boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, September 24, 2026 · all times UTC← 2026-09-23 · archive

Security Box Score — September 24, 2026

CISA adds 2 to KEV; 553 CVEs published, led by Linux (234).

553 CVEs published September 24, 2026: 28 critical, 174 high, 120 medium, 30 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 201 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 153 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1230647287——
KEV catalog size1723

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3066 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux17415832529257171311560.17.8.0020+325 ▲
microsoft10012900206198769116289301.07.8.0047+532 ▲
google5172685332104911831218090.37.5.0027+444 ▲
red hat2308595235840346200.06.7.0037+33 ▲
apple24656367165317148881.46.5.0019+206 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0019-15 ▼
suse1341721121000.07.5.0039+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0046+51 ▲
ubiquiti665362810334.69.1.0050+6 ▲
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache131643147272206163320.37.5.0064-9 ▼
mozilla113301102126730900.08.8.0034+54 ▲
gitlab241007245811533.05.3.0034+8 ▲
drupal2694119668411.15.7.0027+26 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614102233.38.7.0189-1 ▼
go440211000.05.9.0034+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-255 ▼
ibm390100919646033518610.17.5.0037+16 ▲
adobe22483082362376102150.67.5.0036+164 ▲
progress3641539100611.68.1.0046-16 ▼
zohocorp273762470000.08.1.0113+23 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-10 ▼
servicenow5107300200.09.4.0143+5 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link277222261212300.08.5.0192+11 ▲
siemens1552633103000.07.3.0026-4 ▼
synology1946510256000.05.6.0032+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
hikvision390540000.07.1.0038+3 ▲
abb291530000.07.2.0018+2 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1953663117014322210.37.2.0030+137 ▲
sourcecodester632320013894000.05.5.0043+16 ▲
nvidia5118521127370000.07.8.0040+27 ▲
spring017013608314000.06.5.0033-6 ▼
mongodb71169699604100.07.1.0039+39 ▲
itsourcecode371530037116000.02.1.0033+9 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0044+136 ▲
wwbn1061462349740000.06.9.0036+97 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85046.488898.88.8
CVE-2026-60004.239997.89.8
CVE-2026-82329.141296.49.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-85706.092995.210.0
CVE-2026-19632.089695.19.8
CVE-2026-83548.087695.010.0
CVE-2026-79756.075294.38.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8570610.0.0929KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-1888510.0.0724
CVE-2026-1888610.0.0504
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8222210.0.0225
Most disclosures (vendor)
VendorCVEs
linux1969
microsoft1009
oracle635
google519
ibm406
red hat251
apple246
adobe227
dell209
apache145
Most KEV additions (YTD)
VendorKEV
microsoft30
cisco16
google9
apple8
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven89
Packagist16
npm15
PyPI13
crates.io8
RubyGems2
Go1
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-81578PaperCut3
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171772
CVE-2021-27102n/a2021-11-171772
CVE-2021-27101n/a2021-11-171772
CVE-2021-27103n/a2021-11-171772
CVE-2021-21017Adobe2021-11-171772
CVE-2021-28550Adobe2021-11-171772
CVE-2021-42013Apache Software Foundation2021-11-171772
CVE-2021-41773Apache Software Foundation2021-11-171772
CVE-2021-30858Apple2021-11-171772
CVE-2021-30860Apple2021-11-171772

Transactions

ADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026.

ADDED TO KEV — CVE-2026-71362 (Adobe Commerce). Remediation due September 27, 2026.

EXPLOIT PUBLISHED — FreeRDP: 15 CVEs (CVE-2026-55194, CVE-2026-63633, CVE-2026-91945, CVE-2026-91949, CVE-2026-91950, CVE-2026-91951, CVE-2026-91952, CVE-2026-91953, CVE-2026-91954, CVE-2026-91955, CVE-2026-91956, CVE-2026-91957, CVE-2026-91958, CVE-2026-91959, CVE-2026-91960). Public exploit references added.

EXPLOIT PUBLISHED — moxi624 MoguBlog: 6 CVEs (CVE-2026-89260, CVE-2026-89261, CVE-2026-89262, CVE-2026-89263, CVE-2026-89264, CVE-2026-89265). Public exploit references added.

EXPLOIT PUBLISHED — rocq-prover rocq: 5 CVEs (CVE-2020-37268, CVE-2026-72703, CVE-2026-72704, CVE-2026-72705, CVE-2026-72714). Public exploit references added.

EXPLOIT PUBLISHED — cjbi admin3: 4 CVEs (CVE-2026-92918, CVE-2026-92919, CVE-2026-92920, CVE-2026-92921). Public exploit references added.

EXPLOIT PUBLISHED — MaxSite CMS: 4 CVEs (CVE-2026-87927, CVE-2026-87928, CVE-2026-87929, CVE-2026-87930). Public exploit references added.

EXPLOIT PUBLISHED — 201206030 novel-plus: 3 CVEs (CVE-2026-90939, CVE-2026-90940, CVE-2026-90941). Public exploit references added.

EXPLOIT PUBLISHED — elixir-tesla tesla: 3 CVEs (CVE-2026-48594, CVE-2026-48595, CVE-2026-48596). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2016-20096 (Kunshi Network Technology Co., Ltd. Linknat VOS3000). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-0108 (Palo Alto Networks Cloud NGFW). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-30066 (tj-actions changed-files). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4637 (Paessler GmbH PRTG Network Monitor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54460 (open-reception appointment-booking-software). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56812 (phoenixframework phoenix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57851 (Micro-Star International (MSI) KernCoreLib64.sys). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63635 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67549 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-70619 (odysseus-dev odysseus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-72777 (DayuanJiang next-ai-draw-io). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77525 (1Panel-dev MaxKB). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82280 (QuivrHQ quivr). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84810 (claude-world claude-skill-antivirus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86175 (netbox-community netbox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86176 (netbox-community netbox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86177 (pterodactyl panel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86178 (pixelfed). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90942 (casdoor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91143 (snail007 goproxy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91752 (GNU libextractor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91993 (dromara Jpom). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91994 (semaphoreui semaphore). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91995 (pig-mesh pig). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91996 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91997 (evolution-foundation evolution-api). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-91998 (casdoor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93972 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93977 (code-projects Assessment Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94003 (Comfast CF-N1-S). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94030 (SerenityOS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94035 (SourceCodester Drug Recommendation System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94040 (vas3k TaxHacker). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94045 (newbee-ltd newbee-mall). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94092 (dmlc dgl). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94097 (Netcore NBR200V2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94102 (WuzhiCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94144 (drogonframework drogon). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94150 (Omega Solution HRM OS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94214 (ST Engineering iDirect Evolution). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94411 (jishenghua jshERP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94426 (xuxueli xxl-job). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94493 (Gigatech PDV5701). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94495 (jishenghua jshERP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94532 (dromara lamp-cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94540 (MrPear DesktopSMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96551 (sfturing hosp_order). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96552 (sfturing hosp_order). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96556 (Neethuharii CafeManagement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96601 (Abdurrab5 online-makeup-store). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96603 (Abdurrab5 online-makeup-store). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96604 (SoftNews Media Group DataLife Engine). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96676 (Fast FAC1900R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96680 (ByteDance Coze Scraper Extension). Public exploit reference added.

