AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N L 5.3 .0235 83.0 —
AFFECTED Product Versions Fixed ManageEngine EventLog Analyzer unspecified — ManageEngine Log360 unspecified —
TIMELINE Sep 17 Reserved by CNA Sep 24 Published (CNA: Zohocorp)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 2 to KEV; 553 CVEs published, led by Linux (234).
553 CVEs published September 24, 2026: 28 critical, 174 high, 120 medium, 30 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 201 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 153 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 12306 | 47287 | — | — |
| KEV catalog size | 1723 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3066 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 1741 | 5832 | 529 | 2571 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0020 | +325 ▲ |
| microsoft | 1001 | 2900 | 206 | 1987 | 691 | 16 | 289 | 30 | 1.0 | 7.8 | .0047 | +532 ▲ |
| 517 | 2685 | 332 | 1049 | 1183 | 121 | 80 | 9 | 0.3 | 7.5 | .0027 | +444 ▲ | |
| red hat | 230 | 859 | 52 | 358 | 403 | 46 | 2 | 0 | 0.0 | 6.7 | .0037 | +33 ▲ |
| apple | 246 | 563 | 67 | 165 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0019 | +206 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -23 ▼ |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0019 | -15 ▼ |
| suse | 13 | 41 | 7 | 21 | 12 | 1 | 0 | 0 | 0.0 | 7.5 | .0039 | +8 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0046 | +51 ▲ |
| ubiquiti | 6 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | +6 ▲ |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 11 | 41 | 11 | 10 | 17 | 3 | 29 | 7 | 17.1 | 7.2 | .0040 | +4 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | -7 ▼ |
| f5 | 9 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | +9 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 131 | 643 | 147 | 272 | 206 | 16 | 33 | 2 | 0.3 | 7.5 | .0064 | -9 ▼ |
| mozilla | 113 | 301 | 102 | 126 | 73 | 0 | 9 | 0 | 0.0 | 8.8 | .0034 | +54 ▲ |
| gitlab | 24 | 100 | 7 | 24 | 58 | 11 | 5 | 3 | 3.0 | 5.3 | .0034 | +8 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | +26 ▲ |
| github | 6 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | +1 ▲ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | +1 ▲ |
| wordpress | 1 | 6 | 1 | 4 | 1 | 0 | 2 | 2 | 33.3 | 8.7 | .0189 | -1 ▼ |
| go | 4 | 4 | 0 | 2 | 1 | 1 | 0 | 0 | 0.0 | 5.9 | .0034 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | -255 ▼ |
| ibm | 390 | 1009 | 196 | 460 | 335 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | +16 ▲ |
| adobe | 224 | 830 | 82 | 362 | 376 | 10 | 21 | 5 | 0.6 | 7.5 | .0036 | +164 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0046 | -16 ▼ |
| zohocorp | 27 | 37 | 6 | 24 | 7 | 0 | 0 | 0 | 0.0 | 8.1 | .0113 | +23 ▲ |
| solarwinds | 3 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | +3 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | -10 ▼ |
| servicenow | 5 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0143 | +5 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 27 | 72 | 22 | 26 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0192 | +11 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -4 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | +18 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0038 | +3 ▲ |
| abb | 2 | 9 | 1 | 5 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 195 | 366 | 31 | 170 | 143 | 22 | 2 | 1 | 0.3 | 7.2 | .0030 | +137 ▲ |
| sourcecodester | 63 | 232 | 0 | 0 | 138 | 94 | 0 | 0 | 0.0 | 5.5 | .0043 | +16 ▲ |
| nvidia | 51 | 185 | 21 | 127 | 37 | 0 | 0 | 0 | 0.0 | 7.8 | .0040 | +27 ▲ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | -6 ▼ |
| mongodb | 71 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0039 | +39 ▲ |
| itsourcecode | 37 | 153 | 0 | 0 | 37 | 116 | 0 | 0 | 0.0 | 2.1 | .0033 | +9 ▲ |
| hewlett packard enterprise (hpe) | 139 | 148 | 17 | 77 | 48 | 6 | 1 | 1 | 0.7 | 7.2 | .0044 | +136 ▲ |
| wwbn | 106 | 146 | 23 | 49 | 74 | 0 | 0 | 0 | 0.0 | 6.9 | .0036 | +97 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-60004 | .2399 | 97.8 | 9.8 |
| CVE-2026-82329 | .1412 | 96.4 | 9.8 |
| CVE-2026-76460 | .1403 | 96.4 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-83549 | .1076 | 95.7 | 7.8 |
| CVE-2026-85706 | .0929 | 95.2 | 10.0 |
| CVE-2026-19632 | .0896 | 95.1 | 9.8 |
| CVE-2026-83548 | .0876 | 95.0 | 10.0 |
| CVE-2026-79756 | .0752 | 94.3 | 8.7 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-85706 | 10.0 | .0929 | KEV |
| CVE-2026-83548 | 10.0 | .0876 | KEV |
| CVE-2026-18885 | 10.0 | .0724 | |
| CVE-2026-18886 | 10.0 | .0504 | |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-82222 | 10.0 | .0225 |
| Vendor | CVEs |
|---|---|
| linux | 1969 |
| microsoft | 1009 |
| oracle | 635 |
| 519 | |
| ibm | 406 |
| red hat | 251 |
| apple | 246 |
| adobe | 227 |
| dell | 209 |
| apache | 145 |
| Vendor | KEV |
|---|---|
| microsoft | 30 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 89 |
| Packagist | 16 |
| npm | 15 |
| PyPI | 13 |
| crates.io | 8 |
| RubyGems | 2 |
| Go | 1 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE-2026-81578 | PaperCut | 3 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1772 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1772 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1772 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1772 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1772 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1772 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1772 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1772 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1772 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1772 |
ADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026.
ADDED TO KEV — CVE-2026-71362 (Adobe Commerce). Remediation due September 27, 2026.
EXPLOIT PUBLISHED — FreeRDP: 15 CVEs (CVE-2026-55194, CVE-2026-63633, CVE-2026-91945, CVE-2026-91949, CVE-2026-91950, CVE-2026-91951, CVE-2026-91952, CVE-2026-91953, CVE-2026-91954, CVE-2026-91955, CVE-2026-91956, CVE-2026-91957, CVE-2026-91958, CVE-2026-91959, CVE-2026-91960). Public exploit references added.
EXPLOIT PUBLISHED — moxi624 MoguBlog: 6 CVEs (CVE-2026-89260, CVE-2026-89261, CVE-2026-89262, CVE-2026-89263, CVE-2026-89264, CVE-2026-89265). Public exploit references added.
EXPLOIT PUBLISHED — rocq-prover rocq: 5 CVEs (CVE-2020-37268, CVE-2026-72703, CVE-2026-72704, CVE-2026-72705, CVE-2026-72714). Public exploit references added.
EXPLOIT PUBLISHED — cjbi admin3: 4 CVEs (CVE-2026-92918, CVE-2026-92919, CVE-2026-92920, CVE-2026-92921). Public exploit references added.
EXPLOIT PUBLISHED — MaxSite CMS: 4 CVEs (CVE-2026-87927, CVE-2026-87928, CVE-2026-87929, CVE-2026-87930). Public exploit references added.
EXPLOIT PUBLISHED — 201206030 novel-plus: 3 CVEs (CVE-2026-90939, CVE-2026-90940, CVE-2026-90941). Public exploit references added.
