AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0094 59.3 —
AFFECTED Product Versions Fixed Laranode unspecified —
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
248 CVEs published, led by openclaw (79).
248 CVEs published September 26, 2026: 16 critical, 134 high, 87 medium, 10 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 223 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 13235 | 48214 | — | — |
| KEV catalog size | 1726 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3101 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 2114 | 6205 | 530 | 2638 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | +606 ▲ |
| microsoft | 1002 | 2901 | 203 | 1990 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | +533 ▲ |
| 518 | 2686 | 332 | 1050 | 1183 | 121 | 80 | 9 | 0.3 | 7.5 | .0027 | +117 ▲ | |
| red hat | 233 | 862 | 52 | 359 | 405 | 46 | 2 | 0 | 0.0 | 6.7 | .0037 | +23 ▲ |
| apple | 246 | 563 | 67 | 165 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0019 | +202 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -32 ▼ |
| canonical | 0 | 42 | 13 | 11 | 13 | 5 | 0 | 0 | 0.0 | 7.8 | .0019 | -15 ▼ |
| suse | 13 | 41 | 7 | 21 | 12 | 1 | 0 | 0 | 0.0 | 7.5 | .0039 | +8 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0046 | +51 ▲ |
| ubiquiti | 6 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | -17 ▼ |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 11 | 41 | 11 | 10 | 17 | 3 | 29 | 7 | 17.1 | 7.2 | .0040 | +4 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | -7 ▼ |
| f5 | 9 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | +9 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -7 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 137 | 649 | 148 | 275 | 208 | 16 | 33 | 2 | 0.3 | 7.5 | .0064 | -18 ▼ |
| mozilla | 113 | 301 | 102 | 126 | 73 | 0 | 9 | 0 | 0.0 | 8.8 | .0034 | +54 ▲ |
| gitlab | 24 | 100 | 7 | 24 | 58 | 11 | 5 | 3 | 3.0 | 5.3 | .0034 | +2 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | +9 ▲ |
| github | 6 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | +1 ▲ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | +1 ▲ |
| wordpress | 1 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0340 | -1 ▼ |
| go | 4 | 4 | 0 | 2 | 1 | 1 | 0 | 0 | 0.0 | 5.9 | .0034 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | -256 ▼ |
| ibm | 398 | 1017 | 196 | 467 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | +24 ▲ |
| adobe | 224 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | +126 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0046 | -16 ▼ |
| zohocorp | 27 | 37 | 6 | 24 | 7 | 0 | 0 | 0 | 0.0 | 8.1 | .0109 | +23 ▲ |
| solarwinds | 3 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | +3 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | -13 ▼ |
| servicenow | 5 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | +5 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 27 | 72 | 22 | 26 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0182 | +11 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -5 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | +18 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | +9 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0038 | +3 ▲ |
| abb | 2 | 9 | 1 | 5 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +2 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 195 | 366 | 31 | 170 | 143 | 22 | 2 | 1 | 0.3 | 7.2 | .0029 | +124 ▲ |
| sourcecodester | 63 | 232 | 0 | 0 | 138 | 94 | 0 | 0 | 0.0 | 5.5 | .0043 | +15 ▲ |
| openclaw | 82 | 215 | 4 | 109 | 81 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | +82 ▲ |
| nvidia | 51 | 185 | 21 | 127 | 37 | 0 | 0 | 0 | 0.0 | 7.8 | .0040 | -1 ▼ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | -27 ▼ |
| mongodb | 71 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | +39 ▲ |
| itsourcecode | 37 | 153 | 0 | 0 | 37 | 116 | 0 | 0 | 0.0 | 2.1 | .0033 | +7 ▲ |
| hewlett packard enterprise (hpe) | 139 | 148 | 17 | 77 | 48 | 6 | 1 | 1 | 0.7 | 7.2 | .0044 | +136 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9143 | 99.8 | 10.0 |
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-87902 | .1817 | 97.1 | 8.1 |
| CVE-2026-82329 | .1412 | 96.5 | 9.8 |
| CVE-2026-76460 | .1403 | 96.4 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-83549 | .1076 | 95.7 | 7.8 |
| CVE-2026-83548 | .0876 | 95.0 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9143 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-83548 | 10.0 | .0876 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-82222 | 10.0 | .0225 | |
| CVE-2026-82456 | 10.0 | .0173 | |
| CVE-2026-85978 | 10.0 | .0144 |
| Vendor | CVEs |
|---|---|
| linux | 2250 |
| microsoft | 1010 |
| oracle | 634 |
| 518 | |
| ibm | 414 |
| apple | 246 |
| red hat | 245 |
| adobe | 224 |
| dell | 196 |
| apache | 147 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 93 |
| Packagist | 15 |
| npm | 15 |
| PyPI | 14 |
| crates.io | 9 |
| Go | 2 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE-2026-87902 | WordPress | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1774 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1774 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1774 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1774 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1774 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1774 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1774 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1774 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1774 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1774 |
EXPLOIT PUBLISHED — CVE-2026-100310 (GNU libextractor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67615 (Apereo Foundation openEQUELLA). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92764 (opencve). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93349 (frictionlessdata frictionless-py). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-95811 (Lemonldap-NG-Handler). Public exploit reference added.
