boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, September 29, 2026 · all times UTC← 2026-09-28 · archive

Security Box Score — September 29, 2026

CISA adds 1 to KEV; 611 CVEs published, led by Google (142).

611 CVEs published September 29, 2026: 70 critical, 224 high, 169 medium, 46 low; 0 in the KEV catalog at press time; 5 with a public exploit reference; 102 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 211 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1430649292——
KEV catalog size1729

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3164 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux21156205530263871311560.17.8.0019+472 ▲
microsoft10022901202199169216290311.17.8.0047+525 ▲
google6622831355109112221318090.37.5.0027+260 ▲
red hat2618945137641453200.06.7.0036+39 ▲
apple24756467166317148991.66.5.0019+203 ▲
suse2553827162000.07.5.0036+18 ▲
canonical8501612175000.07.8.0021-7 ▼
freebsd04823673000.07.8.0016-32 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0046+51 ▲
ubiquiti665362810334.69.1.0050-17 ▼
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-7 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache176688151288225163320.37.5.0063+18 ▲
mozilla190378111159820900.08.8.0032+131 ▲
gitlab281047246211532.95.3.0034+3 ▲
drupal2694119668411.15.7.0027+9 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614103350.08.7.0340-1 ▼
kubernetes120011000.04.5.0028+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-256 ▼
ibm404102319647333618610.17.5.0037+14 ▲
adobe2248308236437592150.67.5.0036+123 ▲
progress5661540110611.58.1.0046-14 ▼
zohocorp324262970000.08.3.0117+28 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-13 ▼
servicenow5107300200.09.4.0036+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link297422281212300.08.5.0164+13 ▲
siemens1552633103000.07.3.0026-6 ▼
synology1946510256000.05.6.0032+15 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
hitachi energy9122460000.07.0.0030+9 ▲
abb4111640000.07.2.0018+4 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell2073783117215124210.37.2.0027+136 ▲
sourcecodester632320013894000.05.5.0043+15 ▲
openclaw8421741098321000.07.1.0031+84 ▲
nvidia5318725129330000.07.8.0040+1 ▲
spring017013608314000.06.5.0033-91 ▼
mongodb71169699604100.07.1.0038+16 ▲
hewlett packard enterprise (hpe)1571662280559110.67.2.0045+154 ▲
itsourcecode371530037116000.02.1.0033+5 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.914399.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-87902.197697.38.1
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-83548.087695.010.0
CVE-2026-85102.075594.39.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9143KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
Most disclosures (vendor)
VendorCVEs
linux2115
microsoft1002
google662
oracle634
ibm404
red hat267
apple247
adobe224
dell208
mozilla191
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco16
apple9
google9
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven103
Packagist18
npm18
PyPI14
crates.io9
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171777
CVE-2021-27102n/a2021-11-171777
CVE-2021-27101n/a2021-11-171777
CVE-2021-27103n/a2021-11-171777
CVE-2021-21017Adobe2021-11-171777
CVE-2021-28550Adobe2021-11-171777
CVE-2021-42013Apache Software Foundation2021-11-171777
CVE-2021-41773Apache Software Foundation2021-11-171777
CVE-2021-30858Apple2021-11-171777
CVE-2021-30860Apple2021-11-171777

Transactions

ADDED TO KEV — CVE-2026-86950 (Apple iOS and iPadOS). Remediation due October 2, 2026.

EXPLOIT PUBLISHED — sooperset mcp-atlassian: 15 CVEs (CVE-2026-77242, CVE-2026-77243, CVE-2026-77244, CVE-2026-77249, CVE-2026-77250, CVE-2026-77251, CVE-2026-77255, CVE-2026-77258, CVE-2026-77259, CVE-2026-77260, CVE-2026-77262, CVE-2026-77265, CVE-2026-77267, CVE-2026-77268, CVE-2026-77269). Public exploit references added.

EXPLOIT PUBLISHED — AcademySoftwareFoundation OpenImageIO: 12 CVEs (CVE-2026-50291, CVE-2026-59156, CVE-2026-59181, CVE-2026-59956, CVE-2026-63419, CVE-2026-63420, CVE-2026-63422, CVE-2026-63635, CVE-2026-63638, CVE-2026-65969, CVE-2026-65970, CVE-2026-67549). Public exploit references added.

EXPLOIT PUBLISHED — cesanta mongoose: 7 CVEs (CVE-2026-73253, CVE-2026-73254, CVE-2026-73255, CVE-2026-73256, CVE-2026-73257, CVE-2026-73258, CVE-2026-73259). Public exploit references added.

EXPLOIT PUBLISHED — angular: 5 CVEs (CVE-2026-88056, CVE-2026-88057, CVE-2026-88058, CVE-2026-88059, CVE-2026-88060). Public exploit references added.

EXPLOIT PUBLISHED — grokability snipe-it: 5 CVEs (CVE-2026-62368, CVE-2026-63493, CVE-2026-63498, CVE-2026-84206, CVE-2026-88894). Public exploit references added.

EXPLOIT PUBLISHED — GestSup: 4 CVEs (CVE-2026-100389, CVE-2026-102372, CVE-2026-102373, CVE-2026-102374). Public exploit references added.

EXPLOIT PUBLISHED — FreeRDP: 3 CVEs (CVE-2026-55193, CVE-2026-67293, CVE-2026-68580). Public exploit references added.

EXPLOIT PUBLISHED — Ziroom ZHOME A0101: 3 CVEs (CVE-2026-101187, CVE-2026-101260, CVE-2026-101262). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-100303 (TDuckCloud tduck-survey-form). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100310 (GNU libextractor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100312 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100315 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101139 (Webkul Bagisto). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101141 (Eleveo Call Recording Software). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101143 (Eleveo Quality Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101144 (Eleveo Call Recording Software). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101146 (Eleveo Quality Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57228 (OISF suricata). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-75926 (gohugoio hugo). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79718 (Netron). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-79719 (Netron). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93355 (BerriAI litellm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95844 (moquette-io moquette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97896 (krayin laravel-crm). Public exploit reference added.

DUE DATE PASSED — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was September 28, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-67279 (Mikrotik RouterOS). CISA remediation deadline was September 28, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-87902 (WordPress). CISA remediation deadline was September 28, 2026; still in catalog.

RESCORED — NVIDIA Infrastructure Controller: 10 CVEs (CVE-2026-65114, CVE-2026-65117, CVE-2026-65118, CVE-2026-65121, CVE-2026-65124, CVE-2026-65125, CVE-2026-65126, CVE-2026-65127, CVE-2026-65129, CVE-2026-65130). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2017-20051 (InnoSetup Installer). CVSS 5.3 → 2.1 (NVD).

RESCORED — CVE-2023-6394 (Red Hat build of Quarkus 3.2.9.Final). CVSS 7.4 → 9.1 (NVD).

