boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, September 28, 2026 · all times UTC← 2026-09-27 · archive

Security Box Score — September 28, 2026

314 CVEs published, led by Apache Software Foundation (20).

314 CVEs published September 28, 2026: 32 critical, 98 high, 136 medium, 38 low; 0 in the KEV catalog at press time; 10 with a public exploit reference; 10 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 289 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1369548675——
KEV catalog size1728

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3143 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux21146205530263871311560.17.8.0019+471 ▲
microsoft10022901203199169116290311.17.8.0047+525 ▲
google5202689332105111851218090.37.5.0027+118 ▲
red hat2498785136540953200.06.6.0037+27 ▲
apple24756467166317148881.46.5.0019+203 ▲
suse2553827162000.07.5.0039+18 ▲
canonical7491612165000.07.8.0019-8 ▼
freebsd04823673000.07.8.0016-32 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0046+51 ▲
ubiquiti665362810334.69.1.0050-17 ▼
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-7 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache157669151282216163320.37.5.0063-1 ▼
mozilla113301102126730900.08.8.0032+54 ▲
gitlab241007236010533.05.3.0034-1 ▼
drupal2694119668411.15.7.0027+9 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614103350.08.7.0340-1 ▼
kubernetes120011000.04.5.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-256 ▼
ibm398101719546833618610.17.5.0037+8 ▲
adobe2248308236437592150.67.5.0036+123 ▲
progress3641539100611.68.1.0046-16 ▼
zohocorp324262970000.08.3.0109+28 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-13 ▼
servicenow5107300200.09.4.0036+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link297422281212300.08.5.0170+13 ▲
siemens1552633103000.07.3.0026-6 ▼
synology1946510256000.05.6.0032+15 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
abb4111640000.07.2.0018+4 ▲
hikvision390540000.07.1.0038+3 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1993703117114622210.37.2.0029+128 ▲
sourcecodester632320013894000.05.5.0043+15 ▲
openclaw8221541098121000.07.1.0031+82 ▲
nvidia5118521127370000.07.8.0040-1 ▼
spring017013608314000.06.5.0033-91 ▼
mongodb71169699604100.07.1.0038+16 ▲
itsourcecode371530037116000.02.1.0033+7 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0044+136 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.914399.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-87902.224997.68.1
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-83548.087695.010.0
CVE-2026-85102.075594.39.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9143KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
Most disclosures (vendor)
VendorCVEs
linux2114
microsoft1002
oracle634
google520
ibm398
red hat255
apple247
adobe224
dell200
apache167
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco16
google9
apple8
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist18
npm15
PyPI13
crates.io9
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-87902WordPress2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171776
CVE-2021-27102n/a2021-11-171776
CVE-2021-27101n/a2021-11-171776
CVE-2021-27103n/a2021-11-171776
CVE-2021-21017Adobe2021-11-171776
CVE-2021-28550Adobe2021-11-171776
CVE-2021-42013Apache Software Foundation2021-11-171776
CVE-2021-41773Apache Software Foundation2021-11-171776
CVE-2021-30858Apple2021-11-171776
CVE-2021-30860Apple2021-11-171776

Transactions

EXPLOIT PUBLISHED — sooperset mcp-atlassian: 9 CVEs (CVE-2026-77246, CVE-2026-77247, CVE-2026-77253, CVE-2026-77254, CVE-2026-77266, CVE-2026-77270, CVE-2026-77271, CVE-2026-77272, CVE-2026-77274). Public exploit references added.

EXPLOIT PUBLISHED — mathurvishal CloudClassroom-PHP-Project: 7 CVEs (CVE-2026-100311, CVE-2026-100313, CVE-2026-100314, CVE-2026-100739, CVE-2026-100874, CVE-2026-100875, CVE-2026-100877). Public exploit references added.

EXPLOIT PUBLISHED — radareorg radare2: 5 CVEs (CVE-2026-81882, CVE-2026-81883, CVE-2026-81884, CVE-2026-81885, CVE-2026-81886). Public exploit references added.

EXPLOIT PUBLISHED — Unknown WPeMatico RSS Feed Fetcher: 4 CVEs (CVE-2026-89000, CVE-2026-89001, CVE-2026-89003, CVE-2026-89006). Public exploit references added.

EXPLOIT PUBLISHED — OISF suricata: 3 CVEs (CVE-2026-45747, CVE-2026-57225, CVE-2026-57226). Public exploit references added.

EXPLOIT PUBLISHED — vllm-project vllm: 3 CVEs (CVE-2026-73558, CVE-2026-73559, CVE-2026-93592). Public exploit references added.

EXPLOIT PUBLISHED — zhistaredu StarTraining: 3 CVEs (CVE-2026-100878, CVE-2026-100880, CVE-2026-100881). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-100740 (D-Link DIR-895L). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100745 (Edimax BR-6428nC). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100746 (coollabsio Coolify). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100883 (Krayin laravel-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100884 (Krayin laravel-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100886 (Seetong T8108). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73624 (gitpython-developers GitPython). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79759 (Termix-SSH Termix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-81655 (Unknown Ad Inserter). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82841 (Unknown UpdraftPlus: WP Backup & Migration Plugin). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-84069 (Unknown WebFacing™). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-85002 (Unknown EmbedPress). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86609 (Unknown Download Manager). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86839 (Unknown Online Scheduling and Appointment Booking System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86841 (Unknown Online Scheduling and Appointment Booking System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92436 (Unknown Mailchimp for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92995 (Unknown Verge3D Publishing and E-Commerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95847 (moquette-io moquette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95848 (moquette-io moquette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96550 (sfturing hosp_order). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96602 (Abdurrab5 online-makeup-store). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96678 (weiqingwen spring-boot-forum). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96763 (kvcache-ai mooncake). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96777 (Forma LMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96882 (TaleLin lin-cms-spring-boot). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96895 (Unknown WP YouTube Lyte). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96896 (Unknown Malcure Malware Shield — Removal, Repair, Monitor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96897 (Unknown Optima Express IDX). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-96899 (Unknown Optima Express IDX). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97227 (Unknown NextScripts: Social Networks Auto-Poster). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97231 (volotat Anagnorisis). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97319 (Unknown PowerPress Podcasting plugin by Blubrry). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97359 (rejetto hfs2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97647 (ningzichun student-management-system). Public exploit reference added.

