AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0088 57.8 —
AFFECTED Product Versions Fixed Super Forms – Drag & Drop Form Builder unspecified —
TIMELINE Jul 15 Reserved by CNA Oct 2 Published (CNA: Wordfence)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
CISA adds 2 to KEV; 398 CVEs published, led by Apache Software Foundation (69).
398 CVEs published October 2, 2026: 29 critical, 178 high, 150 medium, 17 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 24 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 373 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 793 | 50781 | — | — |
| KEV catalog size | 1733 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3303 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 0 | 6205 | 530 | 2640 | 726 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | 0 |
| microsoft | 1 | 2902 | 201 | 1993 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | 0 |
| 11 | 2842 | 357 | 1101 | 1245 | 131 | 80 | 9 | 0.3 | 7.5 | .0026 | -15 ▼ | |
| red hat | 21 | 920 | 54 | 388 | 425 | 53 | 2 | 0 | 0.0 | 6.8 | .0035 | +1 ▲ |
| apple | 0 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | 0 |
| suse | 0 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | -3 ▼ |
| canonical | 2 | 52 | 16 | 12 | 19 | 5 | 0 | 0 | 0.0 | 7.8 | .0021 | +2 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 182 | 54 | 72 | 55 | 1 | 60 | 17 | 9.3 | 7.8 | .0046 | -11 ▼ |
| ubiquiti | 0 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | 0 |
| palo alto networks | 0 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | 0 |
| fortinet | 1 | 42 | 12 | 10 | 17 | 3 | 30 | 8 | 19.0 | 7.2 | .0040 | +1 ▲ |
| netgear | 0 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | 0 |
| f5 | 0 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | -7 ▼ |
| ivanti | 0 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | 0 |
| sonicwall | 0 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 97 | 804 | 165 | 365 | 249 | 18 | 33 | 2 | 0.2 | 7.5 | .0060 | +96 ▲ |
| mozilla | 0 | 379 | 122 | 169 | 87 | 0 | 9 | 0 | 0.0 | 8.8 | .0031 | -34 ▼ |
| gitlab | 1 | 105 | 8 | 24 | 62 | 11 | 5 | 3 | 2.9 | 5.3 | .0034 | +1 ▲ |
| drupal | 0 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | -26 ▼ |
| github | 0 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | -3 ▼ |
| docker | 0 | 12 | 1 | 8 | 3 | 0 | 0 | 0 | 0.0 | 8.4 | .0017 | 0 |
| wordpress | 0 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0392 | 0 |
| eclipse | 0 | 2 | 2 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.3 | .0050 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | 0 |
| ibm | 0 | 1023 | 196 | 473 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | 0 |
| adobe | 0 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | 0 |
| progress | 0 | 66 | 15 | 40 | 11 | 0 | 6 | 1 | 1.5 | 8.1 | .0045 | -2 ▼ |
| zohocorp | 0 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | -1 ▼ |
| solarwinds | 0 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | 0 |
| servicenow | 0 | 10 | 7 | 3 | 0 | 0 | 2 | 0 | 0.0 | 9.4 | .0036 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | 0 |
| siemens | 0 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | 0 |
| synology | 0 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | 0 |
| rockwell automation | 0 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | -17 ▼ |
| advantech | 0 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | 0 |
| schneider electric | 0 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | -4 ▼ |
| hitachi energy | 0 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0025 | 0 |
| abb | 0 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 0 | 378 | 34 | 170 | 152 | 22 | 2 | 1 | 0.3 | 7.2 | .0027 | -13 ▼ |
| nvidia | 0 | 301 | 25 | 206 | 70 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | -30 ▼ |
| sourcecodester | 2 | 239 | 0 | 0 | 143 | 96 | 0 | 0 | 0.0 | 5.5 | .0042 | +2 ▲ |
| openclaw | 0 | 223 | 4 | 114 | 84 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| mongodb | 0 | 169 | 6 | 99 | 60 | 4 | 1 | 0 | 0.0 | 7.1 | .0038 | 0 |
| hewlett packard enterprise (hpe) | 0 | 166 | 22 | 80 | 55 | 9 | 1 | 1 | 0.6 | 7.2 | .0042 | -86 ▼ |
| itsourcecode | 5 | 158 | 0 | 0 | 37 | 121 | 0 | 0 | 0.0 | 2.1 | .0033 | +5 ▲ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9296 | 99.8 | 10.0 |
| CVE-2026-85046 | .4888 | 98.8 | 8.8 |
| CVE-2026-87902 | .4550 | 98.8 | 8.1 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.5 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE-2026-12269 | .0699 | 94.0 | 8.8 |
| CVE-2026-67276 | .0645 | 93.5 | 9.2 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9296 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 | |
| CVE-2026-75703 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 2115 |
| microsoft | 1002 |
| 647 | |
| oracle | 634 |
| ibm | 404 |
| apache | 291 |
| red hat | 265 |
| apple | 247 |
| adobe | 224 |
| dell | 194 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 17 |
| apple | 9 |
| 9 | |
| fortinet | 8 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 123 |
| NuGet | 24 |
| Packagist | 24 |
| npm | 24 |
| PyPI | 13 |
| crates.io | 10 |
| Go | 9 |
| RubyGems | 5 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-85046 | 0 | |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-102489 | Zammad GmbH | 1 |
| CVE-2026-102490 | Zammad GmbH | 1 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1780 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1780 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1780 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1780 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1780 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1780 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1780 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1780 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1780 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1780 |
ADDED TO KEV — CVE-2026-102489 (Zammad GmbH Zammad). Remediation due October 5, 2026.
ADDED TO KEV — CVE-2026-102490 (Zammad GmbH Zammad). Remediation due October 5, 2026.
EXPLOIT PUBLISHED — GNOME GLib: 6 CVEs (CVE-2026-58010, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016). Public exploit references added.
EXPLOIT PUBLISHED — Google Chrome: 4 CVEs (CVE-2026-95275, CVE-2026-95363, CVE-2026-95373, CVE-2026-95374). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2019-1579 (Palo Alto Networks GlobalProtect Portal/Gateway Interface). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-54403 (Yonyou U8 CRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102293 (realjerrytang tacomall). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102569 (MacWarrior clipbucket-v5). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102620 (Freedesktop Poppler). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102792 (Ziroom ZHOME A0101). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102804 (Nothings stb). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102843 (gedelumbung HospitalManagement). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102846 (gedelumbung HospitalManagement). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102906 (0xshariq github-mcp-server). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102910 (SourceCodester Online Reviewer Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-102913 (SourceCodester Car Driving School Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103115 (OS4ED openSIS-Classic). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103231 (AdithyaYelloju Restaurant-Management-System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103241 (vllm-project vLLM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-4878 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-48864 (Red Hat Enterprise Linux 10). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-64849 (mlflow). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66402 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-67289 (FreeRDP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-71486 (vllm-project vllm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-90843 (SabyasachiRana WebMap). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93984 (Openpanel-dev openpanel). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97062 (Webkul Aureus ERP). Public exploit reference added.
RESCORED — JetBrains YouTrack: 8 CVEs (CVE-2026-100262, CVE-2026-100263, CVE-2026-100270, CVE-2026-100273, CVE-2026-100275, CVE-2026-100276, CVE-2026-100277, CVE-2026-100280). CVSS rescored — before/after on each CVE page.
RESCORED — cisagov Malcolm: 3 CVEs (CVE-2026-55676, CVE-2026-63133, CVE-2026-63134). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2022-37009 (JetBrains IntelliJ IDEA). CVSS 3.9 → 7.8 (NVD).
RESCORED — CVE-2025-32220 (Dimitri Grassi Salon booking system). CVSS 5.4 → 8.8 (NVD).
RESCORED — CVE-2026-100255 (JetBrains TeamCity). CVSS 8.1 → 9.8 (NVD).
RESCORED — CVE-2026-100265 (JetBrains Rider). CVSS 4.8 → 6.5 (NVD).
RESCORED — CVE-2026-100266 (JetBrains Hub). CVSS 7.7 → 6.5 (NVD).
RESCORED — CVE-2026-7064 (AgentDeskAI browser-tools-mcp). CVSS 6.9 → 5.5 (NVD).