EXPLOIT PUBLISHED — elixir-tesla tesla: 3 CVEs (CVE-2026-48594, CVE-2026-48595, CVE-2026-48596). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2016-20096 (Kunshi Network Technology Co., Ltd. Linknat VOS3000). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-0108 (Palo Alto Networks Cloud NGFW). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-30066 (tj-actions changed-files). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4637 (Paessler GmbH PRTG Network Monitor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-54460 (open-reception appointment-booking-software). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-56812 (phoenixframework phoenix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57851 (Micro-Star International (MSI) KernCoreLib64.sys). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63635 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67549 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-70619 (odysseus-dev odysseus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-72777 (DayuanJiang next-ai-draw-io). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-77525 (1Panel-dev MaxKB). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82280 (QuivrHQ quivr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84810 (claude-world claude-skill-antivirus). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86175 (netbox-community netbox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86176 (netbox-community netbox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86177 (pterodactyl panel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86178 (pixelfed). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90942 (casdoor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91143 (snail007 goproxy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91752 (GNU libextractor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91993 (dromara Jpom). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91994 (semaphoreui semaphore). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91995 (pig-mesh pig). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91996 (dromara lamp-cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91997 (evolution-foundation evolution-api). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-91998 (casdoor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93972 (SourceCodester Online Reviewer Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93977 (code-projects Assessment Management). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94003 (Comfast CF-N1-S). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94030 (SerenityOS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94035 (SourceCodester Drug Recommendation System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94040 (vas3k TaxHacker). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94045 (newbee-ltd newbee-mall). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94092 (dmlc dgl). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94097 (Netcore NBR200V2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94102 (WuzhiCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94144 (drogonframework drogon). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94150 (Omega Solution HRM OS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94214 (ST Engineering iDirect Evolution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94411 (jishenghua jshERP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94426 (xuxueli xxl-job). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94493 (Gigatech PDV5701). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94495 (jishenghua jshERP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94532 (dromara lamp-cloud). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94540 (MrPear DesktopSMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96551 (sfturing hosp_order). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96552 (sfturing hosp_order). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96556 (Neethuharii CafeManagement). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96601 (Abdurrab5 online-makeup-store). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96603 (Abdurrab5 online-makeup-store). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96604 (SoftNews Media Group DataLife Engine). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96676 (Fast FAC1900R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96680 (ByteDance Coze Scraper Extension). Public exploit reference added.
DUE DATE PASSED — CVE-2026-87491 (Google Chrome). CISA remediation deadline was September 23, 2026; still in catalog.
RESCORED — Exim: 3 CVEs (CVE-2026-94054, CVE-2026-94055, CVE-2026-94057). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2008-4128. CVSS 4.3 → 8.1 (NVD).
RESCORED — CVE-2025-48384 (git). CVSS 8.1 → 8 (NVD).
RESCORED — CVE-2026-11538 (IBM WebSphere Application Server). CVSS 3.7 → 5.3 (NVD).
RESCORED — CVE-2026-69553 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD).
RESCORED — CVE-2026-70570 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.1 (NVD).
RESCORED — CVE-2026-70575 (Microsoft Windows 11 version 23H2). CVSS 5.3 → 6.5 (NVD).
RESCORED — CVE-2026-88097 (Microsoft Edge (Chromium-based)). CVSS 8.1 → 7.8 (NVD).
RESCORED — CVE-2026-96739 (SEMCMS). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-96751 (pmTicket Project-Management-Software). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-96762 (kvcache-ai mooncake). CVSS 6.9 → 5.5 (NVD).
PATCH SHIPPED — CVE-2026-78225 (Wärtsilä FOS-Onboard). Fixed in FOS-Onboard 5.08.4052.01.
PATCH SHIPPED — CVE-2026-81855 (Wärtsilä FOS-Onboard). Fixed in FOS-Onboard 5.08.4052.01.
PATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4.
PATCH SHIPPED — CVE-2026-96512 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.9.17-16.p2.2.hum1.
How to read these box scores · glossary
553 CVEs published. 25 box scores and 375 table rows below; the remaining 153 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N L 5.3 .0235 83.0 —
AFFECTED Product Versions Fixed ManageEngine EventLog Analyzer unspecified — ManageEngine Log360 unspecified —
TIMELINE Sep 17 Reserved by CNA Sep 24 Published (CNA: Zohocorp)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 53.6 —
AFFECTED Product Versions Fixed Visual Composer Website Builder unspecified —
TIMELINE Jun 14 Reserved by CNA Sep 24 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0074 52.5 —
AFFECTED Product Versions Fixed PaperCut NG/MF unspecified —
TIMELINE Aug 28 Reserved by CNA Sep 24 Published (CNA: PaperCut)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0065 49.1 —
AFFECTED Product Versions Fixed DIR-825 3.00b32 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0046 37.4 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Sep 24 Published (CNA: Deltaww)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0042 34.0 —
AFFECTED Product Versions Fixed ShopXO 2.2.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0041 32.1 —
AFFECTED Product Versions Fixed signoz 0.8.0 – 0.143.0
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0039 30.5 —
AFFECTED Product Versions Fixed Paytium: Mollie payment forms & donations unspecified —
TIMELINE Jul 31 Reserved by CNA Sep 24 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0038 29.0 —
AFFECTED Product Versions Fixed PaperCut NG/MF unspecified —
TIMELINE Sep 9 Reserved by CNA Sep 24 Published (CNA: PaperCut)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0036 27.5 —
AFFECTED Product Versions Fixed eesy_ID2WP – Publish InDesign HTML5 unspecified —
TIMELINE Aug 20 Reserved by CNA Sep 24 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H L H 8.4 .0036 26.5 —
AFFECTED Product Versions Fixed mammoth.js unspecified —
TIMELINE Sep 24 Reserved by CNA Sep 24 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P L N H H N 7.6 .0035 25.8 —
AFFECTED Product Versions Fixed signoz 0.98.0 – 0.143.0
