boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 30, 2026 · all times UTC← 2026-09-29 · archive

Security Box Score — September 30, 2026

CISA adds 1 to KEV; 636 CVEs published, led by NVIDIA (114).

636 CVEs published September 30, 2026: 54 critical, 296 high, 226 medium, 40 low; 1 in the KEV catalog at press time; 0 with a public exploit reference; 20 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 236 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1494149932——
KEV catalog size1730

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3225 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux21156205530263871311560.17.8.0019+472 ▲
microsoft10022901201199269216290311.17.8.0047+525 ▲
google6622831355109512411318090.37.5.0027+260 ▲
red hat2648985137941553200.06.7.0035+42 ▲
apple24756467166317148991.66.5.0019+203 ▲
suse2553827162000.07.5.0036+18 ▲
canonical8501612175000.07.8.0021-7 ▼
freebsd04823673000.07.8.0016-32 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco98182547255160179.37.8.0046+52 ▲
ubiquiti665362810334.69.1.0050-17 ▼
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-7 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache195707158297229163320.37.5.0062+37 ▲
mozilla191379112160840900.08.8.0030+132 ▲
gitlab281047246211532.95.3.0034+3 ▲
drupal2694119668411.15.7.0027+9 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614103350.08.7.0392-1 ▼
kubernetes120011000.04.5.0028+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-256 ▼
ibm404102319647333618610.17.5.0037+14 ▲
adobe2248308236437592150.67.5.0036+123 ▲
progress5661540110611.58.1.0046-14 ▼
zohocorp324262970000.08.3.0117+28 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-13 ▼
servicenow5107300200.09.4.0036+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link297422281212300.08.5.0164+10 ▲
siemens1552633103000.07.3.0026-6 ▼
synology1946510256000.05.6.0032+15 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
hitachi energy9122460000.07.0.0025+9 ▲
abb4111640000.07.2.0018+4 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell2073783117215124210.37.2.0027+136 ▲
nvidia16730125206700000.07.8.0040+115 ▲
sourcecodester682370014295000.05.5.0042+19 ▲
openclaw9022341148421000.07.1.0031+90 ▲
spring017013608314000.06.5.0033-91 ▼
mongodb71169699604100.07.1.0038+16 ▲
hewlett packard enterprise (hpe)1571662280559110.67.2.0042+154 ▲
itsourcecode371530037116000.02.1.00330

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.914399.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-87902.197697.38.1
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-83548.087695.010.0
CVE-2026-85102.075594.39.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9143KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
Most disclosures (vendor)
VendorCVEs
linux2115
microsoft1002
google662
oracle634
ibm404
red hat264
apple247
adobe224
dell207
apache195
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven113
npm19
Packagist18
PyPI15
crates.io9
Go4
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171778
CVE-2021-27102n/a2021-11-171778
CVE-2021-27101n/a2021-11-171778
CVE-2021-27103n/a2021-11-171778
CVE-2021-21017Adobe2021-11-171778
CVE-2021-28550Adobe2021-11-171778
CVE-2021-42013Apache Software Foundation2021-11-171778
CVE-2021-41773Apache Software Foundation2021-11-171778
CVE-2021-30858Apple2021-11-171778
CVE-2021-30860Apple2021-11-171778

Transactions

ADDED TO KEV — CVE-2026-76504 (Cisco Catalyst SD-WAN Manager). Remediation due October 3, 2026.

EXPLOIT PUBLISHED — Google Chrome: 11 CVEs (CVE-2026-95276, CVE-2026-95282, CVE-2026-95287, CVE-2026-95289, CVE-2026-95298, CVE-2026-95345, CVE-2026-95346, CVE-2026-95350, CVE-2026-95357, CVE-2026-95359, CVE-2026-95371). Public exploit references added.

EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.

EXPLOIT PUBLISHED — Project-MONAI MONAI: 6 CVEs (CVE-2026-100840, CVE-2026-100842, CVE-2026-100843, CVE-2026-100844, CVE-2026-100845, CVE-2026-100846). Public exploit references added.

EXPLOIT PUBLISHED — grokability snipe-it: 4 CVEs (CVE-2026-49976, CVE-2026-55694, CVE-2026-55703, CVE-2026-61807). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2016-20097 (Weaver Network Co., Ltd. E-cology 8.0). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-50997 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-15612 (Wazuh Provisioning Scripts (Agent Build Environment)). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-50343. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100306 (TDuckCloud tduck-survey-form). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100744 (coollabsio Coolify). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100873 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100876 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100879 (zhistaredu StarTraining). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100882 (Krayin laravel-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100885 (Krayin laravel-crm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100888 (Trusted Domain Project OpenDKIM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102621 (Freedesktop Poppler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102771 (Naichen ThinkCMF). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 8). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59090 (gimp). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59095 (lobehub). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76208 (thorsten phpMyFAQ). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-76844 (zlib). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-80428 (ILIAS-eLearning e.V. ILIAS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94214 (ST Engineering iDirect Evolution). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94216 (ST Engineering iDirect Evolution). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97064 (yzcheng90 X-SpringBoot). Public exploit reference added.

REJECTED — CVE-2017-20051 (InnoSetup Installer). Record withdrawn by the CNA.

REJECTED — CVE-2025-68195 (Linux). Record withdrawn by the CNA.

REJECTED — CVE-2026-13087 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA.

REJECTED — CVE-2026-94684 (oceanwp Ocean Extra). Record withdrawn by the CNA.

RESCORED — CVE-2023-39417 (Red Hat Advanced Cluster Security 4.2). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2025-21042 (Samsung Mobile Devices). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2025-53844 (Fortinet FortiOS). CVSS 8.3 → 8.8 (NVD).

RESCORED — CVE-2025-66376 (Zimbra Collaboration). CVSS 7.2 → 6.1 (NVD).

RESCORED — CVE-2026-102793 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).

RESCORED — CVE-2026-102794 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).

RESCORED — CVE-2026-10841 (IBM CICS TX Advanced). CVSS 4.2 → 4.8 (NVD).

RESCORED — CVE-2026-42169 (Red Hat Enterprise Linux 9). CVSS 7.3 → 7.8 (NVD).

RESCORED — CVE-2026-50550 (grokability snipe-it). CVSS 5.8 → 6.3 (NVD).

RESCORED — CVE-2026-59328 (Spring Tools for Eclipse). CVSS 4.2 → 5.4 (NVD).

RESCORED — CVE-2026-6384 (Red Hat Enterprise Linux 6). CVSS 7.3 → 7.8 (NVD).

RESCORED — CVE-2026-81352 (Microsoft Web Media Extensions). CVSS 9.8 → 8.8 (NVD).

RESCORED — CVE-2026-86105 (WatchGuard Fireware OS). CVSS 5.3 → 6 (NVD).

RESCORED — CVE-2026-93353 (9001 copyparty). CVSS 6 → 2.3 (NVD).