RESCORED — CVE-2026-79687 (Dell PowerStore 500T). CVSS 9 → 10 (NVD).
RESCORED — CVE-2026-81479 (Dell OpenManage Server Administrator Managed Node (Patch) for Windows). CVSS 5.8 → 5.5 (NVD).
PATCH SHIPPED — Red Hat Hardened Images: 5 CVEs (CVE-2026-19617, CVE-2026-79705, CVE-2026-84233, CVE-2026-88265, CVE-2026-95512). Fix versions published.
PATCH SHIPPED — cisagov Malcolm: 4 CVEs (CVE-2026-55676, CVE-2026-63133, CVE-2026-63134, CVE-2026-63177). Fix versions published.
PATCH SHIPPED — CVE-2026-97062 (Webkul Aureus ERP). Fixed in Aureus ERP 53ad76dd566f414f1773ec6513616fc2b9e251b5.
ENRICHED — Linux: 15 CVEs (CVE-2026-63973, CVE-2026-64001, CVE-2026-98062, CVE-2026-98109, CVE-2026-98152, CVE-2026-98160, CVE-2026-98161, CVE-2026-98162, CVE-2026-98163, CVE-2026-98164, CVE-2026-100074, CVE-2026-100076, CVE-2026-100077, CVE-2026-100078, CVE-2026-100079). Received CVSS/CPE analysis.
How to read these box scores · glossary
398 CVEs published. 25 box scores, 373 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0088 57.8 —
AFFECTED Product Versions Fixed Super Forms – Drag & Drop Form Builder unspecified —
TIMELINE Jul 15 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0064 48.7 —
AFFECTED Product Versions Fixed JSON API Auth unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0056 44.9 —
AFFECTED Product Versions Fixed SiteOrigin Widgets Bundle unspecified —
TIMELINE Sep 15 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H H H 8.1 .0052 42.0 —
AFFECTED Product Versions Fixed Ninja Forms - File Uploads unspecified —
TIMELINE Sep 16 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0049 40.1 —
AFFECTED Product Versions Fixed WPMobile.App – Android and iOS App Builder unspecified —
TIMELINE Sep 21 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0048 39.1 —
AFFECTED Product Versions Fixed DevKit Pro unspecified —
TIMELINE Jul 1 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H N N 8.2 .0047 38.2 —
AFFECTED Product Versions Fixed bc-csharp unspecified —
TIMELINE Jul 16 Reserved by CNA Oct 2 Published (CNA: bcorg)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0046 37.9 —
AFFECTED Product Versions Fixed cPanel unspecified — WP Squared unspecified —
TIMELINE Sep 18 Reserved by CNA Oct 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C L L N 6.1 .0046 37.7 —
AFFECTED Product Versions Fixed WP Statistics – Simple, privacy-friendly Google Analytics alternative unspecified —
TIMELINE Sep 24 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N N L 5.3 .0044 35.6 —
AFFECTED Product Versions Fixed BC-JAVA unspecified — BC-JAVA unspecified — BC-LTS-JAVA 2.73.0 – — BC-LTS-JAVA 2.73.0 – — BC-FJA 1.0.0 – —
TIMELINE Jul 26 Reserved by CNA Oct 2 Published (CNA: bcorg)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0043 35.0 —
AFFECTED Product Versions Fixed Sef - AI Chatbot Platform unspecified —
TIMELINE Aug 26 Reserved by CNA Oct 2 Published (CNA: TR-CERT)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0043 34.6 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Sep 21 Reserved by CNA Oct 2 Published (CNA: apache)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N N N H 8.2 .0043 34.6 —
AFFECTED Product Versions Fixed Apache Thrift unspecified —
TIMELINE Sep 21 Reserved by CNA Oct 2 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C L L N 7.2 .0042 33.9 —
AFFECTED Product Versions Fixed W3 Total Cache unspecified —
TIMELINE Sep 9 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 8.7 .0041 33.1 —
AFFECTED Product Versions Fixed bc-csharp unspecified —
TIMELINE Sep 30 Reserved by CNA Oct 2 Published (CNA: bcorg)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C H H H 9.0 .0040 32.0 —
AFFECTED Product Versions Fixed cPanel unspecified — WP Squared unspecified —
TIMELINE Sep 17 Reserved by CNA Oct 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L R C H H H 9.0 .0040 32.0 —
AFFECTED Product Versions Fixed cPanel unspecified — WP Squared unspecified —
TIMELINE Sep 18 Reserved by CNA Oct 2 Published (CNA: hackerone)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0040 31.5 —
AFFECTED Product Versions Fixed Divi Membership unspecified —
TIMELINE Aug 12 Reserved by CNA Oct 2 Published (CNA: Wordfence)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H N 9.4 .0040 31.6 —
AFFECTED Product Versions Fixed libdave 1.1.0 – —
TIMELINE Oct 2 Reserved by CNA Oct 2 Published (CNA: Bugcrowd)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H N 9.1 .0040 31.4 —
AFFECTED Product Versions Fixed bc-csharp unspecified —
TIMELINE Jul 16 Reserved by CNA Oct 2 Published (CNA: bcorg)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L A L L N 4.8 .0040 31.5 —
AFFECTED Product Versions Fixed Repasat application unspecified —
TIMELINE Jul 6 Reserved by CNA Oct 2 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L A L L N 4.8 .0040 31.5 —
AFFECTED Product Versions Fixed Repasat application unspecified —
TIMELINE Jul 6 Reserved by CNA Oct 2 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L A L L N 4.8 .0040 31.5 —
AFFECTED Product Versions Fixed Repasat application unspecified —
TIMELINE Jul 6 Reserved by CNA Oct 2 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L A L L N 4.8 .0040 31.5 —
AFFECTED Product Versions Fixed Repasat application unspecified —
TIMELINE Sep 22 Reserved by CNA Oct 2 Published (CNA: INCIBE)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L A L L N 4.8 .0038 29.6 —
AFFECTED Product Versions Fixed Repasat application unspecified —
TIMELINE Jul 6 Reserved by CNA Oct 2 Published (CNA: INCIBE)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-59673 | 4.8 | 29.6 | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-63566 | 8.7 | 28.7 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-789 | DTLS handshake reassembler allocates buffer from unchecked 24-bit length |
| CVE-2026-85492 | 6.1 | 28.3 | smub | All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) | CWE-79 | All in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL … |
| CVE-2026-104403 | 5.3 | 25.1 | ThimPress | LearnPress | CWE-639 | WordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDO… |
| CVE-2026-63572 | 7.1 | 23.9 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-770 | Unbounded MAC and bag-decryption iteration counts when loading PKCS#12 files |
| CVE-2026-63578 | 7.1 | 23.9 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-770 | Unbounded PBE iteration count when decrypting PKCS#8 private keys |
| CVE-2026-104123 | 5.5 | 23.8 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System btn_functions.php activity s… |
| CVE-2026-94405 | 5.3 | 23.3 | Shahjada | Download Manager | CWE-639 | WordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnera… |
| CVE-2026-17507 | 8.7 | 23.2 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-195 | MLS membership checks compare a uint32 leaf_index as signed, admitting an out… |
| CVE-2026-63568 | 8.7 | 22.6 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-770 | Unbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustion |
| CVE-2026-10026 | 7.2 | 22.5 | CTX | CTX Feed Pro | CWE-94 | CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution |
| CVE-2026-63574 | 8.7 | 22.2 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-789 | Unbounded allocation from OpenPGP signature and user attribute subpacket lengths |
| CVE-2026-103600 | 8.7 | 22.2 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-674 | Unbounded ASN.1 nesting depth causes process-terminating stack overflow |
| CVE-2026-59669 | 4.8 | 22.2 | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-63573 | 8.2 | 21.4 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-203 | Bleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrap |
| CVE-2026-100107 | 7.2 | 21.3 | extendthemes | Kubio AI Page Builder | CWE-79 | Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting … |
| CVE-2026-100182 | 7.2 | 21.3 | wpchill | Download Monitor | CWE-79 | Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-102565 | 7.2 | 21.3 | bookingalgorithms | BA Book Everything | CWE-79 | BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting vi… |
