boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, October 5, 2026 · all times UTC← 2026-10-04 · archive

Security Box Score — October 5, 2026

413 CVEs published, led by makeplane (38).

413 CVEs published October 5, 2026: 26 critical, 105 high, 205 medium, 46 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 31 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 13 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published138451373——
KEV catalog size1734

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3368 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux06205530264072711560.17.8.0019-188 ▼
microsoft12902201199369216290311.17.8.0047-8 ▼
google382869358111912501328090.37.5.00260
red hat349335438943555200.06.6.0035+1 ▲
apple056467166317148991.66.5.00190
suse053827162000.07.5.0036-9 ▼
canonical2521612195000.07.8.0022+2 ▲
freebsd04823673000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco0182547255160179.37.8.0046-11 ▼
ubiquiti065362810334.69.1.00500
palo alto networks0461426151324.34.7.00220
fortinet142121017330819.07.2.0040+1 ▲
netgear03400277000.04.3.00270
f502671441527.78.7.0050-7 ▼
ivanti0246162025520.88.8.01520
sonicwall019784019421.18.3.0050-5 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache101808165368249183320.27.5.0057+93 ▲
mozilla0379122169870900.08.8.0031-34 ▼
gitlab11058246211532.95.3.0035+1 ▲
drupal094119668411.15.7.0027-26 ▼
github023211100000.07.4.0054-3 ▼
docker1131840000.08.2.0017+1 ▲
wordpress0614103350.08.7.03920
eclipse022000000.09.3.00500
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle0290558116605631012840.17.8.00360
ibm0102319647333618610.17.5.0037-70 ▼
adobe08308236437592150.67.5.0036-2 ▼
progress5711542131611.48.0.0045+3 ▲
zohocorp04262970000.08.3.0117-1 ▼
solarwinds0261853010415.49.1.00670
veeam01961030100.08.6.00420
atlassian11028001300.07.8.0043+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link07422281212300.08.5.0164-3 ▼
siemens052633103000.07.3.0026-1 ▼
synology046510256000.05.6.00320
rockwell automation04353260000.08.6.0029-18 ▼
advantech02021710000.08.6.00710
schneider electric01821150000.08.5.0044-4 ▼
hitachi energy0122460000.07.0.0025-4 ▼
abb0111640000.07.2.00180
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell03783417015222210.37.2.0027-19 ▼
nvidia030125206700000.07.8.0019-30 ▼
sourcecodester1024700147100000.05.5.0041+9 ▲
openclaw022341148421000.07.1.00310
mongodb1170699605100.07.1.0038-9 ▼
spring017013608314000.06.5.00330
itsourcecode141670042125000.02.1.0033+8 ▲
hewlett packard enterprise (hpe)11672380559110.67.2.0042-85 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.929699.810.0
CVE-2026-87902.461298.88.1
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-76460.140396.510.0
CVE-2026-86218.129396.210.0
CVE-2026-85102.075594.39.8
CVE-2026-12269.069994.08.8
CVE-2026-77692.065693.67.5
CVE-2026-17176.049792.07.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9296KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8597810.0.0144
CVE-2026-7336910.0.0125
CVE-2026-7569910.0.0125
CVE-2026-7570310.0.0125
Most disclosures (vendor)
VendorCVEs
linux1927
microsoft994
google662
oracle634
ibm334
apache288
red hat265
apple247
adobe222
dell188
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco17
apple9
google9
fortinet8
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven124
NuGet24
Packagist24
npm24
PyPI14
crates.io10
Go9
RubyGems4
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-86950Apple0
CVE-2026-87491Google0
CVE-2026-88779NetScaler0
CVE-2026-93952Arista Networks0
CVE-2026-102489Zammad GmbH1
CVE-2026-102490Zammad GmbH1
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171783
CVE-2021-27102n/a2021-11-171783
CVE-2021-27101n/a2021-11-171783
CVE-2021-27103n/a2021-11-171783
CVE-2021-21017Adobe2021-11-171783
CVE-2021-28550Adobe2021-11-171783
CVE-2021-42013Apache Software Foundation2021-11-171783
CVE-2021-41773Apache Software Foundation2021-11-171783
CVE-2021-30858Apple2021-11-171783
CVE-2021-30860Apple2021-11-171783

Transactions

EXPLOIT PUBLISHED — envoyproxy envoy: 9 CVEs (CVE-2026-48521, CVE-2026-73511, CVE-2026-73512, CVE-2026-73513, CVE-2026-73546, CVE-2026-73548, CVE-2026-73550, CVE-2026-73552, CVE-2026-73553). Public exploit references added.

EXPLOIT PUBLISHED — Omega Solution CoinEx Crypto: 3 CVEs (CVE-2026-105096, CVE-2026-105097, CVE-2026-105099). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2014-125130 (Damjan CodeArt Google MP3 Audio Player). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-39999 (WordPress.org WordPress). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54402 (iDocView). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2023-54405 (H3C CVM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2024-58388 (Sharp Corporation Multiple Multifunction Printers). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56361. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56362. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56363. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-56365. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-100823 (Mozilla Firefox). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103534 (David-Crty databasement). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103539 (ZongXR SuperMarket). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103542 (formtools.org Form Tools). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-103686 (rhukster dom-sanitizer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104052 (itsourcecode Pet Shop Management System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104118 (Unknown Razorpay for WooCommerce). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104119 (Unknown Simple Shopping Cart). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104120 (modelcontextprotocol mcp-server-fetch). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-104983 (Linux Mint Xreader). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105137 (Laradock). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105147 (SciPhi-AI R2R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105148 (SciPhi-AI R2R). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105156 (YzmCMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105157 (RainyGao DocSys). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105158 (RainyGao DocSys). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-105167 (kishor-23 food-waste-management-system). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-17005 (Unknown Horizontal scrolling announcements). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-37604. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-51879. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-86817 (Unknown Five Star Business Profile and Schema). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93549 (Unknown CoCart). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97233 (volotat Anagnorisis). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-97332 (Unknown User Private Files). Public exploit reference added.

DUE DATE PASSED — CVE-2026-104286 (Fortinet FortiMail). CISA remediation deadline was October 4, 2026; still in catalog.

RESCORED — kishor-23 food-waste-management-system: 4 CVEs (CVE-2026-105168, CVE-2026-105169, CVE-2026-105170, CVE-2026-105171). CVSS rescored — before/after on each CVE page.

RESCORED — CVE-2025-56361. CVSS 7.5 → 5.7 (NVD).

RESCORED — CVE-2025-56362. CVSS 7.5 → 5.7 (NVD).

RESCORED — CVE-2025-56363. CVSS 7.5 → 5.7 (NVD).

RESCORED — CVE-2025-56364. CVSS 7.5 → 5.7 (NVD).

RESCORED — CVE-2025-56365. CVSS 7.5 → 5.7 (NVD).

RESCORED — CVE-2026-103101 (Pexip Infinity). CVSS 8.6 → 7.5 (NVD).

RESCORED — CVE-2026-103109 (Pexip Infinity). CVSS 7.7 → 9.4 (NVD).

RESCORED — CVE-2026-103489 (JetBrains YouTrack). CVSS 2 → 5.4 (NVD).

RESCORED — CVE-2026-103678 (tnef). CVSS 5.4 → 8.1 (NVD).

RESCORED — CVE-2026-103680 (tnef). CVSS 3.1 → 6.5 (NVD).

RESCORED — CVE-2026-37604. CVSS 9.8 → 6.5 (NVD).

PATCH SHIPPED — Red Hat OpenShift Container Platform 4.21: 4 CVEs (CVE-2026-49329, CVE-2026-83589, CVE-2026-87114, CVE-2026-96577). Fix versions published.

PATCH SHIPPED — CVE-2026-102628 (Eummena Cadmos LTI). Fixed in Cadmos LTI 2026-09-02.

