AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 — — YES
AFFECTED Product Versions Fixed Cisco Catalyst SD-WAN Manager 18.3.6 – —
TIMELINE Aug 19 Reserved by CNA Sep 30 Added to CISA KEV, due Oct 3 Sep 30 Published (CNA: cisco)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 1 to KEV; 636 CVEs published, led by NVIDIA (114).
636 CVEs published September 30, 2026: 54 critical, 296 high, 226 medium, 40 low; 1 in the KEV catalog at press time; 0 with a public exploit reference; 20 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 236 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 14941 | 49932 | — | — |
| KEV catalog size | 1730 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3225 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 2115 | 6205 | 530 | 2638 | 713 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | +472 ▲ |
| microsoft | 1002 | 2901 | 201 | 1992 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | +525 ▲ |
| 662 | 2831 | 355 | 1095 | 1241 | 131 | 80 | 9 | 0.3 | 7.5 | .0027 | +260 ▲ | |
| red hat | 264 | 898 | 51 | 379 | 415 | 53 | 2 | 0 | 0.0 | 6.7 | .0035 | +42 ▲ |
| apple | 247 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | +203 ▲ |
| suse | 25 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | +18 ▲ |
| canonical | 8 | 50 | 16 | 12 | 17 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | -7 ▼ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | -32 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 98 | 182 | 54 | 72 | 55 | 1 | 60 | 17 | 9.3 | 7.8 | .0046 | +52 ▲ |
| ubiquiti | 6 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | -17 ▼ |
| palo alto networks | 9 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | -3 ▼ |
| fortinet | 11 | 41 | 11 | 10 | 17 | 3 | 29 | 7 | 17.1 | 7.2 | .0040 | +4 ▲ |
| netgear | 2 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | -7 ▼ |
| f5 | 9 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | +9 ▲ |
| ivanti | 10 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | +7 ▲ |
| sonicwall | 5 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -7 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 195 | 707 | 158 | 297 | 229 | 16 | 33 | 2 | 0.3 | 7.5 | .0062 | +37 ▲ |
| mozilla | 191 | 379 | 112 | 160 | 84 | 0 | 9 | 0 | 0.0 | 8.8 | .0030 | +132 ▲ |
| gitlab | 28 | 104 | 7 | 24 | 62 | 11 | 5 | 3 | 2.9 | 5.3 | .0034 | +3 ▲ |
| drupal | 26 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | +9 ▲ |
| github | 6 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | +1 ▲ |
| docker | 3 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | +1 ▲ |
| wordpress | 1 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0392 | -1 ▼ |
| kubernetes | 1 | 2 | 0 | 0 | 1 | 1 | 0 | 0 | 0.0 | 4.5 | .0028 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 634 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | -256 ▼ |
| ibm | 404 | 1023 | 196 | 473 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | +14 ▲ |
| adobe | 224 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | +123 ▲ |
| progress | 5 | 66 | 15 | 40 | 11 | 0 | 6 | 1 | 1.5 | 8.1 | .0046 | -14 ▼ |
| zohocorp | 32 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | +28 ▲ |
| solarwinds | 3 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | +3 ▲ |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | -13 ▼ |
| servicenow | 5 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 29 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | +10 ▲ |
| siemens | 15 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -6 ▼ |
| synology | 19 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | +15 ▲ |
| rockwell automation | 18 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | +17 ▲ |
| advantech | 17 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | +17 ▲ |
| schneider electric | 9 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | +9 ▲ |
| hitachi energy | 9 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0025 | +9 ▲ |
| abb | 4 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | +4 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 207 | 378 | 31 | 172 | 151 | 24 | 2 | 1 | 0.3 | 7.2 | .0027 | +136 ▲ |
| nvidia | 167 | 301 | 25 | 206 | 70 | 0 | 0 | 0 | 0.0 | 7.8 | .0040 | +115 ▲ |
| sourcecodester | 68 | 237 | 0 | 0 | 142 | 95 | 0 | 0 | 0.0 | 5.5 | .0042 | +19 ▲ |
| openclaw | 90 | 223 | 4 | 114 | 84 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | +90 ▲ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | -91 ▼ |
| mongodb | 71 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | +16 ▲ |
| hewlett packard enterprise (hpe) | 157 | 166 | 22 | 80 | 55 | 9 | 1 | 1 | 0.6 | 7.2 | .0042 | +154 ▲ |
| itsourcecode | 37 | 153 | 0 | 0 | 37 | 116 | 0 | 0 | 0.0 | 2.1 | .0033 | 0 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9143 | 99.8 | 10.0 |
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-87902 | .1976 | 97.3 | 8.1 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.4 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-83549 | .1076 | 95.7 | 7.8 |
| CVE-2026-83548 | .0876 | 95.0 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9143 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-83548 | 10.0 | .0876 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2115 |
| microsoft | 1002 |
| 662 | |
| oracle | 634 |
| ibm | 404 |
| red hat | 264 |
| apple | 247 |
| adobe | 224 |
| dell | 207 |
| apache | 195 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 17 |
| apple | 9 |
| 9 | |
| fortinet | 7 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 113 |
| npm | 19 |
| Packagist | 18 |
| PyPI | 15 |
| crates.io | 9 |
| Go | 4 |
| RubyGems | 2 |
| NuGet | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-83548 | SonicWall | 0 |
| CVE-2026-83549 | SonicWall | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1778 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1778 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1778 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1778 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1778 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1778 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1778 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1778 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1778 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1778 |
ADDED TO KEV — CVE-2026-76504 (Cisco Catalyst SD-WAN Manager). Remediation due October 3, 2026.
EXPLOIT PUBLISHED — Google Chrome: 11 CVEs (CVE-2026-95276, CVE-2026-95282, CVE-2026-95287, CVE-2026-95289, CVE-2026-95298, CVE-2026-95345, CVE-2026-95346, CVE-2026-95350, CVE-2026-95357, CVE-2026-95359, CVE-2026-95371). Public exploit references added.
EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.
EXPLOIT PUBLISHED — Project-MONAI MONAI: 6 CVEs (CVE-2026-100840, CVE-2026-100842, CVE-2026-100843, CVE-2026-100844, CVE-2026-100845, CVE-2026-100846). Public exploit references added.
EXPLOIT PUBLISHED — grokability snipe-it: 4 CVEs (CVE-2026-49976, CVE-2026-55694, CVE-2026-55703, CVE-2026-61807). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2016-20097 (Weaver Network Co., Ltd. E-cology 8.0). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2022-50997 (Weaver Network Co., Ltd. E-cology 9.0). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-15612 (Wazuh Provisioning Scripts (Agent Build Environment)). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-50343. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100306 (TDuckCloud tduck-survey-form). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100744 (coollabsio Coolify). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100873 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100876 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100879 (zhistaredu StarTraining). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100882 (Krayin laravel-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100885 (Krayin laravel-crm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100888 (Trusted Domain Project OpenDKIM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102621 (Freedesktop Poppler). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102771 (Naichen ThinkCMF). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 8). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59090 (gimp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-59095 (lobehub). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76208 (thorsten phpMyFAQ). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-76844 (zlib). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-80428 (ILIAS-eLearning e.V. ILIAS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94214 (ST Engineering iDirect Evolution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-94216 (ST Engineering iDirect Evolution). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97064 (yzcheng90 X-SpringBoot). Public exploit reference added.
REJECTED — CVE-2017-20051 (InnoSetup Installer). Record withdrawn by the CNA.
REJECTED — CVE-2025-68195 (Linux). Record withdrawn by the CNA.
REJECTED — CVE-2026-13087 (Red Hat Enterprise Linux 10). Record withdrawn by the CNA.
REJECTED — CVE-2026-94684 (oceanwp Ocean Extra). Record withdrawn by the CNA.
RESCORED — CVE-2023-39417 (Red Hat Advanced Cluster Security 4.2). CVSS 7.5 → 8.8 (NVD).
RESCORED — CVE-2025-21042 (Samsung Mobile Devices). CVSS 8.8 → 9.8 (NVD).
RESCORED — CVE-2025-53844 (Fortinet FortiOS). CVSS 8.3 → 8.8 (NVD).
RESCORED — CVE-2025-66376 (Zimbra Collaboration). CVSS 7.2 → 6.1 (NVD).