RESCORED — CVE-2024-58376 (renovatebot renovate). CVSS 9.3 → 8.4 (NVD).

RESCORED — CVE-2025-31356 (Intel(R) Trust Domain Extensions (Intel(R) TDX)). CVSS 5.6 → 5.7 (NVD).

RESCORED — CVE-2026-101263 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).

RESCORED — CVE-2026-101264 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).

RESCORED — CVE-2026-101265 (Intelbras TIP 125i). CVSS 2.3 → 1.3 (NVD).

RESCORED — CVE-2026-101277 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-17504 (IBM PowerVM Hypervisor). CVSS 5.1 → 4.4 (NVD).

RESCORED — CVE-2026-51772. CVSS 8.1 → 6.5 (NVD).

RESCORED — CVE-2026-57228 (OISF suricata). CVSS 8.2 → 9.1 (NVD).

RESCORED — CVE-2026-62368 (grokability snipe-it). CVSS 8.1 → 8.4 (NVD).

RESCORED — CVE-2026-63498 (grokability snipe-it). CVSS 8.7 → 5.4 (NVD).

RESCORED — CVE-2026-69559 (Microsoft Teams for Android). CVSS 5.8 → 6.3 (NVD).

RESCORED — CVE-2026-69805 (Microsoft Visual Studio 2022 version 17.14). CVSS 7.5 → 8.1 (NVD).

RESCORED — CVE-2026-69854 (Microsoft Spring Cloud Azure). CVSS 9 → 8.1 (NVD).

RESCORED — CVE-2026-77265 (sooperset mcp-atlassian). CVSS 5.9 → 7.5 (NVD).

RESCORED — CVE-2026-77909 (Microsoft Azure CycleCloud 8.9.2). CVSS 7.7 → 6.5 (NVD).

RESCORED — CVE-2026-78545 (Okta Access Gateway). CVSS 6.6 → 7.2 (NVD).

RESCORED — CVE-2026-78550 (Okta Access Gateway). CVSS 6.6 → 7.2 (NVD).

RESCORED — CVE-2026-88059 (angular). CVSS 4 → 5.8 (NVD).

RESCORED — CVE-2026-88420. CVSS 6.1 → 5.4 (NVD).

PATCH SHIPPED — CVE-2026-102010 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 13.5.0-0.2.hum1.

PATCH SHIPPED — CVE-2026-57759 (Metagauss ProfileGrid). Fixed in ProfileGrid 6.0.0.3.

Yesterday's Results

How to read these box scores · glossary

611 CVEs published. 25 box scores and 375 table rows below; the remaining 211 continue on page 2 — every CVE is listed, nothing truncated.

