CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-87796 Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload 17.09.2026 9.8
CVE-2026-61594 djust has an authorization bypass on the WebSocket/SSE mount path 16.09.2026 9.1
CVE-2026-92576 HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool 16.09.2026 9.2
CVE-2026-92578 WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash 16.09.2026 9.2
CVE-2026-75513 Marten: SQL injection in Marten's LINQ provider via unescaped string literals 16.09.2026 9.1
CVE-2026-92749 SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret 16.09.2026 9.2
CVE-2026-92785 Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes 16.09.2026 9.2
CVE-2026-92787 Feast through 0.66.0 Authentication Bypass via Unverified Token 16.09.2026 9.3
CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard 16.09.2026 9.3
CVE-2026-20284 Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability 17.09.2026 9.1
CVE-2026-20332 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities 17.09.2026 9.9
CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-20130 Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities 16.09.2026 10
CVE-2026-20176 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20192 Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities 16.09.2026 10
CVE-2026-20194 Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities 16.09.2026 9.1
CVE-2026-20211 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20237 Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities 16.09.2026 9.1
CVE-2026-20242 Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability 16.09.2026 9.8
CVE-2026-20322 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control 16.09.2026 9.9
CVE-2026-20324 Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability 16.09.2026 9.9
CVE-2026-20325 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command 16.09.2026 9.9
CVE-2026-20326 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function 16.09.2026 9.8
CVE-2026-20329 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities 16.09.2026 9.9
CVE-2026-20330 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities 16.09.2026 9.9
CVE-2026-20341 Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability 16.09.2026 9.1
CVE-2026-76423 Cisco ISE API Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-92808 Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise 16.09.2026 10
CVE-2026-89083 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 16.09.2026 9.3
CVE-2026-89082 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 16.09.2026 9.3
CVE-2026-73456 Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. 17.09.2026 9.2
CVE-2026-91104 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-91106 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-92717 Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub 16.09.2026 9.3
CVE-2026-92720 Kubero through 3.1.1 Unauthenticated Notifications API Access 16.09.2026 9.3
CVE-2026-20234 Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities 17.09.2026 9.9
CVE-2026-20305 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20306 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.9
CVE-2026-20331 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities 17.09.2026 9.6
CVE-2026-76420 Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability 17.09.2026 9
CVE-2026-92398 Ruijie RG-EW3000GX user_list_note admin os command injection 16.09.2026 9.4
CVE-2026-92397 Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection 16.09.2026 9.4
CVE-2025-59953 LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy 16.09.2026 9.8
CVE-2026-70416 16.09.2026 10
CVE-2026-77411 RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr 16.09.2026 9.5
CVE-2026-77405 RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser 16.09.2026 9.4
CVE-2026-92395 @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 16.09.2026 9.1
CVE-2026-77408 RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow 16.09.2026 9.1
CVE-2026-91843 Stack overflow in login process to the Security Management and Log Servers 17.09.2026 9.8
CVE-2026-73172 16.09.2026 9.3
CVE-2026-40855 Command Injection in T-Mobile 5G Box IDU router via ping functionality 16.09.2026 9.3
CVE-2026-58146 Unauthorized remote code execution in T-Mobile 5G Box IDU routers 16.09.2026 9.4
CVE-2026-58147 Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers 16.09.2026 9.3
CVE-2026-89846 scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read 16.09.2026 9.1
CVE-2026-89847 scsi: qla2xxx: Avoid double completion in async IOCB timeout 16.09.2026 9.8
CVE-2026-89857 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject 16.09.2026 9.8
CVE-2026-89914 KVM: arm64: Sign-extend VA for range-based TLBI invalidation 16.09.2026 9.3
CVE-2026-89915 KVM: arm64: Remove VM-wide VNCR mapping counter 16.09.2026 9.3
CVE-2026-89916 KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry 16.09.2026 9.3
CVE-2026-89918 KVM: arm64: Correctly handle end of VA space TLBI invalidation 16.09.2026 9.3
CVE-2026-89930 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter 16.09.2026 9.3
CVE-2026-89969 nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU 16.09.2026 9.8
CVE-2026-89970 nvmet-auth: Synchronize timeout work during SQ teardown 16.09.2026 9.8
CVE-2026-89972 nvme: add missing SRCU grace period in error path 16.09.2026 9.8
CVE-2026-89990 ceph: lock mutex in ceph_mds_check_access() 16.09.2026 9.8
CVE-2026-90011 scsi: target: iscsi: Reserve a terminator byte for the login payload 16.09.2026 9.1
CVE-2026-90012 spi: Fix DMA mapping ownership on partial map failure 16.09.2026 9.8
