AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0263 85.0 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
314 CVEs published, led by Apache Software Foundation (20).
314 CVEs published September 28, 2026: 32 critical, 98 high, 136 medium, 38 low; 0 in the KEV catalog at press time; 10 with a public exploit reference; 10 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 289 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 13695 | 48675 | — | — |
| KEV catalog size | 1728 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3143 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 2114 | 6205 | 530 | 2638 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | +471 ▲ |
| microsoft | 1002 | 2901 | 203 | 1991 | 691 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | +525 ▲ |
| 520 | 2689 | 332 | 1051 | 1185 | 121 | 80 | 9 | 0.3 | 7.5 | .0027 | +118 ▲ | |
| red hat | 249 | 878 | 51 | 365 | 409 | 53 | 2 | 0 | 0.0 | 6.6 | .0037 | +27 ▲ |
| apple | 247 | 564 | 67 | 166 | 317 | 14 | 88 | 8 | 1.4 | 6.5 | .0019 | +203 ▲ |
| suse | 25 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0039 | +18 ▲ |
| canonical | 7 | 49 | 16 | 12 | 16 | 5 | 0 | 0 | 0.0 | 7.8 | .0019 | -8 ▼ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -32 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0046 | +51 ▲ |
| ubiquiti | 6 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | -17 ▼ |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 11 | 41 | 11 | 10 | 17 | 3 | 29 | 7 | 17.1 | 7.2 | .0040 | +4 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | -7 ▼ |
| f5 | 9 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | +9 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -7 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 157 | 669 | 151 | 282 | 216 | 16 | 33 | 2 | 0.3 | 7.5 | .0063 | -1 ▼ |
| mozilla | 113 | 301 | 102 | 126 | 73 | 0 | 9 | 0 | 0.0 | 8.8 | .0032 | +54 ▲ |
| gitlab | 24 | 100 | 7 | 23 | 60 | 10 | 5 | 3 | 3.0 | 5.3 | .0034 | -1 ▼ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | +9 ▲ |
| github | 6 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | +1 ▲ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | +1 ▲ |
| wordpress | 1 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0340 | -1 ▼ |
| kubernetes | 1 | 2 | 0 | 0 | 1 | 1 | 0 | 0 | 0.0 | 4.5 | .0035 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | -256 ▼ |
| ibm | 398 | 1017 | 195 | 468 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | +8 ▲ |
| adobe | 224 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | +123 ▲ |
| progress | 3 | 64 | 15 | 39 | 10 | 0 | 6 | 1 | 1.6 | 8.1 | .0046 | -16 ▼ |
| zohocorp | 32 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0109 | +28 ▲ |
| solarwinds | 3 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | +3 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | -13 ▼ |
| servicenow | 5 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 29 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0170 | +13 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -6 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | +15 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | +9 ▲ |
| abb | 4 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +4 ▲ |
| hikvision | 3 | 9 | 0 | 5 | 4 | 0 | 0 | 0 | 0.0 | 7.1 | .0038 | +3 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 199 | 370 | 31 | 171 | 146 | 22 | 2 | 1 | 0.3 | 7.2 | .0029 | +128 ▲ |
| sourcecodester | 63 | 232 | 0 | 0 | 138 | 94 | 0 | 0 | 0.0 | 5.5 | .0043 | +15 ▲ |
| openclaw | 82 | 215 | 4 | 109 | 81 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | +82 ▲ |
| nvidia | 51 | 185 | 21 | 127 | 37 | 0 | 0 | 0 | 0.0 | 7.8 | .0040 | -1 ▼ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | -91 ▼ |
| mongodb | 71 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | +16 ▲ |
| itsourcecode | 37 | 153 | 0 | 0 | 37 | 116 | 0 | 0 | 0.0 | 2.1 | .0033 | +7 ▲ |
| hewlett packard enterprise (hpe) | 139 | 148 | 17 | 77 | 48 | 6 | 1 | 1 | 0.7 | 7.2 | .0044 | +136 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9143 | 99.8 | 10.0 |
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-87902 | .2249 | 97.6 | 8.1 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.4 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-83549 | .1076 | 95.7 | 7.8 |
| CVE-2026-83548 | .0876 | 95.0 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9143 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-83548 | 10.0 | .0876 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2114 |
| microsoft | 1002 |
| oracle | 634 |
| 520 | |
| ibm | 398 |
| red hat | 255 |
| apple | 247 |
| adobe | 224 |
| dell | 200 |
| apache | 167 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 16 |
| 9 | |
| apple | 8 |
| fortinet | 7 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 93 |
| Packagist | 18 |
| npm | 15 |
| PyPI | 13 |
| crates.io | 9 |
| Go | 2 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE-2026-87902 | WordPress | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1776 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1776 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1776 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1776 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1776 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1776 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1776 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1776 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1776 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1776 |
EXPLOIT PUBLISHED — sooperset mcp-atlassian: 9 CVEs (CVE-2026-77246, CVE-2026-77247, CVE-2026-77253, CVE-2026-77254, CVE-2026-77266, CVE-2026-77270, CVE-2026-77271, CVE-2026-77272, CVE-2026-77274). Public exploit references added.
EXPLOIT PUBLISHED — mathurvishal CloudClassroom-PHP-Project: 7 CVEs (CVE-2026-100311, CVE-2026-100313, CVE-2026-100314, CVE-2026-100739, CVE-2026-100874, CVE-2026-100875, CVE-2026-100877). Public exploit references added.
EXPLOIT PUBLISHED — radareorg radare2: 5 CVEs (CVE-2026-81882, CVE-2026-81883, CVE-2026-81884, CVE-2026-81885, CVE-2026-81886). Public exploit references added.
EXPLOIT PUBLISHED — Unknown WPeMatico RSS Feed Fetcher: 4 CVEs (CVE-2026-89000, CVE-2026-89001, CVE-2026-89003, CVE-2026-89006). Public exploit references added.
EXPLOIT PUBLISHED — OISF suricata: 3 CVEs (CVE-2026-45747, CVE-2026-57225, CVE-2026-57226). Public exploit references added.
EXPLOIT PUBLISHED — vllm-project vllm: 3 CVEs (CVE-2026-73558, CVE-2026-73559, CVE-2026-93592). Public exploit references added.