DUE DATE PASSED — CVE-2026-87491 (Google Chrome). CISA remediation deadline was September 23, 2026; still in catalog.

RESCORED — Exim: 3 CVEs (CVE-2026-94054, CVE-2026-94055, CVE-2026-94057). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2008-4128. CVSS 4.3 → 8.1 (NVD).

RESCORED — CVE-2025-48384 (git). CVSS 8.1 → 8 (NVD).

RESCORED — CVE-2026-11538 (IBM WebSphere Application Server). CVSS 3.7 → 5.3 (NVD).

RESCORED — CVE-2026-69553 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD).

RESCORED — CVE-2026-70570 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.1 (NVD).

RESCORED — CVE-2026-70575 (Microsoft Windows 11 version 23H2). CVSS 5.3 → 6.5 (NVD).

RESCORED — CVE-2026-88097 (Microsoft Edge (Chromium-based)). CVSS 8.1 → 7.8 (NVD).

RESCORED — CVE-2026-96739 (SEMCMS). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-96751 (pmTicket Project-Management-Software). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-96762 (kvcache-ai mooncake). CVSS 6.9 → 5.5 (NVD).

PATCH SHIPPED — CVE-2026-78225 (Wärtsilä FOS-Onboard). Fixed in FOS-Onboard 5.08.4052.01.

PATCH SHIPPED — CVE-2026-81855 (Wärtsilä FOS-Onboard). Fixed in FOS-Onboard 5.08.4052.01.

PATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4.

PATCH SHIPPED — CVE-2026-96512 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.9.17-16.p2.2.hum1.

Yesterday's Results

How to read these box scores · glossary

553 CVEs published. 25 box scores and 375 table rows below; the remaining 153 continue on page 2 — every CVE is listed, nothing truncated.