RESCORED — CVE-2026-102793 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).
RESCORED — CVE-2026-102794 (Ziroom ZHOME A0101). CVSS 9.4 → 8.5 (NVD).
RESCORED — CVE-2026-10841 (IBM CICS TX Advanced). CVSS 4.2 → 4.8 (NVD).
RESCORED — CVE-2026-42169 (Red Hat Enterprise Linux 9). CVSS 7.3 → 7.8 (NVD).
RESCORED — CVE-2026-50550 (grokability snipe-it). CVSS 5.8 → 6.3 (NVD).
RESCORED — CVE-2026-59328 (Spring Tools for Eclipse). CVSS 4.2 → 5.4 (NVD).
RESCORED — CVE-2026-6384 (Red Hat Enterprise Linux 6). CVSS 7.3 → 7.8 (NVD).
RESCORED — CVE-2026-81352 (Microsoft Web Media Extensions). CVSS 9.8 → 8.8 (NVD).
RESCORED — CVE-2026-86105 (WatchGuard Fireware OS). CVSS 5.3 → 6 (NVD).
RESCORED — CVE-2026-93353 (9001 copyparty). CVSS 6 → 2.3 (NVD).
PATCH SHIPPED — CVE-2026-65488 (LA-Studio Element Kit for Elementor). Fixed in LA-Studio Element Kit for Elementor 1.6.3.
PATCH SHIPPED — CVE-2026-65489 (LA-Studio Element Kit for Elementor). Fixed in LA-Studio Element Kit for Elementor 1.6.3.
PATCH SHIPPED — CVE-2026-76561 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:11.9.0-5.el10_2.
PATCH SHIPPED — CVE-2026-80110 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:11.9.0-5.el10_2.
PATCH SHIPPED — CVE-2026-84268 (GNOME gvfs). Fixed in Red Hat Enterprise Linux 10 0:1.54.4-4.el10_2.1.
PATCH SHIPPED — CVE-2026-88924 (GNOME gvfs). Fixed in Red Hat Enterprise Linux 10 0:1.54.4-4.el10_2.1.
How to read these box scores · glossary
636 CVEs published. 25 box scores and 375 table rows below; the remaining 236 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 — — YES
AFFECTED Product Versions Fixed Cisco Catalyst SD-WAN Manager 18.3.6 – —
TIMELINE Aug 19 Reserved by CNA Sep 30 Added to CISA KEV, due Oct 3 Sep 30 Published (CNA: cisco)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H H H 8.6 .0178 77.4 —
AFFECTED Product Versions Fixed pi-llm-wiki 0.11.0 – 0.11.8
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L P H H H 9.4 .0146 72.6 —
AFFECTED Product Versions Fixed AiSOC 7.2.0 – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0132 69.8 —
AFFECTED Product Versions Fixed AnyTool 0.1.0 – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0107 63.5 —
AFFECTED Product Versions Fixed github-mcp-server 52e764a7d66eac1726fce02ca7bb5a638571801a – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0090 58.1 —
AFFECTED Product Versions Fixed Product Designer App unspecified —
TIMELINE Aug 17 Reserved by CNA Sep 30 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0069 50.9 —
AFFECTED Product Versions Fixed handlebars.java 4.5.3 – —
TIMELINE Sep 30 Reserved by CNA Sep 30 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0065 49.0 —
AFFECTED Product Versions Fixed Simply Schedule Appointments unspecified —
TIMELINE Sep 11 Reserved by CNA Sep 30 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0061 47.1 —
AFFECTED Product Versions Fixed Infinity unspecified —
TIMELINE Sep 30 Reserved by CNA Sep 30 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 8.6 .0056 44.6 —
AFFECTED Product Versions Fixed EasyFlow .NET 6.1.* – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0053 42.6 —
AFFECTED Product Versions Fixed Apache MINA SSHD 1.2.0 – —
TIMELINE Sep 19 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0053 42.6 —
AFFECTED Product Versions Fixed Apache MINA SSHD 1.2.0 – —
TIMELINE Sep 19 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0051 41.2 —
AFFECTED Product Versions Fixed EasyFlow .NET 6.1.* – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: twcert)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0047 37.9 —
AFFECTED Product Versions Fixed Apache MINA SSHD 2.0.0 – —
TIMELINE Aug 20 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0046 37.3 —
AFFECTED Product Versions Fixed Apache MINA SSHD unspecified —
TIMELINE Sep 19 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L H N L P H H H 5.4 .0043 35.3 —
AFFECTED Product Versions Fixed Image Scanner Driver for Linux (fi Series) 2.0.0 – — Image Scanner Driver for Linux (SP Series) 2.0.0 – —
TIMELINE Sep 4 Reserved by CNA Sep 30 Published (CNA: jpcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0043 34.4 —
AFFECTED Product Versions Fixed EasyFlow .NET 6.1.* – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: twcert)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0042 34.2 —
AFFECTED Product Versions Fixed Fireware OS 2026.3 – — Fireware OS 12.0 – —
TIMELINE Sep 5 Reserved by CNA Sep 30 Published (CNA: WatchGuard)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N N H 6.5 .0041 32.9 —
AFFECTED Product Versions Fixed Apache MINA SSHD unspecified —
TIMELINE Sep 19 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H N N 8.7 .0040 32.3 —
AFFECTED Product Versions Fixed AiSOC 7.5.0 – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0040 31.9 —
AFFECTED Product Versions Fixed Apache PLC4X 0.10.0 – 1.0.0 Apache PLC4X 0.10.0 – 1.0.0
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0040 31.7 —
AFFECTED Product Versions Fixed Control RTE (SL) 3.0.0.0 – — Control RTE (for Beckhoff CX) SL 3.0.0.0 – — Control Win (SL) 3.0.0.0 – — Runtime Toolkit 3.0.0.0 – — Safety SIL2 3.0.0.0 – — HMI (SL) 3.0.0.0 – — Development System 3 3.0.0.0 – — Control for BeagleBone SL 3.5.0.0 – — Control for emPC-A/iMX6 SL 3.5.0.0 – — Control for IOT2000 SL 3.5.0.0 – — + 8 more
TIMELINE Aug 25 Reserved by CNA Sep 30 Published (CNA: CERTVDE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H N 8.3 .0039 30.5 —
AFFECTED Product Versions Fixed MISP unspecified —
TIMELINE Sep 30 Reserved by CNA Sep 30 Published (CNA: CIRCL)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0039 30.1 —
AFFECTED Product Versions Fixed Apache MINA SSHD 0.9.0 – —
TIMELINE Sep 19 Reserved by CNA Sep 30 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N H N N 7.1 .0038 29.5 —
AFFECTED Product Versions Fixed EasyFlow .NET 6.1.* – —
TIMELINE Sep 29 Reserved by CNA Sep 30 Published (CNA: twcert)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-103235 | 8.7 | 27.7 | MISP | MISP | CWE-639 | MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitr… |
| CVE-2026-91051 | 6.6 | 27.2 | Unknown | EWWW Image Optimizer | CWE-502 | EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_pa… |
| CVE-2026-102804 | 5.5 | 25.8 | Nothings | stb | CWE-189 | Nothings stb stb_hexwave.h hexwave_init integer overflow |
| CVE-2026-102805 | 5.5 | 25.8 | Nothings | stb | CWE-189 | Nothings stb Image Encoding stb_image_write.h stbi_write_tga_core integer ove… |
| CVE-2026-92867 | 8.7 | 25.5 | Pgpool Global Development Group | Pgpool-II | CWE-787 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an… |
| CVE-2026-94029 | 6.5 | 25.5 | Apache Software Foundation | Apache MINA SSHD | CWE-770 | Apache MINA SSHD: Memory exhaustion in SFTP v6 check-file-name/check-file-han… |
| CVE-2026-97150 | 8.6 | 24.6 | baserCMS Users Community | BcAddonMigrator | CWE-829 | When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrat… |
| CVE-2026-102843 | 2.0 | 23.7 | gedelumbung | HospitalManagement | CWE-22 | gedelumbung HospitalManagement Endpoint data_galeri.php hapus path traversal |
| CVE-2026-102510 | 8.7 | 23.5 | Apache Software Foundation | Apache PLC4X | CWE-129 | Apache PLC4X: Go binding: unbounded allocation and framing failures on wire-c… |
| CVE-2026-93462 | 6.9 | 23.2 | baserCMS User Community | baserCMS | CWE-306 | A missing authentication for critical function vulnerability exists in baserC… |
| CVE-2026-92870 | 8.7 | 22.6 | Pgpool Global Development Group | Pgpool-II | CWE-121 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may al… |
| CVE-2026-103102 | 8.6 | 22.6 | Pexip | Infinity | CWE-770 | Pexip Infinity before 41.0 is affected by improper input validation in the si… |
