| CVE-2026-11608 |
WP Customer Reviews <= 3.7.8 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter |
19.09.2026 |
6.1 |
| CVE-2026-11899 |
PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler |
19.09.2026 |
4.3 |
| CVE-2026-12402 |
OTP Login & Register Woocommerce <= 2.7.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'fb-config' Setting |
19.09.2026 |
4.4 |
| CVE-2026-13191 |
Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order_by' Parameter |
19.09.2026 |
6.5 |
| CVE-2026-13200 |
Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter |
19.09.2026 |
6.5 |
| CVE-2026-13770 |
AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler |
19.09.2026 |
6.4 |
| CVE-2026-15098 |
Real 3D Flipbook <= 5.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightboxtext' Shortcode Attribute |
19.09.2026 |
6.4 |
| CVE-2026-15463 |
SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Parameters |
19.09.2026 |
6.1 |
| CVE-2026-15664 |
Quill Forms | Conversational Multi Step Forms, Surveys & quizzes <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value |
19.09.2026 |
7.2 |
| CVE-2026-15946 |
Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function |
19.09.2026 |
4.3 |
| CVE-2026-15947 |
Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via 'metasync_post_types' Parameter |
19.09.2026 |
4.3 |
| CVE-2026-1242 |
BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation |
19.09.2026 |
4.3 |
| CVE-2026-1641 |
Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting |
19.09.2026 |
6.5 |
| CVE-2026-1984 |
Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action |
19.09.2026 |
5.3 |
| CVE-2026-2278 |
VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset |
19.09.2026 |
4.3 |
| CVE-2026-2422 |
WP Composer <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp_raw_shortcode' Shortcode |
19.09.2026 |
6.4 |
| CVE-2026-4327 |
The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter |
19.09.2026 |
8.8 |
| CVE-2026-4792 |
Bread <= 2.9.12 - Missing Authorization to Unauthenticated Information Exposure |
19.09.2026 |
5.3 |
| CVE-2026-5400 |
Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting via User Input |
19.09.2026 |
6.4 |
| CVE-2026-6295 |
WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter |
19.09.2026 |
4.9 |
| CVE-2026-75959 |
GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter |
19.09.2026 |
4.9 |
| CVE-2026-7527 |
WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' Parameter |
19.09.2026 |
4.7 |
| CVE-2026-85658 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) |
19.09.2026 |
8.1 |
| CVE-2026-87917 |
MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dynamic Content Tag |
19.09.2026 |
6.1 |
| CVE-2026-9232 |
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action |
19.09.2026 |
6.5 |
| CVE-2026-9615 |
Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions |
19.09.2026 |
4.3 |
| CVE-2026-9832 |
Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint |
19.09.2026 |
5.3 |
| CVE-2026-9855 |
Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter |
19.09.2026 |
6.5 |
| CVE-2025-15698 |
Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting |
19.09.2026 |
|
| CVE-2026-16557 |
Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins |
19.09.2026 |
|
| CVE-2026-19860 |
JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback |
19.09.2026 |
|
| CVE-2026-76554 |
WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import |
19.09.2026 |
|
| CVE-2026-76790 |
Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter |
19.09.2026 |
|
| CVE-2026-84750 |
Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Field |
19.09.2026 |
|
| CVE-2026-85574 |
Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains |
19.09.2026 |
|
| CVE-2026-85680 |
Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title |
19.09.2026 |
|
| CVE-2026-86591 |
Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route |
19.09.2026 |
|
| CVE-2026-86814 |
UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email |
19.09.2026 |
|
| CVE-2026-88824 |
Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings |
19.09.2026 |
|
| CVE-2026-88926 |
VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi |
19.09.2026 |
|
| CVE-2026-91847 |
Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR |
19.09.2026 |
|
| CVE-2026-92099 |
WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias Squatting |
19.09.2026 |
|
| CVE-2026-92403 |
Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution |
19.09.2026 |
|
| CVE-2026-92404 |
MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure |
19.09.2026 |
|
| CVE-2026-92420 |
Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR |
19.09.2026 |
|
| CVE-2026-92421 |
Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR |
19.09.2026 |
|
| CVE-2026-92425 |
Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR |
19.09.2026 |
|
| CVE-2026-92430 |
Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook |
19.09.2026 |
|
| CVE-2026-92435 |
Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API |
19.09.2026 |
|
| CVE-2026-93741 |
Totolink A3002MU formWlWds buffer overflow |
19.09.2026 |
|
| CVE-2026-12042 |
WP2Social Auto Publish <= 2.4.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter |
19.09.2026 |
4.4 |
| CVE-2026-13354 |
Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
19.09.2026 |
7.2 |
| CVE-2026-15660 |
SEO Booster <= 7.4.7 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() |
19.09.2026 |
4.3 |
| CVE-2026-15760 |
Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action |