PATCH SHIPPED — CVE-2026-49762 (elixir-lang elixir). Fixed in elixir c64417d72fd5c7d09e963ca3ac5fa2b140978d9e.

ENRICHED — CVE-2026-64043 (Linux). Received CVSS 4.7 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

413 CVEs published. 25 box scores and 375 table rows below; the remaining 13 continue on page 2 — every CVE is listed, nothing truncated.

Totolink A3002MU QoS Rule formIpQoS stack-based overflow
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0110   64.4     —
AFFECTED
  Product  Versions                Fixed
  A3002MU  1.0.0-B20230403.1455 –  —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-119, CWE-121 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/document…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   L   N  U  H  H  H    7.5   .0090   58.3     —
AFFECTED
  Product     Versions  Fixed
  Papermerge  3.5.3 –   —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 5   Published (CNA: mitre)
CWE-24 · CNA: mitre · CVSS v3.1 · 4 references · NVD status: Received
Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0078   54.5     —
AFFECTED
  Product  Versions                Fixed
  A3002MU  1.0.0-B20230403.1455 –  —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Totolink A3002MU File Upload formUploadFile sub_44B250 path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   L    2.1   .0052   42.2     —
AFFECTED
  Product  Versions                Fixed
  A3002MU  1.0.0-B20230403.1455 –  —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
Perforce P4 (Helix Core) — Arbitrary file-write via log configuration path in P4Search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   H   N   H   H   H    7.5   .0051   41.7     —
AFFECTED
  Product          Versions     Fixed
  P4 (Helix Core)  unspecified  2026.4.2
TIMELINE
  Sep 30  Reserved by CNA
  Oct 5   Published (CNA: Perforce)
CWE-73 · CNA: Perforce · CVSS v4.0 · 1 reference · NVD status: Received
qt Qt for MCUs — An empty <img> attribute value in styled text triggers a parser error that halts the device.
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    6.6   .0043   34.8     —
AFFECTED
  Product      Versions  Fixed
  Qt for MCUs  2.12.0 –  —
TIMELINE
  Aug 10  Reserved by CNA
  Oct 5   Published (CNA: Qt)
CWE-230, CWE-617 · CNA: Qt · CVSS v4.0 · 1 reference · NVD status: Received
Perfoce P4 (Helix Core) — Authentication bypass via default auth token in P4Search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0042   34.5     —
AFFECTED
  Product          Versions     Fixed
  P4 (Helix Core)  unspecified  2026.4.2
TIMELINE
  Sep 25  Reserved by CNA
  Oct 5   Published (CNA: Perforce)
CWE-1392 · CNA: Perforce · CVSS v4.0 · 1 reference · NVD status: Received
linlinjava litemall Login Endpoint AdminAuthController.java excessive authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   N   L   N   N    2.9   .0040   32.4     —
AFFECTED
  Product   Versions  Fixed
  litemall  1.0 –     —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-307, CWE-799 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
ChatGPTNextWeb NextChat Proxy Fallback proxy.ts proxyHandler server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0039   31.0     —
AFFECTED
  Product   Versions  Fixed
  NextChat  2.16.0 –  —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 7 references · NVD status: Received
MediaTek, Inc. MediaTek chipset — In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote e…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0038   29.8     —
AFFECTED
  Product           Versions  Fixed
  MediaTek chipset  MT2718 –  —
TIMELINE
  Nov 3   Reserved by CNA
  Oct 5   Published (CNA: MediaTek)
CWE-787 · CNA: MediaTek · CVSS v3.1 · 1 reference · NVD status: Received
Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   N   H   H   H    9.2   .0037   29.1     —
AFFECTED
  Product  Versions  Fixed
  Legcord  1.1.0 –   —
TIMELINE
  Oct 5   Reserved by CNA
  Oct 5   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Received
Perforce P4 (Helix Core) — Ticket host-binding bypass via spoofed client IP in P4Search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   N    5.3   .0037   29.0     —
AFFECTED
  Product          Versions     Fixed
  P4 (Helix Core)  unspecified  2026.4.2
TIMELINE
  Sep 30  Reserved by CNA
  Oct 5   Published (CNA: Perforce)
CWE-290 · CNA: Perforce · CVSS v4.0 · 1 reference · NVD status: Received
Perforce P4 (Helix Core) — RCE via exposed JDWP debug agent in P4Search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0036   27.2     —
AFFECTED
  Product          Versions     Fixed
  P4 (Helix Core)  unspecified  2026.4.2
TIMELINE
  Sep 25  Reserved by CNA
  Oct 5   Published (CNA: Perforce)
CWE-489 · CNA: Perforce · CVSS v4.0 · 1 reference · NVD status: Received
Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   H   N   H   H   H    8.4   .0035   26.6     —
AFFECTED
  Product                   Versions     Fixed
  Mitel MiVoice Office 400  11.0.96.0 –  —
TIMELINE
  Oct 2   Reserved by CNA
  Oct 5   Published (CNA: NCSC.ch)
CWE-31 · CNA: NCSC.ch · CVSS v4.0 · 1 reference · NVD status: Received
Perforce P4 (Helix Core) — Authentication bypass via blank auth token in P4Search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.5   .0035   26.1     —
AFFECTED
  Product          Versions     Fixed
  P4 (Helix Core)  unspecified  2026.4.2
TIMELINE
  Sep 30  Reserved by CNA
  Oct 5   Published (CNA: Perforce)
CWE-636 · CNA: Perforce · CVSS v4.0 · 1 reference · NVD status: Received
n/a Gerapy — Gerapy Project Management views.py project_create path traversal
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   L    2.1   .0033   24.0     —
AFFECTED
  Product  Versions  Fixed
  Gerapy   0.9.0 –   —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-22 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Received
Perforce P4 (Helix Core) — Arbitrary file-write via extension installation in P4Search
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   N   L   L    5.1   .0033   23.6     —
AFFECTED
  Product          Versions     Fixed
  P4 (Helix Core)  unspecified  2026.4.2
TIMELINE
  Sep 30  Reserved by CNA
  Oct 5   Published (CNA: Perforce)
CWE-73 · CNA: Perforce · CVSS v4.0 · 1 reference · NVD status: Received
n/a vgmstream — vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   N   N   L    5.3   .0032   22.7     —
AFFECTED
  Product    Versions  Fixed
  vgmstream  r2117 –   —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-369, CWE-404 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
feelec-yishu feelcrm-os getMemberByGroups Endpoint AjaxRequestController.class.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0032   22.6     —
AFFECTED
  Product     Versions  Fixed
  feelcrm-os  1.0.0 –   —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Received
SourceCodester Drug Recommendation System edit_class.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0032   22.5     —
AFFECTED
  Product                     Versions  Fixed
  Drug Recommendation System  1.0 –     —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
SourceCodester Drug Recommendation System Drug Creation add_drug.php sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0032   22.5     —
AFFECTED
  Product                     Versions  Fixed
  Drug Recommendation System  1.0 –     —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
