boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 23, 2026 · all times UTC← 2026-09-22 · archive

Security Box Score — September 23, 2026

472 CVEs published, led by Red Hat (47).

472 CVEs published September 23, 2026: 42 critical, 188 high, 196 medium, 40 low; 0 in the KEV catalog at press time; 4 with a public exploit reference; 6 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 72 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1175346709——
KEV catalog size1721

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3010 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux15075598526251371311560.17.8.0017+91 ▲
microsoft10012900206198769116289301.07.8.0044+532 ▲
google5172684332104911821218090.37.5.0025+446 ▲
red hat2228515235439946200.06.7.0028+34 ▲
apple24656367165317148881.46.5.0020+206 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0021-14 ▼
suse1341721121000.07.5.0036+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0039+51 ▲
ubiquiti665362810334.69.1.0049+6 ▲
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0038+4 ▲
netgear23400277000.04.3.0025-7 ▼
f592671441527.78.7.0047+9 ▲
ivanti10246162025520.88.8.0147+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache129641147271206163320.37.5.0049-2 ▼
mozilla113301102126730900.08.8.0028+54 ▲
gitlab241007245811533.05.3.0032+8 ▲
drupal2694119668411.15.7.0024+26 ▲
github623211100000.07.4.0045+1 ▲
docker3121830000.08.4.0016+1 ▲
wordpress1614102233.38.7.1658-1 ▼
go440211000.05.9.0029+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0034-255 ▼
ibm37199019545232815610.17.5.0030-3 ▼
adobe22483082362376102040.57.5.0025+164 ▲
progress3641539100611.68.1.0035-16 ▼
zohocorp263662460000.08.1.0121+22 ▲
solarwinds3261853010415.49.1.0060+3 ▲
veeam01961030100.08.6.0032-10 ▼
atlassian3918001300.07.6.00320
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link267121261212300.08.5.0154+10 ▲
siemens1552633103000.07.3.0018-4 ▼
synology1946510256000.05.6.0027+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0068+17 ▲
schneider electric91821150000.08.5.0040+9 ▲
hikvision390540000.07.1.0036+3 ▲
abb291530000.07.2.0018+2 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1903613116614222210.37.2.0020+134 ▲
sourcecodester632320013894000.05.5.0028+21 ▲
nvidia5118521127370000.07.8.0031+27 ▲
spring017013608314000.06.5.0024-5 ▼
mongodb64162694584100.07.1.0026+32 ▲
itsourcecode371530037116000.02.1.0026+17 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0030+136 ▲
wwbn1061462349740000.06.9.0024+97 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-60004.867899.79.8
CVE-2026-85706.092995.110.0
CVE-2026-83549.085194.87.8
CVE-2026-82329.076794.39.8
CVE-2026-86218.074994.210.0
CVE-2026-79756.051592.18.7
CVE-2026-83548.046791.410.0
CVE-2026-74849.044691.09.8
CVE-2026-76698.044491.06.5
CVE-2026-19632.041290.49.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.0929KEV
CVE-2026-8621810.0.0749KEV
CVE-2026-8354810.0.0467KEV
CVE-2026-7565010.0.0215KEV
CVE-2026-8615210.0.0186
CVE-2026-7619510.0.0159
CVE-2026-7619710.0.0159
CVE-2026-8015510.0.0158
CVE-2026-8222210.0.0155
CVE-2026-8200410.0.0144
Most disclosures (vendor)
VendorCVEs
linux1735
microsoft1009
google846
oracle635
ibm387
adobe265
red hat253
apple250
dell204
apache157
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
ivanti5
adobe4
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven92
Packagist40
npm14
PyPI12
crates.io8
RubyGems2
Go1
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171771
CVE-2021-27102n/a2021-11-171771
CVE-2021-27101n/a2021-11-171771
CVE-2021-27103n/a2021-11-171771
CVE-2021-21017Adobe2021-11-171771
CVE-2021-28550Adobe2021-11-171771
CVE-2021-42013Apache Software Foundation2021-11-171771
CVE-2021-41773Apache Software Foundation2021-11-171771
CVE-2021-30858Apple2021-11-171771
CVE-2021-30860Apple2021-11-171771

Transactions

EXPLOIT PUBLISHED — MediaArea MediaInfoLib: 3 CVEs (CVE-2026-25104, CVE-2026-25713, CVE-2026-28764). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-26824. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-26825. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43641 (Softaculous Virtualizor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-47116 (LTSecurity LTK3500SF). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56818 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67615 (Apereo Foundation openEQUELLA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77006 (Unknown WebTotem Backups). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85706 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-87719 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92764 (opencve). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93307 (O-RAN-SC SMO OAM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93533 (spatie Scotty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93739 (Totolink A3002MU). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94536 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95812 (MacWarrior clipbucket-v5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95819 (anirbandutta9 College-Notes-Gallery). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95820 (anirbandutta9 College-Notes-Gallery). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95828 (Mstfakts College-Management-System). Public exploit reference added.

DUE DATE PASSED — CVE-2026-81963 (Microsoft Windows 11 version 23H2). CISA remediation deadline was September 22, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-85880 (Microsoft Windows 10 Version 1607). CISA remediation deadline was September 22, 2026; still in catalog.

RESCORED — Microsoft Windows 10 Version 1607: 3 CVEs (CVE-2026-69512, CVE-2026-72927, CVE-2026-81355). CVSS rescored — before/after on each CVE page.

RESCORED — Okta Access Gateway: 3 CVEs (CVE-2026-78552, CVE-2026-78560, CVE-2026-78579). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-10027 (IBM MQ). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-10853 (IBM MQ). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2026-12749 (IBM Cloud Pak for Business Automation). CVSS 6.4 → 5.4 (NVD).

RESCORED — CVE-2026-12750 (IBM Cloud Pak for Business Automation). CVSS 6.4 → 5.4 (NVD).

RESCORED — CVE-2026-13745 (Google Cloud Gemini CLI). CVSS 9.2 → 7.7 (NVD).

RESCORED — CVE-2026-47116 (LTSecurity LTK3500SF). CVSS 9.3 → 9.2 (NVD).

RESCORED — CVE-2026-59302 (Spring Cloud Stream). CVSS 3.1 → 4.9 (NVD).

RESCORED — CVE-2026-59903 (netty). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-73508 (netty). CVSS 5.3 → 7.5 (NVD).

RESCORED — CVE-2026-78574 (Okta Hyperdrive Integration Plugin). CVSS 7.5 → 6.3 (NVD).

RESCORED — CVE-2026-80225 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD).

RESCORED — CVE-2026-81352 (Microsoft Web Media Extensions). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2026-81380 (Microsoft Visual Studio Code). CVSS 5.3 → 5.9 (NVD).

RESCORED — CVE-2026-82443 (Adobe Campaign Classic). CVSS 9.6 → 9.9 (NVD).

RESCORED — CVE-2026-83660 (Adobe Campaign Classic). CVSS 9.9 → 10 (NVD).

RESCORED — CVE-2026-85501 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD).

RESCORED — CVE-2026-88013 (rclone). CVSS 3.7 → 5.3 (NVD).

RESCORED — CVE-2026-95829 (TDuckCloud tduck-platform). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-95830 (theRealSain Pixtream). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-95833 (itsourcecode Leave Management System). CVSS 5.3 → 2.1 (NVD).

