boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, October 1, 2026 · all times UTC← 2026-09-30 · archive

Security Box Score — October 1, 2026

CISA adds 1 to KEV; 395 CVEs published, led by Apache Software Foundation (28).

395 CVEs published October 1, 2026: 41 critical, 166 high, 144 medium, 24 low; 1 in the KEV catalog at press time; 1 with a public exploit reference; 20 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 370 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published39550382——
KEV catalog size1731

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3267 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux06205530263871311560.17.8.00190
microsoft02901201199269216290311.17.8.00470
google02831356109612441318090.37.5.0027-26 ▼
red hat189175438642453200.06.7.0035+6 ▲
apple056467166317148991.66.5.00190
suse053827162000.07.5.0036-3 ▼
canonical0501612175000.07.8.00210
freebsd04823673000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0182547255160179.37.8.00460
ubiquiti065362810334.69.1.00500
palo alto networks0461426151324.34.7.00220
fortinet142121017330819.07.2.0040+1 ▲
netgear03400277000.04.3.00270
f502671441527.78.7.00500
ivanti0246162025520.88.8.01520
sonicwall019784019421.18.3.0050-2 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache28735163314239183320.37.5.0061+28 ▲
mozilla0379122169870900.08.8.0030-34 ▼
gitlab01047246211532.95.3.00340
drupal094119668411.15.7.00270
github023211100000.07.4.0054-3 ▼
docker0121830000.08.4.00170
wordpress0614103350.08.7.03920
eclipse022000000.09.3.00500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle0290558116605631012840.17.8.00360
ibm0102319647333618610.17.5.00370
adobe08308236437592150.67.5.00360
progress0661540110611.58.1.00460
zohocorp04262970000.08.3.01170
solarwinds0261853010415.49.1.00670
veeam01961030100.08.6.00420
servicenow0107300200.09.4.00360
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link07422281212300.08.5.01640
siemens052633103000.07.3.00260
synology046510256000.05.6.00320
rockwell automation04353260000.08.6.0029-16 ▼
advantech02021710000.08.6.00710
schneider electric01821150000.08.5.0044-4 ▼
hitachi energy0122460000.07.0.00250
abb0111640000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell03783417015222210.37.2.0027-13 ▼
nvidia030125206700000.07.8.0019-30 ▼
sourcecodester02370014295000.05.5.00420
openclaw022341148421000.07.1.00320
spring017013608314000.06.5.00330
mongodb0169699604100.07.1.00380
hewlett packard enterprise (hpe)01662280559110.67.2.0042-86 ▼
itsourcecode21550037118000.02.1.0033+2 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.929699.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-87902.197697.38.1
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-85102.075594.39.8
CVE-2026-79756.075294.38.7
CVE-2026-12269.069994.08.8
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9296KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
CVE-2026-7570310.0.0125
Most disclosures (vendor)
VendorCVEs
linux2115
microsoft1002
google636
oracle634
ibm404
red hat270
apple247
adobe224
apache223
dell194
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet8
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven112
npm18
Packagist17
PyPI14
crates.io9
Go4
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171779
CVE-2021-27102n/a2021-11-171779
CVE-2021-27101n/a2021-11-171779
CVE-2021-27103n/a2021-11-171779
CVE-2021-21017Adobe2021-11-171779
CVE-2021-28550Adobe2021-11-171779
CVE-2021-42013Apache Software Foundation2021-11-171779
CVE-2021-41773Apache Software Foundation2021-11-171779
CVE-2021-30858Apple2021-11-171779
CVE-2021-30860Apple2021-11-171779

Transactions

ADDED TO KEV — CVE-2026-104286 (Fortinet FortiMail). Remediation due October 4, 2026.

EXPLOIT PUBLISHED — Google Chrome: 14 CVEs (CVE-2026-95290, CVE-2026-95295, CVE-2026-95300, CVE-2026-95301, CVE-2026-95330, CVE-2026-95342, CVE-2026-95344, CVE-2026-95358, CVE-2026-95362, CVE-2026-95364, CVE-2026-95366, CVE-2026-95370, CVE-2026-95375, CVE-2026-95376). Public exploit references added.

EXPLOIT PUBLISHED — dolibarr: 9 CVEs (CVE-2026-71503, CVE-2026-71504, CVE-2026-71505, CVE-2026-71506, CVE-2026-71507, CVE-2026-71508, CVE-2026-71509, CVE-2026-71510, CVE-2026-71511). Public exploit references added.

EXPLOIT PUBLISHED — PassMark Software PerformanceTest: 7 CVEs (CVE-2026-80112, CVE-2026-80113, CVE-2026-80114, CVE-2026-80115, CVE-2026-80116, CVE-2026-80118, CVE-2026-80119). Public exploit references added.

EXPLOIT PUBLISHED — FileRun: 4 CVEs (CVE-2026-73693, CVE-2026-73694, CVE-2026-73698, CVE-2026-73699). Public exploit references added.

EXPLOIT PUBLISHED — Trusted Domain Project OpenDMARC: 4 CVEs (CVE-2026-100891, CVE-2026-101015, CVE-2026-101278, CVE-2026-101281). Public exploit references added.

EXPLOIT PUBLISHED — wazuh-manager: 4 CVEs (CVE-2026-74038, CVE-2026-74039, CVE-2026-74044, CVE-2026-74046). Public exploit references added.

EXPLOIT PUBLISHED — Softaculous Virtualizor: 3 CVEs (CVE-2026-43641, CVE-2026-43642, CVE-2026-43643). Public exploit references added.

EXPLOIT PUBLISHED — SPIP: 3 CVEs (CVE-2026-72708, CVE-2026-72709, CVE-2026-72710). Public exploit references added.

EXPLOIT PUBLISHED — Ziroom ZHOME A0101: 3 CVEs (CVE-2026-101261, CVE-2026-101264, CVE-2026-102793). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2010-0738. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2010-1428. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2010-2861. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2015-2291. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2016-20076 (ChrisHurst Simple Backup). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2018-19323. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2018-6882. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2019-25743 (Soliloquywp Soliloquy Lite). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2020-0796 (Microsoft Windows 10 Version 1903 for 32-bit Systems). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-21975 (VMware vRealize Operations). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-22175 (GitLab). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-27065 (Microsoft Exchange Server 2013 Cumulative Update 21). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-27925. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-30333. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-46805 (Ivanti ICS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54342 (Eclipse Equinox OSGi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54344 (Eclipse Equinox OSGi). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-58304 (SPA-CART CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-58387 (Inspur Haiyue HCM Cloud). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-62593 (ray-project ray). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100894 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100900 (DevaslanPHP project-management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100903 (ООО НПО Ритм GEOritm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100907 (Eyeplus). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101000 (Netcore NBR100V2). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101009 (aaPanel BaoTa). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101012 (mathurvishal CloudClassroom-PHP-Project). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101018 (dayrui XunruiCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101037 (FAST FAC1200R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101040 (Ricoh SP 330DN). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101054 (Thinkware U3000). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101067 (dbgate). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101070 (dbgate). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101073 (Netcore NR289-GE). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101076 (Netcore NR289-GE). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101079 (agentverus-scanner). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101132 (deepseek-harness). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101142 (Eleveo Quality Management). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101145 (Eleveo Call Recording Software). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101188 (Netcore POWER13). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101859 (raspap-webgui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-101878 (bitwarden server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102241 (Netcore NAP930). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102245 (MODSetter SurfSense). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102249 (REBUILD). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102361 (gz-yami mall4j). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102365 (gz-yami mall4j). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102373 (GestSup). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102507 (BishopFox sliver). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102805 (Nothings stb). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103113 (OS4ED openSIS-Classic). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-11553 (Tenda HG7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-22681 (Volcengine OpenViking). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-44402 (Voltronic Power SNMP Web Pro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48710 (Kludex starlette). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57517 (Control Web Panel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-57863 (crater-invoice-inc crater). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58143 (Cotonti). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-58144 (Cotonti). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-6958 (Invicti Security Corp. Acunetix). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-7006 (Sublime HQ Pty Ltd Sublime Text 4). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82524 (unopim). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82536 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-82537 (RooCodeInc Roo-Code). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93339 (Metaphor Creations Ditty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93353 (9001 copyparty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93355 (BerriAI litellm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95675 (D-LINK DAP-1360). Public exploit reference added.