| CVE-2026-102772 | 7.2 | 21.3 | jtsternberg | CMB2 | CWE-79 | CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_co… |
| CVE-2026-12951 | 6.5 | 21.3 | wcmp | MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions | CWE-89 | MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'or… |
| CVE-2026-15897 | 8.8 | 20.9 | WebRehab | Super Forms – Drag & Drop Form Builder | CWE-269 | Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber… |
| CVE-2026-90438 | 7.2 | 19.8 | kstover | Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder | CWE-79 | Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Parag… |
| CVE-2026-104120 | 5.5 | 19.4 | modelcontextprotocol | mcp-server-fetch | CWE-918 | modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server… |
| CVE-2026-59670 | 4.8 | 19.4 | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59671 | 4.8 | 19.4 | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-103601 | 8.2 | 19.1 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-354 | CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output b… |
| CVE-2026-97336 | 7.2 | 19.0 | jtsternberg | CMB2 | CWE-79 | CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' … |
| CVE-2026-102002 | 3.1 | 19.1 | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | CWE-200 | Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exp… |
| CVE-2026-18036 | 8.2 | 18.8 | Legion of the Bouncy Castle Inc. | BC-JAVA | CWE-208 | NTRU leaks private key information by reducing secret values with a non-const… |
| CVE-2026-97634 | 6.5 | 18.7 | stellarwp | Event Tickets and Registration | CWE-89 | Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL I… |
| CVE-2026-94180 | 4.3 | 18.7 | Monetizemore | Advanced Ads | CWE-639 | WordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerability |
| CVE-2026-80464 | 4.9 | 18.0 | HAVELSAN Inc. | Sef - AI Chatbot Platform | CWE-918 | API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform |
| CVE-2026-96566 | 7.2 | 17.6 | satollo | Newsletter – Send awesome emails from WordPress | CWE-79 | Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' C… |
| CVE-2026-93756 | 7.2 | 17.1 | smub | Smash Balloon Social Post Feed – Simple Social Feeds for WordPress | CWE-79 | Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site … |
| CVE-2026-94432 | 5.3 | 17.0 | latepoint | Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | CWE-639 | Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Una… |
| CVE-2026-91020 | 5.3 | 16.6 | Unknown | WebToffee Gift Cards for WooCommerce | CWE-472 | WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amou… |
| CVE-2026-103604 | 8.7 | 15.9 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-407 | Quadratic-time escaping when converting X.509 distinguished names to strings |
| CVE-2026-96567 | 7.2 | 15.9 | websoudan | MW WP Form | CWE-79 | MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_i… |
| CVE-2026-16000 | 8.7 | 15.2 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-325 | KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated dat… |
| CVE-2026-96578 | 7.2 | 14.8 | creative-solutions-1 | GSpeech TTS – WordPress Text To Speech Plugin | CWE-79 | GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comme… |
| CVE-2026-13413 | 5.3 | 14.5 | Unknown | CMP – Coming Soon & Maintenance | CWE-284 | CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode B… |
| CVE-2026-103602 | 8.2 | 14.1 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-295 | Name constraints bypass via trailing dot in rfc822Name, dNSName and URI hosts |
| CVE-2026-95670 | 7.2 | 13.8 | mihdan | No External Links | CWE-79 | No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via … |
| CVE-2026-96871 | 7.2 | 13.8 | kitae-park | Mang Board | CWE-79 | Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_t… |
| CVE-2026-97342 | 7.2 | 13.8 | jetmonsters | JetFormBuilder — Dynamic Blocks Form Builder | CWE-79 | JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via '… |
| CVE-2026-97641 | 7.2 | 13.8 | comesio | Relevanssi – A Better Search | CWE-79 | Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Commen… |
| CVE-2026-97663 | 7.2 | 13.8 | ivole | Customer Reviews for WooCommerce | CWE-79 | Customer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Si… |
| CVE-2026-63577 | 8.2 | 13.2 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-295 | Name Constraints bypass: directoryName constraint matched at any position in … |
| CVE-2026-95817 | 7.2 | 13.3 | apasionados | DoFollow Case by Case | CWE-79 | DoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting … |
| CVE-2026-90987 | 5.3 | 13.2 | Unknown | Easy PayPal & Stripe Buy Now Button | CWE-472 | Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amo… |
| CVE-2026-90952 | 5.3 | 13.1 | Unknown | WP Edit Password Protected | CWE-862 | WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access M… |
| CVE-2026-103426 | 7.2 | 12.7 | Relevanssi | Relevanssi Premium | CWE-79 | Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting vi… |
| CVE-2026-15999 | 8.2 | 12.2 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-354 | AES-CCM decryption accepts zero or out-of-range tag length, bypassing authent… |
| CVE-2026-84740 | 6.5 | 11.7 | Unknown | The Events Calendar | CWE-74 | The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Exe… |
| CVE-2026-85005 | 5.4 | 11.7 | Unknown | Popup Maker WP | CWE-862 | Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invoc… |
| CVE-2026-78471 | 5.4 | 11.5 | optimizingmatters | Autoptimize | CWE-79 | Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Com… |
| CVE-2026-63576 | 8.2 | 11.1 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-295 | URI name constraints checked against a mis-parsed host |
| CVE-2026-1661 | 4.3 | 11.1 | Unknown | WP Mail Logging | CWE-79 | WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection |
| CVE-2026-97338 | 6.4 | 10.9 | codename065 | Download Manager | CWE-79 | Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Sc… |
| CVE-2026-63570 | 7.1 | 10.6 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-835 | Pkcs12Store.GetCertificateChain loops forever on cyclic issuer links |
| CVE-2026-93880 | 6.1 | 10.3 | wpsoul | Greenshift – animation and page builder blocks | CWE-79 | Greenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic … |
| CVE-2026-80337 | 5.3 | 10.2 | HAVELSAN Inc. | Sef - AI Chatbot Platform | CWE-862 | Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Pla… |
| CVE-2026-104054 | 2.1 | 10.1 | calcom | cal.diy | CWE-862 | calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessTo… |
| CVE-2026-96647 | 6.4 | 9.0 | webilia | Listdom: AI-powered Business Directory with Classifieds Ads Listings | CWE-79 | Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1… |
| CVE-2026-104052 | 2.1 | 8.9 | itsourcecode | Pet Shop Management System | CWE-74 | itsourcecode Pet Shop Management System admin_reject_completed.php sql injection |
| CVE-2026-104053 | 2.1 | 8.9 | itsourcecode | Pet Shop Management System | CWE-74 | itsourcecode Pet Shop Management System admin_reservefilter.php sql injection |
| CVE-2026-93367 | 7.2 | 8.2 | wp-buy | Visitor Traffic Real Time Statistics pro | CWE-79 | Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored C… |
| CVE-2026-63575 | 7.1 | 8.2 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-835 | PKCS#12 key derivation loops about 2^32 times on a zero or negative iteration… |
| CVE-2026-102731 | await | 8.1 | Apache Software Foundation | Apache Directory LDAP API | CWE-789 | Apache Directory LDAP API: Denial of service via excessive memory allocation … |
| CVE-2026-79618 | 4.3 | 7.3 | Unknown | WP User Frontend | CWE-862 | WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated … |
| CVE-2026-97219 | 4.3 | 7.3 | Unknown | MStore API | CWE-862 | MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter |
| CVE-2026-92924 | 5.4 | 7.1 | Unknown | Unlimited Elements for Elementor | CWE-74 | Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode E… |
| CVE-2026-103552 | 7.3 | 7.0 | Apache Software Foundation | Apache Directory LDAP API | CWE-121 | Apache Directory LDAP API: A unbound client can send a deeply nested search f… |
| CVE-2026-91828 | 7.5 | 6.3 | Unknown | OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. | CWE-400 | OMGF < 6.3.11 - Unauthenticated DoS via do_optimize |
| CVE-2026-16001 | 8.2 | 6.0 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-354 | IesEngine stream-mode MAC forgery via length-dependent KDF split |
| CVE-2026-95512 | 5.5 | 5.9 | Red Hat | Red Hat Hardened Images | CWE-400 | Freetype: freetype: denial of service via repeated subroutine allocations in … |
| CVE-2026-63571 | 8.7 | 5.6 | Legion of the Bouncy Castle Inc. | bc-csharp | CWE-347 | Attribute certificate path validation does not verify the attribute certifica… |
| CVE-2026-84925 | 6.1 | 5.5 | ThemeFusion | Avada | Website Builder For WordPress & WooCommerce | CWE-79 | Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cro… |
| CVE-2026-80443 | 7.4 | 5.0 | HAVELSAN Inc. | Sef - AI Chatbot Platform | CWE-295 | Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI… |
| CVE-2026-103098 | 7.5 | 4.6 | GeoVision Inc. | GV-Eye | CWE-319 | GV-Eye Sensitive information exposure in URL query parameter Vulnerability |
| CVE-2026-94298 | 6.2 | 4.3 | Unknown | BuildKit | CWE-89 | BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter |
| CVE-2026-91784 | 4.8 | 3.9 | cjbassi | gotop | CWE-88 | Argument Injection leading to arbitrary process termination in gotop |
| CVE-2026-103096 | 7.5 | 3.7 | GeoVision Inc. | GV-Eye | CWE-312 | GV-Eye Hardcoded API Key Vulnerability |
| CVE-2026-103097 | 7.5 | 3.7 | GeoVision Inc. | GV-Eye | CWE-312 | GV-Eye Relay Payment API Key Vulnerability |
| CVE-2026-13718 | 6.8 | 3.7 | Unknown | Tabs Responsive | CWE-79 | Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab… |
| CVE-2026-85016 | 6.8 | 3.7 | Unknown | Unlimited Elements for Elementor | CWE-79 | Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon … |
| CVE-2026-91022 | 6.8 | 3.7 | Unknown | Motors | CWE-79 | Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color |
| CVE-2026-90988 | 5.3 | 3.2 | Unknown | Request a Quote | CWE-200 | Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Discl… |
| CVE-2026-97317 | 5.3 | 2.8 | Unknown | Giveaways and Contests by RafflePress | CWE-200 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA S… |
| CVE-2026-97318 | 6.1 | 2.6 | Unknown | Giveaways and Contests by RafflePress | CWE-601 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open… |
| CVE-2026-81740 | 5.3 | 2.6 | Unknown | Paytm Payment Gateway | CWE-287 | Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via… |
| CVE-2026-85004 | 4.3 | 2.3 | Unknown | Popup Maker | CWE-284 | Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect |
| CVE-2026-91023 | 3.1 | 2.3 | Unknown | Motors | CWE-862 | Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-U… |
| CVE-2026-21140 | 6.9 | 1.0 | Samsung Mobile | Samsung Mobile Devices | — | Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release … |
| CVE-2026-103956 | 10.0 | — | AWS | loom | CWE-306 | Missing authentication for critical function in Loom for AWS |
| CVE-2026-90970 | 9.9 | — | GitLab | GitLab AI Gateway | CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine in GitL… |
| CVE-2026-19652 | 9.8 | — | DiviEngine | Divi Membership | CWE-269 | Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id'… |
| CVE-2026-104846 | 9.8 | — | lxsmnsyc | seroval | CWE-843 | Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced c… |
| CVE-2026-103628 | 9.6 | — | Chrome | CWE-787 | Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed … | |
| CVE-2026-104848 | 9.5 | — | tinylibs | tinypool | CWE-1321 | Tinypool: Prototype Pollution gadget in worker options leads to Remote Code E… |
| CVE-2026-104849 | 9.5 | — | tinylibs | tinypool | CWE-94 | Tinypool: Prototype Pollution Gadget to RCE in run() options |
| CVE-2026-75937 | 9.4 | — | Digi International | IX Family | CWE-78 | OS Command Injection in Digi Accelerated Linux (DAL OS) |
| CVE-2026-86325 | 9.4 | — | Moxa | MGate MB3170 Series | CWE-121 | A stack-based buffer overflow vulnerability exists in protocol gateways' acco… |
| CVE-2023-54405 | 9.3 | — | H3C | CVM | CWE-434 | H3C CVM Unauthenticated File Upload via fileUpload/upload Token |
| CVE-2026-82042 | 9.3 | — | UTMStack | UTMStack | CWE-306 | UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter |
| CVE-2026-84411 | 9.3 | — | MikroTik | RouterOS | CWE-191 | MikroTik RouterOS Integer Underflow |
| CVE-2026-95102 | 9.3 | — | Monta | monta.app | CWE-306 | Monta monta.app Missing Authentication for Critical Function |
| CVE-2026-104019 | 9.3 | — | AWS | sagemaker-distribution | CWE-78 | OS command injection in the Studio Space startup validation script in Amazon … |
| CVE-2026-104610 | 9.3 | — | Tenda | HG7 | CWE-119 | Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow |
| CVE-2026-83632 | 9.2 | — | Apache Software Foundation | Apache Thrift | CWE-122 | Apache Thrift: C++ THttpTransport grows its line buffer without bound |
| CVE-2026-91135 | 9.2 | — | Apache Software Foundation | Apache Thrift | CWE-122 | Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (writ… |
| CVE-2026-104467 | 9.2 | — | YesWiki | yeswiki | CWE-862 | YesWiki before 4.6.7 Authorization Bypass via Public API Mode |
| CVE-2026-103648 | 9.1 | — | demsking | image-downloader | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'… |
| CVE-2026-39718 | 8.8 | — | Webriti | Wallstreet | CWE-352 | WordPress Wallstreet theme <= 2.8.6 - Cross Site Request Forgery (CSRF) vulne… |
| CVE-2026-96940 | 8.8 | — | Microsoft | Microsoft Exchange Server 2016 Cumulative Update 23 | CWE-1390 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-103622 | 8.8 | — | Chrome | CWE-416 | Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remot… | |
| CVE-2026-103625 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote… | |
| CVE-2026-104445 | 8.8 | — | YesWiki | yeswiki | CWE-290 | YesWiki before 4.6.7 Authentication Bypass via ActivityPub Inbox Actor Spoofing |
| CVE-2026-104457 | 8.8 | — | YesWiki | yeswiki | CWE-89 | YesWiki before 4.6.7 SQL Injection via filtertags filterN parameter |
| CVE-2026-104462 | 8.8 | — | YesWiki | yeswiki | CWE-89 | YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter |
| CVE-2026-104464 | 8.8 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 SSRF via Bazar abonnements sync actor parameter |
| CVE-2026-104851 | 8.8 | — | fsspec | filesystem_spec | CWE-94 | fsspec: Server-Side Template Injection in ReferenceFileSystem leads to Remote… |
| CVE-2014-125130 | 8.7 | — | Damjan | CodeArt Google MP3 Audio Player | CWE-22 | CodeArt Google MP3 Audio Player 1.0.11 Arbitrary File Read via direct_downloa… |
| CVE-2020-37278 | 8.7 | — | Weaver | e-Bridge | CWE-918 | Weaver e-Bridge Unauthenticated Arbitrary File Read via saveYZJFile |
| CVE-2026-61373 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Java TSaslNonblockingServer pre-auth unbounded SASL frame allo… |
| CVE-2026-63772 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Unauthenticated single-packet crash of Go Thrift servers via t… |
| CVE-2026-66081 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-824 | Apache Thrift: c_glib read_message_begin leaves output parameters unset for n… |
| CVE-2026-66837 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-121 | Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled st… |
| CVE-2026-66858 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-674 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap… |
| CVE-2026-66859 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-457 | Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route |
| CVE-2026-82039 | 8.7 | — | UTMStack | UTMStack | CWE-89 | UTMStack < 11.2.16 SQL Injection via searchGroupsByFilter |
| CVE-2026-82458 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap… |