| CVE-2026-103087 | 7.1 | 22.6 | gosub-io | gosub-engine | CWE-674 | Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1… |
| CVE-2026-92873 | 6.9 | 22.0 | Pgpool Global Development Group | Pgpool-II | CWE-303 | Pgpool-II contains an incorrect implementation of an authentication algorithm… |
| CVE-2026-103099 | 7.5 | 21.9 | Pexip | Infinity | CWE-617 | Pexip Infinity before 41.1 is affected by improper input validation in the me… |
| CVE-2026-103104 | 7.5 | 21.9 | Pexip | Infinity | CWE-617 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper… |
| CVE-2026-103108 | 7.5 | 21.9 | Pexip | Infinity | CWE-617 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by imprope… |
| CVE-2026-102845 | 5.5 | 21.7 | gedelumbung | HospitalManagement | CWE-200 | gedelumbung HospitalManagement HTTP Response index.php error_reporting inform… |
| CVE-2026-97196 | 9.1 | 20.1 | Liquid Web / StellarWP | GiveWP | CWE-1289 | WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability |
| CVE-2026-92871 | 8.7 | 19.5 | Pgpool Global Development Group | Pgpool-II | CWE-476 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow… |
| CVE-2026-102586 | 4.3 | 19.0 | — | moodle | CWE-79 | Moodle: xss via password reset link due to insufficient username escaping |
| CVE-2026-102842 | 2.1 | 18.1 | gedelumbung | HospitalManagement | CWE-284 | gedelumbung HospitalManagement KCFinder File Manager app_user_login_model.php… |
| CVE-2026-6806 | 7.5 | 17.8 | stylemix | Motors – Car Dealership & Classified Listings Plugin | CWE-89 | Motors <= 1.4.109 - Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_ln… |
| CVE-2026-102847 | 2.1 | 17.8 | gedelumbung | HospitalManagement | CWE-79 | gedelumbung HospitalManagement Guest Book buku_tamu.php kirim cross site scri… |
| CVE-2026-102456 | 7.1 | 17.7 | DigiWin | EasyFlow .NET | CWE-89 | DigiWin|EasyFlow .NET - SQL Injection |
| CVE-2026-93995 | 6.5 | 17.5 | Apache Software Foundation | Apache MINA SSHD | CWE-20 | Apache MINA SSHD: Remote execution of JGit "archive -o=file.zip" can write fi… |
| CVE-2026-102910 | 5.5 | 17.2 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System exam-delete.php sql injection |
| CVE-2026-102913 | 5.5 | 17.2 | SourceCodester | Car Driving School Management System | CWE-74 | SourceCodester Car Driving School Management System Master.php save_enrollmen… |
| CVE-2026-103101 | 8.6 | 17.1 | Pexip | Infinity | CWE-770 | Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input va… |
| CVE-2026-103100 | 7.5 | 16.3 | Pexip | Infinity | CWE-617 | Pexip Infinity before 40.1 is affected by improper input validation in the si… |
| CVE-2026-102908 | 5.5 | 16.4 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System questions-view.php sql injec… |
| CVE-2026-102909 | 5.5 | 16.4 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System btn_functions.php sql injection |
| CVE-2026-102577 | 4.3 | 16.4 | — | moodle | CWE-918 | Moodle: ssrf risk in url downloader via ipv4-mapped ipv6 address bypass |
| CVE-2026-102844 | 2.0 | 15.8 | gedelumbung | HospitalManagement | CWE-285 | gedelumbung HospitalManagement laporan_data_pasien.php detail authorization |
| CVE-2026-97347 | 7.2 | 15.3 | kazukiyanamoto | Post Views Stats Counter | CWE-79 | Post Views Stats Counter <= 1.1.7 - Unauthenticated Stored Cross-Site Scripti… |
| CVE-2026-103057 | 5.3 | 15.2 | beenuar | AiSOC | CWE-306 | AiSOC 5.1.0 before 12.0.0 Missing Authentication on Realtime Service Internal… |
| CVE-2026-92869 | 7.1 | 14.8 | Pgpool Global Development Group | Pgpool-II | CWE-787 | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an … |
| CVE-2026-96649 | 7.2 | 14.4 | wpshuffle | Frontend Post Submission Manager Lite – Guest Post and Frontend Submission Forms | CWE-79 | Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-B… |
| CVE-2026-102578 | 5.5 | 14.5 | — | moodle | CWE-89 | Moodle: sql injection in question bank web service |
| CVE-2026-103109 | 7.7 | 14.0 | Pexip | Infinity | CWE-787 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper… |
| CVE-2026-10764 | 8.7 | 13.4 | IQSIGHT | BVMS | CWE-321 | Information disclosure in BVMS 4.5 up to 12.3 |
| CVE-2026-103053 | 5.3 | 13.3 | beenuar | AiSOC | CWE-306 | AiSOC 9.0.0 before 12.0.0 Missing Authentication on Actions Service Response-… |
| CVE-2026-102583 | 2.7 | 13.2 | — | moodle | CWE-425 | Moodle: incorrect capability check in ai generate image web service |
| CVE-2026-102587 | 2.7 | 12.8 | — | moodle | CWE-204 | Moodle: user list filters bypass profile field visibility |
| CVE-2026-102580 | 2.2 | 12.8 | — | moodle | CWE-470 | Moodle: arbitrary class instantiation via report builder audience classname |
| CVE-2026-102846 | 2.0 | 12.2 | gedelumbung | HospitalManagement | CWE-266 | gedelumbung HospitalManagement Configuration sistem.php simpan improper autho… |
| CVE-2026-16596 | 6.5 | 11.7 | wpdirectorykit | WP Directory Kit | CWE-89 | WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_f… |
| CVE-2026-103054 | 7.1 | 11.6 | beenuar | AiSOC | CWE-639 | AiSOC 10.0.0 before 12.0.0 Unauthorized Tenant Access via MSSP |
| CVE-2026-75873 | 9.8 | 11.0 | Unknown | Zella Theme | CWE-434 | Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload |
| CVE-2026-102579 | 4.3 | 11.0 | — | moodle | CWE-359 | Moodle: user profile information disclosure via grade web service |
| CVE-2026-102912 | 2.0 | 10.6 | SourceCodester | Online Leave Management System | CWE-74 | SourceCodester Online Leave Management System page reports sql injection |
| CVE-2026-103111 | 7.6 | 9.6 | PCRE | PCRE2 | CWE-787 | PCRE2 before 10.49, when there is an attacker-controlled regular expression a… |
| CVE-2026-102582 | 2.2 | 9.4 | — | moodle | CWE-425 | Moodle: manual enrolment page accessible when plugin disabled |
| CVE-2026-102459 | 5.1 | 8.9 | DigiWin | EasyFlow .NET | CWE-79 | DigiWin|EasyFlow .NET - Reflected Cross-site Scripting |
| CVE-2026-102584 | 4.3 | 8.4 | — | moodle | CWE-425 | Moodle: missing capability check allows unauthorised grade penalty recalculation |
| CVE-2026-102585 | 4.3 | 8.4 | — | moodle | CWE-842 | Moodle: group validation missing when enrolling user to course |
| CVE-2026-92712 | 6.4 | 8.1 | rockiger | ReactPress – Create React App for WordPress | CWE-79 | ReactPress <= 3.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting… |
| CVE-2026-93908 | 6.4 | 8.1 | rameez_iqbal | Real Estate Manager – Property Listing and Agent Management | CWE-79 | Real Estate Manager <= 7.3 - Authenticated (Subscriber+) Stored Cross-Site Sc… |
| CVE-2025-14564 | 6.4 | 7.8 | ahsangadit | Viable URL Media Uploader | CWE-79 | Viable URL Media Uploader <= 1.0.0 - Authenticated (Author+) Stored Cross-Sit… |
| CVE-2026-86556 | 5.3 | 7.5 | ZTE | U30 Air | CWE-269 | An information disclosure vulnerability in ZTE U30 Air product |
| CVE-2026-103105 | 8.8 | 7.2 | Pexip | Infinity | CWE-863 | Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper… |
| CVE-2026-92872 | 5.3 | 7.2 | Pgpool Global Development Group | Pgpool-II | CWE-532 | Pgpool-II inserts sensitive information into log file, which may allow an aut… |
| CVE-2026-93580 | 5.3 | 7.1 | Unknown | InPost PL | CWE-862 | InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery v… |
| CVE-2026-51936 | 2.1 | 6.8 | Zetetic | SQLCipher | CWE-89 | Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export co… |
| CVE-2026-83560 | 5.3 | 6.3 | Unknown | New User Approve | CWE-200 | New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier AP… |
| CVE-2026-102588 | 6.5 | 6.0 | — | moodle | CWE-346 | Moodle: csrf in xml grade import |
| CVE-2026-85573 | 8.8 | 6.0 | Unknown | All in One Files Upload | CWE-79 | All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stor… |
| CVE-2026-92994 | 8.8 | 6.0 | Unknown | Verge3D Publishing and E-Commerce | CWE-79 | Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API |
