boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Friday, October 2, 2026 · all times UTC← 2026-10-01 · archive

Security Box Score — October 2, 2026

CISA adds 2 to KEV; 398 CVEs published, led by Apache Software Foundation (69).

398 CVEs published October 2, 2026: 29 critical, 178 high, 150 medium, 17 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 24 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 373 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published79350781——
KEV catalog size1733

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3303 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux06205530264072611560.17.8.00190
microsoft12902201199369216290311.17.8.00470
google112842357110112451318090.37.5.0026-15 ▼
red hat219205438842553200.06.8.0035+1 ▲
apple056467166317148991.66.5.00190
suse053827162000.07.5.0036-3 ▼
canonical2521612195000.07.8.0021+2 ▲
freebsd04823673000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0182547255160179.37.8.0046-11 ▼
ubiquiti065362810334.69.1.00500
palo alto networks0461426151324.34.7.00220
fortinet142121017330819.07.2.0040+1 ▲
netgear03400277000.04.3.00270
f502671441527.78.7.0050-7 ▼
ivanti0246162025520.88.8.01520
sonicwall019784019421.18.3.0050-2 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache97804165365249183320.27.5.0060+96 ▲
mozilla0379122169870900.08.8.0031-34 ▼
gitlab11058246211532.95.3.0034+1 ▲
drupal094119668411.15.7.0027-26 ▼
github023211100000.07.4.0054-3 ▼
docker0121830000.08.4.00170
wordpress0614103350.08.7.03920
eclipse022000000.09.3.00500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle0290558116605631012840.17.8.00360
ibm0102319647333618610.17.5.00370
adobe08308236437592150.67.5.00360
progress0661540110611.58.1.0045-2 ▼
zohocorp04262970000.08.3.0117-1 ▼
solarwinds0261853010415.49.1.00670
veeam01961030100.08.6.00420
servicenow0107300200.09.4.00360
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link07422281212300.08.5.01640
siemens052633103000.07.3.00260
synology046510256000.05.6.00320
rockwell automation04353260000.08.6.0029-17 ▼
advantech02021710000.08.6.00710
schneider electric01821150000.08.5.0044-4 ▼
hitachi energy0122460000.07.0.00250
abb0111640000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell03783417015222210.37.2.0027-13 ▼
nvidia030125206700000.07.8.0019-30 ▼
sourcecodester22390014396000.05.5.0042+2 ▲
openclaw022341148421000.07.1.00310
spring017013608314000.06.5.00330
mongodb0169699604100.07.1.00380
hewlett packard enterprise (hpe)01662280559110.67.2.0042-86 ▼
itsourcecode51580037121000.02.1.0033+5 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.929699.810.0
CVE-2026-85046.488898.88.8
CVE-2026-87902.455098.88.1
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.510.0
CVE-2026-86218.129396.210.0
CVE-2026-85102.075594.39.8
CVE-2026-12269.069994.08.8
CVE-2026-67276.064593.59.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9296KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
CVE-2026-7570310.0.0125
Most disclosures (vendor)
VendorCVEs
linux2115
microsoft1002
google647
oracle634
ibm404
apache291
red hat265
apple247
adobe224
dell194
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet8
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven123
NuGet24
Packagist24
npm24
PyPI13
crates.io10
Go9
RubyGems5
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-85046Google0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-102489Zammad GmbH1
CVE-2026-102490Zammad GmbH1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171780
CVE-2021-27102n/a2021-11-171780
CVE-2021-27101n/a2021-11-171780
CVE-2021-27103n/a2021-11-171780
CVE-2021-21017Adobe2021-11-171780
CVE-2021-28550Adobe2021-11-171780
CVE-2021-42013Apache Software Foundation2021-11-171780
CVE-2021-41773Apache Software Foundation2021-11-171780
CVE-2021-30858Apple2021-11-171780
CVE-2021-30860Apple2021-11-171780

Transactions

ADDED TO KEV — CVE-2026-102489 (Zammad GmbH Zammad). Remediation due October 5, 2026.

ADDED TO KEV — CVE-2026-102490 (Zammad GmbH Zammad). Remediation due October 5, 2026.

EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.

EXPLOIT PUBLISHED — Google Chrome: 4 CVEs (CVE-2026-95275, CVE-2026-95363, CVE-2026-95373, CVE-2026-95374). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2019-1579 (Palo Alto Networks GlobalProtect Portal/Gateway Interface). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54403 (Yonyou U8 CRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102293 (realjerrytang tacomall). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102569 (MacWarrior clipbucket-v5). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102620 (Freedesktop Poppler). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102792 (Ziroom ZHOME A0101). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102804 (Nothings stb). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102843 (gedelumbung HospitalManagement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102846 (gedelumbung HospitalManagement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102906 (0xshariq github-mcp-server). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102910 (SourceCodester Online Reviewer Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-102913 (SourceCodester Car Driving School Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103115 (OS4ED openSIS-Classic). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103231 (AdithyaYelloju Restaurant-Management-System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103241 (vllm-project vLLM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-64849 (mlflow). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66402 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67289 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-71486 (vllm-project vllm). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-90843 (SabyasachiRana WebMap). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93984 (Openpanel-dev openpanel). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97062 (Webkul Aureus ERP). Public exploit reference added.

RESCORED — JetBrains YouTrack: 8 CVEs (CVE-2026-100262, CVE-2026-100263, CVE-2026-100270, CVE-2026-100273, CVE-2026-100275, CVE-2026-100276, CVE-2026-100277, CVE-2026-100280). CVSS rescored — before/after on each CVE page.

RESCORED — cisagov Malcolm: 3 CVEs (CVE-2026-55676, CVE-2026-63133, CVE-2026-63134). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2022-37009 (JetBrains IntelliJ IDEA). CVSS 3.9 → 7.8 (NVD).

RESCORED — CVE-2025-32220 (Dimitri Grassi Salon booking system). CVSS 5.4 → 8.8 (NVD).

RESCORED — CVE-2026-100255 (JetBrains TeamCity). CVSS 8.1 → 9.8 (NVD).

RESCORED — CVE-2026-100265 (JetBrains Rider). CVSS 4.8 → 6.5 (NVD).

RESCORED — CVE-2026-100266 (JetBrains Hub). CVSS 7.7 → 6.5 (NVD).

RESCORED — CVE-2026-7064 (AgentDeskAI browser-tools-mcp). CVSS 6.9 → 5.5 (NVD).

RESCORED — CVE-2026-79687 (Dell PowerStore 500T). CVSS 9 → 10 (NVD).

RESCORED — CVE-2026-81479 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 5.8 → 5.5 (NVD).

PATCH SHIPPED — Red Hat Hardened Images: 5 CVEs (CVE-2026-19617, CVE-2026-79705, CVE-2026-84233, CVE-2026-88265, CVE-2026-95512). Fix versions published.