DUE DATE PASSED — CVE-2026-88771 (Citrix NetScaler ADC). CISA remediation deadline was September 30, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-88772 (Citrix NetScaler ADC). CISA remediation deadline was September 30, 2026; still in catalog.

RESCORED — moodle: 5 CVEs (CVE-2026-102578, CVE-2026-102580, CVE-2026-102581, CVE-2026-102582, CVE-2026-102586). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2013-0431. CVSS 5.3 → 3.7 (NVD).

RESCORED — CVE-2015-3246. CVSS 5.1 → 7.4 (NVD).

RESCORED — CVE-2021-22175 (GitLab). CVSS 6.8 → 9.8 (NVD).

RESCORED — CVE-2023-27351 (PaperCut NG). CVSS 8.2 → 7.5 (NVD).

RESCORED — CVE-2024-7399 (Samsung Electronics MagicINFO 9 Server). CVSS 8.8 → 9.8 (NVD).

RESCORED — CVE-2024-9379 (Ivanti CSA (Cloud Services Appliance)). CVSS 6.5 → 7.2 (NVD).

RESCORED — CVE-2026-100268 (JetBrains YouTrack). CVSS 7.7 → 2.7 (NVD).

RESCORED — CVE-2026-10031 (drakkan SFTPGo). CVSS 2.3 → 5.3 (NVD).

RESCORED — CVE-2026-81438 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 3.7 → 7.5 (NVD).

RESCORED — CVE-2026-81439 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 3.7 → 6.5 (NVD).

RESCORED — CVE-2026-81440 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 7.3 → 9.8 (NVD).

RESCORED — CVE-2026-81441 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 4 → 5.5 (NVD).

RESCORED — CVE-2026-81475 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-81476 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-84440 (IBM Guardium Data Protection). CVSS 7.5 → 8.8 (NVD).

RESCORED — CVE-2026-94184 (Red Hat Enterprise Linux 10). CVSS 8.1 → 5.3 (NVD).

PATCH SHIPPED — Brocade SANnav: 8 CVEs (CVE-2026-14441, CVE-2026-14442, CVE-2026-14443, CVE-2026-82368, CVE-2026-82369, CVE-2026-82370, CVE-2026-82371, CVE-2026-82372). Fix versions published.

PATCH SHIPPED — CVE-2026-79654 (Red Hat Satellite 6.16 for RHEL 8). Fixed in Red Hat Satellite 6.16 for RHEL 8 0:4.14.0.23-1.el8sat.