PATCH SHIPPED — CVE-2026-65488 (LA-Studio Element Kit for Elementor). Fixed in LA-Studio Element Kit for Elementor 1.6.3.

PATCH SHIPPED — CVE-2026-65489 (LA-Studio Element Kit for Elementor). Fixed in LA-Studio Element Kit for Elementor 1.6.3.

PATCH SHIPPED — CVE-2026-76561 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:11.9.0-5.el10_2.

PATCH SHIPPED — CVE-2026-80110 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:11.9.0-5.el10_2.

PATCH SHIPPED — CVE-2026-84268 (GNOME gvfs). Fixed in Red Hat Enterprise Linux 10 0:1.54.4-4.el10_2.1.

PATCH SHIPPED — CVE-2026-88924 (GNOME gvfs). Fixed in Red Hat Enterprise Linux 10 0:1.54.4-4.el10_2.1.

Yesterday's Results

How to read these box scores · glossary

636 CVEs published. 25 box scores and 375 table rows below; the remaining 236 continue on page 2 — every CVE is listed, nothing truncated.

Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —   YES
AFFECTED
  Product                        Versions  Fixed
  Cisco Catalyst SD-WAN Manager  18.3.6 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Sep 30  Added to CISA KEV, due Oct 3
  Sep 30  Published (CNA: cisco)
CWE-177 · CNA: cisco · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due October 3, 2026
zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.6   .0178   77.4     —
AFFECTED
  Product      Versions  Fixed
  pi-llm-wiki  0.11.0 –  0.11.8
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
beenuar AiSOC — AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   P   H   H   H    9.4   .0146   72.6     —
AFFECTED
  Product  Versions  Fixed
  AiSOC    7.2.0 –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Deferred
HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0132   69.8     —
AFFECTED
  Product  Versions  Fixed
  AnyTool  0.1.0 –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
0xshariq github-mcp-server Git Remove MCP Tool github.ts child_process.exec os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0107   63.5     —
AFFECTED
  Product            Versions                                    Fixed
  github-mcp-server  52e764a7d66eac1726fce02ca7bb5a638571801a –  —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
productdesignerapp Product Designer App — Product Designer App <= 1.1.3 - Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0090   58.1     —
AFFECTED
  Product               Versions     Fixed
  Product Designer App  unspecified  —
TIMELINE
  Aug 17  Reserved by CNA
  Sep 30  Published (CNA: Wordfence)
CWE-22 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
jknack handlebars.java — Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0069   50.9     —
AFFECTED
  Product          Versions  Fixed
  handlebars.java  4.5.3 –   —
TIMELINE
  Sep 30  Reserved by CNA
  Sep 30  Published (CNA: mitre)
CWE-24 · CNA: mitre · CVSS v3.1 · 3 references · NVD status: Deferred
croixhaug Simply Schedule Appointments — Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0065   49.0     —
AFFECTED
  Product                       Versions     Fixed
  Simply Schedule Appointments  unspecified  —
TIMELINE
  Sep 11  Reserved by CNA
  Sep 30  Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 4 references · NVD status: Deferred
Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0061   47.1     —
AFFECTED
  Product   Versions     Fixed
  Infinity  unspecified  —
TIMELINE
  Sep 30  Reserved by CNA
  Sep 30  Published (CNA: mitre)
CWE-787 · CNA: mitre · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
DigiWin|EasyFlow .NET - Arbitrary File Upload
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0056   44.6     —
AFFECTED
  Product        Versions  Fixed
  EasyFlow .NET  6.1.* –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: twcert)
CWE-434 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Apache MINA SSHD: LDAP password authentication ineffective
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0053   42.6     —
AFFECTED
  Product           Versions  Fixed
  Apache MINA SSHD  1.2.0 –   —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-304 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Apache MINA SSHD: LDAP injection in sshd-ldap
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0053   42.6     —
AFFECTED
  Product           Versions  Fixed
  Apache MINA SSHD  1.2.0 –   —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-90, CWE-305 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
DigiWin|EasyFlow .NET - Insecure Deserialization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0051   41.2     —
AFFECTED
  Product        Versions  Fixed
  EasyFlow .NET  6.1.* –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: twcert)
CWE-502 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Apache MINA SSHD: Asynchronous authentication can bypass signature verification
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0047   37.9     —
AFFECTED
  Product           Versions  Fixed
  Apache MINA SSHD  2.0.0 –   —
TIMELINE
  Aug 20  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-305 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Apache MINA SSHD: Repeated-publickey policy bypass on server
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0046   37.3     —
AFFECTED
  Product           Versions     Fixed
  Apache MINA SSHD  unspecified  —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-304 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
PFU Limited Image Scanner Driver for Linux (fi Series) — Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in t…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   H   N   L   P   H   H   H    5.4   .0043   35.3     —
AFFECTED
  Product                                     Versions  Fixed
  Image Scanner Driver for Linux (fi Series)  2.0.0 –   —
  Image Scanner Driver for Linux (SP Series)  2.0.0 –   —
TIMELINE
  Sep 4   Reserved by CNA
  Sep 30  Published (CNA: jpcert)
CWE-78 · CNA: jpcert · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis
DigiWin|EasyFlow .NET - Missing Authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0043   34.4     —
AFFECTED
  Product        Versions  Fixed
  EasyFlow .NET  6.1.* –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: twcert)
CWE-306 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
WatchGuard Fireware OS — Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0042   34.2     —
AFFECTED
  Product      Versions  Fixed
  Fireware OS  2026.3 –  —
  Fireware OS  12.0 –    —
TIMELINE
  Sep 5   Reserved by CNA
  Sep 30  Published (CNA: WatchGuard)
CWE-476 · CNA: WatchGuard · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Apache MINA SSHD: Memory exhaustion DoS via unbounded SCP command line read
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  N  N  H    6.5   .0041   32.9     —
AFFECTED
  Product           Versions     Fixed
  Apache MINA SSHD  unspecified  —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-770 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
beenuar AiSOC — AiSOC 7.5.0 before 12.0.0 Authentication Bypass via Hard-coded JWT Secret
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   N   N    8.7   .0040   32.3     —
AFFECTED
  Product  Versions  Fixed