PATCH SHIPPED — Red Hat Enterprise Linux 9: 9 CVEs (CVE-2025-11395, CVE-2026-11861, CVE-2026-13097, CVE-2026-18147, CVE-2026-19550, CVE-2026-73197, CVE-2026-73198, CVE-2026-76578, CVE-2026-79678). Fix versions published.

PATCH SHIPPED — CVE-2026-28183 (PublishPress Capabilities). Fixed in PublishPress Capabilities 2.50.0.

PATCH SHIPPED — CVE-2026-84470 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.33-1.el8ap.

PATCH SHIPPED — CVE-2026-93337 (nm-l2tp NetworkManager-l2tp). Fixed in NetworkManager-l2tp 1.52.6.

Yesterday's Results

How to read these box scores · glossary

472 CVEs published. 25 box scores and 375 table rows below; the remaining 72 continue on page 2 — every CVE is listed, nothing truncated.

Changing|CGServiSign - OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   H    8.6   .0217   81.5     —
AFFECTED
  Product      Versions       Fixed
  CGServiSign  1.0.23.1227 –  —
TIMELINE
  Jul 8   Reserved by CNA
  Sep 23  Published (CNA: twcert)
CWE-78 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Received
Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0104   62.5     —
AFFECTED
  Product                   Versions  Fixed
  FAC1203R Gigabit Edition  2.0.4 –   —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0065   49.6     —
AFFECTED
  Product       Versions  Fixed
  Apache Doris  2.0.0 –   4.0.8
TIMELINE
  Mar 9   Reserved by CNA
  Sep 23  Published (CNA: apache)
CWE-287 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
MacWarrior clipbucket-v5 — ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0054   44.4     —
AFFECTED
  Product        Versions     Fixed
  clipbucket-v5  unspecified  —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulnCheck)
CWE-89 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Received
FasterXML jackson-core — jackson-core: UTF8DataInputJsonParser._reportInvalidToken() does not honor maxErrorTokenLength, allowing unbounded StringBuilder growth
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0053   44.0     —
AFFECTED
  Product       Versions  Fixed
  jackson-core  2.8.0 –   —
  jackson-core  3.0.0 –   —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 23  Published (CNA: HeroDevs)
CWE-400, CWE-770 · CNA: HeroDevs · CVSS v3.1 · 2 references · NVD status: Received
travispluse Rename wp-login.php to anything you want — Rename wp-login.php to anything you want <= 2.0.1 - Unauthenticated SQL Injection via 'log' (Username) Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0050   42.2     —
AFFECTED
  Product                                   Versions     Fixed
  Rename wp-login.php to anything you want  unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 23  Published (CNA: Wordfence)
CWE-89 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
FasterXML jackson-databind — jackson-databind: unbounded growth of the type id cache in TypeDeserializerBase retains every unknown raw type ID
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0049   41.1     —
AFFECTED
  Product           Versions  Fixed
  jackson-databind  2.0.0 –   —
  jackson-databind  3.0.0 –   —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 23  Published (CNA: HeroDevs)
CWE-400 · CNA: HeroDevs · CVSS v3.1 · 2 references · NVD status: Received
FasterXML jackson-databind — jackson-databind: quadratic forward-reference completion in Collection and Map deserializers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0049   41.1     —
AFFECTED
  Product           Versions  Fixed
  jackson-databind  2.5.0 –   —
  jackson-databind  3.0.0 –   —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 23  Published (CNA: HeroDevs)
CWE-400 · CNA: HeroDevs · CVSS v3.1 · 2 references · NVD status: Received
tw93 Pake — Pake grants unrestricted IPC access to every HTTPS origin loaded in generated applications
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  H  N    8.2   .0048   40.8     —
AFFECTED
  Product  Versions     Fixed
  Pake     unspecified  —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 23  Published (CNA: JFROG)
CWE-862, CWE-923 · CNA: JFROG · CVSS v3.1 · 5 references · NVD status: Deferred
Tauri framework v2 CSP nonce protection bypass via data and blob URI schemes allows an XSS to RCE chains
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0047   39.9     —
AFFECTED
  Product  Versions  Fixed
  tauri    2.0.0 –   —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: JFROG)
CWE-79 · CNA: JFROG · CVSS v3.1 · 2 references · NVD status: Deferred
SourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0047   39.9     —
AFFECTED
  Product                                       Versions  Fixed
  Smart Attendance System with QR Code Scanner  1.0 –     —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
onSite internet GmbH Auktion NG Auktionssoftware Public Password Reset Endpoint forgotpasswd.html cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0045   38.4     —
AFFECTED
  Product                      Versions    Fixed
  Auktion NG Auktionssoftware  20260722 –  —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
SourceCodester Online Reviewer Management System btn_functions.php add sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   36.9     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Online Reviewer Management System btn_functions.php update sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   36.9     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Online Reviewer Management System btn_functions.php update sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   36.9     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SourceCodester Online Reviewer Management System exam-delete.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0043   36.9     —
AFFECTED
  Product                            Versions  Fixed
  Online Reviewer Management System  1.0 –     —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
iFlytek astron-agent debugToolV2 API endpoint UrlCheckTool.checkUrl server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0043   36.6     —
AFFECTED
  Product       Versions  Fixed
  astron-agent  1.0.0 –   reward-1575
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
ABB Mint Workbench I — Mint Workbench I Path traversal Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   H   N   N    8.2   .0041   35.1     —
AFFECTED
  Product           Versions     Fixed
  Mint Workbench I  unspecified  —
TIMELINE
  Aug 10  Reserved by CNA
  Sep 23  Published (CNA: ABB)
CWE-22 · CNA: ABB · CVSS v4.0 · 1 reference · NVD status: Deferred
iFlytek astron-agent getBotList API endpoint ChatBotMarketMapper.xml sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0039   32.9     —
AFFECTED
  Product       Versions  Fixed
  astron-agent  1.0.0 –   reward-1575
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
Photoview through 2.4.0 Authorization Bypass via shareAlbum
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   L   N    7.1   .0039   32.7     —
AFFECTED
  Product    Versions     Fixed
  photoview  unspecified  —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulnCheck)
CWE-639 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
vsourz1td Advanced Contact form 7 DB — Advanced Contact form 7 DB <= 2.1.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure via 'acf7db' Shortcode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0035   29.1     —
AFFECTED
  Product                     Versions     Fixed
  Advanced Contact form 7 DB  unspecified  —
TIMELINE