19.09.2026 |
6.5 |
| CVE-2026-84434 |
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field |
19.09.2026 |
9.8 |
| CVE-2026-87909 |
WP Photo Album Plus <= 9.2.09.002 - Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection |
19.09.2026 |
7.5 |
| CVE-2026-88944 |
Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter |
19.09.2026 |
4.3 |
| CVE-2026-89081 |
Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters |
19.09.2026 |
6.1 |
| CVE-2026-89093 |
Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register |
19.09.2026 |
5.3 |
| CVE-2026-89274 |
WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content |
19.09.2026 |
9.1 |
| CVE-2026-89333 |
Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter |
19.09.2026 |
6.5 |
| CVE-2026-89334 |
Better Messages <= 2.15.33 - Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint |
19.09.2026 |
6.5 |
| CVE-2026-92229 |
Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter |
19.09.2026 |
9.1 |
| CVE-2026-92807 |
Save as PDF Plugin by PDFCrowd <= 4.6.1 - Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute |
19.09.2026 |
8.8 |
| CVE-2026-92967 |
Pochipp <= 1.20.2 - Reflected Cross-Site Scripting via 'keyword' Parameter |
19.09.2026 |
6.1 |
| CVE-2026-77820 |
WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute |
19.09.2026 |
6.4 |
| CVE-2026-77875 |
Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage |
18.09.2026 |
|
| CVE-2026-93921 |
SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint |
18.09.2026 |
|
| CVE-2026-93922 |
SiYuan through 3.8.4 Stored XSS via notebook names |
18.09.2026 |
|
| CVE-2026-93923 |
SiYuan through 3.8.4 Stored XSS via Heading Style Attribute |
18.09.2026 |
|
| CVE-2026-75885 |
Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint |
18.09.2026 |
|
| CVE-2026-93740 |
Totolink A3002MU formWlEncrypt buffer overflow |
18.09.2026 |
|
| CVE-2026-93739 |
Totolink A3002MU formWlAc buffer overflow |
18.09.2026 |
|
| CVE-2026-93738 |
Totolink A3002MU formSchedule buffer overflow |
18.09.2026 |
|
| CVE-2026-88097 |
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
18.09.2026 |
8.1 |
| CVE-2026-61670 |
microsandbox: Secret values exposed in world-readable process arguments |
18.09.2026 |
6.5 |
| CVE-2026-68928 |
Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode |
18.09.2026 |
8.6 |
| CVE-2026-85271 |
Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of CVE-2026-42857) |
18.09.2026 |
6.1 |
| CVE-2026-57223 |
Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation |
18.09.2026 |
7 |
| CVE-2026-71418 |
Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption |
18.09.2026 |
7.5 |
| CVE-2026-71855 |
Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state |
18.09.2026 |
5.9 |
| CVE-2026-85272 |
Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation |
18.09.2026 |
4.3 |
| CVE-2026-93894 |
|
18.09.2026 |
|
| CVE-2026-57225 |
Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading |
18.09.2026 |
3.3 |
| CVE-2026-57227 |
Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages |
18.09.2026 |
7.5 |
| CVE-2026-57228 |
Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder |
18.09.2026 |
8.2 |
| CVE-2026-57229 |
Suricata smtp/mime: incomplete state reset allows detection bypass |
18.09.2026 |
5.3 |
| CVE-2026-63446 |
Suricata app-layer: passed flows can retain transactions, causing resource exhaustion |
18.09.2026 |
7.5 |
| CVE-2026-63447 |
Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption |
18.09.2026 |
7.5 |
| CVE-2026-63448 |
Suricata smb: some SMB flows can cause resource exhaustion |
18.09.2026 |
5.9 |
| CVE-2026-63449 |
Suricata sip: large SIP message bodies can evade detection with frame keyword |
18.09.2026 |
3.7 |
| CVE-2026-63450 |
Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection |
18.09.2026 |
3.7 |
| CVE-2026-63451 |
Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load |
18.09.2026 |
3.3 |
| CVE-2026-63452 |
Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption |
18.09.2026 |
7.5 |
| CVE-2026-93562 |
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling |
18.09.2026 |
|
| CVE-2026-93574 |
Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in chunk-size parsing |
18.09.2026 |
|
| CVE-2026-57222 |
Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6 |
18.09.2026 |
5.3 |
| CVE-2026-57224 |
Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion |
18.09.2026 |
6.5 |
| CVE-2026-57226 |
Suricata swf: heap buffer overflow in SWF decompression depth handling |
18.09.2026 |
3.7 |
| CVE-2026-58264 |
FluidSynth: Heap-based buffer overrun |
18.09.2026 |
9.8 |
| CVE-2026-61714 |
FluidSynth: Heap Buffer Overflow in MIDI Player |
18.09.2026 |
7.8 |
| CVE-2026-61720 |
FluidSynth: SF2 DMOD Chunk Unsigned Underflow |
18.09.2026 |
6.2 |
| CVE-2026-61721 |
FluidSynth: Heap-based buffer overrun for DLS samples |
18.09.2026 |
8 |
| CVE-2026-61722 |
FluidSynth: DLS Articulation Chunk Integer Overflow |
18.09.2026 |
6.8 |
| CVE-2026-61723 |
FluidSynth: DLS ptbl Chunk Integer Overflow |
18.09.2026 |
6.8 |
| CVE-2026-76899 |
CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` |
18.09.2026 |
5.7 |
| CVE-2026-76902 |
CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}` |
18.09.2026 |
5 |
| CVE-2026-63646 |
CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users |
18.09.2026 |
|
| CVE-2026-63647 |
CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` |
18.09.2026 |
|
| CVE-2026-76900 |
CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime |
