AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0110 64.4 —
AFFECTED Product Versions Fixed A3002MU 1.0.0-B20230403.1455 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
413 CVEs published, led by makeplane (38).
413 CVEs published October 5, 2026: 26 critical, 105 high, 205 medium, 46 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 31 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 13 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1384 | 51373 | — | — |
| KEV catalog size | 1734 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
3368 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 0 | 6205 | 530 | 2640 | 727 | 1 | 15 | 6 | 0.1 | 7.8 | .0019 | -188 ▼ |
| microsoft | 1 | 2902 | 201 | 1993 | 692 | 16 | 290 | 31 | 1.1 | 7.8 | .0047 | -8 ▼ |
| 38 | 2869 | 358 | 1119 | 1250 | 132 | 80 | 9 | 0.3 | 7.5 | .0026 | 0 | |
| red hat | 34 | 933 | 54 | 389 | 435 | 55 | 2 | 0 | 0.0 | 6.6 | .0035 | +1 ▲ |
| apple | 0 | 564 | 67 | 166 | 317 | 14 | 89 | 9 | 1.6 | 6.5 | .0019 | 0 |
| suse | 0 | 53 | 8 | 27 | 16 | 2 | 0 | 0 | 0.0 | 7.5 | .0036 | -9 ▼ |
| canonical | 2 | 52 | 16 | 12 | 19 | 5 | 0 | 0 | 0.0 | 7.8 | .0022 | +2 ▲ |
| freebsd | 0 | 48 | 2 | 36 | 7 | 3 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 0 | 182 | 54 | 72 | 55 | 1 | 60 | 17 | 9.3 | 7.8 | .0046 | -11 ▼ |
| ubiquiti | 0 | 65 | 36 | 28 | 1 | 0 | 3 | 3 | 4.6 | 9.1 | .0050 | 0 |
| palo alto networks | 0 | 46 | 1 | 4 | 26 | 15 | 13 | 2 | 4.3 | 4.7 | .0022 | 0 |
| fortinet | 1 | 42 | 12 | 10 | 17 | 3 | 30 | 8 | 19.0 | 7.2 | .0040 | +1 ▲ |
| netgear | 0 | 34 | 0 | 0 | 27 | 7 | 0 | 0 | 0.0 | 4.3 | .0027 | 0 |
| f5 | 0 | 26 | 7 | 14 | 4 | 1 | 5 | 2 | 7.7 | 8.7 | .0050 | -7 ▼ |
| ivanti | 0 | 24 | 6 | 16 | 2 | 0 | 25 | 5 | 20.8 | 8.8 | .0152 | 0 |
| sonicwall | 0 | 19 | 7 | 8 | 4 | 0 | 19 | 4 | 21.1 | 8.3 | .0050 | -5 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 101 | 808 | 165 | 368 | 249 | 18 | 33 | 2 | 0.2 | 7.5 | .0057 | +93 ▲ |
| mozilla | 0 | 379 | 122 | 169 | 87 | 0 | 9 | 0 | 0.0 | 8.8 | .0031 | -34 ▼ |
| gitlab | 1 | 105 | 8 | 24 | 62 | 11 | 5 | 3 | 2.9 | 5.3 | .0035 | +1 ▲ |
| drupal | 0 | 94 | 11 | 9 | 66 | 8 | 4 | 1 | 1.1 | 5.7 | .0027 | -26 ▼ |
| github | 0 | 23 | 2 | 11 | 10 | 0 | 0 | 0 | 0.0 | 7.4 | .0054 | -3 ▼ |
| docker | 1 | 13 | 1 | 8 | 4 | 0 | 0 | 0 | 0.0 | 8.2 | .0017 | +1 ▲ |
| wordpress | 0 | 6 | 1 | 4 | 1 | 0 | 3 | 3 | 50.0 | 8.7 | .0392 | 0 |
| eclipse | 0 | 2 | 2 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.3 | .0050 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 0 | 2905 | 581 | 1660 | 563 | 101 | 28 | 4 | 0.1 | 7.8 | .0036 | 0 |
| ibm | 0 | 1023 | 196 | 473 | 336 | 18 | 6 | 1 | 0.1 | 7.5 | .0037 | -70 ▼ |
| adobe | 0 | 830 | 82 | 364 | 375 | 9 | 21 | 5 | 0.6 | 7.5 | .0036 | -2 ▼ |
| progress | 5 | 71 | 15 | 42 | 13 | 1 | 6 | 1 | 1.4 | 8.0 | .0045 | +3 ▲ |
| zohocorp | 0 | 42 | 6 | 29 | 7 | 0 | 0 | 0 | 0.0 | 8.3 | .0117 | -1 ▼ |
| solarwinds | 0 | 26 | 18 | 5 | 3 | 0 | 10 | 4 | 15.4 | 9.1 | .0067 | 0 |
| veeam | 0 | 19 | 6 | 10 | 3 | 0 | 1 | 0 | 0.0 | 8.6 | .0042 | 0 |
| atlassian | 1 | 10 | 2 | 8 | 0 | 0 | 13 | 0 | 0.0 | 7.8 | .0043 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 0 | 74 | 22 | 28 | 12 | 12 | 3 | 0 | 0.0 | 8.5 | .0164 | -3 ▼ |
| siemens | 0 | 52 | 6 | 33 | 10 | 3 | 0 | 0 | 0.0 | 7.3 | .0026 | -1 ▼ |
| synology | 0 | 46 | 5 | 10 | 25 | 6 | 0 | 0 | 0.0 | 5.6 | .0032 | 0 |
| rockwell automation | 0 | 43 | 5 | 32 | 6 | 0 | 0 | 0 | 0.0 | 8.6 | .0029 | -18 ▼ |
| advantech | 0 | 20 | 2 | 17 | 1 | 0 | 0 | 0 | 0.0 | 8.6 | .0071 | 0 |
| schneider electric | 0 | 18 | 2 | 11 | 5 | 0 | 0 | 0 | 0.0 | 8.5 | .0044 | -4 ▼ |
| hitachi energy | 0 | 12 | 2 | 4 | 6 | 0 | 0 | 0 | 0.0 | 7.0 | .0025 | -4 ▼ |
| abb | 0 | 11 | 1 | 6 | 4 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dell | 0 | 378 | 34 | 170 | 152 | 22 | 2 | 1 | 0.3 | 7.2 | .0027 | -19 ▼ |
| nvidia | 0 | 301 | 25 | 206 | 70 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | -30 ▼ |
| sourcecodester | 10 | 247 | 0 | 0 | 147 | 100 | 0 | 0 | 0.0 | 5.5 | .0041 | +9 ▲ |
| openclaw | 0 | 223 | 4 | 114 | 84 | 21 | 0 | 0 | 0.0 | 7.1 | .0031 | 0 |
| mongodb | 1 | 170 | 6 | 99 | 60 | 5 | 1 | 0 | 0.0 | 7.1 | .0038 | -9 ▼ |
| spring | 0 | 170 | 13 | 60 | 83 | 14 | 0 | 0 | 0.0 | 6.5 | .0033 | 0 |
| itsourcecode | 14 | 167 | 0 | 0 | 42 | 125 | 0 | 0 | 0.0 | 2.1 | .0033 | +8 ▲ |
| hewlett packard enterprise (hpe) | 1 | 167 | 23 | 80 | 55 | 9 | 1 | 1 | 0.6 | 7.2 | .0042 | -85 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-85706 | .9296 | 99.8 | 10.0 |
| CVE-2026-87902 | .4612 | 98.8 | 8.1 |
| CVE-2026-76461 | .2827 | 98.1 | 9.8 |
| CVE-2026-93616 | .1965 | 97.3 | 9.8 |
| CVE-2026-76460 | .1403 | 96.5 | 10.0 |
| CVE-2026-86218 | .1293 | 96.2 | 10.0 |
| CVE-2026-85102 | .0755 | 94.3 | 9.8 |
| CVE-2026-12269 | .0699 | 94.0 | 8.8 |
| CVE-2026-77692 | .0656 | 93.6 | 7.5 |
| CVE-2026-17176 | .0497 | 92.0 | 7.7 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-85706 | 10.0 | .9296 | KEV |
| CVE-2026-76460 | 10.0 | .1403 | KEV |
| CVE-2026-86218 | 10.0 | .1293 | KEV |
| CVE-2026-75650 | 10.0 | .0395 | KEV |
| CVE-2026-82004 | 10.0 | .0325 | |
| CVE-2026-86152 | 10.0 | .0288 | |
| CVE-2026-85978 | 10.0 | .0144 | |
| CVE-2026-73369 | 10.0 | .0125 | |
| CVE-2026-75699 | 10.0 | .0125 | |
| CVE-2026-75703 | 10.0 | .0125 |
| Vendor | CVEs |
|---|---|
| linux | 1927 |
| microsoft | 994 |
| 662 | |
| oracle | 634 |
| ibm | 334 |
| apache | 288 |
| red hat | 265 |
| apple | 247 |
| adobe | 222 |
| dell | 188 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 17 |
| apple | 9 |
| 9 | |
| fortinet | 8 |
| linux | 6 |
| adobe | 5 |
| ivanti | 5 |
| berriai | 4 |
| checkpoint | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 124 |
| NuGet | 24 |
| Packagist | 24 |
| npm | 24 |
| PyPI | 14 |
| crates.io | 10 |
| Go | 9 |
| RubyGems | 4 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-58704 | 0 | |
| CVE-2026-75650 | Adobe | 0 |
| CVE-2026-86950 | Apple | 0 |
| CVE-2026-87491 | 0 | |
| CVE-2026-88779 | NetScaler | 0 |
| CVE-2026-93952 | Arista Networks | 0 |
| CVE-2026-102489 | Zammad GmbH | 1 |
| CVE-2026-102490 | Zammad GmbH | 1 |
| CVE-2026-84869 | ConnectWise | 2 |
| CVE-2026-86218 | N-able | 2 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1783 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1783 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1783 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1783 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1783 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1783 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1783 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1783 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1783 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1783 |
EXPLOIT PUBLISHED — envoyproxy envoy: 9 CVEs (CVE-2026-48521, CVE-2026-73511, CVE-2026-73512, CVE-2026-73513, CVE-2026-73546, CVE-2026-73548, CVE-2026-73550, CVE-2026-73552, CVE-2026-73553). Public exploit references added.
