boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, September 25, 2026 · all times UTC← 2026-09-24 · archive

Security Box Score — September 25, 2026

CISA adds 3 to KEV; 681 CVEs published, led by Linux (372).

681 CVEs published September 25, 2026: 22 critical, 170 high, 155 medium, 25 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 309 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 281 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1298747966——
KEV catalog size1726

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3086 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux21136204530263871311560.17.8.0020+697 ▲
microsoft10022901203199069216290311.17.8.0047+533 ▲
google5182686332105011831218090.37.5.0027+118 ▲
red hat2338625235940546200.06.7.0037+26 ▲
apple24656367165317148881.46.5.0019+202 ▲
freebsd04823673000.07.8.0016-23 ▼
canonical0421311135000.07.8.0019-15 ▼
suse1341721121000.07.5.0039+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0046+51 ▲
ubiquiti665362810334.69.1.0050+6 ▲
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-7 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache137649148275208163320.37.5.0063-17 ▼
mozilla113301102126730900.08.8.0034+54 ▲
gitlab241007245811533.05.3.0034+8 ▲
drupal2694119668411.15.7.0027+9 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614103350.08.7.0189-1 ▼
go440211000.05.9.0034+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-255 ▼
ibm398101719646733618610.17.5.0037+24 ▲
adobe2248308236437592150.67.5.0036+126 ▲
progress3641539100611.68.1.0046-16 ▼
zohocorp273762470000.08.1.0109+23 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-10 ▼
servicenow5107300200.09.4.0036+5 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link277222261212300.08.5.0175+11 ▲
siemens1552633103000.07.3.0026-4 ▼
synology1946510256000.05.6.0032+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
hikvision390540000.07.1.0038+3 ▲
abb291530000.07.2.0018+2 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1953663117014322210.37.2.0030+137 ▲
sourcecodester632320013894000.05.5.0043+16 ▲
nvidia5118521127370000.07.8.0040-1 ▼
spring017013608314000.06.5.0033-7 ▼
mongodb71169699604100.07.1.0038+39 ▲
itsourcecode371530037116000.02.1.0033+8 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0044+136 ▲
wwbn1061462349740000.06.9.0036+97 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.914399.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-82329.141296.49.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-83548.087695.010.0
CVE-2026-79756.075294.38.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9143KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-1888510.0.0724
CVE-2026-1888610.0.0504
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8222210.0.0225
Most disclosures (vendor)
VendorCVEs
linux2249
microsoft1010
oracle634
google519
ibm414
red hat251
apple246
adobe227
dell196
apache150
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco16
google9
apple8
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven95
Packagist16
npm15
PyPI14
crates.io9
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-87902WordPress2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171773
CVE-2021-27102n/a2021-11-171773
CVE-2021-27101n/a2021-11-171773
CVE-2021-27103n/a2021-11-171773
CVE-2021-21017Adobe2021-11-171773
CVE-2021-28550Adobe2021-11-171773
CVE-2021-42013Apache Software Foundation2021-11-171773
CVE-2021-41773Apache Software Foundation2021-11-171773
CVE-2021-30858Apple2021-11-171773
CVE-2021-30860Apple2021-11-171773

Transactions

ADDED TO KEV — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). Remediation due September 28, 2026.

ADDED TO KEV — CVE-2026-67279 (Mikrotik RouterOS). Remediation due September 28, 2026.

ADDED TO KEV — CVE-2026-87902 (WordPress). Remediation due September 28, 2026.

EXPLOIT PUBLISHED — moquette-io moquette: 5 CVEs (CVE-2026-85724, CVE-2026-95842, CVE-2026-95843, CVE-2026-95845, CVE-2026-95846). Public exploit references added.

EXPLOIT PUBLISHED — Mikrotik RouterOS: 4 CVEs (CVE-2026-67276, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281). Public exploit references added.

EXPLOIT PUBLISHED — radareorg radare2: 4 CVEs (CVE-2026-81878, CVE-2026-81879, CVE-2026-81881, CVE-2026-81882). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-2604 (GNOME Evolution Data Server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-43642 (Softaculous Virtualizor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73241 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73242 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77252 (sooperset mcp-atlassian). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-77261 (sooperset mcp-atlassian). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-89078 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93339 (Metaphor Creations Ditty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93577 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95396 (sfturing hosp_order). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95657 (dgtlmoon Changedetection.io). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95811 (Lemonldap-NG-Handler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95924 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96258 (onSite internet GmbH Auktion NG Auktionssoftware). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96272 (MacWarrior clipbucket-v5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97326 (songxinjianqwe Chat). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97366 (jhen0409 react-native-debugger). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97368 (chillzhuang SpringBlade). Public exploit reference added.

DUE DATE PASSED — CVE-2026-7273 (Zyxel GS1900-48HPv2 firmware). CISA remediation deadline was September 24, 2026; still in catalog.

REJECTED — CVE-2026-22315 (Mesalvo Meona Client Launcher Component). Record withdrawn by the CNA.

DISPUTED — CVE-2026-22314 (Mesalvo Meona Client Launcher Component). Record marked disputed.

RESCORED — Adobe Commerce: 4 CVEs (CVE-2026-48411, CVE-2026-48412, CVE-2026-48414, CVE-2026-48415). CVSS rescored — before/after on each CVE page.

RESCORED — radareorg radare2: 3 CVEs (CVE-2026-81879, CVE-2026-81881, CVE-2026-81882). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-0857 (Mesalvo Meona Client). CVSS 6 → 4.4 (NVD).

RESCORED — CVE-2026-22314 (Mesalvo Meona Client Launcher Component). CVSS 9 → 7.9 (NVD).

RESCORED — CVE-2026-25602 (Mesalvo Meona Server). CVSS 4.4 → 2.3 (NVD).

RESCORED — CVE-2026-55946 (Microsoft Copilot). CVSS 6.1 → 5.9 (NVD).

RESCORED — CVE-2026-68791 (Microsoft Azure Machine Learning). CVSS 8.6 → 7.5 (NVD).

RESCORED — CVE-2026-69399 (Microsoft Azure ARC). CVSS 10 → 9.8 (NVD).

RESCORED — CVE-2026-70009 (Microsoft Azure ARC). CVSS 9.3 → 9.8 (NVD).

RESCORED — CVE-2026-70200 (Microsoft Azure Logic Apps). CVSS 10 → 9.8 (NVD).

RESCORED — CVE-2026-77261 (sooperset mcp-atlassian). CVSS 7.1 → 8.5 (NVD).

RESCORED — CVE-2026-77903 (Microsoft Dataverse). CVSS 9 → 8.1 (NVD).

RESCORED — CVE-2026-78510 (Microsoft 365 Apps for Enterprise). CVSS 9.8 → 8.4 (NVD).

RESCORED — CVE-2026-83944 (Microsoft Azure Logic Apps). CVSS 10 → 9.1 (NVD).