Zohocorp ManageEngine EventLog Analyzer — Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0235   83.0     —
AFFECTED
  Product                         Versions     Fixed
  ManageEngine EventLog Analyzer  unspecified  —
  ManageEngine Log360             unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 24  Published (CNA: Zohocorp)
CWE-248 · CNA: Zohocorp · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
visualcomposer Visual Composer Website Builder — Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.6     —
AFFECTED
  Product                          Versions     Fixed
  Visual Composer Website Builder  unspecified  —
TIMELINE
  Jun 14  Reserved by CNA
  Sep 24  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
PaperCut NG/MF: Remote Code Execution via Scan2Fax
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0074   52.5     —
AFFECTED
  Product         Versions     Fixed
  PaperCut NG/MF  unspecified  —
TIMELINE
  Aug 28  Reserved by CNA
  Sep 24  Published (CNA: PaperCut)
CWE-22, CWE-78 · CNA: PaperCut · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0065   49.1     —
AFFECTED
  Product  Versions   Fixed
  DIR-825  3.00b32 –  —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-119, CWE-787 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Deltaww DIAEnergie — Improper Access Control in DIAEnergie
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0046   37.4     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 24  Published (CNA: Deltaww)
CWE-284 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Deferred
yhx070424 ShopXO Ueditor Upload ueditor.php path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0042   34.0     —
AFFECTED
  Product  Versions  Fixed
  ShopXO   2.2.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0041   32.1     —
AFFECTED
  Product  Versions  Fixed
  signoz   0.8.0 –   0.143.0
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulnCheck)
CWE-1188 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Deferred
paytiumsupport Paytium: Mollie payment forms & donations — Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0039   30.5     —
AFFECTED
  Product                                    Versions     Fixed
  Paytium: Mollie payment forms & donations  unspecified  —
TIMELINE
  Jul 31  Reserved by CNA
  Sep 24  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
PaperCut MF/NG: User permissions are not evaluated on report generation
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0038   29.0     —
AFFECTED
  Product         Versions     Fixed
  PaperCut NG/MF  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Sep 24  Published (CNA: PaperCut)
CWE-639 · CNA: PaperCut · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
eesywp eesy_ID2WP – Publish InDesign HTML5 — eesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0036   27.5     —
AFFECTED
  Product                              Versions     Fixed
  eesy_ID2WP – Publish InDesign HTML5  unspecified  —
TIMELINE
  Aug 20  Reserved by CNA
  Sep 24  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
mwilliamson mammoth.js — mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   L   H    8.4   .0036   26.5     —
AFFECTED
  Product     Versions     Fixed
  mammoth.js  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Sep 24  Published (CNA: mitre)
CWE-1321 · CNA: mitre · CVSS v4.0 · 4 references · NVD status: Awaiting Analysis
SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   N   H   H   N    7.6   .0035   25.8     —
AFFECTED
  Product  Versions  Fixed
  signoz   0.98.0 –  0.143.0
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulnCheck)
CWE-613 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Deferred
Deltaww DIAEnergie — Authentication Bypass in DIAEnergie
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0035   25.3     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 24  Published (CNA: Deltaww)
CWE-287 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Deferred
Deltaww DIAEnergie — Path Traversal in DIAEnergie
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0034   25.2     —
AFFECTED
  Product     Versions     Fixed
  DIAEnergie  unspecified  —
TIMELINE
  Aug 24  Reserved by CNA
  Sep 24  Published (CNA: Deltaww)
CWE-22 · CNA: Deltaww · CVSS v3.1 · 1 reference · NVD status: Deferred
Edimax BR-6428nC goform websRedirect redirect
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0034   24.2     —
AFFECTED
  Product    Versions  Fixed
  BR-6428nC  1.16 –    —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-601 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
n/a MantisZip — MantisZip Preview MainWindow.UI.cs Path.Combine path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   L    2.1   .0034   24.1     —
AFFECTED
  Product    Versions  Fixed
  MantisZip  0.4.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSoc…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    8.6   .0031   21.5     —
AFFECTED
  Product  Versions  Fixed
  Nanomsg  0.5.0 –   —
TIMELINE
  Sep 24  Reserved by CNA
  Sep 24  Published (CNA: mitre)
CWE-122 · CNA: mitre · CVSS v4.0 · 3 references · NVD status: Awaiting Analysis
PaperCut NG/MF: Remote Code Execution via Scripting Subsystem
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   H   N   H   H   H    7.5   .0031   21.3     —
AFFECTED
  Product         Versions     Fixed
  PaperCut NG/MF  unspecified  —
TIMELINE
  Jul 5   Reserved by CNA
  Sep 24  Published (CNA: PaperCut)
CWE-94 · CNA: PaperCut · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Intelliants Subrion CMS actions.json assign-owner information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0029   19.4     —
AFFECTED
  Product      Versions  Fixed
  Subrion CMS  4.2.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
SPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.txt loadCfg information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0029   18.8     —
AFFECTED
  Product                          Versions                    Fixed
  IP Network Audio Device XC-9603  1.2.3_20181106 Build 107 –  —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
TaleLin lin-cms-spring-boot book Endpoint BookController.java getBook improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0029   18.8     —
AFFECTED
  Product              Versions  Fixed
  lin-cms-spring-boot  0.2.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
TaleLin lin-cms-spring-boot book Endpoint BookController.java getBooks improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0029   18.8     —
AFFECTED
  Product              Versions  Fixed
  lin-cms-spring-boot  0.2.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0029   18.8     —
AFFECTED
  Product              Versions  Fixed
  lin-cms-spring-boot  0.2.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   N   L    2.1   .0027   17.2     —
AFFECTED
  Product   Versions  Fixed
  mooncake  0.3.0 –   —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 24  Published (CNA: VulDB)
CWE-400, CWE-770 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
ezGlobal|GPM LIGHT - Sensitive Data Exposure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    6.9   .0026   15.9     —
AFFECTED
  Product    Versions  Fixed
  GPM LIGHT  all –     —
TIMELINE
  Sep 24  Reserved by CNA
  Sep 24  Published (CNA: twcert)
CWE-497 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-183355.415.3themeumKirki – Freeform Page Builder, Website Builder & CustomizerCWE-918Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauth…
