AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0205 80.5 —
AFFECTED Product Versions Fixed raspap-webgui 3.5.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 611 CVEs published, led by Google (142).
611 CVEs published September 29, 2026: 70 critical, 224 high, 169 medium, 46 low; 0 in the KEV catalog at press time; 5 with a public exploit reference; 102 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 211 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 14306 | 49292 | — | — |
| KEV catalog size | 1729 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3164 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 2115 | 6205 | 530 | 2638 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | +472 ▲ |
| microsoft | 1002 | 2901 | 202 | 1991 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | +525 ▲ |
| 662 | 2831 | 355 | 1091 | 1222 | 131 | 80 | 9 | 0.3 | 7.5 | .0027 | +260 ▲ | |
| red hat | 261 | 894 | 51 | 376 | 414 | 53 | 2 | 0 | 0.0 | 6.7 | .0036 | +39 ▲ |
| apple | 247 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | +203 ▲ |
| suse | 25 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | +18 ▲ |
| canonical | 8 | 50 | 16 | 12 | 17 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | -7 ▼ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -32 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 97 | 181 | 53 | 72 | 55 | 1 | 59 | 16 | 8.8 | 7.7 | .0046 | +51 ▲ |
| ubiquiti | 6 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | -17 ▼ |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 11 | 41 | 11 | 10 | 17 | 3 | 29 | 7 | 17.1 | 7.2 | .0040 | +4 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | -7 ▼ |
| f5 | 9 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | +9 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -7 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 176 | 688 | 151 | 288 | 225 | 16 | 33 | 2 | 0.3 | 7.5 | .0063 | +18 ▲ |
| mozilla | 190 | 378 | 111 | 159 | 82 | 0 | 9 | 0 | 0.0 | 8.8 | .0032 | +131 ▲ |
| gitlab | 28 | 104 | 7 | 24 | 62 | 11 | 5 | 3 | 2.9 | 5.3 | .0034 | +3 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | +9 ▲ |
| github | 6 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | +1 ▲ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | +1 ▲ |
| wordpress | 1 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0340 | -1 ▼ |
| kubernetes | 1 | 2 | 0 | 0 | 1 | 1 | 0 | 0 | 0.0 | 4.5 | .0028 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | -256 ▼ |
| ibm | 404 | 1023 | 196 | 473 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | +14 ▲ |
| adobe | 224 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | +123 ▲ |
| progress | 5 | 66 | 15 | 40 | 11 | 0 | 6 | 1 | 1.5 | 8.1 | .0046 | -14 ▼ |
| zohocorp | 32 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | +28 ▲ |
| solarwinds | 3 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | +3 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | -13 ▼ |
| servicenow | 5 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 29 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | +13 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -6 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | +15 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | +9 ▲ |
| hitachi energy | 9 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0030 | +9 ▲ |
| abb | 4 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 207 | 378 | 31 | 172 | 151 | 24 | 2 | 1 | 0.3 | 7.2 | .0027 | +136 ▲ |
| sourcecodester | 63 | 232 | 0 | 0 | 138 | 94 | 0 | 0 | 0.0 | 5.5 | .0043 | +15 ▲ |
| openclaw | 84 | 217 | 4 | 109 | 83 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | +84 ▲ |
| nvidia | 53 | 187 | 25 | 129 | 33 | 0 | 0 | 0 | 0.0 | 7.8 | .0040 | +1 ▲ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | -91 ▼ |
| mongodb | 71 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | +16 ▲ |
| hewlett packard enterprise (hpe) | 157 | 166 | 22 | 80 | 55 | 9 | 1 | 1 | 0.6 | 7.2 | .0045 | +154 ▲ |
| itsourcecode | 37 | 153 | 0 | 0 | 37 | 116 | 0 | 0 | 0.0 | 2.1 | .0033 | +5 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9143 | 99.8 | 10.0 |
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-87902 | .1976 | 97.3 | 8.1 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.4 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-83549 | .1076 | 95.7 | 7.8 |
| CVE-2026-83548 | .0876 | 95.0 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9143 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-83548 | 10.0 | .0876 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2115 |
| microsoft | 1002 |
| 662 | |
| oracle | 634 |
| ibm | 404 |
| red hat | 267 |
| apple | 247 |
| adobe | 224 |
| dell | 208 |
| mozilla | 191 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 16 |
| apple | 9 |
| 9 | |
| fortinet | 7 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 103 |
| Packagist | 18 |
| npm | 18 |
| PyPI | 14 |
| crates.io | 9 |
| Go | 2 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1777 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1777 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1777 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1777 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1777 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1777 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1777 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1777 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1777 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1777 |
ADDED TO KEV — CVE-2026-86950 (Apple iOS and iPadOS). Remediation due October 2, 2026.
EXPLOIT PUBLISHED — sooperset mcp-atlassian: 15 CVEs (CVE-2026-77242, CVE-2026-77243, CVE-2026-77244, CVE-2026-77249, CVE-2026-77250, CVE-2026-77251, CVE-2026-77255, CVE-2026-77258, CVE-2026-77259, CVE-2026-77260, CVE-2026-77262, CVE-2026-77265, CVE-2026-77267, CVE-2026-77268, CVE-2026-77269). Public exploit references added.
EXPLOIT PUBLISHED — AcademySoftwareFoundation OpenImageIO: 12 CVEs (CVE-2026-50291, CVE-2026-59156, CVE-2026-59181, CVE-2026-59956, CVE-2026-63419, CVE-2026-63420, CVE-2026-63422, CVE-2026-63635, CVE-2026-63638, CVE-2026-65969, CVE-2026-65970, CVE-2026-67549). Public exploit references added.
EXPLOIT PUBLISHED — cesanta mongoose: 7 CVEs (CVE-2026-73253, CVE-2026-73254, CVE-2026-73255, CVE-2026-73256, CVE-2026-73257, CVE-2026-73258, CVE-2026-73259). Public exploit references added.
EXPLOIT PUBLISHED — angular: 5 CVEs (CVE-2026-88056, CVE-2026-88057, CVE-2026-88058, CVE-2026-88059, CVE-2026-88060). Public exploit references added.
EXPLOIT PUBLISHED — grokability snipe-it: 5 CVEs (CVE-2026-62368, CVE-2026-63493, CVE-2026-63498, CVE-2026-84206, CVE-2026-88894). Public exploit references added.
EXPLOIT PUBLISHED — GestSup: 4 CVEs (CVE-2026-100389, CVE-2026-102372, CVE-2026-102373, CVE-2026-102374). Public exploit references added.
EXPLOIT PUBLISHED — FreeRDP: 3 CVEs (CVE-2026-55193, CVE-2026-67293, CVE-2026-68580). Public exploit references added.
EXPLOIT PUBLISHED — Ziroom ZHOME A0101: 3 CVEs (CVE-2026-101187, CVE-2026-101260, CVE-2026-101262). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-100303 (TDuckCloud tduck-survey-form). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100310 (GNU libextractor). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100312 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100315 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-101139 (Webkul Bagisto). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-101141 (Eleveo Call Recording Software). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-101143 (Eleveo Quality Management). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-101144 (Eleveo Call Recording Software). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-101146 (Eleveo Quality Management). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3832 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-57228 (OISF suricata). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-75926 (gohugoio hugo). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79718 (Netron). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-79719 (Netron). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93355 (BerriAI litellm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-95844 (moquette-io moquette). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97896 (krayin laravel-crm). Public exploit reference added.
DUE DATE PASSED — CVE-2026-65660 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was September 28, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-67279 (Mikrotik RouterOS). CISA remediation deadline was September 28, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-87902 (WordPress). CISA remediation deadline was September 28, 2026; still in catalog.