  Apr 21  Reserved by CNA
  Sep 23  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
jetmonsters Getwid – Gutenberg Blocks — Getwid <= 2.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps 'customStyle'
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0035   28.6     —
AFFECTED
  Product                    Versions  Fixed
  Getwid – Gutenberg Blocks  2.1.3 –   —
TIMELINE
  Apr 8   Reserved by CNA
  Sep 23  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Foxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0035   28.2     —
AFFECTED
  Product           Versions                       Fixed
  Foxit PDF Editor  Versions 2026.2 and earlier –  —
  Foxit PDF Reader  Versions 2026.2 and earlier –  —
TIMELINE
  Sep 15  Reserved by CNA
  Sep 23  Published (CNA: Foxit)
CWE-73 · CNA: Foxit · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Tauri framework v2 Dialog plugin auto-expands the filesystem scope with attacker-controlled recursion
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   R  C  H  H  N    7.7   .0034   27.3     —
AFFECTED
  Product              Versions  Fixed
  tauri-plugin-dialog  2.0.0 –   —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: JFROG)
CWE-732 · CNA: JFROG · CVSS v3.1 · 2 references · NVD status: Deferred
n/a Dask — Dask Loader core.py from_npy_stack deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   L   L   L    2.0   .0034   27.3     —
AFFECTED
  Product  Versions  Fixed
  Dask     2026.0 –  —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 23  Published (CNA: VulDB)
CWE-20, CWE-502 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-959282.027.3recommenders-teamrecommendersCWE-20recommenders-team recommenders Dict Loading mind_iterator.py pickle.load dese…
CVE-2026-958682.126.7AdithyaYellojuRestaurant-Management-SystemCWE-74AdithyaYelloju Restaurant-Management-System Search Form display_menu.php mysq…
CVE-2026-428017.421.1ASRCrane,FalconCWE-476Deference after null check in as_rrc
CVE-2026-964436.518.7Apache Software FoundationApache DorisCWE-829Apache Doris: JDBC driver URL validation bypass leads to remote code execution
CVE-2026-502276.118.4AcerNitroSense V5CWE-78MQTT WebSocket Command Execution Vulnerability in NitroSense
CVE-2026-757999.014.8UnknownYAHMAN Add-onsCWE-94YAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card…
CVE-2022-49978.614.8Unknownjet-form-builder-stripe-gatewayCWE-89JetFormBuilder Stripe Gateway < 1.1.0 - Unauthenticated Blind SQLi via Paymen…
CVE-2026-917897.813.3Foxit Software Inc.Foxit PDF EditorCWE-787Foxit PDF Editor/Reader U3D File Parsing Integer Overflow Remote Code Executi…
CVE-2026-917947.813.3Foxit Software Inc.Foxit PDF EditorCWE-787Foxit PDF Editor/Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Ex…
CVE-2026-910246.813.0UnknownBooking ManagerCWE-89Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid)
CVE-2026-956255.913.0Tauritauri-plugin-updaterCWE-354Tauri framework v2 missing updater signature version number validation can be…
CVE-2026-910736.812.3UnknownSubscribe FormsCWE-79Subscribe Forms 1.4.1 - 1.6.2 - Author+ Stored XSS via Attention Effect Form …
CVE-2026-918526.111.8Apache Software FoundationApache Sling XSSCWE-79Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl
CVE-2026-143218.211.7Unknowndivi-dashCWE-400Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing
CVE-2025-156966.811.2UnknownReal3D FlipbookCWE-79Real3D Flipbook Lite < 5.4 - Author+ Stored XSS
CVE-2026-850066.811.2UnknownHappyAddons for ElementorCWE-79Happy Addons for Elementor < 3.50.0 - Contributor+ Stored XSS via Creative Bu…
CVE-2026-889976.811.2UnknownJSM Show Post MetadataCWE-79JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Met…
CVE-2026-918017.811.1Foxit Software Inc.Foxit PDF EditorCWE-22Foxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code …
CVE-2026-868426.810.8UnknownReal3D FlipbookCWE-862Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Glob…
CVE-2026-731926.110.7Apache Software FoundationApache Sling XSSCWE-79Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
CVE-2026-919286.110.7Apache Software FoundationApache Sling XSSCWE-79Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and fai…
CVE-2026-919996.110.7Apache Software FoundationApache Sling XSSCWE-79Apache Sling XSS: Improper escaping in the XSS Webconsole plugin
CVE-2026-879795.310.5UnknownPaymob for WooCommerceCWE-862Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to A…
CVE-2026-935115.310.5UnknownPremium PackagesCWE-290Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verificat…
CVE-2026-866088.210.0UnknownWP Recipe MakerCWE-400WP Recipe Maker 9.8.0 - 10.8.1 - Unauthenticated DoS via Unbounded User Meta …
CVE-2026-840265.310.0UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-200Directorist 8.1 - 8.9.4 - Unauthenticated Sensitive Data Disclosure via REST …
CVE-2026-841685.310.0UnknownEasy Hide LoginCWE-200Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure
CVE-2026-847415.310.0UnknownThe Events CalendarCWE-200The Events Calendar 4.5 - 6.17.4.1 - Unauthenticated Non-Public Venue and Org…
CVE-2026-867835.310.0UnknownPost Grid Gutenberg BlocksCWE-200PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API
CVE-2026-889295.310.0UnknownProduct Badge, Label, Countdown Timer for WooCommerceCWE-200Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure
CVE-2026-893315.310.0UnknownFluentBoardsCWE-200FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Discl…
CVE-2026-909855.310.0UnknownWPC Smart Compare for WooCommerceCWE-200WPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protecte…
CVE-2026-935283.710.0UnknownNP Quote Request for WooCommerceCWE-200NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclo…
CVE-2026-823319.89.5Apache Software FoundationApache BuildStreamCWE-59Apache BuildStream: tar source extraction escape
CVE-2026-847422.79.1UnknownThe Events CalendarCWE-863The Events Calendar 6.15.0 - 6.17.4.1 - Contributor+ Content Publication via …
CVE-2026-942516.58.9Apache Software FoundationApache Sling Security BundleCWE-693Apache Sling Security Bundle: ContentDispositionFilter mediates only one addr…
CVE-2026-183654.38.9UnknownzportalsCWE-200Zportals < 6.4.2 - Subscriber+ User Email Disclosure
CVE-2026-866024.38.9UnknownWP Recipe MakerCWE-200WP Recipe Maker 10.3.0 - 10.8.1 - Subscriber+ Draft and Private Recipe Conten…
CVE-2026-866034.38.9UnknownWP Recipe MakerCWE-200WP Recipe Maker < 10.8.2 - Subscriber+ Non-Public List Title Disclosure via w…
CVE-2026-920016.18.6Apache Software FoundationApache Sling XSSCWE-776Apache Sling XSS: Missing parser resource limits
CVE-2026-803426.58.5UnknownPayment Plugins for PayPal WooCommerceCWE-639Payment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hij…
CVE-2026-777655.38.5UnknownBetter PaymentCWE-284Better Payment < 2.3.4 - Unauthenticated Payment Amount Manipulation
CVE-2026-835555.38.5UnknownEmail Subscribers & NewslettersCWE-862Email Subscribers by Icegram Express < 5.9.35 - Unauthenticated Subscription …
CVE-2026-867855.38.5UnknownSocial Commerce for WooCommerceCWE-862Social Commerce for WooCommerce <= 2.5.4 - Unauthenticated Plugin Option and …
CVE-2026-917917.88.4Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-917997.88.4Foxit Software Inc.Foxit PDF EditorCWE-416Foxit Editor/Reader Array resetForm Use-After-Free Vulnerability
CVE-2026-918157.88.4Foxit Software Inc.Foxit PDF EditorCWE-787Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execut…
CVE-2026-828439.07.9UnknownWP OAuth Server ( Login with WordPress )CWE-287WP OAuth Server < 6.4.0 - Subscriber+ Cross-User Account Takeover via OIDC ID…