EXPLOIT PUBLISHED — zhistaredu StarTraining: 3 CVEs (CVE-2026-100878, CVE-2026-100880, CVE-2026-100881). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-100740 (D-Link DIR-895L). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100745 (Edimax BR-6428nC). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100746 (coollabsio Coolify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100883 (Krayin laravel-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100884 (Krayin laravel-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100886 (Seetong T8108). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-73624 (gitpython-developers GitPython). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79759 (Termix-SSH Termix). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-81655 (Unknown Ad Inserter). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-82841 (Unknown UpdraftPlus: WP Backup & Migration Plugin). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-84069 (Unknown WebFacing™). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-85002 (Unknown EmbedPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86609 (Unknown Download Manager). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86839 (Unknown Online Scheduling and Appointment Booking System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86841 (Unknown Online Scheduling and Appointment Booking System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92436 (Unknown Mailchimp for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-92995 (Unknown Verge3D Publishing and E-Commerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-95847 (moquette-io moquette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-95848 (moquette-io moquette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96550 (sfturing hosp_order). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96602 (Abdurrab5 online-makeup-store). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96678 (weiqingwen spring-boot-forum). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96763 (kvcache-ai mooncake). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96777 (Forma LMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96882 (TaleLin lin-cms-spring-boot). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96895 (Unknown WP YouTube Lyte). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96896 (Unknown Malcure Malware Shield — Removal, Repair, Monitor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96897 (Unknown Optima Express IDX). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-96899 (Unknown Optima Express IDX). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97227 (Unknown NextScripts: Social Networks Auto-Poster). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97231 (volotat Anagnorisis). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97319 (Unknown PowerPress Podcasting plugin by Blubrry). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97359 (rejetto hfs2). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97647 (ningzichun student-management-system). Public exploit reference added.
DUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-71362 (Adobe Commerce). CISA remediation deadline was September 27, 2026; still in catalog.
REJECTED — CVE-2026-100655 (netty). Record withdrawn by the CNA.
REJECTED — CVE-2026-100656 (netty). Record withdrawn by the CNA.
REJECTED — CVE-2026-100657 (netty). Record withdrawn by the CNA.
REJECTED — CVE-2026-100658 (netty). Record withdrawn by the CNA.
DISPUTED — CVE-2026-93353 (9001 copyparty). Record marked disputed.
RESCORED — OISF suricata: 8 CVEs (CVE-2026-45751, CVE-2026-57225, CVE-2026-57226, CVE-2026-63448, CVE-2026-63449, CVE-2026-63450, CVE-2026-63451, CVE-2026-71855). CVSS rescored — before/after on each CVE page.
RESCORED — GitLab: 3 CVEs (CVE-2026-3855, CVE-2026-78252, CVE-2026-82837). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2026-100887 (amirsanni Mini-Inventory-and-Sales-Management-System). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2026-100888 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-100889 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-6730 (IBM Concert). CVSS 9.8 → 7.8 (NVD).
RESCORED — CVE-2026-77246 (sooperset mcp-atlassian). CVSS 7.4 → 8.6 (NVD).
RESCORED — CVE-2026-77272 (sooperset mcp-atlassian). CVSS 5.4 → 6.1 (NVD).
RESCORED — CVE-2026-77896 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD).
RESCORED — CVE-2026-78426 (SUSE neuvector). CVSS 3.7 → 2 (NVD).
RESCORED — CVE-2026-78427 (SUSE github.com/neuvector/neuvector). CVSS 4.3 → 5.3 (NVD).
RESCORED — CVE-2026-78428 (SUSE neuvector). CVSS 8 → 8.8 (NVD).
RESCORED — CVE-2026-81884 (radareorg radare2). CVSS 2.5 → 3.3 (NVD).
RESCORED — CVE-2026-93659 (concretecms-community-store community_store). CVSS 9.3 → 8.6 (NVD).
PATCH SHIPPED — elixir-mint mint: 3 CVEs (CVE-2026-91043, CVE-2026-92103, CVE-2026-94194). Fix versions published.
PATCH SHIPPED — CVE-2026-93990 (libexpat). Fixed in libexpat 2.8.5.
How to read these box scores · glossary
314 CVEs published. 25 box scores, 289 table rows — nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0263 85.0 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.5 .0234 82.9 —
AFFECTED Product Versions Fixed BaoTa 11.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0186 78.4 —
AFFECTED Product Versions Fixed N150RT 3.4.0-B20201030 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P H H H 8.5 .0176 77.2 —
AFFECTED Product Versions Fixed BaoTa 11.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P H H H 8.5 .0176 77.2 —
AFFECTED Product Versions Fixed BaoTa 11.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0167 75.9 —
AFFECTED Product Versions Fixed NBR200V2 1.3.241127.071246 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0080 55.0 —
AFFECTED Product Versions Fixed FAC1200R 5.0_20201119_1.0.2 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 7.7 .0080 54.9 —
AFFECTED Product Versions Fixed Eyeplus 57.0.0.0308 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 53.8 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Aug 28 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0067 50.1 —
AFFECTED Product Versions Fixed OpenARC 1.0.0.Beta1 – 1.0.0.Beta0
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0061 47.1 —
AFFECTED Product Versions Fixed UERANSIM 3.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0054 43.0 —
AFFECTED Product Versions Fixed UERANSIM 3.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0053 42.9 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Aug 28 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0050 40.5 —