| CVE-2026-89193 | 7.5 | 6.0 | Unknown | Robin Image Optimizer | CWE-79 | Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL… |
| CVE-2026-102581 | 4.6 | 5.8 | — | moodle | CWE-79 | Moodle: xss in forum post templates due to insufficient escaping |
| CVE-2026-102511 | 8.5 | 5.0 | Apache Software Foundation | Apache PLC4X | CWE-129 | Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts… |
| CVE-2026-6170 | 6.4 | 4.1 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-6171 | 6.4 | 4.1 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-6172 | 6.4 | 4.1 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-6173 | 6.4 | 4.1 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-11895 | 6.4 | 4.1 | devitemsllc | HT Mega Addons for Elementor – Elementor Widgets & Template Builder | CWE-79 | HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored C… |
| CVE-2026-14876 | 6.4 | 4.1 | nextendweb | Smart Slider 3 | CWE-79 | Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-88037 | 6.4 | 4.1 | boldthemes | Bold Page Builder | CWE-79 | Bold Page Builder <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site S… |
| CVE-2026-85001 | 6.8 | 3.7 | Unknown | EmbedPress | CWE-79 | EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showT… |
| CVE-2026-85415 | 6.8 | 3.7 | Unknown | Audio Player Block | CWE-79 | Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download… |
| CVE-2026-87777 | 6.8 | 3.7 | Unknown | Hostinger Reach | CWE-79 | Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor … |
| CVE-2026-92424 | 6.8 | 3.7 | Unknown | Content Egg | CWE-79 | Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue |
| CVE-2026-82127 | 3.5 | 3.7 | Unknown | Schema & Structured Data for WP & AMP | CWE-79 | Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonom… |
| CVE-2026-92868 | 6.9 | 3.7 | Pgpool Global Development Group | Pgpool-II | CWE-295 | An improper certificate validation vulnerability exists in Pgpool-II, which m… |
| CVE-2026-93463 | 5.1 | 3.6 | baserCMS User Community | baserCMS | CWE-79 | Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this… |
| CVE-2026-80333 | 5.3 | 3.5 | Unknown | Solace Extra | CWE-200 | Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure … |
| CVE-2026-88791 | 3.4 | 3.4 | Unknown | Safe Redirect Manager | CWE-601 | Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules |
| CVE-2026-75823 | 7.4 | 3.3 | Unknown | User Frontend | CWE-269 | WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via R… |
| CVE-2026-100143 | 6.5 | 3.3 | Unknown | FluentCart A New Era of eCommerce | CWE-287 | FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Chec… |
| CVE-2026-75824 | 5.3 | 3.3 | Unknown | User Frontend | CWE-284 | WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Regis… |
| CVE-2026-97316 | 5.8 | 3.1 | Unknown | Broken Link Notifier | CWE-918 | Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass |
| CVE-2026-86789 | 5.3 | 3.2 | Unknown | Connections Business Directory | CWE-200 | Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Direct… |
| CVE-2026-94274 | 5.3 | 3.2 | Unknown | YayReviews | CWE-200 | YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST… |
| CVE-2026-96886 | 5.3 | 3.2 | Unknown | Course Booking System | CWE-200 | Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via C… |
| CVE-2026-103106 | 7.8 | 2.9 | Pexip | Infinity | CWE-669 | Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by imprope… |
| CVE-2026-93460 | 5.1 | 2.7 | baserCMS User Community | baserCMS | CWE-79 | A stored cross-site scripting vulnerability via appended strings in email for… |
| CVE-2026-93464 | 5.1 | 2.7 | baserCMS User Community | baserCMS | CWE-79 | A stored cross-site scripting vulnerability via custom content descriptions e… |
| CVE-2026-91072 | 4.4 | 2.7 | Unknown | EWWW Image Optimizer | CWE-73 | EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unres… |
| CVE-2026-90953 | 4.3 | 2.7 | Unknown | Image Optimizer | CWE-200 | Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Si… |
| CVE-2026-88797 | 7.1 | 2.3 | Unknown | Vayu X | CWE-284 | Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and … |
| CVE-2026-85576 | 4.3 | 2.3 | Unknown | All in One Files Upload | CWE-862 | All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plug… |
| CVE-2026-89190 | 4.3 | 2.3 | Unknown | Robin Image Optimizer | CWE-284 | Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy… |
| CVE-2026-94297 | 2.7 | 2.3 | Unknown | Media Library Organizer | CWE-862 | Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term … |
| CVE-2026-102508 | 9.2 | 1.8 | Apache Software Foundation | Apache PLC4X | CWE-295 | Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server ce… |
| CVE-2026-81310 | 5.2 | 1.6 | PFU Limited | Image Scanner Driver for Linux (fi Series) | CWE-59 | Image Scanner Driver for Linux contains a link following vulnerability. An at… |
| CVE-2026-91832 | 7.1 | 1.0 | Unknown | WP Mobile Menu | CWE-79 | WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF |
| CVE-2026-55107 | 10.0 | — | elct9620 | kobako | CWE-94 | Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_m… |
| CVE-2026-76570 | 10.0 | — | joomcode.com | JCTables extension for Joomla | CWE-89 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and w… |
| CVE-2026-96349 | 10.0 | — | SiteSkite | SiteSkite | CWE-94 | WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-102427 | 10.0 | — | ordasoft.com | OrdaSoft Joomla CCK | CWE-434 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in Or… |
| CVE-2026-18782 | 9.8 | — | Trex Digital Smart Manufacturing Systems Inc. | Trex MES | CWE-89 | SQL Injection in Trex Digital Manufacturing's Trex MES |
| CVE-2026-55494 | 9.8 | — | Quenary | tugtainer | CWE-284 | Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs w… |
| CVE-2026-82307 | 9.8 | — | Dolusoft Software Technologies | SOPLOG | CWE-89 | Multiple Vulnerabilities in Dolusoft Software's SOPLOG |
| CVE-2026-88920 | 9.8 | — | Apache Software Foundation | Apache WSS4J | CWE-287 | Apache WSS4J: SAML Sender-Vouches Authentication Bypass |
| CVE-2026-96350 | 9.8 | — | Estatik | Estatik | CWE-266 | WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability |
| CVE-2026-97248 | 9.8 | — | Booking Activities Team | Booking Activities | CWE-502 | WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulner… |
| CVE-2026-97274 | 9.8 | — | miniOrange | OAuth Single Sign On – SSO (OAuth Client) | CWE-290 | WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass … |
| CVE-2026-100512 | 9.8 | — | Hook & Filter | Nested Pages | CWE-502 | WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability |
| CVE-2026-102115 | 9.8 | — | Kiteworks | Core | CWE-640 | Kiteworks Core Authentication Bypass in the Password Reset Workflow |
| CVE-2026-55181 | 9.4 | — | Quenary | tugtainer | CWE-284 | Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false |
| CVE-2026-93903 | 9.4 | — | litespeedtech | LiteSpeed Web Server | CWE-174 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect… |
| CVE-2026-102149 | 9.4 | — | Kiteworks | Email Protection Gateway | CWE-306 | Kiteworks Email Protection Gateway Improper Access Control |
| CVE-2026-102489 | 9.4 | — | Zammad GmbH | Zammad | — | Undisclosed RCE in Zammad v6.3 and higher |
| CVE-2026-102490 | 9.4 | — | Zammad GmbH | Zammad | — | Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha |
| CVE-2026-74864 | 9.3 | — | YunoHost-Apps | sogo_yhn | CWE-639 | Authentication Bypass in sogo_yhn |
| CVE-2026-96822 | 9.3 | — | Hossni Mubarak | Books Gallery | CWE-89 | WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability |
| CVE-2026-102147 | 9.3 | — | Kiteworks | Core | CWE-79 | Kiteworks Core Administrative Account Takeover through Stored Cross-site Scri… |