SourceCodester Drug Recommendation System Symptom Creation add_symptom.php mysqli_real_escape_string sql injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   L   L   L    2.0   .0032   22.5     —
AFFECTED
  Product                     Versions  Fixed
  Drug Recommendation System  1.0 –     —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-74, CWE-89 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   N   N    5.5   .0031   22.0     —
AFFECTED
  Product                   Versions     Fixed
  Mitel MiVoice Office 400  11.0.96.0 –  —
TIMELINE
  Oct 2   Reserved by CNA
  Oct 5   Published (CNA: NCSC.ch)
CWE-31 · CNA: NCSC.ch · CVSS v4.0 · 1 reference · NVD status: Received
n/a Jeebase — Jeebase UserService info updateUser dynamically-determined object attributes
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0030   20.9     —
AFFECTED
  Product  Versions  Fixed
  Jeebase  0.0.1 –   —
TIMELINE
  Oct 4   Reserved by CNA
  Oct 5   Published (CNA: VulDB)
CWE-913, CWE-915 · CNA: VulDB · CVSS v4.0 · 5 references · NVD status: Received
Unknown File Uploads Addon for WooCommerce — File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  N  N    5.9   .0029   19.5     —
AFFECTED
  Product                             Versions  Fixed
  File Uploads Addon for WooCommerce  1.7.2 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Oct 5   Published (CNA: WPScan)
CWE-284 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1044087.618.5GroundhoggGroundhoggCWE-89WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability
CVE-2026-1033355.318.4Deepen BajracharyaVideo Conferencing with ZoomCWE-201WordPress Video Conferencing with Zoom plugin <= 4.6.10 - Sensitive Data Expo…
CVE-2026-1052465.517.3SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System btn_functions.php update sql…
CVE-2026-1051725.516.5itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System login1.php sql injection
CVE-2026-1051825.516.5SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System btn_functions.php update sql…
CVE-2026-1051835.516.5itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System confirm.php sql injection
CVE-2026-1051845.516.5itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System creteria.php sql injection
CVE-2026-1051855.516.5itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System examinee.php sql injection
CVE-2026-1052295.516.5kishor-23food-waste-management-systemCWE-74kishor-23 food-waste-management-system User Registration Endpoint signup.php …
CVE-2026-1052305.516.5kishor-23food-waste-management-systemCWE-74kishor-23 food-waste-management-system deliverymyord.php sql injection
CVE-2026-1052315.516.5kishor-23food-waste-management-systemCWE-74kishor-23 food-waste-management-system Admin Registration signup.php sql inje…
CVE-2026-1052325.516.5kishor-23food-waste-management-systemCWE-74kishor-23 food-waste-management-system Registration deliverysignup.php sql in…
CVE-2026-1052475.516.5SourceCodesterOnline Reviewer Management SystemCWE-74SourceCodester Online Reviewer Management System btn_functions.php course sql…
CVE-2026-1052535.516.5itsourcecodeOnline Admission System ProjectCWE-74itsourcecode Online Admission System Project login1.php sql injection
CVE-2026-1043898.516.1SirvSirvCWE-89WordPress Sirv plugin <= 8.2.5 - SQL Injection vulnerability
CVE-2026-1051755.515.4SourceCodesterDrug Recommendation SystemCWE-74SourceCodester Drug Recommendation System Student Registration add_student.ph…
CVE-2026-1052262.014.6osCommerceosCommerce2CWE-74osCommerce osCommerce2 Newsletter Management newsletters.php include code inj…
CVE-2026-1052515.314.6n/avgmstreamCWE-119vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds
CVE-2026-1048071.914.5MitelMitel MiVoice Office 400CWE-79Mitel MiVoice Office 400 stored Cross-Site Scripting
CVE-2026-1048081.914.5MitelMitel MiVoice Office 400CWE-79Mitel MiVoice Office 400 stored Cross-Site Scripting
CVE-2026-1052485.314.0n/avgmstreamCWE-119vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write
CVE-2026-1050646.513.3Unlimited ElementsUnlimited Elements For Elementor (Free Widgets, Addons, Templates)CWE-470WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) …
CVE-2026-1007276.912.9GROWI, Inc.GROWICWE-552An improper access control vulnerability exists in GROWI, which allow an unau…
CVE-2026-1052635.112.8n/aShaarliCWE-918Shaarli Admin Metadata Endpoint MetadataController.php MetadataController ser…
CVE-2026-205197.512.4MediaTek, Inc.MediaTek chipsetCWE-787In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-205207.512.4MediaTek, Inc.MediaTek chipsetCWE-787In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-205267.512.4MediaTek, Inc.MediaTek chipsetCWE-787In Modem, there is a possible out of bounds write due to a missing bounds che…
CVE-2026-1043885.312.3Blubrry PodcastingPowerPress PodcastingCWE-862WordPress PowerPress Podcasting plugin <= 11.17.9 - Sensitive Data Exposure v…
CVE-2026-1043975.312.3Jeroen PetersName DirectoryCWE-862WordPress Name Directory plugin <= 1.34.2 - Arbitrary Shortcode Execution vul…
CVE-2026-1052332.112.2kishor-23food-waste-management-systemCWE-384kishor-23 food-waste-management-system Login Flow login.php session fixiation
CVE-2026-1033515.312.1Magepeople inc.Taxi Booking Manager for WooCommerceCWE-1284WordPress Taxi Booking Manager for WooCommerce plugin <= 2.1.1 - Other vulner…
CVE-2026-1053066.511.5Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: token introspection audience bypass via…
CVE-2019-25777await11.1—YAMLCWE-502YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to r…
CVE-2026-1048058.510.9MitelMitel MiVoice Office 400CWE-22Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to R…
CVE-2026-1044014.310.7MemberfulMemberful - Membership PluginCWE-497WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exp…
CVE-2026-1030784.310.6AhmadJS Help DeskCWE-639WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (I…
CVE-2026-205255.39.3MediaTek, Inc.MediaTek chipsetCWE-617In Modem, there is a possible system crash due to improper input validation. …
CVE-2026-205275.39.3MediaTek, Inc.MediaTek chipsetCWE-129In Modem, there is a possible system crash due to a missing bounds check. Thi…
CVE-2026-1052452.99.4sgl-projectsglangCWE-310sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmi…
CVE-2026-783715.99.2UnknownFile Uploads Addon for WooCommerceCWE-639File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer U…
CVE-2026-1053025.79.1Red HatRed Hat Build of KeycloakCWE-200Keycloak-services: keycloak-services: user session note mapper exposes upstre…
CVE-2026-1051812.19.0itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System register1.php sql injection
CVE-2026-1051862.19.0itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System new.php sql injection
CVE-2026-1051872.19.0itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System key.php sql injection
CVE-2026-1052542.19.0itsourcecodeOnline Admission SystemCWE-74itsourcecode Online Admission System schoolyear.php sql injection
CVE-2026-1052239.18.8maclofkubernetes-clientCWE-295maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verifi…
CVE-2026-1051732.08.8code-projectsHuman Resource ManagementCWE-79code-projects Human Resource Management Event Creation EventStore.php cross s…
CVE-2026-1051882.08.8code-projectsHuman Resource Management SystemCWE-79code-projects Human Resource Management System Live Event History liveEventHi…
CVE-2026-1050685.38.6PixeliteEvents ManagerCWE-201WordPress Events Manager plugin <= 7.4.5 - Sensitive Data Exposure vulnerability