CVE-2026-935088.17.9UnknownWC Fields FactoryCWE-862WC Fields Factory < 4.1.11 - Subscriber+ Arbitrary Post Meta Manipulation via…
CVE-2026-162646.57.9UnknownNewslettersCWE-639Newsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Di…
CVE-2026-840986.57.9UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-863Directorist 3.1.0 - 8.9.4 - Subscriber+ Arbitrary Listing Deletion via remove…
CVE-2026-841505.47.9UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-639Directorist < 8.9.5 - Subscriber+ Cross-User Favorites Read and Write via RES…
CVE-2026-840465.07.9UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-918Directorist < 8.9.5 - Subscriber+ SSRF via Avatar URL
CVE-2026-879814.77.9UnknownPaymob for WooCommerceCWE-862Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration …
CVE-2026-183644.37.9UnknownzportalsCWE-862Zportals < 6.4.2 - Subscriber+ Arbitrary Plugin Settings Update
CVE-2026-777664.37.9UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-639Directorist 8.5 - 8.9.4 - Subscriber+ Order and Financial Record Disclosure v…
CVE-2026-813394.37.9UnknownMasterStudy LMS WordPress PluginCWE-639MasterStudy LMS < 3.7.50 - Subscriber+ Quiz Attempt Grade Disclosure via IDOR
CVE-2026-840274.37.9UnknownDirectorist: AI-Powered Business Directory, Listings & Classified AdsCWE-862Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery…
CVE-2026-910254.37.9UnknownBooking ManagerCWE-639Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modificatio…
CVE-2026-935104.37.9UnknownPoints and Rewards for WooCommerceCWE-862Points and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points an…
CVE-2026-847433.87.9UnknownThe Events CalendarCWE-863The Events Calendar 6.15.16.1 - 6.17.4.1 - Contributor+ Event/Venue/Organizer…
CVE-2026-870743.77.9UnknownForminator FormsCWE-862Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sendi…
CVE-2026-909513.77.9UnknownPaid Membership SubscriptionsCWE-863Paid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State …
CVE-2026-935073.37.9UnknownWC Fields FactoryCWE-862WC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private …
CVE-2026-870693.17.9UnknownForminator FormsCWE-862Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via mig…
CVE-2026-910772.77.9UnknownEvent Booking Manager for WooCommerceCWE-284Event Booking Manager for WooCommerce 5.3.6 - 5.7.2 - Contributor+ Unpublishe…
CVE-2026-502286.17.7AcerNitroSense V5CWE-489Electron DevTools Arbitrary Code Execution Vulnerability in NitroSense
CVE-2026-923784.17.5NT-wareuniFLOW OnlineCWE-613uniFLOW Online Legacy UI Previous login session retained when entering Reduce…
CVE-2026-917966.17.2Foxit Software Inc.Foxit PDF EditorCWE-693Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulne…
CVE-2026-962736.86.9NationalSecurityAgencyghidraCWE-460Ghidra before 12.1.4 Denial of Service via Crafted Database
CVE-2026-918145.37.0Foxit Software Inc.Foxit PDF EditorCWE-347Security vulnerability: Foxit PDF Editor/Reader Fails to Detect Modifications…
CVE-2026-917907.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vuln…
CVE-2026-917927.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-917937.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vuln…
CVE-2026-918027.86.8Foxit Software Inc.Foxit PDF EditorCWE-787Foxit PDF Editor/Reader — Heap Buffer Overflow in WebP Image Decoding via Bit…
CVE-2026-918047.86.8Foxit Software Inc.Foxit PDF EditorCWE-787Foxit PDF Editor/Reader Out-of-bounds Write Vulnerability While Rendering
CVE-2026-918057.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Use-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree Handling
CVE-2026-918067.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vuln…
CVE-2026-918097.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure Vuln…
CVE-2026-918117.86.8Foxit Software Inc.Foxit PDF EditorCWE-787Foxit PDF Editor/Reader PRC Stream Parsing Out-Of-Bounds Write Remote Code Ex…
CVE-2026-918167.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnera…
CVE-2026-918187.86.8Foxit Software Inc.Foxit PDF EditorCWE-416Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulne…
CVE-2026-918038.86.4Foxit Software Inc.Foxit PDF EditorCWE-427Security Vulnerability Report – Foxit PDF Editor/Reader Updater DLL Search Pa…
CVE-2026-959584.85.6JusticeRageManalyzeCWE-189JusticeRage Manalyze PE Parser pe.cpp _parse_relocations integer underflow
CVE-2026-918076.14.8Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Discl…
CVE-2026-918086.14.8Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disc…
CVE-2026-918106.14.8Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure …
CVE-2026-918176.14.8Foxit Software Inc.Foxit PDF EditorCWE-125Foxit PDF Editor/Reader AcroForm Out-of-Bounds Read Remote Code Execution Vul…
CVE-2026-918008.84.6Foxit Software Inc.Foxit PDF EditorCWE-732Foxit PDF Editor installer local privilege escalation
CVE-2026-796160.64.6qtqtCWE-125Out-of-bounds read vulnerability in Context2D.path and PathSvg.path propertie…
CVE-2026-917988.84.5Foxit Software Inc.Foxit PDF EditorCWE-732Foxit PDF Editor/Reader Updater Privilege Escalation
CVE-2026-813384.63.5UnknownMasterStudy LMS WordPress PluginCWE-345MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discu…
CVE-2026-917884.73.1Foxit Software Inc.Foxit PDF EditorCWE-668Foxit PDF Editor/Reader Missing Authorization Information Disclosure Vulnerab…
CVE-2026-918138.82.9Foxit Software Inc.Foxit PDF EditorCWE-367Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalatio…
CVE-2026-942437.32.8Apache Software FoundationApache Sling Security BundleCWE-346Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
CVE-2026-918127.92.7Foxit Software Inc.Foxit PDF EditorCWE-295Foxit PDF Editor/Reader FoxitUpdater Improper Certificate Validation Local Pr…
CVE-2026-917957.82.1Foxit Software Inc.Foxit PDF EditorCWE-822Foxit PDF Editor/Reader FileOpen Uninitialized Variable Remote Code Execution…
CVE-2026-5916710.0—JiHong88suneditorCWE-79SunEditor: Critical XSS vulnerability - sanitizer bypass
CVE-2026-8670810.0—ZohocorpManageEngine Applications ManagerCWE-321Sensitive data exposure
CVE-2026-195999.9—ZohocorpManageEngine OpManagerCWE-78Remote Code Execution vulnerability
CVE-2026-776029.9—OpenC3cosmosCWE-94OpenC3 COSMOS: Authenticated remote code execution via the user-writable conf…
CVE-2026-844749.9—Red HatRed Hat Ansible Automation Platform 2.4 for RHEL 8CWE-807Automation-controller: automation-controller-container: automation-controller…
CVE-2026-845029.9—Red HatRed Hat Ansible Automation Platform 2.4 for RHEL 8CWE-88Automation-controller: automation-controller-container: automation-controller…
CVE-2026-847199.9—Red HatRed Hat Ansible Automation Platform 2.4 for RHEL 8CWE-862Automation-controller: automation-controller: workflowjobtemplate /copy/ deep…
CVE-2026-890789.9—GitLabGitLabCWE-415Double Free in GitLab
CVE-2026-935779.9—GitLabGitLabCWE-190Integer Overflow or Wraparound in GitLab
CVE-2025-635649.8—n/an/aCWE-89SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 a…
CVE-2026-67219.8—IBMConcertCWE-78Multiple Vulnerabilities in IBM Concert Software
CVE-2026-67309.8—IBMConcertCWE-120Multiple Vulnerabilities in IBM Concert Software
CVE-2026-69289.8—IBMConcertCWE-416Multiple Vulnerabilities in IBM Concert Software
CVE-2026-761839.8—Apache Software FoundationApache TomcatCWE-289Apache Tomcat: Bypass of security constraints for WebSocket endpoints
CVE-2026-862489.8—Apache Software FoundationApache TomcatCWE-287Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes s…