18.09.2026 |
6.8 |
| CVE-2026-76901 |
CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts |
18.09.2026 |
5.8 |
| CVE-2026-84086 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.2 |
| CVE-2026-84089 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.8 |
| CVE-2026-84105 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.7 |
| CVE-2026-84106 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.9 |
| CVE-2026-84108 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-84239 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.6 |
| CVE-2026-84241 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-92708 |
devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers |
18.09.2026 |
7.5 |
| CVE-2026-93868 |
Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
18.09.2026 |
|
| CVE-2026-93869 |
Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex |
18.09.2026 |
|
| CVE-2026-93870 |
Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler |
18.09.2026 |
|
| CVE-2026-93871 |
Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix |
18.09.2026 |
|
| CVE-2026-93872 |
Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter |
18.09.2026 |
|
| CVE-2026-93873 |
Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin |
18.09.2026 |
|
| CVE-2026-52745 |
CordysCRM: Customer Public Pool Sorting Field SQL Injection |
18.09.2026 |
5.3 |
| CVE-2026-61817 |
pg_partman privilege escalation via SQL injection in several functions via time decoder |
18.09.2026 |
8.5 |
| CVE-2026-61818 |
pg_partman SQL injection in undo partition time encoder |
18.09.2026 |
8.5 |
| CVE-2026-61819 |
pg_partman privilege escalation via SQL injection in when using pg_jobmon and encountering exception |
18.09.2026 |
8.5 |
| CVE-2026-61820 |
pg_partman privilege escalation via SQL injection when inheriting template properties |
18.09.2026 |
8.5 |
| CVE-2026-61821 |
pg_partman authorization bypass to move child tables between schemas during retention |
18.09.2026 |
8.5 |
| CVE-2026-61822 |
pg_partman disable maintenance for all partition sets |
18.09.2026 |
6.5 |
| CVE-2026-84073 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.1 |
| CVE-2026-84074 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.9 |
| CVE-2026-84075 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.9 |
| CVE-2026-84076 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.6 |
| CVE-2026-84077 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-84078 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.9 |
| CVE-2026-84081 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-84082 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-84083 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.8 |
| CVE-2026-84084 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.8 |
| CVE-2026-84085 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-61781 |
pg_partman has privilege escalation through SQL injection in create_partition_time() |
18.09.2026 |
9.9 |
| CVE-2026-77528 |
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation |
18.09.2026 |
5.3 |
| CVE-2026-84034 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.8 |
| CVE-2026-84036 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.4 |
| CVE-2026-84064 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.9 |
| CVE-2026-84070 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.9 |
| CVE-2026-84071 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.2 |
| CVE-2026-82890 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
5.9 |
| CVE-2026-82892 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.1 |
| CVE-2026-82893 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.8 |
| CVE-2026-82896 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.6 |
| CVE-2026-82967 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-84031 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9 |
| CVE-2026-93031 |
WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box <= 3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload via Media Import |
18.09.2026 |
8.8 |
| CVE-2026-81623 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
6.3 |
| CVE-2026-81626 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.6 |
| CVE-2026-81656 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.8 |
| CVE-2026-81657 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-81669 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.2 |
| CVE-2026-81933 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.8 |
| CVE-2026-81937 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
7.2 |
| CVE-2026-82340 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-82832 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.6 |
| CVE-2026-82885 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.8 |
| CVE-2026-82887 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
8.8 |
| CVE-2026-11727 |
IBM MQ for HPE NonStop is vulnerable to a denial of service issue |
18.09.2026 |
8.1 |
| CVE-2026-17262 |
IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ] |
18.09.2026 |
5.4 |
| CVE-2026-17619 |
The IBM Platform RTM is affected by an SQL injection vulnerability |
18.09.2026 |
8.6 |
| CVE-2026-18869 |
IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ] |
18.09.2026 |
6.4 |
| CVE-2026-75878 |
IBM Sterling File Gateway is Vulnerable to Authentication Bypass |
18.09.2026 |
9.1 |
| CVE-2026-80441 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-80442 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.9 |
| CVE-2026-91202 |