| CVE-2026-83663 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-674 | Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per f… |
| CVE-2026-83745 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-130 | Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload b… |
| CVE-2026-85493 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift, Apache Thrift: TProtocolUtil.skip follows peer-chosen nesting … |
| CVE-2026-85494 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-130 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap… |
| CVE-2026-86535 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-835 | Apache Thrift: A JSON member name can stall the Node server's event loop inde… |
| CVE-2026-86537 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-191 | Apache Thrift: A truncated HTTP request stops the D library's server, allowin… |
| CVE-2026-87117 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-476 | Apache Thrift: PHP `thrift_protocol` accelerator dereferences a missing conta… |
| CVE-2026-91137 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements |
| CVE-2026-93925 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-121 | Apache Thrift: C++ `THeaderTransport::writeVarint32()` stack buffer overflow … |
| CVE-2026-93926 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-401 | Apache Thrift: C++ `THeaderTransport::untransform()` leaks the zlib stream on… |
| CVE-2026-94422 | 8.7 | — | — | xdg-dbus-proxy | CWE-290 | xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape |
| CVE-2026-94633 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-130 | Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre… |
| CVE-2026-94642 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift: PHP `TSimpleServer` exits the whole process on any non-transpo… |
| CVE-2026-94646 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift: Node.js `server.js` ends the process on any per-connection err… |
| CVE-2026-94658 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-407 | Apache Thrift: Lua `TFramedTransport`/`THttpTransport` re-slice the buffer on… |
| CVE-2026-96277 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift: Ruby `SimpleServer` ends `serve()` on any non-Transport/Protoc… |
| CVE-2026-96294 | 8.7 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift: nodejs web server: no `error` listener on an upgraded WebSocke… |
| CVE-2026-97363 | 8.7 | — | Monta | monta.app | CWE-307 | Monta monta.app Improper Restriction of Excessive Authentication Attempts |
| CVE-2026-104410 | 8.7 | — | siyuan-note | siyuan | CWE-862 | SiYuan before 3.8.5 Information Disclosure via /api/export/preview |
| CVE-2026-104422 | 8.7 | — | ZcashFoundation | zebra | CWE-345 | Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite |
| CVE-2026-104423 | 8.7 | — | ZcashFoundation | zebra | CWE-405 | Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification |
| CVE-2026-104430 | 8.7 | — | ZcashFoundation | zebra | CWE-628 | Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount |
| CVE-2026-104431 | 8.7 | — | ZcashFoundation | zebra | CWE-405 | Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification |
| CVE-2026-104433 | 8.7 | — | kvcache-ai | Mooncake | CWE-125 | Mooncake before 0.3.12 Out-of-Bounds Read via P2P Handshake readString |
| CVE-2026-104438 | 8.7 | — | YesWiki | yeswiki | CWE-862 | YesWiki before 4.6.7 Information Disclosure via listpagestag and includepages… |
| CVE-2026-104460 | 8.7 | — | YesWiki | yeswiki | CWE-89 | YesWiki before 4.6.7 Unauthenticated Blind SQL Injection via newtextsearch |
| CVE-2026-104472 | 8.7 | — | YesWiki | yeswiki | CWE-862 | YesWiki before 4.6.7 Missing Authorization via Attachment Download Handler |
| CVE-2026-86326 | 8.6 | — | Moxa | MGate MB3170 Series | CWE-347 | An improper verification of cryptographic signature vulnerability exists in p… |
| CVE-2026-94591 | 8.6 | — | Armatura LLC | Armatura One | CWE-321 | Armatura LLC Armatura One Use of Hard-coded Cryptographic Key |
| CVE-2026-94592 | 8.6 | — | Armatura LLC | Armatura One | CWE-798 | Armatura LLC Armatura One Use of Hard-coded Credentials |
| CVE-2026-104414 | 8.6 | — | TryGhost | Ghost | CWE-79 | Ghost from 2.5.0 before 6.64.0 Stored XSS via oEmbed Photo Responses |
| CVE-2026-104418 | 8.6 | — | TryGhost | Ghost | CWE-22 | Ghost from 6.10.3 before 6.64.0 RCE via Theme Translation Files |
| CVE-2026-104471 | 8.6 | — | YesWiki | yeswiki | CWE-434 | YesWiki before 4.6.7 Unrestricted File Upload via Bazar CSV Import |
| CVE-2026-94593 | 8.5 | — | Armatura LLC | Armatura One | CWE-532 | Armatura LLC Armatura One Insertion of Sensitive Information into Log File |
| CVE-2026-104411 | 8.5 | — | TryGhost | Ghost | CWE-79 | Ghost 6.22.1 before 6.64.0 Stored XSS via Local Storage File Uploads |
| CVE-2026-104413 | 8.5 | — | TryGhost | Ghost | CWE-79 | Ghost 5.94.0 before 6.64.0 Stored XSS via Bookmark Card Images |
| CVE-2026-104611 | 8.5 | — | Tenda | AC9 | CWE-119 | Tenda AC9 POST Request fast_setting_internet_set stack-based overflow |
| CVE-2026-104847 | 8.5 | — | ProseMirror | prosemirror-view | CWE-79 | ProseMirror: XSS vulnerability in prosemirror-view's paste handling |
| CVE-2026-104854 | 8.5 | — | nrwl | nx | CWE-269 | Nx daemon and plugin worker sockets are accessible to other local users |
| CVE-2026-94483 | 8.3 | — | vercel | next.js | CWE-918 | Next.js: Server-Side Request Forgery in Image Optimization |
| CVE-2026-103958 | 8.3 | — | AWS | loom | CWE-918 | Server-side request forgery in the tool server and remote agent connection ha… |
| CVE-2026-104435 | 8.3 | — | ZcashFoundation | zebra | CWE-347 | Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output |
| CVE-2026-104437 | 8.3 | — | ZcashFoundation | zebra | CWE-347 | Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling |
| CVE-2026-104449 | 8.3 | — | YesWiki | yeswiki | CWE-639 | YesWiki before 4.6.7 Unauthenticated Page Overwrite via Bazar id_fiche |
| CVE-2026-104458 | 8.3 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 SSRF Guard Bypass via IPv6 Transition Addresses |
| CVE-2026-104463 | 8.3 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 Unauthenticated SSRF via ActivityPub Inbox |
| CVE-2026-66055 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Ap… |
| CVE-2026-82459 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-191 | Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenti… |
| CVE-2026-85476 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-835 | Apache Thrift: c_glib `read_all` spins when the underlying read returns 0 |
| CVE-2026-90440 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift: An exception escaping a libevent callback stops the D library'… |
| CVE-2026-94634 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Python `TJSONProtocol` has a string length limit that is off b… |
| CVE-2026-94636 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-409 | Apache Thrift: Python `TZlibTransport` stops enforcing its decompressed-size … |
| CVE-2026-94637 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-409 | Apache Thrift: Go `THeaderTransport` does not bound the inflated size of a ZL… |
| CVE-2026-94644 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: PHP `TJSONProtocol` string/number readers have no size bound |
| CVE-2026-94645 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Node.js `TJSONProtocol` uses a peer-declared container size as… |
| CVE-2026-94648 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: dart `TJsonProtocol`/`TJSONProtocol` has no string size bound |
| CVE-2026-94650 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-674 | Apache Thrift: c_glib generated struct readers have no recursion-depth guard … |
| CVE-2026-94651 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-755 | Apache Thrift: Java `TSaslNonblockingServer` `Computation.run` orphans a conn… |
| CVE-2026-94653 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-407 | Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every… |