CVE-2026-962769.8—Red HatRed Hat Enterprise Linux 10CWE-22Flatpak: flatpak: arbitrary write in host context via flatpak build-init
CVE-2026-857249.6—moquette-iomoquetteCWE-155Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass
CVE-2026-878989.4—WebProsPlesk extension "Site Import"CWE-78OS command injection in Plesk allows remote authenticated users to execute ar…
CVE-2026-878999.4—WebProscPanelCWE-250Execution with unnecessary privileges in cPanel allows remote authenticated u…
CVE-2026-879009.4—WebProsWP Toolkit for cPanelCWE-88Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows r…
CVE-2026-188729.3—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-79IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-933529.3—planklaravel-mediableCWE-434Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload
CVE-2026-956019.3—WBW PluginsProduct Filter by WBWCWE-89WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability
CVE-2026-958489.3—moquette-iomoquetteCWE-636Moquette fails open when configured authentication or authorization classes c…
CVE-2026-965609.3—ModelTCLightLLMCWE-502LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC…
CVE-2026-967549.3—orval-labsorvalCWE-94orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path
CVE-2026-967559.3—orval-labsorvalCWE-94orval @orval/effect 8.14.0 through 8.28.1 Code Injection
CVE-2026-967579.3—orval-labsorvalCWE-94orval before 8.29.0 Code Injection via unescaped OpenAPI media-type
CVE-2026-967589.3—orval-labsorvalCWE-94orval @orval/core before 8.28.0 Code Injection via Form-Data
CVE-2026-967599.3—orval-labsorvalCWE-94orval before 8.29.0 Code Injection via operationId
CVE-2026-967709.3—Temporal Technologies, Inc.s2s-proxyCWE-296s2s-proxy accepts untrusted client certificates
CVE-2026-631329.2—openbaoopenbaoCWE-208OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-674049.2—rabbitmqrabbitmq-serverCWE-295RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch
CVE-2026-967569.2—orval-labsorvalCWE-94orval before 8.30.0 Code Injection via Factory Generation
CVE-2026-672319.1—rabbitmqrabbitmq-serverCWE-295RabbitMQ: Trust-store whitelist by Issuer+Serial only
CVE-2026-758849.1—Red HatRed Hat Ansible Automation Platform 2.4 for RHEL 8CWE-184Awx: awx: privilege escalation to openshift namespace via pod_spec_override i…
CVE-2026-862469.1—Apache Software FoundationApache Tomcat NativeCWE-1188Apache Tomcat Native: Insecure OpenSSL options enabled
CVE-2026-863509.1—Apache Software FoundationApache TomcatCWE-444Apache Tomcat: Regression in fix for CVE-2026-41293 can trigger request heade…
CVE-2026-149138.8—ZohocorpManageEngine OpManagerCWE-89SQL Injection vulnerability
CVE-2026-184908.8—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-502IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-701258.8—MicrosoftMicrosoft 365 Apps for Enterprise—Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-758258.8—ZohocorpManageEngine OpManagerCWE-306Authentication Bypass vulnerability
CVE-2026-769788.8—ZohocorpManageEngine OpManagerCWE-78Command Injection vulnerability
CVE-2026-776018.8—OpenC3cosmosCWE-78OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
CVE-2026-803798.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-804128.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-804238.8—IBMDataStage on Cloud Pak for DataCWE-200DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-804258.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-815378.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-865838.8—carazoImport and export users and customersCWE-266Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+)…
CVE-2026-866778.8—ZohocorpManageEngine Applications ManagerCWE-89Broken Authentication vulnerability
CVE-2026-866788.8—ZohocorpManageEngine Applications ManagerCWE-639Broken Authentication vulnerability
CVE-2026-958478.8—moquette-iomoquetteCWE-99Moquette client IDs can cause cross-session H2 durable-queue corruption
CVE-2026-962758.8—Red HatRed Hat Enterprise Linux 10CWE-22Flatpak: flatpak: arbitrary write access as root via extra-data extraction
CVE-2026-964558.8—Pollen RoboticsReachy MiniCWE-306Reachy Mini daemon allows unauthenticated remote code execution through the a…
CVE-2026-967758.8—MLflowMLflowCWE-502MLflow dspy bypasses pickle deserialization control
CVE-2026-968048.8—MLflowMLflowCWE-502CVE-2026-96804
CVE-2026-556108.7—InvoiceShelfInvoiceShelfCWE-639InvoiceShelf has cross-company user read/update IDOR that enables cross-tenan…
CVE-2026-684928.7—WebProsPleskCWE-426An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8…
CVE-2026-823688.7—BrocadeSANnavCWE-284Insecure access controls on internal service ports in Brocade SANnav versions…
CVE-2026-824058.7—klever-ioklever-goCWE-863Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on att…
CVE-2026-846838.7—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-79Automation-controller: automation-controller-container: automation-controller…
CVE-2026-846918.7—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-134Automation-controller: automation-controller-container: automation-controller…
CVE-2026-958428.7—moquette-iomoquetteCWE-248Moquette uncaught MQTT command exceptions can terminate shared session event …
CVE-2026-958438.7—moquette-iomoquetteCWE-20Moquette malformed shared subscriptions can crash command processing
CVE-2026-958448.7—moquette-iomoquetteCWE-674Moquette deeply nested MQTT topics can cause stack exhaustion
CVE-2026-958458.7—moquette-iomoquetteCWE-770Moquette unbounded per-session message queues allow memory exhaustion
CVE-2026-958468.7—moquette-iomoquetteCWE-862Moquette publishes Last-Will messages without enforcing write authorization
CVE-2026-966738.7—PhotoviewPhotoviewCWE-89Photoview through 2.4.0 SQL Injection via album download route
CVE-2026-823698.6—BrocadeSANnavCWE-78Insufficient input sanitization of shell metacharacters in Brocade SANnav bef…
CVE-2026-823708.6—BrocadeSANnavCWE-77Unauthenticated remote command injection in the Brocade SANnav orchestrator H…
CVE-2026-860648.6—klever-ioklever-goCWE-200Klever-Go: /log controls global node logging
CVE-2026-909018.6—joomshaper.comEasy Store extension for JoomlaCWE-74Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection i…
CVE-2026-909048.6—joomshaper.comEasy Store extension for JoomlaCWE-284Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in Api…
CVE-2026-933498.6—frictionlessdatafrictionless-pyCWE-78Frictionless OS Command Injection via explore Console Command
CVE-2026-966568.6—PlexMedia ServerCWE-73Plex Media Server arbitrary file write
CVE-2026-751318.5—nm-l2tpNetworkManager-l2tpCWE-88NetworkManager-l2tp Privilege Escalation via pppd Username Injection
CVE-2026-760868.5—verbbformieCWE-862Formie: Integration form-settings action allows SSRF and exfiltration of stor…
CVE-2026-766488.5—Red HatRed Hat Ansible Automation Platform 2.7CWE-862Automation-controller: automation-controller-container: aap controller: copya…
CVE-2026-793108.5—n/an/aCWE-94webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The…
CVE-2026-935278.5—bdthemesLive Copy Paste for ElementorCWE-89WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vuln…
CVE-2026-937738.5—Nick van WobbieMollie FormsCWE-89WordPress Mollie Forms plugin <= 2.11.0 - SQL Injection vulnerability
CVE-2026-941248.5—levelfourdevelopmentWP EasyCartCWE-89WordPress WP EasyCart plugin <= 5.9.4 - SQL Injection vulnerability
CVE-2026-56958.4—MicroweberAdministration panelCWE-434Multiple vulnerabilities in the Microweber administration panel