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0035 25.3 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Sep 24 Published (CNA: Deltaww)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0034 25.2 —
AFFECTED Product Versions Fixed DIAEnergie unspecified —
TIMELINE Aug 24 Reserved by CNA Sep 24 Published (CNA: Deltaww)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N L N 2.1 .0034 24.2 —
AFFECTED Product Versions Fixed BR-6428nC 1.16 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P L L L 2.1 .0034 24.1 —
AFFECTED Product Versions Fixed MantisZip 0.4.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 8.6 .0031 21.5 —
AFFECTED Product Versions Fixed Nanomsg 0.5.0 – —
TIMELINE Sep 24 Reserved by CNA Sep 24 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P H N H H H 7.5 .0031 21.3 —
AFFECTED Product Versions Fixed PaperCut NG/MF unspecified —
TIMELINE Jul 5 Reserved by CNA Sep 24 Published (CNA: PaperCut)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0029 19.4 —
AFFECTED Product Versions Fixed Subrion CMS 4.2.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0029 18.8 —
AFFECTED Product Versions Fixed IP Network Audio Device XC-9603 1.2.3_20181106 Build 107 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0029 18.8 —
AFFECTED Product Versions Fixed lin-cms-spring-boot 0.2.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0029 18.8 —
AFFECTED Product Versions Fixed lin-cms-spring-boot 0.2.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0029 18.8 —
AFFECTED Product Versions Fixed lin-cms-spring-boot 0.2.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N N L 2.1 .0027 17.2 —
AFFECTED Product Versions Fixed mooncake 0.3.0 – —
TIMELINE Sep 23 Reserved by CNA Sep 24 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 6.9 .0026 15.9 —
AFFECTED Product Versions Fixed GPM LIGHT all – —
TIMELINE Sep 24 Reserved by CNA Sep 24 Published (CNA: twcert)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-18335 | 5.4 | 15.3 | themeum | Kirki – Freeform Page Builder, Website Builder & Customizer | CWE-918 | Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauth… |
| CVE-2026-96803 | 5.5 | 15.0 | java110 | MicroCommunity | CWE-74 | java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMO… |
| CVE-2026-15731 | 6.4 | 14.5 | magazine3 | WP Multilang – Translation and Multilingual Plugin | CWE-79 | WP Multilang – Translation and Multilingual Plugin <= 2.4.31 - Authenticated … |
| CVE-2026-96773 | 2.1 | 14.4 | Intelliants | Subrion CMS | CWE-601 | Intelliants Subrion CMS Login Page login.php authorize redirect |
| CVE-2026-96763 | 2.1 | 14.2 | kvcache-ai | mooncake | CWE-266 | kvcache-ai mooncake MountSegment Request Processing segment.cpp access control |
| CVE-2026-78309 | 8.8 | 13.3 | Deltaww | DIAEnergie | CWE-89 | SQL Injection in DIAEnergie |
| CVE-2026-78311 | 8.8 | 13.3 | Deltaww | DIAEnergie | CWE-89 | SQL Injection in DIAEnergie |
| CVE-2026-97177 | 6.6 | 13.1 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: generic user update bypasses denied res… |
| CVE-2026-97149 | 5.3 | 11.8 | OpenStack | Swift | CWE-184 | In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the … |
| CVE-2026-78310 | 4.3 | 10.3 | Deltaww | DIAEnergie | CWE-639 | Authorization Bypass Through User-Controlled Key in DIAEnergie |
| CVE-2026-80513 | 7.5 | 9.0 | Unknown | wpForo Forum | CWE-502 | wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields |
| CVE-2026-96777 | 2.1 | 8.7 | Forma | LMS | CWE-74 | Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection |
| CVE-2026-96810 | 2.0 | 7.7 | huanzi-qch | base-admin | CWE-79 | huanzi-qch base-admin Add User CommonController.java save cross site scripting |
| CVE-2026-57590 | 8.1 | 6.7 | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unau… |
| CVE-2026-11744 | 3.8 | 5.4 | PaperCut | PaperCut Hive | CWE-79 | PaperCut Hive Embedded App for Ricoh: Javascript injection |
| CVE-2026-97176 | 4.2 | 5.3 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: essential acr requirement silently bypa… |
| CVE-2026-84151 | 3.5 | 4.9 | Unknown | The Post Grid | CWE-79 | The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses… |
| CVE-2026-88843 | 7.2 | 4.1 | Unknown | MasterStudy LMS WordPress Plugin | CWE-22 | MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Ca… |
| CVE-2026-89002 | 6.8 | 3.6 | Unknown | WPeMatico RSS Feed Fetcher | CWE-79 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign It… |
| CVE-2026-89005 | 6.8 | 3.6 | Unknown | WPeMatico RSS Feed Fetcher | CWE-79 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Cat… |
| CVE-2026-89004 | 2.7 | 3.2 | Unknown | WPeMatico RSS Feed Fetcher | CWE-639 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and… |
| CVE-2026-82195 | 6.5 | 3.0 | Unknown | 10Web Booster | CWE-862 | 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Del… |
| CVE-2026-82850 | 4.3 | 2.7 | Unknown | Masteriyo LMS | CWE-200 | Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure |
| CVE-2026-93662 | 4.3 | 2.7 | Unknown | Events Manager | CWE-200 | Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Dis… |
| CVE-2026-74991 | 6.8 | 2.5 | Unknown | WPForms | CWE-284 | WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscripti… |
| CVE-2026-88846 | 5.3 | 2.5 | Unknown | MasterStudy LMS WordPress Plugin | CWE-862 | MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Regi… |
| CVE-2026-85682 | 8.8 | 2.4 | yourownprogrammer | YOP Poll | CWE-346 | YOP Poll <= 7.0.10 - Unauthenticated Origin Validation Error to Administrator… |
| CVE-2026-97185 | 7.8 | 2.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file |
| CVE-2026-80338 | 6.8 | 2.3 | Unknown | CMB2 | CWE-862 | CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler |
| CVE-2026-82849 | 4.3 | 2.3 | Unknown | Masteriyo LMS | CWE-639 | Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure… |
| CVE-2026-88845 | 4.3 | 2.3 | Unknown | MasterStudy LMS WordPress Plugin | CWE-862 | MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via… |
| CVE-2026-88847 | 4.3 | 2.3 | Unknown | MasterStudy LMS WordPress Plugin | CWE-862 | MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation |
| CVE-2026-93661 | 2.7 | 2.3 | Unknown | Events Manager | CWE-639 | Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR |
| CVE-2026-97155 | 6.5 | 1.3 | Fabasoft | Folio Client | CWE-346 | Fabasoft Folio Client before 2026, a locally installed component that communi… |
| CVE-2026-81645 | 5.9 | 0.4 | Huawei | HarmonyOS | CWE-125 | Out-of-bounds read vulnerability in the graphics module. Successful exploitat… |
| CVE-2026-61732 | 10.0 | — | BitterSecurity | Decepticon | CWE-74 | Decepticon: Role-boundary forgery via ChatML special-token literals in web cr… |
| CVE-2026-97359 | 10.0 | — | rejetto | hfs2 | CWE-1336 | HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection |
| CVE-2026-97360 | 10.0 | — | rejetto | hfs2 | CWE-862 | HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine |
| CVE-2026-19072 | 9.9 | — | Rapid7 | Velociraptor | CWE-164 | Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal |
| CVE-2026-93425 | 9.9 | — | Dokploy | dokploy | CWE-78 | Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (rep… |
| CVE-2026-13249 | 9.8 | — | Honeywell | PD45 Industrial Printer | CWE-78 | Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer v… |
| CVE-2026-93207 | 9.8 | — | Linux | Linux | — | SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry |
| CVE-2026-97413 | 9.8 | — | Linux | Linux | — | RDMA/rtrs-srv: Fix integer underflow in process_read and process_write |
| CVE-2026-81549 | 9.6 | — | IBM | DataStage on Cloud Pak for Data | CWE-918 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-13016 | 9.3 | — | ServiceNow | ServiceNow AI Platform | CWE-89 | Unauthenticated SQL Injection in ServiceNow AI Platform |
| CVE-2026-61604 | 9.3 | — | ixofoundation | ixo-blockchain | CWE-285 | ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization … |
| CVE-2026-61741 | 9.3 | — | http4s | http4s-scala-xml | CWE-611 | http4s-scala-xml has an XML External Entity (XXE) processing issue |
| CVE-2026-61742 | 9.3 | — | bytebase | dbhub | CWE-306 | DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL … |
| CVE-2026-86860 | 9.3 | — | ServiceNow | ServiceNow AI Platform | CWE-862 | Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform |
| CVE-2026-91187 | 9.3 | — | dashbit | nimble_zta | CWE-347 | Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudf… |
| CVE-2026-93291 | 9.3 | — | Eufy | Omni C20 | CWE-295 | Improper certificate validation in Eufy Omni C20 |
| CVE-2026-81630 | 9.2 | — | Botslab | G980H | CWE-345 | Botslab G980H Dashcams Insufficient Verification of Data Authenticity |
| CVE-2026-90481 | 9.2 | — | PortSwigger | Burp Suite DAST | CWE-288 | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) befor… |
| CVE-2026-97404 | 9.2 | — | OpenStack | Zaqar | CWE-348 | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature… |
| CVE-2026-79766 | 9.1 | — | Termix-SSH | Termix | CWE-78 | Termix: OS command injection in ACME/Let's Encrypt certificate-request handle… |
| CVE-2026-93228 | 9.1 | — | Linux | Linux | — | svcrdma: Reject Write/Reply chunks with segcount 0 |
| CVE-2026-93289 | 9.0 | — | Eufy | Omni C20 | CWE-78 | OS command injection in Eufy Omni C20, Omni X10 Pro |
| CVE-2026-94606 | 8.9 | — | goauthentik | authentik | CWE-287 | authentik: MFA Bypass via State Confusion / Parameter Injection in Authentica… |
| CVE-2026-13248 | 8.8 | — | Honeywell | PD45 Industrial Printer | CWE-73 | Authenticated Remote Code Execution via Arbitrary File Write in the Intermec … |
| CVE-2026-81539 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81545 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81547 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-22 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81548 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81552 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-78 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-82093 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-502 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-93280 | 8.8 | — | Linux | Linux | — | greybus: audio: bound the topology section sizes against the fetched size |
| CVE-2026-93284 | 8.8 | — | Linux | Linux | — | drm/pagemap: dma-unmap pages before handling migration errors |
| CVE-2026-93790 | 8.8 | — | Linux | Linux | — | wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif |
| CVE-2026-93793 | 8.8 | — | Linux | Linux | — | wifi: iwlwifi: mvm: validate TX_CMD response layout |
| CVE-2026-93799 | 8.8 | — | Linux | Linux | — | wifi: iwlwifi: mvm: validate sta_id in BA window status notif |
| CVE-2026-93806 | 8.8 | — | Linux | Linux | — | wifi: cfg80211: validate assoc response length before status and IE access |
| CVE-2026-94609 | 8.8 | — | goauthentik | authentik | CWE-269 | authentik: Privilege Escalation to Superuser via Group Hierarchy |
| CVE-2026-97059 | 8.8 | — | OFFIS | DCMTK | CWE-125 | DCMTK through 3.7.0 Heap Over-read via NumberOfFrames |
| CVE-2026-97409 | 8.8 | — | Linux | Linux | — | nvme-fc: Do not cancel requests in io target before it is initialized |
| CVE-2026-97442 | 8.8 | — | Linux | Linux | — | wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi |
| CVE-2026-97509 | 8.8 | — | Linux | Linux | — | thunderbolt: Keep XDomain reference during the lifetime of a service |
| CVE-2026-56744 | 8.7 | — | bsv-blockchain | @bsv/wallet-toolbox | CWE-1288 | `@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied r… |
| CVE-2026-61825 | 8.7 | — | code16 | sharp | CWE-79 | code16/sharp has a stored XSS via data-html-content Sanitizer Bypass |
| CVE-2026-63498 | 8.7 | — | grokability | snipe-it | CWE-79 | Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API |
| CVE-2026-82566 | 8.7 | — | Botslab | G980H | CWE-613 | Botslab G980H Dashcams Insufficient session expiration |
| CVE-2026-84399 | 8.7 | — | Botslab | G980H | CWE-863 | Botslab G980H Dashcams Incorrect Authorization |
| CVE-2026-85057 | 8.7 | — | zitadel | zitadel | CWE-284 | ZITADEL: Actions V1 sandbox escape: host file read via require() |
| CVE-2026-86858 | 8.7 | — | ServiceNow | ServiceNow AI Platform | CWE-284 | Unauthenticated Privilege Escalation via GraphQL in ServiceNow AI Platform |
| CVE-2026-86859 | 8.7 | — | ServiceNow | ServiceNow AI Platform | CWE-284 | Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform |
| CVE-2026-87721 | 8.7 | — | Gerrit | Gerrit | CWE-400 | Denial of Service via Exponential Backtracking in ANTLR Search Query Parser i… |
| CVE-2026-87722 | 8.7 | — | Gerrit | Gerrit | CWE-400 | Regular Expression Denial of Service (ReDoS) in Search Query Predicates and R… |
| CVE-2026-91122 | 8.7 | — | discourse | discourse | CWE-79 | Discourse: Chat MessageBus delivers read-restricted messages to unauthorized … |
| CVE-2026-96883 | 8.7 | — | AWS | pgcollection | CWE-843 | Type confusion in AWS pgcollection allows remote code execution |
| CVE-2026-97057 | 8.7 | — | NodeRedis | redis-parser | CWE-1284 | redis-parser through 3.0.0 Denial of Service via Invalid Array Length |
| CVE-2026-97362 | 8.7 | — | rejetto | hfs2 | CWE-835 | HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread |
| CVE-2026-63493 | 8.6 | — | grokability | snipe-it | CWE-288 | Snipe-IT: 2FA bypass via the API token flow |
| CVE-2026-77581 | 8.6 | — | alam00000 | bentopdf | CWE-918 | BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass |
| CVE-2026-77874 | 8.6 | — | IBM | Enterprise Build of Quarkus | CWE-89 | IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities |
| CVE-2026-77967 | 8.6 | — | Botslab | G980H | CWE-294 | Botslab G980H Dashcams Authentication Bypass by Capture-replay |
| CVE-2026-81455 | 8.6 | — | Dell | ThinOS 10 | CWE-306 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a M… |
| CVE-2026-95985 | 8.6 | — | Amazon | Kiro IDE | CWE-349 | Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untr… |
| CVE-2026-96515 | 8.6 | — | Netlink ICT Pvt Ltd | Netlink ICT HG323RW Router | CWE-434 | Command Injection Vulnerability in Netlink ICT HG323RW Router |
| CVE-2026-56738 | 8.5 | — | thorsten | phpMyFAQ | CWE-89 | phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion |
| CVE-2026-56739 | 8.5 | — | logto-io | logto | CWE-918 | Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint |
| CVE-2026-82371 | 8.5 | — | Brocade | SANnav | CWE-532 | Plaintext exposure of sensitive authentication data in SANnav discovery servi… |
| CVE-2026-82372 | 8.5 | — | Brocade | SANnav | CWE-532 | Improper handling of sensitive data during IPsec policy creation and modifica… |
| CVE-2026-85082 | 8.5 | — | Maple Media | Root Browser Classic | CWE-78 | Maple Media Root Browser Classic 3.3.0 - OS command injection through crafted… |
| CVE-2026-93354 | 8.5 | — | Gimanh | taskview-community | CWE-1188 | Taskview Community Missing Authentication via OAuth Dynamic Client Registration |
| CVE-2026-14443 | 8.4 | — | Brocade | SANnav | CWE-532 | Incomplete log sanitization during bulk IPsec policy collection in Brocade SA… |
| CVE-2026-86857 | 8.4 | — | ServiceNow | ServiceNow AI Platform | — | Authorization Bypass in ServiceNow AI Platform |
| CVE-2026-93827 | 8.4 | — | Linux | Linux | — | virtio-fs: avoid double-free on failed queue setup |
| CVE-2026-95699 | 8.4 | — | MrSteam | iSteamX application | CWE-653 | MrSteam iSteamX Improper Isolation or Compartmentalization |
| CVE-2026-97450 | 8.4 | — | Linux | Linux | — | ACPICA: validate handler object type in two places |
| CVE-2026-97451 | 8.4 | — | Linux | Linux | — | ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) |
| CVE-2026-97452 | 8.4 | — | Linux | Linux | — | ACPICA: Prevent adding invalid references |
| CVE-2026-97455 | 8.4 | — | Linux | Linux | — | ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() |
| CVE-2026-13465 | 8.3 | — | Altera | Trusted Firmware | CWE-121 | EL3 Stack Buffer Overflow in FCS HKDF Request |
| CVE-2026-13466 | 8.3 | — | Altera | Trusted Firmware | CWE-131 | Unit Confusion in VAB Authentication |