  AiSOC    7.5.0 –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: VulnCheck)
CWE-321 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0040   31.9     —
AFFECTED
  Product       Versions  Fixed
  Apache PLC4X  0.10.0 –  1.0.0
  Apache PLC4X  0.10.0 –  1.0.0
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-674, CWE-770, CWE-789 · CNA: apache · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
CODESYS Control RTE (SL) — Improper Synchronization in Monitoring in CODESYS Control Runtime
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0040   31.7     —
AFFECTED
  Product                           Versions   Fixed
  Control RTE (SL)                  3.0.0.0 –  —
  Control RTE (for Beckhoff CX) SL  3.0.0.0 –  —
  Control Win (SL)                  3.0.0.0 –  —
  Runtime Toolkit                   3.0.0.0 –  —
  Safety SIL2                       3.0.0.0 –  —
  HMI (SL)                          3.0.0.0 –  —
  Development System 3              3.0.0.0 –  —
  Control for BeagleBone SL         3.5.0.0 –  —
  Control for emPC-A/iMX6 SL        3.5.0.0 –  —
  Control for IOT2000 SL            3.5.0.0 –  —
  + 8 more
TIMELINE
  Aug 25  Reserved by CNA
  Sep 30  Published (CNA: CERTVDE)
CWE-362 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Deferred
MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   N    8.3   .0039   30.5     —
AFFECTED
  Product  Versions     Fixed
  MISP     unspecified  —
TIMELINE
  Sep 30  Reserved by CNA
  Sep 30  Published (CNA: CIRCL)
CWE-20, CWE-639 · CNA: CIRCL · CVSS v4.0 · 1 reference · NVD status: Deferred
Apache MINA SSHD: Memory exhaustion in SFTP client via unsolicited SFTP replies
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0039   30.1     —
AFFECTED
  Product           Versions  Fixed
  Apache MINA SSHD  0.9.0 –   —
TIMELINE
  Sep 19  Reserved by CNA
  Sep 30  Published (CNA: apache)
CWE-770 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
DigiWin|EasyFlow .NET - Arbitrary File Read
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0038   29.5     —
AFFECTED
  Product        Versions  Fixed
  EasyFlow .NET  6.1.* –   —
TIMELINE
  Sep 29  Reserved by CNA
  Sep 30  Published (CNA: twcert)
CWE-22 · CNA: twcert · CVSS v4.0 · 2 references · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1032358.727.7MISPMISPCWE-639MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitr…
CVE-2026-910516.627.2UnknownEWWW Image OptimizerCWE-502EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_pa…
CVE-2026-1028045.525.8NothingsstbCWE-189Nothings stb stb_hexwave.h hexwave_init integer overflow
CVE-2026-1028055.525.8NothingsstbCWE-189Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer ove…
CVE-2026-928678.725.5Pgpool Global Development GroupPgpool-IICWE-787An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an…
CVE-2026-940296.525.5Apache Software FoundationApache MINA SSHDCWE-770Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-han…
CVE-2026-971508.624.6baserCMS Users CommunityBcAddonMigratorCWE-829When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrat…
CVE-2026-1028432.023.7gedelumbungHospitalManagementCWE-22gedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversal
CVE-2026-1025108.723.5Apache Software FoundationApache PLC4XCWE-129Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-c…
CVE-2026-934626.923.2baserCMS User CommunitybaserCMSCWE-306A missing authentication for critical function vulnerability exists in baserC…
CVE-2026-928708.722.6Pgpool Global Development GroupPgpool-IICWE-121A stack-based buffer overflow vulnerability exists in Pgpool-II, which may al…
CVE-2026-1031028.622.6PexipInfinityCWE-770Pexip Infinity before 41.0 is affected by improper input validation in the si…
CVE-2026-1030877.122.6gosub-iogosub-engineCWE-674Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1…
CVE-2026-928736.922.0Pgpool Global Development GroupPgpool-IICWE-303Pgpool-II contains an incorrect implementation of an authentication algorithm…
CVE-2026-1030997.521.9PexipInfinityCWE-617Pexip Infinity before 41.1 is affected by improper input validation in the me…
CVE-2026-1031047.521.9PexipInfinityCWE-617Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper…
CVE-2026-1031087.521.9PexipInfinityCWE-617Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by imprope…
CVE-2026-1028455.521.7gedelumbungHospitalManagementCWE-200gedelumbung HospitalManagement HTTP Response index.php error_reporting inform…
CVE-2026-971969.120.1Liquid Web / StellarWPGiveWPCWE-1289WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
CVE-2026-928718.719.5Pgpool Global Development GroupPgpool-IICWE-476A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow…
CVE-2026-1025864.319.0—moodleCWE-79Moodle: xss via password reset link due to insufficient username escaping
CVE-2026-1028422.118.1gedelumbungHospitalManagementCWE-284gedelumbung HospitalManagement KCFinder File Manager app_user_login_model.php…
CVE-2026-68067.517.8stylemixMotors – Car Dealership & Classified Listings PluginCWE-89Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_ln…
CVE-2026-1028472.117.8gedelumbungHospitalManagementCWE-79gedelumbung HospitalManagement Guest Book buku_tamu.php kirim cross site scri…
CVE-2026-1024567.117.7DigiWinEasyFlow .NETCWE-89DigiWin|EasyFlow .NET - SQL Injection
CVE-2026-939956.517.5Apache Software FoundationApache MINA SSHDCWE-20Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write fi…
CVE-2026-1029105.517.2SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System exam-delete.php sql injection
CVE-2026-1029135.517.2SourceCodesterCar Driving School Management SystemCWE-74SourceCodester Car Driving School Management System Master.php save_enrollmen…
CVE-2026-1031018.617.1PexipInfinityCWE-770Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input va…
CVE-2026-1031007.516.3PexipInfinityCWE-617Pexip Infinity before 40.1 is affected by improper input validation in the si…
CVE-2026-1029085.516.4SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System questions-view.php sql injec…
CVE-2026-1029095.516.4SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System btn_functions.php sql injection
CVE-2026-1025774.316.4—moodleCWE-918Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass
CVE-2026-1028442.015.8gedelumbungHospitalManagementCWE-285gedelumbung HospitalManagement laporan_data_pasien.php detail authorization
CVE-2026-973477.215.3kazukiyanamotoPost Views Stats CounterCWE-79Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripti…
CVE-2026-1030575.315.2beenuarAiSOCCWE-306AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal…
CVE-2026-928697.114.8Pgpool Global Development GroupPgpool-IICWE-787An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an …
CVE-2026-966497.214.4wpshuffleFrontend Post Submission Manager Lite – Guest Post and Frontend Submission FormsCWE-79Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-B…
CVE-2026-1025785.514.5—moodleCWE-89Moodle: sql injection in question bank web service
CVE-2026-1031097.714.0PexipInfinityCWE-787Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper…
CVE-2026-107648.713.4IQSIGHTBVMSCWE-321Information disclosure in BVMS 4.5 up to 12.3