CVE-2026-90036 NFSD: Prevent client use-after-free during blocked-lock reaping 16.09.2026 9.8
CVE-2026-90037 NFSD: Prevent client use-after-free during close_lru reaping 16.09.2026 9.8
CVE-2026-90038 NFSD: Prevent client use-after-free during export state revocation 16.09.2026 9.8
CVE-2026-90042 ceph: properly decrypt filenames in vmalloc() buffers 16.09.2026 9.8
CVE-2026-90048 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() 16.09.2026 9.8
CVE-2026-90049 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() 16.09.2026 9.3
CVE-2026-73453 Security Advisory 0174 17.09.2026 9.5
CVE-2026-89778 isofs: fix out-of-bounds page array access on empty zisofs block 16.09.2026 9.8
CVE-2026-89779 fs/ntfs3: validate ef->size covers the record's name and value 16.09.2026 9.1
CVE-2026-89783 xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full 16.09.2026 9.8
CVE-2026-89786 ext4: fix out-of-bounds read in ext4_read_inline_dir() 16.09.2026 9.1
CVE-2026-89788 ksmbd: fix tree connection use-after-free in smb2_tree_connect() 16.09.2026 9.8
CVE-2026-81642 Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY 16.09.2026 9.1
CVE-2026-89775 KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation 16.09.2026 9.3
CVE-2026-73461 Security Advisory 0163 17.09.2026 9.4
CVE-2026-27546 Authentication Bypass in _account_log 16.09.2026 9.8
CVE-2026-27565 Remote code execution via uploading a malicious IODD file 16.09.2026 9.8
CVE-2026-73447 Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request 17.09.2026 9.4
CVE-2026-12793 JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter 16.09.2026 9.8
CVE-2026-14349 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action 16.09.2026 9.8
CVE-2026-15638 Cryptographic Padding Oracle 16.09.2026 9.1
CVE-2026-15639 Reflected Cross-Site Scripting 16.09.2026 9.3
CVE-2026-15640 Authentication Bypass via SAML Response Manipulation 16.09.2026 9.5
CVE-2026-73807 mySCADA myPRO Manager Missing Authorization 16.09.2026 9.3
CVE-2026-78225 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.5
CVE-2026-81855 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.3
CVE-2026-61560 @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover 16.09.2026 9.8
CVE-2026-61559 @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery 15.09.2026 9.6
CVE-2026-61568 @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport 16.09.2026 9.6
CVE-2026-68491 16.09.2026 9.4
CVE-2026-91939 Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter 16.09.2026 9.3
CVE-2026-66887 Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-54337 Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite 16.09.2026 9.8
CVE-2026-66890 Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-70748 15.09.2026 9.8
CVE-2026-70756 15.09.2026 9.8
CVE-2026-70757 15.09.2026 9.8
CVE-2026-70913 15.09.2026 9.8
CVE-2026-71133 17.09.2026 10
CVE-2026-71163 16.09.2026 9.9
CVE-2026-73940 15.09.2026 9.8
CVE-2026-73944 15.09.2026 9.1
CVE-2026-73945 16.09.2026 9.9
CVE-2026-73946 16.09.2026 9.1
CVE-2026-73947 15.09.2026 9.8
CVE-2026-73948 16.09.2026 9.9
CVE-2026-73950 15.09.2026 9.8
CVE-2026-73952 15.09.2026 9.1
CVE-2026-73953 15.09.2026 9.8
CVE-2026-73956 15.09.2026 9.8
CVE-2026-73957 16.09.2026 9.3
CVE-2026-73961 15.09.2026 9.8
CVE-2026-73962 16.09.2026 9.6
CVE-2026-73963 15.09.2026 9.8
CVE-2026-82994 15.09.2026 9.8
CVE-2026-82995 15.09.2026 9.8
CVE-2026-82997 16.09.2026 9.9
CVE-2026-82998 16.09.2026 9.9
CVE-2026-82999 16.09.2026 9.9
CVE-2026-83000 15.09.2026 9.8
CVE-2026-83001 16.09.2026 9.1
CVE-2026-83006 16.09.2026 9.1
CVE-2026-83020 17.09.2026 10
CVE-2026-83021 17.09.2026 10
CVE-2026-83027 16.09.2026 9.3
CVE-2026-83029 16.09.2026 9.6
CVE-2026-83031 16.09.2026 9.9
CVE-2026-83035 15.09.2026 9.8
CVE-2026-83036 15.09.2026 9.8
CVE-2026-83037 15.09.2026 9.8
CVE-2026-83038 16.09.2026 9.9
CVE-2026-83039 16.09.2026 9.9
CVE-2026-83040 16.09.2026 9.6
CVE-2026-83042 15.09.2026 9.8
CVE-2026-83043 16.09.2026 9.6
CVE-2026-83054 15.09.2026 9.8
CVE-2026-83055 15.09.2026 9.9
CVE-2026-83056 15.09.2026 9.9
CVE-2026-83057 15.09.2026 9.9
CVE-2026-83058 15.09.2026 9.9
CVE-2026-83059 17.09.2026 10
CVE-2026-83060 15.09.2026 9.8
CVE-2026-83061 15.09.2026 9.8
CVE-2026-83062 15.09.2026 9.8
CVE-2026-83064 15.09.2026 9.1
CVE-2026-83066 15.09.2026 9.8
CVE-2026-83094 15.09.2026 9.8
CVE-2026-83095 15.09.2026 9.8
CVE-2026-83098 15.09.2026 9.8
CVE-2026-83099 15.09.2026 10
CVE-2026-83100 15.09.2026 9.8
CVE-2026-83103 15.09.2026 9.1
CVE-2026-83104 15.09.2026 9.1
CVE-2026-83105 15.09.2026 9
CVE-2026-83107 15.09.2026 9.1
CVE-2026-83108 15.09.2026 9.8
CVE-2026-83149 15.09.2026 9.1
CVE-2026-83151 15.09.2026 9.8
CVE-2026-83154 15.09.2026 9.1
CVE-2026-83196 15.09.2026 9.1
CVE-2026-83197 15.09.2026 9.1
CVE-2026-83201 15.09.2026 9.1
CVE-2026-83202 15.09.2026 9.1
CVE-2026-83229 15.09.2026 9.1
CVE-2026-83232 15.09.2026 9.8
CVE-2026-83260 15.09.2026 9.1
CVE-2026-83261 15.09.2026 9.8
CVE-2026-83268 15.09.2026 9.1
CVE-2026-83269 15.09.2026 9.8
CVE-2026-83282 15.09.2026 9.9
CVE-2026-83283 15.09.2026 9.8
CVE-2026-83327 15.09.2026 9.8
CVE-2026-83339 15.09.2026 9.8
CVE-2026-83355 15.09.2026 9.8
CVE-2026-83452 15.09.2026 9.8
CVE-2026-83462 15.09.2026 9.8
CVE-2026-87128 15.09.2026 9.1
CVE-2026-87129 15.09.2026 9.1
CVE-2026-87170 15.09.2026 9.1
CVE-2026-87172 15.09.2026 9.9
CVE-2026-87173 15.09.2026 9.1
CVE-2026-87175 15.09.2026 9.1
CVE-2026-87176 15.09.2026 9.1
CVE-2026-87184 15.09.2026 9.8
CVE-2026-87186 15.09.2026 9.6
CVE-2026-87188 15.09.2026 9.8
CVE-2026-87189 15.09.2026 9.1
CVE-2026-87214 15.09.2026 9.1
CVE-2026-87217 15.09.2026 9.1
CVE-2026-87223 15.09.2026 9.1
CVE-2026-87230 15.09.2026 10
CVE-2026-89040 Tencent Mass Service Engine in Cluster (MSEC) path traversal 15.09.2026 9.3
