boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Tuesday, October 6, 2026 · all times UTC← 2026-10-05 · archive

Security Box Score — October 6, 2026 — page 2

Edition of October 6, 2026, continued — page 2 of 3. Back to page 1 · page 3

Results (continued, ranked) — ranks 401–1000 of 1020
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1040315.50.6Red HatRed Hat Enterprise Linux 10CWE-772Sssd: sssd: denial of service via memory exhaustion in autofs responder
CVE-2026-1040325.50.6Red HatRed Hat Enterprise Linux 10CWE-408Sssd: sssd: denial of service via unprivileged autofs cache invalidation
CVE-2026-1040355.50.6Red HatRed Hat Enterprise Linux 10CWE-772Sssd: sssd: denial of service via memory exhaustion in kcm responder
CVE-2026-1040375.50.6Red HatRed Hat Enterprise Linux 10CWE-125Sssd: sssd: denial of service via packet length underflow in autofs responder
CVE-2026-1040415.50.6Red HatRed Hat Enterprise Linux 10CWE-770Sssd: sssd: denial of service via unbounded negative cache growth
CVE-2026-1040435.50.6Red HatRed Hat Enterprise Linux 10CWE-125Sssd: sssd: denial of service via undersized packet parsing in nss responder
CVE-2026-253027.10.4Qualcomm, Inc.SnapdragonCWE-347Improper Verification of Cryptographic Signature in Boot
CVE-2026-1040365.80.4Red HatRed Hat Enterprise Linux 10CWE-787Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin
CVE-2026-1040344.70.4Red HatRed Hat Enterprise Linux 10CWE-825Sssd: sssd: denial of service via use-after-free in kcm ticket renewal
CVE-2026-252636.60.3Qualcomm, Inc.SnapdragonCWE-787Out of Bounds write in Linux Camera
CVE-2026-6368810.0—DellDell Container Storage Modules (CSM)CWE-306Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a M…
CVE-2026-6369210.0—DellContainer Storage ModulesCWE-306Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missin…
CVE-2026-10585710.0—payloadcmspayloadCWE-94Payload: RCE in Payload Form Builder
CVE-2026-10610210.0—quasarframeworkquasarCWE-79Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering i…
CVE-2026-672699.9—DellContainer Storage Modules (CSM)CWE-269Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 conta…
CVE-2026-797989.9—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-B…
CVE-2026-544729.8—DellContainer Storage ModulesCWE-798Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use o…
CVE-2026-553309.8—GoogleAndroidCWE-416In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible u…
CVE-2026-614219.8—DellContainer Storage ModulesCWE-798Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use o…
CVE-2026-767429.8—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)CWE-269Authentication Bypass in the Web Management Interface of AOS-S
CVE-2026-767439.8—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Authentication Bypass Vulnerability in the Management Interface of AOS-S
CVE-2026-767449.8—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution…
CVE-2026-767509.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Deserialization of Untrusted Data allows Remote Code Executio…
CVE-2026-767519.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manag…
CVE-2026-767529.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Mana…
CVE-2026-767539.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Format String Vulnerability in HPE Networking ClearPass Polic…
CVE-2026-767549.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in…
CVE-2026-797969.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authentication Bypass Vulnerabilities in ClearPass Policy Manager
CVE-2026-798019.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Missing Integrity Verification allows Remote Code Execution i…
CVE-2026-798059.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access …
CVE-2026-1043349.8—IBMLangflow OSSCWE-94Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1058459.8—payloadcmspayloadCWE-89Payload: SQL Injection in SQLite and Postgres
CVE-2026-1058599.8—payloadcmspayloadCWE-639Payload: Unauthorized update to collection documents
CVE-2026-1064469.8—handlebars-langhandlebars.jsCWE-94Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.b…
CVE-2026-672739.6—DellContainer Storage ModulesCWE-1336Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Impro…
CVE-2026-767459.6—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote …
CVE-2026-863609.6—DellSystem UpdateCWE-22Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitatio…
CVE-2026-911409.6—Progress SoftwareAutonomous REST Connector GenAI AgentsCWE-78OS command injection in Progress Software Autonomous REST Connector GenAI Agents
CVE-2026-1023229.6—GoogleChromeCWE-863Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059…
CVE-2026-1061979.6—GoogleChromeCWE-416Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1062119.6—GoogleChromeCWE-416Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1062279.6—GoogleChromeCWE-416Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remo…
CVE-2026-1062349.6—GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1062399.6—GoogleChromeCWE-190Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.…
CVE-2026-1062419.6—GoogleChromeCWE-863Incorrect authorization in Search in Google Chrome on on Android prior to 155…
CVE-2026-1062819.6—GoogleChromeCWE-416Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remo…
CVE-2026-1062989.6—GoogleChromeCWE-416Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.…
CVE-2026-1063239.6—GoogleChromeCWE-862Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 1…
CVE-2026-1063299.6—GoogleChromeCWE-863Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39…
CVE-2026-1063589.6—GoogleChromeCWE-416Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1063729.6—GoogleChromeCWE-863Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed…
CVE-2026-1063759.6—GoogleChromeCWE-459Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1063829.6—GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1064019.6—GoogleChromeCWE-787Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1064149.6—GoogleChromeCWE-20Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0…
CVE-2026-1064179.6—GoogleChromeCWE-190Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1064199.6—GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39…
CVE-2026-1065019.6—backstagebackstageCWE-200Backstage: Sensitive information exposure in Scaffolder
CVE-2026-1021629.4—Arista NetworksWi-Fi Access PointsCWE-121Security Advisory 0193
CVE-2026-767469.3—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information…
CVE-2026-1011579.3—Arista NetworksCloudVision CUECWE-79Security Advisory 0192
CVE-2026-1011589.3—Arista NetworksCloudVision PortalCWE-79Security Advisory 0185
CVE-2026-1021599.3—Arista NetworksCloudVision CUECWE-306Security Advisory 0190
CVE-2026-1040709.3—SPIPSPIP Crayons PluginCWE-862SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE
CVE-2026-1058449.3—payloadcmspayloadCWE-1321Payload: Prototype pollution in Payload Import Export plugin
CVE-2026-1058519.3—payloadcmspayloadCWE-284Payload: Field access control bypass on auth collections
CVE-2026-1060379.3—kvcache-aiMooncakeCWE-306Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service
CVE-2026-825319.2—smarty-phpsmartyCWE-94Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inhe…
CVE-2026-1058639.2—payloadcmspayloadCWE-290Payload authentication token field handling issue
CVE-2026-1064459.2—handlebars-langhandlebars.jsCWE-184Handlebars: JavaScript Injection via Own Property Check Bypass
CVE-2026-767479.1—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosur…
CVE-2026-771789.1—n/an/aCWE-787Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bo…
CVE-2026-797949.1—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-bas…