| CVE-2026-94654 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-835 | Apache Thrift: Python `TNonblockingServer` busy-loops and stops selecting all… |
| CVE-2026-94655 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-407 | Apache Thrift: Lua `TJsonProtocol` string/number readers have no size bound a… |
| CVE-2026-94656 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: rb `TJsonProtocol`/`TJSONProtocol` has no string size bound |
| CVE-2026-94657 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: javame `TJsonProtocol`/`TJSONProtocol` has no string size bound |
| CVE-2026-96286 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-248 | Apache Thrift: Perl servers end `serve()` when serving one connection fails |
| CVE-2026-96287 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-407 | Apache Thrift: Perl `FramedTransport` reads and TLS socket writes re-slice th… |
| CVE-2026-96288 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-674 | Apache Thrift: Erlang generated struct reads have no recursion-depth guard (u… |
| CVE-2026-96289 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-674 | Apache Thrift: php `--gen php:inlined` struct readers (and `TProtocol::skipBi… |
| CVE-2026-96292 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-407 | Apache Thrift: Lua `THttpTransport:_parseHeaders` matches each header line wi… |
| CVE-2026-96990 | 8.2 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Erlang thrift_json_protocol reads a whole message with no size… |
| CVE-2026-103957 | 8.2 | — | AWS | loom | CWE-201 | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS |
| CVE-2026-104426 | 8.2 | — | ZcashFoundation | zebra | CWE-407 | Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check |
| CVE-2026-104427 | 8.2 | — | ZcashFoundation | zebra | CWE-459 | Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry |
| CVE-2026-104450 | 8.2 | — | YesWiki | yeswiki | CWE-79 | YesWiki before 4.6.7 ACL Bypass and Stored XSS via pointimage Action |
| CVE-2026-104476 | 8.2 | — | backdrop | backdrop | CWE-200 | Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Ar… |
| CVE-2026-51907 | 8.1 | — | n/a | n/a | CWE-22 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image functio… |
| CVE-2026-104988 | 8.1 | — | Red Hat | Red Hat Certificate System 10 | CWE-290 | Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allo… |
| CVE-2026-104026 | 7.8 | — | Meta Platforms, Inc | Sapling SCM | CWE-150 | In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed… |
| CVE-2026-104416 | 7.7 | — | TryGhost | Ghost | CWE-203 | Ghost 4.39.0 before 6.64.0 Invite Token Disclosure via Admin API |
| CVE-2026-104469 | 7.6 | — | YesWiki | yeswiki | CWE-384 | YesWiki before 4.6.7 Session Fixation via Login in AuthController.php |
| CVE-2026-104873 | 7.6 | — | langchain-ai | langgraph | CWE-863 | LangGraph SDK custom auth silently ignores actions= on resource decorators |
| CVE-2026-51916 | 7.5 | — | n/a | n/a | CWE-284 | TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vuln… |
| CVE-2026-67989 | 7.5 | — | n/a | n/a | CWE-1333 | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a … |
| CVE-2026-104845 | 7.5 | — | lxsmnsyc | seroval | CWE-770 | Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserializ… |
| CVE-2026-104861 | 7.5 | — | nodeca | probe-image-size | CWE-400 | probe-image-size: Quadratic-time Denial of Service in the SVG Parser |
| CVE-2026-104733 | 7.4 | — | ProcessOne | ejabberd | CWE-290 | User Impersonation/Authorization Bypass in XMPP Server ejabberd |
| CVE-2026-104859 | 7.3 | — | nrwl | nx | CWE-78 | Nx: OS command injection in the @nx/docker release pipeline |
| CVE-2026-93875 | 7.2 | — | Crocoblock | JetAppointment | CWE-79 | JetAppointment <= 2.5.2.1 - Unauthenticated Stored Cross-Site Scripting via '… |
| CVE-2026-102626 | 7.2 | — | LimeSurvey | LimeSurvey | CWE-79 | LimeSurvey Community Edition 7.4.0 - Stored XSS through the Date/Time date_mi… |
| CVE-2026-104443 | 7.2 | — | YesWiki | yeswiki | CWE-863 | YesWiki before 4.6.7 Scope Bypass via Triples Delete API |
| CVE-2026-104448 | 7.2 | — | YesWiki | yeswiki | CWE-352 | YesWiki before 4.6.7 CSRF Page Deletion via ajaxdeletepage Handler |
| CVE-2026-104456 | 7.2 | — | YesWiki | yeswiki | CWE-89 | YesWiki before 4.6.7 Second-Order SQL Injection via ACL Username |
| CVE-2026-61374 | 7.1 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Java TSaslTransport post-auth data-frame missing size limit |
| CVE-2026-82045 | 7.1 | — | UTMStack | UTMStack | CWE-89 | UTMStack < 11.2.16 JPQL Injection via searchPropertyValues |
| CVE-2026-85215 | 7.1 | — | GG Soft Software Services Inc. | Paperwork | CWE-89 | SQL Injection in GG Soft's Paperwork |
| CVE-2026-96613 | 7.1 | — | Meari | IoT Cloud Platform OpenAPI Service | CWE-862 | Missing Authorization in Meari IoT Cloud Platform OpenAPI Service |
| CVE-2026-104434 | 7.1 | — | ZcashFoundation | zebra | CWE-617 | Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC |
| CVE-2026-104439 | 7.1 | — | YesWiki | yeswiki | CWE-204 | YesWiki before 4.6.7 User Enumeration via Lost-Password Flow |
| CVE-2026-104444 | 7.1 | — | YesWiki | yeswiki | CWE-639 | YesWiki before 4.6.7 Authorization Bypass via Comments API editComment |
| CVE-2026-104447 | 7.1 | — | YesWiki | yeswiki | CWE-352 | YesWiki before 4.6.7 CSRF Package Deletion via autoupdate UpdateAction |
| CVE-2026-104478 | 7.1 | — | getformwork | formwork | CWE-22 | Formwork before 2.3.13 Path Traversal via BackupController Download and Delete |
| CVE-2026-104908 | 7.1 | — | MISP | MISP | CWE-285 | MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Ov… |
| CVE-2026-104912 | 7.1 | — | MISP | MISP | CWE-284 | MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute … |
| CVE-2026-104991 | 7.1 | — | Alanaktion | phproject | CWE-862 | Phproject < 1.8.7 Missing Authorization via Issues REST API |
| CVE-2026-105050 | 7.1 | — | PeaZip | PeaZip | CWE-180 | PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS com… |
| CVE-2026-102795 | 7.0 | — | Apache Software Foundation | Apache Traffic Server | CWE-284 | Apache Traffic Server: SNI to Host header matching policy is not properly enf… |
| CVE-2026-66054 | 6.9 | — | Apache Software Foundation | Apache Thrift | CWE-409 | Apache Thrift: C++ THeaderTransport does not enforce configured maxFrameSize |
| CVE-2026-66331 | 6.9 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: Buffered transport reads are not accounted against MaxMessageSize |
| CVE-2026-82043 | 6.9 | — | UTMStack | UTMStack | CWE-204 | UTMStack < 11.2.16 Account Enumeration via Password Reset Endpoint |
| CVE-2026-85086 | 6.9 | — | Apache Software Foundation | Apache Thrift | CWE-295 | Apache Thrift: Perl TLS client disables certificate verification by default |
| CVE-2026-85087 | 6.9 | — | Apache Software Foundation | Apache Thrift | CWE-295 | Apache Thrift: Python ≥3.12 host-name check silently becomes a no-op |
| CVE-2026-85088 | 6.9 | — | Apache Software Foundation | Apache Thrift | CWE-295 | Apache Thrift, Apache Thrift: The C++ and D clients fall back to the certific… |
| CVE-2026-93474 | 6.9 | — | Monta | monta.app | CWE-522 | Monta monta.app Insufficiently Protected Credentials |
| CVE-2026-97212 | 6.9 | — | Monta | monta.app | CWE-613 | Monta monta.app Insufficient Session Expiration |
| CVE-2026-103762 | 6.9 | — | siyuan-note | siyuan | CWE-862 | SiYuan before v3.8.5 Missing Authorization in Save-Path Resolver Endpoints |
| CVE-2026-103763 | 6.9 | — | siyuan-note | siyuan | CWE-200 | SiYuan before v3.8.5 Information Disclosure via /api/notebook/getNotebookInfo |
| CVE-2026-104417 | 6.9 | — | TryGhost | Ghost | CWE-22 | Ghost 1.20.0 before 6.64.0 Path Traversal via Locale Setting |
| CVE-2026-104420 | 6.9 | — | ZcashFoundation | zebra | CWE-704 | Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks |
| CVE-2026-104421 | 6.9 | — | ZcashFoundation | zebra | CWE-459 | Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes… |