CVE-2026-824098.4—klever-ioklever-goCWE-116Klever-Go: Elasticsearch bulk / painless injection via on-chain account name …
CVE-2026-191798.2—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-74IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-660798.2—rabbitmqrabbitmq-serverCWE-770RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS
CVE-2026-672328.2—rabbitmqrabbitmq-serverCWE-409RabbitMQ: Web-MQTT decompression bomb
CVE-2026-684908.2—WebProscPanelCWE-732Incorrect permission assignment allows local users to obtain sensitive CalDAV…
CVE-2026-760878.2—verbbformieCWE-639Formie: Unauthenticated users can overwrite incomplete submissions via submit…
CVE-2026-844868.2—Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9CWE-489Automation-controller: automation-controller-container: automation-controller…
CVE-2026-908998.2—joomshaper.comEasy Store extension for JoomlaCWE-200Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in …
CVE-2026-909028.2—joomshaper.comEasy Store extension for JoomlaCWE-74Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection i…
CVE-2026-965998.2—isotopeisotope-coreCWE-330Isotope eCommerce through 2.9.10 Weak Order Identifier Generation
CVE-2026-181818.1—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-321IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-191258.1—lynn999EthPress – Web3 LoginCWE-287EthPress <= 2.3.5 - Unauthenticated Authentication Bypass
CVE-2026-777628.1—Apache Software FoundationApache TomcatCWE-362Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request
CVE-2026-847878.1—ZohocorpManageEngine OpManagerCWE-250Privilege Escalation vulnerability
CVE-2026-866838.1—ZohocorpManageEngine Applications ManagerCWE-20Broken Authentication Vulnerability
CVE-2026-944878.1—PublishPressPublishPress CapabilitiesCWE-352WordPress PublishPress Capabilities plugin <= 2.50.1 - Cross Site Request For…
CVE-2026-129747.9—ForcepointForcepoint Security Engine (NGFW)CWE-183Security Policy Bypass in Forcepoint Security Engine (NGFW)
CVE-2026-67947.8—IBMConcertCWE-415Multiple Vulnerabilities in IBM Concert Software
CVE-2026-69357.8—IBMConcertCWE-427Multiple Vulnerabilities in IBM Concert Software
CVE-2026-964427.8—Red HatRed Hat Enterprise Linux 10CWE-94Emacs: emacs: arbitrary code execution, incomplete fix for cve-2024-53920
CVE-2026-965127.8—Red HatRed Hat Enterprise Linux 10CWE-863Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-…
CVE-2026-968897.8—Red HatRed Hat Enterprise Linux 10CWE-416Librsvg: use-after-free when xml includes have duplicated entities
CVE-2026-760897.7—verbbformieCWE-200Formie: Missing authorization on sent notification resend modal exposes submi…
CVE-2026-769797.7—ZohocorpManageEngine OpManagerCWE-91XML Injection vulnerability
CVE-2026-812087.7—IBMDataStage on Cloud Pak for DataCWE-522DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-815367.7—IBMDataStage on Cloud Pak for DataCWE-611DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-844997.7—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-209Automation-controller: automation-controller-container: automation-controller…
CVE-2026-924707.7—GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-123707.6—ZohocorpManageEngine OpManagerCWE-1336Remote Code Execution Vulnerability
CVE-2026-660707.6—rabbitmqrabbitmq-serverCWE-942RabbitMQ: CORS * reflects Origin with Allow-Credentials
CVE-2026-773947.6—OpenC3cosmosCWE-79OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
CVE-2026-847067.6—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-184Automation-controller: automation-controller-container: automation-controller…
CVE-2026-866817.6—ZohocorpManageEngine Applications ManagerCWE-306Broken Access Control vulnerability
CVE-2026-941747.6—WebFactoryEmail LogCWE-89WordPress Email Log plugin <= 2.63 - SQL Injection vulnerability
CVE-2026-955227.6—Syed BalkhiEasy Digital DownloadsCWE-89WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability
CVE-2026-955937.6—Ben RobertsUltimeterCWE-89WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability
CVE-2026-968267.6—Shazzad Hossain KhanW4 Post ListCWE-89WordPress W4 Post List plugin <= 3.0.6 - SQL Injection vulnerability
CVE-2026-66687.5—n/aPgBouncerCWE-190Integer overflow causes an infinite loop in packet buffer growth in PgBouncer
CVE-2026-153587.5—ZohocorpManageEngine OpManagerCWE-428Path Traversal Vulnerability
CVE-2026-198887.5—n/aPgBouncerCWE-476NULL pointer dereference in SCRAM client-final-message parsing in PgBouncer
CVE-2026-599907.5—typeleveljawnCWE-770Jawn: Uncontrolled nesting depth in JSON parser
CVE-2026-616957.5—squarewireCWE-129Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes a…
CVE-2026-618147.5—typeleveljawnCWE-400Jawn: Quadratic parsing effort in AsyncParser
CVE-2026-735917.5—DellSecure Connect Gateway (SCG) Policy ManagerCWE-540Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-758877.5—Red HatRed Hat OpenShift Container Platform 4CWE-22Openshift/console: openshift/console: unauthenticated path traversal in i18n …
CVE-2026-774227.5—jlinejline3CWE-1333JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
CVE-2026-774237.5—jlinejline3CWE-1333JLine: ReDoS in Built-in Less Viewer Search
CVE-2026-777917.5—Apache Software FoundationApache TomcatCWE-400Apache Tomcat: DoS via busy wait during WebSocket close
CVE-2026-783837.5—Apache Software FoundationApache TomcatCWE-770Apache Tomcat: AJP DoS via missing request body
CVE-2026-796777.5—Apache Software FoundationApache TomcatCWE-772Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout
CVE-2026-860657.5—klever-ioklever-goCWE-770Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no conne…
CVE-2026-862437.5—Apache Software FoundationApache Tomcat NativeCWE-126Apache Tomcat Native: DoS via TLS handshake
CVE-2026-870227.5—Apache Software FoundationApache TomcatCWE-130Apache Tomcat: WebSocket message smuggling with per-message-deflate
CVE-2026-888307.5—Red HatRed Hat Hardened ImagesCWE-131Busybox: busybox: tls montgomery reduction allocates bytes instead of digits,…
CVE-2026-955137.5—vcitaOnline Booking & Scheduling Calendar for WordPress by vcitaCWE-862WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin …
CVE-2026-956047.5—TangibleLoops & LogicCWE-862WordPress Loops & Logic plugin <= 4.2.4 - Broken Access Control vulnerability
CVE-2026-965417.5—Red HatRed Hat Enterprise Linux 10CWE-400Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack …
CVE-2026-181847.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-611IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-735887.4—DellSecure Connect Gateway (SCG) Policy ManagerCWE-306Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-769807.4—ZohocorpManageEngine OpManagerCWE-20Data Exposure vulnerability
CVE-2026-862477.4—Apache Software FoundationApache Tomcat NativeCWE-366Apache Tomcat Native: Client certificate requirements can be down-graded
CVE-2026-917757.4—LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS sur…
CVE-2026-927307.4—LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import…
CVE-2026-941817.4—The Browser Company of New YorkArcCWE-451Address Bar Spoof Risk; Missing Fullscreen Notification via Select Element
CVE-2026-941837.4—The Browser Company of New YorkArc SearchCWE-451Address bar spoofing risk in affected Android versions of Arc Search
CVE-2026-956767.4—WatchGuardAuthPoint Authentication GatewayCWE-287AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Au…