DUE DATE PASSED — CVE-2026-42016 (jfrog artifactory). CISA remediation deadline was September 25, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-42018 (jfrog artifactory). CISA remediation deadline was September 25, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-85102 (checkpoint Quantum Security Gateway). CISA remediation deadline was September 25, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-93616 (checkpoint Quantum Security Management). CISA remediation deadline was September 25, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-93952 (Arista Networks VeloCloud Orchestrator (VCO) On-Prem). CISA remediation deadline was September 25, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-94127 (F5 BIG-IP). CISA remediation deadline was September 25, 2026; still in catalog.
RESCORED — CVE-2025-39889 (Linux). CVSS 8.1 → 5.5 (NVD).
PATCH SHIPPED — CVE-2026-94367 (OpenEye Apex Network Video Recorder (NVR)). Fixed in Apex Network Video Recorder (NVR) 3.4.3.
How to read these box scores · glossary
248 CVEs published. 25 box scores, 223 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0094 59.3 —
AFFECTED Product Versions Fixed Laranode unspecified —
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N P H H H 7.7 .0058 45.4 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0043 34.6 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0041 33.0 —
AFFECTED Product Versions Fixed Request a Quote for WooCommerce unspecified —
TIMELINE Jul 28 Reserved by CNA Sep 26 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0035 25.9 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.2
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0035 25.9 —
AFFECTED Product Versions Fixed OpenClaw 2026.6.6 – 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0035 25.9 —
AFFECTED Product Versions Fixed OpenClaw 2026.3.25 – 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H H 7.7 .0035 25.7 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0034 25.2 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.7.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0033 23.3 —
AFFECTED Product Versions Fixed slack unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H L 8.7 .0032 22.4 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.7.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0031 20.9 —
AFFECTED Product Versions Fixed OpenClaw 2026.5.1 – 2026.7.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H H 7.7 .0030 20.7 —
AFFECTED Product Versions Fixed matrix 2026.2.2 – 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H L 8.7 .0030 20.4 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.7.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H N N 6.0 .0029 19.4 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H N N 6.0 .0028 18.6 —
AFFECTED Product Versions Fixed discord unspecified 2026.9.3
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0028 18.2 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 5.3 .0028 18.2 —
AFFECTED Product Versions Fixed OpenClaw 2026.5.2 – 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N L L 5.3 .0028 18.0 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0027 17.3 —
AFFECTED Product Versions Fixed whatsapp unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N N N L 2.3 .0027 16.6 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P L N H H H 7.7 .0026 16.4 —
AFFECTED Product Versions Fixed OpenClaw 2026.4.5 – 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0026 16.0 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0026 16.0 —
AFFECTED Product Versions Fixed slack unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0026 15.7 —
AFFECTED Product Versions Fixed OpenClaw unspecified 2026.8.1
TIMELINE Sep 26 Reserved by CNA Sep 26 Published (CNA: VulnCheck)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-100542 | 2.3 | 15.7 | OpenClaw | OpenClaw | CWE-400 | OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2 |
| CVE-2026-100567 | 8.9 | 15.1 | OpenClaw | OpenClaw | CWE-918 | OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname |
| CVE-2026-100568 | 8.7 | 14.7 | OpenClaw | OpenClaw | CWE-200 | OpenClaw before 2026.8.1 Unauthorized Command Job Access |
| CVE-2026-100548 | 6.0 | 14.7 | OpenClaw | OpenClaw | CWE-200 | OpenClaw before 2026.8.1 Credential Exposure via Embedding Fallback |
| CVE-2026-100559 | 8.6 | 14.5 | OpenClaw | OpenClaw | CWE-78 | OpenClaw before 2026.8.1 Command Injection via Escaped Newlines |