DUE DATE PASSED — CVE-2026-5430 (WSO2 Universal Gateway). CISA remediation deadline was September 27, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-71362 (Adobe Commerce). CISA remediation deadline was September 27, 2026; still in catalog.

REJECTED — CVE-2026-100655 (netty). Record withdrawn by the CNA.

REJECTED — CVE-2026-100656 (netty). Record withdrawn by the CNA.

REJECTED — CVE-2026-100657 (netty). Record withdrawn by the CNA.

REJECTED — CVE-2026-100658 (netty). Record withdrawn by the CNA.

DISPUTED — CVE-2026-93353 (9001 copyparty). Record marked disputed.

RESCORED — OISF suricata: 8 CVEs (CVE-2026-45751, CVE-2026-57225, CVE-2026-57226, CVE-2026-63448, CVE-2026-63449, CVE-2026-63450, CVE-2026-63451, CVE-2026-71855). CVSS rescored — before/after on each CVE page.

RESCORED — GitLab: 3 CVEs (CVE-2026-3855, CVE-2026-78252, CVE-2026-82837). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2026-100887 (amirsanni Mini-Inventory-and-Sales-Management-System). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2026-100888 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-100889 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-6730 (IBM Concert). CVSS 9.8 → 7.8 (NVD).

RESCORED — CVE-2026-77246 (sooperset mcp-atlassian). CVSS 7.4 → 8.6 (NVD).

RESCORED — CVE-2026-77272 (sooperset mcp-atlassian). CVSS 5.4 → 6.1 (NVD).

RESCORED — CVE-2026-77896 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD).

RESCORED — CVE-2026-78426 (SUSE neuvector). CVSS 3.7 → 2 (NVD).

RESCORED — CVE-2026-78427 (SUSE github.com/neuvector/neuvector). CVSS 4.3 → 5.3 (NVD).

RESCORED — CVE-2026-78428 (SUSE neuvector). CVSS 8 → 8.8 (NVD).

RESCORED — CVE-2026-81884 (radareorg radare2). CVSS 2.5 → 3.3 (NVD).

RESCORED — CVE-2026-93659 (concretecms-community-store community_store). CVSS 9.3 → 8.6 (NVD).

PATCH SHIPPED — elixir-mint mint: 3 CVEs (CVE-2026-91043, CVE-2026-92103, CVE-2026-94194). Fix versions published.

PATCH SHIPPED — CVE-2026-93990 (libexpat). Fixed in libexpat 2.8.5.