| CVE-2026-13467 | 8.3 | — | Altera | Trusted Firmware | CWE-787 | Systemic Missing Address Validation in SiP SMC Handlers |
| CVE-2026-58004 | 8.3 | — | Altera | Trusted Firmware | CWE-125 | Crafted oversized firmware image causes EL3 stack overflow during VAB authent… |
| CVE-2026-58005 | 8.3 | — | Altera | Trusted Firmware | CWE-119 | Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary … |
| CVE-2026-58006 | 8.3 | — | Altera | Trusted Firmware | CWE-822 | Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memo… |
| CVE-2026-58007 | 8.3 | — | Altera | Trusted Firmware | CWE-822 | Unchecked SDM mailbox response address enables EL3 secure-memory corruption |
| CVE-2026-58008 | 8.3 | — | Altera | Trusted Firmware | CWE-121 | Unchecked HKDF key-size input in EL3 causes a stack buffer overflow |
| CVE-2026-82157 | 8.3 | — | Dell | ThinOS 10 | CWE-295 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an… |
| CVE-2026-96746 | 8.3 | — | MongoDB | C Driver | CWE-787 | Heap buffer overflow via mid-scan command list growth in client topology moni… |
| CVE-2026-96748 | 8.3 | — | MongoDB | Python Driver | CWE-177 | Connection redirection via percent-encoded delimiter injection in connection … |
| CVE-2026-56736 | 8.2 | — | thorsten | phpMyFAQ | CWE-79 | phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Fronten… |
| CVE-2026-85056 | 8.2 | — | zitadel | zitadel | CWE-287 | ZITADEL: MFA bypass via session reuse in Login V2 |
| CVE-2026-91160 | 8.2 | — | rmyndharis | OpenWA | CWE-862 | OpenWA: A read-only API key can receive a session pairing QR over the WebSock… |
| CVE-2026-97433 | 8.2 | — | Linux | Linux | — | nvme: validate FDP configuration descriptor sizes |
| CVE-2026-56737 | 8.1 | — | thorsten | phpMyFAQ | CWE-287 | phpMyFAQ's two-factor authentication login bypasses the password factor |
| CVE-2026-62368 | 8.1 | — | grokability | snipe-it | CWE-79 | Snipe-IT: Stored XSS via Custom Field name in asset-list column headers |
| CVE-2026-77294 | 8.1 | — | mauriceboe | TREK | CWE-918 | TREK: Server-Side Request Forgery via User-Configurable LLM Base URL |
| CVE-2026-81473 | 8.1 | — | Dell | Rugged Control Center (RCC) | CWE-287 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Impro… |
| CVE-2026-90959 | 8.1 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-22 | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_ur… |
| CVE-2026-93221 | 8.1 | — | Linux | Linux | — | nfsd: convert nfsd_net boolean flags to unsigned long flags word |
| CVE-2026-93224 | 8.1 | — | Linux | Linux | — | svcrdma: Fix unmatched rn_unregister on failed accept |
| CVE-2026-93282 | 8.1 | — | Linux | Linux | — | ksmbd: fix maximum allowed access checks |
| CVE-2026-93786 | 8.1 | — | Linux | Linux | — | ksmbd: preserve VFS inherited POSIX ACL mask |
| CVE-2026-93787 | 8.1 | — | Linux | Linux | — | smb: client: bound dirent name against end of SMB response in cifs_filldir |
| CVE-2026-94611 | 8.1 | — | goauthentik | authentik | CWE-200 | authentik: Stored credentials are readable with view permission alone |
| CVE-2026-89325 | 7.8 | — | Rapid7 | Insight Agent | CWE-427 | Rapid7 Insight Agent: Uncontrolled search path element in InsightVM assessmen… |
| CVE-2026-93237 | 7.8 | — | Linux | Linux | — | LoongArch: Add DIRECT_MAP_PHYSMEM_END definition |
| CVE-2026-93250 | 7.8 | — | Linux | Linux | — | vxlan: mdb: Fix use-after-free in vxlan_mdb_flush() |
| CVE-2026-93262 | 7.8 | — | Linux | Linux | — | md/raid5-ppl: fix use-after-free in ppl_do_flush() |
| CVE-2026-93277 | 7.8 | — | Linux | Linux | — | RDMA/bnxt_re: Validate udata before executing commands |
| CVE-2026-93287 | 7.8 | — | Linux | Linux | — | i2c: smbus: reject oversized block transfers in the common path |
| CVE-2026-93288 | 7.8 | — | Linux | Linux | — | netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state |
| CVE-2026-93782 | 7.8 | — | Linux | Linux | — | vhost-scsi: flush backend after device ioctls |
| CVE-2026-93798 | 7.8 | — | Linux | Linux | — | btrfs: fix reloc root cleanup in merge_reloc_roots() |
| CVE-2026-93813 | 7.8 | — | Linux | Linux | — | btrfs: tree-checker: validate INODE_REF's namelen |
| CVE-2026-93817 | 7.8 | — | Linux | Linux | — | perf: Fix addr_filter_ranges lifetime |
| CVE-2026-95519 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -… |
| CVE-2026-95521 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-78 | Rpm: rpm: shell command injection via macro expansion of source/spec file bas… |
| CVE-2026-97415 | 7.8 | — | Linux | Linux | — | btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF |
| CVE-2026-97421 | 7.8 | — | Linux | Linux | — | RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() |
| CVE-2026-97429 | 7.8 | — | Linux | Linux | — | drm/amdkfd: fix UAF race in destroy_queue_cpsch |
| CVE-2026-97478 | 7.8 | — | Linux | Linux | — | virt: acrn: Fix irqfd use-after-free during eventfd shutdown |
| CVE-2026-97497 | 7.8 | — | Linux | Linux | — | drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id |
| CVE-2026-97513 | 7.8 | — | Linux | Linux | — | media: chips-media: wave5: Release m2m_ctx after Instance Removed from List |
| CVE-2026-79764 | 7.7 | — | Termix-SSH | Termix | CWE-918 | Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist |
| CVE-2026-85496 | 7.7 | — | Botslab | G980H | CWE-340 | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |
| CVE-2026-88390 | 7.7 | — | n/a | n/a | CWE-787 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruin… |
| CVE-2026-93265 | 7.7 | — | Linux | Linux | — | PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node |
| CVE-2026-97428 | 7.7 | — | Linux | Linux | — | drm/amdgpu: harden FRU PIA parsing with bounded helpers |
| CVE-2026-97444 | 7.7 | — | Linux | Linux | — | ACPICA: add boundary checks in two places |
| CVE-2026-97445 | 7.7 | — | Linux | Linux | — | ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources() |
| CVE-2026-97448 | 7.7 | — | Linux | Linux | — | ACPICA: Add validation for node in acpi_ns_build_normalized_path() |
| CVE-2026-97454 | 7.7 | — | Linux | Linux | — | ACPICA: add boundary checks in acpi_ps_get_next_field() |
| CVE-2026-63203 | 7.6 | — | logto-io | logto | CWE-862 | Logto: Account API can disclose stored third-party provider tokens without th… |
| CVE-2026-87720 | 7.6 | — | Gerrit | Gerrit | CWE-613 | Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suf… |
| CVE-2026-7169 | 7.5 | — | Evope Collector | Evope Collector | — | Uncontrolled Search Path Element in Evope Collector |
| CVE-2026-51995 | 7.5 | — | n/a | n/a | CWE-200 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker … |
| CVE-2026-57440 | 7.5 | — | StarCitizenWiki | mediawiki-extensions-EmbedVideo | CWE-79 | Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgE… |
| CVE-2026-61782 | 7.5 | — | web-infra-dev | rsdoctor | CWE-200 | @rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Sou… |
| CVE-2026-61816 | 7.5 | — | zbateson | mail-mime-parser | CWE-400 | zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory D… |
| CVE-2026-63645 | 7.5 | — | openobserve | openobserve | CWE-200 | OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL data… |
| CVE-2026-71540 | 7.5 | — | wazuh | wazuh | CWE-770 | Wazuh Manager cluster header parsing allows pre-authentication memory exhaustion |
| CVE-2026-75907 | 7.5 | — | Norwegian Cruise Line | door access control | CWE-287 | CVE-2026-75907 |
| CVE-2026-88357 | 7.5 | — | n/a | n/a | CWE-1335 | nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer… |
| CVE-2026-88368 | 7.5 | — | n/a | n/a | CWE-681 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerabili… |
| CVE-2026-88372 | 7.5 | — | n/a | n/a | CWE-190 | libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_head… |
| CVE-2026-88376 | 7.5 | — | n/a | n/a | CWE-191 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::C… |
| CVE-2026-88382 | 7.5 | — | n/a | n/a | CWE-770 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocati… |