| CVE-2026-103395 | 9.3 | — | ModelTC | LightLLM | CWE-502 | LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only … |
| CVE-2026-103470 | 9.3 | — | Internet2 | Grouper | CWE-266 | In Internet2 Grouper before 7.5.1 (in some configurations), a user who is all… |
| CVE-2026-103475 | 9.3 | — | yii2-starter-kit | yii2-starter-kit | CWE-489 | yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure |
| CVE-2026-19445 | 9.2 | — | Python Software Foundation | CPython | CWE-416 | Use-after-free of a server-side SSLContext when sni_callback switches contexts |
| CVE-2026-74865 | 9.2 | — | YunoHost-Apps | sogo_yhn | CWE-639 | Authentication Bypass in sogo_yhn |
| CVE-2026-101276 | 9.2 | — | esnet | iperf3 | CWE-416 | iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-f… |
| CVE-2026-101283 | 9.2 | — | esnet | iperf3 | CWE-122 | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt… |
| CVE-2026-102992 | 9.2 | — | piscinajs | piscina | CWE-1321 | piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via exec… |
| CVE-2026-103473 | 9.2 | — | denoland | deno | CWE-78 | Deno 2.7.0 through 2.9.7 Command Injection via node:child_process |
| CVE-2026-103547 | 9.2 | — | OpenBSD | OpenBSD | CWE-863 | In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegate… |
| CVE-2026-62308 | 9.1 | — | Quenary | tugtainer | CWE-918 | Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notific… |
| CVE-2026-75969 | 9.1 | — | PTZOptics | Move 4K 12X | CWE-306 | PTZOptics Missing Authentication in Firmware Upload |
| CVE-2026-87830 | 9.1 | — | Apache Software Foundation | Apache WSS4J | CWE-917 | Apache WSS4J: Streaming WS-SecurityPolicy validation may skip element-protect… |
| CVE-2026-89238 | 9.1 | — | Apache Software Foundation | Apache WSS4J | CWE-345 | Apache WSS4J: WSS4J EncryptedHeader child confusion causing wrong protected-h… |
| CVE-2026-102095 | 9.1 | — | Kiteworks | Email Protection Gateway | CWE-918 | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102102 | 9.1 | — | Kiteworks | Email Protection Gateway | CWE-918 | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102103 | 9.1 | — | Kiteworks | Email Protection Gateway | CWE-918 | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102104 | 9.1 | — | Kiteworks | Email Protection Gateway | CWE-918 | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102105 | 9.1 | — | Kiteworks | Email Protection Gateway | CWE-918 | Kiteworks Email Protection Gateway server-side request forgery |
| CVE-2026-102106 | 9.1 | — | Kiteworks | Email Protection Gateway | CWE-287 | Kiteworks Email Protection Gateway improper authentication |
| CVE-2026-55176 | 9.0 | — | Soft-Machine-io | security | CWE-863 | Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SH… |
| CVE-2026-94389 | 9.0 | — | AcyMailing Newsletter Team | AcyMailing SMTP Newsletter | CWE-94 | WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution… |
| CVE-2026-100277 | 8.9 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by re… |
| CVE-2026-18783 | 8.8 | — | Trex Digital Smart Manufacturing Systems Inc. | Trex MES | CWE-306 | Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manuf… |
| CVE-2026-94076 | 8.8 | — | SEO Squirrly | SEO Plugin by Squirrly SEO | CWE-502 | WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection … |
| CVE-2026-94121 | 8.8 | — | 10Web | 10Web Booster – Website speed optimization, Cache & Page Speed optimizer | CWE-502 | WordPress 10Web Booster – Website speed optimization, Cache & Page Speed opti… |
| CVE-2026-94678 | 8.8 | — | Mat Lipe | Go Live Update Urls | CWE-502 | WordPress Go Live Update Urls plugin <= 7.0.8 - PHP Object Injection vulnerab… |
| CVE-2026-94683 | 8.8 | — | Justin Nealey | DesignSetGo | CWE-502 | WordPress DesignSetGo plugin <= 2.8.0 - PHP Object Injection vulnerability |
| CVE-2026-95531 | 8.8 | — | QuantumCloud | Conversational Forms for ChatBot | CWE-502 | WordPress Conversational Forms for ChatBot plugin <= 1.5.0 - PHP Object Injec… |
| CVE-2026-96831 | 8.8 | — | themifyme | Themify Builder | CWE-502 | WordPress Themify Builder plugin <= 7.8.1 - PHP Object Injection vulnerability |
| CVE-2026-96837 | 8.8 | — | Brainstorm Force | CartFlows | CWE-98 | WordPress CartFlows plugin <= 3.2.0 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-96838 | 8.8 | — | YoOhw Studio | Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification | CWE-352 | WordPress Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & C… |
| CVE-2026-97291 | 8.8 | — | Magazine3 | Schema & Structured Data for WP & AMP | CWE-502 | WordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object I… |
| CVE-2026-100253 | 8.8 | — | JetBrains | TeamCity | CWE-184 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leadi… |
| CVE-2026-100254 | 8.8 | — | JetBrains | TeamCity | CWE-78 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users … |
| CVE-2026-102120 | 8.8 | — | Kiteworks | Core | CWE-78 | Kiteworks Core OS Command Injection |
| CVE-2026-102125 | 8.8 | — | Kiteworks | Core | CWE-653 | Kiteworks Core Sandbox Escape |
| CVE-2026-102377 | 8.8 | — | 10Web | Photo Gallery by 10Web | CWE-502 | WordPress Photo Gallery by 10Web plugin <= 1.8.46 - PHP Object Injection vuln… |
| CVE-2023-54402 | 8.7 | — | iDocView | iDocView | CWE-918 | iDocView SSRF via /doc/upload Endpoint Hardcoded Token |
| CVE-2023-54403 | 8.7 | — | Yonyou | U8 CRM | CWE-22 | Yonyou U8 CRM Arbitrary File Read via getemaildata.php |
| CVE-2024-58387 | 8.7 | — | Inspur | Haiyue HCM Cloud | CWE-22 | Inspur HCM Cloud Arbitrary File Read via file/download Endpoint |
| CVE-2026-47097 | 8.7 | — | AJA Video Systems | HELO Plus | CWE-321 | AJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export Bundle |
| CVE-2026-55094 | 8.7 | — | taskcluster | taskcluster | CWE-20 | Taskcluster: Unauthenticated remote code execution in `web-server` via GraphQ… |
| CVE-2026-55224 | 8.7 | — | mineadmin | MineAdmin | CWE-22 | MineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/Uninstall |
| CVE-2026-76992 | 8.7 | — | CODESYS | Development System 3 | CWE-770 | Uncontrolled Memory Allocation in CODESYS Gateway Client |
| CVE-2026-101880 | 8.7 | — | OpenClaw | OpenClaw Windows Node | CWE-863 | OpenClaw Windows Node before 2026.7.1 Authorization Bypass |
| CVE-2026-101882 | 8.7 | — | OpenClaw | OpenClaw Windows Node | CWE-184 | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execAp… |
| CVE-2026-102092 | 8.7 | — | Kiteworks | Core | CWE-79 | Kiteworks Core stored XSS |
| CVE-2026-102100 | 8.7 | — | Kiteworks | Core | CWE-79 | Kiteworks Core stored XSS |
| CVE-2026-102993 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage when retrieving Roman page labels |
| CVE-2026-102994 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible long runtimes/large memory usage when parsing indirect objects |
| CVE-2026-102995 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2) |
| CVE-2026-102996 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage when parsing font data |
| CVE-2026-102997 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible long runtimes for partially malformed FlateDecode streams (Fo… |
| CVE-2026-102998 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible long runtimes when generating appearance streams |
| CVE-2026-102999 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible long runtimes with large amount of embedded files |
| CVE-2026-103000 | 8.7 | — | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage when retrieving alphabetical page labels |
| CVE-2026-103270 | 8.7 | — | ModelTC | LightLLM | CWE-306 | LightLLM through 1.2.0 Missing Authentication on RL Control Routes |
| CVE-2026-103471 | 8.7 | — | Corvusoft | restbed | CWE-770 | restbed through 5.0.0 Denial of Service via Unbounded Header Buffering |