| CVE-2026-100561 | 8.6 | 14.5 | OpenClaw | OpenClaw | CWE-88 | OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper |
| CVE-2026-100544 | 8.7 | 14.2 | openclaw | voice-call | CWE-862 | openclaw voice-call before 2026.8.1 Authorization Bypass |
| CVE-2026-100586 | 8.7 | 14.2 | OpenClaw | OpenClaw | CWE-269 | OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind |
| CVE-2026-100587 | 8.7 | 14.2 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.7.1 Authorization Bypass via Codex Install |
| CVE-2026-100596 | 8.7 | 14.2 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration |
| CVE-2026-100525 | 5.3 | 14.1 | openclaw | diagnostics-prometheus | CWE-862 | OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass |
| CVE-2026-100528 | 5.9 | 14.0 | OpenClaw | OpenClaw | CWE-200 | OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint |
| CVE-2026-100594 | 7.1 | 13.7 | OpenClaw | OpenClaw | CWE-200 | OpenClaw before 2026.7.1 Authorization Bypass via trajectory export |
| CVE-2026-100595 | 7.1 | 13.7 | OpenClaw | OpenClaw | CWE-200 | OpenClaw before 2026.7.1 Authorization Bypass via diagnostics |
| CVE-2026-100557 | 8.7 | 13.2 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch |
| CVE-2026-100540 | 7.6 | 12.6 | openclaw | feishu | CWE-863 | OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account |
| CVE-2026-100574 | 8.2 | 12.5 | OpenClaw | OpenClaw | CWE-918 | OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS |
| CVE-2026-100578 | 7.2 | 12.2 | OpenClaw | OpenClaw | CWE-269 | OpenClaw before 2026.7.1 Authorization Bypass via chat.send |
| CVE-2026-100579 | 7.2 | 12.2 | OpenClaw | OpenClaw | CWE-639 | OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester |
| CVE-2026-100554 | 2.3 | 10.8 | OpenClaw | OpenClaw | CWE-613 | OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass |
| CVE-2026-15273 | 6.4 | 10.8 | Automatic.css | Automatic.css | CWE-79 | Automatic.css 4.0.0 - Unauthenticated Stored Cross-Site Scripting via REQUEST… |
| CVE-2026-100553 | 5.3 | 10.7 | OpenClaw | OpenClaw | CWE-863 | OpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpin |
| CVE-2026-100522 | 5.1 | 10.2 | Cotonti | Cotonti | CWE-79 | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter |
| CVE-2026-100582 | 7.1 | 9.9 | openclaw | msteams | CWE-862 | OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass |
| CVE-2026-100576 | 5.3 | 10.0 | OpenClaw | OpenClaw | CWE-918 | OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates |
| CVE-2026-100529 | 7.4 | 9.4 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer |
| CVE-2026-100545 | 6.0 | 9.4 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation |
| CVE-2026-100539 | 2.1 | 9.3 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Memory Access Control Bypass |
| CVE-2026-100566 | 6.9 | 9.0 | openclaw | line | CWE-863 | OpenClaw LINE before 2026.8.1 Access Control Inheritance |
| CVE-2026-100521 | 5.1 | 8.9 | Cotonti | Cotonti | CWE-79 | Cotonti through 1.0.0 Reflected XSS via search highlight parameter |
| CVE-2026-100555 | 7.1 | 8.5 | OpenClaw | OpenClaw | CWE-918 | OpenClaw before 2026.8.1 DNS Rebinding via attachment delivery |
| CVE-2026-100585 | 8.6 | 8.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel |
| CVE-2026-100312 | 2.1 | 8.0 | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection |
| CVE-2026-100311 | 2.0 | 7.8 | mathurvishal | CloudClassroom-PHP-Project | CWE-79 | mathurvishal CloudClassroom-PHP-Project Faculty Video Management managevideos… |
| CVE-2026-100550 | 5.3 | 7.6 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Authentication Bypass via Access Group |
| CVE-2026-100562 | 5.3 | 7.6 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Authorization Bypass via sessions.create |
| CVE-2026-100563 | 5.3 | 7.6 | OpenClaw | OpenClaw | CWE-1236 | OpenClaw before 2026.8.1 CSV Formula Injection via Session Labels |
| CVE-2026-100564 | 5.3 | 7.6 | OpenClaw | OpenClaw | CWE-1236 | OpenClaw before 2026.8.1 CSV Formula Injection via Attendance Export |
| CVE-2026-100523 | 5.1 | 7.5 | Cotonti | Cotonti | CWE-601 | Cotonti through 1.0.0 Open Redirect via message.php redirect parameter |
| CVE-2026-100537 | 2.3 | 7.5 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.8.1 Authentication Bypass via Active Memory |
| CVE-2026-100530 | 8.5 | 7.2 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.8.1 Exec Approval Directory Binding |