| CVE-2026-93826 | 7.5 | — | Linux | Linux | — | HID: hidpp: fix potential UAF in hidpp_connect_event() |
| CVE-2026-93830 | 7.5 | — | Linux | Linux | — | net: stmmac: xgmac2: disable RBUE in default RX interrupt mask |
| CVE-2026-94613 | 7.5 | — | goauthentik | authentik | CWE-770 | authentik: Denial of Service via Document Type Declarations in SAML Messages |
| CVE-2026-96749 | 7.5 | — | MongoDB | Python Driver | CWE-190 | Heap out-of-bounds write via signed size overflow in BSON document encoding |
| CVE-2026-97417 | 7.5 | — | Linux | Linux | — | netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() |
| CVE-2026-97508 | 7.5 | — | Linux | Linux | — | thunderbolt: Set tb->root_switch to NULL when domain is stopped |
| CVE-2026-57178 | 7.4 | — | python-social-auth | social-core | CWE-287 | social-auth-core: VK App backend accepts unsigned callback data when auth_key… |
| CVE-2026-61788 | 7.4 | — | bytebase | dbhub | CWE-184 | @bytebase/dbhub's read-only mode does not prevent database writes |
| CVE-2026-88907 | 7.4 | — | TÜBİTAK ULAKBİM | UlakPDF | CWE-863 | SAML ePPN Attribute Validation Bypass in TÜBİTAK ULAKBİM's UlakPDF |
| CVE-2026-93225 | 7.4 | — | Linux | Linux | — | phy: fsl-imx8mq-usb: fix typec switch leak on probe error path |
| CVE-2026-93260 | 7.4 | — | Linux | Linux | — | powerpc/xive: propagate IPI init errors to prevent use-after-free |
| CVE-2026-93543 | 7.4 | — | x.org | libXi | CWE-125 | Out-of-bounds read in libXi's XI2 class parser |
| CVE-2026-94612 | 7.4 | — | goauthentik | authentik | CWE-287 | authentik: Authentication bypass via assertion confusion in SAML sources |
| CVE-2026-97474 | 7.4 | — | Linux | Linux | — | wifi: iwlwifi: mld: purge async notifications upon nic error |
| CVE-2026-12559 | 7.3 | — | OpenText | Vendor Invoice Management for SAP Solutions | CWE-79 | Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for S… |
| CVE-2026-61823 | 7.3 | — | code16 | sharp | CWE-79 | code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute |
| CVE-2026-96750 | 7.3 | — | MongoDB | Compass | CWE-94 | Shell script injection via server-supplied database name in Open MongoDB shell |
| CVE-2026-61815 | 7.2 | — | zbateson | mail-mime-parser | CWE-93 | zbateson/mail-mime-parser has CRLF header injection via attachment filename |
| CVE-2026-91123 | 7.2 | — | discourse | discourse | CWE-22 | Discourse: Reject literal backslash path separators in iframe src traversal g… |
| CVE-2026-4638 | 7.1 | — | Paessler GmbH | PRTG Network Monitor | CWE-209 | Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler P… |
| CVE-2026-48070 | 7.1 | — | docmost | docmost | CWE-22 | Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local… |
| CVE-2026-77293 | 7.1 | — | mauriceboe | TREK | CWE-639 | TREK: Cross-user note-file deletion (IDOR / Broken Access Control) |
| CVE-2026-82094 | 7.1 | — | IBM | DataStage on Cloud Pak for Data | CWE-22 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-82164 | 7.1 | — | Dell | Trusted Device Client, | CWE-732 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect… |
| CVE-2026-82585 | 7.1 | — | Botslab | G980H | CWE-319 | Botslab G980H Dashcams Cleartext Transmission of Sensitive Information |
| CVE-2026-82708 | 7.1 | — | Botslab | G980H | CWE-22 | Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Dire… |
| CVE-2026-93229 | 7.1 | — | Linux | Linux | — | nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry |
| CVE-2026-93816 | 7.1 | — | Linux | Linux | — | f2fs: validate inline dentry name lengths before conversion |
| CVE-2026-96744 | 7.1 | — | MongoDB | Laravel MongoDB (PHP) | CWE-943 | Unauthorized cache lock takeover via expression injection in lock owner value… |
| CVE-2026-97437 | 7.1 | — | Linux | Linux | — | ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() |
| CVE-2026-97438 | 7.1 | — | Linux | Linux | — | fs/ntfs3: validate index entry key bounds |
| CVE-2026-97496 | 7.1 | — | Linux | Linux | — | drm/amdkfd: Fix OOB memory exposure in get_wave_state() |
| CVE-2026-97520 | 7.1 | — | Linux | Linux | — | gfs2: move quota_init qc iterator increment |
| CVE-2026-79959 | 7.0 | — | Botslab | G980H | CWE-798 | Botslab G980H Dashcams Use of Hard-coded Credentials |
| CVE-2026-88956 | 7.0 | — | Botslab | G980H | CWE-306 | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-93796 | 7.0 | — | Linux | Linux | — | wifi: iwlwifi: pcie: null RX pointers after free |
| CVE-2026-93801 | 7.0 | — | Linux | Linux | — | smb/client: zero-initialize stack-allocated cifs_open_info_data |
| CVE-2026-93810 | 7.0 | — | Linux | Linux | — | cachefiles: Fix double fput |
| CVE-2026-14441 | 6.9 | — | Brocade | SANnav | CWE-1025 | Logic flaw in SANnav Java cache key handling object comparison handling |
| CVE-2026-14442 | 6.9 | — | Brocade | SANnav | CWE-532 | Information exposure vulnerability in the job scheduling component of SANnav … |
| CVE-2026-84403 | 6.9 | — | Botslab | G980H | CWE-306 | Botslab G980H Dashcams Missing Authentication for Critical Function |
| CVE-2026-87118 | 6.9 | — | Botslab | G980H | CWE-787 | Botslab G980H Dashcams Out-of-bounds Write |
| CVE-2026-97058 | 6.9 | — | alexei | sprintf-js | CWE-1284 | sprintf-js through 1.1.3 Denial of Service via Unbounded Precision |
| CVE-2026-26054 | 6.8 | — | sumatrapdfreader | sumatrapdf | CWE-125 | SumatraPDF: Heap out-of-bounds read in MOBI header parser. |
| CVE-2026-57176 | 6.8 | — | python-social-auth | social-core | CWE-289 | social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in … |
| CVE-2026-84283 | 6.8 | — | FluteCode | Secure Folder | CWE-922 | FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass t… |
| CVE-2026-88916 | 6.8 | — | TÜBİTAK ULAKBİM | UlakPDF | CWE-863 | Admin Access Bypass via Header Fallback in TÜBİTAK ULAKBİM's UlakPDF |
| CVE-2026-92680 | 6.8 | — | Araxis | Merge | CWE-522 | Araxis Merge insufficiently protected credentials |
| CVE-2026-93290 | 6.8 | — | Eufy | Omni C20 | CWE-798 | Use of Hard-coded Credentials in Eufy Omni C20 |
| CVE-2026-94416 | 6.8 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-290 | Aap-gateway: aap-gateway: authorization bypass via workload identity token fo… |
| CVE-2026-79761 | 6.6 | — | Termix-SSH | Termix | CWE-78 | Termix: Command injection in SSH key deployment verification |
| CVE-2026-4806 | 6.5 | — | alexvtn | Custom Thank You Page for WooCommerce | CWE-862 | Custom Thank You Page for WooCommerce <= 1.1.2 - Missing Authorization to Una… |
| CVE-2026-54461 | 6.5 | — | HabitRPG | habitica | CWE-1333 | Habitica: Regex Injection / ReDoS in Member Search |
| CVE-2026-61811 | 6.5 | — | wazuh | wazuh | CWE-674 | Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Work… |
| CVE-2026-65422 | 6.5 | — | Genetec Inc. | Genetec Security Center | CWE-862 | A flaw in the authorization mechanism for Media Gateway API in Genetec Securi… |
| CVE-2026-65827 | 6.5 | — | docmost | docmost | CWE-400 | Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial … |
| CVE-2026-76907 | 6.5 | — | suitenumerique | docs | CWE-200 | LaSuite Doc: Public Documents Enumeration |
| CVE-2026-77798 | 6.5 | — | Rapid7 | Velociraptor | CWE-833 | Velociraptor Authenticated Denial of Service |
| CVE-2026-91133 | 6.5 | — | discourse | discourse | CWE-943 | Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure |
| CVE-2026-93541 | 6.5 | — | X.org | libXi | CWE-125 | Out-of-bounds read in libXi's XQueryDeviceState() |
| CVE-2026-93542 | 6.5 | — | x.org | libXi | CWE-125 | Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_c… |
| CVE-2026-93544 | 6.5 | — | x.org | libXi | CWE-125 | Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing |
| CVE-2026-93545 | 6.5 | — | x.org | libXi | CWE-125 | Out-of-bounds read in libXi's XListInputDevices() |
| CVE-2026-94281 | 6.5 | — | x.org | libXi | CWE-125 | Out-of-bounds read in libXi's XListInputDevices() class parsing |
| CVE-2026-57175 | 6.4 | — | python-social-auth | social-core | CWE-287 | social-auth-core has an Improper Authentication issue |
| CVE-2026-79760 | 6.4 | — | Termix-SSH | Termix | CWE-918 | Termix: Authenticated blind SSRF through notification channel test endpoints |