EXPLOIT PUBLISHED — Omega Solution CoinEx Crypto: 3 CVEs (CVE-2026-105096, CVE-2026-105097, CVE-2026-105099). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2014-125130 (Damjan CodeArt Google MP3 Audio Player). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-39999 (WordPress.org WordPress). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-54402 (iDocView). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2023-54405 (H3C CVM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2024-58388 (Sharp Corporation Multiple Multifunction Printers). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-56361. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-56362. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-56363. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2025-56365. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-100823 (Mozilla Firefox). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103534 (David-Crty databasement). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103539 (ZongXR SuperMarket). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103542 (formtools.org Form Tools). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-103686 (rhukster dom-sanitizer). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104052 (itsourcecode Pet Shop Management System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104118 (Unknown Razorpay for WooCommerce). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104119 (Unknown Simple Shopping Cart). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104120 (modelcontextprotocol mcp-server-fetch). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-104983 (Linux Mint Xreader). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105137 (Laradock). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105147 (SciPhi-AI R2R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105148 (SciPhi-AI R2R). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105156 (YzmCMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105157 (RainyGao DocSys). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105158 (RainyGao DocSys). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-105167 (kishor-23 food-waste-management-system). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-17005 (Unknown Horizontal scrolling announcements). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-37604. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-51879. Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-86817 (Unknown Five Star Business Profile and Schema). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93454 (Webkul Aureus ERP). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-93549 (Unknown CoCart). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97233 (volotat Anagnorisis). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-97332 (Unknown User Private Files). Public exploit reference added.
DUE DATE PASSED — CVE-2026-104286 (Fortinet FortiMail). CISA remediation deadline was October 4, 2026; still in catalog.
RESCORED — kishor-23 food-waste-management-system: 4 CVEs (CVE-2026-105168, CVE-2026-105169, CVE-2026-105170, CVE-2026-105171). CVSS rescored — before/after on each CVE page.
RESCORED — CVE-2025-56361. CVSS 7.5 → 5.7 (NVD).
RESCORED — CVE-2025-56362. CVSS 7.5 → 5.7 (NVD).
RESCORED — CVE-2025-56363. CVSS 7.5 → 5.7 (NVD).
RESCORED — CVE-2025-56364. CVSS 7.5 → 5.7 (NVD).
RESCORED — CVE-2025-56365. CVSS 7.5 → 5.7 (NVD).
RESCORED — CVE-2026-103101 (Pexip Infinity). CVSS 8.6 → 7.5 (NVD).
RESCORED — CVE-2026-103109 (Pexip Infinity). CVSS 7.7 → 9.4 (NVD).
RESCORED — CVE-2026-103489 (JetBrains YouTrack). CVSS 2 → 5.4 (NVD).
RESCORED — CVE-2026-103678 (tnef). CVSS 5.4 → 8.1 (NVD).
RESCORED — CVE-2026-103680 (tnef). CVSS 3.1 → 6.5 (NVD).
RESCORED — CVE-2026-37604. CVSS 9.8 → 6.5 (NVD).
PATCH SHIPPED — Red Hat OpenShift Container Platform 4.21: 4 CVEs (CVE-2026-49329, CVE-2026-83589, CVE-2026-87114, CVE-2026-96577). Fix versions published.
PATCH SHIPPED — CVE-2026-102628 (Eummena Cadmos LTI). Fixed in Cadmos LTI 2026-09-02.
PATCH SHIPPED — CVE-2026-49762 (elixir-lang elixir). Fixed in elixir c64417d72fd5c7d09e963ca3ac5fa2b140978d9e.
ENRICHED — CVE-2026-64043 (Linux). Received CVSS 4.7 and CPE data from NVD.
How to read these box scores · glossary
413 CVEs published. 25 box scores and 375 table rows below; the remaining 13 continue on page 2 — every CVE is listed, nothing truncated.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0110 64.4 —
AFFECTED Product Versions Fixed A3002MU 1.0.0-B20230403.1455 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0090 58.3 —
AFFECTED Product Versions Fixed Papermerge 3.5.3 – —
TIMELINE Oct 5 Reserved by CNA Oct 5 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0078 54.5 —
AFFECTED Product Versions Fixed A3002MU 1.0.0-B20230403.1455 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P L L L 2.1 .0052 42.2 —
AFFECTED Product Versions Fixed A3002MU 1.0.0-B20230403.1455 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P H N H H H 7.5 .0051 41.7 —
AFFECTED Product Versions Fixed P4 (Helix Core) unspecified 2026.4.2
TIMELINE Sep 30 Reserved by CNA Oct 5 Published (CNA: Perforce)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N N N H 6.6 .0043 34.8 —
AFFECTED Product Versions Fixed Qt for MCUs 2.12.0 – —
TIMELINE Aug 10 Reserved by CNA Oct 5 Published (CNA: Qt)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 10.0 .0042 34.5 —
AFFECTED Product Versions Fixed P4 (Helix Core) unspecified 2026.4.2
TIMELINE Sep 25 Reserved by CNA Oct 5 Published (CNA: Perforce)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H N N N L N N 2.9 .0040 32.4 —
AFFECTED Product Versions Fixed litemall 1.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0039 31.0 —
AFFECTED Product Versions Fixed NextChat 2.16.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0038 29.8 —
AFFECTED Product Versions Fixed MediaTek chipset MT2718 – —
TIMELINE Nov 3 Reserved by CNA Oct 5 Published (CNA: MediaTek)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N H P N N H H H 9.2 .0037 29.1 —
AFFECTED Product Versions Fixed Legcord 1.1.0 – —
TIMELINE Oct 5 Reserved by CNA Oct 5 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L N 5.3 .0037 29.0 —
AFFECTED Product Versions Fixed P4 (Helix Core) unspecified 2026.4.2
TIMELINE Sep 30 Reserved by CNA Oct 5 Published (CNA: Perforce)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0036 27.2 —
AFFECTED Product Versions Fixed P4 (Helix Core) unspecified 2026.4.2
TIMELINE Sep 25 Reserved by CNA Oct 5 Published (CNA: Perforce)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N H N H H H 8.4 .0035 26.6 —
AFFECTED Product Versions Fixed Mitel MiVoice Office 400 11.0.96.0 – —
TIMELINE Oct 2 Reserved by CNA Oct 5 Published (CNA: NCSC.ch)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L P N N H H H 9.5 .0035 26.1 —
AFFECTED Product Versions Fixed P4 (Helix Core) unspecified 2026.4.2
TIMELINE Sep 30 Reserved by CNA Oct 5 Published (CNA: Perforce)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N L L 2.1 .0033 24.0 —
AFFECTED Product Versions Fixed Gerapy 0.9.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N N L L 5.1 .0033 23.6 —
AFFECTED Product Versions Fixed P4 (Helix Core) unspecified 2026.4.2
TIMELINE Sep 30 Reserved by CNA Oct 5 Published (CNA: Perforce)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N P N N L 5.3 .0032 22.7 —
AFFECTED Product Versions Fixed vgmstream r2117 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0032 22.6 —
AFFECTED Product Versions Fixed feelcrm-os 1.0.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0032 22.5 —
AFFECTED Product Versions Fixed Drug Recommendation System 1.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0032 22.5 —
AFFECTED Product Versions Fixed Drug Recommendation System 1.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N L L L 2.0 .0032 22.5 —
AFFECTED Product Versions Fixed Drug Recommendation System 1.0 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H N N 5.5 .0031 22.0 —
AFFECTED Product Versions Fixed Mitel MiVoice Office 400 11.0.96.0 – —
TIMELINE Oct 2 Reserved by CNA Oct 5 Published (CNA: NCSC.ch)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N L L L 2.1 .0030 20.9 —
AFFECTED Product Versions Fixed Jeebase 0.0.1 – —
TIMELINE Oct 4 Reserved by CNA Oct 5 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H N N U H N N 5.9 .0029 19.5 —
AFFECTED Product Versions Fixed File Uploads Addon for WooCommerce 1.7.2 – —
TIMELINE Jun 29 Reserved by CNA Oct 5 Published (CNA: WPScan)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-104408 | 7.6 | 18.5 | Groundhogg | Groundhogg | CWE-89 | WordPress Groundhogg plugin <= 4.8.3 - SQL Injection vulnerability |