CVE-2026-73458 On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou 15.09.2026 9.2
CVE-2026-76669 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76670 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76672 Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76673 Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator 15.09.2026 9.8
CVE-2026-76674 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways 15.09.2026 9.8
CVE-2026-76675 Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways 15.09.2026 9.1
CVE-2026-69204 Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) 15.09.2026 9.2
CVE-2026-19773 libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability 16.09.2026 9.8
CVE-2026-45579 DIRAC: RCE in RequestManager due to eval on untrusted input 15.09.2026 9.9
CVE-2026-53459 Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints 15.09.2026 9.3
CVE-2026-61667 DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval 15.09.2026 9.9
CVE-2026-12351 IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection 16.09.2026 9.8
CVE-2023-54398 Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet 15.09.2026 9.3
CVE-2024-58385 Yonyou U8 CRM SQL Injection via fillbacksettingedit.php 15.09.2026 9.3
CVE-2026-46488 motionEye: Authentication possible via password hash 15.09.2026 9.1
CVE-2026-53710 MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server 15.09.2026 10
CVE-2026-89026 Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate 15.09.2026 9.3
CVE-2026-89022 BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion 15.09.2026 9.1
CVE-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts 15.09.2026 9
CVE-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding 15.09.2026 9
CVE-2026-55211 surfio IRAP header size fields cause out-of-bounds reads 15.09.2026 9.8
CVE-2023-54397 Tornado before 6.3.3 HTTP Request Smuggling via Content-Length 15.09.2026 9
CVE-2024-14029 Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding 15.09.2026 9
CVE-2026-91931 Flowise before 3.1.4 Remote Code Execution via Custom MCP npx 15.09.2026 9
CVE-2026-91932 Flowise before 3.1.4 Remote Code Execution via cwd Parameter 15.09.2026 9
CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass 15.09.2026 9.2
CVE-2026-91988 atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP 15.09.2026 9.2
CVE-2026-61549 Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend 16.09.2026 9
CVE-2026-63696 16.09.2026 9.1
CVE-2026-55158 Conflibot: Command injection via crafted pull request branch names under pull_request_target 15.09.2026 9.1
CVE-2026-63695 16.09.2026 9.8
CVE-2026-39919 Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter 15.09.2026 9.3
CVE-2026-46495 OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI 15.09.2026 9.2
CVE-2026-59971 MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) 15.09.2026 10
CVE-2026-77179 Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback 15.09.2026 9.4
CVE-2026-89308 Arbitrary command execution in TrxTimeATTENDANCE 15.09.2026 9.3
CVE-2026-91995 pig before 4.1.0 Unverified Password Change via /register/password 15.09.2026 9.3
CVE-2026-91998 Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp 15.09.2026 9.4
CVE-2026-52824 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover 16.09.2026 9.1
CVE-2026-57147 praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery 15.09.2026 9.8
CVE-2026-57139 PraisonAI MCPServer exposes unauthenticated HTTP tools/call 15.09.2026 9.8
CVE-2026-57140 PraisonAI AgentOS exposes unauthenticated agent listing and invocation 15.09.2026 9.4
CVE-2026-57148 praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) 16.09.2026 9.8
CVE-2026-57138 PraisonAI codeMode sandbox escape via Function constructor 15.09.2026 9.9
CVE-2026-57141 PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool 15.09.2026 9.8
CVE-2026-48717 OpenAM OAuth Authorization Bypass via PKCE Challenge 15.09.2026 9.1
CVE-2026-45051 OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage 15.09.2026 9.2
CVE-2026-46619 OpenAM Authentication Bypass via MSISDN LDAP Injection 15.09.2026 9.3
CVE-2026-62263 OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass 15.09.2026 9.2
CVE-2026-45052 OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints 16.09.2026 9.3
CVE-2026-62379 OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback 15.09.2026 9.8
CVE-2026-90711 proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 15.09.2026 9.1
CVE-2026-91003 D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow 15.09.2026 9.4
CVE-2026-91001 D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow 15.09.2026 9.4
CVE-2026-90847 EFM ipTIME C200E System Setup iux_set.cgi os command injection 15.09.2026 9.4
CVE-2026-12944 Incomplete Security Scanner Blocklist Enables Network-Based Code Execution 16.09.2026 9.6
CVE-2026-67399 15.09.2026 9.3
CVE-2026-53713 Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure 16.09.2026 9.1
CVE-2026-54333 UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable 15.09.2026 9.8
CVE-2026-54334 UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen` 16.09.2026 9.8
CVE-2026-50006 Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode 15.09.2026 9.1
CVE-2026-55209 resdata insufficiently validates untrusted GRDECL files 14.09.2026 9.8
CVE-2026-16338 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 14.09.2026 9.9
CVE-2026-59178 ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade 14.09.2026 9.8
CVE-2026-90942 Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints 14.09.2026 9.3
CVE-2026-90945 Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret 16.09.2026 9.3
CVE-2026-57578 DotVVM: Missing authorization in AuthorizeActionFilter 14.09.2026 9.2