CVE-2026-1048118.48.3MitelMitel MiVoice Office 400CWE-20Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution
CVE-2026-1052949.17.7LegcordLegcordCWE-15Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig
CVE-2026-1050555.37.5WP MailsterWP MailsterCWE-862WordPress WP Mailster plugin <= 1.9.0.0 - Broken Access Control vulnerability
CVE-2026-970715.37.4VillaThemeCURCYCWE-682WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability
CVE-2026-1052251.97.5osCommerceosCommerce2CWE-74osCommerce osCommerce2 Payment payment.php include code injection
CVE-2017-20285await7.2—YAMLCWE-470YAML versions before 1.30 for Perl allow a loaded document to trigger the DES…
CVE-2026-1030795.47.0AhmadJS Help DeskCWE-639WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (I…
CVE-2026-205345.37.0MediaTek, Inc.MediaTek chipsetCWE-125In Modem, there is a possible out of bounds read due to an incorrect bounds c…
CVE-2026-205385.37.0MediaTek, Inc.MediaTek chipsetCWE-126In Modem, there is a possible out of bounds read due to a missing permission …
CVE-2026-205395.37.0MediaTek, Inc.MediaTek chipsetCWE-126In Modem, there is a possible out of bounds read due to a missing bounds chec…
CVE-2026-205405.37.0MediaTek, Inc.MediaTek chipsetCWE-126In Modem, there is a possible out of bounds read due to a missing bounds chec…
CVE-2026-205415.37.0MediaTek, Inc.MediaTek chipsetCWE-126In Modem, there is a possible out of bounds read due to a missing permission …
CVE-2026-841695.37.0UnknownUPI QR Code Payment GatewayCWE-639UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-St…
CVE-2026-19954await6.8—Net-Whois-RawCWE-176Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line t…
CVE-2026-397215.45.7Brainstorm ForceStarter TemplatesCWE-862WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerabi…
CVE-2026-205446.85.3MediaTek, Inc.MediaTek chipsetCWE-787In meta, there is a possible out of bounds write due to a missing bounds chec…
CVE-2026-1046754.35.2Liquid Web / StellarWPEvent TicketsCWE-862WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability
CVE-2026-1050624.34.7BrandtossWP Admin AuditCWE-862WordPress WP Admin Audit plugin <= 1.2.17 - Broken Access Control vulnerability
CVE-2026-1023936.54.6Brainstorm ForceStarter TemplatesCWE-79WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vuln…
CVE-2026-1029146.54.6Brainstorm ForcePresto PlayerCWE-79WordPress Presto Player plugin <= 4.5.2 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-1030846.54.6LeapWorxPremium Addons for ElementorCWE-79WordPress Premium Addons for Elementor plugin <= 4.11.109 - Cross Site Script…
CVE-2026-1043966.54.6Jeroen PetersName DirectoryCWE-79WordPress Name Directory plugin <= 1.34.2 - Cross Site Scripting (XSS) vulner…
CVE-2026-1044006.54.6bPluginsB BlocksCWE-79WordPress B Blocks plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1044046.54.6Liquid Web / StellarWPGiveWPCWE-79WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability
CVE-2026-1044096.54.6WP ChillImage Photo Gallery Final Tiles GridCWE-79WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.13 - Cross Site …
CVE-2026-1046736.54.6SonaarMP3 Audio Player for Music, Radio & Podcast by SonaarCWE-79WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1…
CVE-2026-1052926.04.4chatermChatermCWE-352Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback
CVE-2026-1051792.03.9SourceCodesterDrug Recommendation SystemCWE-310SourceCodester Drug Recommendation System Password add_user.php missing encry…
CVE-2026-1043866.53.3WPFunnels TeamWP VRCWE-862WordPress WP VR plugin <= 9.1.3 - Broken Access Control vulnerability
CVE-2026-1047068.42.5MitelMitel MiVoice Office 400CWE-31Mitel MiVoice Office 400 view system files path traversal
CVE-2026-205218.42.4MediaTek, Inc.MediaTek chipsetCWE-121In Video HAL, there is a possible escalation of privilege due to a missing bo…
CVE-2026-205228.42.4MediaTek, Inc.MediaTek chipsetCWE-787In neuropilot, there is a possible out of bounds write due to a missing bound…
CVE-2026-205238.42.4MediaTek, Inc.MediaTek chipsetCWE-787In neuropilot, there is a possible out of bounds write due to a missing bound…
CVE-2026-205248.42.4MediaTek, Inc.MediaTek chipsetCWE-1285In apu, there is a possible memory corruption due to improper input validatio…
CVE-2026-1050566.52.3impleCodeeCommerce Product CatalogCWE-79WordPress eCommerce Product Catalog plugin <= 3.6.2 - Cross Site Scripting (X…
CVE-2026-1050606.52.3ThemepointsLogo ShowcaseCWE-79WordPress Logo Showcase plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-1050696.52.3Nikki BlightQR RedirectorCWE-79WordPress QR Redirector plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerab…
CVE-2026-1052957.72.0gitaheadGitAheadCWE-494GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass
CVE-2026-205318.41.8MediaTek, Inc.MediaTek chipsetCWE-416In apu, there is a possible memory corruption due to use after free. This cou…
CVE-2026-205435.51.8MediaTek, Inc.MediaTek chipsetCWE-215In Modem, there is a possible information disclosure due to a logic error. Th…
CVE-2026-1053014.01.6Red HatRed Hat Build of KeycloakCWE-918Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetc…
CVE-2026-205286.71.6MediaTek, Inc.MediaTek chipsetCWE-787In ccci, there is a possible out of bounds write and read due to a missing bo…
CVE-2026-191857.81.3zephyrprojectzephyrCWE-822Unvalidated user-supplied buffer pointers in the I3C do_ccc system call handl…
CVE-2026-205326.21.4MediaTek, Inc.MediaTek chipsetCWE-415In apu, there is a possible application crash due to double free. This could …
CVE-2026-205296.71.1MediaTek, Inc.MediaTek chipsetCWE-787In battery, there is a possible out of bounds write due to a missing bounds c…
CVE-2026-205306.71.1MediaTek, Inc.MediaTek chipsetCWE-787In display, there is a possible out of bounds write due to a missing bounds c…
CVE-2026-205336.71.1MediaTek, Inc.MediaTek chipsetCWE-190In display, there is a possible escalation of privilege due to an integer ove…
CVE-2026-205366.71.1MediaTek, Inc.MediaTek chipsetCWE-416In aidl, there is a possible memory corruption due to use after free. This co…
CVE-2026-205376.71.1MediaTek, Inc.MediaTek chipsetCWE-416In aidl, there is a possible memory corruption due to use after free. This co…
CVE-2026-205426.71.1MediaTek, Inc.MediaTek chipsetCWE-416In apusys, there is a possible memory corruption due to use after free. This …
CVE-2026-205796.71.1MediaTek, Inc.MediaTek chipsetCWE-787In vdec, there is a possible out of bounds write due to type confusion. This …
CVE-2026-205876.71.1MediaTek, Inc.MediaTek chipsetCWE-843In mtee, there is a possible escalation of privilege due to type confusion. T…
CVE-2026-205886.71.1MediaTek, Inc.MediaTek chipsetCWE-787In mtee, there is a possible escalation of privilege due to a missing bounds …
CVE-2026-205896.71.1MediaTek, Inc.MediaTek chipsetCWE-787In venc, there is a possible out of bounds write due to type confusion. This …
CVE-2026-1052492.41.0n/avgmstreamCWE-119vgmstream TXTP File txtp_process.c make_group_random use after free
CVE-2026-191848.40.9zephyrprojectzephyrCWE-787Out-of-bounds write in the NXP GAU ADC driver due to byte-versus-sample buffe…
CVE-2026-205356.70.9MediaTek, Inc.MediaTek chipsetCWE-862In aidl, there is a possible escalation of privilege due to a missing permiss…
CVE-2026-1044077.10.7Blubrry PodcastingPowerPress PodcastingCWE-352WordPress PowerPress Podcasting plugin <= 11.17.9 - Cross Site Request Forger…
CVE-2026-1048098.40.3MitelMitel MiVoice Office 400CWE-73Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Ex…