Yesterday's Results

How to read these box scores · glossary

395 CVEs published. 25 box scores, 370 table rows — nothing truncated.

Fortinet FortiMail — An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet…
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —   YES
AFFECTED
  Product    Versions  Fixed
  FortiMail  8.0.0 –   —
TIMELINE
  Oct 1   Added to CISA KEV, due Oct 4
  Oct 1   Reserved by CNA
  Oct 1   Published (CNA: fortinet)
CWE-22 · CNA: fortinet · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis · KEV due October 4, 2026
Teledyne FLIR Aware2 — Local File Inclusion in Teledyne FLIR Robots running Aware2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0      —      —     —
AFFECTED
  Product  Versions     Fixed
  Aware2   unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Oct 1   Published (CNA: Mandiant)
CWE-22 · CNA: Mandiant · CVSS v4.0 · 1 reference · NVD status: Received
Unknown BackupSheep WordPress Backup Plugin — BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0      —      —     —
AFFECTED
  Product                              Versions     Fixed
  BackupSheep WordPress Backup Plugin  unspecified  —
TIMELINE
  Sep 28  Reserved by CNA
  Oct 1   Published (CNA: WPScan)
CWE-73 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
Fortra BoKS Manager boks-server — Predictable Active Directory service-account passwords in BoKS Manager
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9      —      —     —
AFFECTED
  Product                   Versions     Fixed
  BoKS Manager boks-server  unspecified  —
TIMELINE
  Aug 25  Reserved by CNA
  Oct 1   Published (CNA: Fortra)
CWE-338 · CNA: Fortra · CVSS v3.1 · 1 reference · NVD status: Deferred
Red Hat Red Hat Satellite 6.16 for RHEL 8 — Foreman: safemode bypass leading to rce
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9      —      —     —
AFFECTED
  Product                            Versions     Fixed
  Red Hat Satellite 6.16 for RHEL 8  unspecified  0:1.5.0-2.el8sat
  Red Hat Satellite 6.16 for RHEL 9  unspecified  0:1.5.0-2.el9sat
  Red Hat Satellite 6.18 for RHEL 9  unspecified  0:1.5.0-2.el9sat
  Red Hat Satellite 6.19 for RHEL 9  unspecified  0:3.18.0.14-1.el9sat
TIMELINE
  Sep 23  Reserved by CNA
  Oct 1   Published (CNA: redhat)
CWE-94 · CNA: redhat · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis
Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product                                         Versions   Fixed
  Fortra's Core Privileged Access Manager (BoKS)  8.1.0.0 –  —
TIMELINE
  Jun 18  Reserved by CNA
  Oct 1   Published (CNA: Fortra)
CWE-121 · CNA: Fortra · CVSS v3.1 · 1 reference · NVD status: Awaiting Analysis
WebRehab Super Forms – Drag & Drop Form Builder — Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product                                 Versions     Fixed
  Super Forms – Drag & Drop Form Builder  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Oct 1   Published (CNA: Wordfence)
CWE-269 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product             Versions  Fixed
  Apache HTTP Server  2.4.0 –   —
TIMELINE
  Jun 19  Reserved by CNA
  Oct 1   Published (CNA: apache)
CWE-416 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product             Versions  Fixed
  Apache HTTP Server  2.4.0 –   —
TIMELINE
  Jun 26  Reserved by CNA
  Oct 1   Published (CNA: apache)
CWE-416 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product             Versions  Fixed
  Apache HTTP Server  2.4.0 –   —
TIMELINE
  Jul 7   Reserved by CNA
  Oct 1   Published (CNA: apache)
CWE-269 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Awaiting Analysis
superdav42 Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform — Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product                                                        Versions     Fixed
  Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform  unspecified  —
TIMELINE
  Aug 18  Reserved by CNA
  Oct 1   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 13 references · NVD status: Deferred
Paul Ryan Authorizer — WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8      —      —     —
AFFECTED
  Product     Versions  Fixed
  Authorizer  n/a –     3.16.0
TIMELINE
  Oct 1   Reserved by CNA
  Oct 1   Published (CNA: Patchstack)
CWE-266 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
GetSimpleCMS-CE GetSimpleCMS-CE — GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   R  C  H  H  H    9.6      —      —     —
AFFECTED
  Product          Versions  Fixed
  GetSimpleCMS-CE  < 1.5 –   —
TIMELINE
  Jun 22  Reserved by CNA
  Oct 1   Published (CNA: GitHub_M)
CWE-352 · CNA: GitHub_M · CVSS v3.1 · 1 reference · NVD status: Deferred
ASUS Router — Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user …
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    9.4      —      —     —
AFFECTED
  Product  Versions              Fixed
  Router   3.0.0.6_102 series –  —
TIMELINE
  Jun 30  Reserved by CNA
  Oct 1   Published (CNA: ASUS)
CWE-134 · CNA: ASUS · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
Teledyne FLIR Aware2 — Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   A   L   N   N   N   H   H   H    9.4      —      —     —
AFFECTED
  Product  Versions     Fixed
  Aware2   unspecified  —
TIMELINE
  Jul 7   Reserved by CNA
  Oct 1   Published (CNA: Mandiant)
CWE-319 · CNA: Mandiant · CVSS v4.0 · 1 reference · NVD status: Received
Thales SConnect — SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4      —      —     —
AFFECTED
  Product   Versions     Fixed
  SConnect  unspecified  —
TIMELINE
  Jul 30  Reserved by CNA
  Oct 1   Published (CNA: THA-PSIRT)
CWE-130, CWE-252, CWE-347, CWE-457 · CNA: THA-PSIRT · CVSS v4.0 · 1 reference · NVD status: Received
Teledyne FLIR Aware2 — Hardcoded Passwords in Teledyne FLIR Robots running Aware2
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   A   L   N   N   N   H   H   H    9.4      —      —     —
AFFECTED
  Product  Versions     Fixed
  Aware2   unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Oct 1   Published (CNA: Mandiant)
CWE-798 · CNA: Mandiant · CVSS v4.0 · 1 reference · NVD status: Received
foundation50 classroom50 — Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    9.4      —      —     —
AFFECTED
  Product      Versions    Fixed
  classroom50  < 1.11.0 –  —
TIMELINE
  Sep 21  Reserved by CNA
  Oct 1   Published (CNA: GitHub_M)
CWE-22, CWE-59 · CNA: GitHub_M · CVSS v4.0 · 2 references · NVD status: Received
WAGO 0751-9x01 — Path traversal in dynamically created BACnet File Objects
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3      —      —     —
AFFECTED
  Product              Versions  Fixed
  0751-9x01            1.0.0 –   —
  0750-811x-xxxx-xxxx  1.0.0 –   —
  0750-821x-xxx-xxx    1.0.0 –   —
  0762-420x-8000-000x  1.0.0 –   —
  0762-430x-8000-000x  1.0.0 –   —
  0762-520x-8000-000x  1.0.0 –   —
  0762-530x-8000-000x  1.0.0 –   —
  0762-620x-8000-000x  1.0.0 –   —
  0762-630x-8000-000x  1.0.0 –   —
  0752-8303-8000-0002  1.0.0 –   —
  + 12 more
TIMELINE
  Apr 16  Reserved by CNA
  Oct 1   Published (CNA: CERTVDE)
CWE-22 · CNA: CERTVDE · CVSS v4.0 · 1 reference · NVD status: Awaiting Analysis
WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    9.3      —      —     —
AFFECTED
  Product            Versions     Fixed
  Endpoint Security  unspecified  —
TIMELINE
  Jun 23  Reserved by CNA
  Oct 1   Published (CNA: WatchGuard)
CWE-306, CWE-798 · CNA: WatchGuard · CVSS v4.0 · 1 reference · NVD status: Received
nickboss WordPress File Upload — WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS   EPSS   %ile   KEV
   N   L   N   N  C  H  N  L    9.3      —      —     —
AFFECTED
  Product                Versions  Fixed
  WordPress File Upload  n/a –     5.2.0
TIMELINE
  Jul 13  Reserved by CNA
  Oct 1   Published (CNA: Patchstack)
CWE-89 · CNA: Patchstack · CVSS v3.1 · 1 reference · NVD status: Deferred
Johnson Controls EasyIO FS32 — : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embed…
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3      —      —     —
AFFECTED
  Product      Versions     Fixed
  EasyIO FS32  unspecified  —
TIMELINE
  Aug 6   Reserved by CNA
  Oct 1   Published (CNA: jci)
CWE-321 · CNA: jci · CVSS v4.0 · 1 reference · NVD status: Received
Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   L   H   H    9.3      —      —     —
AFFECTED
  Product                            Versions  Fixed
  Genian NAC 5.0.75 LTS Release      135823 –  —
  Genian NAC 5.0.85 Release Stable   147181 –  —
  Genian NAC 5.0.86 Release          148018 –  —
  Genian ZTNA 6.0.35 LTS Release     135814 –  —
  Genian ZTNA 6.0.45 Release Stable  147169 –  —
  Genian ZTNA 6.0.46 Release         148028 –  —