CVE-2026-20353 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76440 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76441 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76443 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability 15.09.2026 9.8
CVE-2026-61534 Yayson: Prototype pollution in the Store/LegacyStore deserialization 14.09.2026 9.1
CVE-2026-90943 parallax filament-comments through 3.0.0 Stored XSS via Comment Body 14.09.2026 9.3
CVE-2026-57124 PraisonAI UI MCP connect endpoint allows unauthenticated local command execution 14.09.2026 9.8
CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set 14.09.2026 9.8
CVE-2026-57131 praisonai: Jobs API exposes agent-execution endpoints with no authentication 14.09.2026 9.8
CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation 14.09.2026 9.1
CVE-2026-57123 PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in 14.09.2026 9.8
CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass 14.09.2026 9.8
CVE-2026-82434 Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs 14.09.2026 10
CVE-2026-90961 MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials 14.09.2026 9.3
CVE-2026-90937 froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL 16.09.2026 9.4
CVE-2026-12258 Inadequate access control in the Hiperdino REST API 14.09.2026 9.2
CVE-2026-90919 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization 14.09.2026 9.3
CVE-2026-21391 Improper Claim Validation in PingAM OIDC Provider 14.09.2026 9.5
CVE-2026-90898 Bifrost unauthenticated remote code execution via MCP stdio client registration 14.09.2026 9.8
CVE-2026-90703 D-Link DWR-M921 formDiskCreateShare system os command injection 15.09.2026 9.4
CVE-2026-90702 D-Link DWR-M921 formDiskFormat system os command injection 15.09.2026 9.4
CVE-2026-90699 D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection 14.09.2026 9.4
CVE-2026-90693 D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow 15.09.2026 9.4
CVE-2026-90692 D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow 15.09.2026 9.4
CVE-2026-85192 Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 14.09.2026 9.4
CVE-2026-90680 D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow 16.09.2026 9.4
CVE-2026-90607 Totolink A3002MU boa formNewSchedule buffer overflow 14.09.2026 9.4
CVE-2026-90608 Totolink A3002MU boa formPortFw buffer overflow 16.09.2026 9.4
CVE-2026-90606 Totolink A3002MU boa formIpv6Setup buffer overflow 15.09.2026 9.4
CVE-2026-90605 Totolink A3002MU boa formFilter buffer overflow 15.09.2026 9.4
CVE-2026-81648 CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router 14.09.2026 10
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG 13.09.2026 9.3
CVE-2026-90562 LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key 16.09.2026 9.2
CVE-2026-90493 Tonec Internet Download Manager Kernel Driver idmwfp.sys access control 15.09.2026 9.3
CVE-2026-90647 15.09.2026 9.1
CVE-2026-90558 sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers 14.09.2026 9.3
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution 14.09.2026 9.8
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation 14.09.2026 9.8
CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 12.09.2026 10
CVE-2026-87719 Deserialization of Untrusted Data in GitLab 15.09.2026 9.9
CVE-2026-90456 14.09.2026 9.2
CVE-2026-89697 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() 14.09.2026 9.1
CVE-2026-89702 nfsd: size fh_verify server sockaddr slot by xpt_locallen 13.09.2026 9.8
CVE-2026-89703 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations 13.09.2026 9.8
CVE-2026-89708 nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown 13.09.2026 9.8
CVE-2026-89712 NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock 14.09.2026 9.8
CVE-2026-89713 NFSD: check truncate permission under inode lock 13.09.2026 9.1
CVE-2026-80945 crypto: iaa - unmap dst before software fallback on decompress 13.09.2026 9.1
CVE-2026-80976 seg6: reset IP6CB after IPv6 decapsulation 14.09.2026 9.8
CVE-2026-80980 net/smc: stop killed, freed and out_of_sync sharing a byte 13.09.2026 9.8
CVE-2026-80981 net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() 13.09.2026 9.8
CVE-2026-80986 net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages 13.09.2026 9.8
CVE-2026-81002 xdp: fix zero-copy frame layout 14.09.2026 9.8
CVE-2026-89448 iommu/vt-d: Force requesting ACS when tboot is enabled 14.09.2026 9.3
CVE-2026-89478 sctp: drop a chunk if its transport was removed 14.09.2026 9.8
CVE-2026-89479 sctp: stop processing a packet once its association is deleted 14.09.2026 9.8
CVE-2026-89482 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone 14.09.2026 9.8
CVE-2026-89485 lockd: pin next file across nlm_inspect_file lock-drop 14.09.2026 9.8
CVE-2026-89492 ocfs2: validate directory-index entry counts when reading metadata 13.09.2026 9.8
CVE-2026-89494 ocfs2: validate lengths in dlm_mig_lockres_handler 14.09.2026 9.8
CVE-2026-89495 ocfs2: bound namelen in dlm_migrate_request_handler 14.09.2026 9.8
CVE-2026-89526 svcrdma: Validate Read chunk positions before reconstruction 13.09.2026 9.8
CVE-2026-89530 svcrdma: Reject inline replies that overflow the pull-up buffer 13.09.2026 9.8
CVE-2026-89532 svcrdma: Fix pcl_for_each_segment for empty chunks 14.09.2026 9.1
CVE-2026-89533 svcrdma: Fix offset arithmetic in read_chunk_range 14.09.2026 9.8
CVE-2026-89536 SUNRPC: wait for in-flight client TLS handshake callback 14.09.2026 9.8
CVE-2026-89537 SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 13.09.2026 9.1
CVE-2026-89538 SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field 14.09.2026 9.8
CVE-2026-89541 SUNRPC: harden gss_unwrap_resp_priv length checks 14.09.2026 9.8