CVE-2026-1056369.9—makeplaneplaneCWE-918Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)
CVE-2026-1056919.9—penpotpenpotCWE-78Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy …
CVE-2026-1056979.9—langflow-ailangflowCWE-78Langflow: OS command injection (RCE) via arbitrary command in MCP stdio serve…
CVE-2026-1057409.9—langflow-ailangflowCWE-78Langflow: Authenticated RCE via MCP Stdio transport allows any user to execut…
CVE-2026-883959.8—n/an/aCWE-89GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rub…
CVE-2026-972839.8—Liquid Web / StellarWPAdvanced Post ManagerCWE-502WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulner…
CVE-2026-1056399.8—makeplaneplaneCWE-200Plane: Pre-auth workspace invitation hijack via email-squat and self-served i…
CVE-2026-1056419.8—makeplaneplaneCWE-798Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli com…
CVE-2026-1056379.6—makeplaneplaneCWE-639Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling …
CVE-2026-1057639.6—twentyhqtwentyCWE-522Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace membe…
CVE-2026-215899.3—AtlassianBamboo Data Center—h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data…
CVE-2026-911079.3—OS4EDopenSIS-ClassicCWE-639openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
CVE-2026-1024289.3—ordasoft.comOrdaSoft Joomla CCKCWE-89Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft J…
CVE-2026-1033529.3—WP BASEWP BASE BookingCWE-89WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability
CVE-2026-772269.2—CamundaCamunda 7CWE-863Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint
CVE-2026-1056389.1—makeplaneplaneCWE-307Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP b…
CVE-2026-1056409.1—makeplaneplaneCWE-287Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed…
CVE-2026-798209.0—Hewlett Packard Enterprise (HPE)HPE Integrated Lights-Out (iLO) 7CWE-287A remote user validation failure vulnerability exists in HPE Integrated Light…
CVE-2026-455248.8—GoogleAndroidCWE-862In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape d…
CVE-2026-552808.8—GoogleAndroidCWE-457In multiple locations, there is a possible out-of-bounds write due to uniniti…
CVE-2026-588358.8—GoogleAndroidCWE-122In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due t…
CVE-2026-929318.8—Progress Software@progress/sitefinity-nextjs-sdkCWE-918CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Rende…
CVE-2026-972578.8—PressTigersSimple Event PlannerCWE-502WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnera…
CVE-2026-1005118.8—Vektor Inc.VK Google Job Posting ManagerCWE-502WordPress VK Google Job Posting Manager plugin <= 1.3.1 - PHP Object Injectio…
CVE-2026-1019198.8—Red HatMulticluster Engine for KubernetesCWE-20Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namesp…
CVE-2026-1056428.8—TryGhostGhostCWE-94Ghost: Remote Code Execution via Bookmark Card Images
CVE-2026-1027758.7—phoca.czPhoca Cart extension for JoomlaCWE-639Joomla Extension - phoca.cz - Authorisation bypass through user-controlled ke…
CVE-2026-1048928.7—makeplaneplaneCWE-256Plane: Plaintext logging of API token
CVE-2026-1049668.7—makeplaneplaneCWE-639Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Mo…
CVE-2026-1049688.7—makeplaneplaneCWE-862Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-s…
CVE-2026-1049768.7—makeplaneplaneCWE-918Plane: SSRF in Gitea OAuth
CVE-2026-1049798.7—makeplaneplaneCWE-79Plane: Cross-tenant stored XSS in intake enables account takeover
CVE-2026-1056308.7—makeplaneplaneCWE-79Plane: Stored XSS via SVG attachment served inline on the application origin …
CVE-2026-1056328.7—makeplaneplaneCWE-284Plane: Broken Access Control - joinProject GraphQL mutation allows self-join …
CVE-2026-632778.5—The Document FoundationLibreOfficeCWE-829RCE via calcext:data-mappings, sql provider and jdbc connector
CVE-2026-1030668.5—WP BASEWP BASE BookingCWE-89WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability
CVE-2026-1049718.5—makeplaneplaneCWE-639Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint an…
CVE-2026-1057868.5—laurent22joplinCWE-306Joplin: Unauthenticated account takeover via an attacker-chosen application-a…
CVE-2026-121718.4—cookpeteauto-changelogCWE-22auto-changelog: code execution via untrusted in-repository configuration (han…
CVE-2026-866718.4—Eclipse FoundationEclipse CheCWE-73In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POS…
CVE-2026-1057628.3—langgeniusdifyCWE-918Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-file…
CVE-2026-942018.2—ash-projectashCWE-770Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom t…
CVE-2026-1048528.2—ardatangraphql-toolsCWE-1321GraphQL Tools has prototype pollution in well-established utility function `m…
CVE-2026-1049788.2—makeplaneplaneCWE-863Plane: Invitation Hijack in Project Join Flow via Missing Authorization and E…
CVE-2026-1049708.1—makeplaneplaneCWE-362Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthen…
CVE-2026-1049748.1—makeplaneplaneCWE-284Plane: Disabled User Auto-Reactivation on Login
CVE-2026-1056348.1—makeplaneplaneCWE-269Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles
CVE-2026-1056508.1—TryGhostGhostCWE-79Ghost: Stored XSS via oEmbed Photo Responses
CVE-2026-1057838.0—laurent22joplinCWE-346Joplin Web Clipper pairing allows cross-origin theft of a permanent API token
CVE-2026-778057.9—Progress SoftwareProgress® Telerik® Fiddler® ClassicCWE-347Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fi…
CVE-2026-498857.8—GoogleAndroidCWE-190In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write d…
CVE-2026-499337.8—GoogleAndroidCWE-824In handle_le_monitor_device_event of msft.cc, there is a possible control-flo…
CVE-2026-499377.8—GoogleAndroidCWE-119In multiple functions of MessageQueueBase.h, there is a possible out of bound…
CVE-2026-552667.8—GoogleAndroidCWE-400In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write…
CVE-2026-552697.8—GoogleAndroidCWE-20In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety…
CVE-2026-552707.8—GoogleAndroidCWE-441In dialInternal in multiple locations, there is a possible permission bypass …
CVE-2026-552867.8—GoogleAndroidCWE-119In stpropnci_process of stpropnci.cc, there is a possible out of bounds write…
CVE-2026-588157.8—GoogleAndroidCWE-119In multiple locations, there is a possible out of bounds write due to an inco…
CVE-2026-588417.8—GoogleAndroidCWE-269In multiple functions of VirtualAudioControllerTest.java, there is a possible…
CVE-2026-588547.8—GoogleAndroidCWE-843In multiple locations, there is a possible memory corruption due to type conf…
CVE-2026-588597.8—GoogleAndroidCWE-248In multiple places, there is a possible denial of service due to an uncaught …
CVE-2026-1049777.7—makeplaneplaneCWE-918Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is…
CVE-2026-1057647.7—immich-appimmichCWE-94Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE
CVE-2026-973037.6—Apps MavScratch & Win – Giveaways and ContestsCWE-862WordPress Scratch & Win – Giveaways and Contests plugin <= 3.0.2 - Broken Acc…
CVE-2026-1049737.6—makeplaneplaneCWE-918Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery
CVE-2026-1056287.6—makeplaneplaneCWE-918Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Sta…
CVE-2026-04617.5—AMDZynq™ UltraScale+ MPSoCsCWE-787Insufficient boundary validation in the USB boot mode implementation of AMD Z…
CVE-2026-588657.5—GoogleAndroidCWE-119In multiple functions of PduParser.java, there is a possible persistent denia…