AFFECTED Product Versions Fixed NBR100V2 1.3.240614.030928 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 6.9 .0050 40.2 —
AFFECTED Product Versions Fixed NotionNext 4.10.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H L 8.2 .0049 39.7 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Aug 28 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N L 5.5 .0046 37.6 —
AFFECTED Product Versions Fixed Mongoose 7.0 – 7.22
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L N N 5.5 .0045 36.9 —
AFFECTED Product Versions Fixed GEOritm 2.45.0 – 2.46
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0045 36.8 —
AFFECTED Product Versions Fixed VoceChat Server 0.5.0 – —
TIMELINE Sep 27 Reserved by CNA Sep 28 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N C H H H 9.0 .0042 33.9 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Aug 28 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0040 31.2 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Sep 7 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0040 31.2 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Sep 14 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0040 31.2 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Sep 14 Reserved by CNA Sep 28 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L A N N N 4.8 .0039 30.5 —
AFFECTED Product Versions Fixed Cloud Web application Actual Web Version – —
TIMELINE Apr 27 Reserved by CNA Sep 28 Published (CNA: INCIBE)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C L L L 7.4 .0037 28.7 —
AFFECTED Product Versions Fixed Apache Roller 6.1.5 – —
TIMELINE Aug 28 Reserved by CNA Sep 28 Published (CNA: apache)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-100890 | 5.5 | 28.6 | Trusted Domain Project | OpenDMARC | CWE-404 | Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv… |
| CVE-2026-82379 | 7.7 | 28.3 | Apache Software Foundation | Apache Roller | CWE-294 | Apache Roller: WSSE digest authentication headers can be replayed |
| CVE-2026-82348 | 7.7 | 27.8 | Apache Software Foundation | Apache Roller | CWE-639 | Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups |
| CVE-2026-86530 | 8.6 | 27.3 | BUFFALO INC. | WSR-300HP | CWE-78 | BUFFALO Wi-Fi products handle some web form input improperly to assemble comm… |
| CVE-2026-95104 | 8.7 | 26.9 | BUFFALO INC. | WSR-300HP | CWE-121 | Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A… |
| CVE-2026-100902 | 5.7 | 24.2 | Barco | ClickShare CX-20 Gen2 | CWE-20 | Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of… |
| CVE-2026-101018 | 2.0 | 23.8 | dayrui | XunruiCMS | CWE-74 | dayrui XunruiCMS Group Editing Home.php group_all_edit sql injection |
| CVE-2026-101016 | 5.5 | 23.0 | Trusted Domain Project | OpenDMARC | CWE-755 | Trusted Domain Project OpenDMARC opendmarc_policy.c opendmarc_policy_parse_dm… |
| CVE-2026-101017 | 5.5 | 23.0 | Trusted Domain Project | OpenDMARC | CWE-755 | Trusted Domain Project OpenDMARC opendmarc_policy.c strcasecmp exceptional co… |
| CVE-2026-101014 | 5.5 | 21.8 | Trusted Domain Project | OpenDMARC | CWE-189 | Trusted Domain Project OpenDMARC DMARC Record opendmarc_util.c opendmarc_util… |
| CVE-2026-100751 | 7.5 | 20.8 | regularlabs.com | Tabs & Accordions (Free, Pro) extension for Joomla | CWE-79 | Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url … |
| CVE-2026-7170 | 4.8 | 20.6 | TPVEnlanube | Cloud Web application | CWE-79 | Stored Cross-Site Scripting (XSS) in TPVEnlanube |
| CVE-2026-7171 | 4.8 | 20.6 | TPVEnlanube | Cloud Web application | CWE-79 | Stored Cross-Site Scripting (XSS) in TPVEnlanube |
| CVE-2026-100894 | 2.1 | 20.7 | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection |
| CVE-2026-100909 | 5.5 | 20.1 | n/a | OctoberCMS | CWE-918 | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery |
| CVE-2026-101005 | 5.5 | 20.1 | n/a | October CMS | CWE-918 | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server… |
| CVE-2026-82376 | 7.7 | 20.0 | Apache Software Foundation | Apache Roller | CWE-611 | Apache Roller: XML external entity processing in trackback response parser |
| CVE-2026-82915 | 6.5 | 19.9 | Bimser Solution Software Trade Inc. | eBA Plus Document and Workflow Management System | CWE-22 | Path Traversal in Bimser Solution Software's eBA Plus |
| CVE-2026-100891 | 5.5 | 19.7 | Trusted Domain Project | OpenDMARC | CWE-172 | Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_poli… |
| CVE-2026-101015 | 5.5 | 19.7 | Trusted Domain Project | OpenDMARC | CWE-20 | Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equiv… |
| CVE-2026-82386 | 7.7 | 19.5 | Apache Software Foundation | Apache Roller | CWE-611 | Apache Roller: XML external entity processing in OPML bookmark import |
| CVE-2026-100906 | 5.5 | 19.0 | n/a | Eyeplus | CWE-200 | Eyeplus ONVIF Device GetUsers information disclosure |
| CVE-2026-100907 | 5.5 | 19.0 | n/a | Eyeplus | CWE-200 | Eyeplus p2pcam Service snapshot information disclosure |
| CVE-2026-100901 | 5.5 | 18.2 | athlon1600 | youtube-downloader | CWE-918 | athlon1600 youtube-downloader stream.php stream server-side request forgery |
| CVE-2026-82380 | 8.1 | 18.0 | Apache Software Foundation | Apache Roller | CWE-352 | Apache Roller: CSRF protection bypass via self-generated salt validation |
| CVE-2026-82385 | 6.5 | 18.0 | Apache Software Foundation | Apache Roller | CWE-200 | Apache Roller: Weblog template include escapes the Velocity sandbox and reads… |
| CVE-2026-82546 | 6.1 | 18.0 | Apache Software Foundation | Apache Roller | CWE-79 | Apache Roller: Stored cross-site scripting through incoming Trackback links |
| CVE-2026-85134 | 8.8 | 16.8 | Bimser Solution Software Trade Inc. | eBA Plus Document and Workflow Management System | CWE-434 | Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus |
| CVE-2026-90979 | await | 16.5 | Apache Software Foundation | Apache Karaf | CWE-90 | Apache Karaf: LDAP filter injection in JAAS LDAP login modules |
| CVE-2026-101012 | 5.5 | 15.2 | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection |
| CVE-2026-101013 | 5.5 | 15.2 | mathurvishal | CloudClassroom-PHP-Project | CWE-74 | mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection |
| CVE-2026-82382 | 6.1 | 15.1 | Apache Software Foundation | Apache Roller | CWE-79 | Apache Roller: Reflected cross-site scripting in the frontpage directory para… |
| CVE-2026-101010 | 2.0 | 14.5 | aaPanel | BaoTa | CWE-74 | aaPanel BaoTa data.py getData sql injection |
| CVE-2026-100750 | 8.5 | 12.3 | regularlabs.com | Modules Anywhere (Pro) extension for Joomla | CWE-918 | Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules An… |