CVE-2026-1057939.1—microsoftUFOCWE-78Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `p…
CVE-2026-1057949.1—microsoftmsquicCWE-295MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
CVE-2026-1058359.1—plankaplankaCWE-307PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint
CVE-2026-1021679.0—Arista NetworksWi-Fi Access PointsCWE-121Security Advisory 0197
CVE-2026-1064488.9—StableLibstablelibCWE-1321StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding
CVE-2026-767488.8—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Authenticated Privilege Escalation Vulnerability in the API of AOS-S
CVE-2026-797978.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Improper Access Control in HPE Networking ClearPass Android Client Application
CVE-2026-797998.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass …
CVE-2026-798008.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in …
CVE-2026-798028.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Command Injection Vulnerability in the ClearPass Policy Manager Client Software
CVE-2026-798038.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Command Injection Leading to Privilege Escalation in ClearPass …
CVE-2026-855238.8—Felisify Information Technologies Industry and Trade Inc.SambaBoxCWE-78OS Command Injection in Felisify Informatics' SambaBox
CVE-2026-976558.8—IBMLangflow OSSCWE-94Langflow OSS is affected by multiple vulnerabilities
CVE-2026-976768.8—IBMLangflow OSSCWE-94Langflow OSS is affected by multiple vulnerabilities
CVE-2026-976788.8—IBMLangflow OSSCWE-693Langflow OSS is affected by multiple vulnerabilities
CVE-2026-976798.8—IBMLangflow OSSCWE-94Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1012078.8—DellOpenManage IntegrationCWE-78Dell OpenManage Integration with Microsoft Windows Admin Center, versions pri…
CVE-2026-1024068.8—ElasticKibanaCWE-639Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-T…
CVE-2026-1043358.8—IBMLangflow OSSCWE-284Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1057888.8—microsoftUFOCWE-78Microsoft UFO: Authenticated Android shell command injection in Mobile MCP ty…
CVE-2026-1057968.8—microsoftkiotaCWE-94Kiota: Code injection through doc-comment delimiter reformation in Kiota Java…
CVE-2026-1057978.8—microsoftsimplechatCWE-78SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary…
CVE-2026-1058128.8—awsbedrock-agentcore-starter-toolkitCWE-94Code injection via unencoded configuration values during Python code generati…
CVE-2026-1058508.8—payloadcmspayloadCWE-837Payload: Order confirmation validation issue in Payload Ecommerce
CVE-2026-1060388.8—kvcache-aiMooncakeCWE-306Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remov…
CVE-2026-1060408.8—kvcache-aiMooncakeCWE-862Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplic…
CVE-2026-1061908.8—GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1061938.8—GoogleChromeCWE-416Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1062008.8—GoogleChromeCWE-416Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1062018.8—GoogleChromeCWE-362Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1062038.8—GoogleChromeCWE-459Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059…
CVE-2026-1062048.8—GoogleChromeCWE-416Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remot…
CVE-2026-1062078.8—GoogleChromeCWE-367Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1062128.8—GoogleChromeCWE-863Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-1062188.8—JetBrainsTeamCityCWE-184In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape lea…
CVE-2026-1062208.8—GoogleChromeCWE-200Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed…
CVE-2026-1062258.8—GoogleChromeCWE-862Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 all…
CVE-2026-1062358.8—GoogleChromeCWE-416Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1062408.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1062488.8—GoogleChromeCWE-416Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1062498.8—GoogleChromeCWE-863Incorrect authorization in Autofill in Google Chrome on on Android prior to 1…
CVE-2026-1062528.8—GoogleChromeCWE-697Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed…
CVE-2026-1062558.8—GoogleChromeCWE-362Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1062568.8—GoogleChromeCWE-200Information leak in Passwords in Google Chrome on on Android prior to 155.0.8…
CVE-2026-1062578.8—GoogleChromeCWE-416Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remo…
CVE-2026-1062688.8—GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1062698.8—GoogleChromeCWE-416Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remot…
CVE-2026-1062748.8—GoogleChromeCWE-706Incorrect reference resolution in Browser in Google Chrome on on Mac prior to…
CVE-2026-1062788.8—GoogleChromeCWE-416Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1062838.8—GoogleChromeCWE-416Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a…
CVE-2026-1062918.8—GoogleChromeCWE-416Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-1063088.8—GoogleChromeCWE-706Incorrect reference resolution in Autofill in Google Chrome on on Android pri…
CVE-2026-1063098.8—GoogleChromeCWE-863Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.…
CVE-2026-1063148.8—GoogleChromeCWE-863Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 …
CVE-2026-1063158.8—GoogleChromeCWE-416Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1063188.8—GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1063348.8—GoogleChromeCWE-200Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1063358.8—GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1063418.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1063428.8—GoogleChromeCWE-200Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1063468.8—GoogleChromeCWE-754Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39…
CVE-2026-1063478.8—GoogleChromeCWE-416Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1063498.8—GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1063508.8—GoogleChromeCWE-863Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-1063528.8—GoogleChromeCWE-863Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39…
CVE-2026-1063578.8—GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1063718.8—GoogleChromeCWE-863Incorrect authorization in Transactions Platform in Google Chrome on on Andro…
CVE-2026-1063738.8—GoogleChromeCWE-416Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39…
CVE-2026-1063748.8—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote…
CVE-2026-1063838.8—GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1063878.8—GoogleChromeCWE-862Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.805…
CVE-2026-1064118.8—GoogleChromeCWE-416Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1064218.8—GoogleChromeCWE-416Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remot…
CVE-2026-1064238.8—GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1064438.8—KozeaWeasyPrintCWE-20WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE
CVE-2026-968908.7—GitHubEnterprise ServerCWE-918Server-Side Request Forgery vulnerability was identified in GitHub Enterprise…
CVE-2026-1021618.7—Arista NetworksCloudVision CUECWE-290Security Advisory 0190
CVE-2026-1021638.7—Arista NetworksWi-Fi Access PointsCWE-787Security Advisory 0195
CVE-2026-1057988.7—microsoftsimplechatCWE-79SimpleChat: Stored XSS via group document filename in inline onclick handler
CVE-2026-1058548.7—payloadcmspayloadCWE-400Payload: ReDoS in Multipart Content-Type Validation
CVE-2026-1058628.7—payloadcmspayloadCWE-79Payload: Bypassed sanitization of user uploaded SVGs