RESCORED — CVE-2026-83946 (Microsoft Azure Portal). CVSS 8.2 → 6.1 (NVD).

RESCORED — CVE-2026-83964 (Adobe Connect). CVSS 6.2 → 7.5 (NVD).

RESCORED — CVE-2026-85885 (Microsoft 365 Copilot). CVSS 9.9 → 8.8 (NVD).

RESCORED — CVE-2026-85889 (Microsoft Azure AI Foundry). CVSS 10 → 9.8 (NVD).

RESCORED — CVE-2026-90902 (joomshaper.com Easy Store extension for Joomla). CVSS 8.2 → 8.6 (NVD).

PATCH SHIPPED — Red Hat Hardened Images: 5 CVEs (CVE-2026-88831, CVE-2026-88832, CVE-2026-88835, CVE-2026-88837, CVE-2026-88839). Fix versions published.

PATCH SHIPPED — CVE-2026-88264 (containers crun). Fixed in Red Hat Hardened Images 1.30-1.hum1.

Yesterday's Results

How to read these box scores · glossary

681 CVEs published. 25 box scores and 375 table rows below; the remaining 281 continue on page 2 — every CVE is listed, nothing truncated.

clavaque s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions — s2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0104   62.5     —
AFFECTED
  Product                                                                                                        Versions     Fixed
  s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions  unspecified  —
TIMELINE
  Aug 13  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
Netgate pfSense Plus — In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerabilit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  C  H  H  H    8.5   .0103   62.1     —
AFFECTED
  Product       Versions     Fixed
  pfSense Plus  unspecified  —
  pfSense CE    unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Sep 25  Published (CNA: mitre)
CWE-24 · CNA: mitre · CVSS v3.1 · 4 references · NVD status: Received
flippercode WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings — WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0075   53.0     —
AFFECTED
  Product                                                                                      Versions     Fixed
  WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings  unspecified  —
TIMELINE
  Jun 26  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
sslzen SSL Zen — SSL Certificate Installer & HTTPS Redirects — SSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  N  N    4.9   .0056   44.1     —
AFFECTED
  Product                                                Versions     Fixed
  SSL Zen — SSL Certificate Installer & HTTPS Redirects  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
dashbitco lazy_html — lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   P   N   N   N    2.3   .0054   42.9     —
AFFECTED
  Product    Versions                                    Fixed
  lazy_html  0.1.0 –                                     —
  lazy_html  1dee15746c024916b3110af8b168c2f3b3065fbd –  —
TIMELINE
  Sep 21  Reserved by CNA
  Sep 25  Published (CNA: EEF)
CWE-79 · CNA: EEF · CVSS v4.0 · 5 references · NVD status: Deferred
101gen Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code — Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0053   42.5     —
AFFECTED
  Product                                                                                 Versions     Fixed
  Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 14 references · NVD status: Deferred
knitpay Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more — Knit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0047   38.5     —
AFFECTED
  Product                                                    Versions     Fixed
  Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
wpchill Modula Image Gallery – Photo Grid & Video Gallery — Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0039   30.9     —
AFFECTED
  Product                                            Versions     Fixed
  Modula Image Gallery – Photo Grid & Video Gallery  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
ivole Customer Reviews for WooCommerce — Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0039   29.8     —
AFFECTED
  Product                           Versions     Fixed
  Customer Reviews for WooCommerce  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
ladela Online Scheduling and Appointment Booking System – Bookly — Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0037   28.2     —
AFFECTED
  Product                                                    Versions     Fixed
  Online Scheduling and Appointment Booking System – Bookly  unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-639 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Containerd has image-pull DoS via crafted OCI index graph amplification
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0036   26.7     —
AFFECTED
  Product     Versions              Fixed
  containerd  >= 2.0.0, < 2.0.13 –  —
TIMELINE
  Jun 9   Reserved by CNA
  Sep 25  Published (CNA: GitHub_M)
CWE-400, CWE-770, CWE-834 · CNA: GitHub_M · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
ihomefinder Optima Express IDX — Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0035   25.4     —
AFFECTED
  Product             Versions     Fixed
  Optima Express IDX  unspecified  —
TIMELINE
  Sep 18  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
flippercode WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings — WP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  N    6.4   .0033   23.4     —
AFFECTED
  Product                                                                                      Versions     Fixed
  WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings  unspecified  —
TIMELINE
  Jun 24  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 12 references · NVD status: Deferred
pr-gateway Blog2Social: Social Media Auto Post & Scheduler — Blog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  L  N    4.3   .0032   22.6     —
AFFECTED
  Product                                          Versions     Fixed
  Blog2Social: Social Media Auto Post & Scheduler  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
misp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute Values
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   N   N   N    6.3   .0032   22.3     —
AFFECTED
  Product       Versions     Fixed
  misp-modules  unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Sep 25  Published (CNA: CIRCL)
CWE-78 · CNA: CIRCL · CVSS v4.0 · 1 reference · NVD status: Deferred
phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  N  N    8.6   .0032   22.1     —
AFFECTED
  Product  Versions     Fixed
  phpIPAM  unspecified  —
TIMELINE
  Sep 25  Reserved by CNA
  Sep 25  Published (CNA: mitre)
CWE-863 · CNA: mitre · CVSS v3.1 · 2 references · NVD status: Received
ladela Online Scheduling and Appointment Booking System – Bookly — Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  N    5.3   .0032   21.8     —
AFFECTED
  Product                                                    Versions     Fixed
  Online Scheduling and Appointment Booking System – Bookly  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-285 · CNA: Wordfence · CVSS v3.1 · 9 references · NVD status: Deferred