| CVE-2026-86838 | 5.3 | 10.9 | Unknown | Bookly | CWE-472 | Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation |
| CVE-2026-101036 | 1.9 | 10.1 | FLB-Music | FLB-Music-Player | CWE-22 | FLB-Music FLB-Music-Player createParsedTrack.ts path.join path traversal |
| CVE-2026-101006 | 2.1 | 9.2 | Frappe | HR | CWE-285 | Frappe HR Permission Validation __init__.py get_attendance_requests authoriza… |
| CVE-2026-101011 | 2.0 | 9.0 | aaPanel | BaoTa | CWE-74 | aaPanel BaoTa Domain domainMod.py get_domain_status sql injection |
| CVE-2026-94283 | 6.5 | 8.7 | x.org | libX11 | CWE-125 | Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute p… |
| CVE-2026-100898 | 2.1 | 8.0 | DevaslanPHP | project-management | CWE-74 | DevaslanPHP project-management Timesheet Dashboard ActivitiesReport.php where… |
| CVE-2026-100899 | 2.1 | 8.0 | DevaslanPHP | project-management | CWE-74 | DevaslanPHP project-management Timesheet Dashboard MonthlyReport.php whereRaw… |
| CVE-2026-100904 | 5.1 | 7.8 | amirsanni | mini-inventory-and-sales-management-system | CWE-79 | amirsanni mini-inventory-and-sales-management-system Items Management Items.p… |
| CVE-2026-94286 | 7.1 | 7.2 | x.org | libXtst | CWE-126 | Out-of-bounds read in libXtst's RECORD reply parser |
| CVE-2026-84744 | 6.5 | 7.0 | Unknown | WPForms | CWE-94 | WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution … |
| CVE-2026-82381 | 5.4 | 6.9 | Apache Software Foundation | Apache Roller | CWE-79 | Apache Roller: Stored cross-site scripting in the authoring UI |
| CVE-2026-82387 | 5.4 | 6.9 | Apache Software Foundation | Apache Roller | CWE-79 | Apache Roller: Stored cross-site scripting via uploaded media content type |
| CVE-2026-93000 | 6.8 | 6.5 | Unknown | SPS-Suite | CWE-89 | SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search |
| CVE-2026-88828 | 5.4 | 5.4 | Unknown | Blacklist Manager | CWE-288 | Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction By… |
| CVE-2026-100897 | 5.1 | 4.9 | fuzui | StudentInfo | CWE-285 | fuzui StudentInfo Password Change Endpoint moditypasswordstu authorization |
| CVE-2026-89303 | 6.4 | 4.8 | Unknown | Post Voting System | CWE-89 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
| CVE-2026-100900 | 2.0 | 3.9 | DevaslanPHP | project-management | CWE-918 | DevaslanPHP project-management Jira Import jira-import updateJiraProjects ser… |
| CVE-2026-82969 | 5.4 | 3.3 | Bimser Solution Software Trade Inc. | eBA Plus Document and Workflow Management System | CWE-79 | Stored XSS in BİMSER's eBA Plus |
| CVE-2026-89300 | 5.3 | 2.5 | Unknown | WP Verify API | CWE-862 | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to A… |
| CVE-2026-94282 | 5.6 | 2.2 | x.org | libXi | CWE-125 | Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion |
| CVE-2026-89411 | 5.3 | 1.4 | Unknown | Paymattic | CWE-345 | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe Paymen… |
| CVE-2026-92996 | 5.3 | 1.4 | Unknown | Verge3D Publishing and E-Commerce | CWE-345 | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done |
| CVE-2026-87723 | 5.4 | 1.3 | fuse-archive | CWE-426 | Untrusted Search Path (PATH Hijacking) in fuse-archive | |
| CVE-2026-94285 | 5.1 | 1.2 | x.org | libX11 | CWE-125 | Out-of-bounds read in libX11's byte-oriented codeset parser |
| CVE-2026-94284 | 5.5 | 0.9 | x.org | libX11 | CWE-125 | Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration pars… |
| CVE-2026-94287 | 5.5 | 0.8 | x.org | libXpm | CWE-1050 | Denial of service via unsigned underflow in libXpm's write path |
| CVE-2026-85526 | 9.9 | — | Canonical | LXD | CWE-22 | Path traversal via Btrfs optimized-backup subvolumes[].path enables root file… |
| CVE-2026-87799 | 9.9 | — | Canonical | LXD | CWE-59 | Arbitrary file write on LXD host via symlink in migration stream |
| CVE-2026-90924 | 9.8 | — | Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. | Logsign SIEM | CWE-1392 | Default Admin Credentials in Innotim Software's Logsign SIEM |
| CVE-2026-12342 | 9.6 | — | SailPoint Technologies | IdentityIQ | CWE-20 | SailPoint IdentityIQ Improper Form Validation Vulnerability |
| CVE-2026-85185 | 9.6 | — | Canonical | LXD | CWE-22 | Path traversal in LXD btrfs storage driver allows arbitrary file deletion and… |
| CVE-2026-88804 | 9.6 | — | SUSE | Rancher | CWE-79 | Unauthenticated update of public UI settings leading to stored cross-site scr… |
| CVE-2026-19759 | 9.4 | — | Google Cloud | Application Integration | CWE-863 | Incorrect Authorization in Application Integration allows Internal Stubby RPC… |
| CVE-2026-81867 | 9.4 | — | Google Cloud | Application Integration | CWE-502 | Deserialization of Untrusted Data in Application Integration allows Remote Co… |
| CVE-2026-101263 | 9.4 | — | Ziroom | ZHOME A0101 | CWE-77 | Ziroom ZHOME A0101 set_online_client command injection |
| CVE-2026-101264 | 9.4 | — | Ziroom | ZHOME A0101 | CWE-77 | Ziroom ZHOME A0101 set_passwd command injection |
| CVE-2026-73640 | 9.3 | — | Dayforce | Payroll | CWE-89 | Time-based SQL Injection in Dayforce Payroll |
| CVE-2026-86102 | 9.3 | — | WatchGuard | WatchGuard AP | CWE-78 | WatchGuard AP Command Injection in Internal Management API Allows Command Exe… |
| CVE-2026-100752 | 9.3 | — | ordasoft.com | Real Estate Manager (Free) extension for Joomla | CWE-89 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estat… |
| CVE-2026-101039 | 9.3 | — | FAST | FAC1900R | CWE-119 | FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow |
| CVE-2026-101072 | 9.3 | — | Netcore | NR289-GE | CWE-77 | Netcore NR289-GE CGI ap_ip.cgi system os command injection |
| CVE-2026-101075 | 9.3 | — | Netcore | NR289-GE | CWE-77 | Netcore NR289-GE Location Time location_time.cgi system os command injection |
| CVE-2026-101076 | 9.3 | — | Netcore | NR289-GE | CWE-77 | Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection |
| CVE-2026-101077 | 9.3 | — | Netcore | NR289-GE | CWE-287 | Netcore NR289-GE boa_temp process_request missing authentication |
| CVE-2026-101108 | 9.3 | — | ordasoft.com | Vehicle Manager (Free) extension for Joomla | CWE-89 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Ma… |
| CVE-2026-101110 | 9.3 | — | ordasoft.com | Book Library (Free) extension for Joomla | CWE-89 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Libra… |
| CVE-2026-101891 | 9.3 | — | WatchGuard | WatchGuard AP | CWE-284 | WatchGuard AP Improper Access Control in API Service Allows Unauthenticated A… |
| CVE-2026-102361 | 9.3 | — | gz-yami | mall4j | CWE-306 | mall4j through 4.0 Missing Authentication in Password Update Endpoint |