Yesterday's Results

How to read these box scores · glossary

314 CVEs published. 25 box scores, 289 table rows — nothing truncated.

Netcore NBR200V2 Web Management network_tools eval os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0263   85.0     —
AFFECTED
  Product   Versions             Fixed
  NBR200V2  1.3.241127.071246 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Awaiting Analysis
aaPanel BaoTa File Merge files.py merge_split_file command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.5   .0234   82.9     —
AFFECTED
  Product  Versions  Fixed
  BaoTa    11.0 –    —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0186   78.4     —
AFFECTED
  Product  Versions           Fixed
  N150RT   3.4.0-B20201030 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
aaPanel BaoTa Database Backup database.py InputSql os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   H   H   H    8.5   .0176   77.2     —
AFFECTED
  Product  Versions  Fixed
  BaoTa    11.0 –    —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   H   H   H    8.5   .0176   77.2     —
AFFECTED
  Product  Versions  Fixed
  BaoTa    11.0 –    —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Netcore NBR200V2 Tools Ping network_tools system os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0167   75.9     —
AFFECTED
  Product   Versions             Fixed
  NBR200V2  1.3.241127.071246 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0080   55.0     —
AFFECTED
  Product   Versions              Fixed
  FAC1200R  5.0_20201119_1.0.2 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
n/a Eyeplus — Eyeplus p2pcam HTTP stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    7.7   .0080   54.9     —
AFFECTED
  Product  Versions       Fixed
  Eyeplus  57.0.0.0308 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.8     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Aug 28  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-502 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
Trusted Domain Project OpenARC libopenarc arc-canon.c arc_parse_canon_t null pointer dereference
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0067   50.1     —
AFFECTED
  Product  Versions       Fixed
  OpenARC  1.0.0.Beta1 –  1.0.0.Beta0
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-404, CWE-476 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
aligungr UERANSIM nr-gnb handler.cpp ULInformationTransfer memory corruption
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0061   47.1     —
AFFECTED
  Product   Versions  Fixed
  UERANSIM  3.0 –     —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-119 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
aligungr UERANSIM nr-gnb encode.cpp DecodePlainMmMessage uncaught exception
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0054   43.0     —
AFFECTED
  Product   Versions  Fixed
  UERANSIM  3.0 –     —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-248 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0053   42.9     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Aug 28  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-862 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0050   40.5     —
AFFECTED
  Product   Versions             Fixed
  NBR100V2  1.3.240614.030928 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-862, CWE-863 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
notionnext-org NotionNext Authentication Guard cache.js cleanCache missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0050   40.2     —
AFFECTED
  Product     Versions  Fixed
  NotionNext  4.10.0 –  —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 4 references · NVD status: Deferred
Apache Roller: Anonymous setup action allows frontpage configuration tampering
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  L    8.2   .0049   39.7     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Aug 28  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-306 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
Cesanta Mongoose MQTT Broker main.c fn stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    5.5   .0046   37.6     —
AFFECTED
  Product   Versions  Fixed
  Mongoose  7.0 –     7.22
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
ООО НПО Ритм GEOritm REST API obj-groups missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   N   N    5.5   .0045   36.9     —
AFFECTED
  Product  Versions  Fixed
  GEOritm  2.45.0 –  2.46
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Deferred
Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0045   36.8     —
AFFECTED
  Product          Versions  Fixed
  VoceChat Server  0.5.0 –   —
TIMELINE
  Sep 27  Reserved by CNA
  Sep 28  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Apache Roller: OAuth authorization endpoint trusts request-supplied identity
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  C  H  H  H    9.0   .0042   33.9     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Aug 28  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-863 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
Apache Roller: Stored XSS in comment moderation via comment author URL
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0040   31.2     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Sep 7   Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-79 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
Apache Roller: Stored javascript: URI in HTML comments
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0040   31.2     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-79 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
Apache Roller: Reflected XSS in the optional LDAP comment authenticator
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0040   31.2     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Sep 14  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-79 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Deferred
TPVEnlanube Cloud Web application — Stored Cross-Site Scripting (XSS) in TPVEnlanube
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   N   N   N    4.8   .0039   30.5     —
AFFECTED
  Product                Versions              Fixed
  Cloud Web application  Actual Web Version –  —
TIMELINE
  Apr 27  Reserved by CNA
  Sep 28  Published (CNA: INCIBE)
CWE-79 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Received
Apache Roller: Server-side request forgery via entry trackback and enclosure URLs