RaspAP raspap-webgui SSID Processing WiFiManager.php writeWpaSupplicant os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0205   80.5     —
AFFECTED
  Product        Versions  Fixed
  raspap-webgui  3.5.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Netcore NAP930 Network Tools CGI network_tools eval os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0201   80.1     —
AFFECTED
  Product  Versions             Fixed
  NAP930   0.1.241010.141410 –  —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   L    2.1   .0158   74.5     —
AFFECTED
  Product        Versions  Fixed
  raspap-webgui  3.5.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
MODSetter SurfSense MCP Connector Integration test command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0116   65.8     —
AFFECTED
  Product    Versions  Fixed
  SurfSense  2.0.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-74, CWE-77 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Hitachi Energy RTU500 series CMU firmware — A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life v…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0116   65.8     —
AFFECTED
  Product                     Versions  Fixed
  RTU500 series CMU firmware  9.0 –     —
TIMELINE
  May 7   Reserved by CNA
  Sep 29  Published (CNA: Hitachi Energy)
CWE-23 · CNA: Hitachi Energy · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Hitachi Energy RTU500 series CMU firmware — An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0058   45.4     —
AFFECTED
  Product                     Versions  Fixed
  RTU500 series CMU firmware  9.0 –     —
TIMELINE
  May 7   Reserved by CNA
  Sep 29  Published (CNA: Hitachi Energy)
CWE-306 · CNA: Hitachi Energy · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    7.4   .0047   38.5     —
AFFECTED
  Product        Versions  Fixed
  raspap-webgui  3.5.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-266, CWE-269 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Wireshark Foundation Wireshark — Heap-based Buffer Overflow in Wireshark
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0045   36.9     —
AFFECTED
  Product    Versions  Fixed
  Wireshark  4.6.0 –   —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 29  Published (CNA: GitLab)
CWE-122 · CNA: GitLab · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Hitachi Energy Asset Suite — Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for confi…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   H   H   N    8.5   .0042   33.7     —
AFFECTED
  Product      Versions  Fixed
  Asset Suite  9.6.0 –   —
TIMELINE
  Apr 29  Reserved by CNA
  Sep 29  Published (CNA: Hitachi Energy)
CWE-306 · CNA: Hitachi Energy · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Hitachi Energy Asset Suite — Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCach…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   N   N   L    5.1   .0042   33.7     —
AFFECTED
  Product      Versions  Fixed
  Asset Suite  9.6.0 –   —
TIMELINE
  Jun 9   Reserved by CNA
  Sep 29  Published (CNA: Hitachi Energy)
CWE-306 · CNA: Hitachi Energy · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_domain improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0041   32.7     —
AFFECTED
  Product    Versions  Fixed
  OpenDMARC  1.4.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Trusted Domain Project OpenDMARC Multi-Record Set opendmarc_policy_query_dmarc authentication spoofing
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0040   31.9     —
AFFECTED
  Product    Versions  Fixed
  OpenDMARC  1.4.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-287, CWE-290 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
n/a FastAdmin — FastAdmin Database Management database.php unnecessary privileges
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   P   H   H   H    7.1   .0039   30.9     —
AFFECTED
  Product    Versions          Fixed
  FastAdmin  1.6.1.20250430 –  —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-250 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
Wireshark Foundation Wireshark — Heap-based Buffer Overflow in Wireshark
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0039   30.7     —
AFFECTED
  Product    Versions  Fixed
  Wireshark  4.6.0 –   —
TIMELINE
  Sep 22  Reserved by CNA
  Sep 29  Published (CNA: GitLab)
CWE-122 · CNA: GitLab · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0039   30.0     —
AFFECTED
  Product    Versions  Fixed
  SurfSense  2.0.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   N   N   H   H   H    8.6   .0038   29.8     —
AFFECTED
  Product   Versions          Fixed
  FAC1203R  20200116_2.0.4 –  —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0038   29.7     —
AFFECTED
  Product      Versions  Fixed
  shell-quote  1.8.4 –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 29  Published (CNA: harborist)
CWE-78 · CNA: harborist · CVSS v4.0 · 4 references · NVD status: Received
n/a Rebuild — Rebuild Login Endpoint login improper authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0038   29.8     —
AFFECTED
  Product  Versions  Fixed
  Rebuild  4.4.0 –   —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: VulDB)
CWE-287 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Deferred
GitLab GitLab — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  C  H  H  N    8.7   .0036   27.6     —
AFFECTED
  Product  Versions  Fixed
  GitLab   13.11 –   —
TIMELINE
  Sep 2   Reserved by CNA
  Sep 29  Published (CNA: GitLab)
CWE-79 · CNA: GitLab · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Dassault Systèmes GEOVIA Geospatial Data Manager — Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0036   26.7     —
AFFECTED
  Product                         Versions                              Fixed
  GEOVIA Geospatial Data Manager  Release 3DEXPERIENCE R2024x Golden –  —
TIMELINE
  Sep 1   Reserved by CNA
  Sep 29  Published (CNA: 3DS)
CWE-94 · CNA: 3DS · CVSS v3.1 · 1 reference · NVD status: Received
GitLab GitLab — Missing Authorization in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  L  N  N    3.7   .0034   25.5     —
AFFECTED
  Product  Versions  Fixed
  GitLab   15.11 –   —
TIMELINE
  Mar 20  Reserved by CNA
  Sep 29  Published (CNA: GitLab)
CWE-862 · CNA: GitLab · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Flowring Agentflow 4.0 - SQL Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0034   25.2     —
AFFECTED
  Product        Versions     Fixed
  Agentflow 4.0  unspecified  —
TIMELINE
  Sep 23  Reserved by CNA
  Sep 29  Published (CNA: ZUSO ART)
CWE-89 · CNA: ZUSO ART · CVSS v4.0 · 1 reference · NVD status: Deferred
Octopus Deploy Octopus Server — In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Pr…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0033   24.3     —
AFFECTED
  Product         Versions    Fixed
  Octopus Server  2019.4.1 –  —
TIMELINE
  Sep 28  Reserved by CNA
  Sep 29  Published (CNA: Octopus)
CWE-502 · CNA: Octopus · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
GitLab GitLab — Incorrect Authorization in GitLab
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  L  N  N    4.3   .0033   23.7     —
AFFECTED
  Product  Versions  Fixed
  GitLab   17.9 –    —
TIMELINE
  Jun 1   Reserved by CNA
  Sep 29  Published (CNA: GitLab)
CWE-863 · CNA: GitLab · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Hitachi Energy RTU500 series CMU firmware — An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an a…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0032   23.0     —
AFFECTED
  Product                     Versions  Fixed
  RTU500 series CMU firmware  9.0 –     —
TIMELINE
  May 7   Reserved by CNA
  Sep 29  Published (CNA: Hitachi Energy)