| CVE-2026-73642 | 9.2 | — | Dayforce | Payroll | CWE-22 | Path Traversal in Dayforce Payroll |
| CVE-2026-49994 | 9.1 | — | dannymcc | bluehood | CWE-306 | Bluehood: Missing authentication on Bluehood API routes when web auth is enabled |
| CVE-2026-101894 | 9.1 | — | XhmikosR | decompress | CWE-22 | @xhmikosr/decompress: Path traversal via symlink chain |
| CVE-2026-102268 | 9.1 | — | jpadilla | pyjwt | CWE-347 | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public… |
| CVE-2026-102334 | 9.1 | — | NginxProxyManager | nginx-proxy-manager | CWE-307 | Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection |
| CVE-2026-101074 | 8.9 | — | Netcore | NR289-GE | CWE-119 | Netcore NR289-GE Authentication boa password-check stack-based overflow |
| CVE-2026-12264 | 8.8 | — | Zohocorp | DDI Central | CWE-434 | Authenticated File Write via HA Failover Config Upload leads to RCE |
| CVE-2026-12265 | 8.8 | — | Zohocorp | DDI Central | CWE-284 | Missing Authorization on HA Failover Config allows Complete Data Destruction |
| CVE-2026-12268 | 8.8 | — | Zohocorp | DDI Central | CWE-20 | Authenticated PowerShell Injection leads to RCE |
| CVE-2026-12269 | 8.8 | — | Zohocorp | DDI Central | CWE-269 | Authenticated File Write to RCE via keepalived in DDI Central |
| CVE-2026-78424 | 8.8 | — | SUSE | NeuVector | CWE-78 | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Cod… |
| CVE-2026-86595 | 8.8 | — | Iron Mountain Archiving Services Inc. | enVision | CWE-89 | SQLi in Iron Mountain's enVision |
| CVE-2026-86950 | 8.8 | — | Apple | iOS and iPadOS | CWE-787 | An out-of-bounds write issue was addressed with improved bounds checking. Thi… |
| CVE-2026-87741 | 8.8 | — | Brainstorm Force | ConvertPlus | CWE-78 | ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via '… |
| CVE-2026-88808 | 8.8 | — | SUSE | Rancher | CWE-250 | Fleet agent copies downstream resources with cluster-admin privileges, allowi… |
| CVE-2026-90926 | 8.8 | — | Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. | Logsign SIEM | CWE-94 | Code Injection in Innotim Software's Logsign SIEM |
| CVE-2026-48100 | 8.7 | — | polybase | payy | CWE-349 | Payy: agg_agg trailing message slots are unconstrained and allow forged burn … |
| CVE-2026-54675 | 8.7 | — | FreePBX | security-reporting | CWE-22 | FreePBX: Authenticated Remote Code Execution via File Upload and Convert in S… |
| CVE-2026-96538 | 8.7 | — | EnterpriseDB | WarehousePG | CWE-862 | WarehousePG pg_file_write/pg_file_rename/pg_file_unlink/pg_logdir_ls privileg… |
| CVE-2026-100371 | 8.7 | — | InvoicePlane | InvoicePlane | CWE-863 | InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables P… |
| CVE-2024-42002 | 8.6 | — | Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | CWE-94 | Unsafe use of eval() method in ros2 topic hz tool |
| CVE-2026-54674 | 8.6 | — | FreePBX | security-reporting | CWE-78 | Authenticated Command Injection in FreePBX UCP Interface |
| CVE-2026-54708 | 8.6 | — | FreePBX | security-reporting | CWE-22 | Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module |
| CVE-2026-54710 | 8.6 | — | FreePBX | security-reporting | CWE-20 | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsaf… |
| CVE-2026-75600 | 8.6 | — | FreePBX | security-reporting | CWE-78 | FreePBX: Authenticated API generatedocs Host Command Injection |
| CVE-2026-87969 | 8.6 | — | WatchGuard | WatchGuard AP | CWE-78 | WatchGuard AP Authenticated Command Injection in Diagnostic CLI |
| CVE-2026-93348 | 8.6 | — | unslothai | unsloth-zoo | CWE-94 | Unsloth Zoo Code Injection via model_type in config.json |
| CVE-2026-101038 | 8.6 | — | FAST | FAC1200R | CWE-119 | FAST FAC1200R MmtAtePrase stack-based overflow |
| CVE-2026-101081 | 8.5 | — | D-Link | DI-8400 | CWE-119 | D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp… |
| CVE-2026-101187 | 8.5 | — | Ziroom | ZHOME A0101 | CWE-74 | Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command… |
| CVE-2026-101260 | 8.5 | — | Ziroom | ZHOME A0101 | CWE-74 | Ziroom ZHOME A0101 firstLogin command injection |
| CVE-2026-101261 | 8.5 | — | Ziroom | ZHOME A0101 | CWE-74 | Ziroom ZHOME A0101 firstSetup_wifi command injection |
| CVE-2026-101262 | 8.5 | — | Ziroom | ZHOME A0101 | CWE-74 | Ziroom ZHOME A0101 set_online_client command injection |
| CVE-2026-55157 | 8.4 | — | ooples | token-optimizer-mcp | CWE-78 | Token Optimizer MCP: OS command injection in smart_user via username in get-u… |
| CVE-2026-81375 | 8.3 | — | Google Cloud | Application Integration | CWE-610 | Confused Deputy in Application Integration allows Internal File Read |
| CVE-2026-101909 | 8.3 | — | axios | axios | CWE-1321 | Axios: Prototype Pollution Gadget in axios toFormData Options |
| CVE-2026-102296 | 8.3 | — | ZoneMinder | zoneminder | CWE-120 | ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response |
| CVE-2026-54160 | 8.2 | — | networkupstools | nut | CWE-829 | Network UPS Tools: A PWN Request in make-dist workflow can execute PR-control… |
| CVE-2026-91043 | 8.2 | — | elixir-mint | mint | CWE-770 | HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_s… |
| CVE-2026-101292 | 8.2 | — | Red Hat | Red Hat AMQ Broker 7 | CWE-470 | Artemis-core-client: unsafe reflection in apache activemq artemis federation … |
| CVE-2026-101901 | 8.2 | — | axios | axios | CWE-400 | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Ses… |
| CVE-2026-101903 | 8.2 | — | axios | axios | CWE-1333 | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| CVE-2026-101906 | 8.2 | — | axios | axios | CWE-400 | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via u… |
| CVE-2026-82323 | 8.1 | — | Enocta Educational Technologies Inc. | Enocta Platform | CWE-639 | Improper Authorization in Enocta Educational's Enocta Platform |
| CVE-2026-88805 | 8.1 | — | SUSE | Rancher | CWE-613 | Session Not Revoked Server-Side on Logout in Rancher |
| CVE-2026-4556 | 7.8 | — | Extegrity | Exam4 | CWE-78 | macOS Exam4 Local Privilege Escalation via Command Injection |
| CVE-2026-16513 | 7.8 | — | zephyrproject | zephyr | CWE-787 | Missing write validation of user-supplied handle pointer in the RTIO syscall … |
| CVE-2026-18413 | 7.8 | — | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_seque… |
| CVE-2026-18414 | 7.8 | — | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence… |
| CVE-2026-102004 | 7.8 | — | Wind River Systems Inc | VxWorks 7 | CWE-787 | VxWorks 7 |
| CVE-2026-45562 | 7.7 | — | FreePBX | security-reporting | CWE-78 | FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) M… |
| CVE-2026-82928 | 7.7 | — | F&F Filipowski | mH-DEVELOPER | CWE-1242 | Undocumented access path in mH-DEVELOPER |