CVE-2026-1059858.7—craftcmscmsCWE-1336Authenticated RCE via render-components Entry Type overrides
CVE-2026-1061048.7—quasarframeworkquasarCWE-1333Quasar Framework: Super-linear regex backtracking on User-Agent lets one requ…
CVE-2026-1064478.7—StableLibstablelibCWE-674StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, …
CVE-2026-1011548.6—Arista NetworksCloudVision PortalCWE-22Security Advisory 0189
CVE-2026-1011558.6—Arista NetworksCloudVision PortalCWE-22Security Advisory 0189
CVE-2026-1021608.6—Arista NetworksCloudVision CUECWE-78Security Advisory 0190
CVE-2026-1040698.6—danielbrendelhortusfox-webCWE-434HortusFox < 6.2 Remote Code Execution via Theme Import
CVE-2026-1058068.6—payloadcmspayloadCWE-862Payload: Improper access control for MCP API keys
CVE-2026-1058568.6—payloadcmspayloadCWE-89Payload: SQL injection in SQLite/Postgres
CVE-2026-1058688.6—payloadcmspayloadCWE-434Payload: Uploaded XML files could execute same-origin JavaScript
CVE-2026-1061868.6—GoogleChromeCWE-427Uncontrolled search path element in CredentialProvider in Google Chrome on on…
CVE-2026-1058378.5—sezerolibmikmodCWE-190libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow
CVE-2026-1058398.5—sezerolibmikmodCWE-190libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD
CVE-2026-1064398.5—hydra-ecosystemhydraCWE-470Hydra: Mutable instantiate policy sets allow target blocklist bypass
CVE-2026-1064598.5—backstagebackstageCWE-200Backstage: Improper input validation in Sentry scaffolder actions
CVE-2026-1064868.5—backstagebackstageCWE-22Backstage: Improper filesystem validation in Bitbucket pull-request scaffolde…
CVE-2026-1065008.5—backstagebackstageCWE-59Backstage: Improper task state validation in Scaffolder backend
CVE-2026-1065478.5—The HDF GroupHDF5CWE-122HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata
CVE-2026-1058018.4—openapi-generatorsopenapi-python-clientCWE-94openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code G…
CVE-2026-1061058.4—quasarframeworkquasarCWE-732Quasar Framework: Development TLS private keys are cached with overly permiss…
CVE-2026-1065128.4—MISPsachertortephpCWE-20MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Un…
CVE-2026-976808.3—IBMLangflow OSSCWE-284Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1061078.3—quasarframeworkquasarCWE-79Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constr…
CVE-2026-1061918.3—GoogleChromeCWE-862Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-1061948.3—GoogleChromeCWE-862Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.…
CVE-2026-1062288.3—GoogleChromeCWE-441Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-1062338.3—GoogleChromeCWE-416Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1062388.3—GoogleChromeCWE-362Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1062478.3—GoogleChromeCWE-122Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1062928.3—GoogleChromeCWE-122Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-1062938.3—GoogleChromeCWE-843Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1063778.3—GoogleChromeCWE-362Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-1063788.3—GoogleChromeCWE-250Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059…
CVE-2026-1063938.3—GoogleChromeCWE-416Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1064098.3—GoogleChromeCWE-706Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac p…
CVE-2026-1064128.3—GoogleChromeCWE-367Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allo…
CVE-2026-1064268.3—GoogleChromeCWE-362Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a rem…
CVE-2026-672708.2—DellContainer Storage Modules (CSM)CWE-295Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Im…
CVE-2026-863618.2—DellSystem UpdateCWE-732Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permissi…
CVE-2026-863628.2—DellSystem UpdateCWE-284Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Co…
CVE-2026-941148.2—Apache Software FoundationApache Commons BCELCWE-386Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time…
CVE-2026-976748.1—IBMLangflow OSSCWE-94Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1033608.1—IBMLangflow OSSCWE-22Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1058588.1—payloadcmspayloadCWE-94Payload: Remote Code Execution through first-register
CVE-2026-1058658.1—payloadcmspayloadCWE-22Payload: Incomplete validation during the upload file lifecycle
CVE-2026-1064888.1—backstagebackstageCWE-287Backstage: Improper authentication in the OIDC provider
CVE-2026-1065038.1—backstagebackstageCWE-178Backstage: Scaffolder action input authorization bypass
CVE-2026-651427.8—NVIDIAModel-OptimizerCWE-502NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause d…
CVE-2026-798067.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Local Privilege Escalation in ClearPass Policy Manager OnGuard …
CVE-2026-798077.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Local Missing Integrity Verification Vulnerability leads to Loc…
CVE-2026-798087.8—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Local Authenticated Buffer Overflow Vulnerability in the ClearPass Policy Man…
CVE-2026-1012587.8—Red HatRed Hat Enterprise Linux 10CWE-787Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write…
CVE-2026-1060627.8—Red HatRed Hat Enterprise Linux 10CWE-119Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface …
CVE-2026-1064407.8—hydra-ecosystemhydraCWE-470Hydra: Optuna custom_search_space can resolve and execute untrusted callables…
CVE-2026-1064417.8—hydra-ecosystemhydraCWE-94Hydra logging configuration permits unsafe callable resolution
CVE-2026-1064427.8—hydra-ecosystemhydraCWE-184Hydra instantiate target blacklist bypasses permit code execution
CVE-2026-435987.7—AMDAMD Instinct™ MI210CWE-822Improper input validation in the AMD ROCm Communication Collectives Library (…
CVE-2026-614117.7—DellContainer Storage ModulesCWE-532Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Inser…
CVE-2026-761057.7—DellContainer Storage ModulesCWE-330Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of…
CVE-2026-1010277.7—GiteaGitea—Gitea migration SSRF through ALLOWED_DOMAINS address check bypass
CVE-2026-1013317.7—IBMLangflow OSSCWE-522Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1021657.7—Arista NetworksWi-Fi Access PointsCWE-121Security Advisory 0198
CVE-2026-1058407.7—Uwe OhselrzszCWE-22lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()
CVE-2026-1058417.7—Uwe OhselrzszCWE-78lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode
CVE-2026-1058497.7—payloadcmspayloadCWE-201Payload: API key disclosure through ordinary document reads
CVE-2026-1064557.7—backstagebackstageCWE-918Backstage: Improper validation of MkDocs plugin configuration in TechDocs
CVE-2026-1064987.7—backstagebackstageCWE-863Backstage: Improper URL validation in catalog entity placeholder resolution
CVE-2026-1065057.7—backstagebackstageCWE-426Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend
CVE-2026-1065097.7—backstagebackstageCWE-94Backstage: Improper validation of MkDocs theme configuration in TechDocs
CVE-2026-636977.6—DellSystem UpdateCWE-295Dell System Update, versions prior to 2.3.0.0, contains an Improper Certifica…
CVE-2026-1011527.6—Arista NetworksCloudVision PortalCWE-601Security Advisory 0187
CVE-2026-1058557.6—payloadcmspayloadCWE-284Payload: Field-level password update restrictions were not enforced
CVE-2026-1064927.6—backstagebackstageCWE-269Backstage: Improper preservation of access restrictions during service creden…
CVE-2026-951407.5—n/an/aCWE-22kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability…
CVE-2026-1038317.5—TrueLayerTrueLayer Magento 2 PluginCWE-502Insecure deserialization in the TrueLayer Magento 2 plugin