PATCH SHIPPED — cisagov Malcolm: 4 CVEs (CVE-2026-55676, CVE-2026-63133, CVE-2026-63134, CVE-2026-63177). Fix versions published.

PATCH SHIPPED — CVE-2026-97062 (Webkul Aureus ERP). Fixed in Aureus ERP 53ad76dd566f414f1773ec6513616fc2b9e251b5.

ENRICHED — Linux: 15 CVEs (CVE-2026-63973, CVE-2026-64001, CVE-2026-98062, CVE-2026-98109, CVE-2026-98152, CVE-2026-98160, CVE-2026-98161, CVE-2026-98162, CVE-2026-98163, CVE-2026-98164, CVE-2026-100074, CVE-2026-100076, CVE-2026-100077, CVE-2026-100078, CVE-2026-100079). Received CVSS/CPE analysis.

Yesterday's Results

How to read these box scores · glossary

398 CVEs published. 25 box scores, 373 table rows — nothing truncated.

WebRehab Super Forms – Drag & Drop Form Builder — Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  H  H    9.1   .0088   57.8     —
AFFECTED
  Product                                 Versions     Fixed
  Super Forms – Drag & Drop Form Builder  unspecified  —
TIMELINE
  Jul 15  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-26 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
parorrey JSON API Auth — JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0064   48.7     —
AFFECTED
  Product        Versions     Fixed
  JSON API Auth  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
gpriday SiteOrigin Widgets Bundle — SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0056   44.9     —
AFFECTED
  Product                    Versions     Fixed
  SiteOrigin Widgets Bundle  unspecified  —
TIMELINE
  Sep 15  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-98 · CNA: Wordfence · CVSS v3.1 · 7 references · NVD status: Deferred
SaturdayDrive Ninja Forms - File Uploads — Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0052   42.0     —
AFFECTED
  Product                     Versions     Fixed
  Ninja Forms - File Uploads  unspecified  —
TIMELINE
  Sep 16  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
amauric WPMobile.App – Android and iOS App Builder — WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0049   40.1     —
AFFECTED
  Product                                     Versions     Fixed
  WPMobile.App – Android and iOS App Builder  unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-862 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
dplugins DevKit Pro — DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0048   39.1     —
AFFECTED
  Product     Versions     Fixed
  DevKit Pro  unspecified  —
TIMELINE
  Jul 1   Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Legion of the Bouncy Castle Inc. bc-csharp — IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   N   N    8.2   .0047   38.2     —
AFFECTED
  Product    Versions     Fixed
  bc-csharp  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Oct 2   Published (CNA: bcorg)
CWE-203 · CNA: bcorg · CVSS v4.0 · 3 references · NVD status: Undergoing Analysis
Webpros cPanel — Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0046   37.9     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 2   Published (CNA: hackerone)
CWE-78 · CNA: hackerone · CVSS v3.0 · 7 references · NVD status: Deferred
veronalabs WP Statistics – Simple, privacy-friendly Google Analytics alternative — WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  L  L  N    6.1   .0046   37.7     —
AFFECTED
  Product                                                                Versions     Fixed
  WP Statistics – Simple, privacy-friendly Google Analytics alternative  unspecified  —
TIMELINE
  Sep 24  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 10 references · NVD status: Deferred
Legion of the Bouncy Castle Inc. BC-JAVA — Password-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry points
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   L    5.3   .0044   35.6     —
AFFECTED
  Product      Versions     Fixed
  BC-JAVA      unspecified  —
  BC-JAVA      unspecified  —
  BC-LTS-JAVA  2.73.0 –     —
  BC-LTS-JAVA  2.73.0 –     —
  BC-FJA       1.0.0 –      —
TIMELINE
  Jul 26  Reserved by CNA
  Oct 2   Published (CNA: bcorg)
CWE-770 · CNA: bcorg · CVSS v4.0 · 7 references · NVD status: Undergoing Analysis
HAVELSAN Inc. Sef - AI Chatbot Platform — SQL Injection in HAVELSAN's Sef - AI Chatbot Platform
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0043   35.0     —
AFFECTED
  Product                    Versions     Fixed
  Sef - AI Chatbot Platform  unspecified  —
TIMELINE
  Aug 26  Reserved by CNA
  Oct 2   Published (CNA: TR-CERT)
CWE-89 · CNA: TR-CERT · CVSS v3.1 · 1 reference · NVD status: Deferred
Apache Thrift: Lua `TBinaryProtocol:readMessageBegin` bypasses `checkStringSize` on the pre-versioned name
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0043   34.6     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Oct 2   Published (CNA: apache)
CWE-130, CWE-770 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Deferred
Apache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0043   34.6     —
AFFECTED
  Product        Versions     Fixed
  Apache Thrift  unspecified  —
TIMELINE
  Sep 21  Reserved by CNA
  Oct 2   Published (CNA: apache)
CWE-248, CWE-755, CWE-770 · CNA: apache · CVSS v4.0 · 2 references · NVD status: Deferred
boldgrid W3 Total Cache — W3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment Content
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  L  N    7.2   .0042   33.9     —
AFFECTED
  Product         Versions     Fixed
  W3 Total Cache  unspecified  —
TIMELINE
  Sep 9   Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-79 · CNA: Wordfence · CVSS v3.1 · 6 references · NVD status: Deferred
Legion of the Bouncy Castle Inc. bc-csharp — Unbounded HSS public key level count allows huge array allocation during signature verification
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0041   33.1     —
AFFECTED
  Product    Versions     Fixed
  bc-csharp  unspecified  —
TIMELINE
  Sep 30  Reserved by CNA
  Oct 2   Published (CNA: bcorg)
CWE-789 · CNA: bcorg · CVSS v4.0 · 2 references · NVD status: Undergoing Analysis
Webpros cPanel — There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  C  H  H  H    9.0   .0040   32.0     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Sep 17  Reserved by CNA
  Oct 2   Published (CNA: hackerone)
CWE-79 · CNA: hackerone · CVSS v3.0 · 7 references · NVD status: Deferred
Webpros cPanel — There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts inter…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   R  C  H  H  H    9.0   .0040   32.0     —
AFFECTED
  Product     Versions     Fixed
  cPanel      unspecified  —
  WP Squared  unspecified  —
TIMELINE
  Sep 18  Reserved by CNA
  Oct 2   Published (CNA: hackerone)
CWE-79 · CNA: hackerone · CVSS v3.0 · 7 references · NVD status: Deferred
DiviEngine Divi Membership — Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0040   31.5     —
AFFECTED
  Product          Versions     Fixed
  Divi Membership  unspecified  —
TIMELINE
  Aug 12  Reserved by CNA
  Oct 2   Published (CNA: Wordfence)
CWE-287 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Discord libdave — Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.4   .0040   31.6     —
AFFECTED
  Product  Versions  Fixed
  libdave  1.1.0 –   —
TIMELINE
  Oct 2   Reserved by CNA
  Oct 2   Published (CNA: Bugcrowd)
CWE-390, CWE-863 · CNA: Bugcrowd · CVSS v4.0 · 4 references · NVD status: Awaiting Analysis