CVE-2026-968035.515.0java110MicroCommunityCWE-74java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMO…
CVE-2026-157316.414.5magazine3WP Multilang – Translation and Multilingual PluginCWE-79WP Multilang – Translation and Multilingual Plugin <= 2.4.31 - Authenticated …
CVE-2026-967732.114.4IntelliantsSubrion CMSCWE-601Intelliants Subrion CMS Login Page login.php authorize redirect
CVE-2026-967632.114.2kvcache-aimooncakeCWE-266kvcache-ai mooncake MountSegment Request Processing segment.cpp access control
CVE-2026-783098.813.3DeltawwDIAEnergieCWE-89SQL Injection in DIAEnergie
CVE-2026-783118.813.3DeltawwDIAEnergieCWE-89SQL Injection in DIAEnergie
CVE-2026-971776.613.1Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: generic user update bypasses denied res…
CVE-2026-971495.311.8OpenStackSwiftCWE-184In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the …
CVE-2026-783104.310.3DeltawwDIAEnergieCWE-639Authorization Bypass Through User-Controlled Key in DIAEnergie
CVE-2026-805137.59.0UnknownwpForo ForumCWE-502wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields
CVE-2026-967772.18.7FormaLMSCWE-74Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection
CVE-2026-968102.07.7huanzi-qchbase-adminCWE-79huanzi-qch base-admin Add User CommonController.java save cross site scripting
CVE-2026-575908.16.7Apache Software FoundationApache DolphinSchedulerCWE-863Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unau…
CVE-2026-117443.85.4PaperCutPaperCut HiveCWE-79PaperCut Hive Embedded App for Ricoh: Javascript injection
CVE-2026-971764.25.3Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: essential acr requirement silently bypa…
CVE-2026-841513.54.9UnknownThe Post GridCWE-79The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses…
CVE-2026-888437.24.1UnknownMasterStudy LMS WordPress PluginCWE-22MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Ca…
CVE-2026-890026.83.6UnknownWPeMatico RSS Feed FetcherCWE-79WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign It…
CVE-2026-890056.83.6UnknownWPeMatico RSS Feed FetcherCWE-79WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Cat…
CVE-2026-890042.73.2UnknownWPeMatico RSS Feed FetcherCWE-639WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and…
CVE-2026-821956.53.0Unknown10Web BoosterCWE-86210Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Del…
CVE-2026-828504.32.7UnknownMasteriyo LMSCWE-200Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure
CVE-2026-936624.32.7UnknownEvents ManagerCWE-200Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Dis…
CVE-2026-749916.82.5UnknownWPFormsCWE-284WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscripti…
CVE-2026-888465.32.5UnknownMasterStudy LMS WordPress PluginCWE-862MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Regi…
CVE-2026-856828.82.4yourownprogrammerYOP PollCWE-346YOP Poll <= 7.0.10 - Unauthenticated Origin Validation Error to Administrator…
CVE-2026-971857.82.3Red HatRed Hat Enterprise Linux 10CWE-787Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
CVE-2026-803386.82.3UnknownCMB2CWE-862CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler
CVE-2026-828494.32.3UnknownMasteriyo LMSCWE-639Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure…
CVE-2026-888454.32.3UnknownMasterStudy LMS WordPress PluginCWE-862MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via…
CVE-2026-888474.32.3UnknownMasterStudy LMS WordPress PluginCWE-862MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation
CVE-2026-936612.72.3UnknownEvents ManagerCWE-639Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR
CVE-2026-971556.51.3FabasoftFolio ClientCWE-346Fabasoft Folio Client before 2026, a locally installed component that communi…
CVE-2026-816455.90.4HuaweiHarmonyOSCWE-125Out-of-bounds read vulnerability in the graphics module. Successful exploitat…
CVE-2026-6173210.0—BitterSecurityDecepticonCWE-74Decepticon: Role-boundary forgery via ChatML special-token literals in web cr…
CVE-2026-9735910.0—rejettohfs2CWE-1336HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection
CVE-2026-9736010.0—rejettohfs2CWE-862HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine
CVE-2026-190729.9—Rapid7VelociraptorCWE-164Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal
CVE-2026-934259.9—DokploydokployCWE-78Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (rep…
CVE-2026-132499.8—HoneywellPD45 Industrial PrinterCWE-78Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer v…
CVE-2026-932079.8—LinuxLinux—SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-974139.8—LinuxLinux—RDMA/rtrs-srv: Fix integer underflow in process_read and process_write
CVE-2026-815499.6—IBMDataStage on Cloud Pak for DataCWE-918DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-130169.3—ServiceNowServiceNow AI PlatformCWE-89Unauthenticated SQL Injection in ServiceNow AI Platform
CVE-2026-616049.3—ixofoundationixo-blockchainCWE-285ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization …
CVE-2026-617419.3—http4shttp4s-scala-xmlCWE-611http4s-scala-xml has an XML External Entity (XXE) processing issue
CVE-2026-617429.3—bytebasedbhubCWE-306DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL …
CVE-2026-868609.3—ServiceNowServiceNow AI PlatformCWE-862Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform
CVE-2026-911879.3—dashbitnimble_ztaCWE-347Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudf…
CVE-2026-932919.3—EufyOmni C20CWE-295Improper certificate validation in Eufy Omni C20
CVE-2026-816309.2—BotslabG980HCWE-345Botslab G980H Dashcams Insufficient Verification of Data Authenticity
CVE-2026-904819.2—PortSwiggerBurp Suite DASTCWE-288In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) befor…
CVE-2026-974049.2—OpenStackZaqarCWE-348In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature…
CVE-2026-797669.1—Termix-SSHTermixCWE-78Termix: OS command injection in ACME/Let's Encrypt certificate-request handle…
CVE-2026-932289.1—LinuxLinux—svcrdma: Reject Write/Reply chunks with segcount 0
CVE-2026-932899.0—EufyOmni C20CWE-78OS command injection in Eufy Omni C20, Omni X10 Pro
CVE-2026-946068.9—goauthentikauthentikCWE-287authentik: MFA Bypass via State Confusion / Parameter Injection in Authentica…
CVE-2026-132488.8—HoneywellPD45 Industrial PrinterCWE-73Authenticated Remote Code Execution via Arbitrary File Write in the Intermec …
CVE-2026-815398.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-815458.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-815478.8—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-815488.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-815528.8—IBMDataStage on Cloud Pak for DataCWE-78DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-820938.8—IBMDataStage on Cloud Pak for DataCWE-502DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-932808.8—LinuxLinux—greybus: audio: bound the topology section sizes against the fetched size
CVE-2026-932848.8—LinuxLinux—drm/pagemap: dma-unmap pages before handling migration errors
CVE-2026-937908.8—LinuxLinux—wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif
CVE-2026-937938.8—LinuxLinux—wifi: iwlwifi: mvm: validate TX_CMD response layout
CVE-2026-937998.8—LinuxLinux—wifi: iwlwifi: mvm: validate sta_id in BA window status notif
CVE-2026-938068.8—LinuxLinux—wifi: cfg80211: validate assoc response length before status and IE access
CVE-2026-946098.8—goauthentikauthentikCWE-269authentik: Privilege Escalation to Superuser via Group Hierarchy
CVE-2026-970598.8—OFFISDCMTKCWE-125DCMTK through 3.7.0 Heap Over-read via NumberOfFrames
CVE-2026-974098.8—LinuxLinux—nvme-fc: Do not cancel requests in io target before it is initialized