| CVE-2026-104425 | 6.9 | — | ZcashFoundation | zebra | CWE-405 | Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed T… |
| CVE-2026-104428 | 6.9 | — | ZcashFoundation | zebra | CWE-617 | Zebra before 11.0.0 Denial of Service via getblock Verbosity 2 |
| CVE-2026-104429 | 6.9 | — | ZcashFoundation | zebra | CWE-770 | Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages |
| CVE-2026-104432 | 6.9 | — | ZcashFoundation | zebra | CWE-754 | Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response |
| CVE-2026-104440 | 6.9 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 Blind SSRF via bazarlist API idtypeannonce Parameter |
| CVE-2026-104441 | 6.9 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 Unauthenticated SSRF via valeur Action |
| CVE-2026-104442 | 6.9 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 Unauthenticated SSRF via syndication Action |
| CVE-2026-104446 | 6.9 | — | YesWiki | yeswiki | CWE-306 | YesWiki before 4.6.7 Unauthenticated Open Mail Relay via Contact Mail Handler |
| CVE-2026-104454 | 6.9 | — | YesWiki | yeswiki | CWE-1333 | YesWiki before 4.6.7 ReDoS via wakka.php Edit-Preview Endpoint |
| CVE-2026-104455 | 6.9 | — | YesWiki | yeswiki | CWE-200 | YesWiki before 4.6.7 Read-ACL Bypass via recentchangesrssplus RSS Action |
| CVE-2026-104459 | 6.9 | — | YesWiki | yeswiki | CWE-918 | YesWiki before 4.6.7 SSRF via ActivityPub WebFinger actor_handle |
| CVE-2026-105030 | 6.9 | — | rajnandan1 | kener | CWE-200 | Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API |
| CVE-2026-19856 | 6.5 | — | Unknown | All in One SEO | — | All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via … |
| CVE-2026-32585 | 6.5 | — | airano | Airano MCP Bridge | CWE-862 | WordPress Airano MCP Bridge plugin <= 2.11.0 - Broken Access Control vulnerab… |
| CVE-2026-39439 | 6.5 | — | Kiera Howe | WebSamurai | CWE-862 | WordPress WebSamurai plugin <= 1.0.7 - Broken Access Control vulnerability |
| CVE-2026-82041 | 6.5 | — | UTMStack | UTMStack | CWE-862 | UTMStack < 11.2.16 Missing Authorization via Command WebSocket |
| CVE-2026-85209 | 6.5 | — | AVEZ Electronics Communication Training and Consultancy Trade Inc. | Learning Management System (LMS) | CWE-862 | IDOR in AVEZ Electronics's LMS |
| CVE-2026-102798 | 6.5 | — | ThemeREX Group | ThemeREX Addons | CWE-79 | WordPress ThemeREX Addons plugin <= 2.46.0 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-103036 | 6.5 | — | middleapi | orpc | CWE-915 | @orpc/json-schema: Prototype injection in smart coercion |
| CVE-2026-103918 | 6.5 | — | middleapi | orpc | CWE-915 | @orpc/zod: Prototype injection in smart coercion |
| CVE-2026-97876 | 6.4 | — | GNU | grub2 | CWE-822 | Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MM… |
| CVE-2026-102797 | 6.4 | — | ThemeREX Group | ThemeREX Addons | CWE-918 | WordPress ThemeREX Addons plugin <= 2.46.0 - Server Side Request Forgery (SSR… |
| CVE-2026-82044 | 6.3 | — | UTMStack | UTMStack | CWE-918 | UTMStack < 11.2.16 Server-Side Request Forgery via downloadPdf |
| CVE-2026-85483 | 6.3 | — | Apache Software Foundation | Apache Thrift | CWE-393 | Apache Thrift: c_glib TZlibTransport reports a full read after a premature st… |
| CVE-2026-86536 | 6.3 | — | Apache Software Foundation | Apache Thrift | CWE-1321 | Apache Thrift, Apache Thrift, Apache Thrift: A map key from the wire can repl… |
| CVE-2026-92834 | 6.3 | — | Apache Software Foundation | Apache Thrift | CWE-393 | Apache Thrift: C++ WebSocket server transport does not read a full request le… |
| CVE-2026-94484 | 6.3 | — | vercel | next.js | CWE-524 | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user con… |
| CVE-2026-94485 | 6.3 | — | vercel | next.js | CWE-346 | Next.js: Information disclosure in Next.js App Router metadata image routes v… |
| CVE-2026-94543 | 6.3 | — | vercel | next.js | CWE-524 | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applicat… |
| CVE-2026-94544 | 6.3 | — | vercel | next.js | CWE-524 | Next.js: Pending `use cache` fill can leak Draft Mode content into regular re… |
| CVE-2026-94638 | 6.3 | — | Apache Software Foundation | Apache Thrift | CWE-770 | Apache Thrift: PHP `thrift_protocol` C extension ignores the configured `maxS… |
| CVE-2026-94652 | 6.3 | — | Apache Software Foundation | Apache Thrift | CWE-401 | Apache Thrift: C++ `TEvhttpServer` leaks its `RequestContext` when the proces… |
| CVE-2026-101104 | 6.3 | — | Meari | IoT Cloud Platform OpenAPI Service | CWE-862 | Missing Authorization in Meari IoT Cloud Platform OpenAPI Service |
| CVE-2026-104419 | 6.3 | — | ZcashFoundation | zebra | CWE-345 | Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes |
| CVE-2026-104424 | 6.3 | — | ZcashFoundation | zebra | CWE-131 | Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate |
| CVE-2026-104436 | 6.3 | — | ZcashFoundation | zebra | CWE-770 | Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locato… |
| CVE-2026-104468 | 6.3 | — | YesWiki | yeswiki | CWE-613 | YesWiki before 4.6.7 Non-Expiring Password Reset Tokens via LostPasswordAction |
| CVE-2026-104721 | 6.3 | — | QOS.CH Sarl | Logback-classic | CWE-22 | Logback: Incomplete protection against CVE-2026-19880 |
| CVE-2026-104871 | 6.3 | — | angular | angular-cli | CWE-22 | Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows |
| CVE-2026-104906 | 6.2 | — | MISP | MISP | CWE-79 | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output |
| CVE-2026-104843 | 5.9 | — | astral-sh | uv | CWE-22 | uv: Path traversal on Windows through wheel extraction |
| CVE-2026-104844 | 5.9 | — | postcss | postcss-selector-parser | CWE-400 | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion |
| CVE-2026-104853 | 5.8 | — | nrwl | nx | CWE-22 | Nx: Path traversal in nx migrate package-migrations extraction |
| CVE-2026-104872 | 5.8 | — | open-telemetry | opentelemetry-js-contrib | CWE-532 | Multiple @opentelemetry/instrumentation-* packages expose database username v… |
| CVE-2026-105049 | 5.8 | — | Zilliz | Attu | CWE-306 | Zilliz Attu before 3.0.0 has a Playground feature that does not require authe… |
| CVE-2026-104609 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-74 | onetwothreeneth HospitalManagementSystem edit_accounts.php get sql injection |
| CVE-2026-104637 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-284 | onetwothreeneth HospitalManagementSystem controller.php edit_patient unrestri… |
| CVE-2026-104638 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-287 | onetwothreeneth HospitalManagementSystem sessions.php improper authentication |
| CVE-2026-39444 | 5.4 | — | PublishPress | PublishPress Series | CWE-639 | WordPress PublishPress Series plugin <= 3.1.3 - Insecure Direct Object Refere… |
| CVE-2026-104474 | 5.4 | — | litespeedtech | openlitespeed | CWE-367 | OpenLiteSpeed before 1.9.3 Local Privilege Escalation via lsup.sh Auto-Update |
| CVE-2026-11795 | 5.3 | — | Softtr Informatics Trading Limited Company | E-Commerce Pack | CWE-203 | User Enumeration in Softtr's E-Commerce Pack |
| CVE-2026-12392 | 5.3 | — | Canonical | MAAS | — | RPC secret disclosure via vendor data endpoint in Canonical MAAS |
| CVE-2026-32584 | 5.3 | — | Chiranjit Hazarika | Smart One Click Setup – Complete Demo Import & Export | CWE-201 | WordPress Smart One Click Setup – Complete Demo Import & Export plugin <=… |
| CVE-2026-82040 | 5.3 | — | UTMStack | UTMStack | CWE-918 | UTMStack < 11.2.16 SSRF via IdentityProviderService |
| CVE-2026-104055 | 5.3 | — | Canonical | postgresql-operator | CWE-532 | Monitoring-user password logged in cleartext by postgres_exporter in postgres… |
| CVE-2026-104412 | 5.3 | — | TryGhost | Ghost | CWE-269 | Ghost 0.5.0 before 6.64.0 Privilege Escalation via Staff Role Assignment |
| CVE-2026-104451 | 5.3 | — | YesWiki | yeswiki | CWE-352 | YesWiki before 4.6.7 CSRF Page Revision Restore via RevisionsHandler |
| CVE-2026-104452 | 5.3 | — | YesWiki | yeswiki | CWE-352 | YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler |
| CVE-2026-104453 | 5.3 | — | YesWiki | yeswiki | CWE-352 | YesWiki before 4.6.7 CSRF Tag Deletion via admintag Action |