Legion of the Bouncy Castle Inc. bc-csharp — MTI/A0 DHAgreement does not validate the peer's ephemeral value
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   N    9.1   .0040   31.4     —
AFFECTED
  Product    Versions     Fixed
  bc-csharp  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Oct 2   Published (CNA: bcorg)
CWE-20 · CNA: bcorg · CVSS v4.0 · 2 references · NVD status: Undergoing Analysis
Repasat Repasat application — Multiple vulnerabilities in the Repasat application
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   L   L   N    4.8   .0040   31.5     —
AFFECTED
  Product              Versions     Fixed
  Repasat application  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Oct 2   Published (CNA: INCIBE)
CWE-79 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Repasat Repasat application — Multiple vulnerabilities in the Repasat application
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   L   L   N    4.8   .0040   31.5     —
AFFECTED
  Product              Versions     Fixed
  Repasat application  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Oct 2   Published (CNA: INCIBE)
CWE-79 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Repasat Repasat application — Multiple vulnerabilities in the Repasat application
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   L   L   N    4.8   .0040   31.5     —
AFFECTED
  Product              Versions     Fixed
  Repasat application  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Oct 2   Published (CNA: INCIBE)
CWE-79 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Repasat Repasat application — Multiple vulnerabilities in the Repasat application
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   L   L   N    4.8   .0040   31.5     —
AFFECTED
  Product              Versions     Fixed
  Repasat application  unspecified  —
TIMELINE
  Sep 22  Reserved by CNA
  Oct 2   Published (CNA: INCIBE)
CWE-79 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Repasat Repasat application — Multiple vulnerabilities in the Repasat application
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   A   L   L   N    4.8   .0038   29.6     —
AFFECTED
  Product              Versions     Fixed
  Repasat application  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Oct 2   Published (CNA: INCIBE)
CWE-79 · CNA: INCIBE · CVSS v4.0 · 1 reference · NVD status: Deferred
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-596734.829.6RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-635668.728.7Legion of the Bouncy Castle Inc.bc-csharpCWE-789DTLS handshake reassembler allocates buffer from unchecked 24-bit length
CVE-2026-854926.128.3smubAll in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)CWE-79All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL …
CVE-2026-1044035.325.1ThimPressLearnPressCWE-639WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDO…
CVE-2026-635727.123.9Legion of the Bouncy Castle Inc.bc-csharpCWE-770Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files
CVE-2026-635787.123.9Legion of the Bouncy Castle Inc.bc-csharpCWE-770Unbounded PBE iteration count when decrypting PKCS#8 private keys
CVE-2026-1041235.523.8SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System btn_functions.php activity s…
CVE-2026-944055.323.3ShahjadaDownload ManagerCWE-639WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnera…
CVE-2026-175078.723.2Legion of the Bouncy Castle Inc.BC-JAVACWE-195MLS membership checks compare a uint32 leaf_index as signed, admitting an out…
CVE-2026-635688.722.6Legion of the Bouncy Castle Inc.bc-csharpCWE-770Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion
CVE-2026-100267.222.5CTXCTX Feed ProCWE-94CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
CVE-2026-635748.722.2Legion of the Bouncy Castle Inc.bc-csharpCWE-789Unbounded allocation from OpenPGP signature and user attribute subpacket lengths
CVE-2026-1036008.722.2Legion of the Bouncy Castle Inc.bc-csharpCWE-674Unbounded ASN.1 nesting depth causes process-terminating stack overflow
CVE-2026-596694.822.2RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-635738.221.4Legion of the Bouncy Castle Inc.bc-csharpCWE-203Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap
CVE-2026-1001077.221.3extendthemesKubio AI Page BuilderCWE-79Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting …
CVE-2026-1001827.221.3wpchillDownload MonitorCWE-79Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-1025657.221.3bookingalgorithmsBA Book EverythingCWE-79BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting vi…
CVE-2026-1027727.221.3jtsternbergCMB2CWE-79CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_co…
CVE-2026-129516.521.3wcmpMultiVendorX – WooCommerce Multivendor Marketplace AI Powered SolutionsCWE-89MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'or…
CVE-2026-158978.820.9WebRehabSuper Forms – Drag & Drop Form BuilderCWE-269Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber…
CVE-2026-904387.219.8kstoverNinja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form BuilderCWE-79Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Parag…
CVE-2026-1041205.519.4modelcontextprotocolmcp-server-fetchCWE-918modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server…
CVE-2026-596704.819.4RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596714.819.4RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-1036018.219.1Legion of the Bouncy Castle Inc.bc-csharpCWE-354CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output b…
CVE-2026-973367.219.0jtsternbergCMB2CWE-79CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' …
CVE-2026-1020023.119.1themeisleOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSECWE-200Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exp…
CVE-2026-180368.218.8Legion of the Bouncy Castle Inc.BC-JAVACWE-208NTRU leaks private key information by reducing secret values with a non-const…
CVE-2026-976346.518.7stellarwpEvent Tickets and RegistrationCWE-89Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL I…
CVE-2026-941804.318.7MonetizemoreAdvanced AdsCWE-639WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability
CVE-2026-804644.918.0HAVELSAN Inc.Sef - AI Chatbot PlatformCWE-918API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
CVE-2026-965667.217.6satolloNewsletter – Send awesome emails from WordPressCWE-79Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' C…
CVE-2026-937567.217.1smubSmash Balloon Social Post Feed – Simple Social Feeds for WordPressCWE-79Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site …
CVE-2026-944325.317.0latepointAppointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressCWE-639Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Una…
CVE-2026-910205.316.6UnknownWebToffee Gift Cards for WooCommerceCWE-472WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amou…
CVE-2026-1036048.715.9Legion of the Bouncy Castle Inc.bc-csharpCWE-407Quadratic-time escaping when converting X.509 distinguished names to strings
CVE-2026-965677.215.9websoudanMW WP FormCWE-79MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_i…
CVE-2026-160008.715.2Legion of the Bouncy Castle Inc.bc-csharpCWE-325KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated dat…
CVE-2026-965787.214.8creative-solutions-1GSpeech TTS – WordPress Text To Speech PluginCWE-79GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comme…