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  L  L  L    7.4   .0037   28.7     —
AFFECTED
  Product        Versions  Fixed
  Apache Roller  6.1.5 –   —
TIMELINE
  Aug 28  Reserved by CNA
  Sep 28  Published (CNA: apache)
CWE-918 · CNA: apache · CVSS v3.1 · 4 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1008905.528.6Trusted Domain ProjectOpenDMARCCWE-404Trusted Domain Project OpenDMARC SPF Parser opendmarc_spf.c opendmarc_spf_ipv…
CVE-2026-823797.728.3Apache Software FoundationApache RollerCWE-294Apache Roller: WSSE digest authentication headers can be replayed
CVE-2026-823487.727.8Apache Software FoundationApache RollerCWE-639Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups
CVE-2026-865308.627.3BUFFALO INC.WSR-300HPCWE-78BUFFALO Wi-Fi products handle some web form input improperly to assemble comm…
CVE-2026-951048.726.9BUFFALO INC.WSR-300HPCWE-121Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A…
CVE-2026-1009025.724.2BarcoClickShare CX-20 Gen2CWE-20Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of…
CVE-2026-1010182.023.8dayruiXunruiCMSCWE-74dayrui XunruiCMS Group Editing Home.php group_all_edit sql injection
CVE-2026-1010165.523.0Trusted Domain ProjectOpenDMARCCWE-755Trusted Domain Project OpenDMARC opendmarc_policy.c opendmarc_policy_parse_dm…
CVE-2026-1010175.523.0Trusted Domain ProjectOpenDMARCCWE-755Trusted Domain Project OpenDMARC opendmarc_policy.c strcasecmp exceptional co…
CVE-2026-1010145.521.8Trusted Domain ProjectOpenDMARCCWE-189Trusted Domain Project OpenDMARC DMARC Record opendmarc_util.c opendmarc_util…
CVE-2026-1007517.520.8regularlabs.comTabs & Accordions (Free, Pro) extension for JoomlaCWE-79Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url …
CVE-2026-71704.820.6TPVEnlanubeCloud Web applicationCWE-79Stored Cross-Site Scripting (XSS) in TPVEnlanube
CVE-2026-71714.820.6TPVEnlanubeCloud Web applicationCWE-79Stored Cross-Site Scripting (XSS) in TPVEnlanube
CVE-2026-1008942.120.7mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection
CVE-2026-1009095.520.1n/aOctoberCMSCWE-918OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery
CVE-2026-1010055.520.1n/aOctober CMSCWE-918October CMS SSRF Protection ResizeImages.php validateExternalImageHost server…
CVE-2026-823767.720.0Apache Software FoundationApache RollerCWE-611Apache Roller: XML external entity processing in trackback response parser
CVE-2026-829156.519.9Bimser Solution Software Trade Inc.eBA Plus Document and Workflow Management SystemCWE-22Path Traversal in Bimser Solution Software's eBA Plus
CVE-2026-1008915.519.7Trusted Domain ProjectOpenDMARCCWE-172Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_poli…
CVE-2026-1010155.519.7Trusted Domain ProjectOpenDMARCCWE-20Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equiv…
CVE-2026-823867.719.5Apache Software FoundationApache RollerCWE-611Apache Roller: XML external entity processing in OPML bookmark import
CVE-2026-1009065.519.0n/aEyeplusCWE-200Eyeplus ONVIF Device GetUsers information disclosure
CVE-2026-1009075.519.0n/aEyeplusCWE-200Eyeplus p2pcam Service snapshot information disclosure
CVE-2026-1009015.518.2athlon1600youtube-downloaderCWE-918athlon1600 youtube-downloader stream.php stream server-side request forgery
CVE-2026-823808.118.0Apache Software FoundationApache RollerCWE-352Apache Roller: CSRF protection bypass via self-generated salt validation
CVE-2026-823856.518.0Apache Software FoundationApache RollerCWE-200Apache Roller: Weblog template include escapes the Velocity sandbox and reads…
CVE-2026-825466.118.0Apache Software FoundationApache RollerCWE-79Apache Roller: Stored cross-site scripting through incoming Trackback links
CVE-2026-851348.816.8Bimser Solution Software Trade Inc.eBA Plus Document and Workflow Management SystemCWE-434Arbitrary File Upload Leading to Remote Command Execution in Bimser's eBA Plus
CVE-2026-90979await16.5Apache Software FoundationApache KarafCWE-90Apache Karaf: LDAP filter injection in JAAS LDAP login modules
CVE-2026-1010125.515.2mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection
CVE-2026-1010135.515.2mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection
CVE-2026-823826.115.1Apache Software FoundationApache RollerCWE-79Apache Roller: Reflected cross-site scripting in the frontpage directory para…
CVE-2026-1010102.014.5aaPanelBaoTaCWE-74aaPanel BaoTa data.py getData sql injection
CVE-2026-1007508.512.3regularlabs.comModules Anywhere (Pro) extension for JoomlaCWE-918Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules An…
CVE-2026-868385.310.9UnknownBooklyCWE-472Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation
CVE-2026-1010361.910.1FLB-MusicFLB-Music-PlayerCWE-22FLB-Music FLB-Music-Player createParsedTrack.ts path.join path traversal
CVE-2026-1010062.19.2FrappeHRCWE-285Frappe HR Permission Validation __init__.py get_attendance_requests authoriza…
CVE-2026-1010112.09.0aaPanelBaoTaCWE-74aaPanel BaoTa Domain domainMod.py get_domain_status sql injection
CVE-2026-942836.58.7x.orglibX11CWE-125Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute p…
CVE-2026-1008982.18.0DevaslanPHPproject-managementCWE-74DevaslanPHP project-management Timesheet Dashboard ActivitiesReport.php where…
CVE-2026-1008992.18.0DevaslanPHPproject-managementCWE-74DevaslanPHP project-management Timesheet Dashboard MonthlyReport.php whereRaw…
CVE-2026-1009045.17.8amirsannimini-inventory-and-sales-management-systemCWE-79amirsanni mini-inventory-and-sales-management-system Items Management Items.p…
CVE-2026-942867.17.2x.orglibXtstCWE-126Out-of-bounds read in libXtst's RECORD reply parser
CVE-2026-847446.57.0UnknownWPFormsCWE-94WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution …
CVE-2026-823815.46.9Apache Software FoundationApache RollerCWE-79Apache Roller: Stored cross-site scripting in the authoring UI
CVE-2026-823875.46.9Apache Software FoundationApache RollerCWE-79Apache Roller: Stored cross-site scripting via uploaded media content type
CVE-2026-930006.86.5UnknownSPS-SuiteCWE-89SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search
CVE-2026-888285.45.4UnknownBlacklist ManagerCWE-288Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction By…
CVE-2026-1008975.14.9fuzuiStudentInfoCWE-285fuzui StudentInfo Password Change Endpoint moditypasswordstu authorization
CVE-2026-893036.44.8UnknownPost Voting SystemCWE-89Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
CVE-2026-1009002.03.9DevaslanPHPproject-managementCWE-918DevaslanPHP project-management Jira Import jira-import updateJiraProjects ser…