CVE-2026-1048507.5—modelcontextprotocoltypescript-sdkCWE-345MCP TypeScript SDK: OAuth client could send credentials to an authorization s…
CVE-2026-1057917.5—microsoftUFOCWE-88Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` arg…
CVE-2026-1061107.5—SixLaborsImageSharpCWE-787ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer
CVE-2026-1061127.5—SixLaborsImageSharpCWE-787ImageSharp: ICC LUT16 output channel count can write beyond Vector4
CVE-2026-1061137.5—SixLaborsImageSharpCWE-787ImageSharp: HistogramEqualization uses an unvalidated luminance as an uncheck…
CVE-2026-1061157.5—SixLaborsImageSharpCWE-787ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer
CVE-2026-1061177.5—SixLaborsImageSharpCWE-787ImageSharp: CCITT fax decompression (T4/Modified Huffman): unbounded WriteBit…
CVE-2026-1061187.5—SixLaborsImageSharpCWE-787ImageSharp: Tiled fax TIFF: tile buffer sized by TileWidth but fax decompress…
CVE-2026-821627.4—DellCommand | Configure (DCC)CWE-175Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improp…
CVE-2026-1062797.4—GoogleChromeCWE-706Incorrect reference resolution in Passwords in Google Chrome on on iOS prior …
CVE-2026-711687.3—DellSystem UpdateCWE-22Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitatio…
CVE-2026-798097.3—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads…
CVE-2026-1064517.3—yawkatlz4-javaCWE-367yawkat LZ4 Java: Native library extraction to a shared temporary directory is…
CVE-2026-798107.2—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Remote Code Execution Vulnerabilities in HPE Networking ClearPa…
CVE-2026-798117.2—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated SQL Injection allows Remote Code Execution in ClearPass Policy …
CVE-2026-1011537.2—Arista NetworksCloudVision PortalCWE-22Security Advisory 0188
CVE-2026-1030077.2—ElasticElasticsearchCWE-863Incorrect Authorization in Elasticsearch Leading to Privilege Escalation
CVE-2026-1058617.2—payloadcmspayloadCWE-200Payload external upload trust validation issue
CVE-2026-262877.1—external-secretsexternal-secretsCWE-696External Secrets Operator: label enforcement bypass in webhook generator enab…
CVE-2026-704117.1—DellContainer Storage Modules (CSM)CWE-306Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Mi…
CVE-2026-835507.1—Red HatMulticluster Global HubCWE-489Postgres-exporter: net/http/pprof exposed on metrics listener
CVE-2026-1021557.1—Arista NetworksCloudVision CUECWE-611Security Advisory 0190
CVE-2026-1021587.1—Arista NetworksCloudVision CUECWE-74Security Advisory 0190
CVE-2026-1021687.1—Arista NetworksWi-Fi Access PointsCWE-191Security Advisory 0194
CVE-2026-1021697.1—Arista NetworksWi-Fi Access PointsCWE-476Security Advisory 0194
CVE-2026-1030097.1—ElasticElasticsearchCWE-639Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to …
CVE-2026-1049447.1—TP-Link Systems Inc.Tapo C500 v2.0CWE-823Unauthenticated TDP Function Pointer Dispatch Denial of Service in TP-Link Ta…
CVE-2026-1058117.1—awsqnabot-on-awsCWE-639Authorization bypass through a user-controlled key in the Amazon Q Business L…
CVE-2026-1058347.1—rundeckrundeckCWE-22Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source
CVE-2026-1058477.1—payloadcmspayloadCWE-200Payload: Polymorphic join queries could disclose hidden fields
CVE-2026-1058537.1—payloadcmspayloadCWE-200Payload: Token refresh and password reset responses may expose restricted use…
CVE-2026-1058607.1—payloadcmspayloadCWE-862Payload: Tenant authorization bypass in Multi-Tenant Plugin
CVE-2026-1058677.1—payloadcmspayloadCWE-639Payload: Client uploads could overwrite S3 objects
CVE-2026-1061007.1—payloadcmspayloadCWE-639Payload: Field-level write access bypass in Payload on MongoDB
CVE-2026-1061037.1—quasarframeworkquasarCWE-22Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Geni…
CVE-2026-1061067.1—quasarframeworkquasarCWE-79Quasar Framework: SSR/SSG dev error page discloses the full shell environment…
CVE-2026-569067.0—GoogleAndroidCWE-362In ep_free of eventpoll.c, there is a possible use-after-free due to a race c…
CVE-2026-848547.0—wibu-systems-agwibukeyCWE-787Out of Bound Write on WibuKey for Windows
CVE-2025-83526.9—ESET spol. s.r.oESET PROTECT On-PremCWE-770Denial-of-service vulnerability in ESET PROTECT On-Prem
CVE-2026-666666.9—AutomatticWordPressCWE-201WordPress Core <= 7.1.2 - Unauthenticated Sensitive Data Exposure of Comments…
CVE-2026-770506.9—djangoprojectDjangoCWE-789Potential denial-of-service vulnerability in get_supported_language_variant()
CVE-2026-844296.9—djangoprojectDjangoCWE-407Potential denial-of-service vulnerability in HTTP header parsing
CVE-2026-878906.9—djangoprojectDjangoCWE-918Potential request forgery via spatial lookup byte values
CVE-2026-1021566.9—Arista NetworksCloudVision CUECWE-74Security Advisory 0191
CVE-2026-1040736.9—netbox-communitynetboxCWE-79NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links
CVE-2026-1058056.9—payloadcmspayloadCWE-200Payload: Sort queries could expose protected field information
CVE-2026-1058526.9—payloadcmspayloadCWE-862Payload relationship-query authorization bypass
CVE-2026-1058666.9—payloadcmspayloadCWE-307Payload: Unauthenticated account-lockout denial of service
CVE-2026-1060396.9—kvcache-aiMooncakeCWE-862Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task…
CVE-2026-1060416.9—kvcache-aiMooncakeCWE-862Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSu…
CVE-2026-1065136.9—MISPMISPCWE-284MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via …
CVE-2026-190296.8—The HDF GroupHDF5CWE-125HDF5 scale-offset filter heap buffer over-read via crafted chunk
CVE-2026-569366.8—GoogleAndroidCWE-119In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bound…
CVE-2026-1040486.8—Red HatRed Hat Enterprise Linux 10CWE-1025Sssd: sssd: authorization bypass via cross-domain username collision in hbac …
CVE-2026-1049456.8—TP-Link Systems Inc.Tapo C500 v2.0CWE-121Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Lin…
CVE-2026-1054856.8—DevolutionsServerCWE-294Authentication bypass OAuth device authorization flow in Devolutions Server 2…
CVE-2026-1058386.8—sezerolibmikmodCWE-125libmikmod before 3.3.14 Heap Out-of-Bounds Read via IT Module Loader
CVE-2026-1064576.8—backstagebackstageCWE-287Backstage: Insufficient audience validation in the Cloudflare Access auth pro…
CVE-2026-1064606.8—backstagebackstageCWE-287Backstage: Explicit negative email verification can be ignored during shared …
CVE-2026-569526.7—GoogleAndroidCWE-862In platform_msg_handler_init of default_msg_handlers.c, there is a possible p…
CVE-2026-798136.7—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Local Privilege Escalation in ClearPass Client Software
CVE-2026-798146.7—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Local Arbitrary File Write Leading to Local Privilege Escalation in ClearPass…
CVE-2026-636896.5—DellContainer Storage ModulesCWE-532Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Inser…
CVE-2026-767416.5—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S
CVE-2026-767496.5—Hewlett Packard Enterprise (HPE)AOS-Switch (AOS-S)—Unauthenticated Sensitive Information Disclosure in AOS-S
CVE-2026-798156.5—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Command Injection Vulnerability in the ClearPass Policy Manager…
CVE-2026-1013296.5—IBMLangflow OSSCWE-284Langflow OSS is affected by multiple vulnerabilities
CVE-2026-1024046.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-1024096.5—ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-1024116.5—ElasticElasticsearchCWE-770Allocation of Resources Without Limits or Throttling in Elasticsearch Leading…
CVE-2026-1024126.5—ElasticKibanaCWE-863Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure
CVE-2026-1030056.5—ElasticElasticsearchCWE-789Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia…
CVE-2026-1030066.5—ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-1030086.5—ElasticElasticsearchCWE-674Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
CVE-2026-1057926.5—microsoftUFOCWE-833Microsoft UFO: Authenticated task-result request can deadlock UFO server sess…
CVE-2026-1062196.5—JetBrainsTeamCityCWE-73In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URL…
CVE-2026-1063126.5—GoogleChromeCWE-862Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1064586.5—backstagebackstageCWE-863Backstage: Inconsistent repository filtering in Bitbucket Server catalog even…
CVE-2026-1064896.5—backstagebackstageCWE-22Backstage: Improper authorization enforcement for TechDocs static content
CVE-2026-1064906.5—backstagebackstageCWE-22Backstage: Improper input validation in TechDocs static content requests
CVE-2026-1065046.5—backstagebackstageCWE-532Backstage: Sensitive information exposure in scaffolder task logs
CVE-2026-1065856.5—OpenBSDOpenSSHCWE-409In sshd and ssh in OpenSSH before 10.6, there is no check for whether the max…
CVE-2026-1057906.4—microsoftUFOCWE-918Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket …
CVE-2026-1058486.4—payloadcmspayloadCWE-749Payload: Insufficient Access Control in Stripe REST Proxy
CVE-2026-1064626.4—backstagebackstageCWE-441Backstage: Scaffolder credential handling may allow unintended GitHub authent…
CVE-2026-1064916.4—backstagebackstageCWE-20Backstage: Improper input validation in proxy-backend
CVE-2026-798166.3—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Unauthenticated DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Cle…
CVE-2026-1060266.3—H. Peter Anvintftp-hpaCWE-125tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule
CVE-2026-1060636.3—Red HatRed Hat Enterprise Linux 10CWE-119Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions
CVE-2026-1011566.2—Arista NetworksCloudVision CUECWE-79Security Advisory 0192
CVE-2026-1024136.2—ElasticElastic Agent and Elastic DefendCWE-248Uncaught Exception in Elastic Endpoint Leading to Denial of Service
CVE-2026-1037786.2—DellCommand | Configure (DCC)CWE-321Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of H…
CVE-2026-1040466.2—Red HatRed Hat Enterprise Linux 10CWE-770Sssd: sssd: denial of service via incomplete identity provider authentication…
CVE-2026-123806.1—Akıllı Ticaret Software Technologies Ltd. Co.E-Commerce PackCWE-79Reflected XSS in Akıllı Ticaret's E-Commerce Pack
CVE-2026-636916.1—DellContainer Storage ModulesCWE-862Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missin…
CVE-2026-798126.1—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authenticated Local Denial-of-Service Vulnerability in the OnGuard Agent of C…
CVE-2026-1058426.1—Uwe OhselrzszCWE-122lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname
CVE-2026-1058466.1—payloadcmspayloadCWE-601Payload: Untrusted redirect URL parameter exploit
CVE-2026-1021576.0—Arista NetworksCloudVision CUECWE-639Security Advisory 0190
CVE-2026-1036206.0—GitHubEnterprise ServerCWE-862Missing authorization in GitHub Enterprise Server allowed repository writers …
CVE-2026-1061196.0—langchain-ailangchainjsCWE-943LangChain: MongoDBChatMessageHistory query injection can allow cross-session …
CVE-2026-1061206.0—harttleliquidjsCWE-200LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/jo…
CVE-2026-1061226.0—rabbitmqrabbitmq-java-clientCWE-172RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC con…
CVE-2026-1061115.9—SixLaborsImageSharpCWE-226ImageSharp: EXR ZIP decoder can expose stale allocator data after a short inf…
CVE-2026-1061835.9—GoogleChromeCWE-862Missing authorization in Chromoting in Google Chrome on on Windows prior to 1…
CVE-2026-1062065.9—GoogleChromeCWE-20Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0…
CVE-2026-1062225.9—GoogleChromeCWE-863Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1063285.9—GoogleChromeCWE-863Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.…
CVE-2026-1058045.7—payloadcmspayloadCWE-916Payload: Password hashes use insufficient PBKDF2 iterations
CVE-2026-1060325.7—awsbedrock-agentcore-starter-toolkitCWE-918Server-side request forgery and local file read via unrestricted external Ope…
CVE-2026-1061235.7—rabbitmqrabbitmq-java-clientCWE-509RabbitMQ Java client: plaintext broker credentials leaked in exception messag…
CVE-2026-651225.5—NVIDIATensorRTCWE-125NVIDIA TensorRT contains a vulnerability where an attacker can cause an out o…
CVE-2026-704145.5—DellCommand | Configure (DCC)CWE-256Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plainte…
CVE-2026-760615.5——cri-oCWE-59Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass
CVE-2026-798175.5—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy …
CVE-2026-1059185.5—KusalkasilvaLearning-Management-SystemCWE-74Kusalkasilva Learning-Management-System Login Endpoint login.php mysql_error …
CVE-2026-1059195.5—KusalkasilvaLearning-Management-SystemCWE-74Kusalkasilva Learning-Management-System Administrator Login Endpoint login.ph…
CVE-2026-1059205.5—KusalkasilvaLearning-Management-SystemCWE-74Kusalkasilva Learning-Management-System Student Registration Endpoint student…
CVE-2026-636905.4—DellContainer Storage ModulesCWE-306Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missin…
CVE-2026-891825.4—GiteaGiteaCWE-863Gitea push-to-create bypass of FORCE_PRIVATE policy
CVE-2026-1024075.4—ElasticElasticsearchCWE-863Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream …
CVE-2026-1057895.4—microsoftUFOCWE-88Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool
CVE-2026-1060335.4—Red HatRed Hat Ansible Automation Platform 2CWE-79Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter
CVE-2026-1061795.4—GoogleChromeCWE-451UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.3…
CVE-2026-1061825.4—GoogleChromeCWE-451UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed…
CVE-2026-1062095.4—GoogleChromeCWE-451UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059…
CVE-2026-1062295.4—GoogleChromeCWE-451UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-1062325.4—GoogleChromeCWE-451UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1062365.4—GoogleChromeCWE-451UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 15…
CVE-2026-1062465.4—GoogleChromeCWE-863Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-1062515.4—GoogleChromeCWE-451UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.…
CVE-2026-1062645.4—GoogleChromeCWE-862Missing authorization in Web Authentication (Passkeys & Security Keys) in Goo…
CVE-2026-1062655.4—GoogleChromeCWE-451UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1062705.4—GoogleChromeCWE-863Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.805…
CVE-2026-1062725.4—GoogleChromeCWE-451UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 15…
CVE-2026-1062765.4—GoogleChromeCWE-451UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1062825.4—GoogleChromeCWE-451UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-1062855.4—GoogleChromeCWE-451UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.3…
CVE-2026-1063025.4—GoogleChromeCWE-451UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.805…
CVE-2026-1063055.4—GoogleChromeCWE-451UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.…
CVE-2026-1063115.4—GoogleChromeCWE-1021Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 all…
CVE-2026-1063165.4—GoogleChromeCWE-451UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.…
CVE-2026-1063175.4—GoogleChromeCWE-451UI misrepresentation in FullScreen in Google Chrome on on Android prior to 15…