TIMELINE
  Aug 19  Reserved by CNA
  Oct 1   Published (CNA: krcert)
CWE-284, CWE-306 · CNA: krcert · CVSS v4.0 · 2 references · NVD status: Deferred
Hitachi Industrial Equipment Systems Hitachi Coding Software Suite — Path traversal may allow arbitrary files to be viewed, created, modified, or deleted
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3      —      —     —
AFFECTED
  Product                        Versions     Fixed
  Hitachi Coding Software Suite  unspecified  4.0.0
TIMELINE
  Aug 31  Reserved by CNA
  Oct 1   Published (CNA: Hitachi)
CWE-35 · CNA: Hitachi · CVSS v4.0 · 1 reference · NVD status: Deferred
Hitachi Industrial Equipment Systems Hitachi Coding Software Suite — Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS   EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3      —      —     —
AFFECTED
  Product                        Versions     Fixed
  Hitachi Coding Software Suite  unspecified  4.0.0
TIMELINE
  Aug 31  Reserved by CNA
  Oct 1   Published (CNA: Hitachi)
CWE-306 · CNA: Hitachi · CVSS v4.0 · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-828279.3—Hitachi Industrial Equipment SystemsHitachi Coding Software SuiteCWE-321A hard-coded JWT signing secret key may allow administrative functions to be …
CVE-2026-828299.3—Hitachi Industrial Equipment SystemsHitachi Coding Software SuiteCWE-912Hidden accounts or hard-coded credentials may permit unauthorized access with…
CVE-2026-1032449.3—sgoudelisground-stationCWE-306ground-station before 0.8.0 Authentication Bypass via setup.restore
CVE-2026-1032649.3—fleetdmfleetCWE-287Fleet before 4.87.0 Authentication Bypass via Device Identifiers
CVE-2026-1036559.3—MISPMISPCWE-294MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period
CVE-2026-1037649.3—kvcache-aiMooncakeCWE-822Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/…
CVE-2026-1039229.3—ionic-teamcapacitorCWE-346Capacitor Android and iOS: remote content can be loaded at the app origin via…
CVE-2026-1026289.2—EummenaCadmos LTICWE-215Cadmos LTI exposure of sensitive information via debug mode
CVE-2026-539539.1—GetSimpleCMS-CEGetSimpleCMS-CECWE-338GetSimple CMS: Predictable Password Reset Password Allows Administrator Accou…
CVE-2026-550839.1—dhis2dhis2-coreCWE-502DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)
CVE-2026-566609.1—GetSimpleCMS-CEGetSimpleCMS-CECWE-352GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
CVE-2026-798989.1—FortraBoKS ManagerCWE-78Fortra BoKS Manager crlserver command injection vulnerability
CVE-2026-929669.1—latepointAppointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressCWE-94Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Exe…
CVE-2026-966599.1—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-267Foreman: excessive permissions for viewer role on preview
CVE-2026-863459.0—Red HatRed Hat Directory Server 11CWE-923389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path …
CVE-2026-1026679.0—JoylandJoyland.aiCWE-749Joyland AI WebView command injection
CVE-2026-133138.9—ASUSRouterCWE-489An Active Debug Code vulnerability in certain ASUS router models allows a rem…
CVE-2026-124058.8—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-78Rubygem-foreman_remote_execution: command injection in job invocations via ef…
CVE-2026-198078.8—bytecorestackByteCoreStack – MCP Connector for AI ToolsCWE-269ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via…
CVE-2026-662468.8—HCL SoftwareiControlCWE-250HCL iControl is affected by multiple security vulnerabilities
CVE-2026-706508.8—GetSimpleCMS-CEGetSimpleCMS-CECWE-79GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) vi…
CVE-2026-802758.8—Comelit Group S.p.A.1456B Multi-User GatewayCWE-425Comelit 1456B gateway allows low priviledge user to overwrite installer passw…
CVE-2026-935468.8—Apache Software FoundationApache HTTP ServerCWE-190Apache HTTP Server: mod_dav_fs namespace overflow
CVE-2026-956878.8—wpcleverWPC Shop as a Customer for WooCommerceCWE-269WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+)…
CVE-2026-972848.8—IcegramIcegramCWE-502WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability
CVE-2026-1011478.8—UnknownFeatured Image from URL (FIFU)CWE-352Featured Image from URL (FIFU) Free & Premium - Administrator Account Creatio…
CVE-2026-1030688.8—ByteCore StackByteCoreStack &#8211; MCP Connector for AI ToolsCWE-266WordPress ByteCoreStack – MCP Connector for AI Tools plugin <= 1.2.2 - Privil…
CVE-2026-1034848.8—n/apgvectorCWE-787pgvector buffer overflow in IVFFlat index build
CVE-2026-1037658.8—kvcache-aiMooncakeCWE-306Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
CVE-2026-1040188.8—Wind River Systems IncVxWorks 7CWE-269VxWorks 7 improper privilege management
CVE-2026-1040518.8—HaschekSolutionspictshareCWE-522PictShare < 3.7.1 Sensitive Information Disclosure via info API
CVE-2024-583888.7—Sharp CorporationMultiple Multifunction PrintersCWE-22Sharp Multifunction Printers Local File Inclusion via installed_emanual_down.…
CVE-2026-192538.7—UnknownCache EnablerCWE-73Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletio…
CVE-2026-540498.7—sakaiprojectsakaiCWE-79Sakai Conversations has a Stored XSS Issue
CVE-2026-552308.7—givanzVvvebCWE-79Vvveb: Stored XSS in Vvveb via sanitizeHTML() filter bypass using a quoted gr…
CVE-2026-715428.7—GetSimpleCMS-CEGetSimpleCMS-CECWE-79GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in…
CVE-2026-828268.7—Hitachi Industrial Equipment SystemsHitachi Coding Software SuiteCWE-319Authentication information or sensitive data may be intercepted in transit
CVE-2026-828288.7—Hitachi Industrial Equipment SystemsHitachi Coding Software SuiteCWE-863Improper authorization may allow a general user to perform operations equival…
CVE-2026-1023698.7—TP-Link Systems Inc.Tapo C200 v5CWE-287Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Lin…
CVE-2026-1032628.7—tornadowebtornadoCWE-409Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient
CVE-2026-1032688.7—TryGhostGhostCWE-862Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset
CVE-2026-1032718.7—TryGhostGhostCWE-863Ghost 4.0.0 before 6.63.0 Restricted Content Bypass
CVE-2026-1032728.7—TryGhostGhostCWE-203Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API
CVE-2026-1037618.7—kvcache-aiMooncakeCWE-770Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded…
CVE-2026-1040208.7—Amazonion-pythonCWE-674Uncontrolled recursion in the Ion reader in Amazon Ion Python
CVE-2026-1040578.7—akhilrexpodgrabCWE-362Podgrab Unauthenticated DoS via Concurrent Map Access in WebSocket Handler
CVE-2026-649498.6—Pandora FMSPandora FMSCWE-434Unrestricted File Upload Leading to Remote Code Execution in Admin Tools File…
CVE-2026-887898.6—Apache Software FoundationApache Camel QuarkusCWE-611Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops up…
CVE-2026-892968.6—UnknownPro Like ButtonCWE-89Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter
CVE-2026-955888.6—AcyMailing Newsletter TeamAcyMailing SMTP NewsletterCWE-22WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Arbitrary File Deleti…
CVE-2026-1018888.6—CodexonicsPrime MoverCWE-22Prime Mover < 2.2.1 Zip Slip Path Traversal File Write
CVE-2026-1032778.6—TryGhostGhostCWE-79Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed
CVE-2026-1032838.6—TryGhostGhostCWE-613Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling
CVE-2026-1032928.6—TryGhostGhostCWE-79Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head
CVE-2026-1037588.6—obot-platformobotCWE-863Obot 0.21.1 through 0.24.1 Authorization Bypass via /mcp-connect-composite/ R…
CVE-2026-1037668.6—MacWarriorclipbucket-v5CWE-89ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Par…
CVE-2026-553968.5—Teledyne FLIRAware2CWE-319Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2
CVE-2026-1022948.5—TP-Link System Inc.TL-WR841N v14CWE-78Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration
CVE-2026-1023798.5—VillaThemeBuildKit – Product Builder for WooCommerce – Custom PC BuilderCWE-89WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plug…
CVE-2026-1032598.5—n8n-ion8nCWE-863n8n before 2.39.6 and 2.40.x before 2.40.1 Session Token Leak via Dynamic Cre…
CVE-2026-1032788.5—TryGhostGhostCWE-23Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
CVE-2026-1032868.5—TryGhostGhostCWE-266Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications
CVE-2026-1033388.5—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-89WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-649508.4—Pandora FMSPandora FMSCWE-79Stored Cross-Site Scripting via Directory Name in File Manager Create Directory
CVE-2026-739758.4—4TUResearchDatadjehutyCWE-943djehuty: Authenticated SPARQL injection in session editing allows writing arb…