CVE-2026-933187.5—mobyBuildKitCWE-354Cache poisoning via unvalidated image layer DiffIDs
CVE-2026-1033347.5—Etoile Web Design IncorporatedFive Star Restaurant ReservationsCWE-201WordPress Five Star Restaurant Reservations plugin <= 2.7.24 - Sensitive Data…
CVE-2026-1048917.5—douglasborthwick-cryptomppx-condition-gateCWE-290mppx-condition-gate: Free-access path grants on a self-declared wallet withou…
CVE-2026-1056317.5—makeplaneplaneCWE-639Plane: asset download endpoints scope file lookups to the workspace (not the …
CVE-2026-1056757.5—TryGhostGhostCWE-203Ghost: Invite Token Disclosure in Ghost Admin API
CVE-2026-1057447.5—docling-projectdoclingCWE-22Docling: Arbitrary file read/write (and command execution when shell-escape i…
CVE-2026-1057827.5—scrapyscrapyCWE-470Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
CVE-2026-1056357.4—makeplaneplaneCWE-200Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthoriz…
CVE-2026-1056437.3—TryGhostGhostCWE-79Ghost: Stored XSS via Embed Card Previews
CVE-2026-1056497.3—TryGhostGhostCWE-79Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
CVE-2026-1056517.3—TryGhostGhostCWE-79Ghost: Stored XSS via Bookmark Card Images
CVE-2026-1056797.3—TryGhostGhostCWE-79Ghost: Stored XSS via File Uploads on Local Storage
CVE-2026-1057737.3—Canimaan SoftwareClamXAVCWE-362Canimaan Software ClamXAV local privilege escalation
CVE-2026-498787.2—GoogleAndroidCWE-787In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible …
CVE-2026-936177.2—WP SunshineSunshine Photo CartCWE-502WordPress Sunshine Photo Cart plugin <= 3.7.1 - PHP Object Injection vulnerab…
CVE-2026-1005067.2—WP Spell CheckWP Spell CheckCWE-502WordPress WP Spell Check plugin <= 12.1 - PHP Object Injection vulnerability
CVE-2026-1033487.2—Smackcoders Inc.WP Ultimate ExporterCWE-502WordPress WP Ultimate Exporter plugin <= 3.0 - PHP Object Injection vulnerabi…
CVE-2026-1033497.2—Rymera Web CoProduct Feed PRO for WooCommerceCWE-502WordPress Product Feed PRO for WooCommerce plugin <= 13.5.7 - PHP Object Inje…
CVE-2026-1048907.2—KunstmaanKunstmaanBundlesCMSCWE-434Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated ad…
CVE-2026-1056777.2—TryGhostGhostCWE-22Ghost: Remote Code Execution via Theme Translation Files
CVE-2025-156437.1—Jose FernandezAdsmonetizerCWE-79WordPress Adsmonetizer plugin <= 3.2.4 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-933167.1—mobyBuildKitCWE-476Starting daemon with --cdi-disabled flag can lead to panic on specific builds
CVE-2026-973097.1—Webful CreationsRepairBuddyCWE-862WordPress RepairBuddy plugin <= 4.1226 - Sensitive Data Exposure vulnerability
CVE-2026-1005157.1—VillaThemePhoto Reviews for WooCommerceCWE-79WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Cross Site Scripti…
CVE-2026-1022827.1—cthackersadm-zipCWE-732adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local priv…
CVE-2026-1049757.1—makeplaneplaneCWE-639Plane: Cross-tenant asset authorization bypass in Plane Spaces public-board e…
CVE-2026-1056297.1—makeplaneplaneCWE-639Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Pr…
CVE-2026-1056337.1—makeplaneplaneCWE-639Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope
CVE-2026-1056997.1—langflow-ailangflowCWE-639Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resour…
CVE-2026-1057417.1—langflow-ailangflowCWE-290Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configurat…
CVE-2026-1057617.1—langgeniusdifyCWE-639Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MC…
CVE-2026-588807.0—GoogleAndroidCWE-362In handle_app_val_response of btif_rc.cc, there is a possible way to achieve …
CVE-2026-1022627.0—Newell BrandsDYMO IDCWE-22Newell Brands DYMO ID parent directory open to path traversal through imprope…
CVE-2026-597826.9—ZabbixZabbixCWE-125JavaScript preprocessing memory disclosure
CVE-2026-597866.9—ZabbixZabbixCWE-940Active agent heartbeat missing TLS check
CVE-2026-933216.9—mobyBuildKitCWE-129Malformed LLB file operation can crash buildkitd
CVE-2026-933226.9—mobyBuildKitCWE-129Malformed MergeOp can crash the BuildKit daemon
CVE-2026-970706.9—CozyThemesCozy BlocksCWE-639WordPress Cozy Blocks plugin <= 2.2.23 - Insecure Direct Object References (I…
CVE-2026-973056.9—ThemeisleAI Chatbot for WordPress – Hyve LiteCWE-639WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Dir…
CVE-2026-1027796.9—joomlafry.comTF Content for JoomlaCWE-862Joomla Extension - joomlafry.com - Unauthenticated forced execution of publis…
CVE-2026-1027806.9—joomlafry.comTF Content for JoomlaCWE-862Joomla Extension - joomlafry.com - Unauthenticated cross-record publication a…
CVE-2026-1034336.9—DockerDocker BuildxCWE-862Bake filesystem entitlement consent is skipped for certain secret and oci-lay…
CVE-2026-1054716.9—girishsarafOnline-Appointment-Booking-SystemCWE-89girishsaraf Online-Appointment-Booking-System Registration signup.php sql inj…
CVE-2026-1057516.9—docling-projectdoclingCWE-22Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocum…
CVE-2026-632666.8—The Document FoundationLibreOfficeCWE-22Arbitrary file write via calcext:data-mappings, sql provider and Firebird bac…
CVE-2026-849006.8—HP IncThinPro 8.1CWE-354HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates
CVE-2026-933236.8—mobyBuildKitCWE-789Oversized Dockerfile or .dockerignore can exhaust buildkitd memory
CVE-2026-1049646.8—makeplaneplaneCWE-639Plane: Cross-Workspace Project Modification via Unscoped Project Lookup
CVE-2026-1056446.8—TryGhostGhostCWE-79Ghost: Stored XSS via SVG Files in Content Imports
CVE-2026-632676.7—The Document FoundationLibreOfficeCWE-200LFI and GET SSRF via calcext:data-mappings and csv provider
CVE-2026-632686.7—The Document FoundationLibreOfficeCWE-200LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href
CVE-2026-632696.7—The Document FoundationLibreOfficeCWE-200LFI and GET SSRF via GStreamer and HLS playlists
CVE-2026-632706.7—The Document FoundationLibreOfficeCWE-200Environment/ini-file leaks
CVE-2026-1056886.7—penpotpenpotCWE-269Penpot: Team admin can escalate to owner via team invitation (missing owner-r…
CVE-2026-1057456.7—docling-projectdoclingCWE-696Docling: Plugin entry points are imported before the allow_external_plugins c…
CVE-2026-778046.6—Progress SoftwareProgress® Telerik® Fiddler® ClassicCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Install…
CVE-2026-427006.5—GhozyLabImage Slider WidgetCWE-79WordPress Image Slider Widget plugin <= 1.1.130 - Cross Site Scripting (XSS) …
CVE-2026-552656.5—GoogleAndroidCWE-119In multiple functions of PduParser.java, there is a possible out of bounds re…
CVE-2026-712996.5—Red HatMulticluster Engine for KubernetesCWE-306Maestro: maestro: rest api write endpoints registered without authentication …
CVE-2026-784116.5—Rapid7VelociraptorCWE-863Velociraptor Server Metadata update with Insufficient Permission Check
CVE-2026-890396.5—Grafanamcp-k6CWE-22Arbitrary file read via the convert_playwright_script prompt in mcp-k6
CVE-2026-973046.5—ArrayticsTimeticsCWE-862WordPress Timetics plugin <= 1.0.63 - Broken Access Control vulnerability
CVE-2026-1005096.5—Webful CreationsRepairBuddyCWE-79WordPress RepairBuddy plugin <= 4.1225 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-1023836.5—VillaThemeLookzyCWE-862WordPress Lookzy plugin <= 1.1.14 - Broken Access Control vulnerability
CVE-2026-1030856.5—WP User ManagerWP User ManagerCWE-284WordPress WP User Manager plugin <= 2.9.20 - Privilege Escalation vulnerability