CVE-2026-968087.4—FlatpakFlatpakCWE-61In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-hel…
CVE-2026-181857.3—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-306IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-188757.3—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-74IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-660777.3—rabbitmqrabbitmq-serverCWE-79RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI
CVE-2026-759737.3—Apache Software FoundationApache TomcatCWE-287Apache Tomcat: Cross-context authentication mix-up with Jakarta Authenticatio…
CVE-2026-784377.3—Apache Software FoundationApache TomcatCWE-459Apache Tomcat: HTTP/2 DoS via malformed request
CVE-2026-888327.3—Red HatRed Hat Hardened ImagesCWE-787Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixe…
CVE-2026-758867.2—Red HatRed Hat OpenShift Container Platform 4CWE-441Openshift/console: openshift/console: unauthenticated reverse proxy to in-clu…
CVE-2026-854757.2—Red HatRed Hat Ansible Automation Platform 2.7CWE-96Automation-controller: automation-controller-container: automation-controller…
CVE-2026-909037.2—joomshaper.comEasy Store extension for JoomlaCWE-352Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Ad…
CVE-2026-909057.2—joomshaper.comEasy Store extension for JoomlaCWE-284Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site C…
CVE-2026-937697.2—HumhubHumhubCWE-79HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderFo…
CVE-2026-956037.2—Victor RodriguezReycob Product Import ExportCWE-502WordPress Reycob Product Import Export plugin <= 2.3.0 - PHP Object Injection…
CVE-2026-181777.1—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-862IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-672357.1—rabbitmqrabbitmq-serverCWE-770RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size
CVE-2026-672387.1—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Atom-table exhaustion via reply-to queue name decoding
CVE-2026-824067.1—klever-ioklever-goCWE-841Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native mark…
CVE-2026-847147.1—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-184Automation-controller: automation-controller: incomplete sanitize_jinja() reg…
CVE-2026-847897.1—ZohocorpManageEngine OpManagerCWE-639Broken Access Control vulnerability
CVE-2026-847917.1—ZohocorpManageEngine OpManagerCWE-639Broken Access Control vulnerability
CVE-2026-866797.1—ZohocorpManageEngine Applications ManagerCWE-20Broken Access Control vulnerability
CVE-2026-935267.1—NexcessEvent TicketsCWE-79WordPress Event Tickets plugin <= 5.29.4 - Cross Site Scripting (XSS) vulnera…
CVE-2026-936227.1—NicolasKulkaWPS Limit LoginCWE-79WordPress WPS Limit Login plugin <= 1.5.9.3 - Cross Site Scripting (XSS) vuln…
CVE-2026-937747.1—Jacob N. BreetveltWP Photo Album PlusCWE-79WordPress WP Photo Album Plus plugin <= 9.3.02.002 - Cross Site Scripting (XS…
CVE-2026-941767.1—Kitae ParkMang Board WPCWE-79WordPress Mang Board WP plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-941797.1—RazorpayRazorpay Payment ButtonCWE-79WordPress Razorpay Payment Button plugin <= 2.4.9 - Cross Site Scripting (XSS…
CVE-2026-955157.1—Kevin StoverNinja FormsCWE-79WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-955287.1—Mohammed KaludiCore Web Vitals & PageSpeed BoosterCWE-79WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site S…
CVE-2026-955297.1—codepeopleCalculated Fields FormCWE-79WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XS…
CVE-2026-955907.1—tainacanTainacanCWE-89WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability
CVE-2026-966097.1—RoburAlbatrossCWE-770Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring…
CVE-2026-966517.1—PlexMedia ServerCWE-22Plex Media Server path traversal
CVE-2026-824077.0—klever-ioklever-goCWE-20Klever-Go: Validator registration accepts an unvalidated BLS public key → con…
CVE-2026-966007.0—isotopeisotope-coreCWE-89Isotope eCommerce through 2.9.10 SQL Injection via Backend Callbacks
CVE-2026-672286.9—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component
CVE-2026-672296.9—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata
CVE-2026-922846.9—caddyservercaddyCWE-770Caddy: Unbounded body buffer via {http.request.body} placeholder — memory exh…
CVE-2026-926926.9—sulusuluCWE-89Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
CVE-2026-966116.9—FFmpegFFmpegCWE-190FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_…
CVE-2026-966546.9—PlexMedia ServerCWE-84Plex Media Server URL injection
CVE-2026-967516.9—pmTicketProject-Management-SoftwareCWE-89pmTicket Project-Management-Software add_project.php setSync sql injection
CVE-2026-967626.9—kvcache-aimooncakeCWE-639kvcache-ai mooncake RPC Path UnmountSegment authorization
CVE-2026-614136.8—DellSecure Connect Gateway (SCG) Policy ManagerCWE-269Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-735876.8—DellSecure Connect Gateway (SCG) Policy ManagerCWE-295Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-964456.8—Red HatRed Hat Build of KeycloakCWE-287Keycloak-services: keycloak-services: conditional otp skip-header policy eval…
CVE-2026-888396.7—Red HatRed Hat Hardened ImagesCWE-787Busybox: busybox: passwd/group parser writes heap pointers out of bounds due …
CVE-2026-847166.6—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-266Automation-controller: automation-controller: instance install_bundle issues …
CVE-2026-847246.6—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-88Automation-controller: automation-controller: systemjob extra_vars.days argum…
CVE-2026-181796.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-862IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-181806.5—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-89IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-735816.5—Apache Software FoundationApache TomcatCWE-299Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when c…
CVE-2026-771126.5—Global IT Informatics Technology Services Inc.WeollCWE-918SSRF Leading to JWT Token Disclosure in Global IT Informatics' Weoll
CVE-2026-774216.5—jlinejline3CWE-1333JLine: ReDoS in Nano Editor Regex Search Mode
CVE-2026-793046.5—n/an/a—CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileConte…
CVE-2026-793066.5—n/an/a—CyberPanel v1.9.1 contains a path traversal vulnerability in the compress met…
CVE-2026-847136.5—Red HatRed Hat Ansible Automation Platform 2.7CWE-639Automation-controller: automation-controller: notification.recipients/subject…
CVE-2026-847206.5—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-639Automation-controller: automation-controller: workflowjobnode.ancestor_artifa…
CVE-2026-866016.5—UnknownWP Recipe MakerCWE-74WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via …
CVE-2026-888376.5—Red HatRed Hat Hardened ImagesCWE-305Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, …
CVE-2026-921646.5—streamlinkstreamlinkCWE-73Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading loc…
CVE-2026-935296.5—Bilal NaseerWSP MCP &#8211; AI Agents ConnectorCWE-862WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Contr…
CVE-2026-936186.5—Crocoblock. Jetimpex Inc.JetTricksCWE-79WordPress JetTricks plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-936206.5—PayPlus Tech TeamPayPlus Payment GatewayCWE-862WordPress PayPlus Payment Gateway plugin <= 8.2.5 - Broken Access Control vul…
CVE-2026-937726.5—TomdeverwpForo ForumCWE-79WordPress wpForo Forum plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-941186.5—Leap13Premium Blocks – Gutenberg Blocks for WordPressCWE-79WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - …
CVE-2026-941686.5—Leap13Premium Addons for ElementorCWE-79WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Script…
CVE-2026-943916.5—RustauriusUltimate FAQCWE-79WordPress Ultimate FAQ plugin <= 2.4.14 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-944616.5—metaphorcreationsDittyCWE-79WordPress Ditty plugin <= 3.1.69 - Cross Site Scripting (XSS) vulnerability
CVE-2026-944986.5—AppMySiteAppMySiteCWE-862WordPress AppMySite plugin <= 3.15.4 - Broken Access Control vulnerability
CVE-2026-945006.5—RoxnorElementsKit Elementor addons LiteCWE-79WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scri…
CVE-2026-946716.5—RadiusThemeThe Post GridCWE-79WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-946806.5—RadiusThemeThe Post GridCWE-79WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-946826.5—SecondLineThemesPodcast Importer SecondLineCWE-79WordPress Podcast Importer SecondLine plugin <= 1.5.6 - Cross Site Scripting …
CVE-2026-946846.5—oceanwpOcean ExtraCWE-79WordPress Ocean Extra plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability
CVE-2026-955236.5—weDevsWP User FrontendCWE-290WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability
CVE-2026-955256.5—weDevsWP User FrontendCWE-22WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnera…
CVE-2026-955276.5—Conekta GroupConekta Payment GatewayCWE-862WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vul…
CVE-2026-955306.5—PixelYourSitePixelYourSite – Your smart PIXEL (TAG) ManagerCWE-79WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - C…
CVE-2026-955866.5—ThemeficUltimate Addons for Contact Form 7CWE-79WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Sc…
CVE-2026-956026.5—YITHYITH WooCommerce Request A QuoteCWE-639WordPress YITH WooCommerce Request A Quote plugin < 4.46.1 - Insecure Direct …
CVE-2026-630006.4—redaxocoreCWE-352REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon …
CVE-2026-735866.4—DellSecure Connect Gateway (SCG) Policy ManagerCWE-613Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-847216.4—Red HatRed Hat Ansible Automation Platform 2.7CWE-918Automation-controller: automation-controller: email notification backend allo…
CVE-2026-599806.3—python-hyperhpackCWE-400hpack: Unbounded variable integer decoding can cause run-away computation on …
CVE-2026-735896.3—DellSecure Connect Gateway (SCG) Policy ManagerCWE-261Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-927006.3—caddyservercaddyCWE-178Caddy: fileHidden() case-sensitive pattern bypass — exposes "hidden" files vi…
CVE-2026-964566.3—Pollen RoboticsReachy MiniCWE-287Reachy Mini Bluetooth PIN authentication can be bypassed by racing an authent…
CVE-2026-67186.2—IBMConcertCWE-276Multiple Vulnerabilities in IBM Concert Software
CVE-2026-192676.2—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-306IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-888356.1—Red HatRed Hat Hardened ImagesCWE-125Busybox: busybox: dpkg read_package_field() steps past nul terminator, causin…
CVE-2026-631316.0—openbaoopenbaoCWE-863OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific …
CVE-2026-660676.0—rabbitmqrabbitmq-serverCWE-770RabbitMQ: Stream protocol skips per vhost per user connection limits
CVE-2026-660726.0—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Atom table exhaustion via stream `chunk_selector`
CVE-2026-660746.0—rabbitmqrabbitmq-serverCWE-1333RabbitMQ: ReDoS via management API ?name= filter
CVE-2026-672196.0—rabbitmqrabbitmq-serverCWE-770RabbitMQ: Consistent-hash exchange unbounded weight
CVE-2026-672206.0—rabbitmqrabbitmq-serverCWE-400RabbitMQ: JMS topic exchange erl_scan atom exhaustion
CVE-2026-56965.9—MicroweberAdministration panelCWE-79Multiple vulnerabilities in the Microweber administration panel
CVE-2026-66695.9—n/aPgBouncerCWE-400Unbounded SCRAM iteration count causes CPU exhaustion in PgBouncer
CVE-2026-660805.9—rabbitmqrabbitmq-serverCWE-770RabbitMQ: Super-stream partitions unbounded allocation
CVE-2026-672215.9—rabbitmqrabbitmq-serverCWE-312RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords
CVE-2026-660685.6—rabbitmqrabbitmq-serverCWE-532RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs
CVE-2026-866125.6—UnknownNinja TablesCWE-74Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Flu…
CVE-2026-774205.5—jlinejline3CWE-1333JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
CVE-2026-965135.5—NeethuhariiCafeManagementCWE-284Neethuharii CafeManagement AddProductCode.php unrestricted upload
CVE-2026-965145.5—NeethuhariiCafeManagementCWE-74Neethuharii CafeManagement Login CafePortalLogin.php sql injection
CVE-2026-965565.5—NeethuhariiCafeManagementCWE-266Neethuharii CafeManagement AddCashierCode.php addcashier improper authorization
CVE-2026-966015.5—Abdurrab5online-makeup-storeCWE-74Abdurrab5 online-makeup-store Admin Login index.php sql injection
CVE-2026-966025.5—Abdurrab5online-makeup-storeCWE-74Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection
CVE-2026-966035.5—Abdurrab5online-makeup-storeCWE-862Abdurrab5 online-makeup-store Admin functions.php confirm_user authorization
CVE-2026-966045.5—SoftNews Media GroupDataLife EngineCWE-74SoftNews Media Group DataLife Engine Search search.php strip_data sql injection
CVE-2026-966065.5—LB-LinkBL-CPE600EUCWE-200LB-Link BL-CPE600EU Configuration Backup Mifi_config.bin information disclosure
CVE-2026-185055.4—IBMFinancial Transaction Manager (FTM) for RedHat OpenShiftCWE-601IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
CVE-2026-711775.4—DellSecure Connect Gateway (SCG) Policy ManagerCWE-1021Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-804445.4—Abis Technology Ltd. Co.AVESİSCWE-601Unauthenticated Open Redirect Vulnerability in Abis Technology's AVESİS
CVE-2026-889745.4—wp-graphqlwp-graphqlCWE-863WPGraphQL: Contributor can publish and modify posts without the required capa…
CVE-2026-928745.4—GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-946795.4—WPManageNinjaFluent SupportCWE-862WordPress Fluent Support plugin <= 2.3.2 - Broken Access Control vulnerability
CVE-2026-36265.3—IBMConcertCWE-209Multiple Vulnerabilities in IBM Concert Software
CVE-2026-69255.3—IBMConcertCWE-22Multiple Vulnerabilities in IBM Concert Software
CVE-2026-527445.3—gocdgocdCWE-862GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API
CVE-2026-674055.3—rabbitmqrabbitmq-serverCWE-1385RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)
CVE-2026-738585.3—solspacecraft-freeformCWE-1336Solspace Freeform: Limited Twig template injection via submitted field values
CVE-2026-840915.3—UnknownSUMIT Payment Gateway for WooCommerceCWE-287SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confi…
CVE-2026-847125.3—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-497Automation-controller: automation-controller: unauthenticated /api/v2/ping/ d…
CVE-2026-847175.3—Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8CWE-204Automation-controller: automation-controller: unauthenticated 200-vs-403 orac…
CVE-2026-870705.3—UnknownForminator FormsCWE-348Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP S…
CVE-2026-870715.3—UnknownForminator FormsCWE-20Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitte…
CVE-2026-879785.3—UnknownPaymob for WooCommerceCWE-345Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverifi…

Results continue: ranks 401–472.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-23 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.