| CVE-2026-103472 | 8.7 | — | Corvusoft | restbed | CWE-770 | restbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame Buffering |
| CVE-2026-103474 | 8.7 | — | yii2-starter-kit | yii2-starter-kit | CWE-434 | yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE |
| CVE-2026-103591 | 8.7 | — | AsyncFuncAI | deepwiki-open | CWE-73 | DeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via … |
| CVE-2026-102121 | 8.6 | — | Kiteworks | Secure Data Forms | CWE-200 | Kiteworks Secure Data Forms Exposure of Sensitive Information to an Unauthori… |
| CVE-2026-103239 | 8.6 | — | MISP | MISP | CWE-284 | MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection |
| CVE-2026-103398 | 8.6 | — | Liquid-co | OpenSave | CWE-73 | OpenSave through 2.4.0 Arbitrary File Read and Write via Peer-Controlled Save… |
| CVE-2026-10739 | 8.5 | — | Cato Networks | SDP Client | CWE-23 | Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation |
| CVE-2026-94115 | 8.5 | — | Fatcatapps | Easy Pricing Tables | CWE-89 | WordPress Easy Pricing Tables plugin <= 4.1.2 - SQL Injection vulnerability |
| CVE-2026-94177 | 8.5 | — | Ruben Garcia | GamiPress | CWE-89 | WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability |
| CVE-2026-97287 | 8.5 | — | Nexcess | Event Tickets | CWE-89 | WordPress Event Tickets plugin <= 5.29.5 - SQL Injection vulnerability |
| CVE-2026-97293 | 8.5 | — | David Lingren | Media LIbrary Assistant | CWE-89 | WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability |
| CVE-2026-101885 | 8.5 | — | zeroclaw-labs | ZeroClaw | CWE-22 | ZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_path |
| CVE-2026-46711 | 8.3 | — | Soft-Machine-io | security | CWE-306 | Soft Machine: Unauthenticated workspace API exposes arbitrary file read & dir… |
| CVE-2026-103321 | 8.3 | — | MISP | MISP | CWE-20 | MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image |
| CVE-2026-93621 | 8.2 | — | Passionate Programmer Peter | WP Data Access | CWE-89 | WordPress WP Data Access plugin <= 5.5.84 - SQL Injection vulnerability |
| CVE-2026-96817 | 8.2 | — | MakeCommerce.net | MakeCommerce for WooCommerce | CWE-862 | WordPress MakeCommerce for WooCommerce plugin <= 4.1.0 - Broken Access Contro… |
| CVE-2026-100273 | 8.2 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts… |
| CVE-2026-102984 | 8.2 | — | withastro | astro | CWE-248 | Astro: Malformed port in the Host header can crash the Node adapter |
| CVE-2026-102990 | 8.2 | — | patrickjuchli | basic-ftp | CWE-1333 | basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directo… |
| CVE-2026-51568 | 8.1 | — | n/a | n/a | — | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write… |
| CVE-2026-51570 | 8.1 | — | n/a | n/a | — | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert… |
| CVE-2026-87004 | 8.1 | — | Quenary | tugtainer | CWE-347 | Tugtainer: OIDC id_token claims accepted without signature/audience/expiry ve… |
| CVE-2026-100255 | 8.1 | — | JetBrains | TeamCity | CWE-1289 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator accoun… |
| CVE-2026-102101 | 8.1 | — | Kiteworks | Core | CWE-502 | Kiteworks Core deserialization of untrusted data |
| CVE-2026-102126 | 8.1 | — | Kiteworks | Core | CWE-79 | Kiteworks Core Stored Cross-site Scripting (XSS) |
| CVE-2026-103432 | 8.1 | — | apcupsd | apcupsd | CWE-121 | apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsva… |
| CVE-2026-47489 | 7.8 | — | NVIDIA | GeForce | CWE-281 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47491 | 7.8 | — | NVIDIA | GeForce | CWE-404 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47493 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-862 | NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GP… |
| CVE-2026-47494 | 7.8 | — | NVIDIA | GeForce | CWE-134 | NVIDIA GPU Display Driver for Linux contains a vulnerability where a user mig… |
| CVE-2026-47495 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-787 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerabilit… |
| CVE-2026-47497 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-367 | NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Process… |
| CVE-2026-47498 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-787 | NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP… |
| CVE-2026-47499 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerabilit… |
| CVE-2026-47500 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47501 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47502 | 7.8 | — | NVIDIA | GeForce | CWE-190 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerabilit… |
| CVE-2026-47503 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-787 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual G… |
| CVE-2026-47504 | 7.8 | — | NVIDIA | GeForce | CWE-843 | NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater w… |
| CVE-2026-47505 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47507 | 7.8 | — | NVIDIA | GeForce | CWE-129 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47508 | 7.8 | — | NVIDIA | GeForce | CWE-681 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47510 | 7.8 | — | NVIDIA | GeForce | CWE-190 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47511 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47512 | 7.8 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47513 | 7.8 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47514 | 7.8 | — | NVIDIA | GeForce | CWE-200 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47516 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher… |
| CVE-2026-47519 | 7.8 | — | NVIDIA | Guest driver | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47520 | 7.8 | — | NVIDIA | Guest driver | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47521 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47523 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47528 | 7.8 | — | NVIDIA | GeForce | CWE-824 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47530 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47535 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the fir… |
| CVE-2026-47536 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-125 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47540 | 7.8 | — | NVIDIA | GeForce | CWE-191 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47541 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-787 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the ker… |
| CVE-2026-47545 | 7.8 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47548 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47550 | 7.8 | — | NVIDIA | GeForce | CWE-119 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47551 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47552 | 7.8 | — | NVIDIA | GeForce | CWE-862 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47553 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47556 | 7.8 | — | NVIDIA | GeForce | CWE-190 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47558 | 7.8 | — | NVIDIA | GeForce | CWE-415 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47559 | 7.8 | — | NVIDIA | GeForce | CWE-862 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47560 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47561 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47563 | 7.8 | — | NVIDIA | GeForce | CWE-476 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47569 | 7.8 | — | NVIDIA | GeForce | CWE-843 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47570 | 7.8 | — | NVIDIA | GeForce | CWE-427 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA dr… |
| CVE-2026-47571 | 7.8 | — | NVIDIA | GeForce | CWE-863 | NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode… |