| CVE-2026-103335 | 5.3 | 18.4 | Deepen Bajracharya | Video Conferencing with Zoom | CWE-201 | WordPress Video Conferencing with Zoom plugin <= 4.6.10 - Sensitive Data Expo… |
| CVE-2026-105246 | 5.5 | 17.3 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System btn_functions.php update sql… |
| CVE-2026-105172 | 5.5 | 16.5 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System login1.php sql injection |
| CVE-2026-105182 | 5.5 | 16.5 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System btn_functions.php update sql… |
| CVE-2026-105183 | 5.5 | 16.5 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System confirm.php sql injection |
| CVE-2026-105184 | 5.5 | 16.5 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System creteria.php sql injection |
| CVE-2026-105185 | 5.5 | 16.5 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System examinee.php sql injection |
| CVE-2026-105229 | 5.5 | 16.5 | kishor-23 | food-waste-management-system | CWE-74 | kishor-23 food-waste-management-system User Registration Endpoint signup.php … |
| CVE-2026-105230 | 5.5 | 16.5 | kishor-23 | food-waste-management-system | CWE-74 | kishor-23 food-waste-management-system deliverymyord.php sql injection |
| CVE-2026-105231 | 5.5 | 16.5 | kishor-23 | food-waste-management-system | CWE-74 | kishor-23 food-waste-management-system Admin Registration signup.php sql inje… |
| CVE-2026-105232 | 5.5 | 16.5 | kishor-23 | food-waste-management-system | CWE-74 | kishor-23 food-waste-management-system Registration deliverysignup.php sql in… |
| CVE-2026-105247 | 5.5 | 16.5 | SourceCodester | Online Reviewer Management System | CWE-74 | SourceCodester Online Reviewer Management System btn_functions.php course sql… |
| CVE-2026-105253 | 5.5 | 16.5 | itsourcecode | Online Admission System Project | CWE-74 | itsourcecode Online Admission System Project login1.php sql injection |
| CVE-2026-104389 | 8.5 | 16.1 | Sirv | Sirv | CWE-89 | WordPress Sirv plugin <= 8.2.5 - SQL Injection vulnerability |
| CVE-2026-105175 | 5.5 | 15.4 | SourceCodester | Drug Recommendation System | CWE-74 | SourceCodester Drug Recommendation System Student Registration add_student.ph… |
| CVE-2026-105226 | 2.0 | 14.6 | osCommerce | osCommerce2 | CWE-74 | osCommerce osCommerce2 Newsletter Management newsletters.php include code inj… |
| CVE-2026-105251 | 5.3 | 14.6 | n/a | vgmstream | CWE-119 | vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds |
| CVE-2026-104807 | 1.9 | 14.5 | Mitel | Mitel MiVoice Office 400 | CWE-79 | Mitel MiVoice Office 400 stored Cross-Site Scripting |
| CVE-2026-104808 | 1.9 | 14.5 | Mitel | Mitel MiVoice Office 400 | CWE-79 | Mitel MiVoice Office 400 stored Cross-Site Scripting |
| CVE-2026-105248 | 5.3 | 14.0 | n/a | vgmstream | CWE-119 | vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write |
| CVE-2026-105064 | 6.5 | 13.3 | Unlimited Elements | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | CWE-470 | WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) … |
| CVE-2026-100727 | 6.9 | 12.9 | GROWI, Inc. | GROWI | CWE-552 | An improper access control vulnerability exists in GROWI, which allow an unau… |
| CVE-2026-105263 | 5.1 | 12.8 | n/a | Shaarli | CWE-918 | Shaarli Admin Metadata Endpoint MetadataController.php MetadataController ser… |
| CVE-2026-20519 | 7.5 | 12.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In Modem, there is a possible out of bounds write due to a missing bounds che… |
| CVE-2026-20520 | 7.5 | 12.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In Modem, there is a possible out of bounds write due to a missing bounds che… |
| CVE-2026-20526 | 7.5 | 12.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In Modem, there is a possible out of bounds write due to a missing bounds che… |
| CVE-2026-104388 | 5.3 | 12.3 | Blubrry Podcasting | PowerPress Podcasting | CWE-862 | WordPress PowerPress Podcasting plugin <= 11.17.9 - Sensitive Data Exposure v… |
| CVE-2026-104397 | 5.3 | 12.3 | Jeroen Peters | Name Directory | CWE-862 | WordPress Name Directory plugin <= 1.34.2 - Arbitrary Shortcode Execution vul… |
| CVE-2026-105233 | 2.1 | 12.2 | kishor-23 | food-waste-management-system | CWE-384 | kishor-23 food-waste-management-system Login Flow login.php session fixiation |
| CVE-2026-103351 | 5.3 | 12.1 | Magepeople inc. | Taxi Booking Manager for WooCommerce | CWE-1284 | WordPress Taxi Booking Manager for WooCommerce plugin <= 2.1.1 - Other vulner… |
| CVE-2026-105306 | 6.5 | 11.5 | Red Hat | Red Hat Build of Keycloak | CWE-862 | Keycloak-services: keycloak-services: token introspection audience bypass via… |
| CVE-2019-25777 | await | 11.1 | — | YAML | CWE-502 | YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to r… |
| CVE-2026-104805 | 8.5 | 10.9 | Mitel | Mitel MiVoice Office 400 | CWE-22 | Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to R… |
| CVE-2026-104401 | 4.3 | 10.7 | Memberful | Memberful - Membership Plugin | CWE-497 | WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exp… |
| CVE-2026-103078 | 4.3 | 10.6 | Ahmad | JS Help Desk | CWE-639 | WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (I… |
| CVE-2026-20525 | 5.3 | 9.3 | MediaTek, Inc. | MediaTek chipset | CWE-617 | In Modem, there is a possible system crash due to improper input validation. … |
| CVE-2026-20527 | 5.3 | 9.3 | MediaTek, Inc. | MediaTek chipset | CWE-129 | In Modem, there is a possible system crash due to a missing bounds check. Thi… |
| CVE-2026-105245 | 2.9 | 9.4 | sgl-project | sglang | CWE-310 | sgl-project sglang HTTP Endpoint http_server.py server_info cleartext transmi… |
| CVE-2026-78371 | 5.9 | 9.2 | Unknown | File Uploads Addon for WooCommerce | CWE-639 | File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer U… |
| CVE-2026-105302 | 5.7 | 9.1 | Red Hat | Red Hat Build of Keycloak | CWE-200 | Keycloak-services: keycloak-services: user session note mapper exposes upstre… |
| CVE-2026-105181 | 2.1 | 9.0 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System register1.php sql injection |
| CVE-2026-105186 | 2.1 | 9.0 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System new.php sql injection |
| CVE-2026-105187 | 2.1 | 9.0 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System key.php sql injection |
| CVE-2026-105254 | 2.1 | 9.0 | itsourcecode | Online Admission System | CWE-74 | itsourcecode Online Admission System schoolyear.php sql injection |
| CVE-2026-105223 | 9.1 | 8.8 | maclof | kubernetes-client | CWE-295 | maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verifi… |
| CVE-2026-105173 | 2.0 | 8.8 | code-projects | Human Resource Management | CWE-79 | code-projects Human Resource Management Event Creation EventStore.php cross s… |
| CVE-2026-105188 | 2.0 | 8.8 | code-projects | Human Resource Management System | CWE-79 | code-projects Human Resource Management System Live Event History liveEventHi… |
| CVE-2026-105068 | 5.3 | 8.6 | Pixelite | Events Manager | CWE-201 | WordPress Events Manager plugin <= 7.4.5 - Sensitive Data Exposure vulnerability |
| CVE-2026-104811 | 8.4 | 8.3 | Mitel | Mitel MiVoice Office 400 | CWE-20 | Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution |
| CVE-2026-105294 | 9.1 | 7.7 | Legcord | Legcord | CWE-15 | Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig |
| CVE-2026-105055 | 5.3 | 7.5 | WP Mailster | WP Mailster | CWE-862 | WordPress WP Mailster plugin <= 1.9.0.0 - Broken Access Control vulnerability |
| CVE-2026-97071 | 5.3 | 7.4 | VillaTheme | CURCY | CWE-682 | WordPress CURCY plugin <= 2.2.17 - Broken Access Control vulnerability |
| CVE-2026-105225 | 1.9 | 7.5 | osCommerce | osCommerce2 | CWE-74 | osCommerce osCommerce2 Payment payment.php include code injection |
| CVE-2017-20285 | await | 7.2 | — | YAML | CWE-470 | YAML versions before 1.30 for Perl allow a loaded document to trigger the DES… |
| CVE-2026-103079 | 5.4 | 7.0 | Ahmad | JS Help Desk | CWE-639 | WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (I… |
| CVE-2026-20534 | 5.3 | 7.0 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In Modem, there is a possible out of bounds read due to an incorrect bounds c… |
| CVE-2026-20538 | 5.3 | 7.0 | MediaTek, Inc. | MediaTek chipset | CWE-126 | In Modem, there is a possible out of bounds read due to a missing permission … |
| CVE-2026-20539 | 5.3 | 7.0 | MediaTek, Inc. | MediaTek chipset | CWE-126 | In Modem, there is a possible out of bounds read due to a missing bounds chec… |
| CVE-2026-20540 | 5.3 | 7.0 | MediaTek, Inc. | MediaTek chipset | CWE-126 | In Modem, there is a possible out of bounds read due to a missing bounds chec… |