| CVE-2026-97335 | 7.7 | — | Canonical | LXD | CWE-863 | Incorrect authorization in LXD storage volume API allows reading volumes from… |
| CVE-2026-55160 | 7.6 | — | stringer-rss | stringer | CWE-918 | Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer |
| CVE-2026-93355 | 7.6 | — | BerriAI | litellm | CWE-1390 | LiteLLM Weak JWT Authentication via Email-Based User Lookup |
| CVE-2026-101905 | 7.6 | — | axios | axios | CWE-441 | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hij… |
| CVE-2026-102276 | 7.5 | — | juliangruber | brace-expansion | CWE-400 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st… |
| CVE-2026-102278 | 7.5 | — | juliangruber | brace-expansion | CWE-400 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causin… |
| CVE-2026-102281 | 7.5 | — | nestjs | nest | CWE-248 | Nest: Remote process termination via a deeply nested microservice message pat… |
| CVE-2026-101916 | 7.4 | — | grpc | grpc-node | CWE-295 | @grpc/grpc-js: In certain configurations, getAuthContext can return unauthori… |
| CVE-2026-102266 | 7.4 | — | jpadilla | pyjwt | CWE-347 | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102267 | 7.4 | — | jpadilla | pyjwt | CWE-200 | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| CVE-2026-102271 | 7.4 | — | jpadilla | pyjwt | CWE-347 | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CV… |
| CVE-2026-102272 | 7.4 | — | jpadilla | pyjwt | CWE-347 | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 | — | jpadilla | pyjwt | CWE-347 | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-12267 | 7.2 | — | Zohocorp | DDI Central | CWE-20 | Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE |
| CVE-2026-86330 | 7.2 | — | Red Hat | Red Hat Openshift Data Foundation 4 | CWE-78 | Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_ho… |
| CVE-2024-58386 | 7.1 | — | ZoneMinder | zoneminder | CWE-22 | ZoneMinder 1.37.x Path Traversal via files view |
| CVE-2026-15952 | 7.1 | — | ABB | Protection and control IED manager (PCM600) | CWE-732 | Improper Permission Assignment in Scheduler Service |
| CVE-2026-52748 | 7.1 | — | Kaon | AR2140 | CWE-306 | Missing authentication for backup functionality in Kaon AR2140X |
| CVE-2026-55096 | 7.1 | — | leshchenko1979 | fast-mcp-telegram | CWE-184 | SSRF via DNS-resolution gap in _validate_url_security (file download by URL) |
| CVE-2026-87114 | 7.1 | — | Red Hat | Pen Drive Powered by Red Hat Lightspeed | CWE-829 | Kube-compare: container:// reference extraction runs the image entrypoint and… |
| CVE-2026-90925 | 7.1 | — | Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. | Logsign SIEM | CWE-22 | Path Traversal in Innotim Software's Logsign SIEM |
| CVE-2026-93538 | 7.1 | — | SUSE | Rancher | CWE-290 | Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster label… |
| CVE-2026-97023 | 7.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-61 | Flatpak: flatpak: arbitrary file deletion in root context via path traversal … |
| CVE-2026-101091 | 7.1 | — | siyuan-note | siyuan | CWE-89 | SiYuan before v3.8.4 SQL Injection via Block Query Embed |
| CVE-2026-102335 | 7.1 | — | NginxProxyManager | nginx-proxy-manager | CWE-863 | Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config |
| CVE-2026-102365 | 7.1 | — | gz-yami | mall4j | CWE-862 | mall4j through 4.0 Missing Authorization in Admin User Address Endpoints |
| CVE-2026-80357 | 7.0 | — | Dell | Boot Optimized Server Storage (BOSS) | CWE-1191 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, con… |
| CVE-2026-100392 | 7.0 | — | InvoicePlane | InvoicePlane | CWE-863 | InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (… |
| CVE-2026-101898 | 7.0 | — | axios | axios | CWE-918 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101907 | 7.0 | — | axios | axios | CWE-441 | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirec… |
| CVE-2026-102010 | 7.0 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-825 | Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after… |
| CVE-2026-82935 | 6.9 | — | F&F Filipowski | mH-DEVELOPER | CWE-1104 | Use of End-of-Life components in mH-DEVELOPER |
| CVE-2026-91154 | 6.9 | — | MarcosCamara01 | Ecommerce Template | CWE-306 | Missing authentication in Ecommerce Template product cache revalidation allow… |
| CVE-2026-101083 | 6.9 | — | n/a | PMWeb | CWE-200 | PMWeb encryptionhelper.dll information disclosure |
| CVE-2026-101092 | 6.9 | — | siyuan-note | siyuan | CWE-200 | SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages |
| CVE-2026-101277 | 6.9 | — | Trusted Domain Project | OpenDKIM | CWE-348 | Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less tr… |
| CVE-2026-101900 | 6.9 | — | axios | axios | CWE-74 | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| CVE-2026-101902 | 6.9 | — | axios | axios | CWE-1321 | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Ob… |
| CVE-2026-101904 | 6.9 | — | axios | axios | CWE-74 | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| CVE-2026-101908 | 6.9 | — | axios | axios | CWE-1321 | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
| CVE-2026-101910 | 6.9 | — | beaugunderson | ip-address | CWE-918 | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48… |
| CVE-2026-102362 | 6.9 | — | gz-yami | mall4j | CWE-306 | mall4j through 4.0 Missing Authentication in Product Review Deletion |
| CVE-2026-18747 | 6.8 | — | zephyrproject | zephyr | CWE-125 | Integer underflow of net_buf length in the MCUmgr serial (SMP over console) t… |
| CVE-2026-80359 | 6.8 | — | Dell | Boot Optimized Server Storage (BOSS) | CWE-1191 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, con… |
| CVE-2026-18417 | 6.5 | — | zephyrproject | zephyr | CWE-843 | Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket re… |
| CVE-2026-19444 | 6.5 | — | Kubernetes | Kubernetes | CWE-22 | Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes |
| CVE-2026-93537 | 6.5 | — | SUSE | Rancher | CWE-23 | Path traversal in Fleet Helm valuesFiles allows disclosure of files outside t… |
| CVE-2026-93540 | 6.5 | — | SUSE | Rancher | CWE-266 | Fleet applies namespace labels and annotations without the bundle's service a… |
| CVE-2026-96740 | 6.5 | — | Red Hat | StreamsHub Console for Apache Kafka® | CWE-470 | Streamshub/console: console-operator: streams for apache kafka console: unfil… |
| CVE-2026-101914 | 6.5 | — | grpc | grpc-node | CWE-187 | @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix… |
| CVE-2026-102275 | 6.5 | — | jpadilla | pyjwt | CWE-345 | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity … |
| CVE-2026-82930 | 6.4 | — | F&F Filipowski | mH-DEVELOPER | CWE-306 | Missing Authentication in mH-DEVELOPER |