Cockpit-files: cockpit-files: arbitrary file ownership change via symlink following in privileged paste |
18.09.2026 |
|
| CVE-2026-91203 |
Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition |
18.09.2026 |
|
| CVE-2017-20284 |
Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet |
18.09.2026 |
|
| CVE-2026-11539 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
18.09.2026 |
5.3 |
| CVE-2026-11540 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
18.09.2026 |
5.3 |
| CVE-2026-11545 |
IBM WebSphere Application Server is affected by a privilege escalation |
18.09.2026 |
3.7 |
| CVE-2026-11548 |
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. |
18.09.2026 |
4.8 |
| CVE-2026-11549 |
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. |
18.09.2026 |
6.5 |
| CVE-2026-11710 |
IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability |
18.09.2026 |
6.5 |
| CVE-2026-11711 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
18.09.2026 |
6.5 |
| CVE-2026-11716 |
IBM MQ for HPE NonStop is vulnerable to a denial of service attack |
18.09.2026 |
7.5 |
| CVE-2026-11722 |
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. |
18.09.2026 |
4.8 |
| CVE-2026-11725 |
IBM MQ queue manager is vulnerable to privilege escalation |
18.09.2026 |
8.8 |
| CVE-2026-11726 |
IBM MQ for HPE NonStop is vulnerable to a denial of service issue |
18.09.2026 |
8.1 |
| CVE-2026-75895 |
Out of bounds read at smpp34_unpack() |
18.09.2026 |
|
| CVE-2026-91205 |
Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race |
18.09.2026 |
|
| CVE-2026-93838 |
SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx |
18.09.2026 |
|
| CVE-2026-93839 |
LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint |
18.09.2026 |
|
| CVE-2026-93840 |
vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids |
18.09.2026 |
|
| CVE-2026-93841 |
vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs |
18.09.2026 |
|
| CVE-2019-25776 |
Weaver E-cology SQL Injection via SyncUserInfo.jsp |
18.09.2026 |
|
| CVE-2021-48008 |
Chanjet CRM SQL Injection via get_usedspace.php |
18.09.2026 |
|
| CVE-2023-54399 |
Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree |
18.09.2026 |
|
| CVE-2026-11538 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
18.09.2026 |
3.7 |
| CVE-2026-93854 |
|
18.09.2026 |
|
| CVE-2026-75894 |
Reachable assertion at ranap_handle_co_dt() |
18.09.2026 |
|
| CVE-2026-93852 |
|
18.09.2026 |
|
| CVE-2026-75892 |
Out of bounds write in PDP ctx GSN-Address decode |
18.09.2026 |
|
| CVE-2026-75893 |
Heap based buffer overflow at ipaccess_proxy_read_msg() |
18.09.2026 |
|
| CVE-2026-93650 |
Saleor throttling.py get_client_ip excessive authentication |
18.09.2026 |
|
| CVE-2026-59163 |
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass |
18.09.2026 |
9.1 |
| CVE-2026-92745 |
Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments |
18.09.2026 |
|
| CVE-2026-92747 |
Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list |
18.09.2026 |
|
| CVE-2026-92768 |
Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments |
18.09.2026 |
|
| CVE-2026-93432 |
Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#eval} section in quarkus |
18.09.2026 |
|
| CVE-2026-81180 |
SysReptor: Authenticated RCE by insecure image processing |
18.09.2026 |
8.8 |
| CVE-2026-81181 |
SysReptor: Session Fixation in Password-Protected Shared Notes |
18.09.2026 |
3.7 |
| CVE-2026-81182 |
SysReptor: Unauthorized file disclosure by broken access control in writable shared notes |
18.09.2026 |
4.2 |
| CVE-2026-93748 |
http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale |
18.09.2026 |
|
| CVE-2026-93749 |
source-map-js through 1.2.1 Event Loop Denial of Service |
18.09.2026 |
|
| CVE-2026-93750 |
http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard |
18.09.2026 |
|
| CVE-2026-93751 |
uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars |
18.09.2026 |
|
| CVE-2026-93752 |
CSSOM through 0.5.0 Denial of Service via length Property |
18.09.2026 |
|
| CVE-2026-93753 |
deepmerge through 4.3.1 Prototype Poisoning via mergeObject |
18.09.2026 |
|
| CVE-2026-71537 |
Paymenter: Credit-refund double-spend race condition in service downgrade (doUpgrade) |
18.09.2026 |
6.5 |
| CVE-2026-81178 |
SysReptor: Anonymous note-share link discloses project member identities and non-shared note activity |
18.09.2026 |
3.5 |
| CVE-2026-81179 |
SysReptor: Host header injection might allow account takeover |
18.09.2026 |
8.1 |
| CVE-2026-85058 |
Moquette: Missing Authorization in io.moquette:moquette-broker |
18.09.2026 |
7.5 |
| CVE-2026-32641 |
Parseable: Unauthenticated Denial of Service via panic in Kinesis header parsing middleware |
18.09.2026 |
7.5 |
| CVE-2026-63199 |
Perses: Missing authorization in datasource proxy allows cross-scope secret disclosure |
18.09.2026 |
|
| CVE-2026-63445 |
Perses: Unvalidated project parameter enables filesystem path traversal |
18.09.2026 |
|
| CVE-2026-63458 |
Perses project query parameter authorization bypass exposes cross-project resources |
18.09.2026 |
|
| CVE-2026-69184 |
c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains |
18.09.2026 |
7.5 |
| CVE-2026-93759 |
Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist |
18.09.2026 |
|
| CVE-2026-61550 |
Icinga 2: Improper access control for JSON-RPC update certificate messages |
18.09.2026 |
9.8 |
| CVE-2026-61551 |
Icinga 2: Stack overflow via deeply nested JSON objects |
18.09.2026 |
8.6 |
| CVE-2026-61552 |
Icinga 2 DSL Injection via Unescaped Import Template Name |