CVE-2026-134135.314.5UnknownCMP – Coming Soon & MaintenanceCWE-284CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode B…
CVE-2026-1036028.214.1Legion of the Bouncy Castle Inc.bc-csharpCWE-295Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts
CVE-2026-956707.213.8mihdanNo External LinksCWE-79No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via …
CVE-2026-968717.213.8kitae-parkMang BoardCWE-79Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_t…
CVE-2026-973427.213.8jetmonstersJetFormBuilder — Dynamic Blocks Form BuilderCWE-79JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via '…
CVE-2026-976417.213.8comesioRelevanssi – A Better SearchCWE-79Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Commen…
CVE-2026-976637.213.8ivoleCustomer Reviews for WooCommerceCWE-79Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Si…
CVE-2026-635778.213.2Legion of the Bouncy Castle Inc.bc-csharpCWE-295Name Constraints bypass: directoryName constraint matched at any position in …
CVE-2026-958177.213.3apasionadosDoFollow Case by CaseCWE-79DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting …
CVE-2026-909875.313.2UnknownEasy PayPal & Stripe Buy Now ButtonCWE-472Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amo…
CVE-2026-909525.313.1UnknownWP Edit Password ProtectedCWE-862WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access M…
CVE-2026-1034267.212.7RelevanssiRelevanssi PremiumCWE-79Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting vi…
CVE-2026-159998.212.2Legion of the Bouncy Castle Inc.bc-csharpCWE-354AES-CCM decryption accepts zero or out-of-range tag length, bypassing authent…
CVE-2026-847406.511.7UnknownThe Events CalendarCWE-74The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Exe…
CVE-2026-850055.411.7UnknownPopup Maker WPCWE-862Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invoc…
CVE-2026-784715.411.5optimizingmattersAutoptimizeCWE-79Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Com…
CVE-2026-635768.211.1Legion of the Bouncy Castle Inc.bc-csharpCWE-295URI name constraints checked against a mis-parsed host
CVE-2026-16614.311.1UnknownWP Mail LoggingCWE-79WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection
CVE-2026-973386.410.9codename065Download ManagerCWE-79Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Sc…
CVE-2026-635707.110.6Legion of the Bouncy Castle Inc.bc-csharpCWE-835Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links
CVE-2026-938806.110.3wpsoulGreenshift – animation and page builder blocksCWE-79Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic …
CVE-2026-803375.310.2HAVELSAN Inc.Sef - AI Chatbot PlatformCWE-862Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Pla…
CVE-2026-1040542.110.1calcomcal.diyCWE-862calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessTo…
CVE-2026-966476.49.0webiliaListdom: AI-powered Business Directory with Classifieds Ads ListingsCWE-79Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1…
CVE-2026-1040522.18.9itsourcecodePet Shop Management SystemCWE-74itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
CVE-2026-1040532.18.9itsourcecodePet Shop Management SystemCWE-74itsourcecode Pet Shop Management System admin_reservefilter.php sql injection
CVE-2026-933677.28.2wp-buyVisitor Traffic Real Time Statistics proCWE-79Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored C…
CVE-2026-635757.18.2Legion of the Bouncy Castle Inc.bc-csharpCWE-835PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration…
CVE-2026-102731await8.1Apache Software FoundationApache Directory LDAP APICWE-789Apache Directory LDAP API: Denial of service via excessive memory allocation …
CVE-2026-796184.37.3UnknownWP User FrontendCWE-862WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated …
CVE-2026-972194.37.3UnknownMStore APICWE-862MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
CVE-2026-929245.47.1UnknownUnlimited Elements for ElementorCWE-74Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode E…
CVE-2026-1035527.37.0Apache Software FoundationApache Directory LDAP APICWE-121Apache Directory LDAP API: A unbound client can send a deeply nested search f…
CVE-2026-918287.56.3UnknownOMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.CWE-400OMGF < 6.3.11 - Unauthenticated DoS via do_optimize
CVE-2026-160018.26.0Legion of the Bouncy Castle Inc.bc-csharpCWE-354IesEngine stream-mode MAC forgery via length-dependent KDF split
CVE-2026-955125.55.9Red HatRed Hat Hardened ImagesCWE-400Freetype: freetype: denial of service via repeated subroutine allocations in …
CVE-2026-635718.75.6Legion of the Bouncy Castle Inc.bc-csharpCWE-347Attribute certificate path validation does not verify the attribute certifica…
CVE-2026-849256.15.5ThemeFusionAvada | Website Builder For WordPress & WooCommerceCWE-79Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cro…
CVE-2026-804437.45.0HAVELSAN Inc.Sef - AI Chatbot PlatformCWE-295Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI…
CVE-2026-1030987.54.6GeoVision Inc.GV-EyeCWE-319GV-Eye Sensitive information exposure in URL query parameter Vulnerability
CVE-2026-942986.24.3UnknownBuildKitCWE-89BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter
CVE-2026-917844.83.9cjbassigotopCWE-88Argument Injection leading to arbitrary process termination in gotop
CVE-2026-1030967.53.7GeoVision Inc.GV-EyeCWE-312GV-Eye Hardcoded API Key Vulnerability
CVE-2026-1030977.53.7GeoVision Inc.GV-EyeCWE-312GV-Eye Relay Payment API Key Vulnerability
CVE-2026-137186.83.7UnknownTabs ResponsiveCWE-79Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab…
CVE-2026-850166.83.7UnknownUnlimited Elements for ElementorCWE-79Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon …
CVE-2026-910226.83.7UnknownMotorsCWE-79Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color
CVE-2026-909885.33.2UnknownRequest a QuoteCWE-200Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Discl…
CVE-2026-973175.32.8UnknownGiveaways and Contests by RafflePressCWE-200Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA S…
CVE-2026-973186.12.6UnknownGiveaways and Contests by RafflePressCWE-601Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open…
CVE-2026-817405.32.6UnknownPaytm Payment GatewayCWE-287Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via…
CVE-2026-850044.32.3UnknownPopup MakerCWE-284Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect
CVE-2026-910233.12.3UnknownMotorsCWE-862Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-U…
CVE-2026-211406.91.0Samsung MobileSamsung Mobile Devices—Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release …
CVE-2026-10395610.0—AWSloomCWE-306Missing authentication for critical function in Loom for AWS
CVE-2026-909709.9—GitLabGitLab AI GatewayCWE-1336Improper Neutralization of Special Elements Used in a Template Engine in GitL…
CVE-2026-196529.8—DiviEngineDivi MembershipCWE-269Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id'…
CVE-2026-1048469.8—lxsmnsycserovalCWE-843Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced c…
CVE-2026-1036289.6—GoogleChromeCWE-787Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed …
CVE-2026-1048489.5—tinylibstinypoolCWE-1321Tinypool: Prototype Pollution gadget in worker options leads to Remote Code E…
CVE-2026-1048499.5—tinylibstinypoolCWE-94Tinypool: Prototype Pollution Gadget to RCE in run() options