| CVE-2026-20541 | 5.3 | 7.0 | MediaTek, Inc. | MediaTek chipset | CWE-126 | In Modem, there is a possible out of bounds read due to a missing permission … |
| CVE-2026-84169 | 5.3 | 7.0 | Unknown | UPI QR Code Payment Gateway | CWE-639 | UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-St… |
| CVE-2026-19954 | await | 6.8 | — | Net-Whois-Raw | CWE-176 | Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line t… |
| CVE-2026-39721 | 5.4 | 5.7 | Brainstorm Force | Starter Templates | CWE-862 | WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerabi… |
| CVE-2026-20544 | 6.8 | 5.3 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In meta, there is a possible out of bounds write due to a missing bounds chec… |
| CVE-2026-104675 | 4.3 | 5.2 | Liquid Web / StellarWP | Event Tickets | CWE-862 | WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability |
| CVE-2026-105062 | 4.3 | 4.7 | Brandtoss | WP Admin Audit | CWE-862 | WordPress WP Admin Audit plugin <= 1.2.17 - Broken Access Control vulnerability |
| CVE-2026-102393 | 6.5 | 4.6 | Brainstorm Force | Starter Templates | CWE-79 | WordPress Starter Templates plugin <= 4.7.7 - Cross Site Scripting (XSS) vuln… |
| CVE-2026-102914 | 6.5 | 4.6 | Brainstorm Force | Presto Player | CWE-79 | WordPress Presto Player plugin <= 4.5.2 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-103084 | 6.5 | 4.6 | LeapWorx | Premium Addons for Elementor | CWE-79 | WordPress Premium Addons for Elementor plugin <= 4.11.109 - Cross Site Script… |
| CVE-2026-104396 | 6.5 | 4.6 | Jeroen Peters | Name Directory | CWE-79 | WordPress Name Directory plugin <= 1.34.2 - Cross Site Scripting (XSS) vulner… |
| CVE-2026-104400 | 6.5 | 4.6 | bPlugins | B Blocks | CWE-79 | WordPress B Blocks plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-104404 | 6.5 | 4.6 | Liquid Web / StellarWP | GiveWP | CWE-79 | WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-104409 | 6.5 | 4.6 | WP Chill | Image Photo Gallery Final Tiles Grid | CWE-79 | WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.13 - Cross Site … |
| CVE-2026-104673 | 6.5 | 4.6 | Sonaar | MP3 Audio Player for Music, Radio & Podcast by Sonaar | CWE-79 | WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.1… |
| CVE-2026-105292 | 6.0 | 4.4 | chaterm | Chaterm | CWE-352 | Chaterm before 0.12.1 Login CSRF via chaterm:// OAuth Callback |
| CVE-2026-105179 | 2.0 | 3.9 | SourceCodester | Drug Recommendation System | CWE-310 | SourceCodester Drug Recommendation System Password add_user.php missing encry… |
| CVE-2026-104386 | 6.5 | 3.3 | WPFunnels Team | WP VR | CWE-862 | WordPress WP VR plugin <= 9.1.3 - Broken Access Control vulnerability |
| CVE-2026-104706 | 8.4 | 2.5 | Mitel | Mitel MiVoice Office 400 | CWE-31 | Mitel MiVoice Office 400 view system files path traversal |
| CVE-2026-20521 | 8.4 | 2.4 | MediaTek, Inc. | MediaTek chipset | CWE-121 | In Video HAL, there is a possible escalation of privilege due to a missing bo… |
| CVE-2026-20522 | 8.4 | 2.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In neuropilot, there is a possible out of bounds write due to a missing bound… |
| CVE-2026-20523 | 8.4 | 2.4 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In neuropilot, there is a possible out of bounds write due to a missing bound… |
| CVE-2026-20524 | 8.4 | 2.4 | MediaTek, Inc. | MediaTek chipset | CWE-1285 | In apu, there is a possible memory corruption due to improper input validatio… |
| CVE-2026-105056 | 6.5 | 2.3 | impleCode | eCommerce Product Catalog | CWE-79 | WordPress eCommerce Product Catalog plugin <= 3.6.2 - Cross Site Scripting (X… |
| CVE-2026-105060 | 6.5 | 2.3 | Themepoints | Logo Showcase | CWE-79 | WordPress Logo Showcase plugin <= 4.0.4 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-105069 | 6.5 | 2.3 | Nikki Blight | QR Redirector | CWE-79 | WordPress QR Redirector plugin <= 2.0.5 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-105295 | 7.7 | 2.0 | gitahead | GitAhead | CWE-494 | GitAhead 2.5.0 through 2.7.1 Unverified Update Installation and TLS Bypass |
| CVE-2026-20531 | 8.4 | 1.8 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In apu, there is a possible memory corruption due to use after free. This cou… |
| CVE-2026-20543 | 5.5 | 1.8 | MediaTek, Inc. | MediaTek chipset | CWE-215 | In Modem, there is a possible information disclosure due to a logic error. Th… |
| CVE-2026-105301 | 4.0 | 1.6 | Red Hat | Red Hat Build of Keycloak | CWE-918 | Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetc… |
| CVE-2026-20528 | 6.7 | 1.6 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In ccci, there is a possible out of bounds write and read due to a missing bo… |
| CVE-2026-19185 | 7.8 | 1.3 | zephyrproject | zephyr | CWE-822 | Unvalidated user-supplied buffer pointers in the I3C do_ccc system call handl… |
| CVE-2026-20532 | 6.2 | 1.4 | MediaTek, Inc. | MediaTek chipset | CWE-415 | In apu, there is a possible application crash due to double free. This could … |
| CVE-2026-20529 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In battery, there is a possible out of bounds write due to a missing bounds c… |
| CVE-2026-20530 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In display, there is a possible out of bounds write due to a missing bounds c… |
| CVE-2026-20533 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-190 | In display, there is a possible escalation of privilege due to an integer ove… |
| CVE-2026-20536 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In aidl, there is a possible memory corruption due to use after free. This co… |
| CVE-2026-20537 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In aidl, there is a possible memory corruption due to use after free. This co… |
| CVE-2026-20542 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In apusys, there is a possible memory corruption due to use after free. This … |
| CVE-2026-20579 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In vdec, there is a possible out of bounds write due to type confusion. This … |
| CVE-2026-20587 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-843 | In mtee, there is a possible escalation of privilege due to type confusion. T… |
| CVE-2026-20588 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In mtee, there is a possible escalation of privilege due to a missing bounds … |
| CVE-2026-20589 | 6.7 | 1.1 | MediaTek, Inc. | MediaTek chipset | CWE-787 | In venc, there is a possible out of bounds write due to type confusion. This … |
| CVE-2026-105249 | 2.4 | 1.0 | n/a | vgmstream | CWE-119 | vgmstream TXTP File txtp_process.c make_group_random use after free |
| CVE-2026-19184 | 8.4 | 0.9 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in the NXP GAU ADC driver due to byte-versus-sample buffe… |
| CVE-2026-20535 | 6.7 | 0.9 | MediaTek, Inc. | MediaTek chipset | CWE-862 | In aidl, there is a possible escalation of privilege due to a missing permiss… |
| CVE-2026-104407 | 7.1 | 0.7 | Blubrry Podcasting | PowerPress Podcasting | CWE-352 | WordPress PowerPress Podcasting plugin <= 11.17.9 - Cross Site Request Forger… |
| CVE-2026-104809 | 8.4 | 0.3 | Mitel | Mitel MiVoice Office 400 | CWE-73 | Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Ex… |
| CVE-2026-105636 | 9.9 | — | makeplane | plane | CWE-918 | Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) |
| CVE-2026-105691 | 9.9 | — | penpot | penpot | CWE-78 | Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy … |
| CVE-2026-105697 | 9.9 | — | langflow-ai | langflow | CWE-78 | Langflow: OS command injection (RCE) via arbitrary command in MCP stdio serve… |
| CVE-2026-105740 | 9.9 | — | langflow-ai | langflow | CWE-78 | Langflow: Authenticated RCE via MCP Stdio transport allows any user to execut… |
| CVE-2026-88395 | 9.8 | — | n/a | n/a | CWE-89 | GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rub… |
| CVE-2026-97283 | 9.8 | — | Liquid Web / StellarWP | Advanced Post Manager | CWE-502 | WordPress Advanced Post Manager plugin <= 4.5.5 - PHP Object Injection vulner… |
| CVE-2026-105639 | 9.8 | — | makeplane | plane | CWE-200 | Plane: Pre-auth workspace invitation hijack via email-squat and self-served i… |
| CVE-2026-105641 | 9.8 | — | makeplane | plane | CWE-798 | Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli com… |
| CVE-2026-105637 | 9.6 | — | makeplane | plane | CWE-639 | Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling … |
| CVE-2026-105763 | 9.6 | — | twentyhq | twenty | CWE-522 | Twenty: Plaintext IMAP/SMTP/CalDAV password disclosure to any workspace membe… |
| CVE-2026-21589 | 9.3 | — | Atlassian | Bamboo Data Center | — | h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data… |