RESCORED — NVIDIA Infrastructure Controller: 10 CVEs (CVE-2026-65114, CVE-2026-65117, CVE-2026-65118, CVE-2026-65121, CVE-2026-65124, CVE-2026-65125, CVE-2026-65126, CVE-2026-65127, CVE-2026-65129, CVE-2026-65130). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2017-20051 (InnoSetup Installer). CVSS 5.3 → 2.1 (NVD).
RESCORED — CVE-2023-6394 (Red Hat build of Quarkus 3.2.9.Final). CVSS 7.4 → 9.1 (NVD).
RESCORED — CVE-2024-58376 (renovatebot renovate). CVSS 9.3 → 8.4 (NVD).
RESCORED — CVE-2025-31356 (Intel(R) Trust Domain Extensions (Intel(R) TDX)). CVSS 5.6 → 5.7 (NVD).
RESCORED — CVE-2026-101263 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).
RESCORED — CVE-2026-101264 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).
RESCORED — CVE-2026-101265 (Intelbras TIP 125i). CVSS 2.3 → 1.3 (NVD).
RESCORED — CVE-2026-101277 (Trusted Domain Project OpenDKIM). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-17504 (IBM PowerVM Hypervisor). CVSS 5.1 → 4.4 (NVD).
RESCORED — CVE-2026-51772. CVSS 8.1 → 6.5 (NVD).
RESCORED — CVE-2026-57228 (OISF suricata). CVSS 8.2 → 9.1 (NVD).
RESCORED — CVE-2026-62368 (grokability snipe-it). CVSS 8.1 → 8.4 (NVD).
RESCORED — CVE-2026-63498 (grokability snipe-it). CVSS 8.7 → 5.4 (NVD).
RESCORED — CVE-2026-69559 (Microsoft Teams for Android). CVSS 5.8 → 6.3 (NVD).
RESCORED — CVE-2026-69805 (Microsoft Visual Studio 2022 version 17.14). CVSS 7.5 → 8.1 (NVD).
RESCORED — CVE-2026-69854 (Microsoft Spring Cloud Azure). CVSS 9 → 8.1 (NVD).
RESCORED — CVE-2026-77265 (sooperset mcp-atlassian). CVSS 5.9 → 7.5 (NVD).
RESCORED — CVE-2026-77909 (Microsoft Azure CycleCloud 8.9.2). CVSS 7.7 → 6.5 (NVD).
RESCORED — CVE-2026-78545 (Okta Access Gateway). CVSS 6.6 → 7.2 (NVD).
RESCORED — CVE-2026-78550 (Okta Access Gateway). CVSS 6.6 → 7.2 (NVD).
RESCORED — CVE-2026-88059 (angular). CVSS 4 → 5.8 (NVD).
RESCORED — CVE-2026-88420. CVSS 6.1 → 5.4 (NVD).
PATCH SHIPPED — CVE-2026-102010 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 13.5.0-0.2.hum1.
PATCH SHIPPED — CVE-2026-57759 (Metagauss ProfileGrid). Fixed in ProfileGrid 6.0.0.3.
How to read these box scores · glossary
611 CVEs published. 25 box scores and 375 table rows below; the remaining 211 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0205 80.5 —
AFFECTED Product Versions Fixed raspap-webgui 3.5.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0201 80.1 —
AFFECTED Product Versions Fixed NAP930 0.1.241010.141410 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N L L 2.1 .0158 74.5 —
AFFECTED Product Versions Fixed raspap-webgui 3.5.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0116 65.8 —
AFFECTED Product Versions Fixed SurfSense 2.0.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0116 65.8 —
AFFECTED Product Versions Fixed RTU500 series CMU firmware 9.0 – —
TIMELINE May 7 Reserved by CNA Sep 29 Published (CNA: Hitachi Energy)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0058 45.4 —
AFFECTED Product Versions Fixed RTU500 series CMU firmware 9.0 – —
TIMELINE May 7 Reserved by CNA Sep 29 Published (CNA: Hitachi Energy)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 7.4 .0047 38.5 —
AFFECTED Product Versions Fixed raspap-webgui 3.5.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0045 36.9 —
AFFECTED Product Versions Fixed Wireshark 4.6.0 – —
TIMELINE Sep 22 Reserved by CNA Sep 29 Published (CNA: GitLab)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A H H N 8.5 .0042 33.7 —
AFFECTED Product Versions Fixed Asset Suite 9.6.0 – —
TIMELINE Apr 29 Reserved by CNA Sep 29 Published (CNA: Hitachi Energy)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A N N L 5.1 .0042 33.7 —
AFFECTED Product Versions Fixed Asset Suite 9.6.0 – —
TIMELINE Jun 9 Reserved by CNA Sep 29 Published (CNA: Hitachi Energy)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0041 32.7 —
AFFECTED Product Versions Fixed OpenDMARC 1.4.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0040 31.9 —
AFFECTED Product Versions Fixed OpenDMARC 1.4.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H P H H H 7.1 .0039 30.9 —
AFFECTED Product Versions Fixed FastAdmin 1.6.1.20250430 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0039 30.7 —
AFFECTED Product Versions Fixed Wireshark 4.6.0 – —
TIMELINE Sep 22 Reserved by CNA Sep 29 Published (CNA: GitLab)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0039 30.0 —
AFFECTED Product Versions Fixed SurfSense 2.0.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N N N H H H 8.6 .0038 29.8 —
AFFECTED Product Versions Fixed FAC1203R 20200116_2.0.4 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.2 .0038 29.7 —
AFFECTED Product Versions Fixed shell-quote 1.8.4 – —
TIMELINE Sep 29 Reserved by CNA Sep 29 Published (CNA: harborist)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0038 29.8 —
AFFECTED Product Versions Fixed Rebuild 4.4.0 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C H H N 8.7 .0036 27.6 —
AFFECTED Product Versions Fixed GitLab 13.11 – —
TIMELINE Sep 2 Reserved by CNA Sep 29 Published (CNA: GitLab)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0036 26.7 —
AFFECTED Product Versions Fixed GEOVIA Geospatial Data Manager Release 3DEXPERIENCE R2024x Golden – —
TIMELINE Sep 1 Reserved by CNA Sep 29 Published (CNA: 3DS)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U L N N 3.7 .0034 25.5 —
AFFECTED Product Versions Fixed GitLab 15.11 – —
TIMELINE Mar 20 Reserved by CNA Sep 29 Published (CNA: GitLab)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0034 25.2 —
AFFECTED Product Versions Fixed Agentflow 4.0 unspecified —
TIMELINE Sep 23 Reserved by CNA Sep 29 Published (CNA: ZUSO ART)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.7 .0033 24.3 —
AFFECTED Product Versions Fixed Octopus Server 2019.4.1 – —
TIMELINE Sep 28 Reserved by CNA Sep 29 Published (CNA: Octopus)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U L N N 4.3 .0033 23.7 —
AFFECTED Product Versions Fixed GitLab 17.9 – —
TIMELINE Jun 1 Reserved by CNA Sep 29 Published (CNA: GitLab)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0032 23.0 —
AFFECTED Product Versions Fixed RTU500 series CMU firmware 9.0 – —
TIMELINE May 7 Reserved by CNA Sep 29 Published (CNA: Hitachi Energy)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-101279 | 5.5 | 23.0 | Trusted Domain Project | OpenDMARC | CWE-189 | Trusted Domain Project OpenDMARC opendmarc_policy.c integer overflow |
| CVE-2026-92142 | await | 21.8 | Apache Software Foundation | Apache Karaf | CWE-862 | Apache Karaf: Authorization bypass in JMX MBean lifecycle operations |
| CVE-2026-97024 | 7.1 | 21.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-61 | Flatpak: flatpak: arbitrary write in root context via path traversal in deplo… |
| CVE-2026-96440 | 7.1 | 19.6 | Flowring Technology Corp | Agentflow 4.0 | CWE-22 | Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Di… |
| CVE-2026-102414 | 6.3 | 18.8 | browserify | pbkdf2 | CWE-400 | pbkdf2 rehashes long passwords on every iteration, enabling denial of service |
| CVE-2026-102249 | 5.5 | 18.8 | n/a | REBUILD | CWE-862 | REBUILD file-editor-save authorization |
| CVE-2026-102292 | 2.1 | 18.6 | coolbeans1212 | MateisHomePage-Website | CWE-79 | coolbeans1212 MateisHomePage-Website users.php cross site scripting |
| CVE-2026-102293 | 5.5 | 18.2 | realjerrytang | tacomall | CWE-266 | realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServic… |