CWE-862 · CNA: Hitachi Energy · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1012795.523.0Trusted Domain ProjectOpenDMARCCWE-189Trusted Domain Project OpenDMARC opendmarc_policy.c integer overflow
CVE-2026-92142await21.8Apache Software FoundationApache KarafCWE-862Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
CVE-2026-970247.121.4Red HatRed Hat Enterprise Linux 10CWE-61Flatpak: flatpak: arbitrary write in root context via path traversal in deplo…
CVE-2026-964407.119.6Flowring Technology CorpAgentflow 4.0CWE-22Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Di…
CVE-2026-1024146.318.8browserifypbkdf2CWE-400pbkdf2 rehashes long passwords on every iteration, enabling denial of service
CVE-2026-1022495.518.8n/aREBUILDCWE-862REBUILD file-editor-save authorization
CVE-2026-1022922.118.6coolbeans1212MateisHomePage-WebsiteCWE-79coolbeans1212 MateisHomePage-Website users.php cross site scripting
CVE-2026-1022935.518.2realjerrytangtacomallCWE-266realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServic…
CVE-2026-964299.318.1Flowring Technology CorpAgentflow 4.0CWE-89Flowring Agentflow 4.0 - SQL Injection
CVE-2026-964319.317.9Flowring Technology CorpAgentflow 4.0CWE-434Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type
CVE-2026-89374.316.3GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-1018787.715.8bitwardenbitwarden serverCWE-303Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier…
CVE-2026-1022902.014.5CodeCanyonRocket LMSCWE-79CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting
CVE-2026-970295.714.1Red HatRed Hat Enterprise Linux 10CWE-653Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same …
CVE-2026-1022612.114.0owen2345Camaleon CMSCWE-285owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization
CVE-2026-767188.213.9Hewlett Packard EnterpriseHPE OneViewCWE-79HPE OneView - Cross-site scripting vulnerability
CVE-2026-976857.113.3LimeSurveyLimeSurveyCWE-639LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass…
CVE-2026-1023737.113.4GestSupGestSupCWE-639GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter
CVE-2026-1022442.112.1MODSetterSurfSenseCWE-918MODSetter SurfSense Document Export Feature editor_routes.py server-side requ…
CVE-2026-964308.712.0Flowring Technology CorpAgentflow 4.0CWE-749Flowring Agentflow 4.0 - Exposed Dangerous Method or Function
CVE-2026-1022412.011.3NetcoreNAP930CWE-320Netcore NAP930 Backup/Restore backup_common.sh hard-coded key
CVE-2026-1022632.011.0mwasikzrobo-cafe-rmsCWE-284mwasikz robo-cafe-rms manage-food.php unrestricted upload
CVE-2026-1023725.310.2GestSupGestSupCWE-79GestSup before 3.2.61 Stored XSS via Email Body in LOGIN IMAP Connector
CVE-2026-1023745.310.2GestSupGestSupCWE-79GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IM…
CVE-2026-819144.38.9Apache Software FoundationApache Airflow Google providerCWE-943Apache Airflow Google provider: Google Drive query injection via unescaped fi…
CVE-2026-1022642.07.8mwasikzrobo-cafe-rmsCWE-79mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scri…
CVE-2026-963267.27.8htpluginsHT Contact Form – Drag & Drop Form Builder for WordPressCWE-79HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenti…
CVE-2026-91048await7.6Apache Software FoundationApache KarafCWE-862Apache Karaf: Missing authorization on the jdbc:* shell command scope allows …
CVE-2026-964195.57.4Wireshark FoundationWiresharkCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-91012await5.9Apache Software FoundationApache Karaf—Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privil…
CVE-2026-91085await4.9Apache Software FoundationApache KarafCWE-862Apache Karaf: config:install missing ACL entry allows privilege escalation to…
CVE-2026-953925.54.3Wireshark FoundationWiresharkCWE-126Buffer Over-read in Wireshark
CVE-2026-964175.53.7Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-1024744.03.1Red HatRed Hat Enterprise Linux 6CWE-787Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode es…
CVE-2026-953865.52.8Wireshark FoundationWiresharkCWE-835Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
CVE-2026-953905.52.8Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-953915.52.8Wireshark FoundationWiresharkCWE-416Use After Free in Wireshark
CVE-2026-953955.52.8Wireshark FoundationWiresharkCWE-401Missing Release of Memory after Effective Lifetime in Wireshark
CVE-2026-953885.52.8Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-964155.52.8Wireshark FoundationWiresharkCWE-121Stack-based Buffer Overflow in Wireshark
CVE-2026-964165.52.8Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-964185.52.8Wireshark FoundationWiresharkCWE-835Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
CVE-2026-953944.72.5Wireshark FoundationWiresharkCWE-606Unchecked Input for Loop Condition in Wireshark
CVE-2026-964215.52.4Wireshark FoundationWiresharkCWE-1325Improperly Controlled Sequential Memory Allocation in Wireshark
CVE-2026-964225.52.4Wireshark FoundationWiresharkCWE-617Reachable Assertion in Wireshark
CVE-2026-964235.52.4Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-1012782.12.4Trusted Domain ProjectOpenDMARCCWE-345Trusted Domain Project OpenDMARC PSL Wildcard opendmarc_tld.c : opendmarc_get…
CVE-2026-1024735.52.2Red HatRed Hat Enterprise Linux 6CWE-1333Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disa…
CVE-2026-953934.72.1Wireshark FoundationWiresharkCWE-122Heap-based Buffer Overflow in Wireshark
CVE-2026-964204.71.7Wireshark FoundationWiresharkCWE-126Buffer Over-read in Wireshark
CVE-2026-861575.61.6Progress SoftwareProgress® Telerik® Fiddler® EverywhereCWE-749Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere
CVE-2026-861587.70.3Progress SoftwareProgress® Telerik® Fiddler® EverywhereCWE-306Missing Authentication in the local .NET backend of Progress Telerik Fiddler …
CVE-2026-7137910.0—Toptech SystemsTMS7CWE-552Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties
CVE-2026-9658710.0—ViidureDashcam Android ApplicationCWE-798Use of Hard-coded Credentials in Viidure Dashcam Android Application
CVE-2026-391179.8—n/an/aCWE-94An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plug…
CVE-2026-767219.8—Hewlett Packard Enterprise (HPE)Instant ON—Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution …
CVE-2026-767229.8—Hewlett Packard Enterprise (HPE)Instant ON—Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or D…
CVE-2026-771779.8—n/an/aCWE-94Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for …
CVE-2026-795389.8—n/an/aCWE-94metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Executio…
CVE-2026-767239.6—Hewlett Packard Enterprise (HPE)Instant ON—Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code …
CVE-2026-767249.6—Hewlett Packard Enterprise (HPE)Instant ON—Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking In…
CVE-2026-767259.6—Hewlett Packard Enterprise (HPE)Instant ON—Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs
CVE-2026-952779.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a rem…
CVE-2026-952819.6—GoogleChromeCWE-122Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.5…
CVE-2026-952839.6—GoogleChromeCWE-122Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57…
CVE-2026-952999.6—GoogleChromeCWE-416Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remot…
CVE-2026-953109.6—GoogleChromeCWE-416Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953119.6—GoogleChromeCWE-590Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allo…
CVE-2026-953139.6—GoogleChromeCWE-416Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed …
CVE-2026-953189.6—GoogleChromeCWE-122Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a re…
CVE-2026-953259.6—GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a rem…
CVE-2026-953299.6—GoogleChromeCWE-787Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.80…
CVE-2026-953319.6—GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed …
CVE-2026-953399.6—GoogleChromeCWE-416Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allow…