| CVE-2026-91107 | 9.3 | — | OS4ED | openSIS-Classic | CWE-639 | openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR) |
| CVE-2026-102428 | 9.3 | — | ordasoft.com | OrdaSoft Joomla CCK | CWE-89 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft J… |
| CVE-2026-103352 | 9.3 | — | WP BASE | WP BASE Booking | CWE-89 | WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability |
| CVE-2026-77226 | 9.2 | — | Camunda | Camunda 7 | CWE-863 | Camunda 7.24.0 < 7.24.15 Incorrect Authorization via SetupResource Endpoint |
| CVE-2026-105638 | 9.1 | — | makeplane | plane | CWE-307 | Plane: Magic-code verifier endpoint has no rate limit, enabling 6-digit OTP b… |
| CVE-2026-105640 | 9.1 | — | makeplane | plane | CWE-287 | Plane: Account Takeover via Unverified OAuth Email Match (Gitea, self-managed… |
| CVE-2026-79820 | 9.0 | — | Hewlett Packard Enterprise (HPE) | HPE Integrated Lights-Out (iLO) 7 | CWE-287 | A remote user validation failure vulnerability exists in HPE Integrated Light… |
| CVE-2026-45524 | 8.8 | — | Android | CWE-862 | In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape d… | |
| CVE-2026-55280 | 8.8 | — | Android | CWE-457 | In multiple locations, there is a possible out-of-bounds write due to uniniti… | |
| CVE-2026-58835 | 8.8 | — | Android | CWE-122 | In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due t… | |
| CVE-2026-92931 | 8.8 | — | Progress Software | @progress/sitefinity-nextjs-sdk | CWE-918 | CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Rende… |
| CVE-2026-97257 | 8.8 | — | PressTigers | Simple Event Planner | CWE-502 | WordPress Simple Event Planner plugin <= 1.5.7 - PHP Object Injection vulnera… |
| CVE-2026-100511 | 8.8 | — | Vektor Inc. | VK Google Job Posting Manager | CWE-502 | WordPress VK Google Job Posting Manager plugin <= 1.3.1 - PHP Object Injectio… |
| CVE-2026-101919 | 8.8 | — | Red Hat | Multicluster Engine for Kubernetes | CWE-20 | Hypershift: hypershift: unsanitized kubeconfig passthrough from tenant namesp… |
| CVE-2026-105642 | 8.8 | — | TryGhost | Ghost | CWE-94 | Ghost: Remote Code Execution via Bookmark Card Images |
| CVE-2026-102775 | 8.7 | — | phoca.cz | Phoca Cart extension for Joomla | CWE-639 | Joomla Extension - phoca.cz - Authorisation bypass through user-controlled ke… |
| CVE-2026-104892 | 8.7 | — | makeplane | plane | CWE-256 | Plane: Plaintext logging of API token |
| CVE-2026-104966 | 8.7 | — | makeplane | plane | CWE-639 | Plane: Cross-Workspace IDOR in Estimate and Comment Endpoints Allows Read, Mo… |
| CVE-2026-104968 | 8.7 | — | makeplane | plane | CWE-862 | Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-s… |
| CVE-2026-104976 | 8.7 | — | makeplane | plane | CWE-918 | Plane: SSRF in Gitea OAuth |
| CVE-2026-104979 | 8.7 | — | makeplane | plane | CWE-79 | Plane: Cross-tenant stored XSS in intake enables account takeover |
| CVE-2026-105630 | 8.7 | — | makeplane | plane | CWE-79 | Plane: Stored XSS via SVG attachment served inline on the application origin … |
| CVE-2026-105632 | 8.7 | — | makeplane | plane | CWE-284 | Plane: Broken Access Control - joinProject GraphQL mutation allows self-join … |
| CVE-2026-63277 | 8.5 | — | The Document Foundation | LibreOffice | CWE-829 | RCE via calcext:data-mappings, sql provider and jdbc connector |
| CVE-2026-103066 | 8.5 | — | WP BASE | WP BASE Booking | CWE-89 | WordPress WP BASE Booking plugin <= 6.4.0 - SQL Injection vulnerability |
| CVE-2026-104971 | 8.5 | — | makeplane | plane | CWE-639 | Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint an… |
| CVE-2026-105786 | 8.5 | — | laurent22 | joplin | CWE-306 | Joplin: Unauthenticated account takeover via an attacker-chosen application-a… |
| CVE-2026-12171 | 8.4 | — | cookpete | auto-changelog | CWE-22 | auto-changelog: code execution via untrusted in-repository configuration (han… |
| CVE-2026-86671 | 8.4 | — | Eclipse Foundation | Eclipse Che | CWE-73 | In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POS… |
| CVE-2026-105762 | 8.3 | — | langgenius | dify | CWE-918 | Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-file… |
| CVE-2026-94201 | 8.2 | — | ash-project | ash | CWE-770 | Filtering an :atom attribute with unsafe_to_atom? can exhaust the BEAM atom t… |
| CVE-2026-104852 | 8.2 | — | ardatan | graphql-tools | CWE-1321 | GraphQL Tools has prototype pollution in well-established utility function `m… |
| CVE-2026-104978 | 8.2 | — | makeplane | plane | CWE-863 | Plane: Invitation Hijack in Project Join Flow via Missing Authorization and E… |
| CVE-2026-104970 | 8.1 | — | makeplane | plane | CWE-362 | Plane: InstanceAdminSignUpEndpoint TOCTOU race allows two concurrent unauthen… |
| CVE-2026-104974 | 8.1 | — | makeplane | plane | CWE-284 | Plane: Disabled User Auto-Reactivation on Login |
| CVE-2026-105634 | 8.1 | — | makeplane | plane | CWE-269 | Plane: Privilege Escalation: Project Guest Can Demote Admin/Member Roles |
| CVE-2026-105650 | 8.1 | — | TryGhost | Ghost | CWE-79 | Ghost: Stored XSS via oEmbed Photo Responses |
| CVE-2026-105783 | 8.0 | — | laurent22 | joplin | CWE-346 | Joplin Web Clipper pairing allows cross-origin theft of a permanent API token |
| CVE-2026-77805 | 7.9 | — | Progress Software | Progress® Telerik® Fiddler® Classic | CWE-347 | Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fi… |
| CVE-2026-49885 | 7.8 | — | Android | CWE-190 | In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write d… | |
| CVE-2026-49933 | 7.8 | — | Android | CWE-824 | In handle_le_monitor_device_event of msft.cc, there is a possible control-flo… | |
| CVE-2026-49937 | 7.8 | — | Android | CWE-119 | In multiple functions of MessageQueueBase.h, there is a possible out of bound… | |
| CVE-2026-55266 | 7.8 | — | Android | CWE-400 | In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write… | |
| CVE-2026-55269 | 7.8 | — | Android | CWE-20 | In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety… | |
| CVE-2026-55270 | 7.8 | — | Android | CWE-441 | In dialInternal in multiple locations, there is a possible permission bypass … | |
| CVE-2026-55286 | 7.8 | — | Android | CWE-119 | In stpropnci_process of stpropnci.cc, there is a possible out of bounds write… | |
| CVE-2026-58815 | 7.8 | — | Android | CWE-119 | In multiple locations, there is a possible out of bounds write due to an inco… | |
| CVE-2026-58841 | 7.8 | — | Android | CWE-269 | In multiple functions of VirtualAudioControllerTest.java, there is a possible… | |
| CVE-2026-58854 | 7.8 | — | Android | CWE-843 | In multiple locations, there is a possible memory corruption due to type conf… | |
| CVE-2026-58859 | 7.8 | — | Android | CWE-248 | In multiple places, there is a possible denial of service due to an uncaught … | |
| CVE-2026-104977 | 7.7 | — | makeplane | plane | CWE-918 | Plane: Incomplete fix of CVE-2026-27706 — SSRF still reachable on: missing is… |
| CVE-2026-105764 | 7.7 | — | immich-app | immich | CWE-94 | Immich: Authenticated SVG upload reaches ImageMagick coders and enables RCE |
| CVE-2026-97303 | 7.6 | — | Apps Mav | Scratch & Win – Giveaways and Contests | CWE-862 | WordPress Scratch & Win – Giveaways and Contests plugin <= 3.0.2 - Broken Acc… |
| CVE-2026-104973 | 7.6 | — | makeplane | plane | CWE-918 | Plane: DNS Rebinding Bypass of CVE-2026-30242 SSRF Fix in Webhook Delivery |
| CVE-2026-105628 | 7.6 | — | makeplane | plane | CWE-918 | Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Sta… |
| CVE-2026-0461 | 7.5 | — | AMD | Zynq™ UltraScale+ MPSoCs | CWE-787 | Insufficient boundary validation in the USB boot mode implementation of AMD Z… |
| CVE-2026-58865 | 7.5 | — | Android | CWE-119 | In multiple functions of PduParser.java, there is a possible persistent denia… | |
| CVE-2026-93318 | 7.5 | — | moby | BuildKit | CWE-354 | Cache poisoning via unvalidated image layer DiffIDs |
| CVE-2026-103334 | 7.5 | — | Etoile Web Design Incorporated | Five Star Restaurant Reservations | CWE-201 | WordPress Five Star Restaurant Reservations plugin <= 2.7.24 - Sensitive Data… |
| CVE-2026-104891 | 7.5 | — | douglasborthwick-crypto | mppx-condition-gate | CWE-290 | mppx-condition-gate: Free-access path grants on a self-declared wallet withou… |
| CVE-2026-105631 | 7.5 | — | makeplane | plane | CWE-639 | Plane: asset download endpoints scope file lookups to the workspace (not the … |
| CVE-2026-105675 | 7.5 | — | TryGhost | Ghost | CWE-203 | Ghost: Invite Token Disclosure in Ghost Admin API |
| CVE-2026-105744 | 7.5 | — | docling-project | docling | CWE-22 | Docling: Arbitrary file read/write (and command execution when shell-escape i… |
| CVE-2026-105782 | 7.5 | — | scrapy | scrapy | CWE-470 | Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware |
| CVE-2026-105635 | 7.4 | — | makeplane | plane | CWE-200 | Plane: Unauthenticated Project Invitation Email Disclosure Enables Unauthoriz… |
| CVE-2026-105643 | 7.3 | — | TryGhost | Ghost | CWE-79 | Ghost: Stored XSS via Embed Card Previews |
| CVE-2026-105649 | 7.3 | — | TryGhost | Ghost | CWE-79 | Ghost: Stored XSS via SVG Uploads Bypassing Sanitization |
| CVE-2026-105651 | 7.3 | — | TryGhost | Ghost | CWE-79 | Ghost: Stored XSS via Bookmark Card Images |
| CVE-2026-105679 | 7.3 | — | TryGhost | Ghost | CWE-79 | Ghost: Stored XSS via File Uploads on Local Storage |
| CVE-2026-105773 | 7.3 | — | Canimaan Software | ClamXAV | CWE-362 | Canimaan Software ClamXAV local privilege escalation |
| CVE-2026-49878 | 7.2 | — | Android | CWE-787 | In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible … | |
| CVE-2026-93617 | 7.2 | — | WP Sunshine | Sunshine Photo Cart | CWE-502 | WordPress Sunshine Photo Cart plugin <= 3.7.1 - PHP Object Injection vulnerab… |
| CVE-2026-100506 | 7.2 | — | WP Spell Check | WP Spell Check | CWE-502 | WordPress WP Spell Check plugin <= 12.1 - PHP Object Injection vulnerability |
| CVE-2026-103348 | 7.2 | — | Smackcoders Inc. | WP Ultimate Exporter | CWE-502 | WordPress WP Ultimate Exporter plugin <= 3.0 - PHP Object Injection vulnerabi… |
| CVE-2026-103349 | 7.2 | — | Rymera Web Co | Product Feed PRO for WooCommerce | CWE-502 | WordPress Product Feed PRO for WooCommerce plugin <= 13.5.7 - PHP Object Inje… |
| CVE-2026-104890 | 7.2 | — | Kunstmaan | KunstmaanBundlesCMS | CWE-434 | Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated ad… |
| CVE-2026-105677 | 7.2 | — | TryGhost | Ghost | CWE-22 | Ghost: Remote Code Execution via Theme Translation Files |
| CVE-2025-15643 | 7.1 | — | Jose Fernandez | Adsmonetizer | CWE-79 | WordPress Adsmonetizer plugin <= 3.2.4 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-93316 | 7.1 | — | moby | BuildKit | CWE-476 | Starting daemon with --cdi-disabled flag can lead to panic on specific builds |
| CVE-2026-97309 | 7.1 | — | Webful Creations | RepairBuddy | CWE-862 | WordPress RepairBuddy plugin <= 4.1226 - Sensitive Data Exposure vulnerability |
| CVE-2026-100515 | 7.1 | — | VillaTheme | Photo Reviews for WooCommerce | CWE-79 | WordPress Photo Reviews for WooCommerce plugin <= 1.2.30 - Cross Site Scripti… |
| CVE-2026-102282 | 7.1 | — | cthackers | adm-zip | CWE-732 | adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local priv… |
| CVE-2026-104975 | 7.1 | — | makeplane | plane | CWE-639 | Plane: Cross-tenant asset authorization bypass in Plane Spaces public-board e… |
| CVE-2026-105629 | 7.1 | — | makeplane | plane | CWE-639 | Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Pr… |
| CVE-2026-105633 | 7.1 | — | makeplane | plane | CWE-639 | Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope |
| CVE-2026-105699 | 7.1 | — | langflow-ai | langflow | CWE-639 | Langflow: Authenticated Cross-Project File Disclosure via Unscoped MCP Resour… |
| CVE-2026-105741 | 7.1 | — | langflow-ai | langflow | CWE-290 | Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configurat… |
| CVE-2026-105761 | 7.1 | — | langgenius | dify | CWE-639 | Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MC… |
| CVE-2026-58880 | 7.0 | — | Android | CWE-362 | In handle_app_val_response of btif_rc.cc, there is a possible way to achieve … | |
| CVE-2026-102262 | 7.0 | — | Newell Brands | DYMO ID | CWE-22 | Newell Brands DYMO ID parent directory open to path traversal through imprope… |
| CVE-2026-59782 | 6.9 | — | Zabbix | Zabbix | CWE-125 | JavaScript preprocessing memory disclosure |
| CVE-2026-59786 | 6.9 | — | Zabbix | Zabbix | CWE-940 | Active agent heartbeat missing TLS check |
| CVE-2026-93321 | 6.9 | — | moby | BuildKit | CWE-129 | Malformed LLB file operation can crash buildkitd |
| CVE-2026-93322 | 6.9 | — | moby | BuildKit | CWE-129 | Malformed MergeOp can crash the BuildKit daemon |
| CVE-2026-97070 | 6.9 | — | CozyThemes | Cozy Blocks | CWE-639 | WordPress Cozy Blocks plugin <= 2.2.23 - Insecure Direct Object References (I… |
| CVE-2026-97305 | 6.9 | — | Themeisle | AI Chatbot for WordPress – Hyve Lite | CWE-639 | WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Dir… |
| CVE-2026-102779 | 6.9 | — | joomlafry.com | TF Content for Joomla | CWE-862 | Joomla Extension - joomlafry.com - Unauthenticated forced execution of publis… |
| CVE-2026-102780 | 6.9 | — | joomlafry.com | TF Content for Joomla | CWE-862 | Joomla Extension - joomlafry.com - Unauthenticated cross-record publication a… |
| CVE-2026-103433 | 6.9 | — | Docker | Docker Buildx | CWE-862 | Bake filesystem entitlement consent is skipped for certain secret and oci-lay… |
| CVE-2026-105471 | 6.9 | — | girishsaraf | Online-Appointment-Booking-System | CWE-89 | girishsaraf Online-Appointment-Booking-System Registration signup.php sql inj… |
| CVE-2026-105751 | 6.9 | — | docling-project | docling | CWE-22 | Docling: Arbitrary local file read via draw:image xlink:href in the OpenDocum… |
| CVE-2026-63266 | 6.8 | — | The Document Foundation | LibreOffice | CWE-22 | Arbitrary file write via calcext:data-mappings, sql provider and Firebird bac… |
| CVE-2026-84900 | 6.8 | — | HP Inc | ThinPro 8.1 | CWE-354 | HP ThinPro 8.1 SP10 and ThinPro 9 SP3 Security Updates |
| CVE-2026-93323 | 6.8 | — | moby | BuildKit | CWE-789 | Oversized Dockerfile or .dockerignore can exhaust buildkitd memory |
| CVE-2026-104964 | 6.8 | — | makeplane | plane | CWE-639 | Plane: Cross-Workspace Project Modification via Unscoped Project Lookup |
| CVE-2026-105644 | 6.8 | — | TryGhost | Ghost | CWE-79 | Ghost: Stored XSS via SVG Files in Content Imports |
| CVE-2026-63267 | 6.7 | — | The Document Foundation | LibreOffice | CWE-200 | LFI and GET SSRF via calcext:data-mappings and csv provider |
| CVE-2026-63268 | 6.7 | — | The Document Foundation | LibreOffice | CWE-200 | LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href |
| CVE-2026-63269 | 6.7 | — | The Document Foundation | LibreOffice | CWE-200 | LFI and GET SSRF via GStreamer and HLS playlists |
| CVE-2026-63270 | 6.7 | — | The Document Foundation | LibreOffice | CWE-200 | Environment/ini-file leaks |
| CVE-2026-105688 | 6.7 | — | penpot | penpot | CWE-269 | Penpot: Team admin can escalate to owner via team invitation (missing owner-r… |
| CVE-2026-105745 | 6.7 | — | docling-project | docling | CWE-696 | Docling: Plugin entry points are imported before the allow_external_plugins c… |
| CVE-2026-77804 | 6.6 | — | Progress Software | Progress® Telerik® Fiddler® Classic | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Install… |
| CVE-2026-42700 | 6.5 | — | GhozyLab | Image Slider Widget | CWE-79 | WordPress Image Slider Widget plugin <= 1.1.130 - Cross Site Scripting (XSS) … |
| CVE-2026-55265 | 6.5 | — | Android | CWE-119 | In multiple functions of PduParser.java, there is a possible out of bounds re… | |
| CVE-2026-71299 | 6.5 | — | Red Hat | Multicluster Engine for Kubernetes | CWE-306 | Maestro: maestro: rest api write endpoints registered without authentication … |
| CVE-2026-78411 | 6.5 | — | Rapid7 | Velociraptor | CWE-863 | Velociraptor Server Metadata update with Insufficient Permission Check |
| CVE-2026-89039 | 6.5 | — | Grafana | mcp-k6 | CWE-22 | Arbitrary file read via the convert_playwright_script prompt in mcp-k6 |
| CVE-2026-97304 | 6.5 | — | Arraytics | Timetics | CWE-862 | WordPress Timetics plugin <= 1.0.63 - Broken Access Control vulnerability |
| CVE-2026-100509 | 6.5 | — | Webful Creations | RepairBuddy | CWE-79 | WordPress RepairBuddy plugin <= 4.1225 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-102383 | 6.5 | — | VillaTheme | Lookzy | CWE-862 | WordPress Lookzy plugin <= 1.1.14 - Broken Access Control vulnerability |
| CVE-2026-103085 | 6.5 | — | WP User Manager | WP User Manager | CWE-284 | WordPress WP User Manager plugin <= 2.9.20 - Privilege Escalation vulnerability |
| CVE-2026-103086 | 6.5 | — | Stiofan | UsersWP | CWE-862 | WordPress UsersWP plugin <= 1.2.74 - Broken Access Control vulnerability |
| CVE-2026-103337 | 6.5 | — | Kirillbdev | WC Ukraine Shipping | CWE-862 | WordPress WC Ukraine Shipping plugin <= 1.23.2 - Broken Access Control vulner… |
| CVE-2026-104960 | 6.5 | — | makeplane | plane | CWE-639 | Plane: Authorization bypass in workspace-scoped asset download endpoint expos… |
| CVE-2026-104962 | 6.5 | — | makeplane | plane | CWE-862 | Plane: Cross-project member roster IDOR in ProjectMemberListCreateAPIEndpoint… |
| CVE-2026-104969 | 6.5 | — | makeplane | plane | CWE-639 | Plane: Cross-Tenant Cycle Issue Hijack via IDOR |
| CVE-2026-105680 | 6.5 | — | TryGhost | Ghost | CWE-862 | Ghost: Authorization Issue Allowed Author Role to Delete any Post |