CVE-2026-1063335.4—GoogleChromeCWE-863Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1063375.4—GoogleChromeCWE-451UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059…
CVE-2026-1063385.4—GoogleChromeCWE-451UI misrepresentation in PictureInPicture in Google Chrome on on Android prior…
CVE-2026-1063435.4—GoogleChromeCWE-754Improper state validation in Autofill AI in Google Chrome on on Android prior…
CVE-2026-1063565.4—GoogleChromeCWE-1021Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote …
CVE-2026-1063685.4—GoogleChromeCWE-451UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059…
CVE-2026-1063805.4—GoogleChromeCWE-451UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1064005.4—GoogleChromeCWE-1021Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.3…
CVE-2026-1064065.4—GoogleChromeCWE-862Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.805…
CVE-2026-1064165.4—GoogleChromeCWE-94Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1064205.4—GoogleChromeCWE-682Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.80…
CVE-2026-1064635.4—backstagebackstageCWE-863Backstage: Improper authorization in GitLab organizational user ingestion
CVE-2025-155915.3—OpenTextContent ManagementCWE-79Cross-Site Scripting (XSS) vulnerability identified in OpenText™ Content Mana…
CVE-2026-798185.3—Hewlett Packard Enterprise (HPE)ClearPass Policy Manager (CPPM)—Authentication Bypass in the API Interface Allows Unauthorized Information Di…
CVE-2026-829245.3—Pusula Communication, IT, and Internet Industry and Trade Co. Ltd.Expert MailCWE-799PII Enumeration via Missing Rate Limiting in Pusula Communication's Expert Mail
CVE-2026-879755.3—djangoprojectDjangoCWE-639Privilege abuse in model formsets with editable primary keys
CVE-2026-1011515.3—Arista NetworksCloudVision PortalCWE-601Security Advisory 0187
CVE-2026-1040475.3—Red HatRed Hat Enterprise Linux 10CWE-140Sssd: sssd: information disclosure via query injection in entra id lookups
CVE-2026-1052395.3—Apache Software FoundationApache log4netCWE-158Apache log4net: NUL character truncates EventLogAppender records
CVE-2026-1052405.3—Apache Software FoundationApache log4netCWE-158Apache log4net: NUL character truncates OutputDebugStringAppender records
CVE-2026-1052415.3—Apache Software FoundationApache log4netCWE-176Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch
CVE-2026-1052425.3—Apache Software FoundationApache log4netCWE-755Apache log4net: Request validation failure drops the event in the aspnet-requ…
CVE-2026-1052435.3—Apache Software FoundationApache log4netCWE-778Apache log4net: Oversize EventLogAppender record silently discarded
CVE-2026-1052445.3—Apache Software FoundationApache log4netCWE-116Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content
CVE-2026-1058365.3—WebkulQloAppsCWE-639QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms
CVE-2026-1058645.3—payloadcmspayloadCWE-863Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant
CVE-2026-1061145.3—SixLaborsImageSharpCWE-789ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dime…
CVE-2026-1061165.3—SixLaborsImageSharpCWE-835ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing …
CVE-2026-1061815.3—GoogleChromeCWE-706Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.80…
CVE-2026-1062145.3—GoogleChromeCWE-200Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.…
CVE-2026-1062305.3—GoogleChromeCWE-706Incorrect reference resolution in Offline in Google Chrome on on Android prio…
CVE-2026-1062435.3—GoogleChromeCWE-459Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1063035.3—GoogleChromeCWE-203Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39…
CVE-2026-1063515.3—GoogleChromeCWE-203Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 15…
CVE-2026-1063555.3—GoogleChromeCWE-862Missing authorization in Media in Google Chrome on on Windows prior to 155.0.…
CVE-2026-1063645.3—GoogleChromeCWE-863Incorrect authorization in Omnibox in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-1063885.3—GoogleChromeCWE-862Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39…
CVE-2026-1064505.3—yawkatlz4-javaCWE-770yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every fram…
CVE-2026-1064525.3—yawkatlz4-javaCWE-789yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed leng…
CVE-2026-1064535.3—yawkatlz4-javaCWE-789yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size fro…
CVE-2026-1065025.3—backstagebackstageCWE-532Backstage: Sensitive information may be exposed in Scaffolder task failure ev…
CVE-2026-1065065.3—backstagebackstageCWE-202Backstage: Improper input validation in scaffolder task list ordering
CVE-2026-1065075.3—backstagebackstageCWE-59Backstage: TechDocs arbitrary file read via mkdocs snippets
CVE-2026-1065085.3—backstagebackstageCWE-22Backstage: Potential file exposure through local TechDocs publisher
CVE-2026-344985.1—Johnson ControlsIllustra Standard - L4L ChinaCWE-20L4L
CVE-2026-1011495.1—Arista NetworksCloudVision PortalCWE-918Security Advisory 0186
CVE-2026-1011505.1—Arista NetworksCloudVision PortalCWE-918Security Advisory 0186
CVE-2026-1059505.1—getformworkformworkCWE-79getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site s…
CVE-2026-1062545.1—GoogleChromeCWE-200Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059…
CVE-2026-1063135.1—GoogleChromeCWE-863Incorrect authorization in Browser in Google Chrome on on Android prior to 15…
CVE-2026-951534.9—n/an/aCWE-200An issue in Bludit CMS 3.22.0 allows a remote attacker to obtain sensitive in…
CVE-2026-1061214.9—rabbitmqrabbitmq-java-clientCWE-835RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on trunc…
CVE-2026-1064994.9—backstagebackstageCWE-532Backstage: Secret-derived values may be exposed in scaffolder task logs
CVE-2026-1064024.8—GoogleChromeCWE-863Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39…
CVE-2026-1064564.8—backstagebackstageCWE-863Backstage: Inconsistent credential enforcement for overlapping proxy routes
CVE-2026-882524.7—Red HatRed Hat Enterprise Linux 10CWE-835Sssd: sssd: denial of service via responder connection retry loop during file…
CVE-2026-1040454.7—Red HatRed Hat Enterprise Linux 10CWE-772Sssd: sssd: denial of service via race condition in autofs responder
CVE-2026-1064444.7—handlebars-langhandlebars.jsCWE-116Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled T…
CVE-2026-1061924.6—GoogleChromeCWE-200Information leak in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 …
CVE-2026-1063404.6—GoogleChromeCWE-862Missing authorization in CredentialProvider in Google Chrome on on Windows pr…
CVE-2026-01984.4—GoogleAndroidCWE-862In is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a…
CVE-2026-553074.4—GoogleAndroidCWE-269In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information di…
CVE-2026-1064944.4—backstagebackstageCWE-22Backstage: Improper input validation in cloud storage URL readers
CVE-2026-964004.3—GiteaGiteaCWE-918Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS
CVE-2026-1024084.3—ElasticElasticsearchCWE-1333Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial …
CVE-2026-1024104.3—ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Information Disclosure
CVE-2026-1061844.3—GoogleChromeCWE-908Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1062134.3—GoogleChromeCWE-362Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1062174.3—GoogleChromeCWE-862Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 …
CVE-2026-1062454.3—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1062534.3—GoogleChromeCWE-863Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39…