| CVE-2026-100583 | 5.3 | 7.0 | openclaw | discord | CWE-862 | OpenClaw Discord before 2026.7.1 Authorization Bypass |
| CVE-2026-100546 | 6.1 | 6.9 | OpenClaw | OpenClaw | CWE-362 | OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript |
| CVE-2026-100590 | 5.3 | 6.5 | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.7.1 Authorization Bypass via voice set |
| CVE-2026-98163 | await | 6.6 | Linux | Linux | — | cgroup: Avoid iteration of dying tasks with zero refcount |
| CVE-2026-100551 | 9.0 | 6.2 | OpenClaw | OpenClaw | CWE-295 | OpenClaw iOS Control UI TLS Pin Enforcement Bypass |
| CVE-2026-85081 | 7.5 | 6.0 | Unknown | File Manager | CWE-79 | Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass |
| CVE-2026-89237 | 6.8 | 5.9 | Unknown | Bluff Post | CWE-89 | Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name'… |
| CVE-2026-84097 | 6.5 | 4.8 | Unknown | wp-review-slider-pro | CWE-89 | WP Review Slider Pro < 12.7.12 - Subscriber+ SQLi via Stored Template Filter |
| CVE-2026-100591 | 5.3 | 4.4 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.7.1 Authentication Bypass via Active Memory |
| CVE-2026-100592 | 5.3 | 4.4 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming |
| CVE-2026-84095 | 8.0 | 4.3 | Unknown | wp-review-slider-pro | CWE-79 | WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import |
| CVE-2026-84096 | 8.0 | 4.3 | Unknown | wp-review-slider-pro | CWE-79 | WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Form Fields |
| CVE-2026-16591 | 7.2 | 3.7 | Unknown | WP Directory Kit | CWE-79 | WP Directory Kit < 1.5.8 - Listing Admin+ Stored XSS via Category and Locatio… |
| CVE-2026-92411 | 6.8 | 3.7 | Unknown | WP Delicious | CWE-79 | WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name |
| CVE-2026-96531 | 6.8 | 3.7 | Unknown | Optimole | CWE-79 | Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block |
| CVE-2026-19708 | 5.9 | 3.2 | Unknown | File Manager | CWE-200 | File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure |
| CVE-2026-11871 | 5.3 | 3.2 | Unknown | Team Members | CWE-200 | Team Showcase Supreme <= 9.2 - Unauthenticated Sensitive Data Disclosure via … |
| CVE-2026-100593 | 5.3 | 3.0 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.7.1 Authentication Bypass via activation |
| CVE-2026-100577 | 5.3 | 2.9 | OpenClaw | OpenClaw | CWE-918 | OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset |
| CVE-2026-96526 | 2.7 | 2.7 | Unknown | MCP Server for WordPress | CWE-200 | MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosu… |
| CVE-2026-96532 | 7.5 | 2.5 | Unknown | Testimonials Widget | CWE-862 | Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update |
| CVE-2026-96533 | 5.8 | 2.5 | Unknown | Testimonials Widget | CWE-918 | Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL |
| CVE-2026-100570 | 8.5 | 2.4 | OpenClaw | OpenClaw | CWE-88 | OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS |
| CVE-2026-96525 | 2.7 | 2.3 | Unknown | MCP Server for WordPress | CWE-862 | MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Del… |
| CVE-2026-100504 | 7.3 | 2.0 | NationalSecurityAgency | ghidra | CWE-787 | Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128 |
| CVE-2026-100547 | 6.8 | 1.9 | OpenClaw | OpenClaw | CWE-180 | OpenClaw before 2026.8.1 Authentication Bypass via File URL |
| CVE-2026-100524 | 5.3 | 1.8 | Cotonti | Cotonti | CWE-352 | Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager |
| CVE-2026-100503 | 4.8 | 1.5 | NationalSecurityAgency | ghidra | CWE-416 | Ghidra through 12.1.4 Heap Use-After-Free in Decompiler |
| CVE-2026-100569 | 6.8 | 1.5 | OpenClaw | OpenClaw | CWE-522 | OpenClaw before 2026.8.1 Credential Exposure via Endpoint Override |
| CVE-2026-100505 | 4.8 | 1.5 | NationalSecurityAgency | ghidra | CWE-125 | Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager |
| CVE-2026-100598 | 7.5 | 1.4 | OpenClaw | OpenClaw | CWE-346 | OpenClaw before 2026.7.1 Approval Binding Logic Error |
| CVE-2026-100573 | 4.8 | 1.0 | OpenClaw | OpenClaw | CWE-862 | OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback |
| CVE-2026-96524 | 8.8 | 0.8 | Unknown | MCP Server for WordPress | CWE-352 | MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF |
| CVE-2026-100584 | 5.4 | 0.7 | OpenClaw | OpenClaw | CWE-426 | OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows |
| CVE-2026-100597 | 8.8 | 0.2 | OpenClaw | OpenClaw | CWE-367 | OpenClaw before 2026.7.1 Path Traversal via Filesystem Race |