CVE-2026-89542 SUNRPC: harden gss_krb5_unwrap_v2 against short tokens 14.09.2026 9.8
CVE-2026-89546 SUNRPC: close backchannel before destroying callback service 13.09.2026 9.8
CVE-2026-89550 SUNRPC: svcauth_gss: enforce krb5 token minimum length 14.09.2026 9.8
CVE-2026-89551 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow 14.09.2026 9.8
CVE-2026-89555 mpls: reload header after pskb_may_pull() 14.09.2026 9.8
CVE-2026-89558 md/raid10: fix still_degraded being inverted in raid10_sync_request() 13.09.2026 9.8
CVE-2026-89610 ntfs: verify run length exceeding volume boundary 13.09.2026 9.8
CVE-2026-89611 ntfs: validate non-resident attribute offsets 13.09.2026 9.8
CVE-2026-89612 ntfs: reject invalid MFT LCNs from boot sector 13.09.2026 9.8
CVE-2026-89613 ntfs: reject invalid empty mapping pairs 13.09.2026 9.8
CVE-2026-89614 ntfs: bound the free-cluster bitmap scan to the volume 13.09.2026 9.8
CVE-2026-89630 smb: client: restore the data_offset bound in is_valid_oplock_break() 13.09.2026 9.1
CVE-2026-89631 smb: client: reject a tree connect response whose byte count is too small 13.09.2026 9.1
CVE-2026-89633 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() 13.09.2026 9.8
CVE-2026-89634 smb: client: fix ALIGN() overflow in symlink_data() error context loop 14.09.2026 9.1
CVE-2026-89635 ksmbd: only rebind the reopened file's own oplock on durable reconnect 13.09.2026 9.8
CVE-2026-89636 smb: client: clear ce->tgthint in free_tgts() 14.09.2026 9.8
CVE-2026-89637 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 13.09.2026 9.8
CVE-2026-89643 audit: avoid dropping live tree ref on fsnotify rule autoremove 14.09.2026 9.8
CVE-2026-89649 ceph: bound xattr value length in __build_xattrs() 14.09.2026 9.1
CVE-2026-89650 ceph: bound num_export_targets array for mds info v2/v3 14.09.2026 9.1
CVE-2026-89651 ceph: bound MDSCapAuth path and fs_name decode in handle_session() 13.09.2026 9.8
CVE-2026-89652 ceph: bound copied dentry name length in NFS export get_name 14.09.2026 9.8
CVE-2026-89653 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode 14.09.2026 9.8
CVE-2026-89654 ceph: fix UAF in check_new_map() on session freed during unlock 13.09.2026 9.8
CVE-2026-89655 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock 14.09.2026 9.8
CVE-2026-89656 libceph: reject buckets with mismatched CRUSH ids 14.09.2026 9.8
CVE-2026-89658 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup 13.09.2026 9.8
CVE-2026-89659 NFSD: Prevent client use-after-free during delegation revoke 13.09.2026 9.8
CVE-2026-89660 NFSD: Prevent client use-after-free during admin state revocation 13.09.2026 9.8
CVE-2026-89662 NFSD: Prevent lock owner use-after-free during client teardown 14.09.2026 9.8
CVE-2026-89669 nfsd: initialize copy-notify stateid before publishing it 14.09.2026 9.8
CVE-2026-89671 nfsd: gate nfs3 setacl by argp->mask 14.09.2026 9.1
CVE-2026-89672 nfsd: gate nfs2 setacl by argp->mask 14.09.2026 9.1
CVE-2026-89674 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget 14.09.2026 9.8
CVE-2026-89675 nfsd: fix UAF in async copy cancel and shutdown 13.09.2026 9.8
CVE-2026-89676 nfsd: fix stale s2s_cp_stateids IDR entry for async COPY 13.09.2026 9.8
CVE-2026-89677 nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() 13.09.2026 9.8
CVE-2026-89681 nfsd: fix layout fence worker double-reference race 13.09.2026 9.8
CVE-2026-89686 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke 13.09.2026 9.8
CVE-2026-89688 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry 13.09.2026 9.8
CVE-2026-89689 nfsd: don't free session slots that are still in use 13.09.2026 9.8
CVE-2026-80926 ksmbd: fix use-after-free in oplock break notification 13.09.2026 9.8
CVE-2026-53952 GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw 14.09.2026 9.8
CVE-2026-54072 Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL 15.09.2026 9.3
CVE-2026-62103 WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-62105 WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-82617 Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns 11.09.2026 10
CVE-2026-72709 SPIP < 4.4.18 Missing Authorization via ecrire/action/ 15.09.2026 9.3
CVE-2026-72710 SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection 15.09.2026 9.3
CVE-2026-54047 Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation 11.09.2026 9.2
CVE-2026-3869 11.09.2026 9.2
CVE-2026-89010 WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server 11.09.2026 9.3
CVE-2026-38056 ST Engineering iDirect iQ-Series Terminals Missing Authorization 11.09.2026 9.4
CVE-2026-87987 11.09.2026 10
CVE-2026-87988 11.09.2026 10
CVE-2026-87983 11.09.2026 9.2
CVE-2026-87984 11.09.2026 9.3
CVE-2026-87985 11.09.2026 10
CVE-2026-87986 11.09.2026 10
CVE-2026-89212 XML External Entity in Akana API Platform 11.09.2026 9.2
CVE-2026-80462 Privilege Escalation in Progress Chef Automate 11.09.2026 10
CVE-2026-84390 11.09.2026 9.6
CVE-2026-89243 WWBN AVideo Stored XSS via UserGroups setGroup_name 11.09.2026 9.2
CVE-2026-89249 AVideo YPTWallet Stored XSS via CryptoWallet Configuration 11.09.2026 9.3
CVE-2026-89253 AVideo Stored XSS via donationLink in watch page button 11.09.2026 9.3
CVE-2026-89254 AVideo CustomizeUser Stored XSS via field_name Parameter 11.09.2026 9.3
CVE-2026-89255 AVideo LoginControl Stored XSS via PGP Public Key 11.09.2026 9.3
CVE-2026-89256 AVideo Bookmark Plugin Stored XSS via Chapter Names 11.09.2026 9.3
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get 11.09.2026 9.3
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS 11.09.2026 9.3
CVE-2026-47839 Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin 11.09.2026 9.2
