CWE-125 | radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser |
| CVE-2026-62364 | 2.3 | — | WeblateOrg | wlc | CWE-200 | wlc may disclose API tokens to project-configured URLs |
| CVE-2026-86698 | 2.3 | — | hexpm | hexpm | CWE-613 | Refresh tokens accepted as private repository credentials at the CDN |
| CVE-2026-76909 | 2.1 | — | Unleash | unleash | CWE-79 | Unleash: CR-approval email renders user-controlled raw HTML |
| CVE-2026-95273 | 2.1 | — | dgtlmoon | changedetection.io | CWE-22 | dgtlmoon changedetection.io visual_selector_data flask_app.py static_content … |
| CVE-2026-95396 | 2.1 | — | sfturing | hosp_order | CWE-79 | sfturing hosp_order Public Search Handlers HospitalController.java cross site… |
| CVE-2026-95660 | 2.1 | — | Moonshot AI | Kimi Code | CWE-77 | Moonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command in… |
| CVE-2026-95820 | 2.1 | — | anirbandutta9 | College-Notes-Gallery | CWE-284 | anirbandutta9 College-Notes-Gallery userprofile.php admin1 unrestricted upload |
| CVE-2026-95828 | 2.1 | — | Mstfakts | College-Management-System | CWE-384 | Mstfakts College-Management-System Authentication server.php session_start se… |
| CVE-2026-95657 | 2.0 | — | dgtlmoon | Changedetection.io | CWE-79 | dgtlmoon Changedetection.io Visual Selector visual-selector.js setCurrentSele… |
| CVE-2026-95501 | 1.9 | — | mtrano | APENCMS | CWE-74 | mtrano APENCMS Template weasel.php eval code injection |
| CVE-2026-37603 | await | — | n/a | n/a | — | Improper Restriction of Excessive Authentication Attempts in the administrati… |
| CVE-2026-37604 | await | — | n/a | n/a | — | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the cl… |
| CVE-2026-75432 | await | — | n/a | n/a | — | An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive infor… |
| CVE-2026-79311 | await | — | n/a | n/a | — | webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinj… |
| CVE-2026-79314 | await | — | n/a | n/a | — | A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An auth… |
| CVE-2026-88339 | await | — | n/a | n/a | — | A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone… |
| CVE-2026-88340 | await | — | n/a | n/a | — | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserial… |
| CVE-2026-88341 | await | — | n/a | n/a | — | A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted… |
| CVE-2026-88344 | await | — | n/a | n/a | — | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b… |
| CVE-2026-88345 | await | — | n/a | n/a | — | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b… |
| CVE-2026-88350 | await | — | n/a | n/a | — | An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_al… |
| CVE-2026-88414 | await | — | n/a | n/a | — | MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAc… |
| CVE-2026-88415 | await | — | n/a | n/a | — | MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). … |
| CVE-2026-88416 | await | — | n/a | n/a | — | MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom mode… |
| CVE-2026-88418 | await | — | n/a | n/a | — | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csr… |
| CVE-2026-88624 | await | — | n/a | n/a | — | Missing path validation in the Worktree.remove component of openCode v1.18.26… |
| CVE-2026-89281 | await | — | Apache HTTP Server Project | Apache Lounge Windows | — | CVE-2026-89281 |
| CVE-2026-89282 | await | — | Apache HTTP Server Project | Apache Lounge Windows | — | CVE-2026-89282 |
| CVE-2026-94574 | await | — | GNU Wget (Windows Builds) | Wget | — | CVE-2026-94574 |