CVE-2026-953479.6—GoogleChromeCWE-416Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 a…
CVE-2026-953499.6—GoogleChromeCWE-122Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.5…
CVE-2026-953509.6—GoogleChromeCWE-122Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.5…
CVE-2026-953569.6—GoogleChromeCWE-416Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowe…
CVE-2026-953579.6—GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037…
CVE-2026-1007629.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Content Processes component
CVE-2026-1007709.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Content Processes component
CVE-2026-1007789.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Core & HTML component
CVE-2026-1007869.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the Graphics component
CVE-2026-1008009.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the Disability Access APIs component
CVE-2026-1008049.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the Preferences: Backend component
CVE-2026-1008119.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the DOM: Core & HTML component
CVE-2026-1008189.6—MozillaFirefoxCWE-416Sandbox escape due to use-after-free in the Widget: Gtk component
CVE-2026-1008199.6—MozillaFirefoxCWE-119Sandbox escape due to incorrect boundary conditions in the XPCOM component
CVE-2026-1023049.6—GoogleChromeCWE-416Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a…
CVE-2026-1023069.6—GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a…
CVE-2026-1023089.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a rem…
CVE-2026-1023099.6—GoogleChromeCWE-416Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed …
CVE-2026-1023169.6—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a rem…
CVE-2026-1023319.6—GoogleChromeCWE-122Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.9…
CVE-2026-1024259.5—balbooa.comBalbooa Forms extension for JoomlaCWE-94Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode inje…
CVE-2026-703569.4—Toptech SystemsTMS7CWE-434Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type
CVE-2026-829739.4—psyb0tdocker-mailboxCWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox
CVE-2026-1027939.4—ZiroomZHOME A0101CWE-77Ziroom ZHOME A0101 set_time_zone command injection
CVE-2026-1027949.4—ZiroomZHOME A0101CWE-77Ziroom ZHOME A0101 ping command injection
CVE-2023-544009.3—FumasoftFumeng CloudCWE-89Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname
CVE-2026-71929.3—Shenzhen Dbit Network EquipmentT-CPE301K 4G Mini WiFi RouterCWE-121Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen D…
CVE-2026-220949.3—EVbeeDC 80CWE-1391Weak root password in EVbee DC 80
CVE-2026-855209.3—MyPrestaGoogle Merchant Center FeedCWE-73Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module
CVE-2026-1002919.3—AnjvisionYSSD-RTMP-H5CWE-1188Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5
CVE-2026-1027109.3—Eclipse Foundationeclipse-threadx/threadxCWE-269Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_M…
CVE-2026-1027619.3—Eclipse FoundationNetX DuoCWE-787NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACK…
CVE-2026-1030409.3—ModelTCLightLLMCWE-502LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profi…
CVE-2026-1030419.3—ModelTCLightLLMCWE-502LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache …
CVE-2026-539889.2—FinsysdockhandCWE-306Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints
CVE-2026-861319.2—WatchGuardFireware OSCWE-295Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution
CVE-2026-1028289.2—steveukxgit-jsCWE-78simple-git unsafe-operation guard does not block trailer command configuration
CVE-2026-1028299.2—steveukxgit-jsCWE-78simple-git: `VISUAL` editor environment variable is omitted from unsafe edito…
CVE-2026-844369.1—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-153909.0—DENX Software EngineeringDas U-BootCWE-459Out-of-bounds write in Das U-Boot
CVE-2026-922228.9—Joomla! ProjectJoomla! CMSCWE-918Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in…
CVE-2026-976898.9—urllib3urllib3CWE-770urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size…
CVE-2026-1024248.9—balbooa.comBalbooa Forms extension for JoomlaCWE-22Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates l…
CVE-2026-719718.8—u-bootu-bootCWE-787U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly
CVE-2026-742208.8—u-bootu-bootCWE-195U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply
CVE-2026-742218.8—u-bootu-bootCWE-195U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK
CVE-2026-742228.8—u-bootu-bootCWE-416U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback
CVE-2026-828048.8—Apache Software FoundationApache DolphinSchedulerCWE-78Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE-2026-844218.8—IBMDataStage on Cloud Pak for DataCWE-22DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-877488.8—Interprobe Information Technologies Inc.Qorela DCCWE-862Privilege Escalation via Account Takeover in Interprobe's Qorela DC
CVE-2026-923708.8—TeamViewerFull ClientCWE-284Remote Session Access Control Bypass Leading to Remote Code Execution
CVE-2026-952828.8—GoogleChromeCWE-416Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-952868.8—GoogleChromeCWE-843Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953048.8—GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a r…
CVE-2026-953068.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote…
CVE-2026-953388.8—GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a re…
CVE-2026-953438.8—GoogleChromeCWE-416Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953458.8—GoogleChromeCWE-416Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a rem…
CVE-2026-953538.8—GoogleChromeCWE-416Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953658.8—GoogleChromeCWE-843Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a…
CVE-2026-953698.8—GoogleChromeCWE-841Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-953738.8—GoogleChromeCWE-416Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953808.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote…
CVE-2026-955098.8—qtQt for MCUsCWE-125Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs
CVE-2026-1007578.8—MozillaFirefoxCWE-416Use-after-free in the Widget component
CVE-2026-1007618.8—MozillaFirefoxCWE-416Privilege escalation due to use-after-free in the Graphics: WebGPU component
CVE-2026-1007648.8—MozillaFirefoxCWE-119Privilege escalation due to incorrect boundary conditions in the Graphics: We…
CVE-2026-1007658.8—MozillaFirefoxCWE-416Use-after-free in the JavaScript: WebAssembly component
CVE-2026-1007678.8—MozillaFirefoxCWE-416Use-after-free in the Networking: Cache component
CVE-2026-1007688.8—MozillaFirefoxCWE-416Use-after-free in the Graphics: WebGPU component
CVE-2026-1007698.8—MozillaFirefoxCWE-416Use-after-free in the JavaScript: WebAssembly component
CVE-2026-1007728.8—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-1007738.8—MozillaFirefoxCWE-416Use-after-free in the Storage: IndexedDB component
CVE-2026-1007748.8—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-1007768.8—MozillaFirefoxCWE-416Use-after-free in the JavaScript: WebAssembly component
CVE-2026-1007778.8—MozillaFirefoxCWE-416Use-after-free in the Graphics: Canvas2D component
CVE-2026-1007798.8—MozillaFirefoxCWE-416Use-after-free in the XSLT component
CVE-2026-1007808.8—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-1007828.8—MozillaFirefoxCWE-119Privilege escalation due to incorrect boundary conditions in the Graphics com…
CVE-2026-1007848.8—MozillaFirefoxCWE-416Use-after-free in the Layout: Text and Fonts component
CVE-2026-1007858.8—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-1007898.8—MozillaFirefoxCWE-416Use-after-free in the Graphics: Canvas2D component