| CVE-2026-100581 | 6.8 | 0.1 | OpenClaw | OpenClaw | CWE-312 | OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension |
| CVE-2026-97163 | 10.0 | — | lomart.fr | UP plugin for Joomla | CWE-22 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP… |
| CVE-2026-82901 | 9.8 | — | themefic | Ultra Addons for Contact Form 7 | CWE-434 | Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Up… |
| CVE-2026-85984 | 9.8 | — | cyberlord92 | miniOrange OTP Login, Verification and SMS Notifications | CWE-287 | miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthent… |
| CVE-2026-94132 | 9.5 | — | acymailing.com | AcyMailing Enterprise extension for Joomla | CWE-434 | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in ma… |
| CVE-2026-97160 | 9.4 | — | lomart.fr | UP plugin for Joomla | CWE-94 | Joomla Extension - lomart.fr - Authenticated, privileged PHP command injectio… |
| CVE-2026-100706 | 9.4 | — | kyverno | kyverno | CWE-441 | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath |
| CVE-2026-100714 | 9.4 | — | froxlor | froxlor | CWE-88 | Froxlor before 2.3.12 Command Injection via letsencryptchallengepath |
| CVE-2026-100716 | 9.4 | — | froxlor | froxlor | CWE-59 | Froxlor before 2.3.12 Privilege Escalation via Symlink |
| CVE-2026-94130 | 9.3 | — | joomlaboat.com | YouTube Gallery extension for Joomla | CWE-89 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube … |
| CVE-2026-100720 | 9.3 | — | froxlor | froxlor | CWE-79 | Froxlor before 2.3.12 Stored XSS via SSL certificate issuer |
| CVE-2026-97161 | 9.2 | — | lomart.fr | UP plugin for Joomla | CWE-22 | Joomla Extension - lomart.fr - Various path traversal / file access vectors i… |
| CVE-2026-100606 | 9.2 | — | FlowiseAI | Flowise | CWE-287 | Flowise through 3.1.4 Authentication Bypass via SSO Email Match |
| CVE-2026-100607 | 9.2 | — | FlowiseAI | Flowise | CWE-287 | Flowise through 3.1.4 Authentication Bypass via Email-Only SSO |
| CVE-2026-100684 | 9.2 | — | budibase | server | CWE-287 | Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC |
| CVE-2026-100683 | 8.9 | — | budibase | server | CWE-89 | Budibase before 3.45.0 SQL Injection via column-rename DDL |
| CVE-2026-77203 | 8.8 | — | itthinx | Groups – Memberships and Access Control | CWE-269 | Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'group… |
| CVE-2026-100676 | 8.8 | — | stoatchat | stoatchat | CWE-693 | stoatchat before 0.15.5 Local Filesystem Read via SVG |
| CVE-2026-100603 | 8.7 | — | openclaw | clawhub | CWE-799 | ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports |
| CVE-2026-100608 | 8.7 | — | FlowiseAI | Flowise | CWE-862 | Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard |
| CVE-2026-100614 | 8.7 | — | Cap-go | capgo.app | CWE-639 | Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker |
| CVE-2026-100615 | 8.7 | — | Cap-go | capgo.app | CWE-269 | Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation |
| CVE-2026-100617 | 8.7 | — | Cap-go | capgo.app | CWE-862 | Cap-go capgo.app Authorization Bypass via channel_permission_overrides |
| CVE-2026-100618 | 8.7 | — | Cap-go | capgo.app | CWE-639 | Capgo App Icon Update Privilege Escalation via Service-Role Worker |
| CVE-2026-100619 | 8.7 | — | Cap-go | capgo.app | CWE-266 | Capgo OTA Manifest Poisoning via app_versions.manifest Bypass |
| CVE-2026-100622 | 8.7 | — | Cap-go | capgo.app | CWE-200 | capgo.app through 12.129.0 Cache Restoration of Deleted Bundles |
| CVE-2026-100623 | 8.7 | — | Cap-go | capgo.app | CWE-863 | Capgo Authentication Bypass via Direct PostgREST org_users Table Write |
| CVE-2026-100625 | 8.7 | — | Cap-go | capgo.app | CWE-441 | Capgo Build Upload Proxy Authorization Bypass via TUS Resource |
| CVE-2026-100628 | 8.7 | — | Cap-go | capgo.app | CWE-863 | capgo.app before 12.128.12 Authentication Bypass via apikey |
| CVE-2026-100631 | 8.7 | — | parse-community | parse-server | CWE-943 | Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection |
| CVE-2026-100644 | 8.7 | — | siyuan-note | siyuan | CWE-89 | SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath |
| CVE-2026-100656 | 8.7 | — | netty | netty | CWE-770 | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining |
| CVE-2026-100657 | 8.7 | — | netty | netty | CWE-772 | Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder |
| CVE-2026-100660 | 8.7 | — | netty | netty | CWE-770 | Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention |
| CVE-2026-100661 | 8.7 | — | netty | netty | CWE-400 | Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation |
| CVE-2026-100662 | 8.7 | — | netty | netty | CWE-400 | Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS |
| CVE-2026-100663 | 8.7 | — | netty | netty | CWE-20 | Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 |
| CVE-2026-100664 | 8.7 | — | netty | netty | CWE-20 | Netty 4.2.2 through 4.2.15 HTTP/1 Host Header Authority Confusion |
| CVE-2026-100665 | 8.7 | — | netty | netty | CWE-295 | Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass |
| CVE-2026-100669 | 8.7 | — | getgrav | grav | CWE-178 | Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass |
| CVE-2026-100670 | 8.7 | — | getgrav | grav | CWE-639 | Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass |
| CVE-2026-100672 | 8.7 | — | getgrav | grav | CWE-306 | grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure |
| CVE-2026-100682 | 8.7 | — | budibase | server | CWE-22 | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink |
| CVE-2026-100689 | 8.7 | — | gitpython-developers | GitPython | CWE-22 | GitPython before 3.1.62 Path Traversal via gitmodules path |
| CVE-2026-100690 | 8.7 | — | gohugoio | hugo | CWE-59 | Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks |
| CVE-2026-100692 | 8.7 | — | gohugoio | hugo | CWE-59 | Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots |
| CVE-2026-100700 | 8.7 | — | nodemailer | nodemailer | CWE-407 | nodemailer before 10.0.6 Denial of Service via addressparser |
| CVE-2026-100711 | 8.7 | — | froxlor | froxlor | CWE-613 | froxlor before 2.3.12 Authentication Bypass via Session Persistence |
| CVE-2026-100612 | 8.6 | — | Cap-go | capgo.app | CWE-639 | Capgo SSO Provider ID Authentication Bypass via Incomplete Migration |
| CVE-2026-100639 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL |
| CVE-2026-100640 | 8.6 | — | siyuan-note | siyuan | CWE-200 | SiYuan before v3.8.4 Clipboard Data Disclosure via IPC |
| CVE-2026-100641 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content |
| CVE-2026-100645 | 8.6 | — | siyuan-note | siyuan | CWE-79 | SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban |
| CVE-2026-100646 | 8.6 | — | siyuan-note | siyuan | CWE-346 | SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header |
| CVE-2026-100671 | 8.6 | — | getgrav | grav | CWE-200 | Grav before 2.0.25 Session Cookie Theft via Twig Sandbox |
| CVE-2026-100680 | 8.6 | — | budibase | server | CWE-200 | Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import |
| CVE-2026-100686 | 8.6 | — | budibase | server | CWE-269 | Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/glo… |
| CVE-2026-100693 | 8.6 | — | gohugoio | hugo | CWE-178 | Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass |
| CVE-2026-100633 | 8.5 | — | siyuan-note | siyuan | CWE-863 | SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations |
| CVE-2026-100643 | 8.5 | — | siyuan-note | siyuan | CWE-79 | SiYuan before v3.8.4 Stored XSS via Attribute View textarea |
| CVE-2026-100715 | 8.5 | — | froxlor | froxlor | CWE-59 | Froxlor before 2.3.12 Arbitrary File Deletion via Symlink |
| CVE-2026-100717 | 8.5 | — | froxlor | froxlor | CWE-93 | froxlor before 2.3.12 CRLF Injection via validateUrl userinfo |
| CVE-2026-100673 | 8.4 | — | getgrav | grav | CWE-79 | Grav Data Manager before 1.4.5 Stored XSS via item-detail view |
| CVE-2026-94131 | 8.3 | — | acymailing.com | AcyMailing extension for Joomla | CWE-89 | Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion i… |
| CVE-2026-97162 | 8.3 | — | lomart.fr | UP plugin for Joomla | CWE-89 | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin ext… |
| CVE-2026-100636 | 8.3 | — | siyuan-note | siyuan | CWE-22 | SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder |
| CVE-2026-100637 | 8.3 | — | siyuan-note | siyuan | CWE-73 | SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID |
| CVE-2026-100638 | 8.3 | — | siyuan-note | siyuan | CWE-73 | SiYuan before v3.8.4 Path Traversal via setNotebookIcon |
| CVE-2026-100653 | 8.3 | — | vllm-project | vllm | CWE-348 | vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation |
| CVE-2026-100678 | 8.3 | — | stoatchat | stoatchat | CWE-307 | stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting |
| CVE-2026-100685 | 8.3 | — | budibase | server | CWE-863 | Budibase before 3.45.0 Information Disclosure via Chat Links |