ningzichun student-management-system editLog.php authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   L   N    5.5   .0031   21.4     —
AFFECTED
  Product                    Versions                                    Fixed
  student-management-system  98760f5711cf6dc8b4adca53a9e207ca49b02ebf –  —
TIMELINE
  Sep 24  Reserved by CNA
  Sep 25  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
ningzichun student-management-system getStudent.php authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0030   20.5     —
AFFECTED
  Product                    Versions                                    Fixed
  student-management-system  98760f5711cf6dc8b4adca53a9e207ca49b02ebf –  —
TIMELINE
  Sep 24  Reserved by CNA
  Sep 25  Published (CNA: VulDB)
CWE-285, CWE-639 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
gabelivan Asset CleanUp: Page Speed Booster — Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  C  L  L  N    5.5   .0029   19.8     —
AFFECTED
  Product                            Versions     Fixed
  Asset CleanUp: Page Speed Booster  unspecified  —
TIMELINE
  Jun 11  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-918 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
sslzen SSL Zen — SSL Certificate Installer & HTTPS Redirects — SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0027   17.6     —
AFFECTED
  Product                                                Versions     Fixed
  SSL Zen — SSL Certificate Installer & HTTPS Redirects  unspecified  —
TIMELINE
  Jul 27  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
smub WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More — WPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0027   17.6     —
AFFECTED
  Product                                                                                           Versions     Fixed
  WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More  unspecified  —
TIMELINE
  Sep 10  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
wpchill Modula Image Gallery – Photo Grid & Video Gallery — Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  H  H    8.1   .0027   17.6     —
AFFECTED
  Product                                            Versions     Fixed
  Modula Image Gallery – Photo Grid & Video Gallery  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
radykal Fancy Product Designer — Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0027   17.6     —
AFFECTED
  Product                 Versions     Fixed
  Fancy Product Designer  unspecified  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 25  Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
ningzichun student-management-system addLog.php echo cross site scripting
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   L   N    2.1   .0027   17.6     —
AFFECTED
  Product                    Versions                                    Fixed
  student-management-system  98760f5711cf6dc8b4adca53a9e207ca49b02ebf –  —
TIMELINE
  Sep 24  Reserved by CNA
  Sep 25  Published (CNA: VulDB)
CWE-79, CWE-94 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-958647.217.4themifymeThemify BuilderCWE-79Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'c…
CVE-2026-938996.517.0wordplusBetter Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsCWE-89Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'gro…
CVE-2026-977377.416.7muetyWakapiCWE-843In Wakapi before 2.17.6, the user caching service allows a lookup to be resol…
CVE-2026-958667.215.3cozmoslabsUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-79User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting v…
CVE-2026-977358.015.1ITFlowITFlowCWE-79ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/t…
CVE-2026-977245.314.9swmansionReact Native ReanimatedCWE-1321A prototype pollution vulnerability in Software Mansion React Native Worklets…
CVE-2026-958116.514.9—Lemonldap-NG-HandlerCWE-180Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before…
CVE-2026-835917.214.2mohammed_kaludiAMP for WP – Accelerated Mobile PagesCWE-79AMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Commen…
CVE-2026-933037.214.2htpluginsHT Contact Form – Drag & Drop Form Builder for WordPressCWE-79HT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scrip…
CVE-2026-936547.213.6codename065Premium Packages – Sell Digital Products SecurelyCWE-79Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via '…
CVE-2026-945737.213.6addonsorgRepeater Fields for Elementor FormsCWE-79Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-S…
CVE-2026-960397.213.6bookingalgorithmsBA Book EverythingCWE-79BA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting vi…
CVE-2026-965687.213.6jetmonstersRestaurant Menu and Food OrderingCWE-79Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Si…
CVE-2026-967527.213.6bmarshall511Zero Spam for WordPressCWE-79Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripti…
CVE-2026-964486.613.1Red HatRed Hat Build of KeycloakCWE-285Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping al…
CVE-2026-977212.013.1SanluanPublicCMSCWE-285Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsConte…
CVE-2026-197754.312.8allterraindeveloperOpenStation: Desktop Windows, Dock & Virtual Desktops for WP AdminCWE-862OpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) S…
CVE-2026-60825.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-60835.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-60845.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-60855.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-60865.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-60875.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-60885.112.4Novadigits technologiesStockAgileCWE-79Stored Cross-Site Scripting in StockAgile by Novadigits technologies
CVE-2026-976492.012.0ningzichunstudent-management-systemCWE-1392ningzichun student-management-system example_lite.sql default credentials
CVE-2026-977643.711.9allauthdjango-allauthCWE-180django-allauth before 65.19.4 does not have the expected limits on failed log…
CVE-2026-92289await11.4—Lemonldap-NG-PortalCWE-1390Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKC…
CVE-2026-938976.410.7paoltaiaGeoDirectory – WP Business Directory Plugin and Classified Listings DirectoryCWE-79GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-922126.110.6jetmonstersJetFormBuilder — Dynamic Blocks Form BuilderCWE-79JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL…
CVE-2026-922889.110.2—Lemonldap-NG-PortalCWE-1390Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before …
CVE-2026-977235.49.9madpsyka9q_ubersdrCWE-79madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vul…
CVE-2026-977365.49.7tinyauthtinyauthCWE-777tinyauth before 5.1.3 allows rule bypass by appending an allowed route string…
CVE-2026-842817.29.5radykalFancy Product DesignerCWE-79Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting…
CVE-2026-936566.48.9cozmoslabsUser Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-79User Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site…