CVE-2026-1030535.313.3beenuarAiSOCCWE-306AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-…
CVE-2026-1025832.713.2—moodleCWE-425Moodle: incorrect capability check in ai generate image web service
CVE-2026-1025872.712.8—moodleCWE-204Moodle: user list filters bypass profile field visibility
CVE-2026-1025802.212.8—moodleCWE-470Moodle: arbitrary class instantiation via report builder audience classname
CVE-2026-1028462.012.2gedelumbungHospitalManagementCWE-266gedelumbung HospitalManagement Configuration sistem.php simpan improper autho…
CVE-2026-165966.511.7wpdirectorykitWP Directory KitCWE-89WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_f…
CVE-2026-1030547.111.6beenuarAiSOCCWE-639AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP
CVE-2026-758739.811.0UnknownZella ThemeCWE-434Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
CVE-2026-1025794.311.0—moodleCWE-359Moodle: user profile information disclosure via grade web service
CVE-2026-1029122.010.6SourceCodesterOnline Leave Management SystemCWE-74SourceCodester Online Leave Management System page reports sql injection
CVE-2026-1031117.69.6PCREPCRE2CWE-787PCRE2 before 10.49, when there is an attacker-controlled regular expression a…
CVE-2026-1025822.29.4—moodleCWE-425Moodle: manual enrolment page accessible when plugin disabled
CVE-2026-1024595.18.9DigiWinEasyFlow .NETCWE-79DigiWin|EasyFlow .NET - Reflected Cross-site Scripting
CVE-2026-1025844.38.4—moodleCWE-425Moodle: missing capability check allows unauthorised grade penalty recalculation
CVE-2026-1025854.38.4—moodleCWE-842Moodle: group validation missing when enrolling user to course
CVE-2026-927126.48.1rockigerReactPress – Create React App for WordPressCWE-79ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting…
CVE-2026-939086.48.1rameez_iqbalReal Estate Manager – Property Listing and Agent ManagementCWE-79Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Sc…
CVE-2025-145646.47.8ahsangaditViable URL Media UploaderCWE-79Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Sit…
CVE-2026-865565.37.5ZTEU30 AirCWE-269An information disclosure vulnerability in ZTE U30 Air product
CVE-2026-1031058.87.2PexipInfinityCWE-863Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper…
CVE-2026-928725.37.2Pgpool Global Development GroupPgpool-IICWE-532Pgpool-II inserts sensitive information into log file, which may allow an aut…
CVE-2026-935805.37.1UnknownInPost PLCWE-862InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery v…
CVE-2026-519362.16.8ZeteticSQLCipherCWE-89Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export co…
CVE-2026-835605.36.3UnknownNew User ApproveCWE-200New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier AP…
CVE-2026-1025886.56.0—moodleCWE-346Moodle: csrf in xml grade import
CVE-2026-855738.86.0UnknownAll in One Files UploadCWE-79All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stor…
CVE-2026-929948.86.0UnknownVerge3D Publishing and E-CommerceCWE-79Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
CVE-2026-891937.56.0UnknownRobin Image OptimizerCWE-79Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL…
CVE-2026-1025814.65.8—moodleCWE-79Moodle: xss in forum post templates due to insufficient escaping
CVE-2026-1025118.55.0Apache Software FoundationApache PLC4XCWE-129Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts…
CVE-2026-61706.44.1boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-61716.44.1boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-61726.44.1boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-61736.44.1boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-118956.44.1devitemsllcHT Mega Addons for Elementor – Elementor Widgets & Template BuilderCWE-79HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored C…
CVE-2026-148766.44.1nextendwebSmart Slider 3CWE-79Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-880376.44.1boldthemesBold Page BuilderCWE-79Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S…
CVE-2026-850016.83.7UnknownEmbedPressCWE-79EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showT…
CVE-2026-854156.83.7UnknownAudio Player BlockCWE-79Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download…
CVE-2026-877776.83.7UnknownHostinger ReachCWE-79Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor …
CVE-2026-924246.83.7UnknownContent EggCWE-79Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue
CVE-2026-821273.53.7UnknownSchema & Structured Data for WP & AMPCWE-79Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonom…
CVE-2026-928686.93.7Pgpool Global Development GroupPgpool-IICWE-295An improper certificate validation vulnerability exists in Pgpool-II, which m…
CVE-2026-934635.13.6baserCMS User CommunitybaserCMSCWE-79Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this…
CVE-2026-803335.33.5UnknownSolace ExtraCWE-200Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure …
CVE-2026-887913.43.4UnknownSafe Redirect ManagerCWE-601Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
CVE-2026-758237.43.3UnknownUser FrontendCWE-269WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via R…
CVE-2026-1001436.53.3UnknownFluentCart A New Era of eCommerceCWE-287FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Chec…
CVE-2026-758245.33.3UnknownUser FrontendCWE-284WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Regis…
CVE-2026-973165.83.1UnknownBroken Link NotifierCWE-918Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
CVE-2026-867895.33.2UnknownConnections Business DirectoryCWE-200Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Direct…
CVE-2026-942745.33.2UnknownYayReviewsCWE-200YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST…
CVE-2026-968865.33.2UnknownCourse Booking SystemCWE-200Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via C…
CVE-2026-1031067.82.9PexipInfinityCWE-669Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by imprope…
CVE-2026-934605.12.7baserCMS User CommunitybaserCMSCWE-79A stored cross-site scripting vulnerability via appended strings in email for…
CVE-2026-934645.12.7baserCMS User CommunitybaserCMSCWE-79A stored cross-site scripting vulnerability via custom content descriptions e…
CVE-2026-910724.42.7UnknownEWWW Image OptimizerCWE-73EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unres…
CVE-2026-909534.32.7UnknownImage OptimizerCWE-200Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Si…
CVE-2026-887977.12.3UnknownVayu XCWE-284Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and …
CVE-2026-855764.32.3UnknownAll in One Files UploadCWE-862All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plug…
CVE-2026-891904.32.3UnknownRobin Image OptimizerCWE-284Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy…
CVE-2026-942972.72.3UnknownMedia Library OrganizerCWE-862Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term …
CVE-2026-1025089.21.8Apache Software FoundationApache PLC4XCWE-295Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server ce…
CVE-2026-813105.21.6PFU LimitedImage Scanner Driver for Linux (fi Series)CWE-59Image Scanner Driver for Linux contains a link following vulnerability. An at…
CVE-2026-918327.11.0UnknownWP Mobile MenuCWE-79WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF
CVE-2026-5510710.0—elct9620kobakoCWE-94Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_m…
CVE-2026-7657010.0—joomcode.comJCTables extension for JoomlaCWE-89Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and w…
CVE-2026-9634910.0—SiteSkiteSiteSkiteCWE-94WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability
CVE-2026-10242710.0—ordasoft.comOrdaSoft Joomla CCKCWE-434Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in Or…
CVE-2026-187829.8—Trex Digital Smart Manufacturing Systems Inc.Trex MESCWE-89SQL Injection in Trex Digital Manufacturing's Trex MES
CVE-2026-554949.8—QuenarytugtainerCWE-284Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs w…
CVE-2026-823079.8—Dolusoft Software TechnologiesSOPLOGCWE-89Multiple Vulnerabilities in Dolusoft Software's SOPLOG
CVE-2026-889209.8—Apache Software FoundationApache WSS4JCWE-287Apache WSS4J: SAML Sender-Vouches Authentication Bypass
CVE-2026-963509.8—EstatikEstatikCWE-266WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability
CVE-2026-972489.8—Booking Activities TeamBooking ActivitiesCWE-502WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulner…
CVE-2026-972749.8—miniOrangeOAuth Single Sign On – SSO (OAuth Client)CWE-290WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass …
CVE-2026-1005129.8—Hook & FilterNested PagesCWE-502WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability
CVE-2026-1021159.8—KiteworksCoreCWE-640Kiteworks Core Authentication Bypass in the Password Reset Workflow
CVE-2026-551819.4—QuenarytugtainerCWE-284Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false
CVE-2026-939039.4—litespeedtechLiteSpeed Web ServerCWE-174LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect…
CVE-2026-1021499.4—KiteworksEmail Protection GatewayCWE-306Kiteworks Email Protection Gateway Improper Access Control
CVE-2026-1024899.4—Zammad GmbHZammad—Undisclosed RCE in Zammad v6.3 and higher
CVE-2026-1024909.4—Zammad GmbHZammad—Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha
CVE-2026-748649.3—YunoHost-Appssogo_yhnCWE-639Authentication Bypass in sogo_yhn
CVE-2026-968229.3—Hossni MubarakBooks GalleryCWE-89WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability
CVE-2026-1021479.3—KiteworksCoreCWE-79Kiteworks Core Administrative Account Takeover through Stored Cross-site Scri…
CVE-2026-1033959.3—ModelTCLightLLMCWE-502LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only …
CVE-2026-1034709.3—Internet2GrouperCWE-266In Internet2 Grouper before 7.5.1 (in some configurations), a user who is all…
CVE-2026-1034759.3—yii2-starter-kityii2-starter-kitCWE-489yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure
CVE-2026-194459.2—Python Software FoundationCPythonCWE-416Use-after-free of a server-side SSLContext when sni_callback switches contexts
CVE-2026-748659.2—YunoHost-Appssogo_yhnCWE-639Authentication Bypass in sogo_yhn
CVE-2026-1012769.2—esnetiperf3CWE-416iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-f…
CVE-2026-1012839.2—esnetiperf3CWE-122iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt…
CVE-2026-1029929.2—piscinajspiscinaCWE-1321piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via exec…
CVE-2026-1034739.2—denolanddenoCWE-78Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
CVE-2026-1035479.2—OpenBSDOpenBSDCWE-863In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegate…
CVE-2026-623089.1—QuenarytugtainerCWE-918Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notific…
CVE-2026-759699.1—PTZOpticsMove 4K 12XCWE-306PTZOptics Missing Authentication in Firmware Upload
CVE-2026-878309.1—Apache Software FoundationApache WSS4JCWE-917Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protect…
CVE-2026-892389.1—Apache Software FoundationApache WSS4JCWE-345Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-h…
CVE-2026-1020959.1—KiteworksEmail Protection GatewayCWE-918Kiteworks Email Protection Gateway server-side request forgery
CVE-2026-1021029.1—KiteworksEmail Protection GatewayCWE-918Kiteworks Email Protection Gateway server-side request forgery
CVE-2026-1021039.1—KiteworksEmail Protection GatewayCWE-918Kiteworks Email Protection Gateway server-side request forgery
CVE-2026-1021049.1—KiteworksEmail Protection GatewayCWE-918Kiteworks Email Protection Gateway server-side request forgery
CVE-2026-1021059.1—KiteworksEmail Protection GatewayCWE-918Kiteworks Email Protection Gateway server-side request forgery
CVE-2026-1021069.1—KiteworksEmail Protection GatewayCWE-287Kiteworks Email Protection Gateway improper authentication
CVE-2026-551769.0—Soft-Machine-iosecurityCWE-863Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SH…
CVE-2026-943899.0—AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-94WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution…
CVE-2026-1002778.9—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.19197 account takeover was possible by re…
CVE-2026-187838.8—Trex Digital Smart Manufacturing Systems Inc.Trex MESCWE-306Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manuf…
CVE-2026-940768.8—SEO SquirrlySEO Plugin by Squirrly SEOCWE-502WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection …
CVE-2026-941218.8—10Web10Web Booster – Website speed optimization, Cache & Page Speed optimizerCWE-502WordPress 10Web Booster – Website speed optimization, Cache & Page Speed opti…
CVE-2026-946788.8—Mat LipeGo Live Update UrlsCWE-502WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerab…
CVE-2026-946838.8—Justin NealeyDesignSetGoCWE-502WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability
CVE-2026-955318.8—QuantumCloudConversational Forms for ChatBotCWE-502WordPress Conversational Forms for ChatBot plugin <= 1.5.0 - PHP Object Injec…
CVE-2026-968318.8—themifymeThemify BuilderCWE-502WordPress Themify Builder plugin <= 7.8.1 - PHP Object Injection vulnerability
CVE-2026-968378.8—Brainstorm ForceCartFlowsCWE-98WordPress CartFlows plugin <= 3.2.0 - Remote Code Execution (RCE) vulnerability
CVE-2026-968388.8—YoOhw StudioBlacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout VerificationCWE-352WordPress Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; C…
CVE-2026-972918.8—Magazine3Schema & Structured Data for WP & AMPCWE-502WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object I…
CVE-2026-1002538.8—JetBrainsTeamCityCWE-184In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leadi…
CVE-2026-1002548.8—JetBrainsTeamCityCWE-78In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users …
CVE-2026-1021208.8—KiteworksCoreCWE-78Kiteworks Core OS Command Injection
CVE-2026-1021258.8—KiteworksCoreCWE-653Kiteworks Core Sandbox Escape
CVE-2026-1023778.8—10WebPhoto Gallery by 10WebCWE-502WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vuln…
CVE-2023-544028.7—iDocViewiDocViewCWE-918iDocView SSRF via /doc/upload Endpoint Hardcoded Token
CVE-2023-544038.7—YonyouU8 CRMCWE-22Yonyou U8 CRM Arbitrary File Read via getemaildata.php
CVE-2024-583878.7—InspurHaiyue HCM CloudCWE-22Inspur HCM Cloud Arbitrary File Read via file/download Endpoint
CVE-2026-470978.7—AJA Video SystemsHELO PlusCWE-321AJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export Bundle
CVE-2026-550948.7—taskclustertaskclusterCWE-20Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQ…