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 11.09.2026 9.1
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 11.09.2026 9.8
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 15.09.2026 9.1
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 11.09.2026 9.1
CVE-2026-75940 11.09.2026 9.3
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-89094 14.09.2026 9.9
CVE-2026-89086 10.09.2026 9.1
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 11.09.2026 9.5
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 11.09.2026 9.3
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026 9.1
CVE-2026-65638 10.09.2026 9.2
CVE-2026-65639 10.09.2026 9.5
CVE-2026-68487 10.09.2026 9.9
CVE-2026-68488 10.09.2026 9.9
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 11.09.2026 9.3
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026 9.1
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 11.09.2026 9.3
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026 9.3
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026 9.3
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 15.09.2026 9.3
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026 9.3
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026 9.3
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026 9.3
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026 9.3
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 15.09.2026 9.2
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026 9.3
CVE-2026-8323 Open Redirect in Armiya Information Technologies' Access Control System 10.09.2026 9.3
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables 10.09.2026 9.2
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 10.09.2026 9.5
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 10.09.2026 9.2
CVE-2026-88278 GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay 10.09.2026 9.8
CVE-2026-88285 GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service 10.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-50605 Privilege Escalation Vulnerability in NitroSense and PredatorSense Software 17.09.2026
CVE-2026-87829 Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting 17.09.2026 4.3
CVE-2026-87831 Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field 17.09.2026 4.3
CVE-2026-86320 Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`) 17.09.2026
CVE-2026-86801 To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler 17.09.2026 8.8
CVE-2026-87963 Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter 17.09.2026 8.6
CVE-2026-91017 Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback 17.09.2026 3.7
CVE-2026-44940 Service token exposure and potential privilege escalation in SUSE Observability 17.09.2026 5.7
CVE-2026-90982 @fastify/static vulnerable to route guard bypass via path case-folding 17.09.2026 5.3
CVE-2025-15697 Dictionary <= 1.0 - Reflected XSS via Multiple Parameters 17.09.2026
CVE-2026-85128 Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request 17.09.2026
CVE-2026-85130 WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs 17.09.2026
CVE-2026-86446 LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST Endpoint 17.09.2026
CVE-2026-86707 Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter 17.09.2026
CVE-2026-86709 The Pressengine <= 1.0 - Unauthenticated Authentication Bypass 17.09.2026
CVE-2026-86710 Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter 17.09.2026
CVE-2026-86788 HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag 17.09.2026
CVE-2026-86824 Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key 17.09.2026
CVE-2026-87786 Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates 17.09.2026
CVE-2026-87836 Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export 17.09.2026
CVE-2026-88792 Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update 17.09.2026
CVE-2026-88795 wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token 17.09.2026
CVE-2026-88904 PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation 17.09.2026
CVE-2026-90922 Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch 17.09.2026
CVE-2026-90923 Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion 17.09.2026
CVE-2026-91008 Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel 17.09.2026
CVE-2026-91009 Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment 17.09.2026
CVE-2026-91010 Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion 17.09.2026
CVE-2026-91011 EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion 17.09.2026
CVE-2026-91014 Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint 17.09.2026
CVE-2026-91015 Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired 17.09.2026
CVE-2026-91016 Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure 17.09.2026
CVE-2026-91019 Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosure 17.09.2026
CVE-2026-87796 Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload 17.09.2026 9.8
CVE-2026-87935 Paid Downloads <= 3.15 - Unauthenticated Arbitrary File Upload via 'paiddownloads_update_file' Action 17.09.2026 8.1
CVE-2025-59607 Untrusted Pointer Dereference in Windows Compute 17.09.2026 7.8
CVE-2026-24073 Out-of-bounds Write in Video 17.09.2026 7.8
CVE-2026-24074 Out-of-bounds Write in Video 17.09.2026 7.8
CVE-2026-24075 Buffer Over-read in Qualcomm IPC 17.09.2026 7.8
CVE-2026-24081 Buffer Over-read in BT Controller 17.09.2026 7.4
CVE-2026-25261 Untrusted Pointer Dereference in Camera 17.09.2026 6.7
CVE-2026-25275 Buffer Over-read in WLAN Firmware 17.09.2026 7.5
CVE-2026-25278 Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Software platform based on QNX 17.09.2026 7.8
CVE-2026-25280 Out-of-bounds Write in DSP Service 17.09.2026 7.8