CVE-2026-937476.48.9tomdeverwpForo ForumCWE-79wpForo Forum <= 3.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripti…
CVE-2026-967666.48.9paoltaiaGeoDirectory – WP Business Directory Plugin and Classified Listings DirectoryCWE-79GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-934775.98.4ash-projectashCWE-915Private action arguments can be set by user input on the bulk destroy and bul…
CVE-2026-926099.88.2Apache Software FoundationApache Qpid Broker-JCWE-384Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentic…
CVE-2026-925507.58.0Apache Software FoundationApache Qpid Broker-JCWE-789Apache Qpid Broker-J: Type size/count handling can lead to excessive allocati…
CVE-2026-925607.58.0Apache Software FoundationApache Qpid Broker-JCWE-770Apache Qpid Broker-J: Type size/count handling can lead to excessive allocati…
CVE-2026-927466.48.0jegstudioGutenverse – WordPress Blocks, Page Builder & Site EditorCWE-79Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-943766.48.0wordplusBetter Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsCWE-79Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross…
CVE-2026-92564await8.0Apache Software FoundationApache Qpid Broker-JCWE-674Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-a…
CVE-2026-854176.47.8BrocadeSANnavCWE-532Incomplete property masking in the SANnav logging subsystem
CVE-2026-842797.27.7radykalFancy Product DesignerCWE-79Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting…
CVE-2026-868375.36.9UnknownBooklyCWE-639Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass
CVE-2026-976482.14.7ningzichunstudent-management-systemCWE-352ningzichun student-management-system cross-site request forgery
CVE-2026-805145.34.4UnknownwpForo ForumCWE-348wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate…
CVE-2026-926087.54.3Apache Software FoundationApache Qpid Broker-JCWE-248Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 t…
CVE-2026-925736.54.3Apache Software FoundationApache Qpid Broker-JCWE-409Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery …
CVE-2026-783944.14.1UnknownLink LibraryCWE-22Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter
CVE-2025-148146.44.0wipeoutmediaCSS & JavaScript ToolboxCWE-79CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Contributor+) Stored Cros…
CVE-2026-977317.13.8MinIOMinIOCWE-347MinIO through 7aac2a2 does not verify that every x-amz-* header present on a …
CVE-2026-783936.13.6UnknownLink LibraryCWE-79Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort an…
CVE-2026-755532.42.8Tohoku Electric Power Company, IncorporatedTohoku Electric Power "Yorisou e Net" Android AppCWE-321Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-code…
CVE-2026-978466.82.4Red HatRed Hat Build of KeycloakCWE-287Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtl…
CVE-2026-783974.02.3UnknownLink LibraryCWE-918Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation
CVE-2026-620628.82.2ElementorElementor Website BuilderCWE-352WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forg…
CVE-2026-888484.21.6UnknownMasterStudy LMSCWE-863MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Catego…
CVE-2026-977325.10.0IRONMACEIronshieldCWE-347IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authentic…
CVE-2026-10038210.0—Wikimedia FoundationMediawiki - ExternalData ExtensionCWE-78Unauthenticated remote code execution through wikitext in ExternalData
CVE-2026-921619.8—FriendsOfFlarumoauthCWE-345FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email …
CVE-2026-936439.8—ZimbraZimbra Collaboration Suite (ZCS)CWE-22Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to R…
CVE-2026-1000759.8—LinuxLinux—RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-484829.4—glpi-projectglpiCWE-22GLPI: RCE via Form import
CVE-2026-936419.3—ZimbraZimbra Collaboration Suite (ZCS)CWE-79Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via…
CVE-2026-936429.3—ZimbraZimbra Collaboration Suite (ZCS)CWE-79Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via …
CVE-2026-936479.3—ZimbraZimbra Collaboration Suite (ZCS)CWE-79Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via…
CVE-2026-958329.3—Kovid GoyalkittyCWE-74Reflected unknown field names in the kitty colour control escape code allow c…
CVE-2026-970639.3—yzcheng90X-SpringBootCWE-287X-SpringBoot through 6.0 Authentication Bypass via Login Code
CVE-2026-970649.3—yzcheng90X-SpringBootCWE-1392X-SpringBoot through 6.0 Authentication Bypass via Static Master Code
CVE-2026-1003899.2—GestSupGestSupCWE-434GestSup before 3.2.61 Remote Code Execution via IMAP Attachment
CVE-2026-393539.1—InvoicePlaneInvoicePlaneCWE-98InvoicePlane: Remote Code Execution via Writable Templates Directory
CVE-2026-423229.1—PiwigoPiwigoCWE-434Piwigo: Authenticated RCE via File Upload in Logo Upload Feature
CVE-2026-622629.1—PiwigoPiwigoCWE-89Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`
CVE-2026-844589.1—zammadzammadCWE-287Zammad: Account takeover via unverified email matching during SSO auto-link
CVE-2026-1003909.1—tobychuizoraxyCWE-290Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6
CVE-2025-514578.8—n/an/aCWE-77D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection…
CVE-2026-615258.8—zammadzammadCWE-22Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Po…
CVE-2026-855428.8—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-938348.8—Red HatRed Hat Enterprise Linux 10CWE-416Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape
CVE-2026-944458.8—golang.org/x/playgroundgolang.org/x/playgroundCWE-20Malicious user input may lead to RCE in golang.org/x/playground
CVE-2026-967958.8—horillahorilla-hrCWE-94Horilla: Authenticated RCE in Horilla List-View Export
CVE-2026-968128.8—GooglegVisorCWE-269Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE
CVE-2026-975278.8—LinuxLinux—scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-975288.8—LinuxLinux—scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-975558.8—LinuxLinux—smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-979578.8—LinuxLinux—net: hinic: fix mailbox segment buffer overflow
CVE-2026-981158.8—LinuxLinux—ksmbd: safely drain sessions during logoff
CVE-2026-1003918.8—mhdzumairmediaflow-proxyCWE-918MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Vali…
CVE-2026-567258.7—zammadzammadCWE-306Zammad: Denial of Service via OTRS Import Controller
CVE-2026-567338.7—zammadzammadCWE-269Zammad: Incorrect Authorization and Improper Privilege Management
CVE-2026-890328.7—BerriAIlitellmCWE-863BerriAI LiteLLM < 1.101.0-rc.1 Tenant Isolation Bypass via Semantic Cache Layer
CVE-2026-844628.6—zammadzammadCWE-20Zammad: AI Agent template sanitizer bypass leads to remote code execution
CVE-2026-970608.6—yzcheng90X-SpringBootCWE-639X-SpringBoot through 6.0 Authorization Bypass via User Management
CVE-2026-1003728.6—MacWarriorclipbucket-v5CWE-22ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php
CVE-2026-476798.5—glpi-projectglpiCWE-22GLPI: arbitrary file deletion
CVE-2026-552148.5—glpi-projectglpiCWE-116GLPI: Stored XSS in suppliers