| CVE-2026-91119 | 6.4 | — | discourse | discourse | CWE-79 | Discourse: Encode action_code_who in mention URLs |
| CVE-2026-91161 | 6.4 | — | rmyndharis | OpenWA | CWE-863 | OpenWA: VIEWER API keys can read WhatsApp group invite codes |
| CVE-2026-85738 | 6.3 | — | liketrek | TREK | CWE-918 | TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4) |
| CVE-2026-96745 | 6.3 | — | MongoDB | PHP Driver | CWE-502 | PHP object injection via unsuppressible __pclass class inference in command m… |
| CVE-2026-6544 | 6.2 | — | IBM | Concert | CWE-552 | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-61784 | 6.1 | — | cstigler | node-xhtml-purifier | CWE-79 | xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS |
| CVE-2026-93405 | 6.1 | — | Foundry376 | Mailspring | CWE-79 | Mailspring: Stored XSS in attachment quick preview (unsanitized Markdown/DOCX… |
| CVE-2026-67233 | 6.0 | — | rabbitmq | rabbitmq-server | CWE-862 | RabbitMQ: Monitoring-tag user can DELETE shovels |
| CVE-2026-75558 | 6.0 | — | Botslab | G980H | CWE-321 | Botslab G980H Dashcams Use of Hard-coded Cryptographic Key |
| CVE-2026-88761 | 6.0 | — | Botslab | G980H | CWE-1391 | Botslab G980H Dashcams Use of Weak Credentials |
| CVE-2026-93353 | 6.0 | — | 9001 | copyparty | CWE-59 | copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers |
| CVE-2026-77703 | 5.9 | — | HAVELSAN Inc. | Liman Render Engine | CWE-322 | SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine |
| CVE-2026-77707 | 5.9 | — | HAVELSAN Inc. | Liman Render Engine | CWE-295 | TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Li… |
| CVE-2026-79762 | 5.5 | — | Termix-SSH | Termix | CWE-321 | Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH cr… |
| CVE-2026-88384 | 5.5 | — | n/a | n/a | CWE-476 | OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsi… |
| CVE-2026-96873 | 5.5 | — | The Wikimedia Foundation | Mediawiki - CirrusSearch Extension | CWE-79 | Reflected XSS in CirrusSearch debug explain output |
| CVE-2026-97182 | 5.5 | — | halo-dev | Halo | CWE-20 | halo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralization |
| CVE-2026-97231 | 5.5 | — | volotat | Anagnorisis | CWE-287 | volotat Anagnorisis Socket.IO Connect app.py missing authentication |
| CVE-2026-97324 | 5.5 | — | YunaiV | ruoyi-vue-pro | CWE-266 | YunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderCo… |
| CVE-2026-97326 | 5.5 | — | songxinjianqwe | Chat | CWE-918 | songxinjianqwe Chat chat-server ChatServer.java server-side request forgery |
| CVE-2026-47132 | 5.4 | — | thorsten | phpMyFAQ | CWE-20 | phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticate… |
| CVE-2026-79758 | 5.4 | — | Termix-SSH | Termix | CWE-284 | Termix: Authenticated users can read other users' host status and clear globa… |
| CVE-2026-91120 | 5.4 | — | discourse | discourse | CWE-79 | Discourse: Stored HTML injection in video notification emails |
| CVE-2026-91134 | 5.4 | — | discourse | discourse | CWE-20 | Discourse: Block post iframes whose encoded userinfo bypasses the allowed_ifr… |
| CVE-2026-19532 | 5.3 | — | HAVELSAN Inc. | Liman MYS | CWE-22 | Path Traversal in HAVELSAN's Liman MYS |
| CVE-2026-48072 | 5.3 | — | docmost | docmost | CWE-22 | Docmost: Public image fileName path traversal leads to unauthorized local fil… |
| CVE-2026-77320 | 5.3 | — | mauriceboe | TREK | CWE-200 | TREK: Public trip share link ignores the `share_map` permission server-side (… |
| CVE-2026-79763 | 5.3 | — | Termix-SSH | Termix | CWE-308 | Termix: MFA-critical operations accept the account password as a sole factor … |
| CVE-2026-96747 | 5.3 | — | MongoDB | Python Driver | CWE-918 | Forced local Unix socket connection via dot-sock KMS endpoint in client-side … |
| CVE-2026-97061 | 5.3 | — | blackcandy-org | Black Candy | CWE-862 | Black Candy through 3.2.1 Information Disclosure via Playlist Search |
| CVE-2026-97225 | 5.3 | — | n/a | DbGate | CWE-74 | DbGate JSON Runner runners.js code injection |
| CVE-2026-97226 | 5.3 | — | n/a | DbGate | CWE-22 | DbGate files-style Endpoint files.js fs.readFile path traversal |
| CVE-2026-52853 | 5.2 | — | docmost | docmost | CWE-269 | Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER |
| CVE-2026-4637 | 5.1 | — | Paessler GmbH | PRTG Network Monitor | CWE-79 | Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor |
| CVE-2026-17413 | 5.1 | — | IBM | PowerVM Hypervisor | CWE-129 | This Power System update is being released to address |
| CVE-2026-17503 | 5.1 | — | IBM | PowerVM Hypervisor | CWE-20 | This Power System update is being released to address |
| CVE-2026-17504 | 5.1 | — | IBM | PowerVM Hypervisor | CWE-191 | This Power System update is being released to address |
| CVE-2026-48540 | 5.1 | — | krayin | laravel-crm | CWE-79 | Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title |
| CVE-2026-48541 | 5.1 | — | krayin | laravel-crm | CWE-79 | Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field |
| CVE-2026-48542 | 5.1 | — | krayin | laravel-crm | CWE-79 | Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field |
| CVE-2026-48543 | 5.1 | — | krayin | laravel-crm | CWE-79 | Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description |
| CVE-2026-82716 | 5.1 | — | Botslab | G980H | CWE-532 | Botslab G980H Dashcams Insertion of Sensitive Information into Log File |
| CVE-2026-97062 | 5.1 | — | Webkul | Aureus ERP | CWE-79 | Aureus ERP through 1.6.0 Stored XSS via SVG File Upload |
| CVE-2026-91121 | 5.0 | — | discourse | discourse | CWE-79 | Discourse: Chat upload filenames rendered as raw HTML in excerpts |
| CVE-2026-77825 | 4.9 | — | IBM | ContextForge MCP Gateway | CWE-22 | IBM ContextForge MCP Gateway is affected by path traversal |
| CVE-2026-79680 | 4.5 | — | qt | qt | CWE-288 | Authentication bypass vulnerability in the password authentication mechanism … |
| CVE-2026-56792 | 4.4 | — | Dell | Rugged Control Center (RCC) | CWE-287 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Impro… |
| CVE-2025-32000 | 4.3 | — | HCL Software | HCL Sametime | CWE-20 | Insufficient Input Sanitization is addressed in HCL Sametime 12.0.4. It is re… |
| CVE-2026-3253 | 4.3 | — | mailerlite | MailerLite – Signup forms (official) | CWE-862 | MailerLite – Signup forms (official) <= 1.7.21 - Missing Authorization to Aut… |
| CVE-2026-16302 | 4.3 | — | brainstormforce | Spectra Legacy – Gutenberg Blocks | CWE-200 | Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Se… |
| CVE-2026-18870 | 4.3 | — | IBM | PowerVM Hypervisor | CWE-125 | This Power System update is being released to address |
| CVE-2026-48073 | 4.3 | — | docmost | docmost | CWE-639 | Docmost: Page export can include restricted same-space attachments through fo… |
| CVE-2026-52850 | 4.3 | — | docmost | docmost | CWE-639 | Docmost: Broken access control in transclusion lookup API leaks sync-block co… |
| CVE-2026-57177 | 4.3 | — | python-social-auth | social-core | CWE-352 | social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Ba… |
| CVE-2026-62286 | 4.3 | — | amir20 | dozzle | CWE-200 | Dozzle label filters do not restrict container event and statistics streams |
| CVE-2026-77321 | 4.3 | — | mauriceboe | TREK | CWE-200 | TREK MCP trip summary bypasses delegated OAuth read scopes |
| CVE-2026-79759 | 4.3 | — | Termix-SSH | Termix | CWE-639 | Termix: Cross-User Information Disclosure via Missing Ownership Check in depl… |
| CVE-2026-81508 | 4.3 | — | espressif | esp-idf | CWE-125 | ESF-IDF: Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing |
| CVE-2026-91132 | 4.3 | — | discourse | discourse | CWE-346 | Discourse: Wildcard iframe origin allowlist bypass via authority separators |
| CVE-2026-97311 | 4.3 | — | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: admin rest api role-groups endpoint dis… |
| CVE-2026-57179 | 4.2 | — | python-social-auth | social-core | CWE-384 | social-auth-core has a Session Fixation issue |