CVE-2026-1007908.8—MozillaFirefoxCWE-416Use-after-free in the XSLT component
CVE-2026-1007918.8—MozillaFirefoxCWE-416Use-after-free in the DOM: Core & HTML component
CVE-2026-1007968.8—MozillaFirefoxCWE-416Use-after-free in the JavaScript: WebAssembly component
CVE-2026-1007978.8—MozillaFirefoxCWE-416Privilege escalation due to use-after-free in the Graphics: WebRender component
CVE-2026-1008018.8—MozillaFirefoxCWE-269Privilege escalation in the DLL Services component
CVE-2026-1008078.8—MozillaFirefoxCWE-269Privilege escalation in the DOM: Service Workers component
CVE-2026-1008138.8—MozillaFirefoxCWE-763Invalid pointer in the JavaScript Engine: JIT component
CVE-2026-1008148.8—MozillaFirefoxCWE-119Incorrect boundary conditions in the JavaScript Engine: JIT component
CVE-2026-1008158.8—MozillaFirefoxCWE-416Use-after-free in the CSS Parsing and Computation component
CVE-2026-1008208.8—MozillaFirefoxCWE-269Privilege escalation in the Address Bar component
CVE-2026-1008248.8—MozillaFirefoxCWE-269Privilege escalation in the Places component
CVE-2026-1008258.8—MozillaFirefoxCWE-416Use-after-free in the JavaScript Engine: JIT component
CVE-2026-1008318.8—MozillaFirefoxCWE-416Use-after-free in the DOM: UI Events & Focus Handling component
CVE-2026-1008328.8—MozillaFirefoxCWE-416Use-after-free in the Graphics: Canvas2D component
CVE-2026-1022998.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote…
CVE-2026-1023028.8—GoogleChromeCWE-121Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remot…
CVE-2026-1023218.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote…
CVE-2026-1023238.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote…
CVE-2026-1023268.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote…
CVE-2026-1023288.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote…
CVE-2026-1027128.8—Eclipse FoundationNetX DuoCWE-125On the first DTLS ClientHello, the parser copies a device-claimed session_id …
CVE-2026-1027138.8—Eclipse FoundationNetX DuoCWE-125The TFTP server accepts a DATA datagram of any size. The dispatcher rejects d…
CVE-2015-201228.7—YonyouA6 OACWE-89Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp
CVE-2022-510198.7—akauntingakauntingCWE-78Akaunting before 2.1.31 OS Command Injection via app alias
CVE-2026-40348.7—TibcoAdministratorCWE-74TIBCO Administrator Injection Vulnerability
CVE-2026-615198.7—Liberu SoftwareLiberu CRMCWE-863Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember()
CVE-2026-689118.7—nicotine-plusnicotine-plusCWE-409Nicotine+: Decompression of peer messages can exhaust available memory
CVE-2026-814338.7—WatchGuardFireware OSCWE-120Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote…
CVE-2026-861048.7—WatchGuardFireware OSCWE-400Fireware OS Resource Exhaustion in Login Process Allows Denial of Service
CVE-2026-942048.7—ViidureDashcam Android ApplicationCWE-732Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Andr…
CVE-2026-1002928.7—AnjvisionYSSD-RTMP-H5CWE-78Improper neutralization of special elements used in an OS command ('OS comman…
CVE-2026-1002938.7—AnjvisionYSSD-RTMP-H5CWE-347Improper verification of cryptographic signature in Anjvision YSSD-RTMP-H5
CVE-2026-1002948.7—AnjvisionYSSD-RTMP-H5CWE-798Use of Hard-coded Credentials in Anjvision YSSD-RTMP-H5
CVE-2026-1002988.7—AnjvisionYSSD-RTMP-H5CWE-522Insufficiently Protected Credentials in Anjvision YSSD-RTMP-H5
CVE-2026-1022538.7—esnetiperf3CWE-835iperf3 < 3.22 UDP Receive Worker Infinite Loop DoS
CVE-2026-1026348.7—sgl-projectsglangCWE-694SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room
CVE-2026-1027168.7—Eclipse Foundationeclipse-threadx/netxduoCWE-401An unauthenticated client can drain the RTSP server's packet pool with a coup…
CVE-2026-1027188.7—Eclipse FoundationNetX DuoCWE-125hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not val…
CVE-2026-1028108.7—rochacbrunomarmiteCWE-22Marmite through 0.4.2 Path Traversal via Development Server
CVE-2026-1028118.7—rochacbrunomarmiteCWE-306Marmite through 0.4.2 Unauthenticated API Access via Development Server
CVE-2026-1030428.7—ModelTCLightLLMCWE-770LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Cha…
CVE-2026-1030438.7—alexcorvianchormeCWE-1333anchorme through 3.0.8 Regular Expression Denial of Service
CVE-2026-71938.6—Shenzhen Dbit Network EquipmentT-CPE301K 4G Mini WiFi RouterCWE-798Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen D…
CVE-2026-181458.6—WatchGuardFireware OSCWE-121Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution
CVE-2026-1011278.6—balbooa.comBalbooa Forms extension for JoomlaCWE-79Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS i…
CVE-2026-1022428.6—GoogleMCP Toolbox for DatabasesCWE-22Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for …
CVE-2026-1023178.6—GoogleChromeCWE-269Improper privilege management in Mojo in Google Chrome on on Windows prior to…
CVE-2026-1023608.6—dmonadlib0CWE-125lib0 `readUint8Array` performs an unbounded read past the end of the decoder’…
CVE-2026-1025218.6—dmonadlib0CWE-125lib0 `readFromDataView` out-of-bounds read
CVE-2026-1025568.6—Red HatRed Hat Enterprise Linux 10CWE-843Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion
CVE-2026-1025578.6—Red HatRed Hat Enterprise Linux 10CWE-125Libsoup: libsoup: heap buffer overflow during websocket message reassembly
CVE-2026-1025588.6—Red HatRed Hat Enterprise Linux 10CWE-125Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
CVE-2026-1025598.6—Red HatRed Hat Enterprise Linux 10CWE-125Libsoup: libsoup: heap buffer overflow during websocket client-frame masking
CVE-2026-1025608.6—Red HatRed Hat Enterprise Linux 10CWE-125Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buf…
CVE-2026-1027308.6—Eclipse Foundationeclipse-threadx/levelx(NAND driver)CWE-787Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) tri…
CVE-2026-1028768.6—surrealdbsurrealdbCWE-639SurrealDB before 3.3.0 Cross-Tenant Access via Headers
CVE-2026-1028788.6—hangwinmcp-chrome-bridgeCWE-346mcp-chrome-bridge through 1.0.31 CORS Origin Bypass
CVE-2026-637138.5—Toptech SystemsTMS7CWE-89Toptech TMS7 and TopHAT SQL Injection
CVE-2026-680688.5—Toptech SystemsTMS7CWE-89Toptech TMS7 and TopHAT SQL Injection
CVE-2026-689548.5—Toptech SystemsTMS7CWE-89Toptech TMS7 and TopHAT SQL Injection
CVE-2026-725078.5—Toptech SystemsTMS7CWE-89Toptech TMS7 and TopHAT SQL Injection
CVE-2026-725108.5—Toptech SystemsTMS7CWE-89Toptech TMS7 and TopHAT SQL Injection
CVE-2026-860358.5—WeblateOrgweblateCWE-78Weblate: Mercurial argument injection via repository filenames allows authent…
CVE-2026-1025668.5—OpenNMTCTranslate2CWE-787CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin
CVE-2026-1026978.5—ollamaollamaCWE-863Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefi…
CVE-2026-1027578.5—Eclipse FoundationThreadXCWE-125An unprivileged, memory-protected ThreadX module can have the kernel read and…
CVE-2026-1027928.5—ZiroomZHOME A0101CWE-74Ziroom ZHOME A0101 set_syslog command injection
CVE-2026-1028758.5—videolanvlcCWE-22VLC media player before 3.0.24 Path Traversal via skins2
CVE-2026-1003088.4—AWSgluontsCWE-470GluonTS arbitrary command execution during model deserialization
CVE-2026-1027098.4—Eclipse FoundationThreadXCWE-200Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-s…
CVE-2026-952748.3—GoogleChromeCWE-116Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 …
CVE-2026-952768.3—GoogleChromeCWE-20Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 a…
CVE-2026-953198.3—GoogleChromeCWE-416Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953228.3—GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037…
CVE-2026-953348.3—GoogleChromeCWE-706Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.…
CVE-2026-953358.3—GoogleChromeCWE-416Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remot…