CVE-2026-759379.4—Digi InternationalIX FamilyCWE-78OS Command Injection in Digi Accelerated Linux (DAL OS)
CVE-2026-863259.4—MoxaMGate MB3170 SeriesCWE-121A stack-based buffer overflow vulnerability exists in protocol gateways' acco…
CVE-2023-544059.3—H3CCVMCWE-434H3C CVM Unauthenticated File Upload via fileUpload/upload Token
CVE-2026-820429.3—UTMStackUTMStackCWE-306UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter
CVE-2026-844119.3—MikroTikRouterOSCWE-191MikroTik RouterOS Integer Underflow
CVE-2026-951029.3—Montamonta.appCWE-306Monta monta.app Missing Authentication for Critical Function
CVE-2026-1040199.3—AWSsagemaker-distributionCWE-78OS command injection in the Studio Space startup validation script in Amazon …
CVE-2026-1046109.3—TendaHG7CWE-119Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow
CVE-2026-836329.2—Apache Software FoundationApache ThriftCWE-122Apache Thrift: C++ THttpTransport grows its line buffer without bound
CVE-2026-911359.2—Apache Software FoundationApache ThriftCWE-122Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (writ…
CVE-2026-1044679.2—YesWikiyeswikiCWE-862YesWiki before 4.6.7 Authorization Bypass via Public API Mode
CVE-2026-1036489.1—demskingimage-downloaderCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'…
CVE-2026-397188.8—WebritiWallstreetCWE-352WordPress Wallstreet theme <= 2.8.6 - Cross Site Request Forgery (CSRF) vulne…
CVE-2026-969408.8—MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23CWE-1390Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-1036228.8—GoogleChromeCWE-416Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remot…
CVE-2026-1036258.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote…
CVE-2026-1044458.8—YesWikiyeswikiCWE-290YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing
CVE-2026-1044578.8—YesWikiyeswikiCWE-89YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter
CVE-2026-1044628.8—YesWikiyeswikiCWE-89YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter
CVE-2026-1044648.8—YesWikiyeswikiCWE-918YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter
CVE-2026-1048518.8—fsspecfilesystem_specCWE-94fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote…
CVE-2014-1251308.7—DamjanCodeArt Google MP3 Audio PlayerCWE-22CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_downloa…
CVE-2020-372788.7—Weavere-BridgeCWE-918Weaver e-Bridge Unauthenticated Arbitrary File Read via saveYZJFile
CVE-2026-613738.7—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allo…
CVE-2026-637728.7—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via t…
CVE-2026-660818.7—Apache Software FoundationApache ThriftCWE-824Apache Thrift: c_glib read_message_begin leaves output parameters unset for n…
CVE-2026-668378.7—Apache Software FoundationApache ThriftCWE-121Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled st…
CVE-2026-668588.7—Apache Software FoundationApache ThriftCWE-674Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap…
CVE-2026-668598.7—Apache Software FoundationApache ThriftCWE-457Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route
CVE-2026-820398.7—UTMStackUTMStackCWE-89UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter
CVE-2026-824588.7—Apache Software FoundationApache ThriftCWE-770Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap…
CVE-2026-836638.7—Apache Software FoundationApache ThriftCWE-674Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per f…
CVE-2026-837458.7—Apache Software FoundationApache ThriftCWE-130Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload b…
CVE-2026-854938.7—Apache Software FoundationApache ThriftCWE-248Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting …
CVE-2026-854948.7—Apache Software FoundationApache ThriftCWE-130Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap…
CVE-2026-865358.7—Apache Software FoundationApache ThriftCWE-835Apache Thrift: A JSON member name can stall the Node server's event loop inde…
CVE-2026-865378.7—Apache Software FoundationApache ThriftCWE-191Apache Thrift: A truncated HTTP request stops the D library's server, allowin…
CVE-2026-871178.7—Apache Software FoundationApache ThriftCWE-476Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing conta…
CVE-2026-911378.7—Apache Software FoundationApache ThriftCWE-770Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements
CVE-2026-939258.7—Apache Software FoundationApache ThriftCWE-121Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow …
CVE-2026-939268.7—Apache Software FoundationApache ThriftCWE-401Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on…
CVE-2026-944228.7——xdg-dbus-proxyCWE-290xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape
CVE-2026-946338.7—Apache Software FoundationApache ThriftCWE-130Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre…
CVE-2026-946428.7—Apache Software FoundationApache ThriftCWE-248Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transpo…
CVE-2026-946468.7—Apache Software FoundationApache ThriftCWE-248Apache Thrift: Node.js `server.js` ends the process on any per-connection err…
CVE-2026-946588.7—Apache Software FoundationApache ThriftCWE-407Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on…
CVE-2026-962778.7—Apache Software FoundationApache ThriftCWE-248Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protoc…
CVE-2026-962948.7—Apache Software FoundationApache ThriftCWE-248Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocke…
CVE-2026-973638.7—Montamonta.appCWE-307Monta monta.app Improper Restriction of Excessive Authentication Attempts
CVE-2026-1044108.7—siyuan-notesiyuanCWE-862SiYuan before 3.8.5 Information Disclosure via /api/export/preview
CVE-2026-1044228.7—ZcashFoundationzebraCWE-345Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite
CVE-2026-1044238.7—ZcashFoundationzebraCWE-405Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification
CVE-2026-1044308.7—ZcashFoundationzebraCWE-628Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount
CVE-2026-1044318.7—ZcashFoundationzebraCWE-405Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification
CVE-2026-1044338.7—kvcache-aiMooncakeCWE-125Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString
CVE-2026-1044388.7—YesWikiyeswikiCWE-862YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages…
CVE-2026-1044608.7—YesWikiyeswikiCWE-89YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch
CVE-2026-1044728.7—YesWikiyeswikiCWE-862YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler
CVE-2026-863268.6—MoxaMGate MB3170 SeriesCWE-347An improper verification of cryptographic signature vulnerability exists in p…
CVE-2026-945918.6—Armatura LLCArmatura OneCWE-321Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
CVE-2026-945928.6—Armatura LLCArmatura OneCWE-798Armatura LLC Armatura One Use of Hard-coded Credentials
CVE-2026-1044148.6—TryGhostGhostCWE-79Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses
CVE-2026-1044188.6—TryGhostGhostCWE-22Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files
CVE-2026-1044718.6—YesWikiyeswikiCWE-434YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import
CVE-2026-945938.5—Armatura LLCArmatura OneCWE-532Armatura LLC Armatura One Insertion of Sensitive Information into Log File
CVE-2026-1044118.5—TryGhostGhostCWE-79Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads
CVE-2026-1044138.5—TryGhostGhostCWE-79Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images
CVE-2026-1046118.5—TendaAC9CWE-119Tenda AC9 POST Request fast_setting_internet_set stack-based overflow
CVE-2026-1048478.5—ProseMirrorprosemirror-viewCWE-79ProseMirror: XSS vulnerability in prosemirror-view's paste handling
CVE-2026-1048548.5—nrwlnxCWE-269Nx daemon and plugin worker sockets are accessible to other local users
CVE-2026-944838.3—vercelnext.jsCWE-918Next.js: Server-Side Request Forgery in Image Optimization
CVE-2026-1039588.3—AWSloomCWE-918Server-side request forgery in the tool server and remote agent connection ha…
CVE-2026-1044358.3—ZcashFoundationzebraCWE-347Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output
CVE-2026-1044378.3—ZcashFoundationzebraCWE-347Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling
CVE-2026-1044498.3—YesWikiyeswikiCWE-639YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche
CVE-2026-1044588.3—YesWikiyeswikiCWE-918YesWiki before 4.6.7 SSRF Guard Bypass via IPv6 Transition Addresses
CVE-2026-1044638.3—YesWikiyeswikiCWE-918YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox
CVE-2026-660558.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap…
CVE-2026-824598.2—Apache Software FoundationApache ThriftCWE-191Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenti…
CVE-2026-854768.2—Apache Software FoundationApache ThriftCWE-835Apache Thrift: c_glib `read_all` spins when the underlying read returns 0
CVE-2026-904408.2—Apache Software FoundationApache ThriftCWE-248Apache Thrift: An exception escaping a libevent callback stops the D library'…
CVE-2026-946348.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Python `TJSONProtocol` has a string length limit that is off b…
CVE-2026-946368.2—Apache Software FoundationApache ThriftCWE-409Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size …
CVE-2026-946378.2—Apache Software FoundationApache ThriftCWE-409Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZL…
CVE-2026-946448.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound
CVE-2026-946458.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as…
CVE-2026-946488.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE-2026-946508.2—Apache Software FoundationApache ThriftCWE-674Apache Thrift: c_glib generated struct readers have no recursion-depth guard …
CVE-2026-946518.2—Apache Software FoundationApache ThriftCWE-755Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a conn…
CVE-2026-946538.2—Apache Software FoundationApache ThriftCWE-407Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every…
CVE-2026-946548.2—Apache Software FoundationApache ThriftCWE-835Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all…
CVE-2026-946558.2—Apache Software FoundationApache ThriftCWE-407Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound a…
CVE-2026-946568.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE-2026-946578.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound
CVE-2026-962868.2—Apache Software FoundationApache ThriftCWE-248Apache Thrift: Perl servers end `serve()` when serving one connection fails
CVE-2026-962878.2—Apache Software FoundationApache ThriftCWE-407Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice th…
CVE-2026-962888.2—Apache Software FoundationApache ThriftCWE-674Apache Thrift: Erlang generated struct reads have no recursion-depth guard (u…
CVE-2026-962898.2—Apache Software FoundationApache ThriftCWE-674Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBi…
CVE-2026-962928.2—Apache Software FoundationApache ThriftCWE-407Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line wi…
CVE-2026-969908.2—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size…
CVE-2026-1039578.2—AWSloomCWE-201Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
CVE-2026-1044268.2—ZcashFoundationzebraCWE-407Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check
CVE-2026-1044278.2—ZcashFoundationzebraCWE-459Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry
CVE-2026-1044508.2—YesWikiyeswikiCWE-79YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action
CVE-2026-1044768.2—backdropbackdropCWE-200Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Ar…
CVE-2026-519078.1—n/an/aCWE-22In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image functio…
CVE-2026-1049888.1—Red HatRed Hat Certificate System 10CWE-290Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allo…
CVE-2026-1040267.8—Meta Platforms, IncSapling SCMCWE-150In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed…
CVE-2026-1044167.7—TryGhostGhostCWE-203Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API
CVE-2026-1044697.6—YesWikiyeswikiCWE-384YesWiki before 4.6.7 Session Fixation via Login in AuthController.php
CVE-2026-1048737.6—langchain-ailanggraphCWE-863LangGraph SDK custom auth silently ignores actions= on resource decorators
CVE-2026-519167.5—n/an/aCWE-284TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vuln…
CVE-2026-679897.5—n/an/aCWE-1333crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a …
CVE-2026-1048457.5—lxsmnsycserovalCWE-770Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserializ…
CVE-2026-1048617.5—nodecaprobe-image-sizeCWE-400probe-image-size: Quadratic-time Denial of Service in the SVG Parser
CVE-2026-1047337.4—ProcessOneejabberdCWE-290User Impersonation/Authorization Bypass in XMPP Server ejabberd
CVE-2026-1048597.3—nrwlnxCWE-78Nx: OS command injection in the @nx/docker release pipeline
CVE-2026-938757.2—CrocoblockJetAppointmentCWE-79JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via '…
CVE-2026-1026267.2—LimeSurveyLimeSurveyCWE-79LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_mi…
CVE-2026-1044437.2—YesWikiyeswikiCWE-863YesWiki before 4.6.7 Scope Bypass via Triples Delete API
CVE-2026-1044487.2—YesWikiyeswikiCWE-352YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler
CVE-2026-1044567.2—YesWikiyeswikiCWE-89YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username
CVE-2026-613747.1—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit
CVE-2026-820457.1—UTMStackUTMStackCWE-89UTMStack < 11.2.16 JPQL Injection via searchPropertyValues
CVE-2026-852157.1—GG Soft Software Services Inc.PaperworkCWE-89SQL Injection in GG Soft's Paperwork
CVE-2026-966137.1—MeariIoT Cloud Platform OpenAPI ServiceCWE-862Missing Authorization in Meari IoT Cloud Platform OpenAPI Service
CVE-2026-1044347.1—ZcashFoundationzebraCWE-617Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC
CVE-2026-1044397.1—YesWikiyeswikiCWE-204YesWiki before 4.6.7 User Enumeration via Lost-Password Flow
CVE-2026-1044447.1—YesWikiyeswikiCWE-639YesWiki before 4.6.7 Authorization Bypass via Comments API editComment
CVE-2026-1044477.1—YesWikiyeswikiCWE-352YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction
CVE-2026-1044787.1—getformworkformworkCWE-22Formwork before 2.3.13 Path Traversal via BackupController Download and Delete
CVE-2026-1049087.1—MISPMISPCWE-285MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Ov…
CVE-2026-1049127.1—MISPMISPCWE-284MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute …
CVE-2026-1049917.1—AlanaktionphprojectCWE-862Phproject < 1.8.7 Missing Authorization via Issues REST API
CVE-2026-1050507.1—PeaZipPeaZipCWE-180PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS com…
CVE-2026-1027957.0—Apache Software FoundationApache Traffic ServerCWE-284Apache Traffic Server: SNI to Host header matching policy is not properly enf…