| CVE-2026-96429 | 9.3 | 18.1 | Flowring Technology Corp | Agentflow 4.0 | CWE-89 | Flowring Agentflow 4.0 - SQL Injection |
| CVE-2026-96431 | 9.3 | 17.9 | Flowring Technology Corp | Agentflow 4.0 | CWE-434 | Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type |
| CVE-2026-8937 | 4.3 | 16.3 | GitLab | GitLab | CWE-862 | Missing Authorization in GitLab |
| CVE-2026-101878 | 7.7 | 15.8 | bitwarden | bitwarden server | CWE-303 | Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier… |
| CVE-2026-102290 | 2.0 | 14.5 | CodeCanyon | Rocket LMS | CWE-79 | CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting |
| CVE-2026-97029 | 5.7 | 14.1 | Red Hat | Red Hat Enterprise Linux 10 | CWE-653 | Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same … |
| CVE-2026-102261 | 2.1 | 14.0 | owen2345 | Camaleon CMS | CWE-285 | owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization |
| CVE-2026-76718 | 8.2 | 13.9 | Hewlett Packard Enterprise | HPE OneView | CWE-79 | HPE OneView - Cross-site scripting vulnerability |
| CVE-2026-97685 | 7.1 | 13.3 | LimeSurvey | LimeSurvey | CWE-639 | LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass… |
| CVE-2026-102373 | 7.1 | 13.4 | GestSup | GestSup | CWE-639 | GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter |
| CVE-2026-102244 | 2.1 | 12.1 | MODSetter | SurfSense | CWE-918 | MODSetter SurfSense Document Export Feature editor_routes.py server-side requ… |
| CVE-2026-96430 | 8.7 | 12.0 | Flowring Technology Corp | Agentflow 4.0 | CWE-749 | Flowring Agentflow 4.0 - Exposed Dangerous Method or Function |
| CVE-2026-102241 | 2.0 | 11.3 | Netcore | NAP930 | CWE-320 | Netcore NAP930 Backup/Restore backup_common.sh hard-coded key |
| CVE-2026-102263 | 2.0 | 11.0 | mwasikz | robo-cafe-rms | CWE-284 | mwasikz robo-cafe-rms manage-food.php unrestricted upload |
| CVE-2026-102372 | 5.3 | 10.2 | GestSup | GestSup | CWE-79 | GestSup before 3.2.61 Stored XSS via Email Body in LOGIN IMAP Connector |
| CVE-2026-102374 | 5.3 | 10.2 | GestSup | GestSup | CWE-79 | GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IM… |
| CVE-2026-81914 | 4.3 | 8.9 | Apache Software Foundation | Apache Airflow Google provider | CWE-943 | Apache Airflow Google provider: Google Drive query injection via unescaped fi… |
| CVE-2026-102264 | 2.0 | 7.8 | mwasikz | robo-cafe-rms | CWE-79 | mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scri… |
| CVE-2026-96326 | 7.2 | 7.8 | htplugins | HT Contact Form – Drag & Drop Form Builder for WordPress | CWE-79 | HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenti… |
| CVE-2026-91048 | await | 7.6 | Apache Software Foundation | Apache Karaf | CWE-862 | Apache Karaf: Missing authorization on the jdbc:* shell command scope allows … |
| CVE-2026-96419 | 5.5 | 7.4 | Wireshark Foundation | Wireshark | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'… |
| CVE-2026-91012 | await | 5.9 | Apache Software Foundation | Apache Karaf | — | Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privil… |
| CVE-2026-91085 | await | 4.9 | Apache Software Foundation | Apache Karaf | CWE-862 | Apache Karaf: config:install missing ACL entry allows privilege escalation to… |
| CVE-2026-95392 | 5.5 | 4.3 | Wireshark Foundation | Wireshark | CWE-126 | Buffer Over-read in Wireshark |
| CVE-2026-96417 | 5.5 | 3.7 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-102474 | 4.0 | 3.1 | Red Hat | Red Hat Enterprise Linux 6 | CWE-787 | Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode es… |
| CVE-2026-95386 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
| CVE-2026-95390 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-476 | NULL Pointer Dereference in Wireshark |
| CVE-2026-95391 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-416 | Use After Free in Wireshark |
| CVE-2026-95395 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-401 | Missing Release of Memory after Effective Lifetime in Wireshark |
| CVE-2026-95388 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-96415 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-121 | Stack-based Buffer Overflow in Wireshark |
| CVE-2026-96416 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-96418 | 5.5 | 2.8 | Wireshark Foundation | Wireshark | CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
| CVE-2026-95394 | 4.7 | 2.5 | Wireshark Foundation | Wireshark | CWE-606 | Unchecked Input for Loop Condition in Wireshark |
| CVE-2026-96421 | 5.5 | 2.4 | Wireshark Foundation | Wireshark | CWE-1325 | Improperly Controlled Sequential Memory Allocation in Wireshark |
| CVE-2026-96422 | 5.5 | 2.4 | Wireshark Foundation | Wireshark | CWE-617 | Reachable Assertion in Wireshark |
| CVE-2026-96423 | 5.5 | 2.4 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-101278 | 2.1 | 2.4 | Trusted Domain Project | OpenDMARC | CWE-345 | Trusted Domain Project OpenDMARC PSL Wildcard opendmarc_tld.c : opendmarc_get… |
| CVE-2026-102473 | 5.5 | 2.2 | Red Hat | Red Hat Enterprise Linux 6 | CWE-1333 | Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disa… |
| CVE-2026-95393 | 4.7 | 2.1 | Wireshark Foundation | Wireshark | CWE-122 | Heap-based Buffer Overflow in Wireshark |
| CVE-2026-96420 | 4.7 | 1.7 | Wireshark Foundation | Wireshark | CWE-126 | Buffer Over-read in Wireshark |
| CVE-2026-86157 | 5.6 | 1.6 | Progress Software | Progress® Telerik® Fiddler® Everywhere | CWE-749 | Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere |
| CVE-2026-86158 | 7.7 | 0.3 | Progress Software | Progress® Telerik® Fiddler® Everywhere | CWE-306 | Missing Authentication in the local .NET backend of Progress Telerik Fiddler … |
| CVE-2026-71379 | 10.0 | — | Toptech Systems | TMS7 | CWE-552 | Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties |
| CVE-2026-96587 | 10.0 | — | Viidure | Dashcam Android Application | CWE-798 | Use of Hard-coded Credentials in Viidure Dashcam Android Application |
| CVE-2026-39117 | 9.8 | — | n/a | n/a | CWE-94 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plug… |
| CVE-2026-76721 | 9.8 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution … |
| CVE-2026-76722 | 9.8 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or D… |
| CVE-2026-77177 | 9.8 | — | n/a | n/a | CWE-94 | Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for … |
| CVE-2026-79538 | 9.8 | — | n/a | n/a | CWE-94 | metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Executio… |
| CVE-2026-76723 | 9.6 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code … |
| CVE-2026-76724 | 9.6 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking In… |
| CVE-2026-76725 | 9.6 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs |
| CVE-2026-95277 | 9.6 | — | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a rem… | |
| CVE-2026-95281 | 9.6 | — | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.5… | |
| CVE-2026-95283 | 9.6 | — | Chrome | CWE-122 | Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57… | |
| CVE-2026-95299 | 9.6 | — | Chrome | CWE-416 | Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remot… | |
| CVE-2026-95310 | 9.6 | — | Chrome | CWE-416 | Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95311 | 9.6 | — | Chrome | CWE-590 | Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allo… | |
| CVE-2026-95313 | 9.6 | — | Chrome | CWE-416 | Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed … | |
| CVE-2026-95318 | 9.6 | — | Chrome | CWE-122 | Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a re… | |
| CVE-2026-95325 | 9.6 | — | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a rem… | |
| CVE-2026-95329 | 9.6 | — | Chrome | CWE-787 | Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.80… | |
| CVE-2026-95331 | 9.6 | — | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed … | |
| CVE-2026-95339 | 9.6 | — | Chrome | CWE-416 | Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allow… | |
| CVE-2026-95347 | 9.6 | — | Chrome | CWE-416 | Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 a… | |
| CVE-2026-95349 | 9.6 | — | Chrome | CWE-122 | Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.5… | |
| CVE-2026-95350 | 9.6 | — | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.5… | |
| CVE-2026-95356 | 9.6 | — | Chrome | CWE-416 | Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowe… | |
| CVE-2026-95357 | 9.6 | — | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037… | |
| CVE-2026-100762 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Content Processes component |
| CVE-2026-100770 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Content Processes component |
| CVE-2026-100778 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Core & HTML component |
| CVE-2026-100786 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the Graphics component |
| CVE-2026-100800 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the Disability Access APIs component |
| CVE-2026-100804 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the Preferences: Backend component |
| CVE-2026-100811 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the DOM: Core & HTML component |
| CVE-2026-100818 | 9.6 | — | Mozilla | Firefox | CWE-416 | Sandbox escape due to use-after-free in the Widget: Gtk component |
| CVE-2026-100819 | 9.6 | — | Mozilla | Firefox | CWE-119 | Sandbox escape due to incorrect boundary conditions in the XPCOM component |
| CVE-2026-102304 | 9.6 | — | Chrome | CWE-416 | Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a… | |
| CVE-2026-102306 | 9.6 | — | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a… | |
| CVE-2026-102308 | 9.6 | — | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a rem… | |
| CVE-2026-102309 | 9.6 | — | Chrome | CWE-416 | Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed … | |
| CVE-2026-102316 | 9.6 | — | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a rem… | |
| CVE-2026-102331 | 9.6 | — | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.9… | |
| CVE-2026-102425 | 9.5 | — | balbooa.com | Balbooa Forms extension for Joomla | CWE-94 | Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode inje… |
| CVE-2026-70356 | 9.4 | — | Toptech Systems | TMS7 | CWE-434 | Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type |
| CVE-2026-82973 | 9.4 | — | psyb0t | docker-mailbox | CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox |
| CVE-2026-102793 | 9.4 | — | Ziroom | ZHOME A0101 | CWE-77 | Ziroom ZHOME A0101 set_time_zone command injection |
| CVE-2026-102794 | 9.4 | — | Ziroom | ZHOME A0101 | CWE-77 | Ziroom ZHOME A0101 ping command injection |
| CVE-2023-54400 | 9.3 | — | Fumasoft | Fumeng Cloud | CWE-89 | Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname |
| CVE-2026-7192 | 9.3 | — | Shenzhen Dbit Network Equipment | T-CPE301K 4G Mini WiFi Router | CWE-121 | Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen D… |
| CVE-2026-22094 | 9.3 | — | EVbee | DC 80 | CWE-1391 | Weak root password in EVbee DC 80 |
| CVE-2026-85520 | 9.3 | — | MyPresta | Google Merchant Center Feed | CWE-73 | Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module |
| CVE-2026-100291 | 9.3 | — | Anjvision | YSSD-RTMP-H5 | CWE-1188 | Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 |
| CVE-2026-102710 | 9.3 | — | Eclipse Foundation | eclipse-threadx/threadx | CWE-269 | Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_M… |
| CVE-2026-102761 | 9.3 | — | Eclipse Foundation | NetX Duo | CWE-787 | NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACK… |
| CVE-2026-103040 | 9.3 | — | ModelTC | LightLLM | CWE-502 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profi… |
| CVE-2026-103041 | 9.3 | — | ModelTC | LightLLM | CWE-502 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache … |
| CVE-2026-53988 | 9.2 | — | Finsys | dockhand | CWE-306 | Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints |
| CVE-2026-86131 | 9.2 | — | WatchGuard | Fireware OS | CWE-295 | Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution |
| CVE-2026-102828 | 9.2 | — | steveukx | git-js | CWE-78 | simple-git unsafe-operation guard does not block trailer command configuration |
| CVE-2026-102829 | 9.2 | — | steveukx | git-js | CWE-78 | simple-git: `VISUAL` editor environment variable is omitted from unsafe edito… |
| CVE-2026-84436 | 9.1 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-15390 | 9.0 | — | DENX Software Engineering | Das U-Boot | CWE-459 | Out-of-bounds write in Das U-Boot |
| CVE-2026-92222 | 8.9 | — | Joomla! Project | Joomla! CMS | CWE-918 | Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in… |
| CVE-2026-97689 | 8.9 | — | urllib3 | urllib3 | CWE-770 | urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size… |
| CVE-2026-102424 | 8.9 | — | balbooa.com | Balbooa Forms extension for Joomla | CWE-22 | Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates l… |
| CVE-2026-71971 | 8.8 | — | u-boot | u-boot | CWE-787 | U-Boot before 2026.10-rc3 Out-of-Bounds Write in IP Fragment Reassembly |
| CVE-2026-74220 | 8.8 | — | u-boot | u-boot | CWE-195 | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply |
| CVE-2026-74221 | 8.8 | — | u-boot | u-boot | CWE-195 | U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK |
| CVE-2026-74222 | 8.8 | — | u-boot | u-boot | CWE-416 | U-Boot before 2026.10-rc5 Use-After-Free in lwIP wget Receive Callback |
| CVE-2026-82804 | 8.8 | — | Apache Software Foundation | Apache DolphinScheduler | CWE-78 | Apache DolphinScheduler: Command Injection in the Alert Script Plugin |
| CVE-2026-84421 | 8.8 | — | IBM | DataStage on Cloud Pak for Data | CWE-22 | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-87748 | 8.8 | — | Interprobe Information Technologies Inc. | Qorela DC | CWE-862 | Privilege Escalation via Account Takeover in Interprobe's Qorela DC |
| CVE-2026-92370 | 8.8 | — | TeamViewer | Full Client | CWE-284 | Remote Session Access Control Bypass Leading to Remote Code Execution |
| CVE-2026-95282 | 8.8 | — | Chrome | CWE-416 | Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95286 | 8.8 | — | Chrome | CWE-843 | Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95304 | 8.8 | — | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a r… | |
| CVE-2026-95306 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote… | |
| CVE-2026-95338 | 8.8 | — | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a re… | |
| CVE-2026-95343 | 8.8 | — | Chrome | CWE-416 | Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95345 | 8.8 | — | Chrome | CWE-416 | Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a rem… | |
| CVE-2026-95353 | 8.8 | — | Chrome | CWE-416 | Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95365 | 8.8 | — | Chrome | CWE-843 | Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a… | |