CVE-2026-974428.8—LinuxLinux—wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi
CVE-2026-975098.8—LinuxLinux—thunderbolt: Keep XDomain reference during the lifetime of a service
CVE-2026-567448.7—bsv-blockchain@bsv/wallet-toolboxCWE-1288`@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied r…
CVE-2026-618258.7—code16sharpCWE-79code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
CVE-2026-634988.7—grokabilitysnipe-itCWE-79Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
CVE-2026-825668.7—BotslabG980HCWE-613Botslab G980H Dashcams Insufficient session expiration
CVE-2026-843998.7—BotslabG980HCWE-863Botslab G980H Dashcams Incorrect Authorization
CVE-2026-850578.7—zitadelzitadelCWE-284ZITADEL: Actions V1 sandbox escape: host file read via require()
CVE-2026-868588.7—ServiceNowServiceNow AI PlatformCWE-284Unauthenticated Privilege Escalation via GraphQL in ServiceNow AI Platform
CVE-2026-868598.7—ServiceNowServiceNow AI PlatformCWE-284Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform
CVE-2026-877218.7—GerritGerritCWE-400Denial of Service via Exponential Backtracking in ANTLR Search Query Parser i…
CVE-2026-877228.7—GerritGerritCWE-400Regular Expression Denial of Service (ReDoS) in Search Query Predicates and R…
CVE-2026-911228.7—discoursediscourseCWE-79Discourse: Chat MessageBus delivers read-restricted messages to unauthorized …
CVE-2026-968838.7—AWSpgcollectionCWE-843Type confusion in AWS pgcollection allows remote code execution
CVE-2026-970578.7—NodeRedisredis-parserCWE-1284redis-parser through 3.0.0 Denial of Service via Invalid Array Length
CVE-2026-973628.7—rejettohfs2CWE-835HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread
CVE-2026-634938.6—grokabilitysnipe-itCWE-288Snipe-IT: 2FA bypass via the API token flow
CVE-2026-775818.6—alam00000bentopdfCWE-918BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass
CVE-2026-778748.6—IBMEnterprise Build of QuarkusCWE-89IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
CVE-2026-779678.6—BotslabG980HCWE-294Botslab G980H Dashcams Authentication Bypass by Capture-replay
CVE-2026-814558.6—DellThinOS 10CWE-306Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a M…
CVE-2026-959858.6—AmazonKiro IDECWE-349Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untr…
CVE-2026-965158.6—Netlink ICT Pvt LtdNetlink ICT HG323RW RouterCWE-434Command Injection Vulnerability in Netlink ICT HG323RW Router
CVE-2026-567388.5—thorstenphpMyFAQCWE-89phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
CVE-2026-567398.5—logto-iologtoCWE-918Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint
CVE-2026-823718.5—BrocadeSANnavCWE-532Plaintext exposure of sensitive authentication data in SANnav discovery servi…
CVE-2026-823728.5—BrocadeSANnavCWE-532Improper handling of sensitive data during IPsec policy creation and modifica…
CVE-2026-850828.5—Maple MediaRoot Browser ClassicCWE-78Maple Media Root Browser Classic 3.3.0 - OS command injection through crafted…
CVE-2026-933548.5—Gimanhtaskview-communityCWE-1188Taskview Community Missing Authentication via OAuth Dynamic Client Registration
CVE-2026-144438.4—BrocadeSANnavCWE-532Incomplete log sanitization during bulk IPsec policy collection in Brocade SA…
CVE-2026-868578.4—ServiceNowServiceNow AI Platform—Authorization Bypass in ServiceNow AI Platform
CVE-2026-938278.4—LinuxLinux—virtio-fs: avoid double-free on failed queue setup
CVE-2026-956998.4—MrSteamiSteamX applicationCWE-653MrSteam iSteamX Improper Isolation or Compartmentalization
CVE-2026-974508.4—LinuxLinux—ACPICA: validate handler object type in two places
CVE-2026-974518.4—LinuxLinux—ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)
CVE-2026-974528.4—LinuxLinux—ACPICA: Prevent adding invalid references
CVE-2026-974558.4—LinuxLinux—ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()
CVE-2026-134658.3—AlteraTrusted FirmwareCWE-121EL3 Stack Buffer Overflow in FCS HKDF Request
CVE-2026-134668.3—AlteraTrusted FirmwareCWE-131Unit Confusion in VAB Authentication
CVE-2026-134678.3—AlteraTrusted FirmwareCWE-787Systemic Missing Address Validation in SiP SMC Handlers
CVE-2026-580048.3—AlteraTrusted FirmwareCWE-125Crafted oversized firmware image causes EL3 stack overflow during VAB authent…
CVE-2026-580058.3—AlteraTrusted FirmwareCWE-119Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary …
CVE-2026-580068.3—AlteraTrusted FirmwareCWE-822Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memo…
CVE-2026-580078.3—AlteraTrusted FirmwareCWE-822Unchecked SDM mailbox response address enables EL3 secure-memory corruption
CVE-2026-580088.3—AlteraTrusted FirmwareCWE-121Unchecked HKDF key-size input in EL3 causes a stack buffer overflow
CVE-2026-821578.3—DellThinOS 10CWE-295Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an…
CVE-2026-967468.3—MongoDBC DriverCWE-787Heap buffer overflow via mid-scan command list growth in client topology moni…
CVE-2026-967488.3—MongoDBPython DriverCWE-177Connection redirection via percent-encoded delimiter injection in connection …
CVE-2026-567368.2—thorstenphpMyFAQCWE-79phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Fronten…
CVE-2026-850568.2—zitadelzitadelCWE-287ZITADEL: MFA bypass via session reuse in Login V2
CVE-2026-911608.2—rmyndharisOpenWACWE-862OpenWA: A read-only API key can receive a session pairing QR over the WebSock…
CVE-2026-974338.2—LinuxLinux—nvme: validate FDP configuration descriptor sizes
CVE-2026-567378.1—thorstenphpMyFAQCWE-287phpMyFAQ's two-factor authentication login bypasses the password factor
CVE-2026-623688.1—grokabilitysnipe-itCWE-79Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
CVE-2026-772948.1—mauriceboeTREKCWE-918TREK: Server-Side Request Forgery via User-Configurable LLM Base URL
CVE-2026-814738.1—DellRugged Control Center (RCC)CWE-287Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Impro…
CVE-2026-909598.1—Red HatRed Hat Ansible Automation Platform 2CWE-22Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_ur…
CVE-2026-932218.1—LinuxLinux—nfsd: convert nfsd_net boolean flags to unsigned long flags word
CVE-2026-932248.1—LinuxLinux—svcrdma: Fix unmatched rn_unregister on failed accept
CVE-2026-932828.1—LinuxLinux—ksmbd: fix maximum allowed access checks
CVE-2026-937868.1—LinuxLinux—ksmbd: preserve VFS inherited POSIX ACL mask
CVE-2026-937878.1—LinuxLinux—smb: client: bound dirent name against end of SMB response in cifs_filldir
CVE-2026-946118.1—goauthentikauthentikCWE-200authentik: Stored credentials are readable with view permission alone
CVE-2026-893257.8—Rapid7Insight AgentCWE-427Rapid7 Insight Agent: Uncontrolled search path element in InsightVM assessmen…
CVE-2026-932377.8—LinuxLinux—LoongArch: Add DIRECT_MAP_PHYSMEM_END definition
CVE-2026-932507.8—LinuxLinux—vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()
CVE-2026-932627.8—LinuxLinux—md/raid5-ppl: fix use-after-free in ppl_do_flush()
CVE-2026-932777.8—LinuxLinux—RDMA/bnxt_re: Validate udata before executing commands
CVE-2026-932877.8—LinuxLinux—i2c: smbus: reject oversized block transfers in the common path
CVE-2026-932887.8—LinuxLinux—netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state
CVE-2026-937827.8—LinuxLinux—vhost-scsi: flush backend after device ioctls
CVE-2026-937987.8—LinuxLinux—btrfs: fix reloc root cleanup in merge_reloc_roots()
CVE-2026-938137.8—LinuxLinux—btrfs: tree-checker: validate INODE_REF's namelen
CVE-2026-938177.8—LinuxLinux—perf: Fix addr_filter_ranges lifetime
CVE-2026-955197.8—Red HatRed Hat Enterprise Linux 10CWE-78Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -…