18.09.2026 |
7.2 |
| CVE-2026-69186 |
c-ares: Memory-amplification denial of service via unvalidated DNS header record counts |
18.09.2026 |
5.3 |
| CVE-2026-91127 |
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer |
18.09.2026 |
8.2 |
| CVE-2026-93760 |
NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard |
18.09.2026 |
|
| CVE-2026-93761 |
Denial of service via unbounded regex matching in Mongoid's in-memory query matcher |
18.09.2026 |
|
| CVE-2025-66455 |
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py |
18.09.2026 |
9.8 |
| CVE-2026-33625 |
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading |
18.09.2026 |
8.8 |
| CVE-2026-62278 |
LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to Write Files Outside Data Directory |
18.09.2026 |
8.1 |
| CVE-2026-62279 |
LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User's Vehicle Without Ownership Check |
18.09.2026 |
7.1 |
| CVE-2026-64847 |
AnyIO process-pool workers can block indefinitely on undrained stderr |
18.09.2026 |
|
| CVE-2026-77385 |
Kyoo: Transcoder serves uncataloged files from the media directory |
18.09.2026 |
4.3 |
| CVE-2026-77386 |
Kyoo: OIDC login token can be redirected to an attacker-controlled URL |
18.09.2026 |
6.5 |
| CVE-2026-77396 |
PJSIP: Heap buffer overflow in the AVI parser |
18.09.2026 |
|
| CVE-2026-84975 |
PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends) |
18.09.2026 |
7.4 |
| CVE-2026-84992 |
md-editor-v3: XSS via fenced-code language rendering bypass |
18.09.2026 |
6.1 |
| CVE-2026-92701 |
Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path |
18.09.2026 |
9.1 |
| CVE-2026-92702 |
Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path |
18.09.2026 |
9.1 |
| CVE-2026-93762 |
Data deletion and attribute disclosure via field-name method injection in in-memory queries |
18.09.2026 |
|
| CVE-2026-93763 |
Silent plaintext persistence via unresolved callable database name in encryption schema map |
18.09.2026 |
|
| CVE-2026-93764 |
Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation |
18.09.2026 |
|
| CVE-2026-63349 |
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups |
18.09.2026 |
|
| CVE-2026-77616 |
Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token |
18.09.2026 |
6.1 |
| CVE-2026-93758 |
Cross-principal document update, theft, and deletion via unvalidated id in nested attributes |
18.09.2026 |
|
| CVE-2026-93765 |
Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation |
18.09.2026 |
|
| CVE-2026-55556 |
Rsyslog: Heap buffer overflow in imhttp plugin Basic Authentication handling |
18.09.2026 |
|
| CVE-2026-61548 |
Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data |
18.09.2026 |
8.1 |
| CVE-2026-61833 |
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion |
18.09.2026 |
8.1 |
| CVE-2026-63406 |
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets |
18.09.2026 |
5.9 |
| CVE-2026-77607 |
Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS |
18.09.2026 |
6.1 |
| CVE-2026-77609 |
Semantic MediaWiki has an open redirect in Special:URIResolver |
18.09.2026 |
6.1 |
| CVE-2026-77610 |
Semantic MediaWiki has a query debug output XSS (`DebugFormatter`) |
18.09.2026 |
6.1 |
| CVE-2026-46655 |
virtio-win: Integer overflow causing a heap overflow in Viosock driver |
18.09.2026 |
7.8 |
| CVE-2026-63405 |
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body |
18.09.2026 |
5.9 |
| CVE-2026-77239 |
WACRM: Service-role routes missing a role check |
18.09.2026 |
8.1 |
| CVE-2026-93559 |
Forget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authentication |
18.09.2026 |
|
| CVE-2026-77240 |
WACRM: Database-layer authorization bypasses |
18.09.2026 |
9.9 |
| CVE-2026-77301 |
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) |
18.09.2026 |
7.5 |
| CVE-2026-77339 |
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools |
18.09.2026 |
|
| CVE-2026-77606 |
Semantic MediaWiki has reflected XSS in Special:Ask plain table headers |
18.09.2026 |
6.1 |
| CVE-2026-77608 |
Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters) |
18.09.2026 |
6.1 |
| CVE-2026-91142 |
Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds |
18.09.2026 |
|
| CVE-2026-91147 |
Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash |
18.09.2026 |
|
| CVE-2026-91149 |
Cockpit: cockpit: denial of service via unbounded connection thread spawning |
18.09.2026 |
|
| CVE-2026-93579 |
Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough) |
18.09.2026 |
|
| CVE-2026-58197 |
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement |
18.09.2026 |
8.8 |
| CVE-2026-61672 |
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement |
18.09.2026 |
7.1 |
| CVE-2026-61795 |
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation |
18.09.2026 |
6.8 |
| CVE-2026-93534 |
spatie Scotty Self Update SelfUpdater.php update code download |
18.09.2026 |
|
| CVE-2026-44639 |
NanoMQ: O(N²) Denial of Service in MQTT v5 Property Parsing |
18.09.2026 |
3.7 |
| CVE-2026-61633 |
NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS |
18.09.2026 |
2 |
| CVE-2026-61794 |
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic |
18.09.2026 |
6.8 |
| CVE-2026-62943 |
btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh |
18.09.2026 |
|
| CVE-2026-73863 |
NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRIBE Parsing |
18.09.2026 |
|
| CVE-2026-81321 |
CareCam CM2507 Cleartext Storage of Sensitive Information |
18.09.2026 |
9.8 |
| CVE-2026-81505 |
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials |
18.09.2026 |
|
| CVE-2026-85478 |
CareCam CM2507 Missing Authentication for Critical Function |
18.09.2026 |
3.5 |
| CVE-2026-85497 |
CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
18.09.2026 |
9.8 |
| CVE-2026-93338 |
Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community String |
18.09.2026 |
|
| CVE-2026-93533 |
spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection |
18.09.2026 |
|
| CVE-2025-61682 |
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes |
18.09.2026 |
8.6 |
| CVE-2026-10841 |
Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. |
18.09.2026 |
4.2 |
| CVE-2026-10853 |
IBM MQ queue manager is vulnerable to remote code execution |
19.09.2026 |
7.5 |
| CVE-2026-10858 |
IBM MQ for HPE NonStop is vulnerable to a denial of service attack |
19.09.2026 |
9.9 |
| CVE-2026-11375 |
IBM MQ queue manager is vulnerable to remote code execution |
19.09.2026 |
8.8 |
| CVE-2026-11378 |
IBM MQ queue manager is vulnerable to remote code execution |
19.09.2026 |
8.8 |
| CVE-2026-11381 |
IBM MQ for HPE NonStop is vulnerable to a denial of service issue |
19.09.2026 |
8.8 |
| CVE-2026-11537 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
18.09.2026 |
4.3 |
| CVE-2026-54147 |
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI |
18.09.2026 |
6.5 |
| CVE-2026-54148 |
http4k: `DigestAuthProvider.verify` did not bind to request URI |
18.09.2026 |
8.1 |
| CVE-2026-61682 |
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace |
18.09.2026 |
9.9 |
| CVE-2026-68914 |
Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data |
18.09.2026 |
|
| CVE-2026-77568 |
Mojolicious: CSRF tokens are vulnerable to BREACH attacks |
18.09.2026 |
4.2 |
| CVE-2026-81305 |
CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere |
18.09.2026 |
6.8 |
| CVE-2026-84398 |
CareCam CM2507 Empty Password in Configuration File |
18.09.2026 |
7.5 |
| CVE-2026-84400 |
CareCam CM2507 Missing Authentication for Critical Function |
18.09.2026 |
3.1 |
| CVE-2026-84447 |
libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS |
18.09.2026 |
7.5 |
| CVE-2026-84449 |
libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV |
18.09.2026 |
3.7 |
| CVE-2026-84450 |
libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289) |
18.09.2026 |
4.3 |
| CVE-2026-84451 |
libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read |
18.09.2026 |
6.5 |
| CVE-2026-88259 |
CareCam CM2507 Missing Authentication for Critical Function |
18.09.2026 |
7.5 |
| CVE-2026-93736 |
Mealie before 3.21.0 Information Disclosure via Ratings Endpoint |
18.09.2026 |
|
| CVE-2026-93737 |
Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet |
18.09.2026 |
|
| CVE-2026-10575 |
IBM MQ queue manager is vulnerable to remote code execution |
19.09.2026 |
8.8 |
| CVE-2026-10744 |
IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation |
19.09.2026 |
7.5 |
| CVE-2026-10747 |
IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing |
19.09.2026 |
10 |
| CVE-2026-10751 |
IBM MQ Java messaging is vulnerable to remote code execution |
19.09.2026 |
7.5 |
| CVE-2026-84383 |
libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items |
18.09.2026 |
9.8 |
| CVE-2026-84384 |
libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS |
18.09.2026 |
7.5 |
| CVE-2026-84444 |
libheif uncompressed tiled image encoding allows out-of-bounds write |
18.09.2026 |
7.4 |
| CVE-2026-84446 |
libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames |
18.09.2026 |
7.5 |
| CVE-2026-84448 |
libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image) |
18.09.2026 |
4 |
| CVE-2026-10030 |
IBM MQ Console is vulnerable to privilege escalation |
18.09.2026 |
7.1 |
| CVE-2026-1025 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
18.09.2026 |
6.1 |
| CVE-2026-1029 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
18.09.2026 |
5.4 |
| CVE-2026-1030 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
18.09.2026 |
4.3 |
| CVE-2026-1031 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
18.09.2026 |
6.1 |
| CVE-2026-1037 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
18.09.2026 |
6.1 |
| CVE-2026-63419 |
OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer |
18.09.2026 |
7.8 |
| CVE-2026-63638 |
OpenImageIO: Cineon invalid bit depth heap out-of-bounds write |
18.09.2026 |
8.3 |
| CVE-2026-65969 |
OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV |
18.09.2026 |
5.5 |
| CVE-2026-67549 |
OpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds write |
18.09.2026 |
7.6 |
| CVE-2026-77960 |
Use of Hard-coded Credentials in Bransys ELD |
18.09.2026 |
5.3 |
| CVE-2026-86689 |
Cleartext Transmission of Sensitive Information in Bransys ELD |
18.09.2026 |
5.9 |
| CVE-2025-36045 |
TS4300 Tape Library addresses security vulnerability |
18.09.2026 |
4.3 |
| CVE-2025-36076 |
IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities |
18.09.2026 |
4.3 |
| CVE-2025-36147 |
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting. |
18.09.2026 |
6.1 |
| CVE-2025-36178 |
Multiple vulnerabilities in IBM Controller |
18.09.2026 |
5.4 |
| CVE-2025-36421 |
Multiple vulnerabilities in IBM Controller |
18.09.2026 |
5.9 |
| CVE-2026-10027 |
IBM MQ queue manager is vulnerable to unauthenticated remote code execution |
19.09.2026 |
8.1 |
| CVE-2026-65970 |
OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_native_scanlines` |
18.09.2026 |
5.3 |
| CVE-2026-86520 |
Use of Hard-coded Credentials in Bransys ELD |
18.09.2026 |
7.5 |
| CVE-2026-93532 |
