boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 22, 2026 · all times UTC← 2026-09-21 · archive

Security Box Score — September 22, 2026 — page 2

Edition of September 22, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–455 of 455
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-956615.1—MISPMISPCWE-79MISP Reflected Cross-Site Scripting in Attribute Histogram via Unescaped URL-…
CVE-2026-956655.1—MISPMISPCWE-79MISP Reflected Cross-Site Scripting in Event Export Confirmation Form via Une…
CVE-2026-957015.1—MISPMISPCWE-22MISP Path Traversal via Organization Name in Org-Statistics Logo Check
CVE-2026-957035.1—MISPMISPCWE-20MISP OrganisationsController File Existence and Image-Type Oracle via Forged …
CVE-2026-651175.0—NVIDIAInfrastructure ControllerCWE-259NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-651265.0—NVIDIAInfrastructure ControllerCWE-841NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-956594.8—MISPMISPCWE-20MISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind Thread
CVE-2026-956824.8—MISPMISPCWE-79MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Ema…
CVE-2026-768024.7—projectdiscoverynucleiCWE-78Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
CVE-2026-793154.7—n/an/aCWE-79A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The mana…
CVE-2026-181614.3—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-778IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-756344.3—AdobeContent Credentials Rust SDKCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-761944.3—AdobeContent Credentials Rust SDKCWE-20CAI Content Credentials | Improper Input Validation (CWE-20)
CVE-2026-774254.3—UnleashunleashCWE-639Unleash: A project member can reorder activation strategies belonging to any …
CVE-2026-956664.3—MattermostMattermostCWE-770Unbounded post ID array in the bulk reactions endpoint allows denial of service
CVE-2026-651274.1—NVIDIAInfrastructure ControllerCWE-1258NVIDIA Infrastructure Controller for Linux contains a vulnerability where an …
CVE-2026-776373.8—cloudrevecloudreveCWE-862Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible…
CVE-2026-181733.7—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-295IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-958183.6—The GNU C LibraryglibcCWE-121AT_SECURE program buffer overflow via $ORIGIN processing
CVE-2026-927063.4—darkreaderdarkreaderCWE-200Dark Reader: Ability to request icon-like bitmap data from certain local web …
CVE-2026-818813.3—radareorgradare2CWE-125radare2: Heap out-of-bounds read in radare2 Mach-O Swift metadata parser
CVE-2026-818823.3—radareorgradare2CWE-125radare2: Missing string termination causes heap out-of-bounds read in radare2…
CVE-2026-818833.3—radareorgradare2CWE-125radare2: Out-of-bounds Read at the end of string in the LUA 5.3 bytecode
CVE-2026-952702.9—dgtlmoonchangedetection.ioCWE-203dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timin…
CVE-2026-952722.9—dgtlmoonchangedetection.ioCWE-22dgtlmoon changedetection.io Screenshot flask_app.py static_content path trave…
CVE-2026-818842.5—radareorgradare2CWE-125radare2: Heap out-of-bounds read in radare2 Mach-O LC_DATA_IN_CODE parser
CVE-2026-623642.3—WeblateOrgwlcCWE-200wlc may disclose API tokens to project-configured URLs
CVE-2026-866982.3—hexpmhexpmCWE-613Refresh tokens accepted as private repository credentials at the CDN
CVE-2026-769092.1—UnleashunleashCWE-79Unleash: CR-approval email renders user-controlled raw HTML
CVE-2026-952732.1—dgtlmoonchangedetection.ioCWE-22dgtlmoon changedetection.io visual_selector_data flask_app.py static_content …
CVE-2026-953962.1—sfturinghosp_orderCWE-79sfturing hosp_order Public Search Handlers HospitalController.java cross site…
CVE-2026-956602.1—Moonshot AIKimi CodeCWE-77Moonshot AI Kimi Code MCP Configuration Loader config-loader.ts os command in…
CVE-2026-958202.1—anirbandutta9College-Notes-GalleryCWE-284anirbandutta9 College-Notes-Gallery userprofile.php admin1 unrestricted upload
CVE-2026-958282.1—MstfaktsCollege-Management-SystemCWE-384Mstfakts College-Management-System Authentication server.php session_start se…
CVE-2026-956572.0—dgtlmoonChangedetection.ioCWE-79dgtlmoon Changedetection.io Visual Selector visual-selector.js setCurrentSele…
CVE-2026-955011.9—mtranoAPENCMSCWE-74mtrano APENCMS Template weasel.php eval code injection
CVE-2026-37603await—n/an/a—Improper Restriction of Excessive Authentication Attempts in the administrati…
CVE-2026-37604await—n/an/a—pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the cl…
CVE-2026-75432await—n/an/a—An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive infor…
CVE-2026-79311await—n/an/a—webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinj…
CVE-2026-79314await—n/an/a—A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An auth…
CVE-2026-88339await—n/an/a—A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone…
CVE-2026-88340await—n/an/a—An invalid pointer release vulnerability exists in YARA 4.5.8 during deserial…
CVE-2026-88341await—n/an/a—A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted…
CVE-2026-88344await—n/an/a—An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b…
CVE-2026-88345await—n/an/a—An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b…
CVE-2026-88350await—n/an/a—An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_al…
CVE-2026-88414await—n/an/a—MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAc…
CVE-2026-88415await—n/an/a—MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). …
CVE-2026-88416await—n/an/a—MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom mode…
CVE-2026-88418await—n/an/a—CMSimple 5.24 ships with CSRF protection disabled by default, which turns csr…
CVE-2026-88624await—n/an/a—Missing path validation in the Worktree.remove component of openCode v1.18.26…
CVE-2026-89281await—Apache HTTP Server ProjectApache Lounge Windows—CVE-2026-89281
CVE-2026-89282await—Apache HTTP Server ProjectApache Lounge Windows—CVE-2026-89282
CVE-2026-94574await—GNU Wget (Windows Builds)Wget—CVE-2026-94574