CVE-2026-955217.8—Red HatRed Hat Enterprise Linux 10CWE-78Rpm: rpm: shell command injection via macro expansion of source/spec file bas…
CVE-2026-974157.8—LinuxLinux—btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF
CVE-2026-974217.8—LinuxLinux—RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz()
CVE-2026-974297.8—LinuxLinux—drm/amdkfd: fix UAF race in destroy_queue_cpsch
CVE-2026-974787.8—LinuxLinux—virt: acrn: Fix irqfd use-after-free during eventfd shutdown
CVE-2026-974977.8—LinuxLinux—drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id
CVE-2026-975137.8—LinuxLinux—media: chips-media: wave5: Release m2m_ctx after Instance Removed from List
CVE-2026-797647.7—Termix-SSHTermixCWE-918Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist
CVE-2026-854967.7—BotslabG980HCWE-340Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers
CVE-2026-883907.7—n/an/aCWE-787An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruin…
CVE-2026-932657.7—LinuxLinux—PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node
CVE-2026-974287.7—LinuxLinux—drm/amdgpu: harden FRU PIA parsing with bounded helpers
CVE-2026-974447.7—LinuxLinux—ACPICA: add boundary checks in two places
CVE-2026-974457.7—LinuxLinux—ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()
CVE-2026-974487.7—LinuxLinux—ACPICA: Add validation for node in acpi_ns_build_normalized_path()
CVE-2026-974547.7—LinuxLinux—ACPICA: add boundary checks in acpi_ps_get_next_field()
CVE-2026-632037.6—logto-iologtoCWE-862Logto: Account API can disclose stored third-party provider tokens without th…
CVE-2026-877207.6—GerritGerritCWE-613Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suf…
CVE-2026-71697.5—Evope CollectorEvope Collector—Uncontrolled Search Path Element in Evope Collector
CVE-2026-519957.5—n/an/aCWE-200An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker …
CVE-2026-574407.5—StarCitizenWikimediawiki-extensions-EmbedVideoCWE-79Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgE…
CVE-2026-617827.5—web-infra-devrsdoctorCWE-200@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Sou…
CVE-2026-618167.5—zbatesonmail-mime-parserCWE-400zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory D…
CVE-2026-636457.5—openobserveopenobserveCWE-200OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL data…
CVE-2026-715407.5—wazuhwazuhCWE-770Wazuh Manager cluster header parsing allows pre-authentication memory exhaustion
CVE-2026-759077.5—Norwegian Cruise Linedoor access controlCWE-287CVE-2026-75907
CVE-2026-883577.5—n/an/aCWE-1335nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer…
CVE-2026-883687.5—n/an/aCWE-681NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerabili…
CVE-2026-883727.5—n/an/aCWE-190libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_head…
CVE-2026-883767.5—n/an/aCWE-191Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::C…
CVE-2026-883827.5—n/an/aCWE-770hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocati…
CVE-2026-938267.5—LinuxLinux—HID: hidpp: fix potential UAF in hidpp_connect_event()
CVE-2026-938307.5—LinuxLinux—net: stmmac: xgmac2: disable RBUE in default RX interrupt mask
CVE-2026-946137.5—goauthentikauthentikCWE-770authentik: Denial of Service via Document Type Declarations in SAML Messages
CVE-2026-967497.5—MongoDBPython DriverCWE-190Heap out-of-bounds write via signed size overflow in BSON document encoding
CVE-2026-974177.5—LinuxLinux—netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()
CVE-2026-975087.5—LinuxLinux—thunderbolt: Set tb->root_switch to NULL when domain is stopped
CVE-2026-571787.4—python-social-authsocial-coreCWE-287social-auth-core: VK App backend accepts unsigned callback data when auth_key…
CVE-2026-617887.4—bytebasedbhubCWE-184@bytebase/dbhub's read-only mode does not prevent database writes
CVE-2026-889077.4—TÜBİTAK ULAKBİMUlakPDFCWE-863SAML ePPN Attribute Validation Bypass in TÜBİTAK ULAKBİM's UlakPDF
CVE-2026-932257.4—LinuxLinux—phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
CVE-2026-932607.4—LinuxLinux—powerpc/xive: propagate IPI init errors to prevent use-after-free
CVE-2026-935437.4—x.orglibXiCWE-125Out-of-bounds read in libXi's XI2 class parser
CVE-2026-946127.4—goauthentikauthentikCWE-287authentik: Authentication bypass via assertion confusion in SAML sources
CVE-2026-974747.4—LinuxLinux—wifi: iwlwifi: mld: purge async notifications upon nic error
CVE-2026-125597.3—OpenTextVendor Invoice Management for SAP SolutionsCWE-79Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for S…
CVE-2026-618237.3—code16sharpCWE-79code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
CVE-2026-967507.3—MongoDBCompassCWE-94Shell script injection via server-supplied database name in Open MongoDB shell
CVE-2026-618157.2—zbatesonmail-mime-parserCWE-93zbateson/mail-mime-parser has CRLF header injection via attachment filename
CVE-2026-911237.2—discoursediscourseCWE-22Discourse: Reject literal backslash path separators in iframe src traversal g…
CVE-2026-46387.1—Paessler GmbHPRTG Network MonitorCWE-209Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler P…
CVE-2026-480707.1—docmostdocmostCWE-22Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local…
CVE-2026-772937.1—mauriceboeTREKCWE-639TREK: Cross-user note-file deletion (IDOR / Broken Access Control)
CVE-2026-820947.1—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-821647.1—DellTrusted Device Client,CWE-732Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect…
CVE-2026-825857.1—BotslabG980HCWE-319Botslab G980H Dashcams Cleartext Transmission of Sensitive Information
CVE-2026-827087.1—BotslabG980HCWE-22Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Dire…
CVE-2026-932297.1—LinuxLinux—nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry
CVE-2026-938167.1—LinuxLinux—f2fs: validate inline dentry name lengths before conversion
CVE-2026-967447.1—MongoDBLaravel MongoDB (PHP)CWE-943Unauthorized cache lock takeover via expression injection in lock owner value…
CVE-2026-974377.1—LinuxLinux—ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()
CVE-2026-974387.1—LinuxLinux—fs/ntfs3: validate index entry key bounds
CVE-2026-974967.1—LinuxLinux—drm/amdkfd: Fix OOB memory exposure in get_wave_state()
CVE-2026-975207.1—LinuxLinux—gfs2: move quota_init qc iterator increment
CVE-2026-799597.0—BotslabG980HCWE-798Botslab G980H Dashcams Use of Hard-coded Credentials
CVE-2026-889567.0—BotslabG980HCWE-306Botslab G980H Dashcams Missing Authentication for Critical Function
CVE-2026-937967.0—LinuxLinux—wifi: iwlwifi: pcie: null RX pointers after free
CVE-2026-938017.0—LinuxLinux—smb/client: zero-initialize stack-allocated cifs_open_info_data
CVE-2026-938107.0—LinuxLinux—cachefiles: Fix double fput
CVE-2026-144416.9—BrocadeSANnavCWE-1025Logic flaw in SANnav Java cache key handling object comparison handling
CVE-2026-144426.9—BrocadeSANnavCWE-532Information exposure vulnerability in the job scheduling component of SANnav …
CVE-2026-844036.9—BotslabG980HCWE-306Botslab G980H Dashcams Missing Authentication for Critical Function
CVE-2026-871186.9—BotslabG980HCWE-787Botslab G980H Dashcams Out-of-bounds Write
CVE-2026-970586.9—alexeisprintf-jsCWE-1284sprintf-js through 1.1.3 Denial of Service via Unbounded Precision
CVE-2026-260546.8—sumatrapdfreadersumatrapdfCWE-125SumatraPDF: Heap out-of-bounds read in MOBI header parser.
CVE-2026-571766.8—python-social-authsocial-coreCWE-289social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in …
CVE-2026-842836.8—FluteCodeSecure FolderCWE-922FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass t…