gedelumbung HospitalManagement Password Change password.php simpan improper authentication |
18.09.2026 |
|
| CVE-2025-15399 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
19.09.2026 |
10 |
| CVE-2025-33141 |
IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. |
18.09.2026 |
6.5 |
| CVE-2025-33147 |
IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities |
18.09.2026 |
5.9 |
| CVE-2026-59156 |
OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow |
18.09.2026 |
6.5 |
| CVE-2026-59181 |
OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElements |
18.09.2026 |
6.1 |
| CVE-2026-59956 |
OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is set |
18.09.2026 |
6.1 |
| CVE-2026-63420 |
OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row` |
18.09.2026 |
5.5 |
| CVE-2026-63422 |
OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write |
18.09.2026 |
7.8 |
| CVE-2026-63635 |
OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocation DoS |
18.09.2026 |
5.5 |
| CVE-2025-14753 |
IBM Cloud Pak for Data is vulnerable to path traversal |
18.09.2026 |
7.5 |
| CVE-2025-14754 |
IBM Cloud Pak for Data is vulnerable to OS command injection |
18.09.2026 |
8.8 |
| CVE-2026-75031 |
|
18.09.2026 |
|
| CVE-2026-75883 |
PPPD buffer overflow in PEAP response code |
18.09.2026 |
6.8 |
| CVE-2026-81946 |
PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm |
18.09.2026 |
|
| CVE-2025-53837 |
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue |
18.09.2026 |
9.9 |
| CVE-2026-60115 |
|
18.09.2026 |
|
| CVE-2026-7006 |
Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism |
18.09.2026 |
|
| CVE-2026-81942 |
PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server |
18.09.2026 |
|
| CVE-2026-81943 |
PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCE |
18.09.2026 |
|
| CVE-2026-81944 |
PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server |
18.09.2026 |
|
| CVE-2026-81945 |
PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server |
18.09.2026 |
|
| CVE-2026-93531 |
gedelumbung HospitalManagement cross-site request forgery |
18.09.2026 |
|
| CVE-2026-93687 |
braces through 3.0.3 Stack Overflow via Deeply Nested Patterns |
18.09.2026 |
|
| CVE-2026-93688 |
SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room |
18.09.2026 |
|
| CVE-2026-93689 |
WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O |
18.09.2026 |
|
| CVE-2026-93690 |
uri-js through 4.4.1 Denial of Service via removeDotSegments |
18.09.2026 |
|
| CVE-2026-93506 |
SveltyCMS File Upload Endpoint upload-media server-side request forgery |
18.09.2026 |
|
| CVE-2026-93573 |
Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation and enable request smuggling |
18.09.2026 |
|
| CVE-2026-93685 |
Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering) |
18.09.2026 |
|
| CVE-2025-13882 |
Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager. |
18.09.2026 |
5.3 |
| CVE-2025-1350 |
Multiple vulnerabilities in IBM Controller |
18.09.2026 |
5.3 |
| CVE-2026-93568 |
Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requests |
18.09.2026 |
|
| CVE-2026-93576 |
Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419) |
18.09.2026 |
|
| CVE-2026-93652 |
Integer Overflow or Wraparound in µD3TN |
18.09.2026 |
7.5 |
| CVE-2024-56344 |
IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities |
18.09.2026 |
5.9 |
| CVE-2026-16512 |
Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames |
18.09.2026 |
3.1 |
| CVE-2026-16514 |
Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved |
18.09.2026 |
4.3 |
| CVE-2026-16515 |
ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack |
18.09.2026 |
4.7 |
| CVE-2026-77929 |
ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint |
18.09.2026 |
|
| CVE-2026-85511 |
Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2 |
18.09.2026 |
|
| CVE-2026-93567 |
Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority |
18.09.2026 |
|
| CVE-2026-93569 |
Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority |
18.09.2026 |
|
| CVE-2026-93657 |
hickory-resolver before 0.26.2 DNSSEC Validation Bypass |
18.09.2026 |
|
| CVE-2026-93658 |
uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid |
18.09.2026 |
|
| CVE-2026-93659 |
Concrete CMS Community Store before 2.7.8 Stored XSS |
18.09.2026 |
|
| CVE-2026-93660 |
SQLBot through 1.10.1 Improper Access Control via Dashboard Update |
18.09.2026 |
|
| CVE-2026-10832 |
Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload |
18.09.2026 |
|
| CVE-2026-25684 |
File Type Control rule bypass |
18.09.2026 |
4.4 |
| CVE-2026-77927 |
ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint |
18.09.2026 |
|
| CVE-2026-77928 |
ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint |
18.09.2026 |
|
| CVE-2026-93505 |
SveltyCMS SVG Media Upload media-service.server.ts cross site scripting |
18.09.2026 |
|
| CVE-2026-93558 |
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service |
18.09.2026 |
|
| CVE-2026-93564 |
Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881) |
18.09.2026 |
|
| CVE-2026-93565 |
Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte |
18.09.2026 |
|
| CVE-2026-93566 |
Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line |
18.09.2026 |
|
| CVE-2026-93653 |
Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service) |
18.09.2026 |
|
| CVE-2026-93676 |
Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks |
18.09.2026 |
|
| CVE-2026-93018 |
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p |
18.09.2026 |