CVE-2026-660546.9—Apache Software FoundationApache ThriftCWE-409Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize
CVE-2026-663316.9—Apache Software FoundationApache ThriftCWE-770Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize
CVE-2026-820436.9—UTMStackUTMStackCWE-204UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint
CVE-2026-850866.9—Apache Software FoundationApache ThriftCWE-295Apache Thrift: Perl TLS client disables certificate verification by default
CVE-2026-850876.9—Apache Software FoundationApache ThriftCWE-295Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op
CVE-2026-850886.9—Apache Software FoundationApache ThriftCWE-295Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certific…
CVE-2026-934746.9—Montamonta.appCWE-522Monta monta.app Insufficiently Protected Credentials
CVE-2026-972126.9—Montamonta.appCWE-613Monta monta.app Insufficient Session Expiration
CVE-2026-1037626.9—siyuan-notesiyuanCWE-862SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints
CVE-2026-1037636.9—siyuan-notesiyuanCWE-200SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo
CVE-2026-1044176.9—TryGhostGhostCWE-22Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting
CVE-2026-1044206.9—ZcashFoundationzebraCWE-704Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks
CVE-2026-1044216.9—ZcashFoundationzebraCWE-459Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes…
CVE-2026-1044256.9—ZcashFoundationzebraCWE-405Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed T…
CVE-2026-1044286.9—ZcashFoundationzebraCWE-617Zebra before 11.0.0 Denial of Service via getblock Verbosity 2
CVE-2026-1044296.9—ZcashFoundationzebraCWE-770Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages
CVE-2026-1044326.9—ZcashFoundationzebraCWE-754Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response
CVE-2026-1044406.9—YesWikiyeswikiCWE-918YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter
CVE-2026-1044416.9—YesWikiyeswikiCWE-918YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action
CVE-2026-1044426.9—YesWikiyeswikiCWE-918YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action
CVE-2026-1044466.9—YesWikiyeswikiCWE-306YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler
CVE-2026-1044546.9—YesWikiyeswikiCWE-1333YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint
CVE-2026-1044556.9—YesWikiyeswikiCWE-200YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action
CVE-2026-1044596.9—YesWikiyeswikiCWE-918YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle
CVE-2026-1050306.9—rajnandan1kenerCWE-200Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
CVE-2026-198566.5—UnknownAll in One SEO—All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via …
CVE-2026-325856.5—airanoAirano MCP BridgeCWE-862WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerab…
CVE-2026-394396.5—Kiera HoweWebSamuraiCWE-862WordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerability
CVE-2026-820416.5—UTMStackUTMStackCWE-862UTMStack < 11.2.16 Missing Authorization via Command WebSocket
CVE-2026-852096.5—AVEZ Electronics Communication Training and Consultancy Trade Inc.Learning Management System (LMS)CWE-862IDOR in AVEZ Electronics's LMS
CVE-2026-1027986.5—ThemeREX GroupThemeREX AddonsCWE-79WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulne…
CVE-2026-1030366.5—middleapiorpcCWE-915@orpc/json-schema: Prototype injection in smart coercion
CVE-2026-1039186.5—middleapiorpcCWE-915@orpc/zod: Prototype injection in smart coercion
CVE-2026-978766.4—GNUgrub2CWE-822Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MM…
CVE-2026-1027976.4—ThemeREX GroupThemeREX AddonsCWE-918WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSR…
CVE-2026-820446.3—UTMStackUTMStackCWE-918UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf
CVE-2026-854836.3—Apache Software FoundationApache ThriftCWE-393Apache Thrift: c_glib TZlibTransport reports a full read after a premature st…
CVE-2026-865366.3—Apache Software FoundationApache ThriftCWE-1321Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can repl…
CVE-2026-928346.3—Apache Software FoundationApache ThriftCWE-393Apache Thrift: C++ WebSocket server transport does not read a full request le…
CVE-2026-944846.3—vercelnext.jsCWE-524Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user con…
CVE-2026-944856.3—vercelnext.jsCWE-346Next.js: Information disclosure in Next.js App Router metadata image routes v…
CVE-2026-945436.3—vercelnext.jsCWE-524Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applicat…
CVE-2026-945446.3—vercelnext.jsCWE-524Next.js: Pending `use cache` fill can leak Draft Mode content into regular re…
CVE-2026-946386.3—Apache Software FoundationApache ThriftCWE-770Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxS…
CVE-2026-946526.3—Apache Software FoundationApache ThriftCWE-401Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the proces…
CVE-2026-1011046.3—MeariIoT Cloud Platform OpenAPI ServiceCWE-862Missing Authorization in Meari IoT Cloud Platform OpenAPI Service
CVE-2026-1044196.3—ZcashFoundationzebraCWE-345Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes
CVE-2026-1044246.3—ZcashFoundationzebraCWE-131Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate
CVE-2026-1044366.3—ZcashFoundationzebraCWE-770Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locato…
CVE-2026-1044686.3—YesWikiyeswikiCWE-613YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction
CVE-2026-1047216.3—QOS.CH SarlLogback-classicCWE-22Logback: Incomplete protection against CVE-2026-19880
CVE-2026-1048716.3—angularangular-cliCWE-22Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
CVE-2026-1049066.2—MISPMISPCWE-79MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output
CVE-2026-1048435.9—astral-shuvCWE-22uv: Path traversal on Windows through wheel extraction
CVE-2026-1048445.9—postcsspostcss-selector-parserCWE-400PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion
CVE-2026-1048535.8—nrwlnxCWE-22Nx: Path traversal in nx migrate package-migrations extraction
CVE-2026-1048725.8—open-telemetryopentelemetry-js-contribCWE-532Multiple @opentelemetry/instrumentation-* packages expose database username v…
CVE-2026-1050495.8—ZillizAttuCWE-306Zilliz Attu before 3.0.0 has a Playground feature that does not require authe…
CVE-2026-1046095.5—onetwothreenethHospitalManagementSystemCWE-74onetwothreeneth HospitalManagementSystem edit_accounts.php get sql injection
CVE-2026-1046375.5—onetwothreenethHospitalManagementSystemCWE-284onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestri…
CVE-2026-1046385.5—onetwothreenethHospitalManagementSystemCWE-287onetwothreeneth HospitalManagementSystem sessions.php improper authentication
CVE-2026-394445.4—PublishPressPublishPress SeriesCWE-639WordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object Refere…
CVE-2026-1044745.4—litespeedtechopenlitespeedCWE-367OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update
CVE-2026-117955.3—Softtr Informatics Trading Limited CompanyE-Commerce PackCWE-203User Enumeration in Softtr's E-Commerce Pack
CVE-2026-123925.3—CanonicalMAAS—RPC secret disclosure via vendor data endpoint in Canonical MAAS
CVE-2026-325845.3—Chiranjit HazarikaSmart One Click Setup – Complete Demo Import &amp; ExportCWE-201WordPress Smart One Click Setup – Complete Demo Import &amp; Export plugin <=…