| CVE-2026-105681 | 6.5 | — | TryGhost | Ghost | CWE-943 | Ghost: Authorization Bypass in Comments Feature |
| CVE-2026-105696 | 6.5 | — | penpot | penpot | CWE-862 | Penpot: Share-link page-scope escalation: a share-link holder reads pages out… |
| CVE-2026-105749 | 6.5 | — | docling-project | docling | CWE-400 | Docling: Unbounded table rowspan/colspan in HTML, JATS, ODS and BoxNote backe… |
| CVE-2026-105753 | 6.5 | — | vllm-project | vllm | CWE-617 | vLLM: Mirrored multimodal IPC caches desync after a rejected request — a late… |
| CVE-2026-105754 | 6.5 | — | vllm-project | vllm | CWE-20 | vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied fea… |
| CVE-2026-105756 | 6.5 | — | vllm-project | vllm | CWE-20 | vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on … |
| CVE-2026-105757 | 6.5 | — | vllm-project | vllm | CWE-20 | vLLM: Structured-output request errors escape the request boundary and termin… |
| CVE-2026-71298 | 6.4 | — | Red Hat | Multicluster Engine for Kubernetes | CWE-89 | Maestro: sql identifier injection via properties.* search filter and orderby … |
| CVE-2026-77802 | 6.3 | — | Progress Software | Progress® Telerik® Fiddler® Classic | CWE-444 | HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic |
| CVE-2026-102777 | 6.3 | — | svenbluege.de | Event Gallery for Joomla | CWE-918 | Joomla Extension - svenbluege.de - Server-side request forgery in the Google … |
| CVE-2026-105768 | 6.3 | — | chainguard-dev | apko | CWE-197 | apko /etc/passwd and /etc/group UID/GID truncation writes package-supplied en… |
| CVE-2026-104905 | 6.1 | — | NeoRazorX | facturascripts | CWE-502 | FacturaScripts < 2026.7 PHP Object Injection via WidgetSelect |
| CVE-2026-93320 | 6.0 | — | moby | BuildKit | CWE-441 | BuildKit improperly handles special files in build snapshots |
| CVE-2026-93326 | 6.0 | — | moby | BuildKit | CWE-180 | Crafted Git build source can bypass certain policy validation |
| CVE-2026-105689 | 6.0 | — | penpot | penpot | CWE-918 | Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) i… |
| CVE-2026-93317 | 5.9 | — | moby | BuildKit | CWE-354 | Container blob cache can accept unverified content |
| CVE-2026-105690 | 5.9 | — | penpot | penpot | CWE-613 | Penpot: Server-side session not invalidated on logout; stale auth-token cooki… |
| CVE-2026-105695 | 5.9 | — | penpot | penpot | CWE-862 | Penpot: Missing authorization in chunked-upload assembly lets another authent… |
| CVE-2026-105750 | 5.9 | — | docling-project | docling | CWE-552 | Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode |
| CVE-2026-105759 | 5.9 | — | vllm-project | vllm | CWE-400 | vLLM: Unbounded Prometheus label cardinality from attacker-controlled HTTP me… |
| CVE-2026-93315 | 5.8 | — | moby | BuildKit | CWE-367 | BuildKit proxy CA cleanup can be disrupted by build steps |
| CVE-2026-59788 | 5.7 | — | Zabbix | Zabbix | CWE-79 | Stored XSS vulnerability in OAuth configuration form |
| CVE-2026-93319 | 5.7 | — | moby | BuildKit | CWE-567 | A malicious frontend can cause a daemon panic |
| CVE-2026-28667 | 5.5 | — | Android | CWE-119 | In multiple functions of rw_t5t.cc, there is a possible out-of-bounds read du… | |
| CVE-2026-58834 | 5.5 | — | Android | CWE-20 | In setPermissionGrantState of DevicePolicyManagerService.java, there is a pos… | |
| CVE-2026-78413 | 5.5 | — | Rapid7 | Velociraptor | CWE-276 | Velociraptor privilege escalation via SysmonLogForward client monitoring arti… |
| CVE-2026-104030 | 5.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: denial of service via out-of-bounds read during passkey parsing |
| CVE-2026-105290 | 5.5 | — | feelec-yishu | feelcrm-os | CWE-918 | feelec-yishu feelcrm-os getCurlData Endpoint GoogleController.class.php serve… |
| CVE-2026-105307 | 5.5 | — | n/a | Casdoor | CWE-287 | Casdoor API Endpoint authz_filter.go ApiFilter missing authentication |
| CVE-2026-105382 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-266 | onetwothreeneth HospitalManagementSystem Account Administration controller.ph… |
| CVE-2026-105383 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-74 | onetwothreeneth HospitalManagementSystem controller.php sql injection |
| CVE-2026-105384 | 5.5 | — | UNION | HospitalManagementSystem | CWE-74 | UNION HospitalManagementSystem patient_info.php sql injection |
| CVE-2026-105385 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-74 | onetwothreeneth HospitalManagementSystem transaction_details.php sql injection |
| CVE-2026-105386 | 5.5 | — | onetwothreeneth | HospitalManagementSystem | CWE-74 | onetwothreeneth HospitalManagementSystem print.php get sql injection |
| CVE-2026-105387 | 5.5 | — | girishsaraf | Online-Appointment-Booking-System | CWE-74 | girishsaraf Online-Appointment-Booking-System Patient Login cover.php mysqli_… |
| CVE-2026-105392 | 5.5 | — | Lybbn | Django-Vue-Lyadmin | CWE-320 | Lybbn Django-Vue-Lyadmin JWT Signing settings.py hard-coded key |
| CVE-2026-105447 | 5.5 | — | Red Hat | Red Hat Quay 3 | CWE-863 | Quay: quay: global read-only superuser can access build trigger write credent… |
| CVE-2026-105468 | 5.5 | — | girishsaraf | Online-Appointment-Booking-System | CWE-74 | girishsaraf Online-Appointment-Booking-System Login mlogin.php mysqli_query s… |
| CVE-2026-105469 | 5.5 | — | girishsaraf | Online-Appointment-Booking-System | CWE-74 | girishsaraf Online-Appointment-Booking-System AJAX Endpoint get_town.php sql … |
| CVE-2026-105470 | 5.5 | — | girishsaraf | Online-Appointment-Booking-System | CWE-74 | girishsaraf Online-Appointment-Booking-System Doctor Search Endpoint locateus… |
| CVE-2026-0482 | 5.4 | — | AMD | Alveo™ Accelerator Cards | CWE-787 | In AMD Versal™ Adaptive SoC devices, insufficient boundary checks in USB boot… |
| CVE-2026-71297 | 5.4 | — | Red Hat | Multicluster Engine for Kubernetes | CWE-306 | Maestro: maestro: grpc broker has no auth interceptor and client mtls is opti… |
| CVE-2026-102295 | 5.4 | — | Red Hat | Red Hat Quay 3 | CWE-79 | Quay: quay: dom-based cross-site scripting via oauth local callback format=js… |
| CVE-2026-104893 | 5.4 | — | makeplane | plane | CWE-770 | Plane: Improper validation allows arbitrary modification of API token rate li… |
| CVE-2026-104955 | 5.4 | — | makeplane | plane | CWE-269 | Plane: Project Member can escalate Project Guest to Member via PATCH /project… |
| CVE-2026-104961 | 5.4 | — | makeplane | plane | CWE-863 | Plane: WorkspaceOwnerPermission missing is_active check allows deactivated us… |
| CVE-2026-104965 | 5.4 | — | makeplane | plane | CWE-639 | Plane: Cross-Tenant Issue Relation Creation via IDOR |
| CVE-2026-104967 | 5.4 | — | makeplane | plane | CWE-639 | Plane: Cross-workspace association destruction and issue mutation/read via un… |
| CVE-2026-105692 | 5.4 | — | penpot | penpot | CWE-284 | Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Li… |
| CVE-2026-105694 | 5.4 | — | penpot | penpot | CWE-79 | Penpot: Stored XSS via Unsanitised SVG Uploads |
| CVE-2026-105698 | 5.4 | — | langflow-ai | langflow | CWE-639 | Langflow: Cross-user flow access and vertex execution via deprecated /api/v1/… |
| CVE-2026-59787 | 5.3 | — | Zabbix | Zabbix | CWE-143 | SNMP trap injection in zabbix_trap_receiver.pl |
| CVE-2026-94669 | 5.3 | — | WP ManageNinja LLC | Fluent Forms Pro Add On Pack | CWE-862 | WordPress Fluent Forms Pro Add On Pack plugin <= 6.2.13 - Broken Access Contr… |
| CVE-2026-97275 | 5.3 | — | VillaTheme | BuildKit – Product Builder for WooCommerce – Custom PC Builder | CWE-1284 | WordPress BuildKit – Product Builder for WooCommerce – Custom PC Builder plug… |
| CVE-2026-102426 | 5.3 | — | joomshaper.com | SP Page Builder (Pro) extension for Joomla | CWE-79 | Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filt… |
| CVE-2026-102778 | 5.3 | — | svenbluege.de | Event Gallery for Joomla | CWE-352 | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on … |
| CVE-2026-103684 | 5.3 | — | Arraytics | WP Event Solution | CWE-862 | WordPress WP Event Solution plugin <= 4.1.25 - Broken Access Control vulnerab… |
| CVE-2026-104956 | 5.3 | — | makeplane | plane | CWE-943 | Plane: Unauthenticated ORM field-name injection via `group_by`/`sub_group_by`… |
| CVE-2026-105073 | 5.3 | — | Arraytics | WP Event Solution | CWE-497 | WordPress WP Event Solution plugin <= 4.1.25 - Sensitive Data Exposure vulner… |
| CVE-2026-105396 | 5.3 | — | heymrun | heym | CWE-346 | Heym before v0.0.112 HITL Review Token Leak via Spoofable Origin Header |
| CVE-2026-105421 | 5.3 | — | Kit | Kit (formerly ConvertKit) for WooCommerce | CWE-862 | WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.2.0 - Broken … |
| CVE-2026-105686 | 5.3 | — | penpot | penpot | CWE-770 | Penpot: Repeated chunk index causes temporary-storage amplification |