CVE-2026-714838.5—horillahorilla-hrCWE-79Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View
CVE-2026-1001728.5—ail projectail frameworkCWE-79Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic va…
CVE-2026-1001768.5—ail projectail frameworkCWE-79Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip
CVE-2026-567318.4—zammadzammadCWE-79Zammad: Cross-Site Scripting in Ticket Notifications
CVE-2026-978988.4—akiaakiaCWE-639Broken authorization in Akia keyless entry lets an authenticated guest unlock…
CVE-2026-1002488.4—RattadanCosmowarp ContractCWE-1025The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to…
CVE-2026-1003688.4—alastairlundyCliInvoke.SpecializationsCWE-78CliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrap…
CVE-2026-1003698.4—alastairlundyCliInvokeCWE-88CliInvoke: Argument Injection in Extensibility Runner Factory
CVE-2026-1005018.3—pawelmalakflameCWE-307Flame through 2.4.0 Brute-Force Attack via Login Endpoint
CVE-2026-672368.2—rabbitmqrabbitmq-serverCWE-312RabbitMQ: Plaintext username:password stored in an insecure cookie after succ…
CVE-2026-674098.2—rabbitmqrabbitmq-serverCWE-252RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruct…
CVE-2026-674108.2—rabbitmqrabbitmq-serverCWE-200RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint
CVE-2026-975258.2—LinuxLinux—x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-446428.1—PiwigoPiwigoCWE-89Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrad…
CVE-2026-517738.1—n/an/aCWE-918An issue in the VMware datastore driver of OpenStack glance_store. When an au…
CVE-2026-975708.1—LinuxLinux—bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-975738.1—LinuxLinux—bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-978758.1—rojo-rbxrojoCWE-350DNS rebinding vulnerability in rojo serve HTTP API
CVE-2026-980698.1—LinuxLinux—net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-980708.1—LinuxLinux—net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-981308.1—LinuxLinux—sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-791537.8—n/an/aCWE-269Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access co…
CVE-2026-918377.8—GNOMENetworkManager-iodineCWE-78Networkmanager-iodine: networkmanager-iodine: local privilege escalation to r…
CVE-2026-918387.8—GNOMENetworkManager-sstpCWE-78Networkmanager-sstp: networkmanager-sstp: local privilege escalation to root …
CVE-2026-918397.8—GNOMENetworkManager-fortisslvpnCWE-93Networkmanager-fortisslvpn: networkmanager-fortisslvpn: local privilege escal…
CVE-2026-918407.8—GNOMENetworkManager-vpncCWE-93Networkmanager-vpnc: networkmanager-vpnc: local privilege escalation to root …
CVE-2026-918417.8—GNOMENetworkManager-vpncCWE-93Networkmanager-vpnc: networkmanager-vpnc: incomplete fix for cve-2018-10900 a…
CVE-2026-975487.8—LinuxLinux—xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-975757.8—LinuxLinux—media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-975767.8—LinuxLinux—media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-975777.8—LinuxLinux—media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity
CVE-2026-975787.8—LinuxLinux—media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
CVE-2026-975797.8—LinuxLinux—media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity
CVE-2026-975807.8—LinuxLinux—media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-975847.8—LinuxLinux—afs: Fix incorrect free in candidate cleanup in afs_lookup_server()
CVE-2026-975947.8—LinuxLinux—landlock: Fix use-after-free of the source's parent directory
CVE-2026-976027.8—LinuxLinux—inet: frags: invalidate queues before flushing them
CVE-2026-976117.8—LinuxLinux—net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-976127.8—LinuxLinux—net: mpls: clear inner_protocol when the last label is popped
CVE-2026-979037.8—LinuxLinux—exit: hold a reference to thread_pid across proc_flush_pid
CVE-2026-979107.8—LinuxLinux—ASoC: sprd: validate compress buffer sizes against fixed allocations
CVE-2026-979117.8—LinuxLinux—accel: ethosu: Ensure SRAM region size matches job
CVE-2026-979377.8—LinuxLinux—ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-979407.8—LinuxLinux—ipv6: fix fib6 walker UAF on seq stop
CVE-2026-979417.8—LinuxLinux—mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-979717.8—LinuxLinux—nstree: check listing permission before taking a namespace reference
CVE-2026-979917.8—LinuxLinux—vdpa_sim_blk: reject out-of-range sector starts
CVE-2026-980027.8—LinuxLinux—iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-980177.8—LinuxLinux—net/sched: defer qdisc freeing after failed creation
CVE-2026-980237.8—LinuxLinux—vxlan: reject dynamic fdb entries that reference a nexthop id
CVE-2026-980527.8—LinuxLinux—net: bcmasp: clear txcb->last before writing each descriptor
CVE-2026-980737.8—LinuxLinux—net: Remove conflicting altnames for dying netns in __dev_change_net_namespac…
CVE-2026-981127.8—LinuxLinux—ksmbd: fix listener task lifetime on netdev events
CVE-2026-981167.8—LinuxLinux—ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
CVE-2026-981227.8—LinuxLinux—vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
CVE-2026-981437.8—LinuxLinux—accel: ethosu: Don't read the U65 rounding mode as a storage mode
CVE-2026-981567.8—LinuxLinux—drm/virtio: use the DMA API for resource backing on Xen
CVE-2026-494707.7—glpi-projectglpiCWE-307GLPI: Missing Rate Limiting on Login and TOTP Verification — Account Takeover…
CVE-2026-672397.6—rabbitmqrabbitmq-serverCWE-79RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI
CVE-2026-848937.6—IBMGuardium Data ProtectionCWE-89IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-52677.5—CienaNavigator NCSCWE-306Unauthenticated Event Stream Exposure of Session Tokens in Navigator NCS
CVE-2026-107587.5—EsriLercCWE-190Esri Lerc has a security vulnerability
CVE-2026-498507.5—InvoicePlaneInvoicePlaneCWE-22InvoicePlane: Missing CSRF Protection on State-Changing delete Actions
CVE-2026-505477.5—InvoicePlaneInvoicePlaneCWE-22InvoicePlane permits local file inclusion through the e-invoice XML configura…
CVE-2026-526227.5—n/an/aCWE-200An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Termi…
CVE-2026-536107.5—glpi-projectglpiCWE-79GLPI: Reflected XSS in dashboards
CVE-2026-536257.5—glpi-projectglpiCWE-862GLPI: Privilege Escalation via authtype API manipulation
CVE-2026-574437.5—issdandavisSCBE-AETHERMOORECWE-306SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email…
CVE-2026-672377.5—rabbitmqrabbitmq-serverCWE-79RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint
CVE-2026-848827.5—IBMGuardium Data ProtectionCWE-22IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-848847.5—IBMGuardium Data ProtectionCWE-256IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-850297.5—IBMGuardium Data ProtectionCWE-22IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-880037.5—InvoicePlaneInvoicePlaneCWE-863InvoicePlane: Failure to Revoke Administrative Privileges After Role Downgrade
CVE-2026-884217.5—n/an/aCWE-284Incorrect access control in the BlogPage.get_entries() component of APSL pupu…