CVE-2026-552248.7—mineadminMineAdminCWE-22MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
CVE-2026-769928.7—CODESYSDevelopment System 3CWE-770Uncontrolled Memory Allocation in CODESYS Gateway Client
CVE-2026-1018808.7—OpenClawOpenClaw Windows NodeCWE-863OpenClaw Windows Node before 2026.7.1 Authorization Bypass
CVE-2026-1018828.7—OpenClawOpenClaw Windows NodeCWE-184OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execAp…
CVE-2026-1020928.7—KiteworksCoreCWE-79Kiteworks Core stored XSS
CVE-2026-1021008.7—KiteworksCoreCWE-79Kiteworks Core stored XSS
CVE-2026-1029938.7—py-pdfpypdfCWE-400pypdf: Possible large memory usage when retrieving Roman page labels
CVE-2026-1029948.7—py-pdfpypdfCWE-400pypdf: Possible long runtimes/large memory usage when parsing indirect objects
CVE-2026-1029958.7—py-pdfpypdfCWE-400pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
CVE-2026-1029968.7—py-pdfpypdfCWE-400pypdf: Possible large memory usage when parsing font data
CVE-2026-1029978.7—py-pdfpypdfCWE-400pypdf: Possible long runtimes for partially malformed FlateDecode streams (Fo…
CVE-2026-1029988.7—py-pdfpypdfCWE-400pypdf: Possible long runtimes when generating appearance streams
CVE-2026-1029998.7—py-pdfpypdfCWE-400pypdf: Possible long runtimes with large amount of embedded files
CVE-2026-1030008.7—py-pdfpypdfCWE-400pypdf: Possible large memory usage when retrieving alphabetical page labels
CVE-2026-1032708.7—ModelTCLightLLMCWE-306LightLLM through 1.2.0 Missing Authentication on RL Control Routes
CVE-2026-1034718.7—CorvusoftrestbedCWE-770restbed through 5.0.0 Denial of Service via Unbounded Header Buffering
CVE-2026-1034728.7—CorvusoftrestbedCWE-770restbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame Buffering
CVE-2026-1034748.7—yii2-starter-kityii2-starter-kitCWE-434yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
CVE-2026-1035918.7—AsyncFuncAIdeepwiki-openCWE-73DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via …
CVE-2026-1021218.6—KiteworksSecure Data FormsCWE-200Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthori…
CVE-2026-1032398.6—MISPMISPCWE-284MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
CVE-2026-1033988.6—Liquid-coOpenSaveCWE-73OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save…
CVE-2026-107398.5—Cato NetworksSDP ClientCWE-23Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation
CVE-2026-941158.5—FatcatappsEasy Pricing TablesCWE-89WordPress Easy Pricing Tables plugin <= 4.1.2 - SQL Injection vulnerability
CVE-2026-941778.5—Ruben GarciaGamiPressCWE-89WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability
CVE-2026-972878.5—NexcessEvent TicketsCWE-89WordPress Event Tickets plugin <= 5.29.5 - SQL Injection vulnerability
CVE-2026-972938.5—David LingrenMedia LIbrary AssistantCWE-89WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability
CVE-2026-1018858.5—zeroclaw-labsZeroClawCWE-22ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path
CVE-2026-467118.3—Soft-Machine-iosecurityCWE-306Soft Machine: Unauthenticated workspace API exposes arbitrary file read & dir…
CVE-2026-1033218.3—MISPMISPCWE-20MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image
CVE-2026-936218.2—Passionate Programmer PeterWP Data AccessCWE-89WordPress WP Data Access plugin <= 5.5.84 - SQL Injection vulnerability
CVE-2026-968178.2—MakeCommerce.netMakeCommerce for WooCommerceCWE-862WordPress MakeCommerce for WooCommerce plugin <= 4.1.0 - Broken Access Contro…
CVE-2026-1002738.2—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts…
CVE-2026-1029848.2—withastroastroCWE-248Astro: Malformed port in the Host header can crash the Node adapter
CVE-2026-1029908.2—patrickjuchlibasic-ftpCWE-1333basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directo…
CVE-2026-515688.1—n/an/a—modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write…
CVE-2026-515708.1—n/an/a—modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert…
CVE-2026-870048.1—QuenarytugtainerCWE-347Tugtainer: OIDC id_token claims accepted without signature/audience/expiry ve…
CVE-2026-1002558.1—JetBrainsTeamCityCWE-1289In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator accoun…
CVE-2026-1021018.1—KiteworksCoreCWE-502Kiteworks Core deserialization of untrusted data
CVE-2026-1021268.1—KiteworksCoreCWE-79Kiteworks Core Stored Cross-site Scripting (XSS)
CVE-2026-1034328.1—apcupsdapcupsdCWE-121apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsva…
CVE-2026-474897.8—NVIDIAGeForceCWE-281NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-474917.8—NVIDIAGeForceCWE-404NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-474937.8—NVIDIAVirtual GPU ManagerCWE-862NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GP…
CVE-2026-474947.8—NVIDIAGeForceCWE-134NVIDIA GPU Display Driver for Linux contains a vulnerability where a user mig…
CVE-2026-474957.8—NVIDIAVirtual GPU ManagerCWE-787NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerabilit…
CVE-2026-474977.8—NVIDIAVirtual GPU ManagerCWE-367NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Process…
CVE-2026-474987.8—NVIDIAVirtual GPU ManagerCWE-787NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP…
CVE-2026-474997.8—NVIDIAVirtual GPU ManagerCWE-125NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerabilit…
CVE-2026-475007.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475017.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475027.8—NVIDIAGeForceCWE-190NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerabilit…
CVE-2026-475037.8—NVIDIAVirtual GPU ManagerCWE-787NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual G…
CVE-2026-475047.8—NVIDIAGeForceCWE-843NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater w…
CVE-2026-475057.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475077.8—NVIDIAGeForceCWE-129NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475087.8—NVIDIAGeForceCWE-681NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475107.8—NVIDIAGeForceCWE-190NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475117.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475127.8—NVIDIAGeForceCWE-125NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475137.8—NVIDIAGeForceCWE-125NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475147.8—NVIDIAGeForceCWE-200NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475167.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher…
CVE-2026-475197.8—NVIDIAGuest driverCWE-125NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker…
CVE-2026-475207.8—NVIDIAGuest driverCWE-125NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker…
CVE-2026-475217.8—NVIDIAVirtual GPU ManagerCWE-125NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker…
CVE-2026-475237.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475287.8—NVIDIAGeForceCWE-824NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475307.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475357.8—NVIDIAVirtual GPU ManagerCWE-125NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the fir…
CVE-2026-475367.8—NVIDIAVirtual GPU ManagerCWE-125NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker…