CVE-2026-829695.43.3Bimser Solution Software Trade Inc.eBA Plus Document and Workflow Management SystemCWE-79Stored XSS in BİMSER's eBA Plus
CVE-2026-893005.32.5UnknownWP Verify APICWE-862WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to A…
CVE-2026-942825.62.2x.orglibXiCWE-125Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion
CVE-2026-894115.31.4UnknownPaymatticCWE-345Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe Paymen…
CVE-2026-929965.31.4UnknownVerge3D Publishing and E-CommerceCWE-345Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done
CVE-2026-877235.41.3Googlefuse-archiveCWE-426Untrusted Search Path (PATH Hijacking) in fuse-archive
CVE-2026-942855.11.2x.orglibX11CWE-125Out-of-bounds read in libX11's byte-oriented codeset parser
CVE-2026-942845.50.9x.orglibX11CWE-125Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration pars…
CVE-2026-942875.50.8x.orglibXpmCWE-1050Denial of service via unsigned underflow in libXpm's write path
CVE-2026-855269.9—CanonicalLXDCWE-22Path traversal via Btrfs optimized-backup subvolumes[].path enables root file…
CVE-2026-877999.9—CanonicalLXDCWE-59Arbitrary file write on LXD host via symlink in migration stream
CVE-2026-909249.8—Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.Logsign SIEMCWE-1392Default Admin Credentials in Innotim Software's Logsign SIEM
CVE-2026-123429.6—SailPoint TechnologiesIdentityIQCWE-20SailPoint IdentityIQ Improper Form Validation Vulnerability
CVE-2026-851859.6—CanonicalLXDCWE-22Path traversal in LXD btrfs storage driver allows arbitrary file deletion and…
CVE-2026-888049.6—SUSERancherCWE-79Unauthenticated update of public UI settings leading to stored cross-site scr…
CVE-2026-197599.4—Google CloudApplication IntegrationCWE-863Incorrect Authorization in Application Integration allows Internal Stubby RPC…
CVE-2026-818679.4—Google CloudApplication IntegrationCWE-502Deserialization of Untrusted Data in Application Integration allows Remote Co…
CVE-2026-1012639.4—ZiroomZHOME A0101CWE-77Ziroom ZHOME A0101 set_online_client command injection
CVE-2026-1012649.4—ZiroomZHOME A0101CWE-77Ziroom ZHOME A0101 set_passwd command injection
CVE-2026-736409.3—DayforcePayrollCWE-89Time-based SQL Injection in Dayforce Payroll
CVE-2026-861029.3—WatchGuardWatchGuard APCWE-78WatchGuard AP Command Injection in Internal Management API Allows Command Exe…
CVE-2026-1007529.3—ordasoft.comReal Estate Manager (Free) extension for JoomlaCWE-89Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estat…
CVE-2026-1010399.3—FASTFAC1900RCWE-119FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow
CVE-2026-1010729.3—NetcoreNR289-GECWE-77Netcore NR289-GE CGI ap_ip.cgi system os command injection
CVE-2026-1010759.3—NetcoreNR289-GECWE-77Netcore NR289-GE Location Time location_time.cgi system os command injection
CVE-2026-1010769.3—NetcoreNR289-GECWE-77Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection
CVE-2026-1010779.3—NetcoreNR289-GECWE-287Netcore NR289-GE boa_temp process_request missing authentication
CVE-2026-1011089.3—ordasoft.comVehicle Manager (Free) extension for JoomlaCWE-89Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Ma…
CVE-2026-1011109.3—ordasoft.comBook Library (Free) extension for JoomlaCWE-89Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Libra…
CVE-2026-1018919.3—WatchGuardWatchGuard APCWE-284WatchGuard AP Improper Access Control in API Service Allows Unauthenticated A…
CVE-2026-1023619.3—gz-yamimall4jCWE-306mall4j through 4.0 Missing Authentication in Password Update Endpoint
CVE-2026-736429.2—DayforcePayrollCWE-22Path Traversal in Dayforce Payroll
CVE-2026-499949.1—dannymccbluehoodCWE-306Bluehood: Missing authentication on Bluehood API routes when web auth is enabled
CVE-2026-1018949.1—XhmikosRdecompressCWE-22@xhmikosr/decompress: Path traversal via symlink chain
CVE-2026-1022689.1—jpadillapyjwtCWE-347PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public…
CVE-2026-1023349.1—NginxProxyManagernginx-proxy-managerCWE-307Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection
CVE-2026-1010748.9—NetcoreNR289-GECWE-119Netcore NR289-GE Authentication boa password-check stack-based overflow
CVE-2026-122648.8—ZohocorpDDI CentralCWE-434Authenticated File Write via HA Failover Config Upload leads to RCE
CVE-2026-122658.8—ZohocorpDDI CentralCWE-284Missing Authorization on HA Failover Config allows Complete Data Destruction
CVE-2026-122688.8—ZohocorpDDI CentralCWE-20Authenticated PowerShell Injection leads to RCE
CVE-2026-122698.8—ZohocorpDDI CentralCWE-269Authenticated File Write to RCE via keepalived in DDI Central
CVE-2026-784248.8—SUSENeuVectorCWE-78OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Cod…
CVE-2026-865958.8—Iron Mountain Archiving Services Inc.enVisionCWE-89SQLi in Iron Mountain's enVision
CVE-2026-869508.8—AppleiOS and iPadOSCWE-787An out-of-bounds write issue was addressed with improved bounds checking. Thi…
CVE-2026-877418.8—Brainstorm ForceConvertPlusCWE-78ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via '…
CVE-2026-888088.8—SUSERancherCWE-250Fleet agent copies downstream resources with cluster-admin privileges, allowi…
CVE-2026-909268.8—Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.Logsign SIEMCWE-94Code Injection in Innotim Software's Logsign SIEM
CVE-2026-481008.7—polybasepayyCWE-349Payy: agg_agg trailing message slots are unconstrained and allow forged burn …
CVE-2026-546758.7—FreePBXsecurity-reportingCWE-22FreePBX: Authenticated Remote Code Execution via File Upload and Convert in S…
CVE-2026-965388.7—EnterpriseDBWarehousePGCWE-862WarehousePG pg_file_write/pg_file_rename/pg_file_unlink/pg_logdir_ls privileg…
CVE-2026-1003718.7—InvoicePlaneInvoicePlaneCWE-863InvoicePlane: Incomplete Authorization Remediation in Users::form() Enables P…
CVE-2024-420028.6—Open Source Robotics FoundationRobot Operating System 2 (ROS 2)CWE-94Unsafe use of eval() method in ros2 topic hz tool
CVE-2026-546748.6—FreePBXsecurity-reportingCWE-78Authenticated Command Injection in FreePBX UCP Interface
CVE-2026-547088.6—FreePBXsecurity-reportingCWE-22Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module
CVE-2026-547108.6—FreePBXsecurity-reportingCWE-20FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsaf…
CVE-2026-756008.6—FreePBXsecurity-reportingCWE-78FreePBX: Authenticated API generatedocs Host Command Injection
CVE-2026-879698.6—WatchGuardWatchGuard APCWE-78WatchGuard AP Authenticated Command Injection in Diagnostic CLI
CVE-2026-933488.6—unslothaiunsloth-zooCWE-94Unsloth Zoo Code Injection via model_type in config.json