CVE-2026-1030866.5—StiofanUsersWPCWE-862WordPress UsersWP plugin <= 1.2.74 - Broken Access Control vulnerability
CVE-2026-1033376.5—KirillbdevWC Ukraine ShippingCWE-862WordPress WC Ukraine Shipping plugin <= 1.23.2 - Broken Access Control vulner…
CVE-2026-1049606.5—makeplaneplaneCWE-639Plane: Authorization bypass in workspace-scoped asset download endpoint expos…
CVE-2026-1049626.5—makeplaneplaneCWE-862Plane: Cross-project member roster IDOR in ProjectMemberListCreateAPIEndpoint…
CVE-2026-1049696.5—makeplaneplaneCWE-639Plane: Cross-Tenant Cycle Issue Hijack via IDOR
CVE-2026-1056806.5—TryGhostGhostCWE-862Ghost: Authorization Issue Allowed Author Role to Delete any Post
CVE-2026-1056816.5—TryGhostGhostCWE-943Ghost: Authorization Bypass in Comments Feature
CVE-2026-1056966.5—penpotpenpotCWE-862Penpot: Share-link page-scope escalation: a share-link holder reads pages out…
CVE-2026-1057496.5—docling-projectdoclingCWE-400Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backe…
CVE-2026-1057536.5—vllm-projectvllmCWE-617vLLM: Mirrored multimodal IPC caches desync after a rejected request — a late…
CVE-2026-1057546.5—vllm-projectvllmCWE-20vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied fea…
CVE-2026-1057566.5—vllm-projectvllmCWE-20vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on …
CVE-2026-1057576.5—vllm-projectvllmCWE-20vLLM: Structured-output request errors escape the request boundary and termin…
CVE-2026-712986.4—Red HatMulticluster Engine for KubernetesCWE-89Maestro: sql identifier injection via properties.* search filter and orderby …
CVE-2026-778026.3—Progress SoftwareProgress® Telerik® Fiddler® ClassicCWE-444HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic
CVE-2026-1027776.3—svenbluege.deEvent Gallery for JoomlaCWE-918Joomla Extension - svenbluege.de - Server-side request forgery in the Google …
CVE-2026-1057686.3—chainguard-devapkoCWE-197apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied en…
CVE-2026-1049056.1—NeoRazorXfacturascriptsCWE-502FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect
CVE-2026-933206.0—mobyBuildKitCWE-441BuildKit improperly handles special files in build snapshots
CVE-2026-933266.0—mobyBuildKitCWE-180Crafted Git build source can bypass certain policy validation
CVE-2026-1056896.0—penpotpenpotCWE-918Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) i…
CVE-2026-933175.9—mobyBuildKitCWE-354Container blob cache can accept unverified content
CVE-2026-1056905.9—penpotpenpotCWE-613Penpot: Server-side session not invalidated on logout; stale auth-token cooki…
CVE-2026-1056955.9—penpotpenpotCWE-862Penpot: Missing authorization in chunked-upload assembly lets another authent…
CVE-2026-1057505.9—docling-projectdoclingCWE-552Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
CVE-2026-1057595.9—vllm-projectvllmCWE-400vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP me…
CVE-2026-933155.8—mobyBuildKitCWE-367BuildKit proxy CA cleanup can be disrupted by build steps
CVE-2026-597885.7—ZabbixZabbixCWE-79Stored XSS vulnerability in OAuth configuration form
CVE-2026-933195.7—mobyBuildKitCWE-567A malicious frontend can cause a daemon panic
CVE-2026-286675.5—GoogleAndroidCWE-119In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read du…
CVE-2026-588345.5—GoogleAndroidCWE-20In setPermissionGrantState of DevicePolicyManagerService.java, there is a pos…
CVE-2026-784135.5—Rapid7VelociraptorCWE-276Velociraptor privilege escalation via SysmonLogForward client monitoring arti…
CVE-2026-1040305.5—Red HatRed Hat Enterprise Linux 10CWE-125Sssd: sssd: denial of service via out-of-bounds read during passkey parsing
CVE-2026-1052905.5—feelec-yishufeelcrm-osCWE-918feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php serve…
CVE-2026-1053075.5—n/aCasdoorCWE-287Casdoor API Endpoint authz_filter.go ApiFilter missing authentication
CVE-2026-1053825.5—onetwothreenethHospitalManagementSystemCWE-266onetwothreeneth HospitalManagementSystem Account Administration controller.ph…
CVE-2026-1053835.5—onetwothreenethHospitalManagementSystemCWE-74onetwothreeneth HospitalManagementSystem controller.php sql injection
CVE-2026-1053845.5—UNIONHospitalManagementSystemCWE-74UNION HospitalManagementSystem patient_info.php sql injection
CVE-2026-1053855.5—onetwothreenethHospitalManagementSystemCWE-74onetwothreeneth HospitalManagementSystem transaction_details.php sql injection
CVE-2026-1053865.5—onetwothreenethHospitalManagementSystemCWE-74onetwothreeneth HospitalManagementSystem print.php get sql injection
CVE-2026-1053875.5—girishsarafOnline-Appointment-Booking-SystemCWE-74girishsaraf Online-Appointment-Booking-System Patient Login cover.php mysqli_…
CVE-2026-1053925.5—LybbnDjango-Vue-LyadminCWE-320Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key
CVE-2026-1054475.5—Red HatRed Hat Quay 3CWE-863Quay: quay: global read-only superuser can access build trigger write credent…
CVE-2026-1054685.5—girishsarafOnline-Appointment-Booking-SystemCWE-74girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query s…
CVE-2026-1054695.5—girishsarafOnline-Appointment-Booking-SystemCWE-74girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql …
CVE-2026-1054705.5—girishsarafOnline-Appointment-Booking-SystemCWE-74girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus…
CVE-2026-04825.4—AMDAlveo™ Accelerator CardsCWE-787In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot…
CVE-2026-712975.4—Red HatMulticluster Engine for KubernetesCWE-306Maestro: maestro: grpc broker has no auth interceptor and client mtls is opti…
CVE-2026-1022955.4—Red HatRed Hat Quay 3CWE-79Quay: quay: dom-based cross-site scripting via oauth local callback format=js…
CVE-2026-1048935.4—makeplaneplaneCWE-770Plane: Improper validation allows arbitrary modification of API token rate li…
CVE-2026-1049555.4—makeplaneplaneCWE-269Plane: Project Member can escalate Project Guest to Member via PATCH /project…
CVE-2026-1049615.4—makeplaneplaneCWE-863Plane: WorkspaceOwnerPermission missing is_active check allows deactivated us…
CVE-2026-1049655.4—makeplaneplaneCWE-639Plane: Cross-Tenant Issue Relation Creation via IDOR
CVE-2026-1049675.4—makeplaneplaneCWE-639Plane: Cross-workspace association destruction and issue mutation/read via un…
CVE-2026-1056925.4—penpotpenpotCWE-284Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Li…
CVE-2026-1056945.4—penpotpenpotCWE-79Penpot: Stored XSS via Unsanitised SVG Uploads
CVE-2026-1056985.4—langflow-ailangflowCWE-639Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/…
CVE-2026-597875.3—ZabbixZabbixCWE-143SNMP trap injection in zabbix_trap_receiver.pl
CVE-2026-946695.3—WP ManageNinja LLCFluent Forms Pro Add On PackCWE-862WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Broken Access Contr…
CVE-2026-972755.3—VillaThemeBuildKit – Product Builder for WooCommerce – Custom PC BuilderCWE-1284WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plug…
CVE-2026-1024265.3—joomshaper.comSP Page Builder (Pro) extension for JoomlaCWE-79Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filt…
CVE-2026-1027785.3—svenbluege.deEvent Gallery for JoomlaCWE-352Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on …
CVE-2026-1036845.3—ArrayticsWP Event SolutionCWE-862WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerab…
CVE-2026-1049565.3—makeplaneplaneCWE-943Plane: Unauthenticated ORM field-name injection via `group_by`/`sub_group_by`…
CVE-2026-1050735.3—ArrayticsWP Event SolutionCWE-497WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulner…