CVE-2026-475407.8—NVIDIAGeForceCWE-191NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475417.8—NVIDIAVirtual GPU ManagerCWE-787NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker…
CVE-2026-475457.8—NVIDIAGeForceCWE-125NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475487.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475507.8—NVIDIAGeForceCWE-119NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475517.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475527.8—NVIDIAGeForceCWE-862NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475537.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475567.8—NVIDIAGeForceCWE-190NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475587.8—NVIDIAGeForceCWE-415NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475597.8—NVIDIAGeForceCWE-862NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475607.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475617.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475637.8—NVIDIAGeForceCWE-476NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475697.8—NVIDIAGeForceCWE-843NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475707.8—NVIDIAGeForceCWE-427NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA dr…
CVE-2026-475717.8—NVIDIAGeForceCWE-863NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode…
CVE-2026-475727.8—NVIDIAGeForceCWE-843NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475737.8—NVIDIAGeForceCWE-787NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cau…
CVE-2026-475747.8—NVIDIAVirtual GPU ManagerCWE-669NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an a…
CVE-2026-475757.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows contains a vulnerability in the display…
CVE-2026-475777.8—NVIDIAGeForceCWE-190NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475787.8—NVIDIAGeForceCWE-131NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475797.8—NVIDIAGeForceCWE-416The NVIDIA GPU Display Driver for Windows contains a vulnerability in the ker…
CVE-2026-475837.8—NVIDIAGeForceCWE-843NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475857.8—NVIDIAGeForceCWE-191NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475877.8—NVIDIARTX, Quadro, NVSCWE-416NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivi…
CVE-2026-475887.8—NVIDIARTX, Quadro, NVSCWE-416NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivi…
CVE-2026-475897.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher…
CVE-2026-475907.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher…
CVE-2026-475917.8—NVIDIAGeForceCWE-863NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475927.8—NVIDIAGeForceCWE-125NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475937.8—NVIDIAGeForceCWE-121NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-475947.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher…
CVE-2026-475957.8—NVIDIAGeForceCWE-281NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-475977.8—NVIDIAGeForceCWE-416NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-475997.8—NVIDIAGeForceCWE-281NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-sour…
CVE-2026-476007.8—NVIDIAGeForceCWE-908NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-476017.8—NVIDIAGeForceCWE-787NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-536057.8—pollen-roboticsreachy-mini-osCWE-250Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo system…
CVE-2026-621467.8—Red HatRed Hat OpenShift Container Platform 4CWE-501Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime …
CVE-2026-1002567.8—JetBrainsIntelliJ IDEACWE-829In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script c…
CVE-2026-1021127.8—KiteworksCoreCWE-78Kiteworks Core Local Privilege Escalation
CVE-2026-1021137.8—KiteworksCoreCWE-59Kiteworks Core Local Privilege Escalation
CVE-2026-1021187.8—KiteworksCoreCWE-59Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
CVE-2026-475767.7—NVIDIAGeForceCWE-125NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-1002667.7—JetBrainsHubCWE-862In JetBrains Hub before 2026.2.52366 missing authorisation allowed authentica…
CVE-2026-1002687.7—JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.2.19197 project administrators could read c…
CVE-2026-1018847.7—OpenClawOpenClaw Windows NodeCWE-184OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment O…
CVE-2026-195537.6—Python Software FoundationCPythonCWE-297SSLContext.wrap_bio() missing validation of server_hostname parameter
CVE-2026-551777.6—dfpc-coeCloudTAKCWE-918CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled…
CVE-2026-620857.6—MelapressWP Activity LogCWE-89WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability
CVE-2026-620977.6—WPTastyBusiness DirectoryCWE-89WordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerability
CVE-2026-940827.6—FatcatappsQuiz CatCWE-89WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability
CVE-2026-963457.6—EstatikEstatikCWE-89WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability
CVE-2026-963467.6—weDevsWP ERPCWE-89WordPress WP ERP plugin <= 1.17.9 - SQL Injection vulnerability
CVE-2026-968277.6—MelapressAdmin Notices ManagerCWE-89WordPress Admin Notices Manager plugin <= 1.6.0 - SQL Injection vulnerability
CVE-2026-968287.6—VidishCategory Discount WoocommerceCWE-89WordPress Category Discount Woocommerce plugin <= 5.18 - SQL Injection vulner…
CVE-2026-1002627.6—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users…
CVE-2026-855327.5—Apache Software FoundationApache WSS4JCWE-20Apache WSS4J: Insufficient Validation of Derived-Key Parameters
CVE-2026-921217.5—Apache Software FoundationApache WSS4JCWE-693Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming cod…
CVE-2026-941207.5—GravityKitGravityExport Lite for Gravity FormsCWE-862WordPress GravityExport Lite for Gravity Forms plugin <= 2.7.2 - Broken Acces…
CVE-2026-941237.5—Syed BalkhiNextGEN GalleryCWE-22WordPress NextGEN Gallery plugin <= 4.5.0 - Arbitrary File Download vulnerabi…
CVE-2026-941787.5—Javier CarazoImport and export users and customersCWE-266WordPress Import and export users and customers plugin <= 2.5.2 - Privilege E…
CVE-2026-955877.5—HostingerHostinger MigratorCWE-862WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability
CVE-2026-956167.5—Apache Software FoundationApache WSS4JCWE-190Apache WSS4J: Unauthenticated denial of service via integer overflow in DER p…
CVE-2026-963487.5—BooklyBooklyCWE-862WordPress Bookly plugin <= 28.2 - Broken Access Control vulnerability
CVE-2026-968187.5—mra13 / Team Tips and Tricks HQWP Express Checkout (Accept PayPal Payments)CWE-862WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Brok…
CVE-2026-968237.5—CusRevCustomer Reviews for WooCommerceCWE-862WordPress Customer Reviews for WooCommerce plugin <= 5.120.0 - Arbitrary Cont…
CVE-2026-971977.5—WebToffeeWordPress Backup & MigrationCWE-862WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Contro…
CVE-2026-972407.5—EstebanStifLi Backup ToolsCWE-201WordPress StifLi Backup Tools plugin <= 2.2.7 - Sensitive Data Exposure vulne…
CVE-2026-972417.5—PrecisionWPBackupEaseCWE-201WordPress BackupEase plugin <= 2.2.2 - Sensitive Data Exposure vulnerability
CVE-2026-972447.5—WPFunnelsCreator LMSCWE-35WordPress Creator LMS plugin <= 1.2.19 - Path Traversal vulnerability