| CVE-2026-95369 | 8.8 | — | Chrome | CWE-841 | Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95373 | 8.8 | — | Chrome | CWE-416 | Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95380 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote… | |
| CVE-2026-95509 | 8.8 | — | qt | Qt for MCUs | CWE-125 | Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs |
| CVE-2026-100757 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Widget component |
| CVE-2026-100761 | 8.8 | — | Mozilla | Firefox | CWE-416 | Privilege escalation due to use-after-free in the Graphics: WebGPU component |
| CVE-2026-100764 | 8.8 | — | Mozilla | Firefox | CWE-119 | Privilege escalation due to incorrect boundary conditions in the Graphics: We… |
| CVE-2026-100765 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-100767 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Networking: Cache component |
| CVE-2026-100768 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: WebGPU component |
| CVE-2026-100769 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-100772 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-100773 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Storage: IndexedDB component |
| CVE-2026-100774 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-100776 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-100777 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: Canvas2D component |
| CVE-2026-100779 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the XSLT component |
| CVE-2026-100780 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-100782 | 8.8 | — | Mozilla | Firefox | CWE-119 | Privilege escalation due to incorrect boundary conditions in the Graphics com… |
| CVE-2026-100784 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Layout: Text and Fonts component |
| CVE-2026-100785 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-100789 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: Canvas2D component |
| CVE-2026-100790 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the XSLT component |
| CVE-2026-100791 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: Core & HTML component |
| CVE-2026-100796 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript: WebAssembly component |
| CVE-2026-100797 | 8.8 | — | Mozilla | Firefox | CWE-416 | Privilege escalation due to use-after-free in the Graphics: WebRender component |
| CVE-2026-100801 | 8.8 | — | Mozilla | Firefox | CWE-269 | Privilege escalation in the DLL Services component |
| CVE-2026-100807 | 8.8 | — | Mozilla | Firefox | CWE-269 | Privilege escalation in the DOM: Service Workers component |
| CVE-2026-100813 | 8.8 | — | Mozilla | Firefox | CWE-763 | Invalid pointer in the JavaScript Engine: JIT component |
| CVE-2026-100814 | 8.8 | — | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the JavaScript Engine: JIT component |
| CVE-2026-100815 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the CSS Parsing and Computation component |
| CVE-2026-100820 | 8.8 | — | Mozilla | Firefox | CWE-269 | Privilege escalation in the Address Bar component |
| CVE-2026-100824 | 8.8 | — | Mozilla | Firefox | CWE-269 | Privilege escalation in the Places component |
| CVE-2026-100825 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the JavaScript Engine: JIT component |
| CVE-2026-100831 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the DOM: UI Events & Focus Handling component |
| CVE-2026-100832 | 8.8 | — | Mozilla | Firefox | CWE-416 | Use-after-free in the Graphics: Canvas2D component |
| CVE-2026-102299 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote… | |
| CVE-2026-102302 | 8.8 | — | Chrome | CWE-121 | Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remot… | |
| CVE-2026-102321 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote… | |
| CVE-2026-102323 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote… | |
| CVE-2026-102326 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote… | |
| CVE-2026-102328 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote… | |
| CVE-2026-102712 | 8.8 | — | Eclipse Foundation | NetX Duo | CWE-125 | On the first DTLS ClientHello, the parser copies a device-claimed session_id … |
| CVE-2026-102713 | 8.8 | — | Eclipse Foundation | NetX Duo | CWE-125 | The TFTP server accepts a DATA datagram of any size. The dispatcher rejects d… |
| CVE-2015-20122 | 8.7 | — | Yonyou | A6 OA | CWE-89 | Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp |
| CVE-2022-51019 | 8.7 | — | akaunting | akaunting | CWE-78 | Akaunting before 2.1.31 OS Command Injection via app alias |
| CVE-2026-4034 | 8.7 | — | Tibco | Administrator | CWE-74 | TIBCO Administrator Injection Vulnerability |
| CVE-2026-61519 | 8.7 | — | Liberu Software | Liberu CRM | CWE-863 | Liberu CRM 0.9.1 < 10.0.0 Broken Access Control via TeamPolicy::addTeamMember() |
| CVE-2026-68911 | 8.7 | — | nicotine-plus | nicotine-plus | CWE-409 | Nicotine+: Decompression of peer messages can exhaust available memory |
| CVE-2026-81433 | 8.7 | — | WatchGuard | Fireware OS | CWE-120 | Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote… |
| CVE-2026-86104 | 8.7 | — | WatchGuard | Fireware OS | CWE-400 | Fireware OS Resource Exhaustion in Login Process Allows Denial of Service |
| CVE-2026-94204 | 8.7 | — | Viidure | Dashcam Android Application | CWE-732 | Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Andr… |
| CVE-2026-100292 | 8.7 | — | Anjvision | YSSD-RTMP-H5 | CWE-78 | Improper neutralization of special elements used in an OS command ('OS comman… |
| CVE-2026-100293 | 8.7 | — | Anjvision | YSSD-RTMP-H5 | CWE-347 | Improper verification of cryptographic signature in Anjvision YSSD-RTMP-H5 |
| CVE-2026-100294 | 8.7 | — | Anjvision | YSSD-RTMP-H5 | CWE-798 | Use of Hard-coded Credentials in Anjvision YSSD-RTMP-H5 |
| CVE-2026-100298 | 8.7 | — | Anjvision | YSSD-RTMP-H5 | CWE-522 | Insufficiently Protected Credentials in Anjvision YSSD-RTMP-H5 |
| CVE-2026-102253 | 8.7 | — | esnet | iperf3 | CWE-835 | iperf3 < 3.22 UDP Receive Worker Infinite Loop DoS |
| CVE-2026-102634 | 8.7 | — | sgl-project | sglang | CWE-694 | SGLang through 0.5.20 Denial of Service via Duplicate bootstrap_room |
| CVE-2026-102716 | 8.7 | — | Eclipse Foundation | eclipse-threadx/netxduo | CWE-401 | An unauthenticated client can drain the RTSP server's packet pool with a coup… |
| CVE-2026-102718 | 8.7 | — | Eclipse Foundation | NetX Duo | CWE-125 | hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not val… |
| CVE-2026-102810 | 8.7 | — | rochacbruno | marmite | CWE-22 | Marmite through 0.4.2 Path Traversal via Development Server |
| CVE-2026-102811 | 8.7 | — | rochacbruno | marmite | CWE-306 | Marmite through 0.4.2 Unauthenticated API Access via Development Server |
| CVE-2026-103042 | 8.7 | — | ModelTC | LightLLM | CWE-770 | LightLLM through 1.2.0 Unauthenticated Memory Exhaustion via NCCL Control Cha… |
| CVE-2026-103043 | 8.7 | — | alexcorvi | anchorme | CWE-1333 | anchorme through 3.0.8 Regular Expression Denial of Service |
| CVE-2026-7193 | 8.6 | — | Shenzhen Dbit Network Equipment | T-CPE301K 4G Mini WiFi Router | CWE-798 | Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen D… |
| CVE-2026-18145 | 8.6 | — | WatchGuard | Fireware OS | CWE-121 | Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution |
| CVE-2026-101127 | 8.6 | — | balbooa.com | Balbooa Forms extension for Joomla | CWE-79 | Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS i… |