CVE-2026-25281 Allocation of Resources Without Limits or Throttling in OOBM 17.09.2026 7.4
CVE-2026-25282 Out-of-bounds Read in OOBM 17.09.2026 7.9
CVE-2026-25283 Stack-based Buffer Overflow in OOBM 17.09.2026 8.8
CVE-2026-25284 Buffer Over-read in OOBM 17.09.2026 7.3
CVE-2026-25290 Integer Overflow or Wraparound in OOBM 17.09.2026 7.8
CVE-2026-25294 Buffer Over-read in WLAN Firmware 17.09.2026 7.4
CVE-2026-50604 Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software 17.09.2026
CVE-2026-50603 Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense 17.09.2026
CVE-2026-92839 17.09.2026 4.3
CVE-2026-86311 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 17.09.2026 6.4
CVE-2026-89064 All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Insufficient Credential Protection via Authorization Basic Header 17.09.2026 5.3
CVE-2026-81546 17.09.2026 7.7
CVE-2026-92838 GeoVision GV-Remote E-Map dll hijacking vulnerability 17.09.2026 7.8
CVE-2026-65388 16.09.2026
CVE-2026-85789 16.09.2026
CVE-2026-61588 djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client 16.09.2026 6.5
CVE-2026-61589 djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path 16.09.2026 6.3
CVE-2026-61596 djust has broken object-level access control (IDOR) 16.09.2026 7.1
CVE-2026-61599 djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path 16.09.2026
CVE-2026-61591 djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection) 16.09.2026 8.1
CVE-2026-61594 djust has an authorization bypass on the WebSocket/SSE mount path 16.09.2026 9.1
CVE-2026-61592 djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack) 16.09.2026 7.4
CVE-2026-61597 djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags 16.09.2026
CVE-2026-92576 HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool 16.09.2026
CVE-2026-92577 AVideo through 29.0 API get_api_video Broken Access Control via clean_title 16.09.2026
CVE-2026-92578 WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash 16.09.2026
CVE-2026-92579 AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision 16.09.2026
CVE-2026-92580 AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF 16.09.2026
CVE-2026-92581 AVideo through 29.0 Like Counter Desynchronization via Array Parameter 16.09.2026
CVE-2026-92582 AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass 16.09.2026
CVE-2026-92583 AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment 16.09.2026
CVE-2026-92584 AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header 16.09.2026
CVE-2026-92585 AVideo through 29.0 Missing Authorization Check via API Like Endpoint 16.09.2026
CVE-2026-92586 AVideo through 29.0 Missing Authorization via comment API endpoint 16.09.2026
CVE-2026-92587 n8n before 1.123.76 Sandbox Escape via Git Relative URL 16.09.2026
CVE-2026-92588 n8n before 1.123.76 Improper Authorization via Source Control Push 16.09.2026
CVE-2026-92589 Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder 16.09.2026
CVE-2026-92590 Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields 16.09.2026
CVE-2026-92591 Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer 16.09.2026
CVE-2026-92592 Craft CMS before 4.18.6 Remote Code Execution via signed cookie 16.09.2026
CVE-2026-92593 Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution 16.09.2026
CVE-2026-92594 Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL 16.09.2026
CVE-2026-92595 Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent 16.09.2026
CVE-2026-92596 Nodemailer before 9.1.0 Denial of Service via addressparser 16.09.2026
CVE-2026-92597 Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment 16.09.2026
CVE-2026-92598 Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass 16.09.2026
CVE-2026-92599 Joi before 17.13.7 and 18.2.6 ReDoS via isoDate 16.09.2026
CVE-2026-89034 TCH QRing R20_B006 Unauthenticated BLE Access 16.09.2026
CVE-2026-64684 RMCP: Custom HTTP headers leak to cross-origin redirect targets 16.09.2026 6.8
CVE-2026-85469 Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope 16.09.2026
CVE-2026-62997 Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via unsafe `torch.load` 16.09.2026
CVE-2026-75513 Marten: SQL injection in Marten's LINQ provider via unescaped string literals 16.09.2026 9.1
CVE-2026-81871 OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning 16.09.2026
CVE-2026-81869 OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation 16.09.2026
CVE-2026-81872 OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full 16.09.2026
CVE-2026-20121 CIsco FTD Bypass Access List 16.09.2026 5.3
CVE-2026-63506 Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site 16.09.2026 8.8
CVE-2026-76426 Cisco ISE REST API SQL Injection Vulnerability 16.09.2026 4.9
CVE-2026-76427 Cisco ISE XML External Entity Injection Vulnerability 16.09.2026 4.9
CVE-2026-76431 Cisco Identity Services Engine Arbitrary File Deletion Vulnerability 16.09.2026 4.9
CVE-2026-76447 Cisco Identity Services Engine Certificate Reload Vulnerability 16.09.2026 5.3
CVE-2026-92748 BC Security Empire before 6.7.1 Path Traversal File Upload RCE 16.09.2026
CVE-2026-92749 SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret 16.09.2026
CVE-2026-92750 Harness through 3.3.0 Missing Access Control via infraproviders endpoint 16.09.2026
CVE-2026-92751 CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter 16.09.2026
CVE-2026-92752 metasfresh Unauthorized Access via Document Attachments and Comments Endpoints 16.09.2026
CVE-2026-92753 PatrowlManager through 1.8.4 Authorization Bypass via Events API 16.09.2026
CVE-2026-92754 PatrowlManager through 1.8.4 Improper Access Control via users API 16.09.2026