CVE-2026-1010388.6—FASTFAC1200RCWE-119FAST FAC1200R MmtAtePrase stack-based overflow
CVE-2026-1010818.5—D-LinkDI-8400CWE-119D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp…
CVE-2026-1011878.5—ZiroomZHOME A0101CWE-74Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command…
CVE-2026-1012608.5—ZiroomZHOME A0101CWE-74Ziroom ZHOME A0101 firstLogin command injection
CVE-2026-1012618.5—ZiroomZHOME A0101CWE-74Ziroom ZHOME A0101 firstSetup_wifi command injection
CVE-2026-1012628.5—ZiroomZHOME A0101CWE-74Ziroom ZHOME A0101 set_online_client command injection
CVE-2026-551578.4—ooplestoken-optimizer-mcpCWE-78Token Optimizer MCP: OS command injection in smart_user via username in get-u…
CVE-2026-813758.3—Google CloudApplication IntegrationCWE-610Confused Deputy in Application Integration allows Internal File Read
CVE-2026-1019098.3—axiosaxiosCWE-1321Axios: Prototype Pollution Gadget in axios toFormData Options
CVE-2026-1022968.3—ZoneMinderzoneminderCWE-120ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response
CVE-2026-541608.2—networkupstoolsnutCWE-829Network UPS Tools: A PWN Request in make-dist workflow can execute PR-control…
CVE-2026-910438.2—elixir-mintmintCWE-770HPACK-indexed cookie fields in Mint HTTP/2 responses bypass max_header_list_s…
CVE-2026-1012928.2—Red HatRed Hat AMQ Broker 7CWE-470Artemis-core-client: unsafe reflection in apache activemq artemis federation …
CVE-2026-1019018.2—axiosaxiosCWE-400Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Ses…
CVE-2026-1019038.2—axiosaxiosCWE-1333Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
CVE-2026-1019068.2—axiosaxiosCWE-400Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via u…
CVE-2026-823238.1—Enocta Educational Technologies Inc.Enocta PlatformCWE-639Improper Authorization in Enocta Educational's Enocta Platform
CVE-2026-888058.1—SUSERancherCWE-613Session Not Revoked Server-Side on Logout in Rancher
CVE-2026-45567.8—ExtegrityExam4CWE-78macOS Exam4 Local Privilege Escalation via Command Injection
CVE-2026-165137.8—zephyrprojectzephyrCWE-787Missing write validation of user-supplied handle pointer in the RTIO syscall …
CVE-2026-184137.8—zephyrprojectzephyrCWE-787Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_seque…
CVE-2026-184147.8—zephyrprojectzephyrCWE-787Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence…
CVE-2026-1020047.8—Wind River Systems IncVxWorks 7CWE-787VxWorks 7
CVE-2026-455627.7—FreePBXsecurity-reportingCWE-78FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) M…
CVE-2026-829287.7—F&F FilipowskimH-DEVELOPERCWE-1242Undocumented access path in mH-DEVELOPER
CVE-2026-973357.7—CanonicalLXDCWE-863Incorrect authorization in LXD storage volume API allows reading volumes from…
CVE-2026-551607.6—stringer-rssstringerCWE-918Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer
CVE-2026-933557.6—BerriAIlitellmCWE-1390LiteLLM Weak JWT Authentication via Email-Based User Lookup
CVE-2026-1019057.6—axiosaxiosCWE-441Axios: Node HTTP adapter prototype-pollution gadget allows request socket hij…
CVE-2026-1022767.5—juliangruberbrace-expansionCWE-400brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing st…
CVE-2026-1022787.5—juliangruberbrace-expansionCWE-400brace-expansion: DoS via uncontrolled recursion on nested brace groups causin…
CVE-2026-1022817.5—nestjsnestCWE-248Nest: Remote process termination via a deeply nested microservice message pat…
CVE-2026-1019167.4—grpcgrpc-nodeCWE-295@grpc/grpc-js: In certain configurations, getAuthContext can return unauthori…
CVE-2026-1022667.4—jpadillapyjwtCWE-347PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
CVE-2026-1022677.4—jpadillapyjwtCWE-200PyJWT: PyJWKClient follows redirects when fetching JWKS
CVE-2026-1022717.4—jpadillapyjwtCWE-347PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CV…
CVE-2026-1022727.4—jpadillapyjwtCWE-347PyJWT BOM Bypass
CVE-2026-1022737.4—jpadillapyjwtCWE-347PyJWT accepts public JWK containers as HMAC secrets
CVE-2026-122677.2—ZohocorpDDI CentralCWE-20Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE
CVE-2026-863307.2—Red HatRed Hat Openshift Data Foundation 4CWE-78Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_ho…
CVE-2024-583867.1—ZoneMinderzoneminderCWE-22ZoneMinder 1.37.x Path Traversal via files view
CVE-2026-159527.1—ABBProtection and control IED manager (PCM600)CWE-732Improper Permission Assignment in Scheduler Service
CVE-2026-527487.1—KaonAR2140CWE-306Missing authentication for backup functionality in Kaon AR2140X
CVE-2026-550967.1—leshchenko1979fast-mcp-telegramCWE-184SSRF via DNS-resolution gap in _validate_url_security (file download by URL)
CVE-2026-871147.1—Red HatPen Drive Powered by Red Hat LightspeedCWE-829Kube-compare: container:// reference extraction runs the image entrypoint and…
CVE-2026-909257.1—Innotim Software, Telecommunications and Consultancy Trade Ltd. Co.Logsign SIEMCWE-22Path Traversal in Innotim Software's Logsign SIEM
CVE-2026-935387.1—SUSERancherCWE-290Cross-tenant BundleDeployment and Secret disclosure via spoofed cluster label…
CVE-2026-970237.1—Red HatRed Hat Enterprise Linux 10CWE-61Flatpak: flatpak: arbitrary file deletion in root context via path traversal …
CVE-2026-1010917.1—siyuan-notesiyuanCWE-89SiYuan before v3.8.4 SQL Injection via Block Query Embed
CVE-2026-1023357.1—NginxProxyManagernginx-proxy-managerCWE-863Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config
CVE-2026-1023657.1—gz-yamimall4jCWE-862mall4j through 4.0 Missing Authorization in Admin User Address Endpoints
CVE-2026-803577.0—DellBoot Optimized Server Storage (BOSS)CWE-1191Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, con…
CVE-2026-1003927.0—InvoicePlaneInvoicePlaneCWE-863InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (…
CVE-2026-1018987.0—axiosaxiosCWE-918Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
CVE-2026-1019077.0—axiosaxiosCWE-441Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirec…
CVE-2026-1020107.0—Red HatRed Hat Enterprise Linux 10CWE-825Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after…
CVE-2026-829356.9—F&F FilipowskimH-DEVELOPERCWE-1104Use of End-of-Life components in mH-DEVELOPER
CVE-2026-911546.9—MarcosCamara01Ecommerce TemplateCWE-306Missing authentication in Ecommerce Template product cache revalidation allow…
CVE-2026-1010836.9—n/aPMWebCWE-200PMWeb encryptionhelper.dll information disclosure
CVE-2026-1010926.9—siyuan-notesiyuanCWE-200SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages
CVE-2026-1012776.9—Trusted Domain ProjectOpenDKIMCWE-348Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less tr…
CVE-2026-1019006.9—axiosaxiosCWE-74Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
CVE-2026-1019026.9—axiosaxiosCWE-1321Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Ob…
CVE-2026-1019046.9—axiosaxiosCWE-74Axios: Header Injection via Inherited headers After Minimal Interceptor
CVE-2026-1019086.9—axiosaxiosCWE-1321Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
CVE-2026-1019106.9—beaugundersonip-addressCWE-918ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48…
CVE-2026-1023626.9—gz-yamimall4jCWE-306mall4j through 4.0 Missing Authentication in Product Review Deletion
CVE-2026-187476.8—zephyrprojectzephyrCWE-125Integer underflow of net_buf length in the MCUmgr serial (SMP over console) t…
CVE-2026-803596.8—DellBoot Optimized Server Storage (BOSS)CWE-1191Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, con…
CVE-2026-184176.5—zephyrprojectzephyrCWE-843Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket re…
CVE-2026-194446.5—KubernetesKubernetesCWE-22Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes
CVE-2026-935376.5—SUSERancherCWE-23Path traversal in Fleet Helm valuesFiles allows disclosure of files outside t…
CVE-2026-935406.5—SUSERancherCWE-266Fleet applies namespace labels and annotations without the bundle's service a…
CVE-2026-967406.5—Red HatStreamsHub Console for Apache Kafka®CWE-470Streamshub/console: console-operator: streams for apache kafka console: unfil…
CVE-2026-1019146.5—grpcgrpc-nodeCWE-187@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix…
CVE-2026-1022756.5—jpadillapyjwtCWE-345PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity …
CVE-2026-829306.4—F&F FilipowskimH-DEVELOPERCWE-306Missing Authentication in mH-DEVELOPER
CVE-2026-184156.3—zephyrprojectzephyrCWE-787Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6…
CVE-2026-829296.3—F&F FilipowskimH-DEVELOPERCWE-321Use of Shared Cryptographic Key in mH-DEVELOPER
CVE-2026-863356.3—CanonicalLXDCWE-862LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject …
CVE-2026-921036.3—elixir-mintmintCWE-770Mint HTTP/2 client buffers oversized frames up to 16 MiB before enforcing max…
CVE-2026-941946.3—elixir-mintmintCWE-444Mint HTTP/1 client applies chunked framing when chunked is not the final tran…
CVE-2026-1019116.3—beaugundersonip-addressCWE-400ip-address: Address6 builds a parse diagnostic proportional to the input with…
CVE-2026-1019126.3—beaugundersonip-addressCWE-697ip-address: isInSubnet() and isHostInSubnet() compare addresses of different …
CVE-2026-1019136.3—beaugundersonip-addressCWE-697ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10…
CVE-2026-1023636.3—gz-yamimall4jCWE-306mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number
CVE-2026-877526.1—Rolantis Information Technologies Tourism Industry and Trade Co. Ltd.AgentisCWE-79HTML Injection in Rolantis Information Technologies' Agentis
CVE-2026-829336.0—F&F FilipowskimH-DEVELOPERCWE-1428Cleartext Transmission of Sensitive Information in mH-DEVELOPER
CVE-2026-187465.9—zephyrprojectzephyrCWE-476NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context …
CVE-2026-829365.9—F&F FilipowskimH-DEVELOPERCWE-770Denial of Service in mH-DEVELOPER
CVE-2026-1022745.9—jpadillapyjwtCWE-755PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
CVE-2026-877985.8—CanonicalLXDCWE-59LXD client recursive file pull allows directory escape via malicious VM agent
CVE-2026-1010405.7—RicohSP 330DNCWE-404Ricoh SP 330DN/SP 221/SP C252SF/Aficio SP 3500SF HTTP Multipart Form-Data den…
CVE-2026-159535.6—ABBProtection and control IED manager (PCM600)CWE-22Path Traversal During Project Archive Import
CVE-2026-704135.6—DellLive Optics CollectorCWE-259Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use o…
CVE-2026-976865.5—Wind RiverVxWorks 7CWE-772VxWorks 7 Memory Resource leak
CVE-2026-1010525.5—refly-aireflyCWE-259refly-ai refly JWT Token app.config.ts hard-coded credentials
CVE-2026-1010535.5—ThinkwareU3000CWE-266Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control
CVE-2026-1010545.5—ThinkwareU3000CWE-266Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control
CVE-2026-1010555.5—ThinkwareU3000CWE-200Thinkware U3000 TCP Service GET_STATUS information disclosure
CVE-2026-1010665.5—n/adbgateCWE-22dbgate Archive Link Creation archive.js createLink path traversal
CVE-2026-1010675.5—n/adbgateCWE-22dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal
CVE-2026-1010685.5—n/adbgateCWE-22dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path t…
CVE-2026-1010695.5—n/adbgateCWE-22dbgate Export databaseConnections.js exportModelSql path traversal
CVE-2026-1010705.5—n/adbgateCWE-22dbgate Files Endpoint runners.js files path traversal
CVE-2026-1010735.5—NetcoreNR289-GECWE-287Netcore NR289-GE CGI Dispatcher boa improper authentication
CVE-2026-1010825.5—n/aPMWebCWE-22PMWeb downloader.aspx path traversal
CVE-2026-1011885.5—NetcorePOWER13CWE-640Netcore POWER13 ubus routerd.passwd_set password recovery
CVE-2026-1020055.5—Wind River IncVxWorks 7CWE-401VxWorks Memory Allocation
CVE-2026-1020065.5—Wind River Systems IncVxWorks 7CWE-401VxWorks 7 Memory allocation
CVE-2026-935395.4—SUSERancherCWE-306Unauthenticated GitRepo Spec Mutation via Fleet Git Webhook Receiver
CVE-2026-188255.3—github.com/antonoconnect-corsCWE-346Origin validation error in the connect-xcors npm package
CVE-2026-527495.3—KaonAR2140CWE-287Improper Authentication in Kaon AR2140X
CVE-2026-551565.3—ooplestoken-optimizer-mcpCWE-22Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log …
CVE-2026-829325.3—F&F FilipowskimH-DEVELOPERCWE-923Missing Firewall Configuration in mH-DEVELOPER
CVE-2026-1007535.3—ordasoft.comReal Estate Manager (Free) extension for JoomlaCWE-79Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Esta…
CVE-2026-1010935.3—CotontiCotontiCWE-352Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion
CVE-2026-1010985.3—ag-ui-protocolag-uiCWE-400ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource cons…
CVE-2026-1010995.3—ag-ui-protocolag-uiCWE-755ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition
CVE-2026-1011005.3—ag-ui-protocolag-uiCWE-459ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddlewar…
CVE-2026-1011015.3—ag-ui-protocolag-uiCWE-248ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception
CVE-2026-1011025.3—deepseek-aideepseek-harnessCWE-264deepseek-ai deepseek-harness Code Mode Sandbox run_code sandbox