| CVE-2026-105693 | 5.3 | — | penpot | penpot | CWE-862 | Penpot: Anonymous share-link token disclosure & page-scope bypass via get-vie… |
| CVE-2026-105758 | 5.3 | — | vllm-project | vllm | CWE-770 | vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled max_fram… |
| CVE-2026-105760 | 5.3 | — | vllm-project | vllm | CWE-400 | vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion |
| CVE-2026-59785 | 5.1 | — | Zabbix | Zabbix | CWE-204 | Hidden host credentials inferable via multiselect.get filtering |
| CVE-2026-101893 | 5.1 | — | Newell Brands | DYMO ID | CWE-611 | Newell Brands DYMO ID document parsing failing file type extension authentica… |
| CVE-2026-102776 | 5.1 | — | svenbluege.de | Event Gallery for Joomla | CWE-352 | Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks o… |
| CVE-2026-105397 | 5.1 | — | ThimPress | LearnPress | CWE-79 | LearnPress WordPress Plugin through 4.4.9.1 Stored XSS via Quiz Question Hint… |
| CVE-2026-78412 | 4.9 | — | Rapid7 | Velociraptor | CWE-639 | WatchEvent API streams another organization's live events |
| CVE-2026-105645 | 4.9 | — | TryGhost | Ghost | CWE-1333 | Ghost: Regular Expression Denial of Service in External Media Inliner |
| CVE-2026-105646 | 4.9 | — | TryGhost | Ghost | CWE-1333 | Ghost: Regular Expression Denial of Service in Content Import |
| CVE-2026-105676 | 4.9 | — | TryGhost | Ghost | CWE-22 | Ghost: Path Traversal via Locale Setting |
| CVE-2026-105687 | 4.9 | — | penpot | penpot | CWE-269 | Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-… |
| CVE-2026-105785 | 4.8 | — | laurent22 | joplin | CWE-620 | Joplin Server password reset accepts tokens issued for unrelated purposes |
| CVE-2026-105784 | 4.6 | — | laurent22 | joplin | CWE-79 | Joplin whiteboard card rendering allows CSS injection into application chrome |
| CVE-2026-39763 | 4.3 | — | Deepak Anand | WP Dummy Content Generator | CWE-862 | WordPress WP Dummy Content Generator plugin <= 4.0.0 - Broken Access Control … |
| CVE-2026-39783 | 4.3 | — | WP SYNTEX | Polylang | CWE-862 | WordPress Polylang plugin <= 3.8.7 - Sensitive Data Exposure vulnerability |
| CVE-2026-104894 | 4.3 | — | makeplane | plane | CWE-639 | Plane: Cross-Tenant Module Issue Linking via IDOR |
| CVE-2026-104963 | 4.3 | — | makeplane | plane | CWE-200 | Plane: Workspace cycle and module endpoints missing project-membership filter… |
| CVE-2026-105678 | 4.3 | — | TryGhost | Ghost | CWE-269 | Ghost: Editors Could Promote Staff Users to Their Own Role |
| CVE-2026-105684 | 4.3 | — | penpot | penpot | CWE-200 | Penpot: Share-link page-scope escape — comment RPCs leak comment content, aut… |
| CVE-2026-105747 | 4.3 | — | docling-project | docling | CWE-409 | Docling: METS-GBS archive member limit enforced after full member enumeration… |
| CVE-2026-105748 | 4.3 | — | docling-project | docling | CWE-73 | Docling: Crafted DoclingDocument JSON embeds local image files into converted… |
| CVE-2026-102576 | 4.2 | — | Red Hat | Red Hat Quay 3 | CWE-79 | Quay: quay: dom-based cross-site scripting via unvalidated redirect_url on si… |
| CVE-2026-105755 | 4.2 | — | vllm-project | vllm | CWE-639 | vLLM: Flash late-interaction scoring caches query embeddings under a caller-c… |
| CVE-2026-105647 | 4.0 | — | TryGhost | Ghost | CWE-367 | Ghost: Server-Side Request Forgery in Bookmark Fetching |
| CVE-2026-105648 | 4.0 | — | TryGhost | Ghost | CWE-184 | Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses |
| CVE-2026-105743 | 4.0 | — | docling-project | docling | CWE-367 | Docling: SSRF guard bypass in remote resource fetching (DNS rebinding / multi… |
| CVE-2026-105683 | 3.8 | — | TryGhost | Ghost | CWE-35 | Ghost: Path Traversal Vulnerability in Ghost ImageSize Service |
| CVE-2026-105742 | 3.7 | — | docling-project | docling | CWE-201 | Docling: Configured HTTP headers sent to every remote image host named by a d… |
| CVE-2026-77803 | 3.6 | — | Progress Software | Progress® Telerik® Fiddler® Classic | CWE-444 | Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic |
| CVE-2026-105712 | 3.6 | — | GnuPG | GnuPG | CWE-61 | gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an… |
| CVE-2026-58856 | 3.3 | — | Android | CWE-119 | In returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is … | |
| CVE-2026-104029 | 3.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: denial of service via out-of-bounds read in autofs responder |
| CVE-2026-105652 | 3.1 | — | TryGhost | Ghost | CWE-203 | Ghost: Password Hash Ordering Disclosure in Ghost Admin API |
| CVE-2026-105752 | 3.1 | — | vllm-project | vllm | CWE-200 | vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant… |
| CVE-2026-105682 | 2.7 | — | TryGhost | Ghost | CWE-918 | Ghost: Server-Side Request Forgery in Webhook Trigger |
| CVE-2026-105326 | 2.5 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-88 | Cups: cups: argument injection in mailto notifier via notify-recipient-uri |
| CVE-2026-59783 | 2.3 | — | Zabbix | Zabbix | CWE-787 | Server DoS via binary items |
| CVE-2026-103546 | 2.3 | — | MongoDB, Inc. | Mongodb Controllers for Kubernetes | CWE-918 | Improper validation of Ops Manager configuration in MongoDB Kubernetes Operator |
| CVE-2026-105766 | 2.3 | — | Chainguard | Chainguard Academy (edu) | CWE-319 | Chainguard Academy (edu) Nginx directory redirect downgrades HTTPS requests t… |
| CVE-2026-105746 | 2.2 | — | docling-project | docling | CWE-668 | Docling: KServe v2 OCR engine does not enforce enable_remote_services |
| CVE-2026-105288 | 2.1 | — | feelec-yishu | feelcrm-os | CWE-79 | feelec-yishu feelcrm-os Crm Endpoint functions.php index cross site scripting |
| CVE-2026-105291 | 2.1 | — | feelec-yishu | feelcrm-os | CWE-79 | feelec-yishu feelcrm-os Department Search Endpoint GroupController.class.php … |
| CVE-2026-105329 | 2.1 | — | n/a | TallCMS | CWE-74 | TallCMS PluginManager ThemeManager.php code injection |
| CVE-2026-105388 | 2.1 | — | feelec-yishu | feelcrm-os | CWE-74 | feelec-yishu feelcrm-os Member Endpoint MemberController.class.php index sql … |
| CVE-2026-105389 | 2.1 | — | feelec-yishu | feelcrm-os | CWE-284 | feelec-yishu feelcrm-os UploadTicketFile Endpoint UploadController.class.php … |
| CVE-2026-105438 | 2.1 | — | n/a | O2OA | CWE-918 | O2OA General url ActionUploadExcelWithUrl server-side request forgery |
| CVE-2026-105444 | 2.1 | — | dotnet | eShop | CWE-99 | dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection |
| CVE-2026-105767 | 2.1 | — | Chainguard | Chainguard Academy (edu) | CWE-78 | Chainguard Academy (edu) integrate-platform-docs composite action interpolate… |
| CVE-2026-105289 | 2.0 | — | feelec-yishu | feelcrm-os | CWE-79 | feelec-yishu feelcrm-os Create Customer Endpoint CrmDefineFormModel.class.php… |
| CVE-2026-105315 | 2.0 | — | n/a | django-haystack | CWE-94 | django-haystack more_like_this Template Tag elasticsearch_backend.py _to_pyth… |
| CVE-2026-28625 | await | — | Android | — | In multiple locations, there is a possible permission bypass due to a logic e… | |
| CVE-2026-28640 | await | — | Android | — | In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.jav… | |
| CVE-2026-28641 | await | — | Android | — | In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceControll… | |
| CVE-2026-28647 | await | — | Android | — | In updateState of DeviceAdminAppsPreferenceController.java, there is a possib… | |
| CVE-2026-28648 | await | — | Android | — | In Settings, there is a possible permission bypass due to a confused deputy. … | |
| CVE-2026-37719 | await | — | n/a | n/a | — | An issue in dormakaba evolo Service (all versions) allows a remote attacker t… |
| CVE-2026-49880 | await | — | Android | — | In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds … | |
| CVE-2026-78860 | await | — | n/a | n/a | — | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary cod… |
| CVE-2026-78861 | await | — | n/a | n/a | — | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary cod… |
| CVE-2026-78862 | await | — | n/a | n/a | — | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary cod… |
| CVE-2026-82988 | await | — | Viewsonic | vCast | — | CVE-2026-82988 |
| CVE-2026-82989 | await | — | Viewsonic | vCast | — | CVE-2026-82989 |
| CVE-2026-88391 | await | — | n/a | n/a | — | Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables… |
| CVE-2026-88392 | await | — | n/a | n/a | — | Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local… |
| CVE-2026-88393 | await | — | n/a | n/a | — | WookTeam v1.6.6 and before is vulnerable to RCE in the project task export in… |
Results continue: ranks 401–413.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-10-05 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.