| CVE-2026-102242 | 8.6 | — | MCP Toolbox for Databases | CWE-22 | Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for … | |
| CVE-2026-102317 | 8.6 | — | Chrome | CWE-269 | Improper privilege management in Mojo in Google Chrome on on Windows prior to… | |
| CVE-2026-102360 | 8.6 | — | dmonad | lib0 | CWE-125 | lib0 `readUint8Array` performs an unbounded read past the end of the decoder’… |
| CVE-2026-102521 | 8.6 | — | dmonad | lib0 | CWE-125 | lib0 `readFromDataView` out-of-bounds read |
| CVE-2026-102556 | 8.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-843 | Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion |
| CVE-2026-102557 | 8.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: libsoup: heap buffer overflow during websocket message reassembly |
| CVE-2026-102558 | 8.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth |
| CVE-2026-102559 | 8.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: libsoup: heap buffer overflow during websocket client-frame masking |
| CVE-2026-102560 | 8.6 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buf… |
| CVE-2026-102730 | 8.6 | — | Eclipse Foundation | eclipse-threadx/levelx(NAND driver) | CWE-787 | Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) tri… |
| CVE-2026-102876 | 8.6 | — | surrealdb | surrealdb | CWE-639 | SurrealDB before 3.3.0 Cross-Tenant Access via Headers |
| CVE-2026-102878 | 8.6 | — | hangwin | mcp-chrome-bridge | CWE-346 | mcp-chrome-bridge through 1.0.31 CORS Origin Bypass |
| CVE-2026-63713 | 8.5 | — | Toptech Systems | TMS7 | CWE-89 | Toptech TMS7 and TopHAT SQL Injection |
| CVE-2026-68068 | 8.5 | — | Toptech Systems | TMS7 | CWE-89 | Toptech TMS7 and TopHAT SQL Injection |
| CVE-2026-68954 | 8.5 | — | Toptech Systems | TMS7 | CWE-89 | Toptech TMS7 and TopHAT SQL Injection |
| CVE-2026-72507 | 8.5 | — | Toptech Systems | TMS7 | CWE-89 | Toptech TMS7 and TopHAT SQL Injection |
| CVE-2026-72510 | 8.5 | — | Toptech Systems | TMS7 | CWE-89 | Toptech TMS7 and TopHAT SQL Injection |
| CVE-2026-86035 | 8.5 | — | WeblateOrg | weblate | CWE-78 | Weblate: Mercurial argument injection via repository filenames allows authent… |
| CVE-2026-102566 | 8.5 | — | OpenNMT | CTranslate2 | CWE-787 | CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin |
| CVE-2026-102697 | 8.5 | — | ollama | ollama | CWE-863 | Ollama 0.14.0 before 0.31.2 Experimental Agent Bash Approval Bypass via Prefi… |
| CVE-2026-102757 | 8.5 | — | Eclipse Foundation | ThreadX | CWE-125 | An unprivileged, memory-protected ThreadX module can have the kernel read and… |
| CVE-2026-102792 | 8.5 | — | Ziroom | ZHOME A0101 | CWE-74 | Ziroom ZHOME A0101 set_syslog command injection |
| CVE-2026-102875 | 8.5 | — | videolan | vlc | CWE-22 | VLC media player before 3.0.24 Path Traversal via skins2 |
| CVE-2026-100308 | 8.4 | — | AWS | gluonts | CWE-470 | GluonTS arbitrary command execution during model deserialization |
| CVE-2026-102709 | 8.4 | — | Eclipse Foundation | ThreadX | CWE-200 | Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-s… |
| CVE-2026-95274 | 8.3 | — | Chrome | CWE-116 | Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 … | |
| CVE-2026-95276 | 8.3 | — | Chrome | CWE-20 | Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95319 | 8.3 | — | Chrome | CWE-416 | Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95322 | 8.3 | — | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037… | |
| CVE-2026-95334 | 8.3 | — | Chrome | CWE-706 | Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.… | |
| CVE-2026-95335 | 8.3 | — | Chrome | CWE-416 | Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remot… | |
| CVE-2026-95341 | 8.3 | — | Chrome | CWE-20 | Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 … | |
| CVE-2026-95348 | 8.3 | — | Chrome | CWE-416 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a… | |
| CVE-2026-95351 | 8.3 | — | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a rem… | |
| CVE-2026-95354 | 8.3 | — | Chrome | CWE-416 | Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95355 | 8.3 | — | Chrome | CWE-863 | Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154… | |
| CVE-2026-95372 | 8.3 | — | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed … | |
| CVE-2026-95381 | 8.3 | — | Chrome | CWE-20 | Improper input validation in Printing in Google Chrome prior to 154.0.8037.57… | |
| CVE-2026-96274 | 8.3 | — | Baicells | Nova 430H eNodeB (model pBS3101SH) | CWE-248 | Uncaught exception in Baicells Nova 430H |
| CVE-2026-102301 | 8.3 | — | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a … | |
| CVE-2026-102324 | 8.3 | — | Chrome | CWE-416 | Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 al… | |
| CVE-2026-102676 | 8.3 | — | electron | electron | CWE-269 | Electron: <webview> can enable Node.js integration in Web Workers despite emb… |
| CVE-2026-102760 | 8.3 | — | Eclipse Foundation | NetX Duo | CWE-416 | When NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent o… |
| CVE-2026-13224 | 8.2 | — | WatchGuard | Fireware OS | CWE-22 | Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local F… |
| CVE-2026-76719 | 8.2 | — | Hewlett Packard Enterprise | HPE OneView | CWE-79 | HPE OneView - Cross-site scripting vulnerability |
| CVE-2026-84782 | 8.2 | — | OpenSSL | OpenSSL | CWE-125 | DTLS Retransmits Handshake Messages From a Stale Buffer Offset |
| CVE-2026-86128 | 8.2 | — | WatchGuard | Fireware OS | CWE-476 | Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allow… |
| CVE-2026-86132 | 8.2 | — | WatchGuard | Fireware OS | CWE-191 | Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Ser… |
| CVE-2026-86133 | 8.2 | — | WatchGuard | Fireware OS | CWE-1284 | Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial… |
| CVE-2026-92227 | 8.2 | — | Joomla! Project | Joomla! CMS | CWE-287 | Joomla! Core - [20260914] - Core - MFA Authentication Bypass through remember… |
| CVE-2026-102555 | 8.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri b… |
| CVE-2026-102633 | 8.2 | — | libexpat | libexpat | CWE-190 | libexpat 2.7.2 through 2.8.5 Integer Overflow in expat_realloc |
| CVE-2026-102673 | 8.2 | — | electron | electron | CWE-346 | Electron drops inherited HTML sandbox restrictions for popups opened through … |
| CVE-2026-102674 | 8.2 | — | electron | electron | CWE-266 | Electron: Windows opened from a sandboxed top-level document do not inherit i… |
| CVE-2026-102762 | 8.2 | — | Eclipse Foundation | NetX Duo | CWE-401 | The NetX Duo MQTT client leaks the packet carrying a malformed PUBLISH messag… |
| CVE-2026-76726 | 8.1 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authentication Bypass Leading to Unauthorized Network Access in HPE Networkin… |
| CVE-2026-84842 | 8.1 | — | IBM | Guardium Data Protection | CWE-22 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-95333 | 8.1 | — | Chrome | CWE-416 | Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a r… | |
| CVE-2026-102826 | 8.1 | — | steveukx | git-js | CWE-77 | simple-git allows command execution through unblocked Git configuration includes |
| CVE-2026-102827 | 8.1 | — | steveukx | git-js | CWE-77 | simple-git: unsafe-operations plugin bypass via git long-option abbreviation … |
| CVE-2026-102831 | 8.1 | — | jupyterlab | jupyterlab | CWE-79 | JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells paste… |