CVE-2026-1053965.3—heymrunheymCWE-346Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header
CVE-2026-1054215.3—KitKit (formerly ConvertKit) for WooCommerceCWE-862WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.2.0 - Broken …
CVE-2026-1056865.3—penpotpenpotCWE-770Penpot: Repeated chunk index causes temporary-storage amplification
CVE-2026-1056935.3—penpotpenpotCWE-862Penpot: Anonymous share-link token disclosure & page-scope bypass via get-vie…
CVE-2026-1057585.3—vllm-projectvllmCWE-770vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_fram…
CVE-2026-1057605.3—vllm-projectvllmCWE-400vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
CVE-2026-597855.1—ZabbixZabbixCWE-204Hidden host credentials inferable via multiselect.get filtering
CVE-2026-1018935.1—Newell BrandsDYMO IDCWE-611Newell Brands DYMO ID document parsing failing file type extension authentica…
CVE-2026-1027765.1—svenbluege.deEvent Gallery for JoomlaCWE-352Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks o…
CVE-2026-1053975.1—ThimPressLearnPressCWE-79LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint…
CVE-2026-784124.9—Rapid7VelociraptorCWE-639WatchEvent API streams another organization's live events
CVE-2026-1056454.9—TryGhostGhostCWE-1333Ghost: Regular Expression Denial of Service in External Media Inliner
CVE-2026-1056464.9—TryGhostGhostCWE-1333Ghost: Regular Expression Denial of Service in Content Import
CVE-2026-1056764.9—TryGhostGhostCWE-22Ghost: Path Traversal via Locale Setting
CVE-2026-1056874.9—penpotpenpotCWE-269Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-…
CVE-2026-1057854.8—laurent22joplinCWE-620Joplin Server password reset accepts tokens issued for unrelated purposes
CVE-2026-1057844.6—laurent22joplinCWE-79Joplin whiteboard card rendering allows CSS injection into application chrome
CVE-2026-397634.3—Deepak AnandWP Dummy Content GeneratorCWE-862WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control …
CVE-2026-397834.3—WP SYNTEXPolylangCWE-862WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability
CVE-2026-1048944.3—makeplaneplaneCWE-639Plane: Cross-Tenant Module Issue Linking via IDOR
CVE-2026-1049634.3—makeplaneplaneCWE-200Plane: Workspace cycle and module endpoints missing project-membership filter…
CVE-2026-1056784.3—TryGhostGhostCWE-269Ghost: Editors Could Promote Staff Users to Their Own Role
CVE-2026-1056844.3—penpotpenpotCWE-200Penpot: Share-link page-scope escape — comment RPCs leak comment content, aut…
CVE-2026-1057474.3—docling-projectdoclingCWE-409Docling: METS-GBS archive member limit enforced after full member enumeration…
CVE-2026-1057484.3—docling-projectdoclingCWE-73Docling: Crafted DoclingDocument JSON embeds local image files into converted…
CVE-2026-1025764.2—Red HatRed Hat Quay 3CWE-79Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on si…
CVE-2026-1057554.2—vllm-projectvllmCWE-639vLLM: Flash late-interaction scoring caches query embeddings under a caller-c…
CVE-2026-1056474.0—TryGhostGhostCWE-367Ghost: Server-Side Request Forgery in Bookmark Fetching
CVE-2026-1056484.0—TryGhostGhostCWE-184Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses
CVE-2026-1057434.0—docling-projectdoclingCWE-367Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi…
CVE-2026-1056833.8—TryGhostGhostCWE-35Ghost: Path Traversal Vulnerability in Ghost ImageSize Service
CVE-2026-1057423.7—docling-projectdoclingCWE-201Docling: Configured HTTP headers sent to every remote image host named by a d…
CVE-2026-778033.6—Progress SoftwareProgress® Telerik® Fiddler® ClassicCWE-444Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic
CVE-2026-1057123.6—GnuPGGnuPGCWE-61gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an…
CVE-2026-588563.3—GoogleAndroidCWE-119In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is …
CVE-2026-1040293.3—Red HatRed Hat Enterprise Linux 10CWE-125Sssd: sssd: denial of service via out-of-bounds read in autofs responder
CVE-2026-1056523.1—TryGhostGhostCWE-203Ghost: Password Hash Ordering Disclosure in Ghost Admin API
CVE-2026-1057523.1—vllm-projectvllmCWE-200vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant…
CVE-2026-1056822.7—TryGhostGhostCWE-918Ghost: Server-Side Request Forgery in Webhook Trigger
CVE-2026-1053262.5—Red HatRed Hat Enterprise Linux 10CWE-88Cups: cups: argument injection in mailto notifier via notify-recipient-uri
CVE-2026-597832.3—ZabbixZabbixCWE-787Server DoS via binary items
CVE-2026-1035462.3—MongoDB, Inc.Mongodb Controllers for KubernetesCWE-918Improper validation of Ops Manager configuration in MongoDB Kubernetes Operator
CVE-2026-1057662.3—ChainguardChainguard Academy (edu)CWE-319Chainguard Academy (edu) Nginx directory redirect downgrades HTTPS requests t…
CVE-2026-1057462.2—docling-projectdoclingCWE-668Docling: KServe v2 OCR engine does not enforce enable_remote_services
CVE-2026-1052882.1—feelec-yishufeelcrm-osCWE-79feelec-yishu feelcrm-os Crm Endpoint functions.php index cross site scripting
CVE-2026-1052912.1—feelec-yishufeelcrm-osCWE-79feelec-yishu feelcrm-os Department Search Endpoint GroupController.class.php …
CVE-2026-1053292.1—n/aTallCMSCWE-74TallCMS PluginManager ThemeManager.php code injection
CVE-2026-1053882.1—feelec-yishufeelcrm-osCWE-74feelec-yishu feelcrm-os Member Endpoint MemberController.class.php index sql …
CVE-2026-1053892.1—feelec-yishufeelcrm-osCWE-284feelec-yishu feelcrm-os UploadTicketFile Endpoint UploadController.class.php …
CVE-2026-1054382.1—n/aO2OACWE-918O2OA General url ActionUploadExcelWithUrl server-side request forgery
CVE-2026-1054442.1—dotneteShopCWE-99dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection
CVE-2026-1057672.1—ChainguardChainguard Academy (edu)CWE-78Chainguard Academy (edu) integrate-platform-docs composite action interpolate…
CVE-2026-1052892.0—feelec-yishufeelcrm-osCWE-79feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php…
CVE-2026-1053152.0—n/adjango-haystackCWE-94django-haystack more_like_this Template Tag elasticsearch_backend.py _to_pyth…
CVE-2026-28625await—GoogleAndroid—In multiple locations, there is a possible permission bypass due to a logic e…
CVE-2026-28640await—GoogleAndroid—In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.jav…
CVE-2026-28641await—GoogleAndroid—In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceControll…
CVE-2026-28647await—GoogleAndroid—In updateState of DeviceAdminAppsPreferenceController.java, there is a possib…
CVE-2026-28648await—GoogleAndroid—In Settings, there is a possible permission bypass due to a confused deputy. …
CVE-2026-37719await—n/an/a—An issue in dormakaba evolo Service (all versions) allows a remote attacker t…
CVE-2026-49880await—GoogleAndroid—In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds …
CVE-2026-78860await—n/an/a—An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary cod…
CVE-2026-78861await—n/an/a—An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary cod…
CVE-2026-78862await—n/an/a—An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary cod…
CVE-2026-82988await—ViewsonicvCast—CVE-2026-82988
CVE-2026-82989await—ViewsonicvCast—CVE-2026-82989
CVE-2026-88391await—n/an/a—Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables…
CVE-2026-88392await—n/an/a—Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local…
CVE-2026-88393await—n/an/a—WookTeam v1.6.6 and before is vulnerable to RCE in the project task export in…

Results continue: ranks 401–413.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-10-05 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.