CVE-2026-889166.8—TÜBİTAK ULAKBİMUlakPDFCWE-863Admin Access Bypass via Header Fallback in TÜBİTAK ULAKBİM's UlakPDF
CVE-2026-926806.8—AraxisMergeCWE-522Araxis Merge insufficiently protected credentials
CVE-2026-932906.8—EufyOmni C20CWE-798Use of Hard-coded Credentials in Eufy Omni C20
CVE-2026-944166.8—Red HatRed Hat Ansible Automation Platform 2CWE-290Aap-gateway: aap-gateway: authorization bypass via workload identity token fo…
CVE-2026-797616.6—Termix-SSHTermixCWE-78Termix: Command injection in SSH key deployment verification
CVE-2026-48066.5—alexvtnCustom Thank You Page for WooCommerceCWE-862Custom Thank You Page for WooCommerce <= 1.1.2 - Missing Authorization to Una…
CVE-2026-544616.5—HabitRPGhabiticaCWE-1333Habitica: Regex Injection / ReDoS in Member Search
CVE-2026-618116.5—wazuhwazuhCWE-674Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Work…
CVE-2026-654226.5—Genetec Inc.Genetec Security CenterCWE-862A flaw in the authorization mechanism for Media Gateway API in Genetec Securi…
CVE-2026-658276.5—docmostdocmostCWE-400Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial …
CVE-2026-769076.5—suitenumeriquedocsCWE-200LaSuite Doc: Public Documents Enumeration
CVE-2026-777986.5—Rapid7VelociraptorCWE-833Velociraptor Authenticated Denial of Service
CVE-2026-911336.5—discoursediscourseCWE-943Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure
CVE-2026-935416.5—X.orglibXiCWE-125Out-of-bounds read in libXi's XQueryDeviceState()
CVE-2026-935426.5—x.orglibXiCWE-125Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_c…
CVE-2026-935446.5—x.orglibXiCWE-125Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing
CVE-2026-935456.5—x.orglibXiCWE-125Out-of-bounds read in libXi's XListInputDevices()
CVE-2026-942816.5—x.orglibXiCWE-125Out-of-bounds read in libXi's XListInputDevices() class parsing
CVE-2026-571756.4—python-social-authsocial-coreCWE-287social-auth-core has an Improper Authentication issue
CVE-2026-797606.4—Termix-SSHTermixCWE-918Termix: Authenticated blind SSRF through notification channel test endpoints
CVE-2026-911196.4—discoursediscourseCWE-79Discourse: Encode action_code_who in mention URLs
CVE-2026-911616.4—rmyndharisOpenWACWE-863OpenWA: VIEWER API keys can read WhatsApp group invite codes
CVE-2026-857386.3—liketrekTREKCWE-918TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4)
CVE-2026-967456.3—MongoDBPHP DriverCWE-502PHP object injection via unsuppressible __pclass class inference in command m…
CVE-2026-65446.2—IBMConcertCWE-552Multiple Vulnerabilities in IBM Concert Software
CVE-2026-617846.1—cstiglernode-xhtml-purifierCWE-79xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
CVE-2026-934056.1—Foundry376MailspringCWE-79Mailspring: Stored XSS in attachment quick preview (unsanitized Markdown/DOCX…
CVE-2026-672336.0—rabbitmqrabbitmq-serverCWE-862RabbitMQ: Monitoring-tag user can DELETE shovels
CVE-2026-755586.0—BotslabG980HCWE-321Botslab G980H Dashcams Use of Hard-coded Cryptographic Key
CVE-2026-887616.0—BotslabG980HCWE-1391Botslab G980H Dashcams Use of Weak Credentials
CVE-2026-933536.0—9001copypartyCWE-59copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers
CVE-2026-777035.9—HAVELSAN Inc.Liman Render EngineCWE-322SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine
CVE-2026-777075.9—HAVELSAN Inc.Liman Render EngineCWE-295TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Li…
CVE-2026-797625.5—Termix-SSHTermixCWE-321Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH cr…
CVE-2026-883845.5—n/an/aCWE-476OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsi…
CVE-2026-968735.5—The Wikimedia FoundationMediawiki - CirrusSearch ExtensionCWE-79Reflected XSS in CirrusSearch debug explain output
CVE-2026-971825.5—halo-devHaloCWE-20halo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralization
CVE-2026-972315.5—volotatAnagnorisisCWE-287volotat Anagnorisis Socket.IO Connect app.py missing authentication
CVE-2026-973245.5—YunaiVruoyi-vue-proCWE-266YunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderCo…
CVE-2026-973265.5—songxinjianqweChatCWE-918songxinjianqwe Chat chat-server ChatServer.java server-side request forgery
CVE-2026-471325.4—thorstenphpMyFAQCWE-20phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticate…
CVE-2026-797585.4—Termix-SSHTermixCWE-284Termix: Authenticated users can read other users' host status and clear globa…
CVE-2026-911205.4—discoursediscourseCWE-79Discourse: Stored HTML injection in video notification emails
CVE-2026-911345.4—discoursediscourseCWE-20Discourse: Block post iframes whose encoded userinfo bypasses the allowed_ifr…
CVE-2026-195325.3—HAVELSAN Inc.Liman MYSCWE-22Path Traversal in HAVELSAN's Liman MYS
CVE-2026-480725.3—docmostdocmostCWE-22Docmost: Public image fileName path traversal leads to unauthorized local fil…
CVE-2026-773205.3—mauriceboeTREKCWE-200TREK: Public trip share link ignores the `share_map` permission server-side (…
CVE-2026-797635.3—Termix-SSHTermixCWE-308Termix: MFA-critical operations accept the account password as a sole factor …
CVE-2026-967475.3—MongoDBPython DriverCWE-918Forced local Unix socket connection via dot-sock KMS endpoint in client-side …
CVE-2026-970615.3—blackcandy-orgBlack CandyCWE-862Black Candy through 3.2.1 Information Disclosure via Playlist Search
CVE-2026-972255.3—n/aDbGateCWE-74DbGate JSON Runner runners.js code injection
CVE-2026-972265.3—n/aDbGateCWE-22DbGate files-style Endpoint files.js fs.readFile path traversal
CVE-2026-528535.2—docmostdocmostCWE-269Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER
CVE-2026-46375.1—Paessler GmbHPRTG Network MonitorCWE-79Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor
CVE-2026-174135.1—IBMPowerVM HypervisorCWE-129This Power System update is being released to address
CVE-2026-175035.1—IBMPowerVM HypervisorCWE-20This Power System update is being released to address
CVE-2026-175045.1—IBMPowerVM HypervisorCWE-191This Power System update is being released to address
CVE-2026-485405.1—krayinlaravel-crmCWE-79Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title
CVE-2026-485415.1—krayinlaravel-crmCWE-79Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field
CVE-2026-485425.1—krayinlaravel-crmCWE-79Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field
CVE-2026-485435.1—krayinlaravel-crmCWE-79Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description
CVE-2026-827165.1—BotslabG980HCWE-532Botslab G980H Dashcams Insertion of Sensitive Information into Log File
CVE-2026-970625.1—WebkulAureus ERPCWE-79Aureus ERP through 1.6.0 Stored XSS via SVG File Upload
CVE-2026-911215.0—discoursediscourseCWE-79Discourse: Chat upload filenames rendered as raw HTML in excerpts
CVE-2026-778254.9—IBMContextForge MCP GatewayCWE-22IBM ContextForge MCP Gateway is affected by path traversal
CVE-2026-796804.5—qtqtCWE-288Authentication bypass vulnerability in the password authentication mechanism …
CVE-2026-567924.4—DellRugged Control Center (RCC)CWE-287Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Impro…
CVE-2025-320004.3—HCL SoftwareHCL SametimeCWE-20Insufficient Input Sanitization is addressed in HCL Sametime 12.0.4. It is re…
CVE-2026-32534.3—mailerliteMailerLite – Signup forms (official)CWE-862MailerLite – Signup forms (official) <= 1.7.21 - Missing Authorization to Aut…
CVE-2026-163024.3—brainstormforceSpectra Legacy – Gutenberg BlocksCWE-200Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Se…
CVE-2026-188704.3—IBMPowerVM HypervisorCWE-125This Power System update is being released to address
CVE-2026-480734.3—docmostdocmostCWE-639Docmost: Page export can include restricted same-space attachments through fo…