| CVE-2026-19743 | 7.8 | — | TeamViewer | Full Client | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) … |
| CVE-2026-65102 | 7.8 | — | NVIDIA | DeepStream | CWE-190 | NVIDIA DeepStream contains a vulnerability where an attacker could cause an i… |
| CVE-2026-73598 | 7.8 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-732 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-84414 | 7.8 | — | IBM | i | CWE-732 | IBM i is Affected By An Incorrect Permission Assignment Vulnerability in Netw… |
| CVE-2026-92368 | 7.8 | — | TeamViewer | Full Client | CWE-122 | Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to … |
| CVE-2026-95298 | 7.8 | — | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a l… | |
| CVE-2026-95315 | 7.8 | — | Chrome | CWE-416 | Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a loca… | |
| CVE-2026-102437 | 7.8 | — | esengine | DeepSeek-Reasonix | CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Comman… |
| CVE-2026-102677 | 7.8 | — | electron | electron | CWE-20 | Electron: Sandboxed preload code cache can be poisoned by a compromised renderer |
| CVE-2026-102925 | 7.8 | — | pypa | virtualenv | CWE-78 | virtualenv bash and fish activation scripts execute commands embedded in paths |
| CVE-2026-84409 | 7.7 | — | Lantronix | G520 Series | CWE-79 | Lantronix G520 Series Cellular Gateway Cross-site Scripting |
| CVE-2026-91191 | 7.7 | — | Lantronix | G520 Series | CWE-347 | Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic… |
| CVE-2026-102930 | 7.7 | — | pypa | virtualenv | CWE-494 | virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked… |
| CVE-2026-97687 | 7.6 | — | urllib3 | urllib3 | CWE-295 | urllib3: HTTPS proxy TLS configuration may be ignored or overridden |
| CVE-2026-13046 | 7.5 | — | WatchGuard | Fireware OS | CWE-502 | Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Exe… |
| CVE-2026-63209 | 7.5 | — | klauspost | compress | CWE-190 | Integer Overflow or Wraparound and Out-of-bounds Write in compress |
| CVE-2026-71302 | 7.5 | — | Toptech Systems | TMS7 | CWE-384 | Toptech TMS7 and TopHAT Session Fixation |
| CVE-2026-72897 | 7.5 | — | OpenSSL | OpenSSL | CWE-787 | Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake |
| CVE-2026-84440 | 7.5 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-84783 | 7.5 | — | OpenSSL | OpenSSL | CWE-416 | Use-After-Free in X.509 Extension Cache Under Concurrent Use |
| CVE-2026-84784 | 7.5 | — | OpenSSL | OpenSSL | CWE-770 | QUIC: Unbounded RETIRE_CONNECTION_ID Backlog |
| CVE-2026-86450 | 7.5 | — | Parla Auto Automotive Trading Limited Company | DetaWix Mobile Web Portal | CWE-201 | Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal |
| CVE-2026-95280 | 7.5 | — | Chrome | CWE-362 | Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote… | |
| CVE-2026-100805 | 7.5 | — | Mozilla | Firefox | CWE-362 | Race condition, use-after-free in the Audio/Video component |
| CVE-2026-102327 | 7.5 | — | Chrome | CWE-863 | Incorrect authorization in WebView in Google Chrome on on Android prior to 15… | |
| CVE-2026-102495 | 7.5 | — | Apache Software Foundation | Apache XMLSchema | CWE-674 | Apache XMLSchema: Denial of service through unbounded recursion when resolvin… |
| CVE-2026-102496 | 7.5 | — | Apache Software Foundation | Apache XMLSchema | CWE-674 | Apache XMLSchema: Denial of service through deeply nested schema structures |
| CVE-2026-102497 | 7.5 | — | Apache Software Foundation | Apache XMLSchema | CWE-674 | Apache XMLSchema: Denial of service through cyclic schema definitions in the … |
| CVE-2026-102600 | 7.5 | — | socketio | socket.io | CWE-20 | Socket.IO: Prototype Pollution via Unsafe Client Session Lookup |
| CVE-2026-102823 | 7.5 | — | Eugeny | russh | CWE-20 | russh: Client-side channel-scoped Handler callbacks fire for channel IDs the … |
| CVE-2026-102675 | 7.4 | — | electron | electron | CWE-346 | Electron: File and HTTP protocol handlers allow cross-origin reads without co… |
| CVE-2026-92369 | 7.3 | — | TeamViewer | Full Client | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Insta… |
| CVE-2026-102937 | 7.3 | — | pypa | virtualenv | CWE-78 | virtualenv: Command injection via --prompt in activate.bat (batch activator) |
| CVE-2026-76727 | 7.2 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON |
| CVE-2026-76728 | 7.2 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Server-Side Request Forgery Leading to Remote Code Execution in… |
| CVE-2026-84422 | 7.2 | — | IBM | Guardium Data Protection | CWE-78 | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-86101 | 7.2 | — | WatchGuard | Fireware OS | CWE-285 | Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access |
| CVE-2026-93853 | 7.2 | — | EnterpriseDB | Barman | CWE-283 | Barman snapshot backup deletion trusts unverified backup catalog metadata |
| CVE-2026-100296 | 7.2 | — | Anjvision | YSSD-RTMP-H5 | CWE-754 | Improper Check for Unusual or Exceptional Conditions in Anjvision YSSD-RTMP-H5 |
| CVE-2026-18105 | 7.1 | — | WatchGuard | Fireware OS | CWE-400 | Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Deni… |
| CVE-2026-74225 | 7.1 | — | u-boot | u-boot | CWE-787 | U-Boot before 2026.10-rc5 Out-of-Bounds Write via DHCPv6 |
| CVE-2026-86136 | 7.1 | — | WatchGuard | Fireware OS | CWE-22 | Fireware OS Missing Authorization in wgagent Management API Allows Denial of … |
| CVE-2026-90441 | 7.1 | — | WatchGuard | Fireware OS | CWE-200 | Fireware OS Missing Authorization in wgagent Management API Allows Denial of … |
| CVE-2026-92231 | 7.1 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5… |
| CVE-2026-92232 | 7.1 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via white… |
| CVE-2026-95520 | 7.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffe… |
| CVE-2026-102639 | 7.1 | — | MobilityDB | MobilityDB | CWE-195 | MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization |
| CVE-2026-102714 | 7.1 | — | Eclipse Foundation | NetX Duo | CWE-125 | `_nx_icmpv6_validate_options()` scans the option area with `while (length > 2… |
| CVE-2026-102715 | 7.1 | — | Eclipse Foundation | eclipse-threadx/netxduo | CWE-787 | mDNS string-cache lookup matches on slot size, so a peer name aliases a short… |
| CVE-2026-102808 | 7.1 | — | PX4 | PX4-Autopilot | CWE-476 | PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress |
| CVE-2026-102809 | 7.1 | — | PX4 | PX4-Autopilot | CWE-789 | PX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 Command |
| CVE-2026-19547 | 7.0 | — | Artifex Software Inc. | Ghostscript | CWE-426 | Local Privilege Escalation in Ghostscript for Windows |
| CVE-2026-90913 | 7.0 | — | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260903] - Core - Improper ACL checks for access level webse… |
| CVE-2026-90915 | 7.0 | — | Joomla! Project | Joomla! CMS | CWE-22 | Joomla! Core - [20260905] - Core - Arbitrary directory deletion via cache pur… |
| CVE-2026-92226 | 7.0 | — | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice … |
| CVE-2026-92371 | 7.0 | — | TeamViewer | Full Client | CWE-59 | Local Privilege Escalation via Improper Link Resolution in Cloud Session Reco… |
| CVE-2026-100299 | 7.0 | — | Anjvision | YSSD-RTMP-H5 | CWE-1391 | Use of Weak Credentials in Anjvision YSSD-RTMP-H5 |
| CVE-2026-102569 | 7.0 | — | MacWarrior | clipbucket-v5 | CWE-89 | ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter |
| CVE-2026-102570 | 7.0 | — | MacWarrior | clipbucket-v5 | CWE-89 | ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter |
| CVE-2026-41875 | 6.9 | — | OpenSolution | Quick.Cart | CWE-352 | Cross-Site Request Forgery in admin panel of Quick.Cart |
| CVE-2026-90907 | 6.9 | — | Joomla! Project | Joomla! CMS | CWE-639 | Joomla! Core - [20260902] - Core - Unauthorized user account creation via pro… |
| CVE-2026-90917 | 6.9 | — | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged … |
| CVE-2026-90918 | 6.9 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260908] - Core - XSS in HTML Mail Templates in Joomla 4.0.0… |
| CVE-2026-97688 | 6.9 | — | urllib3 | urllib3 | CWE-835 | urllib3: Chunked Deflate streaming can enter an infinite loop |
| CVE-2026-100297 | 6.9 | — | Anjvision | YSSD-RTMP-H5 | CWE-918 | Server-Side request forgery (SSRF) in Anjvision YSSD-RTMP-H5 |
| CVE-2026-101112 | 6.9 | — | balbooa.com | Balbooa Forms extension for Joomla | CWE-639 | Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balb… |
| CVE-2026-101126 | 6.9 | — | balbooa.com | Balbooa Forms extension for Joomla | CWE-22 | Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < … |
| CVE-2026-102252 | 6.9 | — | OSV-SCALIBR | CWE-22 | Path Traversal in VMDK Extractor in OSV-SCALIBR | |
| CVE-2026-102567 | 6.9 | — | OpenNMT | CTranslate2 | CWE-125 | CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization |
| CVE-2026-102721 | 6.9 | — | Eclipse Foundation | NetX Duo | CWE-125 | A TFTP server that answers with a short ERROR packet makes the client read up… |
| CVE-2026-102722 | 6.9 | — | Eclipse Foundation | NetX Duo | CWE-918 | In the IPv4 PASV path, the FTP Client accepts whatever address was sent in th… |
| CVE-2025-33207 | 6.8 | — | NVIDIA | BlueField GA | CWE-1262 | NVIDIA ConnectX and Bluefield contain a vulnerability in a control register, … |
| CVE-2026-102507 | 6.8 | — | BishopFox | sliver | CWE-125 | Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC |
| CVE-2026-102568 | 6.8 | — | pardus | pardus-parental-control | CWE-863 | Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py |
| CVE-2026-102830 | 6.8 | — | jupyterlab | jupyterlab | CWE-79 | JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language pac… |
| CVE-2026-76729 | 6.6 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Format String Vulnerability allows Memory Corruption in HPE Net… |
| CVE-2026-66083 | 6.5 | — | Apache Software Foundation | Apache DolphinScheduler | CWE-306 | Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information v… |
| CVE-2026-73597 | 6.5 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-352 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-76730 | 6.5 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Improper PAPI Packet handling leads to unauthorized access in HPE Networking … |
| CVE-2026-76731 | 6.5 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authentication Bypass in the Captive Portal of HPE Networking Instant On |
| CVE-2026-81862 | 6.5 | — | Apache Software Foundation | Apache Airflow Teradata provider | CWE-532 | Apache Airflow Teradata provider: Teradata transfer operators embed cloud sto… |
| CVE-2026-95327 | 6.5 | — | Chrome | CWE-200 | Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowe… | |
| CVE-2026-95328 | 6.5 | — | Chrome | CWE-441 | Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.… | |
| CVE-2026-95336 | 6.5 | — | Chrome | CWE-200 | Information leak in Transactions Platform in Google Chrome prior to 154.0.803… | |
| CVE-2026-95382 | 6.5 | — | Chrome | CWE-20 | Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 all… | |
| CVE-2026-100286 | 6.5 | — | Devolutions | Server | CWE-200 | Missing authorization in the data source settings API in Devolutions Server 2… |
| CVE-2026-100795 | 6.5 | — | Mozilla | Firefox | CWE-770 | Denial-of-service in the Networking component |
| CVE-2026-100812 | 6.5 | — | Mozilla | Firefox | CWE-770 | Denial-of-service in the Graphics component |
| CVE-2026-100826 | 6.5 | — | Mozilla | Firefox | CWE-770 | Denial-of-service in the Storage: StorageManager component |
| CVE-2026-102623 | 6.5 | — | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-476 | Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed eph… |
| CVE-2026-102821 | 6.5 | — | Eugeny | russh | CWE-400 | Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-sta… |
| CVE-2026-73594 | 6.4 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-295 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-76732 | 6.4 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Net… |
| CVE-2026-76875 | 6.3 | — | PyPy | PyPy | CWE-416 | PyPy pyexpat ExternalEntityParserCreate Use-After-Free |
| CVE-2026-81930 | 6.3 | — | Apache Software Foundation | Apache Airflow Snowflake provider | CWE-522 | Apache Airflow Snowflake provider: Unvalidated account field redirects SQL AP… |
| CVE-2026-86843 | 6.3 | — | Apache Software Foundation | Apache Airflow Teradata provider | CWE-89 | Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in… |
| CVE-2026-102598 | 6.3 | — | pallets | werkzeug | CWE-67 | Werkzeug safe_join() allows Windows special device names |
| CVE-2026-102635 | 6.3 | — | ImageMagick | ImageMagick | CWE-908 | ImageMagick before 7.1.2-32 and 6.9.13-57 Uninitialized Heap Memory Disclosur… |
| CVE-2026-102719 | 6.3 | — | Eclipse Foundation | netxduo | CWE-330 | Predictable DTLS HelloVerifyRequest Cookie in NetX Secure |
| CVE-2026-102759 | 6.3 | — | Eclipse Foundation | NetX Duo | CWE-354 | NetX Secure TLS accepts an empty application-data record without verifying it… |
| CVE-2026-102820 | 6.2 | — | Eugeny | russh | CWE-125 | pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::re… |
| CVE-2026-71972 | 6.0 | — | u-boot | u-boot | CWE-787 | U-Boot through 2026.10-rc5 Out-of-Bounds Write in BMP RLE8 Decoder |
| CVE-2026-102723 | 6.0 | — | Eclipse Foundation | NetX Duo | CWE-476 | NULL Pointer Dereference on MSRP Attribute Table Exhaustion |
| CVE-2026-102724 | 6.0 | — | Eclipse Foundation | NetX Duo | CWE-476 | NULL Pointer Dereference When Evicting the Sole MSRP Attribute |
| CVE-2026-102725 | 6.0 | — | Eclipse Foundation | NetX Duo | CWE-125 | Out-of-bounds Read from Unvalidated MSRP Attribute List Length |
| CVE-2026-102726 | 6.0 | — | Eclipse Foundation | NetX Duo | CWE-125 | Unbounded PPP IPCP Option Parsing Causes a Worker Stall and Out-of-bounds Read |
| CVE-2026-102727 | 6.0 | — | Eclipse Foundation | NetX Duo | CWE-923 | FTP Passive Data Connection Not Bound to the Authenticated Control Peer |
| CVE-2026-102806 | 6.0 | — | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.9.5 Sandbox Isolation Bypass via Media Pipelines |
| CVE-2026-102807 | 6.0 | — | OpenClaw | OpenClaw | CWE-863 | OpenClaw before 2026.9.4 Authorization Bypass via MCP App Standalone Ticket |
| CVE-2026-12345 | 5.9 | — | Python Software Foundation | CPython | CWE-59 | Race condition in tempfile.TemporaryDirectory cleanup allows deleting files o… |
| CVE-2026-76114 | 5.9 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-319 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-90906 | 5.9 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.… |
| CVE-2026-90914 | 5.9 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260904] - Core - XSS in the generic media output layouts in… |
Results continue: ranks 401–611.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-29 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.