CVE-2026-820405.3—UTMStackUTMStackCWE-918UTMStack < 11.2.16 SSRF via IdentityProviderService
CVE-2026-1040555.3—Canonicalpostgresql-operatorCWE-532Monitoring-user password logged in cleartext by postgres_exporter in postgres…
CVE-2026-1044125.3—TryGhostGhostCWE-269Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment
CVE-2026-1044515.3—YesWikiyeswikiCWE-352YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler
CVE-2026-1044525.3—YesWikiyeswikiCWE-352YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler
CVE-2026-1044535.3—YesWikiyeswikiCWE-352YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action
CVE-2026-1044705.3—YesWikiyeswikiCWE-79YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action
CVE-2026-1044775.3—showdownjsshowdownCWE-79Showdown through 2.1.0 XSS via unescaped quote in href and src attributes
CVE-2026-1048745.3—aio-libsmultidictCWE-401Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtr…
CVE-2026-1049005.3—MISPMISPCWE-79MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index
CVE-2026-1049105.3—MISPMISPCWE-285MISP Information Disclosure via Related Events Listing Bypassing Per-Event Au…
CVE-2026-1049145.3—MISPMISPCWE-284MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute …
CVE-2026-1050295.3—uvdesksupport-center-bundleCWE-639UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating…
CVE-2026-57825.2—Loglama.netTurkHotspotCWE-79Reflected XSS in Loglama.NET's TurkHotspot
CVE-2026-945945.1—Armatura LLCArmatura OneCWE-532Armatura LLC Armatura One Insertion of Sensitive Information into Log File
CVE-2026-1044615.1—YesWikiyeswikiCWE-79YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField
CVE-2026-1044655.1—YesWikiyeswikiCWE-79YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler
CVE-2026-1044665.1—YesWikiyeswikiCWE-79YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute
CVE-2026-1044735.1—YesWikiyeswikiCWE-79YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages
CVE-2026-1044755.1—iduraridurar-erp-crmCWE-79IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload
CVE-2026-1044795.1—mindstellarshopclassCWE-79Shopclass before 6.2.0 Stored XSS via Listing Description Field
CVE-2026-1049015.1—MISPMISPCWE-79MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting vi…
CVE-2026-596624.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596634.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596644.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596654.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596664.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596674.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-596684.8—RepasatRepasat applicationCWE-79Multiple vulnerabilities in the Repasat application
CVE-2026-1049074.8—MISPMISPCWE-79MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler
CVE-2026-396004.7—Mehul GohilAculect AI CompanionCWE-601WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Fo…
CVE-2026-397174.3—ThimPressLearnPressCWE-862WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability
CVE-2026-518994.3—n/an/aCWE-284In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api…
CVE-2026-1050464.3—KenticoXperienceCWE-425Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks …
CVE-2026-1050484.0—ZillizAttuCWE-1289The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of r…
CVE-2026-396013.7—WPdevelopBooking CalendarCWE-362WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability
CVE-2026-1050433.6—MathWorksSimulinkCWE-451MathWorks Simulink before R2026b, when showing a crafted .slx file, can have …
CVE-2026-1049942.5—aquasecTrivyCWE-24Trivy before 0.71.0 allows directory traversal in Terraform filesystem functi…
CVE-2026-944862.3—vercelnext.jsCWE-346Next.js: Information disclosure in the Next.js development server's Model Con…
CVE-2026-1044152.3—TryGhostGhostCWE-203Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API
CVE-2026-1046062.1—itsourcecodeOnline Admission System ProjectCWE-74itsourcecode Online Admission System Project confirm.php sql injection
CVE-2026-1046122.1—SourceCodesterStudent Result Management SystemCWE-79SourceCodester Student Result Management System Announcement new_announcement…
CVE-2026-1046132.1—CodeAstroSimple Pharmacy Management SystemCWE-74CodeAstro Simple Pharmacy Management System view.php sql injection
CVE-2026-1046142.1—CodeAstroSimple Pharmacy Management SystemCWE-74CodeAstro Simple Pharmacy Management System delete.php sql injection
CVE-2026-1046252.1—CodeAstroSimple Loan Management SystemCWE-74CodeAstro Simple Loan Management System index.php sql injection
CVE-2026-1048552.0—bytecodealliancewasmtimeCWE-362Wasmtime: Preemption and traps during bulk operations enable breaking interna…
CVE-2026-1050511.9—IrdetoDenuvo Anti-TamperCWE-348Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence …
CVE-2026-51898await—n/an/a—sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.e…
CVE-2026-51901await—n/an/a—SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent ex…
CVE-2026-51904await—n/an/a—SuperAGI up to v0.0.14 contains an improper access control vulnerability in t…
CVE-2026-51906await—n/an/a—In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image func…
CVE-2026-51911await—n/an/a—vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_…
CVE-2026-51914await—n/an/a—TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control…
CVE-2026-51915await—n/an/a—TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control…
CVE-2026-51917await—n/an/a—FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.
CVE-2026-51918await—n/an/a—FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code ().
CVE-2026-51922await—n/an/a—agentscope v1.0.20 contains code injection in execute_shell_command (src/agen…
CVE-2026-59265await—Apache Software FoundationApache OpenOfficeCWE-426Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead t…
CVE-2026-103621await—GoogleChromeCWE-190Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allow…
CVE-2026-103623await—GoogleChromeCWE-416Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed…
CVE-2026-103624await—GoogleChromeCWE-416Use after free in Contextual Tasks in Google Chrome on on Windows prior to 15…
CVE-2026-103626await—GoogleChromeCWE-863Incorrect authorization in FileSystem in Google Chrome on on Windows prior to…
CVE-2026-103627await—GoogleChromeCWE-200Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a rem…
CVE-2026-103629await—GoogleChromeCWE-190Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a re…
CVE-2026-103630await—GoogleChromeCWE-416Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a rem…
CVE-2026-103631await—GoogleChromeCWE-122Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a r…
CVE-2026-103877await—Apache Software FoundationApache Directory LDAP APICWE-502Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements
CVE-2026-103878await—Apache Software FoundationApache Directory LDAP APICWE-345Apache Directory LDAP API: Injection of plaintext responses during StartTLS
CVE-2026-103880await—Apache Software FoundationApache Directory LDAP APICWE-405Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor…
CVE-2026-103885await—Apache Software FoundationApache Directory LDAP API—Apache Directory LDAP API: Denial of service via crafted telephone number values

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-10-02 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.