CVE-2026-917657.5—PHP GroupPHPCWE-674SOAP: Unbounded Recursion in Server-Side cleanup_xml_node
CVE-2026-975237.5—LinuxLinux—mptcp: close race between scheduler and state change
CVE-2026-975247.5—LinuxLinux—mptcp: avoid unneeded actions on subflow reset
CVE-2026-975317.5—LinuxLinux—scsi: qla2xxx: Skip vport under deletion in report ID acquisition
CVE-2026-975367.5—LinuxLinux—scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown
CVE-2026-975577.5—LinuxLinux—smb: client: avoid leaking refcount in cifs_queue_oplock_break()
CVE-2026-975627.5—LinuxLinux—smb: client: pin DFS superblock in iterator callback
CVE-2026-975837.5—LinuxLinux—afs: Clear stale peer app data after address list changes
CVE-2026-975957.5—LinuxLinux—mac802154: fix use-after-free of sdata via queued RX frames
CVE-2026-979907.5—LinuxLinux—vdpa_sim_net: check TX pull result before RX copy
CVE-2026-980507.5—LinuxLinux—mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context
CVE-2026-980567.5—LinuxLinux—nvme: remove stale namespaces by NSID range during scan
CVE-2026-981087.5—LinuxLinux—Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan
CVE-2026-1002087.5—MicrosoftMicrosoft 365 Apps for EnterpriseCWE-190Microsoft Office Outlook Remote Code Execution Vulnerability
CVE-2026-980967.4—LinuxLinux—ipv6: sr: restore network header before routing and forwarding
CVE-2026-1003107.3—GNUlibextractorCWE-426GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
CVE-2026-1004197.3—GitoxideLabsgitoxideCWE-59gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink
CVE-2026-336397.2—InvoicePlaneInvoicePlaneCWE-89InvoicePlane permits DDL injection through tax_rate_decimal_places
CVE-2026-423237.2—PiwigoPiwigoCWE-89Piwigo: SQL Injection in Batch Manager
CVE-2026-423247.2—PiwigoPiwigoCWE-89Piwigo: Second-Order SQL Injection
CVE-2026-848627.2—IBMGuardium Data ProtectionCWE-502IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-857507.2—PiwigoPiwigoCWE-20Piwigo arbitrary file read and remote code execution via insecure image proce…
CVE-2026-1003877.2—pgpointcloudpointcloudCWE-125pgPointcloud through 1.2.5 heap out-of-bounds read via WKB deserialization
CVE-2026-536267.1—glpi-projectglpiCWE-639GLPI: Arbitrary Document Read via Form Context Authorization Bypass
CVE-2026-536297.1—glpi-projectglpiCWE-89GLPI: SQL injection in history tab
CVE-2026-567237.1—zammadzammadCWE-863Zammad: Missing authorization on ticket attachment download
CVE-2026-567247.1—zammadzammadCWE-639Zammad: Incorrect implementation of permission checks in the knowledge base m…
CVE-2026-567277.1—zammadzammadCWE-287Zammad: PGP signature spoofing via unvalidated verification return
CVE-2026-574497.1—actualbudgetactualCWE-200Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Priva…
CVE-2026-674087.1—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-P…
CVE-2026-674197.1—rabbitmqrabbitmq-serverCWE-407RabbitMQ: Consecutive topic wildcards cause combinatorial routing work
CVE-2026-844647.1—zammadzammadCWE-200Zammad: IDOR in External Data Source rendering exposes ticket, user, group, a…
CVE-2026-844657.1—zammadzammadCWE-290Zammad: S/MIME signature verification allows forged sender impersonation
CVE-2026-933067.1—IBMServer FirmwareCWE-125This Power System update is being released to address
CVE-2026-933657.1—BluditBludit CMSCWE-862Bludit CMS 3.22.0 Missing Authorization via content-get-list AJAX Endpoint
CVE-2026-975897.0—LinuxLinux—s390/crypto: Fix wrong return code to engine in asynch callbacks
CVE-2026-976087.0—LinuxLinux—netfilter: nf_log: unregister loggers before per-net teardown
CVE-2026-976097.0—LinuxLinux—netfilter: cttimeout: prevent UAF during module unload
CVE-2026-979267.0—LinuxLinux—ufs: validate cylinder group metadata before caching it
CVE-2026-979317.0—LinuxLinux—ALSA: us122l: Prevent write upgrades for read mappings
CVE-2026-979537.0—LinuxLinux—net: stmmac: fix TX descriptor availability check for TSO traffic
CVE-2026-980277.0—LinuxLinux—net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size
CVE-2026-980297.0—LinuxLinux—eth: nfp: bound the ntuple rule dump by the caller's buffer size
CVE-2026-980307.0—LinuxLinux—net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size
CVE-2026-980417.0—LinuxLinux—bpf: Don't predict JMP32 pointer vs zero comparisons
CVE-2026-980837.0—LinuxLinux—btrfs: fix transaction use-after-free in raid stripe insertion
CVE-2026-981507.0—LinuxLinux—bpf: Fix BPF_F_CPU validation for sparse CPU IDs
CVE-2026-981547.0—LinuxLinux—nvme-rdma: fix -EIO cleanup order in queue_rq
CVE-2026-175456.9—PHP GroupPHPCWE-67PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O…
CVE-2026-632076.9—zammadzammadCWE-200Zammad: Sensitive Information Exposure in Integration Administration API
CVE-2026-672266.9—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list
CVE-2026-844616.9—zammadzammadCWE-203Zammad: Missing rate limiting allows password brute-forcing during two-factor…
CVE-2026-968756.9—The Wikimedia FoundationMediawiki - Cargo extensionCWE-79Reflected XSS in Cargo Drilldown hierarchy filters
CVE-2026-968766.9—The Wikimedia FoundationMediawiki - Cargo extensionCWE-79Anonymous reflected XSS in CargoExport invalid-alias errors
CVE-2026-968776.9—The Wikimedia FoundationMediawiki - Cargo extensionCWE-79Reflected XSS through Cargo Drilldown full-text search
CVE-2026-968786.9—The Wikimedia FoundationMediawiki - Cargo extensionCWE-79Cargo Exhibit field alias allows stored XSS
CVE-2026-968796.9—The Wikimedia FoundationMediawiki - FlaggedRevs extensionCWE-212"Checked by" label in page history should not be shown if the underlying revi…
CVE-2026-978656.9—n/aOpen-Web-AnalyticsCWE-20Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deseri…
CVE-2026-1001876.9—ail projectail frameworkCWE-20AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Byp…
CVE-2026-1001926.9—yzcheng90X-SpringBootCWE-306X-SpringBoot through 6.0 Credential Exposure via Unauthenticated Endpoint
CVE-2026-1003066.9—TDuckCloudtduck-survey-formCWE-602TDuck survey form through 6.0 Write Password Bypass via Client-Side Enforcement
CVE-2026-1003776.9—Wikimedia FoundationMediawiki - WikiLambda ExtensionCWE-200Revision-deleted pages can be viewed through WikiLambda's action=edit and Spe…
CVE-2026-1004186.9—pawelmalakflameCWE-200Flame through 2.4.0 Information Exposure via GET /api/config
CVE-2026-804316.8—Kovid GoyalkittyCWE-787Out-of-bounds write in the kitty text sizing protocol allows termination of t…
CVE-2025-141816.5—PHP GroupPHPCWE-190Integer overflow to buffer overflow in soap HTTP parsing
CVE-2026-634316.5—horillahorilla-hrCWE-862Horilla: Missing Authorization on Payroll Component Views Exposes Employee Sa…
CVE-2026-634326.5—horillahorilla-hrCWE-94Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allo…
CVE-2026-852746.5—InvoicePlaneInvoicePlaneCWE-352InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Pro…
CVE-2026-852896.5—InvoicePlaneInvoicePlaneCWE-352InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints
CVE-2026-852916.5—InvoicePlaneInvoicePlaneCWE-639InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Withou…
CVE-2026-917676.5—PHP GroupPHPCWE-122Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server c…