| CVE-2026-100703 | 8.3 | — | kyverno | kyverno | CWE-200 | Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib |
| CVE-2026-100704 | 8.3 | — | kyverno | kyverno | CWE-863 | Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass |
| CVE-2026-100705 | 8.3 | — | kyverno | kyverno | CWE-918 | Kyverno before 1.19.1 SSRF via legacy apiCall service executor |
| CVE-2026-100707 | 8.3 | — | kyverno | kyverno | CWE-22 | Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path |
| CVE-2026-100635 | 8.2 | — | siyuan-note | siyuan | CWE-319 | SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie |
| CVE-2026-100652 | 8.2 | — | vllm-project | vllm | CWE-20 | vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids |
| CVE-2026-100702 | 8.2 | — | nodemailer | nodemailer | CWE-674 | Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays |
| CVE-2026-100610 | 7.7 | — | FlowiseAI | Flowise | CWE-639 | Flowise through 3.1.4 Missing Authorization via upsert-history |
| CVE-2026-100709 | 7.7 | — | froxlor | froxlor | CWE-287 | Froxlor before 2.3.12 2FA Bypass via Namespace Confusion |
| CVE-2026-100609 | 7.6 | — | FlowiseAI | Flowise | CWE-639 | Flowise through 3.1.4 Insecure Direct Object Reference via Credential |
| CVE-2026-100605 | 7.5 | — | FlowiseAI | Flowise | CWE-862 | Flowise through 3.1.4 Missing Authorization via Chat Message Routes |
| CVE-2026-72668 | 7.3 | — | Elastic | Kibana | CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Pri… |
| CVE-2026-100627 | 7.2 | — | Cap-go | capgo.app | CWE-639 | Capgo bundle promotion API channel RBAC deny override bypass |
| CVE-2026-100642 | 7.2 | — | siyuan-note | siyuan | CWE-346 | SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth |
| CVE-2026-100602 | 7.1 | — | openclaw | clawhub | CWE-862 | ClawHub Changelog Preview Information Disclosure via Authorization Bypass |
| CVE-2026-100611 | 7.1 | — | Cap-go | capgo.app | CWE-269 | Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list |
| CVE-2026-100632 | 7.1 | — | parse-community | parse-server | CWE-200 | Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery |
| CVE-2026-100650 | 7.1 | — | vllm-project | vllm | CWE-400 | vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization |
| CVE-2026-100651 | 7.1 | — | vllm-project | vllm | CWE-400 | vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass |
| CVE-2026-100654 | 7.1 | — | vllm-project | vllm | CWE-129 | vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids |
| CVE-2026-100668 | 7.1 | — | getgrav | grav | CWE-200 | Grav before 2.0.25 Sandbox Escape via array Filter |
| CVE-2026-100675 | 7.1 | — | stoatchat | stoatchat | CWE-248 | stoatchat before 0.15.5 Denial of Service via mass mentions |
| CVE-2026-100679 | 7.1 | — | stoatchat | stoatchat | CWE-639 | stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket |
| CVE-2026-100688 | 7.1 | — | budibase | server | CWE-639 | Budibase server before 3.45.0 Cross-Tenant Information Disclosure |
| CVE-2026-100708 | 7.1 | — | froxlor | froxlor | CWE-200 | Froxlor before 2.3.13 Private Key Disclosure via Certificates API |
| CVE-2026-100712 | 7.1 | — | froxlor | froxlor | CWE-352 | froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF |
| CVE-2026-100713 | 7.1 | — | froxlor | froxlor | CWE-367 | Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync |
| CVE-2026-100718 | 7.1 | — | froxlor | froxlor | CWE-276 | Froxlor before 2.3.12 Authentication Bypass via EmailSender.add |
| CVE-2026-100719 | 7.1 | — | froxlor | froxlor | CWE-200 | Froxlor before 2.3.12 Credential Disclosure via DirProtections API |
| CVE-2026-100616 | 7.0 | — | Cap-go | capgo.app | CWE-863 | capgo.app Authentication Bypass via PostgREST customer_id Mutation |
| CVE-2026-100629 | 7.0 | — | Cap-go | capgo.app | CWE-863 | Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH |
| CVE-2026-100687 | 7.0 | — | budibase | server | CWE-200 | Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast |
| CVE-2026-100600 | 6.9 | — | openclaw | clawhub | CWE-770 | ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API |
| CVE-2026-100601 | 6.9 | — | openclaw | clawhub | CWE-918 | ClawHub SSRF via Unchecked DNS Resolution in Profile Image |
| CVE-2026-100647 | 6.9 | — | vllm-project | vllm | CWE-20 | vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt |
| CVE-2026-100648 | 6.9 | — | vllm-project | vllm | CWE-400 | vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding |
| CVE-2026-100655 | 6.9 | — | netty | netty | CWE-770 | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler |
| CVE-2026-100658 | 6.9 | — | netty | netty | CWE-770 | Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler |
| CVE-2026-100659 | 6.9 | — | netty | netty | CWE-444 | Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass |
| CVE-2026-100666 | 6.9 | — | netty | netty | CWE-444 | Netty 4.2.0 through 4.2.17 Response Desynchronization via HttpServerCodec |
| CVE-2026-100667 | 6.9 | — | getgrav | grav | CWE-304 | grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass |
| CVE-2026-100677 | 6.9 | — | stoatchat | stoatchat | CWE-209 | stoatchat before 0.15.5 Account Enumeration via Error Location |
| CVE-2026-100696 | 6.9 | — | vrana | adminer | CWE-918 | Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver |
| CVE-2026-100698 | 6.9 | — | vrana | adminer | CWE-918 | Adminer before 6.0.2 Privileged-Port SSRF via host_port Regex |
| CVE-2026-100699 | 6.9 | — | nodemailer | nodemailer | CWE-20 | Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment |
| CVE-2026-100710 | 6.9 | — | froxlor | froxlor | CWE-200 | Froxlor before 2.3.12 DKIM Private Key Disclosure via API |
| CVE-2026-78582 | 6.5 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Unauthorized Deletion of Data |
| CVE-2026-82294 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-82300 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-94396 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94397 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94398 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94399 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-94400 | 6.5 | — | Elastic | Kibana | CWE-400 | Uncontrolled Resource Consumption in Kibana Leading to denial of service |
| CVE-2026-72662 | 6.3 | — | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Unautho… |
| CVE-2026-100649 | 6.3 | — | vllm-project | vllm | CWE-770 | vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass |
| CVE-2026-100681 | 6.3 | — | budibase | server | CWE-918 | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook |
| CVE-2026-100613 | 6.0 | — | Cap-go | capgo.app | CWE-863 | capgo.app Authorization Bypass via Stale Channel Permission Overrides |
| CVE-2026-100701 | 6.0 | — | nodemailer | nodemailer | CWE-295 | Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion |
| CVE-2026-100314 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql inje… |
| CVE-2026-100315 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injection |
| CVE-2026-100739 | 5.5 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection |
| CVE-2026-100604 | 5.3 | — | openclaw | clawhub | CWE-863 | ClawHub Authentication Bypass via Former Publisher Skill Control |
| CVE-2026-100621 | 5.3 | — | Cap-go | capgo.app | CWE-284 | capgo.app Content-Lock Bypass via r2-direct Bundle Mutation |
| CVE-2026-100624 | 5.3 | — | Cap-go | capgo.app | CWE-613 | Capgo.app before 12.264.5 Upload Expiry Bypass via build upload |
| CVE-2026-100626 | 5.3 | — | Cap-go | capgo.app | CWE-639 | capgo through 12.128.2 IDOR via PUT /app icon endpoint |
| CVE-2026-100634 | 5.3 | — | siyuan-note | siyuan | CWE-862 | SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows |
| CVE-2026-100674 | 5.3 | — | stoatchat | stoatchat | CWE-180 | stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization |
| CVE-2026-100695 | 5.3 | — | vrana | adminer | CWE-79 | Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE |
| CVE-2026-100697 | 5.3 | — | vrana | adminer | CWE-918 | Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver |
| CVE-2026-100620 | 5.1 | — | Cap-go | @capgo/cli | CWE-269 | Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Cons… |
| CVE-2026-100630 | 5.1 | — | WWBN | AVideo | CWE-79 | AVideo Stored XSS via HTML Entity Bypass in trailer1 Field |
| CVE-2026-100691 | 5.1 | — | gohugoio | hugo | CWE-79 | Hugo before 0.166.0 Stored XSS via lineAnchors code block option |
| CVE-2026-100694 | 5.1 | — | gohugoio | hugo | CWE-79 | Hugo before 0.166.0 Cross-Site Scripting via text/org |
| CVE-2026-94408 | 4.9 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service |
| CVE-2026-100313 | 2.1 | — | mathurvishal | CloudClassroom-PHP-Project | CWE-79 | mathurvishal CloudClassroom-PHP-Project updatequery.php cross site scripting |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-26 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.