| CVE-2026-47572 | 7.8 | — | NVIDIA | GeForce | CWE-843 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47573 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA NVAPI for Windows contains a vulnerability where an attacker could cau… |
| CVE-2026-47574 | 7.8 | — | NVIDIA | Virtual GPU Manager | CWE-669 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an a… |
| CVE-2026-47575 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the display… |
| CVE-2026-47577 | 7.8 | — | NVIDIA | GeForce | CWE-190 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47578 | 7.8 | — | NVIDIA | GeForce | CWE-131 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47579 | 7.8 | — | NVIDIA | GeForce | CWE-416 | The NVIDIA GPU Display Driver for Windows contains a vulnerability in the ker… |
| CVE-2026-47583 | 7.8 | — | NVIDIA | GeForce | CWE-843 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47585 | 7.8 | — | NVIDIA | GeForce | CWE-191 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47587 | 7.8 | — | NVIDIA | RTX, Quadro, NVS | CWE-416 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivi… |
| CVE-2026-47588 | 7.8 | — | NVIDIA | RTX, Quadro, NVS | CWE-416 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivi… |
| CVE-2026-47589 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher… |
| CVE-2026-47590 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher… |
| CVE-2026-47591 | 7.8 | — | NVIDIA | GeForce | CWE-863 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47592 | 7.8 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47593 | 7.8 | — | NVIDIA | GeForce | CWE-121 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-47594 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability wher… |
| CVE-2026-47595 | 7.8 | — | NVIDIA | GeForce | CWE-281 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47597 | 7.8 | — | NVIDIA | GeForce | CWE-416 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47599 | 7.8 | — | NVIDIA | GeForce | CWE-281 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-sour… |
| CVE-2026-47600 | 7.8 | — | NVIDIA | GeForce | CWE-908 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-47601 | 7.8 | — | NVIDIA | GeForce | CWE-787 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-53605 | 7.8 | — | pollen-robotics | reachy-mini-os | CWE-250 | Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo system… |
| CVE-2026-62146 | 7.8 | — | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-501 | Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime … |
| CVE-2026-100256 | 7.8 | — | JetBrains | IntelliJ IDEA | CWE-829 | In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script c… |
| CVE-2026-102112 | 7.8 | — | Kiteworks | Core | CWE-78 | Kiteworks Core Local Privilege Escalation |
| CVE-2026-102113 | 7.8 | — | Kiteworks | Core | CWE-59 | Kiteworks Core Local Privilege Escalation |
| CVE-2026-102118 | 7.8 | — | Kiteworks | Core | CWE-59 | Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation |
| CVE-2026-47576 | 7.7 | — | NVIDIA | GeForce | CWE-125 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-100266 | 7.7 | — | JetBrains | Hub | CWE-862 | In JetBrains Hub before 2026.2.52366 missing authorisation allowed authentica… |
| CVE-2026-100268 | 7.7 | — | JetBrains | YouTrack | CWE-639 | In JetBrains YouTrack before 2026.2.19197 project administrators could read c… |
| CVE-2026-101884 | 7.7 | — | OpenClaw | OpenClaw Windows Node | CWE-184 | OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment O… |
| CVE-2026-19553 | 7.6 | — | Python Software Foundation | CPython | CWE-297 | SSLContext.wrap_bio() missing validation of server_hostname parameter |
| CVE-2026-55177 | 7.6 | — | dfpc-coe | CloudTAK | CWE-918 | CloudTAK: Authenticated full-read SSRF in /api/esri* routes — user-controlled… |
| CVE-2026-62085 | 7.6 | — | Melapress | WP Activity Log | CWE-89 | WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability |
| CVE-2026-62097 | 7.6 | — | WPTasty | Business Directory | CWE-89 | WordPress Business Directory plugin <= 6.4.27 - SQL Injection vulnerability |
| CVE-2026-94082 | 7.6 | — | Fatcatapps | Quiz Cat | CWE-89 | WordPress Quiz Cat plugin <= 3.1.1 - SQL Injection vulnerability |
| CVE-2026-96345 | 7.6 | — | Estatik | Estatik | CWE-89 | WordPress Estatik plugin <= 4.3.5 - SQL Injection vulnerability |
| CVE-2026-96346 | 7.6 | — | weDevs | WP ERP | CWE-89 | WordPress WP ERP plugin <= 1.17.9 - SQL Injection vulnerability |
| CVE-2026-96827 | 7.6 | — | Melapress | Admin Notices Manager | CWE-89 | WordPress Admin Notices Manager plugin <= 1.6.0 - SQL Injection vulnerability |
| CVE-2026-96828 | 7.6 | — | Vidish | Category Discount Woocommerce | CWE-89 | WordPress Category Discount Woocommerce plugin <= 5.18 - SQL Injection vulner… |
| CVE-2026-100262 | 7.6 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users… |
| CVE-2026-85532 | 7.5 | — | Apache Software Foundation | Apache WSS4J | CWE-20 | Apache WSS4J: Insufficient Validation of Derived-Key Parameters |
| CVE-2026-92121 | 7.5 | — | Apache Software Foundation | Apache WSS4J | CWE-693 | Apache WSS4J: WS-SecurityPolicy signature checks skipped in the streaming cod… |
| CVE-2026-94120 | 7.5 | — | GravityKit | GravityExport Lite for Gravity Forms | CWE-862 | WordPress GravityExport Lite for Gravity Forms plugin <= 2.7.2 - Broken Acces… |
| CVE-2026-94123 | 7.5 | — | Syed Balkhi | NextGEN Gallery | CWE-22 | WordPress NextGEN Gallery plugin <= 4.5.0 - Arbitrary File Download vulnerabi… |
| CVE-2026-94178 | 7.5 | — | Javier Carazo | Import and export users and customers | CWE-266 | WordPress Import and export users and customers plugin <= 2.5.2 - Privilege E… |
| CVE-2026-95587 | 7.5 | — | Hostinger | Hostinger Migrator | CWE-862 | WordPress Hostinger Migrator plugin <= 1.0 - Broken Access Control vulnerability |
| CVE-2026-95616 | 7.5 | — | Apache Software Foundation | Apache WSS4J | CWE-190 | Apache WSS4J: Unauthenticated denial of service via integer overflow in DER p… |
| CVE-2026-96348 | 7.5 | — | Bookly | Bookly | CWE-862 | WordPress Bookly plugin <= 28.2 - Broken Access Control vulnerability |
| CVE-2026-96818 | 7.5 | — | mra13 / Team Tips and Tricks HQ | WP Express Checkout (Accept PayPal Payments) | CWE-862 | WordPress WP Express Checkout (Accept PayPal Payments) plugin <= 2.4.9 - Brok… |
| CVE-2026-96823 | 7.5 | — | CusRev | Customer Reviews for WooCommerce | CWE-862 | WordPress Customer Reviews for WooCommerce plugin <= 5.120.0 - Arbitrary Cont… |
| CVE-2026-97197 | 7.5 | — | WebToffee | WordPress Backup & Migration | CWE-862 | WordPress WordPress Backup & Migration plugin <= 1.6.0 - Broken Access Contro… |
| CVE-2026-97240 | 7.5 | — | Esteban | StifLi Backup Tools | CWE-201 | WordPress StifLi Backup Tools plugin <= 2.2.7 - Sensitive Data Exposure vulne… |
| CVE-2026-97241 | 7.5 | — | PrecisionWP | BackupEase | CWE-201 | WordPress BackupEase plugin <= 2.2.2 - Sensitive Data Exposure vulnerability |
| CVE-2026-97244 | 7.5 | — | WPFunnels | Creator LMS | CWE-35 | WordPress Creator LMS plugin <= 1.2.19 - Path Traversal vulnerability |
| CVE-2026-102091 | 7.5 | — | Kiteworks | Secure Data Forms | CWE-918 | Kiteworks Secure Data Forms server-side request forgery |
| CVE-2026-102128 | 7.5 | — | Kiteworks | Email Protection Gateway | CWE-287 | Kiteworks Email Protection Gateway Improper Authentication |
| CVE-2026-102143 | 7.5 | — | Kiteworks | Email Protection Gateway | CWE-306 | Kiteworks Email Protection Gateway Unrestricted Upload of File with Dangerous… |
| CVE-2026-102717 | 7.5 | — | Eclipse Foundation | NetX Duo | CWE-125 | MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash |
| CVE-2026-102123 | 7.4 | — | Kiteworks | Core | CWE-22 | Kiteworks Core Path Traversal |
| CVE-2026-103446 | 7.4 | — | The Wikimedia Foundation | MediaWiki WikiLambda extension | CWE-639 | WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments |
| CVE-2026-47496 | 7.3 | — | NVIDIA | Virtual GPU Manager | CWE-787 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual G… |
| CVE-2026-47580 | 7.3 | — | NVIDIA | GeForce | CWE-862 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel … |
| CVE-2026-101295 | 7.3 | — | Red Hat | Assisted Installer for Red Hat OpenShift Container Platform 2 | CWE-22 | Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catal… |
| CVE-2026-93624 | 7.2 | — | codepeople | Music Player for WooCommerce | CWE-502 | WordPress Music Player for WooCommerce plugin <= 1.9.1 - PHP Object Injection… |
| CVE-2026-93651 | 7.2 | — | Dotstore | Minimum and Maximum Quantity for WooCommerce | CWE-502 | WordPress Minimum and Maximum Quantity for WooCommerce plugin <= 2.1.2 - PHP … |
| CVE-2026-93771 | 7.2 | — | WPFactory | Cost of Goods for WooCommerce | CWE-502 | WordPress Cost of Goods for WooCommerce plugin <= 3.5.2 - PHP Object Injectio… |
| CVE-2026-94122 | 7.2 | — | A WP Life | Responsive Slider Gallery | CWE-502 | WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vu… |
| CVE-2026-94677 | 7.2 | — | Nexcess | Kadence WooCommerce Email Designer | CWE-502 | WordPress Kadence WooCommerce Email Designer plugin <= 1.5.19.1 - PHP Object … |
| CVE-2026-96343 | 7.2 | — | weDevs | WP ERP | CWE-502 | WordPress WP ERP plugin <= 1.17.9 - PHP Object Injection vulnerability |
| CVE-2026-96344 | 7.2 | — | impleCode | eCommerce Product Catalog | CWE-502 | WordPress eCommerce Product Catalog plugin <= 3.6.0 - PHP Object Injection vu… |
| CVE-2026-96815 | 7.2 | — | appsbd | Vitepos | CWE-266 | WordPress Vitepos plugin <= 3.5.0 - Privilege Escalation vulnerability |
| CVE-2026-96832 | 7.2 | — | keywordrush | Content Egg | CWE-502 | WordPress Content Egg plugin <= 6.3.1 - PHP Object Injection vulnerability |
| CVE-2026-96833 | 7.2 | — | Themefic | Ultimate Addons for Contact Form 7 | CWE-502 | WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.51 - PHP Object In… |
| CVE-2026-97245 | 7.2 | — | SureCart | SureCart | CWE-266 | WordPress SureCart plugin <= 4.7.2 - Privilege Escalation vulnerability |
| CVE-2026-97256 | 7.2 | — | Greg – SiteOrigin | Page Builder by SiteOrigin | CWE-502 | WordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection … |
| CVE-2026-102089 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-22 | Kiteworks Email Protection Gateway path traversal |
| CVE-2026-102093 | 7.2 | — | Kiteworks | Core | CWE-269 | Kiteworks Core improper privilege management |
| CVE-2026-102094 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-470 | Kiteworks Email Protection Gateway unsafe reflection |
| CVE-2026-102096 | 7.2 | — | Kiteworks | Core | CWE-78 | Kiteworks Core OS command injection |
| CVE-2026-102097 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-22 | Kiteworks Email Protection Gateway remote code execution |
| CVE-2026-102098 | 7.2 | — | Kiteworks | Core | CWE-89 | Kiteworks Core SQL Injection |
| CVE-2026-102099 | 7.2 | — | Kiteworks | Core | CWE-22 | Kiteworks Core arbitrary file write |
| CVE-2026-102108 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-502 | Kiteworks Email Protection Gateway deserialization of untrusted data |
| CVE-2026-102114 | 7.2 | — | Kiteworks | Core | CWE-78 | Kiteworks Core OS Command Injection |
| CVE-2026-102116 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-22 | Kiteworks Email Protection Gateway Path Traversal |
| CVE-2026-102117 | 7.2 | — | Kiteworks | Core | CWE-807 | Kiteworks Core Remote Code Execution |
| CVE-2026-102119 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-22 | Kiteworks Email Protection Gateway Path Traversal |
| CVE-2026-102129 | 7.2 | — | Kiteworks | Core | CWE-266 | Kiteworks Core Incorrect Privilege Assignment |
| CVE-2026-102130 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-94 | Kiteworks Email Protection Gateway Remote Code Execution |
| CVE-2026-102131 | 7.2 | — | Kiteworks | Email Protection Gateway | CWE-94 | Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity |
| CVE-2026-102132 | 7.2 | — | Kiteworks | Core | CWE-284 | Kiteworks Core Privilege Escalation through Improper Access Control |
| CVE-2026-102142 | 7.2 | — | Kiteworks | Core | CWE-1336 | Kiteworks Core Remote Code Execution through Server-Side Template Injection |
| CVE-2026-102150 | 7.2 | — | Kiteworks | Secure Data Forms | CWE-306 | Kiteworks Secure Data Forms Missing Authentication for Critical Function |
| CVE-2026-102392 | 7.2 | — | ThemeHigh | Extra Product Options For WooCommerce | Custom Product Addons and Fields | CWE-502 | WordPress Extra Product Options For WooCommerce | Custom Product Addons and F… |
| CVE-2026-103441 | 7.2 | — | The Wikimedia Foundation | MediaWiki Wikibase extension | CWE-502 | Unauthenticated arbitrary file deletion through Wikibase serialized entity pa… |
| CVE-2026-103442 | 7.2 | — | The Wikimedia Foundation | MediaWiki CentralAuth extension | CWE-15 | MergeAccount PHP object injection via session-key substitution |
| CVE-2026-27371 | 7.1 | — | WPFunnels | WPFunnels | CWE-79 | WordPress WPFunnels plugin <= 3.13.1 - Reflected Cross Site Scripting (XSS) v… |
| CVE-2026-47554 | 7.1 | — | NVIDIA | GeForce | CWE-347 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mo… |
| CVE-2026-47602 | 7.1 | — | NVIDIA | GeForce | CWE-119 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in t… |
| CVE-2026-93512 | 7.1 | — | ilGhera | JW Player for WordPress | CWE-79 | WordPress JW Player for WordPress plugin <= 2.3.11 - Cross Site Scripting (XS… |
| CVE-2026-93514 | 7.1 | — | rainafarai | Notification for Telegram | CWE-79 | WordPress Notification for Telegram plugin <= 3.5.2 - Cross Site Scripting (X… |
| CVE-2026-93770 | 7.1 | — | VeronaLabs | WP Statistics | CWE-79 | WordPress WP Statistics plugin <= 14.16.13 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-94078 | 7.1 | — | Gemini Labs | Site Reviews | CWE-79 | WordPress Site Reviews plugin <= 8.3.1 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-94081 | 7.1 | — | lukeseager | WordPress Persistent Login | CWE-79 | WordPress WordPress Persistent Login plugin <= 3.1.3 - Cross Site Scripting (… |
| CVE-2026-94171 | 7.1 | — | VillaTheme | CURCY | CWE-79 | WordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-94499 | 7.1 | — | wpWax | FormGent | CWE-862 | WordPress FormGent plugin <= 1.12.2 - Broken Access Control vulnerability |
| CVE-2026-96351 | 7.1 | — | RadiusTheme | Classified Listing | CWE-79 | WordPress Classified Listing plugin <= 6.1.3 - Cross Site Scripting (XSS) vul… |
| CVE-2026-96352 | 7.1 | — | YITHEMES | YITH WooCommerce Ajax Search | CWE-79 | WordPress YITH WooCommerce Ajax Search plugin <= 2.28.0 - Cross Site Scriptin… |
| CVE-2026-96814 | 7.1 | — | WP Titan Labs | WooCommerce Product Table Lite | CWE-79 | WordPress WooCommerce Product Table Lite plugin <= 5.6.7 - Cross Site Scripti… |
| CVE-2026-96816 | 7.1 | — | vendidero | Trusted Shops Easy Integration for WooCommerce | CWE-79 | WordPress Trusted Shops Easy Integration for WooCommerce plugin <= 2.0.6 - Cr… |
| CVE-2026-96819 | 7.1 | — | bobbingwide | oik | CWE-79 | WordPress oik plugin <= 4.15.4 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-96820 | 7.1 | — | awesomesupport | Awesome Support | CWE-79 | WordPress Awesome Support plugin <= 6.3.9 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-96830 | 7.1 | — | Nexcess | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.16.9 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-96836 | 7.1 | — | Morteza Geransayeh | Parsi Date | CWE-79 | WordPress Parsi Date plugin <= 6.3 - Cross Site Scripting (XSS) vulnerability |
Results continue: ranks 401–636.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-09-30 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.