CVE-2026-917686.5—PHP GroupPHPCWE-1023IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comp…
CVE-2026-930306.5—IBMIBM Financial Transaction Manager (FTM) for Redhat OpenShiftCWE-611FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive i…
CVE-2026-618376.3—rabbitmqrabbitmq-serverCWE-285RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology t…
CVE-2026-672236.3—rabbitmqrabbitmq-serverCWE-90RabbitMQ: LDAP DN injection via unescaped substitution
CVE-2026-672256.3—rabbitmqrabbitmq-serverCWE-770RabbitMQ: Stream-protocol frame length never validated against frame_max
CVE-2026-672306.3—rabbitmqrabbitmq-serverCWE-770RabbitMQ: Web-STOMP unbounded pre-auth accumulation
CVE-2026-672426.3—rabbitmqrabbitmq-serverCWE-613RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp
CVE-2026-844636.3—zammadzammadCWE-79Zammad: Stored HTML injection in Knowledge Base video widget enables forced s…
CVE-2026-1001776.3—ail projectail frameworkCWE-20Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Org…
CVE-2026-1001906.3—ail projectail frameworkCWE-79Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework…
CVE-2026-183116.1—ReadwiseReaderCWE-79CVE-2026-18311
CVE-2026-183126.1—ReadwiseReaderCWE-79CVE-2026-18312
CVE-2026-183206.1—ReadwiseReaderCWE-79CVE-2026-18320
CVE-2026-789026.1—n/an/aCWE-79Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows …
CVE-2026-1002376.1—The Wikimedia FoundationMediawiki - Thanks ExtensionCWE-79Stored i18n XSS in the Flow integration of Thanks
CVE-2026-536276.0—glpi-projectglpiCWE-862GLPI: Unexpected access to update operations through the API
CVE-2026-547906.0—InvoicePlaneInvoicePlaneCWE-89InvoicePlane: Second-order SQL injection through the unvalidated custom_field…
CVE-2026-660716.0—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values
CVE-2026-660736.0—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Atom table exhaustion via management API node field
CVE-2026-674116.0—rabbitmqrabbitmq-serverCWE-863RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permissi…
CVE-2026-674126.0—rabbitmqrabbitmq-serverCWE-862RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost …
CVE-2026-674136.0—rabbitmqrabbitmq-serverCWE-1333RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker …
CVE-2026-804326.0—Kovid GoyalkittyCWE-862Missing authorization in the kitty drag and drop protocol allows a client to …
CVE-2026-1003046.0—TDuckCloudtduck-survey-formCWE-636TDuck survey form 6.0 Information Disclosure via Fail-Open Form Ownership Check
CVE-2026-536285.9—glpi-projectglpiCWE-285GLPI: Unallowed authentication method update by administrator
CVE-2026-672225.9—rabbitmqrabbitmq-serverCWE-400RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client
CVE-2026-672275.9—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Atom exhaustion: to_atom on global-parameter :name
CVE-2026-674155.9—rabbitmqrabbitmq-serverCWE-400RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Den…
CVE-2026-860665.9—horillahorilla-hrCWE-352Horilla attendance approval endpoint is vulnerable to cross-site request forgery
CVE-2026-917665.9—PHP GroupPHPCWE-200Cross-origin credential leak in HTTP stream wrapper redirects
CVE-2026-928425.9—PHP GroupPHPCWE-122OOB read / info leak in convert.* stream filters when line-break-chars contai…
CVE-2026-1005025.9—pawelmalakflameCWE-613Flame through 2.4.0 Admin Token Insufficient Session Expiration
CVE-2026-936825.8—PHP GroupPHPCWE-125Out-of-bounds read in the HTTP stream wrapper when following a redirect with …
CVE-2026-958355.6—Kovid GoyalkittyCWE-862Missing ownership check on the shared memory object named by the kitty askpas…
CVE-2026-972225.5—GNOMEGnumericCWE-416Gnumeric: gnumeric: heap use-after-free when opening a malformed workbook
CVE-2026-978645.5—GibbonEduGibbonCWE-287GibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authe…
CVE-2026-978715.5—ZhonglunCloudPosCWE-74Zhonglun CloudPos JSBridge JSBridge.cs OpenLocalBrowser code injection
CVE-2026-978775.5—zhistareduStarTrainingCWE-255zhistaredu StarTraining JWT Token application.yml UserLoginService.createToke…
CVE-2026-978785.5—zhistareduStarTrainingCWE-287zhistaredu StarTraining Druid Console index.html anonymous missing authentica…
CVE-2026-978795.5—zhistareduStarTrainingCWE-287zhistaredu StarTraining api-docs Endpoint SecurityConfig.java missing authent…
CVE-2026-978825.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project Faculty Authentication loginlinkfacul…
CVE-2026-978835.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updatequery.php sql injection
CVE-2026-978855.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updatefaculty.php sql injection
CVE-2026-458015.3—glpi-projectglpiCWE-269GLPI: Unauthorized Debug Mode Activation via Profile Update (Privilege Escala…
CVE-2026-552175.3—glpi-projectglpiCWE-285GLPI: Unallowed modfication of knowbase items comments and translations
CVE-2026-567285.3—zammadzammadCWE-200Zammad: Cross-User Taskbar Item Access Control Vulnerability
CVE-2026-567325.3—zammadzammadCWE-20Zammad: Malicious input in Ticket Body Enables Session Termination
CVE-2026-567345.3—zammadzammadCWE-918Zammad: Avatar Image URL Server-Side Request Forwarding
CVE-2026-567355.3—zammadzammadCWE-82Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad
CVE-2026-618555.3—zammadzammadCWE-347Zammad: Invalid PGP Detached Signatures Reported as Good Signature on Inbound…
CVE-2026-630065.3—zammadzammadCWE-22Zammad: HTML sanitizer API path allowlist bypass via interior path traversal …
CVE-2026-632065.3—zammadzammadCWE-20Zammad: Remote image tracking bypass via shortened URL scheme
CVE-2026-632165.3—zammadzammadCWE-80Zammad: Stored XSS via unescaped option labels in the object attribute option…
CVE-2026-844605.3—zammadzammadCWE-639Zammad: Missing Authorization in TagsController#list Allows Cross-Object Tag …
CVE-2026-852905.3—InvoicePlaneInvoicePlaneCWE-117InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging
CVE-2026-933635.3—payloadcmspayloadCWE-862Payload CMS storage-vercel-blob Adapter Improper Access Control on Upload Route
CVE-2026-933645.3—BluditBludit CMSCWE-915Bludit CMS 3.22.0 Mass Assignment Privilege Escalation via Pages::edit()
CVE-2026-933665.3—BluditBludit CMSCWE-639Bludit CMS 3.22.0 Authorization Bypass via list-images/delete-image AJAX Endp…
CVE-2026-1002305.3—input-leapInput LeapCWE-180Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag…
CVE-2026-1003035.3—TDuckCloudtduck-survey-formCWE-862TDuck survey form through 6.0 Missing Authorization in Form Theme Management …
CVE-2026-1003055.3—TDuckCloudtduck-survey-formCWE-862TDuck survey form through 6.0 Fill-In Restriction Bypass via Authenticated Su…
CVE-2026-1003785.3—Wikimedia FoundationMediawiki - Translate ExtensionCWE-862Missing permission check in the Translate sandbox doRemind action
CVE-2026-1003795.3—Wikimedia FoundationWikipedia Android AppCWE-200Cross-request disclosure of CentralAuth cookies in Wikipedia Android App
CVE-2026-1003805.3—Wikimedia FoundationMediawiki - Wikibase ExtensionCWE-79Reflected XSS in Wikibase Special:SetLabel language validation