CVE-2026-953418.3—GoogleChromeCWE-20Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 …
CVE-2026-953488.3—GoogleChromeCWE-416Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a…
CVE-2026-953518.3—GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a rem…
CVE-2026-953548.3—GoogleChromeCWE-416Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a …
CVE-2026-953558.3—GoogleChromeCWE-863Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154…
CVE-2026-953728.3—GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed …
CVE-2026-953818.3—GoogleChromeCWE-20Improper input validation in Printing in Google Chrome prior to 154.0.8037.57…
CVE-2026-962748.3—BaicellsNova 430H eNodeB (model pBS3101SH)CWE-248Uncaught exception in Baicells Nova 430H
CVE-2026-1023018.3—GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a …
CVE-2026-1023248.3—GoogleChromeCWE-416Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 al…
CVE-2026-1026768.3—electronelectronCWE-269Electron: <webview> can enable Node.js integration in Web Workers despite emb…
CVE-2026-1027608.3—Eclipse FoundationNetX DuoCWE-416When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent o…
CVE-2026-132248.2—WatchGuardFireware OSCWE-22Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local F…
CVE-2026-767198.2—Hewlett Packard EnterpriseHPE OneViewCWE-79HPE OneView - Cross-site scripting vulnerability
CVE-2026-847828.2—OpenSSLOpenSSLCWE-125DTLS Retransmits Handshake Messages From a Stale Buffer Offset
CVE-2026-861288.2—WatchGuardFireware OSCWE-476Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allow…
CVE-2026-861328.2—WatchGuardFireware OSCWE-191Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Ser…
CVE-2026-861338.2—WatchGuardFireware OSCWE-1284Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial…
CVE-2026-922278.2—Joomla! ProjectJoomla! CMSCWE-287Joomla! Core - [20260914] - Core - MFA Authentication Bypass through remember…
CVE-2026-1025558.2—Red HatRed Hat Enterprise Linux 10CWE-125Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri b…
CVE-2026-1026338.2—libexpatlibexpatCWE-190libexpat 2.7.2 through 2.8.5 Integer Overflow in expat_realloc
CVE-2026-1026738.2—electronelectronCWE-346Electron drops inherited HTML sandbox restrictions for popups opened through …
CVE-2026-1026748.2—electronelectronCWE-266Electron: Windows opened from a sandboxed top-level document do not inherit i…
CVE-2026-1027628.2—Eclipse FoundationNetX DuoCWE-401The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH messag…
CVE-2026-767268.1—Hewlett Packard Enterprise (HPE)Instant ON—Authentication Bypass Leading to Unauthorized Network Access in HPE Networkin…
CVE-2026-848428.1—IBMGuardium Data ProtectionCWE-22IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-953338.1—GoogleChromeCWE-416Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a r…
CVE-2026-1028268.1—steveukxgit-jsCWE-77simple-git allows command execution through unblocked Git configuration includes
CVE-2026-1028278.1—steveukxgit-jsCWE-77simple-git: unsafe-operations plugin bypass via git long-option abbreviation …
CVE-2026-1028318.1—jupyterlabjupyterlabCWE-79JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells paste…
CVE-2026-197437.8—TeamViewerFull ClientCWE-22Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) …
CVE-2026-651027.8—NVIDIADeepStreamCWE-190NVIDIA DeepStream contains a vulnerability where an attacker could cause an i…
CVE-2026-735987.8—DellSecure Connect Gateway (SCG) Policy ManagerCWE-732Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-844147.8—IBMiCWE-732IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Netw…
CVE-2026-923687.8—TeamViewerFull ClientCWE-122Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to …
CVE-2026-952987.8—GoogleChromeCWE-416Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a l…
CVE-2026-953157.8—GoogleChromeCWE-416Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a loca…
CVE-2026-1024377.8—esengineDeepSeek-ReasonixCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Comman…
CVE-2026-1026777.8—electronelectronCWE-20Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
CVE-2026-1029257.8—pypavirtualenvCWE-78virtualenv bash and fish activation scripts execute commands embedded in paths
CVE-2026-844097.7—LantronixG520 SeriesCWE-79Lantronix G520 Series Cellular Gateway Cross-site Scripting
CVE-2026-911917.7—LantronixG520 SeriesCWE-347Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic…
CVE-2026-1029307.7—pypavirtualenvCWE-494virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked…
CVE-2026-976877.6—urllib3urllib3CWE-295urllib3: HTTPS proxy TLS configuration may be ignored or overridden
CVE-2026-130467.5—WatchGuardFireware OSCWE-502Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Exe…
CVE-2026-632097.5—klauspostcompressCWE-190Integer Overflow or Wraparound and Out-of-bounds Write in compress
CVE-2026-713027.5—Toptech SystemsTMS7CWE-384Toptech TMS7 and TopHAT Session Fixation
CVE-2026-728977.5—OpenSSLOpenSSLCWE-787Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
CVE-2026-844407.5—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-847837.5—OpenSSLOpenSSLCWE-416Use-After-Free in X.509 Extension Cache Under Concurrent Use
CVE-2026-847847.5—OpenSSLOpenSSLCWE-770QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
CVE-2026-864507.5—Parla Auto Automotive Trading Limited CompanyDetaWix Mobile Web PortalCWE-201Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal
CVE-2026-952807.5—GoogleChromeCWE-362Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote…
CVE-2026-1008057.5—MozillaFirefoxCWE-362Race condition, use-after-free in the Audio/Video component
CVE-2026-1023277.5—GoogleChromeCWE-863Incorrect authorization in WebView in Google Chrome on on Android prior to 15…
CVE-2026-1024957.5—Apache Software FoundationApache XMLSchemaCWE-674Apache XMLSchema: Denial of service through unbounded recursion when resolvin…
CVE-2026-1024967.5—Apache Software FoundationApache XMLSchemaCWE-674Apache XMLSchema: Denial of service through deeply nested schema structures
CVE-2026-1024977.5—Apache Software FoundationApache XMLSchemaCWE-674Apache XMLSchema: Denial of service through cyclic schema definitions in the …
CVE-2026-1026007.5—socketiosocket.ioCWE-20Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
CVE-2026-1028237.5—EugenyrusshCWE-20russh: Client-side channel-scoped Handler callbacks fire for channel IDs the …
CVE-2026-1026757.4—electronelectronCWE-346Electron: File and HTTP protocol handlers allow cross-origin reads without co…
CVE-2026-923697.3—TeamViewerFull ClientCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Insta…
CVE-2026-1029377.3—pypavirtualenvCWE-78virtualenv: Command injection via --prompt in activate.bat (batch activator)
CVE-2026-767277.2—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON
CVE-2026-767287.2—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Server-Side Request Forgery Leading to Remote Code Execution in…
CVE-2026-844227.2—IBMGuardium Data ProtectionCWE-78IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-861017.2—WatchGuardFireware OSCWE-285Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access
CVE-2026-938537.2—EnterpriseDBBarmanCWE-283Barman snapshot backup deletion trusts unverified backup catalog metadata
CVE-2026-1002967.2—AnjvisionYSSD-RTMP-H5CWE-754Improper Check for Unusual or Exceptional Conditions in Anjvision YSSD-RTMP-H5
CVE-2026-181057.1—WatchGuardFireware OSCWE-400Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Deni…
CVE-2026-742257.1—u-bootu-bootCWE-787U-Boot before 2026.10-rc5 Out-of-Bounds Write via DHCPv6
CVE-2026-861367.1—WatchGuardFireware OSCWE-22Fireware OS Missing Authorization in wgagent Management API Allows Denial of …
CVE-2026-904417.1—WatchGuardFireware OSCWE-200Fireware OS Missing Authorization in wgagent Management API Allows Denial of …
CVE-2026-922317.1—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5…