CVE-2026-761468.4—Genians, IncGenian SSL PNS (xenics_auther)CWE-78Genians, Inc Genian SSL PNS OS Command Injection
CVE-2026-1025148.4—PeaZipPeaZipCWE-787Out-of-bounds write in PeaZip PEA extractor allows code execution via a craft…
CVE-2026-1013228.3—Eclipse FoundationEclipse BaSyx AAS Web UICWE-201In Eclipse BaSyx AAS Web UI versions v2-241220 through releases before v2-260…
CVE-2026-1032468.3—n8n-ion8nCWE-639n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Too…
CVE-2026-1037578.3—BudibasebudibaseCWE-918Budibase before 3.41.0 SSRF via uploadUrl in AI Table Generation
CVE-2023-544048.2—colinhackszodCWE-770Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation
CVE-2026-125408.2—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-78Foreman: command injection in foreman-rake errors:fetch_log via request_id pa…
CVE-2026-125418.2—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-78Foreman: command injection in foreman-rake database tasks
CVE-2026-942508.2—Apache Software FoundationApache APISIXCWE-770Apache APISIX: Batch response aggregation can exhaust worker memory
CVE-2026-967808.2—patorjkfiglet.jsCWE-835figlet is vulnerable to denial of service via unbounded loop when whitespaceB…
CVE-2026-1032638.2—tornadowebtornadoCWE-59Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink
CVE-2026-1037608.2—kvcache-aiMooncakeCWE-400Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Hands…
CVE-2026-1043568.2—HaschekSolutionspictshareCWE-338PictShare < 3.7.1 Predictable Delete Code via rand()
CVE-2026-143168.1—FortraCore Privileged Access Manager (BoKS)CWE-122Heap buffer overflow in boks_sshd revoked-key error handling
CVE-2026-159838.1—WebRehabSuper Forms – Drag & Drop Form BuilderCWE-73Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory…
CVE-2026-736368.1—Apache Software FoundationApache HTTP ServerCWE-294Apache HTTP Server: mod_auth_digest one-time-nonce replay attack
CVE-2026-1032578.1—n8n-ion8nCWE-22n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node
CVE-2026-1034938.1—JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX co…
CVE-2026-1030678.0—MemberfulMemberful - Membership PluginCWE-352WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request…
CVE-2026-798997.9—FortraBoKS ManagerCWE-377Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
CVE-2026-86187.7—TP-Link Systems Inc.Deco M9 Plus V2CWE-121Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv…
CVE-2026-125447.7—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-502Foreman: ssti and insecure deserialization in foreman-rake configuration
CVE-2026-846827.7—TP-Link Systems Inc.Archer AX90 v1CWE-78TDDPv2 setProductVer Command Injection in Archer AX90
CVE-2026-1034317.7——collectlCWE-150Collectl: collectl: colmux does not sanitize ansi/vt100 terminal escape seque…
CVE-2025-714277.6—GongRzheOffice-PowerPoint-MCP-ServerCWE-22Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentati…
CVE-2026-552327.6—givanzVvvebCWE-918Vvveb: Server-side request forgery in Vvveb via IPv6 bypass of validateUrl() …
CVE-2026-620597.6—Ultimate MemberUltimate MemberCWE-89WordPress Ultimate Member plugin <= 2.13.1 - SQL Injection vulnerability
CVE-2026-620607.6—captivateaudioCaptivate SyncCWE-89WordPress Captivate Sync plugin <= 3.3.2 - SQL Injection vulnerability
CVE-2026-972777.6—Apps MavSocial BoostCWE-862WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability
CVE-2026-972977.6—Apps MavGratisfactionCWE-862WordPress Gratisfaction plugin <= 4.6.3 - Broken Access Control vulnerability
CVE-2026-1032797.6—TryGhostGhostCWE-613Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass
CVE-2026-1036517.6—MISPMISPCWE-287MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor …
CVE-2026-124237.5—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-306Foreman: unauthenticated information disclosure via provisioning token valida…
CVE-2026-467297.5—Apache Software FoundationApache HTTP ServerCWE-476Apache HTTP Server: mod_heartmonitor denial of service
CVE-2026-473607.5—Apache Software FoundationApache HTTP ServerCWE-200Apache HTTP Server: mod_session: Session cookie not removed during internal r…
CVE-2026-480057.5—Apache Software FoundationApache HTTP ServerCWE-306Apache HTTP Server: mod_auth_digest reauthentication attack
CVE-2026-561537.5—Apache Software FoundationApache HTTP ServerCWE-787Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char
CVE-2026-564497.5—Apache Software FoundationApache HTTP ServerCWE-787Apache HTTP Server: mod_proxy_html: crash in dump_content
CVE-2026-566617.5—GetSimpleCMS-CEGetSimpleCMS-CECWE-918GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
CVE-2026-596857.5—Apache Software FoundationApache HTTP ServerCWE-787Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name…
CVE-2026-620737.5—ThemeisleWP Full Stripe FreeCWE-862WordPress WP Full Stripe Free plugin <= 8.5.6 - Broken Access Control vulnera…
CVE-2026-630457.5—Apache Software FoundationApache HTTP ServerCWE-284Apache HTTP Server: mod_proxy_ftp PASV address handling
CVE-2026-632927.5—Apache Software FoundationApache HTTP ServerCWE-121Apache HTTP Server: mod_vhost_alias stack overflow
CVE-2026-636867.5—Apache Software FoundationApache HTTP ServerCWE-476Apache HTTP Server: mod_xml2enc crash on charset conversion failure
CVE-2026-637187.5—Apache Software FoundationApache HTTP ServerCWE-444Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
CVE-2026-649477.5—Pandora FMSPandora FMSCWE-352CSRF Bypass Leading to Remote Code Execution via Unrestricted File Upload in …
CVE-2026-684957.5—FasterXMLjackson-dataformats-binaryCWE-400jackson-dataformats-binary: CBOR parser does not enforce StreamReadConstraint…
CVE-2026-684967.5—FasterXMLjackson-dataformats-binaryCWE-400jackson-dataformats-binary: Smile parser does not enforce StreamReadConstrain…
CVE-2026-761457.5—Genians, IncGenian SSL PNS (frodo-core)CWE-269Genians, Inc Genian SSL PNS Improper Privilege Management
CVE-2026-798967.5—FortraBoKS ManagerCWE-125Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerabi…
CVE-2026-802767.5—Comelit Group S.p.A.1456B Multi-User GatewayCWE-306Comelit 1456B gateway exposes remote configuration password via unauthenticat…
CVE-2026-817397.5—UnknownPaytm Payment GatewayCWE-79Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback
CVE-2026-818097.5—UnknownPaytm Payment GatewayCWE-89Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback
CVE-2026-863447.5—Red HatRed Hat Directory Server 11CWE-400389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via c…
CVE-2026-922457.5—croixhaugSimply Schedule AppointmentsCWE-862Simply Schedule Appointments <= 1.6.12.32 - Missing Authorization to Unauthen…
CVE-2026-938827.5—thimpressLearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-639LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sen…
CVE-2026-962557.5—UnknownPayments for HubtelCWE-200Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Dis…
CVE-2026-1005147.5—Pete NelsonREST API LogCWE-639WordPress REST API Log plugin <= 1.7.2 - Insecure Direct Object References (I…
CVE-2026-1005177.5—VillaThemePhoto Reviews for WooCommerceCWE-639WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Insecure Direct Ob…
CVE-2026-1025047.5——ImagerCWE-190Imager versions before 1.037 for Perl exit the process reading a raw image wi…
CVE-2026-1032517.5—n8n-ion8nCWE-862n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via…
CVE-2026-159117.4—confluentconfluent-kafkaCWE-295Confluent Kafka Python Improper TLS Certificate Validation
CVE-2026-649467.4—Pandora FMSPandora FMSCWE-79CSRF Bypass Leading to Stored Cross-Site Scripting via Unrestricted SVG Uploa…
CVE-2026-671057.4—HCL SoftwareHCL BigFix Service ManagementCWE-319HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-1039217.4—ardatangraphql-toolsCWE-295GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocke…
CVE-2026-648937.3—Johnson ControlsEasyIO NEOCWE-319- Cleartext Transmission of Sensitive Information vulnerability in Johnson Co…
CVE-2026-736377.3—Apache Software FoundationApache HTTP ServerCWE-416Apache HTTP Server: mod_auth_digest DoS attack
CVE-2026-761437.3—Genians, IncGenian SSL PNS (frodo-core)CWE-862Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass
CVE-2026-149957.2—optimizingmattersAutoptimizeCWE-79Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQ…
CVE-2026-344937.2—Johnson ControlsEasyIO FS32CWE-1191- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allow…
CVE-2026-344947.2—Johnson ControlsNeo Series MVP2CWE-1191- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 a…
CVE-2026-539647.2—adfinisdocument-merge-serviceCWE-1336Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
CVE-2026-552317.2—givanzVvvebCWE-22Vvveb: Path traversal in Vvveb via sanitizeFileName() bypass enables arbitrar…