CVE-2026-1062604.3—GoogleChromeCWE-863Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-1062774.3—GoogleChromeCWE-200Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed…
CVE-2026-1063214.3—GoogleChromeCWE-200Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a…
CVE-2026-1063254.3—GoogleChromeCWE-706Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.3…
CVE-2026-1063304.3—GoogleChromeCWE-200Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1063324.3—GoogleChromeCWE-190Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1063364.3—GoogleChromeCWE-203Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-1063544.3—GoogleChromeCWE-668Improper resource exposure in Extensions in Google Chrome prior to 155.0.8059…
CVE-2026-1063604.3—GoogleChromeCWE-200Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1063794.3—GoogleChromeCWE-908Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-1063904.3—GoogleChromeCWE-684Incorrect provision of specified functionality in SanitizerAPI in Google Chro…
CVE-2026-1063924.3—GoogleChromeCWE-200Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-1063944.3—GoogleChromeCWE-459Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-1063984.3—GoogleChromeCWE-863Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1064154.3—GoogleChromeCWE-200Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-1064544.3—twistedtwistedCWE-1333Twisted: IMAP wildcardToRegexp() ReDoS
CVE-2026-1064614.3—backstagebackstageCWE-863Backstage: Incorrect authorization in scaffolder task listing
CVE-2026-1064974.3—backstagebackstageCWE-178Backstage: Inconsistent catalog property permission evaluation
CVE-2026-1061874.2—GoogleChromeCWE-862Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 …
CVE-2026-1062264.2—GoogleChromeCWE-20Improper input validation in Compositing in Google Chrome prior to 155.0.8059…
CVE-2026-1062624.2—GoogleChromeCWE-459Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-1062954.2—GoogleChromeCWE-863Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.…
CVE-2026-1063204.2—GoogleChromeCWE-672Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-1063454.2—GoogleChromeCWE-672Use of released resource in Session in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-1063914.2—GoogleChromeCWE-863Incorrect authorization in WebShare in Google Chrome on on Android prior to 1…
CVE-2026-1064104.2—GoogleChromeCWE-862Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 …
CVE-2026-1064134.2—GoogleChromeCWE-367Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a r…
CVE-2026-1065524.2—OpenBSDOpenSSHCWE-23In sftp in OpenSSH before 10.6, a server can trigger directory traversal (cau…
CVE-2026-1061094.1—quasarframeworkquasarCWE-22Quasar Framework: App Vite build cleanup can recursively remove unsafe config…
CVE-2026-1058003.7—i18nexti18next-http-backendCWE-74i18next-http-backend incomplete URL validation permits SSRF
CVE-2026-1064493.7—yawkatlz4-javaCWE-674yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses onc…
CVE-2026-1065823.7—OpenBSDOpenSSHCWE-514In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used …
CVE-2026-1065873.6—OpenBSDOpenSSHCWE-843In sshd in OpenSSH before 10.6, the value "none" for a configuration option i…
CVE-2026-565963.5—HCL SoftwareHCL BigFix Service ManagementCWE-20HCL BigFix Service Management is affected by multiple security vulnerabilities.
CVE-2026-1064873.5—backstagebackstageCWE-441Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
CVE-2026-1057953.1—microsoftkiotaCWE-22Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
CVE-2026-1061013.1—quasarframeworkquasarCWE-843Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Int…
CVE-2026-1061803.1—GoogleChromeCWE-203Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-1062103.1—GoogleChromeCWE-203Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1062243.1—GoogleChromeCWE-862Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 …
CVE-2026-1063393.1—GoogleChromeCWE-672Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-1064963.1—backstagebackstageCWE-22Backstage: Inconsistent enforcement of allowed location types during catalog …
CVE-2026-1065883.1—OpenBSDOpenSSHCWE-653In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the s…
CVE-2026-1064933.0—backstagebackstageCWE-22Backstage: Cloud storage catalog locations may cross configured storage bound…
CVE-2026-1065892.9—OpenBSDOpenSSHCWE-272In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SC…
CVE-2026-1065832.5—OpenBSDOpenSSHCWE-99In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line…
CVE-2026-1065842.5—OpenBSDOpenSSHCWE-193In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expir…
CVE-2026-1065862.5—OpenBSDOpenSSHCWE-670In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was…
CVE-2026-1021642.3—Arista NetworksWi-Fi Access PointsCWE-125Security Advisory 0196
CVE-2026-1051112.3—Apache Software FoundationApache Commons BCELCWE-79Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling store…
CVE-2026-1057992.3—langchain-ailangchainjsCWE-943LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
CVE-2026-1065532.2—OpenBSDOpenSSHCWE-669In sshd in OpenSSH before 10.6, credentials can incorrectly persist after fai…
CVE-2026-1065552.2—OpenBSDOpenSSHCWE-669In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can…
CVE-2026-1059212.1—KusalkasilvaLearning-Management-SystemCWE-74Kusalkasilva Learning-Management-System search_class.php sql injection
CVE-2026-1059222.1—vllm-projectvLLMCWE-404vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of se…
CVE-2026-1059572.1—SourceCodesterPerformance Indicator SystemCWE-74SourceCodester Performance Indicator System view_product.php sql injection
CVE-2026-758181.8—GNUAspellCWE-122Heap Buffer Overflow in GNU Aspell's prezip utility
CVE-2026-758191.8—GNUAspellCWE-125Out-of-bounds Read in GNU Aspell
CVE-2026-758201.8—GNUAspellCWE-190Integer Truncation Leading to Heap Corruption in GNU Aspell
CVE-2025-45871await—n/an/a—LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injectio…
CVE-2025-71383await—n/an/a—Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed vi…
CVE-2025-71384await—n/an/a—Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi net…
CVE-2026-9226await—DevolutionsServerCWE-294Authentication bypass in the Azure AD external login flow in Devolutions Serv…
CVE-2026-70357await—GiteaGiteaCWE-918Gitea repository migration SSRF through DNS rebinding
CVE-2026-73278await—GiteaGiteaCWE-287Gitea WebAuthn bypass during OAuth and OIDC sign-in
CVE-2026-79960await—GiteaGiteaCWE-863Gitea deploy key pushes acting as the repository owner
CVE-2026-80048await—Red HatRed Hat Enterprise Linux 10CWE-770Sssd: sssd-kcm: local denial of service via excessive memory preallocation
CVE-2026-86684await—GiteaGiteaCWE-863Gitea push mirror local path check uses the repository owner
CVE-2026-89430await—GiteaGiteaCWE-367Gitea push mirror SSRF and forced writes to internal Git hosts
CVE-2026-94205await—GiteaGiteaCWE-441Gitea fork workflow approval bypass through maintainer-triggered events
CVE-2026-95106await—GiteaGitea—Gitea review and execution mismatch through duplicate tree entries
CVE-2026-95112await—GiteaGitea—Gitea issue reference parsing CPU exhaustion
CVE-2026-96399await—GiteaGiteaCWE-125Gitea denial of service through external issue tracker patterns
CVE-2026-96404await—GiteaGitea—Gitea installer authentication bypass for existing accounts
CVE-2026-96580await—GiteaGiteaCWE-400Gitea Actions memory exhaustion through large static matrices
CVE-2026-96589await—GiteaGiteaCWE-672Gitea private repository access retained after rejected transfer
CVE-2026-96594await—GiteaGiteaCWE-79Gitea repository media API stored XSS
CVE-2026-97208await—GiteaGiteaCWE-863Gitea push mirror API bypass of DISABLE_NEW_PUSH policy