CVE-2026-922327.1—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via white…
CVE-2026-955207.1—Red HatRed Hat Enterprise Linux 10CWE-787Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffe…
CVE-2026-1026397.1—MobilityDBMobilityDBCWE-195MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization
CVE-2026-1027147.1—Eclipse FoundationNetX DuoCWE-125`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2…
CVE-2026-1027157.1—Eclipse Foundationeclipse-threadx/netxduoCWE-787mDNS string-cache lookup matches on slot size, so a peer name aliases a short…
CVE-2026-1028087.1—PX4PX4-AutopilotCWE-476PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress
CVE-2026-1028097.1—PX4PX4-AutopilotCWE-789PX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 Command
CVE-2026-195477.0—Artifex Software Inc.GhostscriptCWE-426Local Privilege Escalation in Ghostscript for Windows
CVE-2026-909137.0—Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260903] - Core - Improper ACL checks for access level webse…
CVE-2026-909157.0—Joomla! ProjectJoomla! CMSCWE-22Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache pur…
CVE-2026-922267.0—Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice …
CVE-2026-923717.0—TeamViewerFull ClientCWE-59Local Privilege Escalation via Improper Link Resolution in Cloud Session Reco…
CVE-2026-1002997.0—AnjvisionYSSD-RTMP-H5CWE-1391Use of Weak Credentials in Anjvision YSSD-RTMP-H5
CVE-2026-1025697.0—MacWarriorclipbucket-v5CWE-89ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter
CVE-2026-1025707.0—MacWarriorclipbucket-v5CWE-89ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter
CVE-2026-418756.9—OpenSolutionQuick.CartCWE-352Cross-Site Request Forgery in admin panel of Quick.Cart
CVE-2026-909076.9—Joomla! ProjectJoomla! CMSCWE-639Joomla! Core - [20260902] - Core - Unauthorized user account creation via pro…
CVE-2026-909176.9—Joomla! ProjectJoomla! CMSCWE-284Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged …
CVE-2026-909186.9—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0…
CVE-2026-976886.9—urllib3urllib3CWE-835urllib3: Chunked Deflate streaming can enter an infinite loop
CVE-2026-1002976.9—AnjvisionYSSD-RTMP-H5CWE-918Server-Side request forgery (SSRF) in Anjvision YSSD-RTMP-H5
CVE-2026-1011126.9—balbooa.comBalbooa Forms extension for JoomlaCWE-639Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balb…
CVE-2026-1011266.9—balbooa.comBalbooa Forms extension for JoomlaCWE-22Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < …
CVE-2026-1022526.9—GoogleOSV-SCALIBRCWE-22Path Traversal in VMDK Extractor in OSV-SCALIBR
CVE-2026-1025676.9—OpenNMTCTranslate2CWE-125CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization
CVE-2026-1027216.9—Eclipse FoundationNetX DuoCWE-125A TFTP server that answers with a short ERROR packet makes the client read up…
CVE-2026-1027226.9—Eclipse FoundationNetX DuoCWE-918In the IPv4 PASV path, the FTP Client accepts whatever address was sent in th…
CVE-2025-332076.8—NVIDIABlueField GACWE-1262NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, …
CVE-2026-1025076.8—BishopFoxsliverCWE-125Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC
CVE-2026-1025686.8—parduspardus-parental-controlCWE-863Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py
CVE-2026-1028306.8—jupyterlabjupyterlabCWE-79JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language pac…
CVE-2026-767296.6—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Format String Vulnerability allows Memory Corruption in HPE Net…
CVE-2026-660836.5—Apache Software FoundationApache DolphinSchedulerCWE-306Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information v…
CVE-2026-735976.5—DellSecure Connect Gateway (SCG) Policy ManagerCWE-352Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-767306.5—Hewlett Packard Enterprise (HPE)Instant ON—Improper PAPI Packet handling leads to unauthorized access in HPE Networking …
CVE-2026-767316.5—Hewlett Packard Enterprise (HPE)Instant ON—Authentication Bypass in the Captive Portal of HPE Networking Instant On
CVE-2026-818626.5—Apache Software FoundationApache Airflow Teradata providerCWE-532Apache Airflow Teradata provider: Teradata transfer operators embed cloud sto…
CVE-2026-953276.5—GoogleChromeCWE-200Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowe…
CVE-2026-953286.5—GoogleChromeCWE-441Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.…
CVE-2026-953366.5—GoogleChromeCWE-200Information leak in Transactions Platform in Google Chrome prior to 154.0.803…
CVE-2026-953826.5—GoogleChromeCWE-20Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 all…
CVE-2026-1002866.5—DevolutionsServerCWE-200Missing authorization in the data source settings API in Devolutions Server 2…
CVE-2026-1007956.5—MozillaFirefoxCWE-770Denial-of-service in the Networking component
CVE-2026-1008126.5—MozillaFirefoxCWE-770Denial-of-service in the Graphics component
CVE-2026-1008266.5—MozillaFirefoxCWE-770Denial-of-service in the Storage: StorageManager component
CVE-2026-1026236.5—Red HatRed Hat OpenShift Virtualization 4CWE-476Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed eph…
CVE-2026-1028216.5—EugenyrusshCWE-400Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-sta…
CVE-2026-735946.4—DellSecure Connect Gateway (SCG) Policy ManagerCWE-295Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-767326.4—Hewlett Packard Enterprise (HPE)Instant ON—Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Net…
CVE-2026-768756.3—PyPyPyPyCWE-416PyPy pyexpat ExternalEntityParserCreate Use-After-Free
CVE-2026-819306.3—Apache Software FoundationApache Airflow Snowflake providerCWE-522Apache Airflow Snowflake provider: Unvalidated account field redirects SQL AP…
CVE-2026-868436.3—Apache Software FoundationApache Airflow Teradata providerCWE-89Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in…
CVE-2026-1025986.3—palletswerkzeugCWE-67Werkzeug safe_join() allows Windows special device names
CVE-2026-1026356.3—ImageMagickImageMagickCWE-908ImageMagick before 7.1.2-32 and 6.9.13-57 Uninitialized Heap Memory Disclosur…
CVE-2026-1027196.3—Eclipse FoundationnetxduoCWE-330Predictable DTLS HelloVerifyRequest Cookie in NetX Secure
CVE-2026-1027596.3—Eclipse FoundationNetX DuoCWE-354NetX Secure TLS accepts an empty application-data record without verifying it…
CVE-2026-1028206.2—EugenyrusshCWE-125pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::re…
CVE-2026-719726.0—u-bootu-bootCWE-787U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder
CVE-2026-1027236.0—Eclipse FoundationNetX DuoCWE-476NULL Pointer Dereference on MSRP Attribute Table Exhaustion
CVE-2026-1027246.0—Eclipse FoundationNetX DuoCWE-476NULL Pointer Dereference When Evicting the Sole MSRP Attribute
CVE-2026-1027256.0—Eclipse FoundationNetX DuoCWE-125Out-of-bounds Read from Unvalidated MSRP Attribute List Length
CVE-2026-1027266.0—Eclipse FoundationNetX DuoCWE-125Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read
CVE-2026-1027276.0—Eclipse FoundationNetX DuoCWE-923FTP Passive Data Connection Not Bound to the Authenticated Control Peer
CVE-2026-1028066.0—OpenClawOpenClawCWE-863OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines
CVE-2026-1028076.0—OpenClawOpenClawCWE-863OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket
CVE-2026-123455.9—Python Software FoundationCPythonCWE-59Race condition in tempfile.TemporaryDirectory cleanup allows deleting files o…
CVE-2026-761145.9—DellSecure Connect Gateway (SCG) Policy ManagerCWE-319Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1…
CVE-2026-909065.9—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.…
CVE-2026-909145.9—Joomla! ProjectJoomla! CMSCWE-79Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in…

Results continue: ranks 401–611.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.