CVE-2026-1020917.5—KiteworksSecure Data FormsCWE-918Kiteworks Secure Data Forms server-side request forgery
CVE-2026-1021287.5—KiteworksEmail Protection GatewayCWE-287Kiteworks Email Protection Gateway Improper Authentication
CVE-2026-1021437.5—KiteworksEmail Protection GatewayCWE-306Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous…
CVE-2026-1027177.5—Eclipse FoundationNetX DuoCWE-125MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash
CVE-2026-1021237.4—KiteworksCoreCWE-22Kiteworks Core Path Traversal
CVE-2026-1034467.4—The Wikimedia FoundationMediaWiki WikiLambda extensionCWE-639WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments
CVE-2026-474967.3—NVIDIAVirtual GPU ManagerCWE-787NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual G…
CVE-2026-475807.3—NVIDIAGeForceCWE-862NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel …
CVE-2026-1012957.3—Red HatAssisted Installer for Red Hat OpenShift Container Platform 2CWE-22Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catal…
CVE-2026-936247.2—codepeopleMusic Player for WooCommerceCWE-502WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection…
CVE-2026-936517.2—DotstoreMinimum and Maximum Quantity for WooCommerceCWE-502WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.1.2 - PHP …
CVE-2026-937717.2—WPFactoryCost of Goods for WooCommerceCWE-502WordPress Cost of Goods for WooCommerce plugin <= 3.5.2 - PHP Object Injectio…
CVE-2026-941227.2—A WP LifeResponsive Slider GalleryCWE-502WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vu…
CVE-2026-946777.2—NexcessKadence WooCommerce Email DesignerCWE-502WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object …
CVE-2026-963437.2—weDevsWP ERPCWE-502WordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerability
CVE-2026-963447.2—impleCodeeCommerce Product CatalogCWE-502WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vu…
CVE-2026-968157.2—appsbdViteposCWE-266WordPress Vitepos plugin <= 3.5.0 - Privilege Escalation vulnerability
CVE-2026-968327.2—keywordrushContent EggCWE-502WordPress Content Egg plugin <= 6.3.1 - PHP Object Injection vulnerability
CVE-2026-968337.2—ThemeficUltimate Addons for Contact Form 7CWE-502WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.51 - PHP Object In…
CVE-2026-972457.2—SureCartSureCartCWE-266WordPress SureCart plugin <= 4.7.2 - Privilege Escalation vulnerability
CVE-2026-972567.2—Greg – SiteOriginPage Builder by SiteOriginCWE-502WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection …
CVE-2026-1020897.2—KiteworksEmail Protection GatewayCWE-22Kiteworks Email Protection Gateway path traversal
CVE-2026-1020937.2—KiteworksCoreCWE-269Kiteworks Core improper privilege management
CVE-2026-1020947.2—KiteworksEmail Protection GatewayCWE-470Kiteworks Email Protection Gateway unsafe reflection
CVE-2026-1020967.2—KiteworksCoreCWE-78Kiteworks Core OS command injection
CVE-2026-1020977.2—KiteworksEmail Protection GatewayCWE-22Kiteworks Email Protection Gateway remote code execution
CVE-2026-1020987.2—KiteworksCoreCWE-89Kiteworks Core SQL Injection
CVE-2026-1020997.2—KiteworksCoreCWE-22Kiteworks Core arbitrary file write
CVE-2026-1021087.2—KiteworksEmail Protection GatewayCWE-502Kiteworks Email Protection Gateway deserialization of untrusted data
CVE-2026-1021147.2—KiteworksCoreCWE-78Kiteworks Core OS Command Injection
CVE-2026-1021167.2—KiteworksEmail Protection GatewayCWE-22Kiteworks Email Protection Gateway Path Traversal
CVE-2026-1021177.2—KiteworksCoreCWE-807Kiteworks Core Remote Code Execution
CVE-2026-1021197.2—KiteworksEmail Protection GatewayCWE-22Kiteworks Email Protection Gateway Path Traversal
CVE-2026-1021297.2—KiteworksCoreCWE-266Kiteworks Core Incorrect Privilege Assignment
CVE-2026-1021307.2—KiteworksEmail Protection GatewayCWE-94Kiteworks Email Protection Gateway Remote Code Execution
CVE-2026-1021317.2—KiteworksEmail Protection GatewayCWE-94Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity
CVE-2026-1021327.2—KiteworksCoreCWE-284Kiteworks Core Privilege Escalation through Improper Access Control
CVE-2026-1021427.2—KiteworksCoreCWE-1336Kiteworks Core Remote Code Execution through Server-Side Template Injection
CVE-2026-1021507.2—KiteworksSecure Data FormsCWE-306Kiteworks Secure Data Forms Missing Authentication for Critical Function
CVE-2026-1023927.2—ThemeHighExtra Product Options For WooCommerce | Custom Product Addons and FieldsCWE-502WordPress Extra Product Options For WooCommerce | Custom Product Addons and F…
CVE-2026-1034417.2—The Wikimedia FoundationMediaWiki Wikibase extensionCWE-502Unauthenticated arbitrary file deletion through Wikibase serialized entity pa…
CVE-2026-1034427.2—The Wikimedia FoundationMediaWiki CentralAuth extensionCWE-15MergeAccount PHP object injection via session-key substitution
CVE-2026-273717.1—WPFunnelsWPFunnelsCWE-79WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) v…
CVE-2026-475547.1—NVIDIAGeForceCWE-347NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo…
CVE-2026-476027.1—NVIDIAGeForceCWE-119NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t…
CVE-2026-935127.1—ilGheraJW Player for WordPressCWE-79WordPress JW Player for WordPress plugin <= 2.3.11 - Cross Site Scripting (XS…
CVE-2026-935147.1—rainafaraiNotification for TelegramCWE-79WordPress Notification for Telegram plugin <= 3.5.2 - Cross Site Scripting (X…
CVE-2026-937707.1—VeronaLabsWP StatisticsCWE-79WordPress WP Statistics plugin <= 14.16.13 - Cross Site Scripting (XSS) vulne…
CVE-2026-940787.1—Gemini LabsSite ReviewsCWE-79WordPress Site Reviews plugin <= 8.3.1 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-940817.1—lukeseagerWordPress Persistent LoginCWE-79WordPress WordPress Persistent Login plugin <= 3.1.3 - Cross Site Scripting (…
CVE-2026-941717.1—VillaThemeCURCYCWE-79WordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerability
CVE-2026-944997.1—wpWaxFormGentCWE-862WordPress FormGent plugin <= 1.12.2 - Broken Access Control vulnerability
CVE-2026-963517.1—RadiusThemeClassified ListingCWE-79WordPress Classified Listing plugin <= 6.1.3 - Cross Site Scripting (XSS) vul…
CVE-2026-963527.1—YITHEMESYITH WooCommerce Ajax SearchCWE-79WordPress YITH WooCommerce Ajax Search plugin <= 2.28.0 - Cross Site Scriptin…
CVE-2026-968147.1—WP Titan LabsWooCommerce Product Table LiteCWE-79WordPress WooCommerce Product Table Lite plugin <= 5.6.7 - Cross Site Scripti…
CVE-2026-968167.1—vendideroTrusted Shops Easy Integration for WooCommerceCWE-79WordPress Trusted Shops Easy Integration for WooCommerce plugin <= 2.0.6 - Cr…
CVE-2026-968197.1—bobbingwideoikCWE-79WordPress oik plugin <= 4.15.4 - Cross Site Scripting (XSS) vulnerability
CVE-2026-968207.1—awesomesupportAwesome SupportCWE-79WordPress Awesome Support plugin <= 6.3.9 - Cross Site Scripting (XSS) vulner…
CVE-2026-968307.1—NexcessGiveWPCWE-79WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability
CVE-2026-968367.1—Morteza GeransayehParsi DateCWE-79WordPress Parsi Date plugin <= 6.3 - Cross Site Scripting (XSS) vulnerability

Results continue: ranks 401–636.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-30 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.