CVE-2026-1011095.3—ordasoft.comVehicle Manager (Free) extension for JoomlaCWE-79Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle M…
CVE-2026-1011115.3—ordasoft.comBook Library (Free) extension for JoomlaCWE-79Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Libr…
CVE-2026-1019175.3—jpadillapyjwtCWE-770PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown ki…
CVE-2026-1019185.3—jpadillapyjwtCWE-248PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (…
CVE-2026-1022655.3—jpadillapyjwtCWE-674PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
CVE-2026-1022775.3—juliangruberbrace-expansionCWE-400brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU …
CVE-2026-1022975.3—ZoneMinderzoneminderCWE-863ZoneMinder before 1.38.4 Incorrect Authorization in frames API index
CVE-2026-1023335.3—cle-bhttpdbgCWE-79httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL
CVE-2026-1023645.3—gz-yamimall4jCWE-287mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin…
CVE-2026-1023675.3—gz-yamimall4jCWE-613mall4j through 4.0 Insufficient Session Expiration via Token Refresh
CVE-2026-736415.1—DayforcePayrollCWE-79Multiple Reflected XSS in Dayforce Payroll
CVE-2026-803585.1—DellBoot Optimized Server Storage (BOSS)CWE-1191Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, con…
CVE-2026-1022694.8—jpadillapyjwtCWE-180PyJWT: Non-canonical signature segments enable raw-token revocation bypass
CVE-2026-1003704.7—rhuksterdom-sanitizerCWE-20DOMSanitizer - Incomplete data: URL Sanitization in DOMSanitizer::isDangerous…
CVE-2026-595634.6—Zscalerzscaler-mcp-serverCWE-305HMAC Confirmation Token Unbinding in zscaler-mcp-server
CVE-2026-1023324.6—amir20dozzleCWE-22Dozzle before 11.1.2 Path Traversal via Log ZIP Download
CVE-2026-1022704.4—jpadillapyjwtCWE-1333PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
CVE-2026-130184.3—GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-863344.2—CanonicalLXDCWE-22CLI Path Traversal via Content-Disposition in LXD Image Export/Copy
CVE-2026-823264.1—Enocta Educational Technologies Inc.Enocta PlatformCWE-79HTML Injection in Enocta Educational's Enocta Platform
CVE-2026-970263.9—Red HatRed Hat Enterprise Linux 10CWE-378Flatpak: flatpak: world-writable temporary child repositories in system-helpe…
CVE-2026-184163.7—zephyrprojectzephyrCWE-125Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_pat…
CVE-2026-973993.7—The GNU C LibraryglibcCWE-126One-byte overread in strncasecmp on Power8
CVE-2026-1013333.7—Red HatRed Hat Build of KeycloakCWE-770Keycloak-services: keycloak-services: unbounded metric series creation via id…
CVE-2026-1019153.7—grpcgrpc-nodeCWE-550@grpc/grpc-js: The server transmits some error messages thrown by method hand…
CVE-2026-970273.6—Red HatRed Hat Enterprise Linux 10CWE-20Flatpak: flatpak: denial of service via unsanitized keys in exported desktop …
CVE-2026-970253.2—Red HatRed Hat Enterprise Linux 10CWE-378Flatpak: flatpak: world-readable oci authentication token in system-helper ca…
CVE-2026-1022793.1—laravelframeworkCWE-80Laravel: XSS in Debug Page Information
CVE-2026-1012652.3—IntelbrasTIP 125iCWE-540Intelbras TIP 125i Básico sensitive information in source
CVE-2026-1010712.1—Acrel ElectricUnet Web ServiceCWE-284Acrel Electric Unet Web Service Upload Endpoint upload unrestricted upload
CVE-2026-1011052.1—code-projectsMatrimonial SystemCWE-74code-projects Matrimonial System Profile Creation Endpoint create_profile pro…
CVE-2026-1011422.1—EleveoQuality ManagementCWE-22Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path trave…
CVE-2026-1011432.1—EleveoQuality ManagementCWE-200Eleveo Quality Management QMBODownload information disclosure
CVE-2026-1011442.1—EleveoCall Recording SoftwareCWE-266Eleveo Call Recording Software Query Builder searchAction.do access control
CVE-2026-1011452.1—EleveoCall Recording SoftwareCWE-74Eleveo Call Recording Software User Management userAddAction.do ldap injection
CVE-2026-1011462.1—EleveoQuality ManagementCWE-200Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAu…
CVE-2026-1012022.1—FastStoneImage ViewerCWE-119FastStone Image Viewer TGA Image out-of-bounds write
CVE-2026-1012032.1—FastStoneImage ViewerCWE-119FastStone Image Viewer 1bpp RLE Decoder out-of-bounds write
CVE-2026-1012042.1—FastStoneImage ViewerCWE-119FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds
CVE-2026-1012052.1—FastStoneImage ViewerCWE-119FastStone Image Viewer PCX Decoder out-of-bounds
CVE-2026-1018612.1—langflow-ailangflowCWE-94Langflow Code Execution via eval() in Component Input Schema
CVE-2026-1023662.1—gz-yamimall4jCWE-434mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints
CVE-2026-1011392.0—WebkulBagistoCWE-862Webkul Bagisto Invoice Mass Status Update state authorization
CVE-2026-1011412.0—EleveoCall Recording SoftwareCWE-79Eleveo Call Recording Software Play Audio audio.jsp cross site scripting
CVE-2026-1010781.9—deepseek-aideepseek-harnessCWE-653deepseek-ai deepseek-harness Landlock Backend profiles.ts isolation
CVE-2026-1011311.9—deepseek-aideepseek-harnessCWE-20deepseek-ai deepseek-harness dsh index.ts reliance on untrusted inputs in a s…
CVE-2026-1011321.3—DeepSeekdeepseek-harnessCWE-22DeepSeek deepseek-harness Bundle Patch profile.ts loadProfile path traversal
CVE-2026-1010790.9—agentverusagentverus-scannerCWE-20agentverus agentverus-scanner context.js isSecurityDefenseSkill reliance on u…
CVE-2026-1010800.9—TencentAI-Infra-GuardCWE-22Tencent AI-Infra-Guard File Access dir_actions.py startsWith path traversal
CVE-2026-84894await—Meta Platforms, Incmoxygen—In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps u…
CVE-2026-84895await—Facebookproxygen—In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSes…
CVE-2026-85644await——XS-Parse-KeywordCWE-125XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as a…
CVE-2026-88815await——DBICWE-843DBI versions before 1.654 for Perl incorrectly treat numeric values as string…
CVE-2026-88816await——DBICWE-843DBI versions before 1.654 for Perl incorrectly treat numeric values as string…
CVE-2026-91006await—Apache Software FoundationApache KarafCWE-78Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / Ins…
CVE-2026-91095await—Facebookproxygen—In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::on…
CVE-2026-91096await—Facebookproxygen—In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::termi…
CVE-2026-96760await—AuthlibAuthlib—Authlib library contains a signature‑verification bypass vulnerability

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-28 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.