CVE-2026-565897.2—HCL SoftwareHCL BigFix Service ManagementCWE-79HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-714527.2—Johnson ControlsEasyIO FS32CWE-78- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows O…
CVE-2026-757867.2—Pandora FMSPandora FMSCWE-89SQL Injection in Grafana Integration Endpoint (query.php)
CVE-2026-852357.2—wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-856797.2—extendifyExtendifyCWE-79Extendify <= 3.1.6 - Unauthenticated Stored Cross-Site Scripting via 'styles.…
CVE-2026-921447.2—wpmudevForminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-922447.2—wpovernightPDF Invoices & Packing Slips for WooCommerceCWE-79PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stor…
CVE-2026-943907.2—DotstoreHide Shipping Method For WooCommerceCWE-502WordPress Hide Shipping Method For WooCommerce plugin <= 1.5.4 - PHP Object I…
CVE-2026-965617.2—tigroumeowAI Engine – The Chatbot, AI Framework & MCP for WordPressCWE-79AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_'…
CVE-2026-965737.2—codepeopleAppointment Hour Booking – Booking CalendarCWE-79Appointment Hour Booking <= 1.5.97 - Unauthenticated Stored DOM-Based Cross-S…
CVE-2026-968137.2—10webForm Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-79Form Maker by 10Web <= 1.15.47 - Unauthenticated Stored Cross-Site Scripting …
CVE-2026-976617.2—scottpatersonBusiness Essentials for Contact Form 7CWE-79Business Essentials for Contact Form 7 <= 1.2.1 - Unauthenticated Stored Cros…
CVE-2026-1030827.2—LA-StudioLA-Studio Element Kit for ElementorCWE-918WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side R…
CVE-2026-1034907.2—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible v…
CVE-2026-90327.1—TP-Link Systems Inc.Tapo C200 V5CWE-476Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service…
CVE-2026-149837.1—Teledyne FLIRAware2CWE-306Missing Authentication in Teledyne FLIR Robots running Aware2
CVE-2026-649487.1—Pandora FMSPandora FMSCWE-639Missing Authorization in get_module_detail AJAX Endpoint Allows Cross-Group M…
CVE-2026-714267.1—GetSimpleCMS-CEGetSimpleCMS-CECWE-22GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "temp…
CVE-2026-739767.1—4TUResearchDatadjehutyCWE-943djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operat…
CVE-2026-782107.1—Octopus DeployOctopus ServerCWE-863In affected versions of Octopus Server, users with certain scoped permission …
CVE-2026-785787.1—TP-Link Systems Inc.Tapo C200 v5CWE-306Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Den…
CVE-2026-823577.1—RT-Labs ABC-OpenCWE-476RT-Labs AB C-Open CANopen NULL pointer dereference
CVE-2026-823587.1—RT-Labs ABC-OpenCWE-863RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass
CVE-2026-924127.1—UnknownFive Star Restaurant ReviewsCWE-79Five Star Restaurant Reviews < 2.3.14 - Reflected XSS
CVE-2026-965777.1—Red HatAssisted Installer for Red Hat OpenShift Container Platform 2CWE-306Oc-mirror__release-4.21: embedded local cache registry listens on all interfa…
CVE-2026-972607.1—maxfoundryMaxGalleriaCWE-79WordPress MaxGalleria plugin <= 6.5.3 - Cross Site Scripting (XSS) vulnerability
CVE-2026-972687.1—PremmercePremmerce Wishlist for WooCommerceCWE-79WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Sc…
CVE-2026-972737.1—PremmercePremmerce Wishlist for WooCommerceCWE-79WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.13 - Cross Site Sc…
CVE-2026-1023787.1—bPluginsParallax Section blockCWE-79WordPress Parallax Section block plugin <= 2.0.4 - Cross Site Scripting (XSS)…
CVE-2026-1032487.1—n8n-ion8nCWE-89n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase
CVE-2026-1032527.1—n8n-ion8nCWE-639n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential…
CVE-2026-1032557.1—n8n-ion8nCWE-73n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection vi…
CVE-2026-1032567.1—n8n-ion8nCWE-522n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentica…
CVE-2026-1032667.1—TryGhostGhostCWE-863Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification
CVE-2026-1032887.1—TryGhostGhostCWE-639Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
CVE-2026-1032897.1—TryGhostGhostCWE-943Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments
CVE-2026-1034887.1—JetBrainsYouTrackCWE-863In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authe…
CVE-2026-1036597.1—MISPMISPCWE-285MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisatio…
CVE-2026-934957.0—ASUSMotherboard(PRIME Z390-A )CWE-665Improper initialization in an ASUS certain motherboard allows an physically p…
CVE-2026-1018897.0—CodexonicsPrime MoverCWE-22Prime Mover < 2.2.1 Path Traversal via wprime-config.json
CVE-2026-1032507.0—n8n-ion8nCWE-943n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory
CVE-2026-1032537.0—n8n-ion8nCWE-89n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Dro…
CVE-2026-1032547.0—n8n-ion8nCWE-22n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation
CVE-2026-1040597.0—lektorlektorCWE-352Lektor 3.3.14 CSRF via Admin API Endpoints
CVE-2026-976626.9—AWSsecurity-agent-mcp-serverCWE-73Argument injection in the diff scan operation in AWS security-agent-mcp-serve…
CVE-2026-1002516.9—Wormhole AppWormholeCWE-918Wormhole.app SSRF
CVE-2026-1026666.9—JoylandJoyland.aiCWE-798Joyland AI hard-coded credentials for push notifications
CVE-2026-1026686.9—JoylandJoyland.aiCWE-295Joyland AI accepts TLS certificates without validation
CVE-2026-1026696.9—JoylandJoyland.aiCWE-297Joyland AI hostname checking disabled
CVE-2026-1026716.9—JoylandJoyland.aiCWE-295Joyland AI WebView accepts invalid SSL certificates
CVE-2026-1032456.9—n8n-ion8nCWE-347n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification
CVE-2026-1032496.9—n8n-ion8nCWE-79n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator
CVE-2026-1032586.9—n8n-ion8nCWE-943n8n before 2.39.6 and 2.40.x before 2.40.1 Filter Bypass via Parameter Interp…
CVE-2026-1032616.9—tornadowebtornadoCWE-770Tornado before 6.5.9 Denial of Service via Query String
CVE-2026-1032696.9—TryGhostGhostCWE-862Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts
CVE-2026-1032746.9—TryGhostGhostCWE-862Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read
CVE-2026-1032766.9—TryGhostGhostCWE-173Ghost before 6.20.0 File Read via URL Encoding Bypass
CVE-2026-1032806.9—TryGhostGhostCWE-201Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint
CVE-2026-1035056.9—AWSaws-efs-csi-driverCWE-88AWS EFS CSI Driver Mount Option Injection via mounttargetipmap
CVE-2026-1035326.9—immich-appImmichCWE-266immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess imprope…
CVE-2026-782496.8—Fujifilm Business Innovation Corp.Apeos 3060 / 2560 / 1860 Japan modelCWE-22A path traversal vulnerability exists in the web management interface of mult…
CVE-2026-125456.7—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-78Rubygem-hammer_cli: command injection via insecure editor invocation
CVE-2026-1034946.6—JetBrainsYouTrackCWE-266In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible v…
CVE-2026-552516.5—netbox-communitydevicetype-libraryCWE-94NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Mal…
CVE-2026-560976.5—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-89Rubygem-katello: sql injection in registry proxy via labels
CVE-2026-670756.5—HCLSoftwareDigital ExperienceCWE-79HCL Digital Experience is affected by improper input sanitation
CVE-2026-799006.5—FortraBoKS Manager boks-serverCWE-787Heap overflow in KSL checksum initialization
CVE-2026-909746.5—UnknownWP Fusion LiteCWE-862WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings U…
CVE-2026-911096.5—croixhaugSimply Schedule AppointmentsCWE-639Simply Schedule Appointments <= 1.6.12.31 - Insecure Direct Object Reference …
CVE-2026-972516.5—magepeopleteamBus Ticket Booking with Seat ReservationCWE-639WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.9.3 - Insecure…
CVE-2026-972586.5—Aruba.itAruba Migration ToolCWE-862WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulner…
CVE-2026-972696.5—WPFunnelsWPFunnelsCWE-639WordPress WPFunnels plugin <= 3.13.1 - Insecure Direct Object References (IDO…
CVE-2026-972806.5—Mamunur RashidReview SchemaCWE-862WordPress Review Schema plugin 3.1.0 - Broken Access Control vulnerability
CVE-2026-1023946.5—WPDeveloperEssential Addons for ElementorCWE-79WordPress Essential Addons for Elementor plugin <= 6.8.4 - Cross Site Scripti…
CVE-2026-1030636.5—WpmetElementsKit Elementor addons LiteCWE-79WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scri…
CVE-2026-1030646.5—WpmetElementsKit Elementor addons LiteCWE-79WordPress ElementsKit Elementor addons Lite plugin <= 4.0.6 - Cross Site Scri…
CVE-2026-1033396.5—WpmetMetformCWE-79WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1033436.5—WP ManageNinja LLCFluentFormCWE-79WordPress FluentForm plugin <= 6.2.14 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1034916.5—JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API al…