| CVE-2026-84302 | 4.2 | — | discourse | discourse | CWE-862 | Discourse: Non-participant moderators can read, edit, and delete PM content t… |
| CVE-2026-77797 | 3.6 | — | Rapid7 | Velociraptor | CWE-20 | Velociraptor Prefetch parser out of bounds |
| CVE-2026-17511 | 3.4 | — | IBM | PowerVM Hypervisor | CWE-212 | This Power System update is being released to address |
| CVE-2026-18857 | 3.4 | — | IBM | OPENBMC | CWE-125 | This Power System update is being released to address |
| CVE-2026-63630 | 3.4 | — | alam00000 | bentopdf | CWE-201 | BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfi… |
| CVE-2026-18104 | 3.3 | — | IBM | Db2 Mirror for i | CWE-327 | IBM Db2 Mirror for i is vulnerable to obtain sensitive information [] |
| CVE-2026-19492 | 3.2 | — | IBM | PowerVM Hypervisor | CWE-457 | This Power System update is being released to address |
| CVE-2026-73064 | 2.9 | — | trustedfirmware | Mbed TLS | CWE-394 | In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can c… |
| CVE-2026-97179 | 2.1 | — | n/a | O2OA | CWE-200 | O2OA Cipher Connection CipherConnectionAction.java list information disclosure |
| CVE-2026-97224 | 2.1 | — | n/a | Excalidraw | CWE-79 | Excalidraw Imported File restore.ts cross site scripting |
| CVE-2026-97232 | 2.1 | — | volotat | Anagnorisis | CWE-22 | volotat Anagnorisis page.html start_streaming path traversal |
| CVE-2026-97320 | 2.1 | — | YunaiV | ruoyi-vue-pro | CWE-918 | YunaiV/zhijiantianya ruoyi-vue-pro AI Knowledge AiKnowledgeDocumentServiceImp… |
| CVE-2026-97321 | 2.1 | — | YunaiV | ruoyi-vue-pro | CWE-74 | YunaiV/zhijiantianya ruoyi-vue-pro GoView Data Endpoint GoViewDataServiceImpl… |
| CVE-2026-97322 | 2.1 | — | YunaiV | ruoyi-vue-pro | CWE-79 | YunaiV/zhijiantianya ruoyi-vue-pro File Upload FileController.java cross site… |
| CVE-2026-97323 | 2.1 | — | YunaiV | ruoyi-vue-pro | CWE-22 | YunaiV/zhijiantianya ruoyi-vue-pro File Upload MpMaterialServiceImpl.java get… |
| CVE-2026-97325 | 2.1 | — | YunaiV | ruoyi-vue-pro | CWE-601 | YunaiV/zhijiantianya ruoyi-vue-pro OAuth2 Client OAuth2ClientServiceImpl.java… |
| CVE-2026-97365 | 2.1 | — | chonkie-inc | littrs | CWE-22 | chonkie-inc littrs lib.rs mount path traversal |
| CVE-2026-97366 | 2.1 | — | jhen0409 | react-native-debugger | CWE-77 | jhen0409 react-native-debugger Open in Editor window.js openDevTools os comma… |
| CVE-2026-97368 | 2.1 | — | chillzhuang | SpringBlade | CWE-285 | chillzhuang SpringBlade user-auth-info Endpoint UserServiceImpl.java UserServ… |
| CVE-2026-97233 | 2.0 | — | volotat | Anagnorisis | CWE-79 | volotat Anagnorisis Media Filename PlaylistManager.js html cross site scripting |
| CVE-2026-51994 | await | — | n/a | n/a | — | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Reque… |
| CVE-2026-51996 | await | — | n/a | n/a | — | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker … |
| CVE-2026-51997 | await | — | n/a | n/a | — | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker … |
| CVE-2026-52001 | await | — | n/a | n/a | — | An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker … |
| CVE-2026-85491 | await | — | — | Catalyst-Seal | CWE-706 | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a p… |
| CVE-2026-88351 | await | — | n/a | n/a | — | An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1… |
| CVE-2026-88355 | await | — | n/a | n/a | — | An incorrect buffer size calculation vulnerability exists in tinyexpr commit … |
| CVE-2026-88358 | await | — | n/a | n/a | — | simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::p… |
| CVE-2026-88359 | await | — | n/a | n/a | — | libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_form… |
| CVE-2026-88360 | await | — | n/a | n/a | — | libvips 8.19.0 contains a memory access vulnerability when processing little-… |
| CVE-2026-88361 | await | — | n/a | n/a | — | SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::B… |
| CVE-2026-88362 | await | — | n/a | n/a | — | MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_… |
| CVE-2026-88365 | await | — | n/a | n/a | — | minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_… |
| CVE-2026-88366 | await | — | n/a | n/a | — | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerabili… |
| CVE-2026-88367 | await | — | n/a | n/a | — | NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in n… |
| CVE-2026-88369 | await | — | n/a | n/a | — | zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondu… |
| CVE-2026-88370 | await | — | n/a | n/a | — | libconfini 1.16.4 contains a heap out-of-bounds write condition involving the… |
| CVE-2026-88371 | await | — | n/a | n/a | — | ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code… |
| CVE-2026-88373 | await | — | n/a | n/a | — | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in … |
| CVE-2026-88377 | await | — | n/a | n/a | — | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hv… |
| CVE-2026-88378 | await | — | n/a | n/a | — | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_… |
| CVE-2026-88383 | await | — | n/a | n/a | — | libical 4.0.6 contains an incompatible function pointer in icalparameter_stri… |
| CVE-2026-88385 | await | — | n/a | n/a | — | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() durin… |
| CVE-2026-88386 | await | — | n/a | n/a | — | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_r… |
| CVE-2026-88387 | await | — | n/a | n/a | — | LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRa… |
| CVE-2026-88388 | await | — | n/a | n/a | — | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnera… |
| CVE-2026-93205 | await | — | Linux | Linux | — | iommu/arm-smmu-v3: Manage teardown with devm |
| CVE-2026-93206 | await | — | Linux | Linux | — | PCI/proc: Use file_ns_capable() when checking config space read access |
| CVE-2026-93208 | await | — | Linux | Linux | — | kasan: fix cache shrink race with CPU hotplug |
| CVE-2026-93209 | await | — | Linux | Linux | — | Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb |
| CVE-2026-93210 | await | — | Linux | Linux | — | smb: client: harden DFS cache against invalid target hints |
| CVE-2026-93211 | await | — | Linux | Linux | — | nfsd: initialize DRC hash table before registering shrinker |
| CVE-2026-93212 | await | — | Linux | Linux | — | nfsd: guard nfsd_serv deref in nfsd_file_net_dispose |
| CVE-2026-93213 | await | — | Linux | Linux | — | of: fix out-of-bounds read in of_alias_scan() stem parser |
| CVE-2026-93214 | await | — | Linux | Linux | — | usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() |
| CVE-2026-93215 | await | — | Linux | Linux | — | cdx: Fix double free when sysfs file creation fails |
| CVE-2026-93216 | await | — | Linux | Linux | — | mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_me… |
| CVE-2026-93217 | await | — | Linux | Linux | — | mm/madvise: skip device-private PMDs in cold and pageout walks |
| CVE-2026-93218 | await | — | Linux | Linux | — | mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd |
| CVE-2026-93219 | await | — | Linux | Linux | — | clocksource/drivers/timer-sun4i: Advertise a real minimum delta |
| CVE-2026-93220 | await | — | Linux | Linux | — | sched_ext: Keep kick_sync waiting on the rq's own CPU |
| CVE-2026-93222 | await | — | Linux | Linux | — | signal: avoid shared siginfo namespace rewrites |
| CVE-2026-93223 | await | — | Linux | Linux | — | staging: media: tegra-video: fix of_node_put() on VIP parse errors |
| CVE-2026-93226 | await | — | Linux | Linux | — | ipv6: use RCU iterator to dump route exceptions |
| CVE-2026-93227 | await | — | Linux | Linux | — | mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn |
| CVE-2026-93230 | await | — | Linux | Linux | — | mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier |
| CVE-2026-93231 | await | — | Linux | Linux | — | lockd: fix swapped arguments in nlmsvc_match_ip() |
| CVE-2026-93232 | await | — | Linux | Linux | — | mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages |
Results continue: ranks 401–553.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-24 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.