| CVE-2026-104470 | 5.3 | — | YesWiki | yeswiki | CWE-79 | YesWiki before 4.6.7 SSRF and XSS via Bazar valeur Action |
| CVE-2026-104477 | 5.3 | — | showdownjs | showdown | CWE-79 | Showdown through 2.1.0 XSS via unescaped quote in href and src attributes |
| CVE-2026-104874 | 5.3 | — | aio-libs | multidict | CWE-401 | Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtr… |
| CVE-2026-104900 | 5.3 | — | MISP | MISP | CWE-79 | MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index |
| CVE-2026-104910 | 5.3 | — | MISP | MISP | CWE-285 | MISP Information Disclosure via Related Events Listing Bypassing Per-Event Au… |
| CVE-2026-104914 | 5.3 | — | MISP | MISP | CWE-284 | MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute … |
| CVE-2026-105029 | 5.3 | — | uvdesk | support-center-bundle | CWE-639 | UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating… |
| CVE-2026-5782 | 5.2 | — | Loglama.net | TurkHotspot | CWE-79 | Reflected XSS in Loglama.NET's TurkHotspot |
| CVE-2026-94594 | 5.1 | — | Armatura LLC | Armatura One | CWE-532 | Armatura LLC Armatura One Insertion of Sensitive Information into Log File |
| CVE-2026-104461 | 5.1 | — | YesWiki | yeswiki | CWE-79 | YesWiki before 4.6.7 Stored XSS via Unsanitized SVG Upload in Bazar FileField |
| CVE-2026-104465 | 5.1 | — | YesWiki | yeswiki | CWE-79 | YesWiki before 4.6.7 Reflected XSS via field Parameter in mail Handler |
| CVE-2026-104466 | 5.1 | — | YesWiki | yeswiki | CWE-79 | YesWiki before 4.6.7 Stored XSS via Wakka Markdown Image src Attribute |
| CVE-2026-104473 | 5.1 | — | YesWiki | yeswiki | CWE-79 | YesWiki before 4.5.3 Multiple Reflected XSS via BazaR and listpages |
| CVE-2026-104475 | 5.1 | — | idurar | idurar-erp-crm | CWE-79 | IDURAR ERP CRM through 4.1.1 Stored XSS via SVG Upload |
| CVE-2026-104479 | 5.1 | — | mindstellar | shopclass | CWE-79 | Shopclass before 6.2.0 Stored XSS via Listing Description Field |
| CVE-2026-104901 | 5.1 | — | MISP | MISP | CWE-79 | MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting vi… |
| CVE-2026-59662 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59663 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59664 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59665 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59666 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59667 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-59668 | 4.8 | — | Repasat | Repasat application | CWE-79 | Multiple vulnerabilities in the Repasat application |
| CVE-2026-104907 | 4.8 | — | MISP | MISP | CWE-79 | MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler |
| CVE-2026-39600 | 4.7 | — | Mehul Gohil | Aculect AI Companion | CWE-601 | WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Fo… |
| CVE-2026-39717 | 4.3 | — | ThimPress | LearnPress | CWE-862 | WordPress LearnPress plugin <= 4.4.9.1 - Broken Access Control vulnerability |
| CVE-2026-51899 | 4.3 | — | n/a | n/a | CWE-284 | In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api… |
| CVE-2026-105046 | 4.3 | — | Kentico | Xperience | CWE-425 | Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks … |
| CVE-2026-105048 | 4.0 | — | Zilliz | Attu | CWE-1289 | The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of r… |
| CVE-2026-39601 | 3.7 | — | WPdevelop | Booking Calendar | CWE-362 | WordPress Booking Calendar plugin <= 11.8.4 - Race Condition vulnerability |
| CVE-2026-105043 | 3.6 | — | MathWorks | Simulink | CWE-451 | MathWorks Simulink before R2026b, when showing a crafted .slx file, can have … |
| CVE-2026-104994 | 2.5 | — | aquasec | Trivy | CWE-24 | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functi… |
| CVE-2026-94486 | 2.3 | — | vercel | next.js | CWE-346 | Next.js: Information disclosure in the Next.js development server's Model Con… |
| CVE-2026-104415 | 2.3 | — | TryGhost | Ghost | CWE-203 | Ghost 0.7.2 before 6.64.0 Password Hash Ordering Disclosure via Admin API |
| CVE-2026-104606 | 2.1 | — | itsourcecode | Online Admission System Project | CWE-74 | itsourcecode Online Admission System Project confirm.php sql injection |
| CVE-2026-104612 | 2.1 | — | SourceCodester | Student Result Management System | CWE-79 | SourceCodester Student Result Management System Announcement new_announcement… |
| CVE-2026-104613 | 2.1 | — | CodeAstro | Simple Pharmacy Management System | CWE-74 | CodeAstro Simple Pharmacy Management System view.php sql injection |
| CVE-2026-104614 | 2.1 | — | CodeAstro | Simple Pharmacy Management System | CWE-74 | CodeAstro Simple Pharmacy Management System delete.php sql injection |
| CVE-2026-104625 | 2.1 | — | CodeAstro | Simple Loan Management System | CWE-74 | CodeAstro Simple Loan Management System index.php sql injection |
| CVE-2026-104855 | 2.0 | — | bytecodealliance | wasmtime | CWE-362 | Wasmtime: Preemption and traps during bulk operations enable breaking interna… |
| CVE-2026-105051 | 1.9 | — | Irdeto | Denuvo Anti-Tamper | CWE-348 | Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence … |
| CVE-2026-51898 | await | — | n/a | n/a | — | sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.e… |
| CVE-2026-51901 | await | — | n/a | n/a | — | SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent ex… |
| CVE-2026-51904 | await | — | n/a | n/a | — | SuperAGI up to v0.0.14 contains an improper access control vulnerability in t… |
| CVE-2026-51906 | await | — | n/a | n/a | — | In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image func… |
| CVE-2026-51911 | await | — | n/a | n/a | — | vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_… |
| CVE-2026-51914 | await | — | n/a | n/a | — | TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control… |
| CVE-2026-51915 | await | — | n/a | n/a | — | TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control… |
| CVE-2026-51917 | await | — | n/a | n/a | — | FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. |
| CVE-2026-51918 | await | — | n/a | n/a | — | FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). |
| CVE-2026-51922 | await | — | n/a | n/a | — | agentscope v1.0.20 contains code injection in execute_shell_command (src/agen… |
| CVE-2026-59265 | await | — | Apache Software Foundation | Apache OpenOffice | CWE-426 | Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead t… |
| CVE-2026-103621 | await | — | Chrome | CWE-190 | Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allow… | |
| CVE-2026-103623 | await | — | Chrome | CWE-416 | Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed… | |
| CVE-2026-103624 | await | — | Chrome | CWE-416 | Use after free in Contextual Tasks in Google Chrome on on Windows prior to 15… | |
| CVE-2026-103626 | await | — | Chrome | CWE-863 | Incorrect authorization in FileSystem in Google Chrome on on Windows prior to… | |
| CVE-2026-103627 | await | — | Chrome | CWE-200 | Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a rem… | |
| CVE-2026-103629 | await | — | Chrome | CWE-190 | Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a re… | |
| CVE-2026-103630 | await | — | Chrome | CWE-416 | Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a rem… | |
| CVE-2026-103631 | await | — | Chrome | CWE-122 | Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a r… | |
| CVE-2026-103877 | await | — | Apache Software Foundation | Apache Directory LDAP API | CWE-502 | Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elements |
| CVE-2026-103878 | await | — | Apache Software Foundation | Apache Directory LDAP API | CWE-345 | Apache Directory LDAP API: Injection of plaintext responses during StartTLS |
| CVE-2026-103880 | await | — | Apache Software Foundation | Apache Directory LDAP API | CWE-405 | Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor… |
| CVE-2026-103885 | await | — | Apache Software Foundation | Apache Directory LDAP API | — | Apache Directory LDAP API: Denial of service via crafted telephone number values |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-10-02 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.