CVE-2026-528504.3—docmostdocmostCWE-639Docmost: Broken access control in transclusion lookup API leaks sync-block co…
CVE-2026-571774.3—python-social-authsocial-coreCWE-352social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Ba…
CVE-2026-622864.3—amir20dozzleCWE-200Dozzle label filters do not restrict container event and statistics streams
CVE-2026-773214.3—mauriceboeTREKCWE-200TREK MCP trip summary bypasses delegated OAuth read scopes
CVE-2026-797594.3—Termix-SSHTermixCWE-639Termix: Cross-User Information Disclosure via Missing Ownership Check in depl…
CVE-2026-815084.3—espressifesp-idfCWE-125ESF-IDF: Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing
CVE-2026-911324.3—discoursediscourseCWE-346Discourse: Wildcard iframe origin allowlist bypass via authority separators
CVE-2026-973114.3—Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: admin rest api role-groups endpoint dis…
CVE-2026-571794.2—python-social-authsocial-coreCWE-384social-auth-core has a Session Fixation issue
CVE-2026-843024.2—discoursediscourseCWE-862Discourse: Non-participant moderators can read, edit, and delete PM content t…
CVE-2026-777973.6—Rapid7VelociraptorCWE-20Velociraptor Prefetch parser out of bounds
CVE-2026-175113.4—IBMPowerVM HypervisorCWE-212This Power System update is being released to address
CVE-2026-188573.4—IBMOPENBMCCWE-125This Power System update is being released to address
CVE-2026-636303.4—alam00000bentopdfCWE-201BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfi…
CVE-2026-181043.3—IBMDb2 Mirror for iCWE-327IBM Db2 Mirror for i is vulnerable to obtain sensitive information []
CVE-2026-194923.2—IBMPowerVM HypervisorCWE-457This Power System update is being released to address
CVE-2026-730642.9—trustedfirmwareMbed TLSCWE-394In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can c…
CVE-2026-971792.1—n/aO2OACWE-200O2OA Cipher Connection CipherConnectionAction.java list information disclosure
CVE-2026-972242.1—n/aExcalidrawCWE-79Excalidraw Imported File restore.ts cross site scripting
CVE-2026-972322.1—volotatAnagnorisisCWE-22volotat Anagnorisis page.html start_streaming path traversal
CVE-2026-973202.1—YunaiVruoyi-vue-proCWE-918YunaiV/zhijiantianya ruoyi-vue-pro AI Knowledge AiKnowledgeDocumentServiceImp…
CVE-2026-973212.1—YunaiVruoyi-vue-proCWE-74YunaiV/zhijiantianya ruoyi-vue-pro GoView Data Endpoint GoViewDataServiceImpl…
CVE-2026-973222.1—YunaiVruoyi-vue-proCWE-79YunaiV/zhijiantianya ruoyi-vue-pro File Upload FileController.java cross site…
CVE-2026-973232.1—YunaiVruoyi-vue-proCWE-22YunaiV/zhijiantianya ruoyi-vue-pro File Upload MpMaterialServiceImpl.java get…
CVE-2026-973252.1—YunaiVruoyi-vue-proCWE-601YunaiV/zhijiantianya ruoyi-vue-pro OAuth2 Client OAuth2ClientServiceImpl.java…
CVE-2026-973652.1—chonkie-inclittrsCWE-22chonkie-inc littrs lib.rs mount path traversal
CVE-2026-973662.1—jhen0409react-native-debuggerCWE-77jhen0409 react-native-debugger Open in Editor window.js openDevTools os comma…
CVE-2026-973682.1—chillzhuangSpringBladeCWE-285chillzhuang SpringBlade user-auth-info Endpoint UserServiceImpl.java UserServ…
CVE-2026-972332.0—volotatAnagnorisisCWE-79volotat Anagnorisis Media Filename PlaylistManager.js html cross site scripting
CVE-2026-51994await—n/an/a—mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Reque…
CVE-2026-51996await—n/an/a—An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker …
CVE-2026-51997await—n/an/a—An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker …
CVE-2026-52001await—n/an/a—An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker …
CVE-2026-85491await——Catalyst-SealCWE-706Catalyst::Seal versions before 0.03 for Perl allow one request to disable a p…
CVE-2026-88351await—n/an/a—An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1…
CVE-2026-88355await—n/an/a—An incorrect buffer size calculation vulnerability exists in tinyexpr commit …
CVE-2026-88358await—n/an/a—simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::p…
CVE-2026-88359await—n/an/a—libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_form…
CVE-2026-88360await—n/an/a—libvips 8.19.0 contains a memory access vulnerability when processing little-…
CVE-2026-88361await—n/an/a—SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::B…
CVE-2026-88362await—n/an/a—MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_…
CVE-2026-88365await—n/an/a—minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_…
CVE-2026-88366await—n/an/a—NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerabili…
CVE-2026-88367await—n/an/a—NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in n…
CVE-2026-88369await—n/an/a—zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondu…
CVE-2026-88370await—n/an/a—libconfini 1.16.4 contains a heap out-of-bounds write condition involving the…
CVE-2026-88371await—n/an/a—ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code…
CVE-2026-88373await—n/an/a—libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in …
CVE-2026-88377await—n/an/a—Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hv…
CVE-2026-88378await—n/an/a—QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_…
CVE-2026-88383await—n/an/a—libical 4.0.6 contains an incompatible function pointer in icalparameter_stri…
CVE-2026-88385await—n/an/a—Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() durin…
CVE-2026-88386await—n/an/a—libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_r…
CVE-2026-88387await—n/an/a—LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRa…
CVE-2026-88388await—n/an/a—Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnera…
CVE-2026-93205await—LinuxLinux—iommu/arm-smmu-v3: Manage teardown with devm
CVE-2026-93206await—LinuxLinux—PCI/proc: Use file_ns_capable() when checking config space read access
CVE-2026-93208await—LinuxLinux—kasan: fix cache shrink race with CPU hotplug
CVE-2026-93209await—LinuxLinux—Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
CVE-2026-93210await—LinuxLinux—smb: client: harden DFS cache against invalid target hints
CVE-2026-93211await—LinuxLinux—nfsd: initialize DRC hash table before registering shrinker
CVE-2026-93212await—LinuxLinux—nfsd: guard nfsd_serv deref in nfsd_file_net_dispose
CVE-2026-93213await—LinuxLinux—of: fix out-of-bounds read in of_alias_scan() stem parser
CVE-2026-93214await—LinuxLinux—usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()
CVE-2026-93215await—LinuxLinux—cdx: Fix double free when sysfs file creation fails
CVE-2026-93216await—LinuxLinux—mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_me…
CVE-2026-93217await—LinuxLinux—mm/madvise: skip device-private PMDs in cold and pageout walks
CVE-2026-93218await—LinuxLinux—mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd
CVE-2026-93219await—LinuxLinux—clocksource/drivers/timer-sun4i: Advertise a real minimum delta
CVE-2026-93220await—LinuxLinux—sched_ext: Keep kick_sync waiting on the rq's own CPU
CVE-2026-93222await—LinuxLinux—signal: avoid shared siginfo namespace rewrites
CVE-2026-93223await—LinuxLinux—staging: media: tegra-video: fix of_node_put() on VIP parse errors
CVE-2026-93226await—LinuxLinux—ipv6: use RCU iterator to dump route exceptions
CVE-2026-93227await—LinuxLinux—mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn
CVE-2026-93230await—LinuxLinux—mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier
CVE-2026-93231await—LinuxLinux—lockd: fix swapped arguments in nlmsvc_match_ip()
CVE-2026-93232await—LinuxLinux—mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages

Results continue: ranks 401–553.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-24 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.