| CVE-2026-18415 | 6.3 | — | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6… |
| CVE-2026-82929 | 6.3 | — | F&F Filipowski | mH-DEVELOPER | CWE-321 | Use of Shared Cryptographic Key in mH-DEVELOPER |
| CVE-2026-86335 | 6.3 | — | Canonical | LXD | CWE-862 | LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject … |
| CVE-2026-92103 | 6.3 | — | elixir-mint | mint | CWE-770 | Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max… |
| CVE-2026-94194 | 6.3 | — | elixir-mint | mint | CWE-444 | Mint HTTP/1 client applies chunked framing when chunked is not the final tran… |
| CVE-2026-101911 | 6.3 | — | beaugunderson | ip-address | CWE-400 | ip-address: Address6 builds a parse diagnostic proportional to the input with… |
| CVE-2026-101912 | 6.3 | — | beaugunderson | ip-address | CWE-697 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different … |
| CVE-2026-101913 | 6.3 | — | beaugunderson | ip-address | CWE-697 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10… |
| CVE-2026-102363 | 6.3 | — | gz-yami | mall4j | CWE-306 | mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number |
| CVE-2026-87752 | 6.1 | — | Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. | Agentis | CWE-79 | HTML Injection in Rolantis Information Technologies' Agentis |
| CVE-2026-82933 | 6.0 | — | F&F Filipowski | mH-DEVELOPER | CWE-1428 | Cleartext Transmission of Sensitive Information in mH-DEVELOPER |
| CVE-2026-18746 | 5.9 | — | zephyrproject | zephyr | CWE-476 | NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context … |
| CVE-2026-82936 | 5.9 | — | F&F Filipowski | mH-DEVELOPER | CWE-770 | Denial of Service in mH-DEVELOPER |
| CVE-2026-102274 | 5.9 | — | jpadilla | pyjwt | CWE-755 | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-87798 | 5.8 | — | Canonical | LXD | CWE-59 | LXD client recursive file pull allows directory escape via malicious VM agent |
| CVE-2026-101040 | 5.7 | — | Ricoh | SP 330DN | CWE-404 | Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data den… |
| CVE-2026-15953 | 5.6 | — | ABB | Protection and control IED manager (PCM600) | CWE-22 | Path Traversal During Project Archive Import |
| CVE-2026-70413 | 5.6 | — | Dell | Live Optics Collector | CWE-259 | Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use o… |
| CVE-2026-97686 | 5.5 | — | Wind River | VxWorks 7 | CWE-772 | VxWorks 7 Memory Resource leak |
| CVE-2026-101052 | 5.5 | — | refly-ai | refly | CWE-259 | refly-ai refly JWT Token app.config.ts hard-coded credentials |
| CVE-2026-101053 | 5.5 | — | Thinkware | U3000 | CWE-266 | Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control |
| CVE-2026-101054 | 5.5 | — | Thinkware | U3000 | CWE-266 | Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control |
| CVE-2026-101055 | 5.5 | — | Thinkware | U3000 | CWE-200 | Thinkware U3000 TCP Service GET_STATUS information disclosure |
| CVE-2026-101066 | 5.5 | — | n/a | dbgate | CWE-22 | dbgate Archive Link Creation archive.js createLink path traversal |
| CVE-2026-101067 | 5.5 | — | n/a | dbgate | CWE-22 | dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal |
| CVE-2026-101068 | 5.5 | — | n/a | dbgate | CWE-22 | dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path t… |
| CVE-2026-101069 | 5.5 | — | n/a | dbgate | CWE-22 | dbgate Export databaseConnections.js exportModelSql path traversal |
| CVE-2026-101070 | 5.5 | — | n/a | dbgate | CWE-22 | dbgate Files Endpoint runners.js files path traversal |
| CVE-2026-101073 | 5.5 | — | Netcore | NR289-GE | CWE-287 | Netcore NR289-GE CGI Dispatcher boa improper authentication |
| CVE-2026-101082 | 5.5 | — | n/a | PMWeb | CWE-22 | PMWeb downloader.aspx path traversal |
| CVE-2026-101188 | 5.5 | — | Netcore | POWER13 | CWE-640 | Netcore POWER13 ubus routerd.passwd_set password recovery |
| CVE-2026-102005 | 5.5 | — | Wind River Inc | VxWorks 7 | CWE-401 | VxWorks Memory Allocation |
| CVE-2026-102006 | 5.5 | — | Wind River Systems Inc | VxWorks 7 | CWE-401 | VxWorks 7 Memory allocation |
| CVE-2026-93539 | 5.4 | — | SUSE | Rancher | CWE-306 | Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver |
| CVE-2026-18825 | 5.3 | — | github.com/antono | connect-cors | CWE-346 | Origin validation error in the connect-xcors npm package |
| CVE-2026-52749 | 5.3 | — | Kaon | AR2140 | CWE-287 | Improper Authentication in Kaon AR2140X |
| CVE-2026-55156 | 5.3 | — | ooples | token-optimizer-mcp | CWE-22 | Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log … |
| CVE-2026-82932 | 5.3 | — | F&F Filipowski | mH-DEVELOPER | CWE-923 | Missing Firewall Configuration in mH-DEVELOPER |
| CVE-2026-100753 | 5.3 | — | ordasoft.com | Real Estate Manager (Free) extension for Joomla | CWE-79 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Esta… |
| CVE-2026-101093 | 5.3 | — | Cotonti | Cotonti | CWE-352 | Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion |
| CVE-2026-101098 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-400 | ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource cons… |
| CVE-2026-101099 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-755 | ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition |
| CVE-2026-101100 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-459 | ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddlewar… |
| CVE-2026-101101 | 5.3 | — | ag-ui-protocol | ag-ui | CWE-248 | ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception |
| CVE-2026-101102 | 5.3 | — | deepseek-ai | deepseek-harness | CWE-264 | deepseek-ai deepseek-harness Code Mode Sandbox run_code sandbox |
| CVE-2026-101109 | 5.3 | — | ordasoft.com | Vehicle Manager (Free) extension for Joomla | CWE-79 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle M… |
| CVE-2026-101111 | 5.3 | — | ordasoft.com | Book Library (Free) extension for Joomla | CWE-79 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Libr… |
| CVE-2026-101917 | 5.3 | — | jpadilla | pyjwt | CWE-770 | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown ki… |
| CVE-2026-101918 | 5.3 | — | jpadilla | pyjwt | CWE-248 | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (… |
| CVE-2026-102265 | 5.3 | — | jpadilla | pyjwt | CWE-674 | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102277 | 5.3 | — | juliangruber | brace-expansion | CWE-400 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU … |
| CVE-2026-102297 | 5.3 | — | ZoneMinder | zoneminder | CWE-863 | ZoneMinder before 1.38.4 Incorrect Authorization in frames API index |
| CVE-2026-102333 | 5.3 | — | cle-b | httpdbg | CWE-79 | httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL |
| CVE-2026-102364 | 5.3 | — | gz-yami | mall4j | CWE-287 | mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin… |
| CVE-2026-102367 | 5.3 | — | gz-yami | mall4j | CWE-613 | mall4j through 4.0 Insufficient Session Expiration via Token Refresh |
| CVE-2026-73641 | 5.1 | — | Dayforce | Payroll | CWE-79 | Multiple Reflected XSS in Dayforce Payroll |
| CVE-2026-80358 | 5.1 | — | Dell | Boot Optimized Server Storage (BOSS) | CWE-1191 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, con… |
| CVE-2026-102269 | 4.8 | — | jpadilla | pyjwt | CWE-180 | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| CVE-2026-100370 | 4.7 | — | rhukster | dom-sanitizer | CWE-20 | DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerous… |
| CVE-2026-59563 | 4.6 | — | Zscaler | zscaler-mcp-server | CWE-305 | HMAC Confirmation Token Unbinding in zscaler-mcp-server |
| CVE-2026-102332 | 4.6 | — | amir20 | dozzle | CWE-22 | Dozzle before 11.1.2 Path Traversal via Log ZIP Download |
| CVE-2026-102270 | 4.4 | — | jpadilla | pyjwt | CWE-1333 | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
| CVE-2026-13018 | 4.3 | — | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-86334 | 4.2 | — | Canonical | LXD | CWE-22 | CLI Path Traversal via Content-Disposition in LXD Image Export/Copy |
| CVE-2026-82326 | 4.1 | — | Enocta Educational Technologies Inc. | Enocta Platform | CWE-79 | HTML Injection in Enocta Educational's Enocta Platform |
| CVE-2026-97026 | 3.9 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-378 | Flatpak: flatpak: world-writable temporary child repositories in system-helpe… |
| CVE-2026-18416 | 3.7 | — | zephyrproject | zephyr | CWE-125 | Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_pat… |
| CVE-2026-97399 | 3.7 | — | The GNU C Library | glibc | CWE-126 | One-byte overread in strncasecmp on Power8 |
| CVE-2026-101333 | 3.7 | — | Red Hat | Red Hat Build of Keycloak | CWE-770 | Keycloak-services: keycloak-services: unbounded metric series creation via id… |
| CVE-2026-101915 | 3.7 | — | grpc | grpc-node | CWE-550 | @grpc/grpc-js: The server transmits some error messages thrown by method hand… |
| CVE-2026-97027 | 3.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-20 | Flatpak: flatpak: denial of service via unsanitized keys in exported desktop … |
| CVE-2026-97025 | 3.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-378 | Flatpak: flatpak: world-readable oci authentication token in system-helper ca… |
| CVE-2026-102279 | 3.1 | — | laravel | framework | CWE-80 | Laravel: XSS in Debug Page Information |
| CVE-2026-101265 | 2.3 | — | Intelbras | TIP 125i | CWE-540 | Intelbras TIP 125i Básico sensitive information in source |
| CVE-2026-101071 | 2.1 | — | Acrel Electric | Unet Web Service | CWE-284 | Acrel Electric Unet Web Service Upload Endpoint upload unrestricted upload |
| CVE-2026-101105 | 2.1 | — | code-projects | Matrimonial System | CWE-74 | code-projects Matrimonial System Profile Creation Endpoint create_profile pro… |
| CVE-2026-101142 | 2.1 | — | Eleveo | Quality Management | CWE-22 | Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path trave… |
| CVE-2026-101143 | 2.1 | — | Eleveo | Quality Management | CWE-200 | Eleveo Quality Management QMBODownload information disclosure |
| CVE-2026-101144 | 2.1 | — | Eleveo | Call Recording Software | CWE-266 | Eleveo Call Recording Software Query Builder searchAction.do access control |
| CVE-2026-101145 | 2.1 | — | Eleveo | Call Recording Software | CWE-74 | Eleveo Call Recording Software User Management userAddAction.do ldap injection |
| CVE-2026-101146 | 2.1 | — | Eleveo | Quality Management | CWE-200 | Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAu… |
| CVE-2026-101202 | 2.1 | — | FastStone | Image Viewer | CWE-119 | FastStone Image Viewer TGA Image out-of-bounds write |
| CVE-2026-101203 | 2.1 | — | FastStone | Image Viewer | CWE-119 | FastStone Image Viewer 1bpp RLE Decoder out-of-bounds write |
| CVE-2026-101204 | 2.1 | — | FastStone | Image Viewer | CWE-119 | FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds |
| CVE-2026-101205 | 2.1 | — | FastStone | Image Viewer | CWE-119 | FastStone Image Viewer PCX Decoder out-of-bounds |
| CVE-2026-101861 | 2.1 | — | langflow-ai | langflow | CWE-94 | Langflow Code Execution via eval() in Component Input Schema |
| CVE-2026-102366 | 2.1 | — | gz-yami | mall4j | CWE-434 | mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints |
| CVE-2026-101139 | 2.0 | — | Webkul | Bagisto | CWE-862 | Webkul Bagisto Invoice Mass Status Update state authorization |
| CVE-2026-101141 | 2.0 | — | Eleveo | Call Recording Software | CWE-79 | Eleveo Call Recording Software Play Audio audio.jsp cross site scripting |
| CVE-2026-101078 | 1.9 | — | deepseek-ai | deepseek-harness | CWE-653 | deepseek-ai deepseek-harness Landlock Backend profiles.ts isolation |
| CVE-2026-101131 | 1.9 | — | deepseek-ai | deepseek-harness | CWE-20 | deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a s… |
| CVE-2026-101132 | 1.3 | — | DeepSeek | deepseek-harness | CWE-22 | DeepSeek deepseek-harness Bundle Patch profile.ts loadProfile path traversal |
| CVE-2026-101079 | 0.9 | — | agentverus | agentverus-scanner | CWE-20 | agentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on u… |
| CVE-2026-101080 | 0.9 | — | Tencent | AI-Infra-Guard | CWE-22 | Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal |
| CVE-2026-84894 | await | — | Meta Platforms, Inc | moxygen | — | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps u… |
| CVE-2026-84895 | await | — | proxygen | — | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSes… | |
| CVE-2026-85644 | await | — | — | XS-Parse-Keyword | CWE-125 | XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as a… |
| CVE-2026-88815 | await | — | — | DBI | CWE-843 | DBI versions before 1.654 for Perl incorrectly treat numeric values as string… |
| CVE-2026-88816 | await | — | — | DBI | CWE-843 | DBI versions before 1.654 for Perl incorrectly treat numeric values as string… |
| CVE-2026-91006 | await | — | Apache Software Foundation | Apache Karaf | CWE-78 | Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / Ins… |
| CVE-2026-91095 | await | — | proxygen | — | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::on… | |
| CVE-2026-91096 | await | — | proxygen | — | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::termi… | |
| CVE-2026-96760 | await | — | Authlib | Authlib | — | Authlib library contains a signature‑verification bypass vulnerability |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-28 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.