CVE-2026-97626await—GiteaGiteaCWE-200Gitea profile feed disclosure bypassing user visibility
CVE-2026-101023await—GiteaGitea—Gitea OAuth2 refresh token grant accepts access tokens
CVE-2026-101029await—GiteaGiteaCWE-209Gitea migration and pull mirror SSRF through multi-answer DNS
CVE-2026-103059await—GiteaGitea—Gitea built-in SSH server authentication bypass through key case folding
CVE-2026-103504await—GiteaGiteaCWE-272Gitea API team demotion not applied to unit permissions
CVE-2026-103667await—GiteaGiteaCWE-79Gitea container registry stored XSS through blob media type
CVE-2026-103670await—GiteaGitea—Gitea trusted workflow cancellation by unapproved fork runs
CVE-2026-104626await—GiteaGiteaCWE-841Gitea fork workflow job revival through later approval
CVE-2026-104632await—GiteaGitea—Gitea fork workflow approval bypass through cancel and rerun
CVE-2026-104633await—GiteaGiteaCWE-400Gitea migration memory exhaustion from zero page size
CVE-2026-104636await—GiteaGiteaCWE-918Gitea SSRF through Git HTTP redirects in mirrors and fetches
CVE-2026-105267await—GiteaGiteaCWE-732Gitea tag delete route deletes releases without release permission
CVE-2026-105268await—GiteaGiteaCWE-639Gitea issue attachment API allows changing comment attachments
CVE-2026-105488await—DevolutionsServerCWE-862Missing authorization in the global vault in Devolutions Server 2026.3.7.0 an…
CVE-2026-106016await—MozillaFirefox—Mitigation bypass in the File Handling component
CVE-2026-106185await—GoogleChromeCWE-20Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-106188await—GoogleChromeCWE-441Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.…
CVE-2026-106189await—GoogleChromeCWE-94Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.3…
CVE-2026-106195await—GoogleChromeCWE-863Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155…
CVE-2026-106196await—GoogleChromeCWE-862Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0…
CVE-2026-106198await—GoogleChromeCWE-862Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-106199await—GoogleChromeCWE-863Incorrect authorization in Actor in Google Chrome on on Android prior to 155.…
CVE-2026-106202await—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0…
CVE-2026-106205await—GoogleChromeCWE-862Missing authorization in Passwords in Google Chrome on on Android prior to 15…
CVE-2026-106208await—GoogleChromeCWE-862Missing authorization in API in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-106215await—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0…
CVE-2026-106216await—GoogleChromeCWE-352Cross-site request forgery in ReadingList in Google Chrome on on Android prio…
CVE-2026-106221await—GoogleChromeCWE-441Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059…
CVE-2026-106223await—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8…
CVE-2026-106231await—GoogleChromeCWE-908Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059…
CVE-2026-106237await—GoogleChromeCWE-200Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-106242await—GoogleChromeCWE-200Information leak in Omnibox in Google Chrome on on Android prior to 155.0.805…
CVE-2026-106244await—GoogleChromeCWE-863Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.3…
CVE-2026-106250await—GoogleChromeCWE-862Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-106258await—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0…
CVE-2026-106259await—GoogleChromeCWE-863Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.…
CVE-2026-106261await—GoogleChromeCWE-908Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-106263await—GoogleChromeCWE-20Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-106266await—GoogleChromeCWE-441Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-106267await—GoogleChromeCWE-862Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-106271await—GoogleChromeCWE-862Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-106273await—GoogleChromeCWE-908Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-106275await—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8…
CVE-2026-106280await—GoogleChromeCWE-863Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.…
CVE-2026-106284await—GoogleChromeCWE-125Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.…
CVE-2026-106286await—GoogleChromeCWE-441Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a …
CVE-2026-106287await—GoogleChromeCWE-221Information loss in CORS in Google Chrome prior to 155.0.8059.39 allowed a re…
CVE-2026-106288await—GoogleChromeCWE-862Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allo…
CVE-2026-106289await—GoogleChromeCWE-862Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-106290await—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8…
CVE-2026-106294await—GoogleChromeCWE-459Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.80…
CVE-2026-106296await—GoogleChromeCWE-269Improper privilege management in UI in Google Chrome on on Mac prior to 155.0…
CVE-2026-106297await—GoogleChromeCWE-863Incorrect authorization in Scheduling in Google Chrome prior to 155.0.8059.39…
CVE-2026-106299await—GoogleChromeCWE-20Improper input validation in WebAudio in Google Chrome prior to 155.0.8059.39…
CVE-2026-106300await—GoogleChromeCWE-367Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowe…
CVE-2026-106301await—GoogleChromeCWE-441Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-106304await—GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a…
CVE-2026-106306await—GoogleChromeCWE-863Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-106307await—GoogleChromeCWE-863Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-106310await—GoogleChromeCWE-672Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.3…
CVE-2026-106322await—GoogleChromeCWE-601Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed …
CVE-2026-106324await—GoogleChromeCWE-863Incorrect authorization in WebAppInstalls in Google Chrome on on Android prio…
CVE-2026-106326await—GoogleChromeCWE-441Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 a…
CVE-2026-106327await—GoogleChromeCWE-863Incorrect authorization in Core in Google Chrome prior to 155.0.8059.39 allow…
CVE-2026-106331await—GoogleChromeCWE-20Improper input validation in Extensions in Google Chrome prior to 155.0.8059.…
CVE-2026-106344await—GoogleChromeCWE-862Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 …
CVE-2026-106348await—GoogleChromeCWE-200Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed…
CVE-2026-106353await—GoogleChromeCWE-20Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0…
CVE-2026-106359await—GoogleChromeCWE-441Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 15…
CVE-2026-106361await—GoogleChromeCWE-684Incorrect provision of specified functionality in Mobile in Google Chrome on …
CVE-2026-106362await—GoogleChromeCWE-862Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 all…
CVE-2026-106363await—GoogleChromeCWE-862Missing authorization in FullScreen in Google Chrome prior to 155.0.8059.39 a…
CVE-2026-106365await—GoogleChromeCWE-862Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-106366await—GoogleChromeCWE-459Incomplete cleanup in CustomTabs in Google Chrome on on Android prior to 155.…
CVE-2026-106367await—GoogleChromeCWE-862Missing authorization in Mobile in Google Chrome on on Android prior to 155.0…
CVE-2026-106369await—GoogleChromeCWE-862Missing authorization in Translate in Google Chrome prior to 155.0.8059.39 al…
CVE-2026-106370await—GoogleChromeCWE-908Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8…
CVE-2026-106376await—GoogleChromeCWE-908Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0…
CVE-2026-106381await—GoogleChromeCWE-863Incorrect authorization in Passwords in Google Chrome on on iOS prior to 155.…