CVE-2026-1034926.5—JetBrainsYouTrackCWE-835In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted…
CVE-2026-1036796.5——tnefCWE-416Tnef: use-after-free and double-free in get_body_files() via multi-value body…
CVE-2026-1038846.5—Red HatRed Hat Build of KeycloakCWE-22Keycloak-services: keycloak-services: path traversal in x.509 crl distributio…
CVE-2026-866106.4—UnknownDownload ManagerCWE-79Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon
CVE-2026-894246.4—inisevDuplicate PostCWE-79Duplicate Post <= 1.5.6 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-909926.4—davidandersonRedux FrameworkCWE-79Redux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scr…
CVE-2026-942126.4—Apache Software FoundationApache APISIXCWE-347Apache APISIX: unauthenticated impersonation issue in saml-auth
CVE-2026-962566.4—wpdevteamGutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-79Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cro…
CVE-2026-962686.4—awesomesupportAwesome Support – WordPress HelpDesk & Support PluginCWE-79Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scri…
CVE-2026-1019256.4—robin-wbbp style packCWE-79bbp style pack <= 6.4.8 - Authenticated (Subscriber+) Stored Cross-Site Scrip…
CVE-2026-648926.3—Johnson ControlsEasy IO NeoCWE-200- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO…
CVE-2026-942696.3—Apache Software FoundationApache APISIXCWE-647Apache APISIX: Servlet-style normalization creates a route/upstream authoriza…
CVE-2026-972816.3—weDevsWP Project ManagerCWE-862WordPress WP Project Manager plugin <= 4.0.7 - Broken Access Control vulnerab…
CVE-2026-1025056.3——ImagerCWE-131Imager versions before 1.037 for Perl overflow a heap buffer fetching float s…
CVE-2026-1030046.3—vercelnext.jsCWE-524next.js cache leak on warm `use cache` handlers accessing root param
CVE-2026-1032606.3—n8n-ion8nCWE-862n8n before 2.39.6 and 2.40.x before 2.40.1 Approval Bypass via Send and Wait …
CVE-2026-1040586.3—akhilrexpodgrabCWE-306Podgrab Missing Authentication on WebSocket /ws Endpoint
CVE-2026-1041826.2—uhopstream-jsonCWE-407stream-json: JSONC parser and verifier re-scan the whole accumulated comment …
CVE-2026-199026.1—spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-79Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dyn…
CVE-2026-835896.1—Red HatRed Hat OpenShift Container Platform 4CWE-601Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect
CVE-2026-890476.1—inisevSocial Media Share Buttons & Social Sharing IconsCWE-79Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Ba…
CVE-2026-894276.1—spacetimeAd Inserter – Ad Manager & AdSense AdsCWE-79Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via 's' Search Parameter
CVE-2026-1001796.1—codepeopleCalculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & MoreCWE-79Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting …
CVE-2026-1040026.0—AWSpowertools-lambda-pythonCWE-390Fail-open error handling in the data masking utility in Powertools for AWS La…
CVE-2026-341895.9—Pandora FMSPandora FMSCWE-352CSRF in Event Response Deletion
CVE-2026-341905.9—Pandora FMSPandora FMSCWE-352CSRF in Alert Command Deletion
CVE-2026-761475.9—Genians, IncGenian NAC 4.0.175 ReleaseCWE-22Genians, Inc Genian NAC/ZTNA Remote Code Execution
CVE-2026-1037545.9—Red HatRed Hat Ansible Automation Platform 2CWE-22Ansible-runner: ansible-runner: path traversal and symlink escape in unstream…
CVE-2026-714545.8—CWE-79 - Cross-site ScriptingCAPEC-63CWE-79Improper neutralization of input during web page generation ('cross-site scri…
CVE-2026-1032475.8—n8n-ion8nCWE-639n8n before 1.123.80 Credential Tampering via Duplicate Node IDs
CVE-2026-782425.7—Apache Software FoundationApache APISIXCWE-532Apache APISIX: data-mask may fail to redact request headers in logger output
CVE-2026-278725.6—Johnson ControlsEasy IO FGCWE-269EasyIO FG
CVE-2026-278735.6—Johnson ControlsEasyIO FGCWE-798- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG a…
CVE-2026-714485.6—Johnson ControlsEasyIO FS32CWE-1188: Insecure Default Initialization of Resource vulnerability in Johnson Contro…
CVE-2026-714515.6—Johnson ControlsEasyIO FS32CWE-78- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows -…
CVE-2026-714535.6—Johnson ControlsEasyIO FS32CWE-73- External Control of File Name or Path vulnerability in Johnson Controls Eas…
CVE-2026-1034975.5—JetBrainsYouTrackCWE-918In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VC…
CVE-2026-1035365.5—ZongXRSupermarketCWE-287ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrde…
CVE-2026-1035385.5—ZongXRSuperMarketCWE-287ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderControll…
CVE-2026-1036415.5—Red HatRed Hat Enterprise Linux 10CWE-125Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanl…
CVE-2026-1036875.5—rhuksterdom-sanitizerCWE-183rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete black…
CVE-2026-122415.4—mihail-barinovAdvanced Woo Labels – Product Labels & Badges for WooCommerceCWE-79Advanced Woo Labels – Product Labels & Badges for WooCommerce <= 2.51 - Impro…
CVE-2026-620635.4—Magepeople inc.WpTravellyCWE-862WordPress WpTravelly plugin <= 2.3.1 - Broken Access Control vulnerability
CVE-2026-909725.4—UnknownWP Fusion LiteCWE-284WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CR…
CVE-2026-1023705.4—TP-Link Systems Inc.Kasa EC70 V4CWE-1191Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa…
CVE-2026-1034965.4—JetBrainsYouTrackCWE-639In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed readi…
CVE-2026-1036785.4——tnefCWE-125Tnef: heap out-of-bounds read in get_rtf_data_from_buf() via uncompressed rtf…
CVE-2026-1041815.4—filamentphpfilamentCWE-306Filament: Multi-factor authentication (app) management actions do not require…
CVE-2026-125425.3—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-78Foreman: command injection in foreman-tail
CVE-2026-553945.3—Teledyne FLIRAware2CWE-319Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2
CVE-2026-584155.3—Apache Software FoundationApache HTTP ServerCWE-552Apache HTTP Server: mod_dav_fs property database read access
CVE-2026-620585.3—WPExpertsCF7 AppsCWE-201WordPress CF7 Apps plugin <= 3.7.2 - Sensitive Data Exposure vulnerability
CVE-2026-620615.3—MetagaussProfileGridCWE-639WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (…
CVE-2026-671045.3—HCL SoftwareHCL BigFix Service ManagementCWE-200HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-671065.3—HCL SoftwareHCL BigFix Service ManagementCWE-200HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-671715.3—HCL SoftwareHCL BigFix Service ManagementCWE-200HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-785775.3—TP-Link Systems Inc.Tapo C200 v5CWE-306Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 &…
CVE-2026-797685.3—Apache Software FoundationApache HTTP ServerCWE-55Apache HTTP Server: mod_userdir information disclosure
CVE-2026-828065.3—Apache Software FoundationApache APISIXCWE-488Apache APISIX: cross-request permission pollution via static permission list …
CVE-2026-925375.3—satolloNewsletter – Send awesome emails from WordPressCWE-522Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials vi…
CVE-2026-925485.3—hcabreraWP Popular PostsCWE-200WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_t…
CVE-2026-961735.3—UnknownPayments for HubtelCWE-639Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR
CVE-2026-962005.3—UnknownPayments for HubtelCWE-862Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery vi…
CVE-2026-1023815.3—AhmadMajestic SupportCWE-862WordPress Majestic Support plugin <= 1.2.0 - Broken Access Control vulnerability
CVE-2026-1023905.3—VillaThemeAFFI – Affiliate Marketing for WooCommerceCWE-862WordPress AFFI – Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken…
CVE-2026-1026705.3—JoylandJoyland.aiCWE-319Joyland AI enables HTTP
CVE-2026-1032655.3—fleetdmfleetCWE-863Fleet before 4.89.0 Information Disclosure via MDM Command Results
CVE-2026-1032675.3—TryGhostGhostCWE-807Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite
CVE-2026-1032735.3—TryGhostGhostCWE-863Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token
CVE-2026-1032755.3—TryGhostGhostCWE-203Ghost 5.42.2 before 6.58.0 Password Hash Disclosure
CVE-2026-1032815.3—TryGhostGhostCWE-201Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API
CVE-2026-1032825.3—TryGhostGhostCWE-362Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token
CVE-2026-1032845.3—TryGhostGhostCWE-863Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback
CVE-2026-1032855.3—TryGhostGhostCWE-352Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery
CVE-2026-1032915.3—TryGhostGhostCWE-918Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch
CVE-2026-1033365.3—Smackcoders Inc.WP Ultimate CSV ImporterCWE-201WordPress WP Ultimate CSV Importer plugin <= 9.1 - Sensitive Data Exposure vu…
CVE-2026-1033405.3—Gemini LabsSite ReviewsCWE-862WordPress Site Reviews plugin <= 8.3.2 - Broken Access Control vulnerability
CVE-2026-1033415.3—Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-862WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-1033455.3—Shamim RajaniPie RegisterCWE-201WordPress Pie Register plugin <= 3.8.4.13 - Sensitive Data Exposure vulnerabi…
CVE-2026-1033475.3—hcaptchahCaptcha for WPCWE-290WordPress hCaptcha for WP plugin <= 5.3.0 - Bypass Vulnerability vulnerability
CVE-2026-1033535.3—WP ManageNinja LLCFluentFormCWE-696WordPress FluentForm plugin <= 6.2.14 - Broken Access Control vulnerability
CVE-2026-1038585.3—MISPMISPCWE-285MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access…
CVE-2026-552525.1—openrundevopenrunCWE-601OpenRun: Redirect URL validation bypass using //host paths leads to Open Redi…
CVE-2026-942765.1—Apache Software FoundationApache APISIXCWE-287Apache APISIX: Openid-connect introspection validation issue
CVE-2026-1018905.1—CodexonicsPrime MoverCWE-79Prime Mover < 2.2.1 Stored XSS via Package Metadata
CVE-2026-1032875.1—TryGhostGhostCWE-918Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook
CVE-2026-1032905.1—TryGhostGhostCWE-35Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize
CVE-2026-1035315.1—n/aOpenSCCWE-119OpenSC card-setcos.c setcos_construct_fci_44 stack-based overflow
CVE-2026-1036625.1—MISPMISPCWE-79MISP Reflected XSS in Taxonomy Tag Confirmation Forms
CVE-2026-1041835.1—uhopstream-jsonCWE-1321stream-json: Prototype pollution: Assembler writes this.current[this.key] on …
CVE-2026-278745.0—Johnson ControlsEasyIO FS32CWE-798: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32…
CVE-2026-71734.8—CrocanticketsEntradiumCWE-79Multiple vulnerabilities in Entradium by Crocantickets
CVE-2026-71744.8—CrocanticketsEntradiumCWE-79Multiple vulnerabilities in Entradium by Crocantickets
CVE-2026-71754.8—CrocanticketsEntradiumCWE-79Multiple vulnerabilities in Entradium by Crocantickets
CVE-2026-71764.8—CrocanticketsEntradiumCWE-79Multiple vulnerabilities in Entradium by Crocantickets
CVE-2026-98644.8—FortraCore Privileged Access Manager (BoKS)CWE-338Fortra BoKS Server Agent adjoin machine-account password generation vulnerabi…
CVE-2026-938324.8—MotorolaSetup AppCWE-862A component of one of the Motorola system applications was exported without p…
CVE-2026-1036644.8—MISPMISPCWE-79MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter
CVE-2026-879704.7—UnknownIf-So Dynamic ContentCWE-79If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes
CVE-2026-1001844.7—codepeopleCalculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & MoreCWE-79Calculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting …
CVE-2026-170534.4—zephyrprojectzephyrCWE-862SMBus callback-removal syscalls accept an unvalidated user pointer, letting u…
CVE-2025-319804.3—HCL SoftwareHCL BigFix Service ManagementCWE-20HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-425284.3—Apache Software FoundationApache HTTP ServerCWE-789Apache HTTP Server: mod_dav shared lock overflow
CVE-2026-560984.3—Red HatRed Hat Satellite 6.16 for RHEL 8CWE-203Rubygem-katello: improper authorization logic allows resource enumeration
CVE-2026-662474.3—HCL SoftwareiControlCWE-942iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) poli…
CVE-2026-889994.3—davidandersonRedux FrameworkCWE-862Redux Framework <= 4.5.14 - Missing Authorization to Authenticated (Subscribe…
CVE-2026-1023824.3—AhmadMajestic SupportCWE-639WordPress Majestic Support plugin <= 1.2.0 - Insecure Direct Object Reference…
CVE-2026-1034954.3—JetBrainsYouTrackCWE-862In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloa…
CVE-2026-773874.0—geopygeopyCWE-1333geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
CVE-2026-218333.7—HCL SoftwareAIONCWE-1032HCL AION is susceptible to a Missing "Content-Security-Policy" header Vulnera…
CVE-2026-423563.7—Apache Software FoundationApache HTTP ServerCWE-430Apache HTTP Server: limited RCE for some internal redirects to non-CGI files …
CVE-2026-671723.7—HCL SoftwareHCL BigFix Service ManagementCWE-200HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-662483.1—HCL SoftwareiControlCWE-209HCL iControl is affected by an Improper Error Handling vulnerability
CVE-2026-662493.1—HCL SoftwareiControlCWE-614HCL iControl is affected by a Missing Secure Attribute vulnerability
CVE-2026-662533.1—HCL SoftwareiControlCWE-613HCL iControl is affected by a Session Timeout vulnerability
CVE-2026-879733.1—UnknownIf-So Dynamic ContentCWE-79If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name
CVE-2026-1036803.1——tnefCWE-787Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix g…
CVE-2026-565992.2—HCL SoftwareHCL BigFix Service ManagementCWE-614HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-942202.1—Apache Software FoundationApache APISIXCWE-352Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin
CVE-2026-1018872.1—arkqbluez-alsaCWE-369BlueALSA bluealsad LC3plus Decoder Division-by-Zero DoS
CVE-2026-1035342.1—David-CrtydatabasementCWE-266David-Crty databasement Snapshot Model snapshots SnapshotPolicy.view access c…
CVE-2026-1035392.1—ZongXRSuperMarketCWE-287ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing aut…
CVE-2026-1035402.1—formtools.orgForm ToolsCWE-791formtools.org Form Tools Client Settings Clients.class.php updateClientSettin…
CVE-2026-1035412.1—formtools.orgForm ToolsCWE-284formtools.org Form Tools Ajax actions.php uploadFile unrestricted upload
CVE-2026-1035422.1—formtools.orgForm ToolsCWE-918formtools.org Form Tools AJAX Endpoint actions.php smart_fill server-side req…
CVE-2026-1035432.1—itsourcecodeLeave Management SystemCWE-74itsourcecode Leave Management System controller.php sql injection
CVE-2026-1035442.1—datadrivenconstructionOpenConstructionERPCWE-488datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_clien…
CVE-2026-1036902.1—itsourcecodeLeave Management SystemCWE-74itsourcecode Leave Management System controller.php sql injection
CVE-2026-1039232.1—KaTeXKaTeXCWE-807KaTeX: Existing prototype pollution can bypass trust restrictions
CVE-2026-1034892.0—JetBrainsYouTrackCWE-79In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failu…
CVE-2026-1036862.0—rhuksterdom-sanitizerCWE-79rhukster dom-sanitizer URL Validation DOMSanitizer.php isDangerousUrl cross s…
CVE-2026-761441.8—Genians, IncGenian SSL PNS (frodo-core)CWE-434Genians, Inc Genian SSL PNS Unrestricted File Upload
CVE-2026-1035331.2—David-CrtydatabasementCWE-22David-Crty databasement database-servers API Endpoint RestoreRequest.php 511 …
CVE-2026-51873await—n/an/a—Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_pr…
CVE-2026-51874await—n/an/a—In Devika v1.0, the Patcher Agent save_code_to_project function contains a pa…
CVE-2026-51875await—n/an/a—In Devika v1.0, the Feature Agent save_code_to_project function contains a pa…
CVE-2026-51876await—n/an/a—DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book co…
CVE-2026-51878await—n/an/a—deeptutor 1.4.0 contains an authorization bypass through a user-controlled ob…
CVE-2026-51879await—n/an/a—deeptutor 1.4.0 contains an authorization bypass through a user-controlled ob…
CVE-2026-51880await—n/an/a—deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Thro…
CVE-2026-51881await—n/an/a—deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live…
CVE-2026-51882await—n/an/a—The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat …
CVE-2026-51883await—n/an/a—The knowledge base creation and document upload interfaces in Langchain-Chatc…
CVE-2026-51884await—n/an/a—The /knowledge_base/upload_temp_docs temporary document upload endpoint in La…
CVE-2026-51886await—n/an/a—langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: ex…
CVE-2026-51888await—n/an/a—langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact i…
CVE-2026-51892await—n/an/a—infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/d…
CVE-2026-51893await—n/an/a—infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace…
CVE-2026-51894await—n/an/a—infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_m…
CVE-2026-51895await—n/an/a—Ragflow 0.24.0 and prior contains improper access control in update_metadata_…
CVE-2026-51896await—n/an/a—infiniflow ragflow 0.25.3 contains improper access control in resume (api/app…
CVE-2026-51897await—n/an/a—RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/eval…
CVE-2026-104056await—AuthlibAuthlib—CVE-2026-104056

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-10-01 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.