CVE-2026-1003815.3—Wikimedia FoundationMediawiki - UploadWizard ExtensionCWE-79UploadWizard Flickr collection and set titles allow DOM XSS
CVE-2026-1003885.3—rustdeskrustdeskCWE-862RustDesk before 1.5.0 Missing Authorization Check on Incoming File Clipboard …
CVE-2026-567265.1—zammadzammadCWE-862Zammad: Missing authorization check in GitHub + GitLab integration allows cro…
CVE-2026-632055.1—zammadzammadCWE-639Zammad: Channel admins can read unauthorized attachments via signature rich-t…
CVE-2026-632085.1—zammadzammadCWE-116Zammad: Microsoft Graph error logs expose partially masked OAuth access tokens
CVE-2026-674075.1—rabbitmqrabbitmq-serverCWE-862RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not e…
CVE-2026-978975.1—Krayinlaravel-crmCWE-79Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting
CVE-2026-1001745.1—ail projectail frameworkCWE-79Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped…
CVE-2026-1003735.1—open-metadataOpenMetadataCWE-918OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass
CVE-2026-393724.9—InvoicePlaneInvoicePlaneCWE-200InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata i…
CVE-2026-278674.8—TeldatRegesta Smart HD-PLC - TLDPH16D2CWE-79CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC O…
CVE-2026-672414.8—rabbitmqrabbitmq-serverCWE-862RabbitMQ: AMQP 1.0 management exchange.declare skips alternate-exchange permi…
CVE-2026-852924.8—InvoicePlaneInvoicePlaneCWE-697InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-…
CVE-2026-852934.8—InvoicePlaneInvoicePlaneCWE-79InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice a…
CVE-2026-1003764.8—Wikimedia FoundationMediawiki - TemplateSandbox ExtensionCWE-79TemplateSandbox can be abused for XSS by asking another user to preview a pag…
CVE-2026-1003834.8—Wikimedia FoundationMediawiki - WikiLambda ExtensionCWE-79Stored i18n XSS in WikiLambda's VisualEditor integration
CVE-2026-494694.6—glpi-projectglpiCWE-90GLPI: LDAP filter injection in user import feature
CVE-2026-674064.6—rabbitmqrabbitmq-serverCWE-200RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Pla…
CVE-2026-804304.6—Kovid GoyalkittyCWE-59Improper link resolution in the kitty drag and drop protocol allows a client …
CVE-2026-958344.6—Kovid GoyalkittyCWE-416Use after free in the kitty drag and drop protocol when a drag source item is…
CVE-2026-674214.5—rabbitmqrabbitmq-serverCWE-862RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling
CVE-2026-61034.3—PHP GroupPHPCWE-190Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection
CVE-2026-917694.3—PHP GroupPHPCWE-297TLS Hostname Verification Falls Back to CN After SAN Mismatch
CVE-2026-974694.3—DALIBOPostgreSQL AnonymizerCWE-328PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink
CVE-2025-12183.4—PHP GroupPHPCWE-122Various packet overreads in mysqlnd_writeprotocol.c
CVE-2026-978662.9—ZhonglunCloudPOSCWE-300Zhonglun CloudPOS Automatic Update Program.cs channel accessible
CVE-2026-972282.7—Rapid7PlatformCWE-943Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup
CVE-2026-632042.3—zammadzammadCWE-639Zammad: Authenticated agents can read AI summary error messages from inaccess…
CVE-2026-658282.3—zammadzammadCWE-862Zammad: Pending upload deletion bypass via legacy attachment endpoint
CVE-2026-672342.3—rabbitmqrabbitmq-serverCWE-20RabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism pre…
CVE-2026-674202.3—rabbitmqrabbitmq-serverCWE-862RabbitMQ OAuth credential refresh retains revoked runtime tags
CVE-2026-968742.3—The Wikimedia FoundationMediawiki - Cargo extensionCWE-79Stored XSS in Cargo Drilldown tab names
CVE-2026-1004172.3—rustdeskrustdeskCWE-862RustDesk before 1.5.0 One-Way File Transfer Bypass
CVE-2026-567292.1—zammadzammadCWE-200Zammad: Titles of knowledge base answers will be shown across all categories …
CVE-2026-567302.1—zammadzammadCWE-862Zammad: Missing authorization in GraphQL mutation for suggesting knowledge ba…
CVE-2026-660782.1—rabbitmqrabbitmq-serverCWE-862RabbitMQ: protected tag bypass via bulk-delete
CVE-2026-978842.1—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project Student Update Functionality updatest…
CVE-2026-978862.1—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project managevideos2.php sql injection
CVE-2026-978952.1—krayinlaravel-crmCWE-266krayin laravel-crm User Management UserController.php privileges management
CVE-2026-978682.0—sheshbabuzenCWE-79sheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site …
CVE-2026-978962.0—krayinlaravel-crmCWE-79krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross sit…
CVE-2026-978691.2—n/alangchain4jCWE-20langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticS…
CVE-2026-51772await—n/an/a—A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v…
CVE-2026-88389await—n/an/a—Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerabil…
CVE-2026-88420await—n/an/a—A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.sav…
CVE-2026-97522await—LinuxLinux—mptcp: fix bad accounting in __mptcp_subflow_push_pending()
CVE-2026-97526await—LinuxLinux—s390/pai: Support CPU hotplug for PMU PAI
CVE-2026-97529await—LinuxLinux—scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[]
CVE-2026-97530await—LinuxLinux—scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature
CVE-2026-97532await—LinuxLinux—scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path
CVE-2026-97533await—LinuxLinux—x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF
CVE-2026-97534await—LinuxLinux—f2fs: accurately adjust free_sections during free_segment_range
CVE-2026-97535await—LinuxLinux—scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size
CVE-2026-97537await—LinuxLinux—scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking
CVE-2026-97538await—LinuxLinux—hwmon: (asus_rog_ryujin) Validate HID report lengths
CVE-2026-97539await—LinuxLinux—usb: xusbatm: don't rely on id table pointer arithmetic
CVE-2026-97540await—LinuxLinux—net: usb: pegasus: don't rely on id table pointer arithmetic
CVE-2026-97541await—LinuxLinux—wifi: ath9k_htc: don't store usb_device_id
CVE-2026-97542await—LinuxLinux—xfs: bail out on bitmap errors in xrep_agfl_fill
CVE-2026-97543await—LinuxLinux—xfs: destroy seen inode bitmap when we fail to add a dirpath
CVE-2026-97544await—LinuxLinux—xfs: don't leak dqacct if rhashtable insertion fails
CVE-2026-97545await—LinuxLinux—xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails
CVE-2026-97546await—LinuxLinux—xfs: don't spin forever on zero-length dirents when salvaging them
CVE-2026-97547await—LinuxLinux—xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
CVE-2026-97549await—LinuxLinux—xfs: fix under-reservation of blocks when repairing sf directories
CVE-2026-97550await—LinuxLinux—xfs: fix unit conversions in per_binval computation
CVE-2026-97551await—LinuxLinux—xfs: initialise args->total for parent pointer updates
CVE-2026-97552await—LinuxLinux—xfs: initialise error in xfs_defer_finish_one()

Results continue: ranks 401–681.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-25 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.