|
| CVE-2026-93019 |
Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read |
18.09.2026 |
|
| CVE-2026-62282 |
OpenCVE: Server-Side Request Forgery (SSRF) in notifications |
18.09.2026 |
6.5 |
| CVE-2026-79294 |
|
18.09.2026 |
|
| CVE-2026-93560 |
Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos |
18.09.2026 |
|
| CVE-2026-88622 |
|
18.09.2026 |
|
| CVE-2026-88623 |
|
18.09.2026 |
|
| CVE-2023-5778 |
Missing Length Check |
18.09.2026 |
7.5 |
| CVE-2026-93504 |
SveltyCMS User Attribute Update Endpoint +server.ts access control |
18.09.2026 |
|
| CVE-2026-93586 |
ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob |
18.09.2026 |
|
| CVE-2026-93587 |
ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder |
18.09.2026 |
|
| CVE-2026-93588 |
ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM |
18.09.2026 |
|
| CVE-2026-93589 |
ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder |
18.09.2026 |
|
| CVE-2026-93590 |
ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder |
18.09.2026 |
|
| CVE-2026-93591 |
SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go |
18.09.2026 |
|
| CVE-2026-93592 |
vLLM before 0.28.0 Denial of Service via negative token ID |
18.09.2026 |
|
| CVE-2026-93593 |
ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission |
18.09.2026 |
|
| CVE-2026-93594 |
ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries |
18.09.2026 |
|
| CVE-2026-93595 |
ArcadeDB before 26.9.1 ACL Bypass via query_database Tool |
18.09.2026 |
|
| CVE-2026-93596 |
ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect |
18.09.2026 |
|
| CVE-2026-93597 |
ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses |
18.09.2026 |
|
| CVE-2026-93598 |
ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle |
18.09.2026 |
|
| CVE-2026-93599 |
rustls-webpki before 0.103.13 Panic via empty BIT STRING |
18.09.2026 |
|
| CVE-2026-93600 |
rustls webpki Name Constraints URI Validation Bypass |
18.09.2026 |
|
| CVE-2026-93601 |
rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass |
18.09.2026 |
|
| CVE-2026-93602 |
rustls-webpki before 0.103.10 CRL Revocation Check Bypass |
18.09.2026 |
|
| CVE-2026-93603 |
vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function |
18.09.2026 |
|
| CVE-2026-93604 |
vm2 3.11.8 Sandbox Escape via crypto.setFips |
18.09.2026 |
|
| CVE-2026-93605 |
vm2 NodeVM before 3.12.1 Remote Code Execution via child_process |
18.09.2026 |
|
| CVE-2026-93606 |
vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species |
18.09.2026 |
|
| CVE-2026-93491 |
Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipeline queue |
18.09.2026 |
|
| CVE-2026-93492 |
Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size |
18.09.2026 |
|
| CVE-2026-93488 |
Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams |
18.09.2026 |
|
| CVE-2026-28199 |
Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell |
18.09.2026 |
|
| CVE-2026-21806 |
HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (CVE-2026-21806) |
18.09.2026 |
3.1 |
| CVE-2026-28197 |
Privilege Escalation via Argument Injection in NetBackup Flex OS Shell |
18.09.2026 |
|
| CVE-2026-28198 |
Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell |
18.09.2026 |
|
| CVE-2026-81627 |
Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram |
18.09.2026 |
|
| CVE-2026-93563 |
Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos |
18.09.2026 |
|
| CVE-2026-93572 |
Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patched preallocation limits |
18.09.2026 |
|
| CVE-2026-93575 |
Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder |
18.09.2026 |
|
| CVE-2026-93578 |
Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass |
18.09.2026 |
|
| CVE-2026-93561 |
Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling |
18.09.2026 |
|
| CVE-2026-92976 |
Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0 |
18.09.2026 |
|
| CVE-2026-15579 |
|
18.09.2026 |
|
| CVE-2026-87743 |
Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus http security |
18.09.2026 |
|
| CVE-2026-15797 |
Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_title |
18.09.2026 |
6.4 |
| CVE-2026-18405 |
Jeg Kit for Elementor <= 3.2.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
18.09.2026 |
7.2 |
| CVE-2026-87915 |
Popup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter |
18.09.2026 |
7.2 |
| CVE-2026-90884 |
WP Recipe Maker <= 10.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint |
18.09.2026 |
5.4 |
| CVE-2026-21822 |
A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822). |
18.09.2026 |
6.3 |
| CVE-2025-13533 |
CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Assignment Engine Fields |
18.09.2026 |
4.4 |
| CVE-2026-40530 |
|
18.09.2026 |
8 |
| CVE-2026-40531 |
|
18.09.2026 |
4.3 |
| CVE-2026-40532 |
|
18.09.2026 |
6.5 |
| CVE-2026-40533 |
|
18.09.2026 |
5.3 |
| CVE-2026-40534 |
|
18.09.2026 |
5.4 |
| CVE-2026-40535 |
|
18.09.2026 |
6.5 |
| CVE-2026-40536 |
|
18.09.2026 |
4.3 |
| CVE-2026-40537 |
|
18.09.2026 |
4.3 |
| CVE-2026-40538 |
|
18.09.2026 |
3.7 |
| CVE-2026-40539 |
|
18.09.2026 |
7.1 |
| CVE-2026-4036 |
|
18.09.2026 |
6.5 |
| CVE-2026-56595 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
3.1 |
| CVE-2026-56597 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
3.1 |
| CVE-2026-83561 |
Complianz GDPR/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex |
18.09.2026 |
7.2 |
| CVE-2026-85410 |
Master Addons for Elementor <= 3.2.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter |
18.09.2026 |
8.1 |