CVE-2026-92759 SecObserve before 1.59.1 Information Disclosure via API Configuration 16.09.2026
CVE-2026-92760 Shlink through 5.1.6 Mercure Token Authorization Bypass 16.09.2026
CVE-2026-92761 WebVirtCloud Missing Authorization on Instance Control Actions 16.09.2026
CVE-2026-92762 Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup 16.09.2026
CVE-2026-92763 Rundeck through 6.2.1 Authorization Bypass via Project Import 16.09.2026
CVE-2026-92764 OpenCVE before 3.1.0 Organization API Ignores Token Scope 16.09.2026
CVE-2026-92765 ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList 16.09.2026
CVE-2026-92770 Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter 16.09.2026
CVE-2026-92771 Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query 16.09.2026
CVE-2026-92772 Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX 16.09.2026
CVE-2026-92773 Trigger.dev before 4.6.0 GitHub App Installation Takeover 16.09.2026
CVE-2026-92774 Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission 16.09.2026
CVE-2026-92775 Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch 16.09.2026
CVE-2026-92776 Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass 16.09.2026
CVE-2026-92778 CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes 16.09.2026
CVE-2026-92779 Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings 16.09.2026
CVE-2026-92780 KnowStreaming through 3.4.1 Missing Authorization on the REST API 16.09.2026
CVE-2026-92781 Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes 16.09.2026
CVE-2026-92782 Chroma through 1.5.9 Authorization Bypass via Collection Identifier 16.09.2026
CVE-2026-92783 Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion 16.09.2026
CVE-2026-92784 @refinedev/inferencer through 7.0.0 Code Injection via API Field Names 16.09.2026
CVE-2026-92785 Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes 16.09.2026
CVE-2026-92786 LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model 16.09.2026
CVE-2026-92787 Feast through 0.66.0 Authentication Bypass via Unverified Token 16.09.2026
CVE-2026-92788 Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node 16.09.2026
CVE-2026-92789 Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect 16.09.2026
CVE-2026-92790 Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header 16.09.2026
CVE-2026-92791 Uber Kraken through 0.1.29 Path Traversal via tag parameter 16.09.2026
CVE-2026-92792 OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier 16.09.2026
CVE-2026-92793 GoAdmin through 1.2.26 Authorization Bypass via Query Parameter 16.09.2026
CVE-2026-92794 OpenSign through 2.41.3 Information Disclosure via getDocument 16.09.2026
CVE-2026-92795 Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin 16.09.2026
CVE-2026-92796 Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass 16.09.2026
CVE-2026-92800 Docs before 5.4.1 Stale Collaboration Session After Access Revocation 16.09.2026
CVE-2026-92801 cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions 16.09.2026
CVE-2026-92802 kan through 0.6.0 Authorization Bypass via GitHub Project Import 16.09.2026
CVE-2026-92803 LibreTranslate through 1.9.6 Missing Access Check on the download_file Route 16.09.2026
CVE-2026-92804 Nango through 0.70.4 Server-Side Request Forgery via Configuration 16.09.2026
CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard 16.09.2026
CVE-2026-92806 phpList before 3.6.17 Cross-Site Request Forgery via massremove.php 16.09.2026
CVE-2026-92809 PrestaShop psgdpr through 1.4.3 GDPR Log Forgery 16.09.2026
CVE-2026-92810 PrestaShop blockwishlist through 3.0.2 Information Disclosure 16.09.2026
CVE-2026-92811 browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass 16.09.2026
CVE-2026-92812 decap-server Path Traversal via Sibling Directory Prefix Matching 16.09.2026
CVE-2026-92813 Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass 16.09.2026
CVE-2026-92814 changedetection.io through 0.60.6 Cross-Site Scripting via watch_title 16.09.2026
CVE-2026-92815 changedetection.io through 0.60.6 SSRF via browser-step Goto URL 16.09.2026
CVE-2026-92816 ComfyUI before 0.30.0 Path Traversal via dataset save nodes 16.09.2026
CVE-2025-56563 16.09.2026
CVE-2025-56565 16.09.2026
CVE-2025-56566 16.09.2026
CVE-2026-20071 ISE 802.1x Session Hijack Vulnerability 16.09.2026 3.8
CVE-2026-20072 ISE information disclosure 16.09.2026 4.9
CVE-2026-20120 Cisco FTD ACL bypass vulnerability 16.09.2026 5.8
CVE-2026-20135 Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability 16.09.2026 8.6
CVE-2026-20154 Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software Logging Denial of Service 16.09.2026 8.6
CVE-2026-20222 Cisco Secure Adaptive Security Appliance Software and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability 16.09.2026 7.4
CVE-2026-20235 Cisco Identity Services Engine Information Disclosure Vulnerability 16.09.2026 4.9
CVE-2026-20247 Cisco Identity Services Engine Unauthenticated SQL Injection Vulnerability 16.09.2026 7.5
CVE-2026-20248 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability 16.09.2026 6.8
CVE-2026-20249 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability 16.09.2026 8.6
CVE-2026-20250 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 3100 and 4200 Series DTLS Denial of Service Vulnerability 16.09.2026 8.6
CVE-2026-20282 Cisco Identity Services Engine Authenticated Write Vulnerability 16.09.2026 4.9
CVE-2026-20283 Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability 17.09.2026 6.5
CVE-2026-20284 Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability 17.09.2026 9.1
CVE-2026-20285 Cisco Identity Services Engine Authorization Bypass Vulnerability 16.09.2026 4.3
CVE-2026-20286 Cisco Identity Services Engine Authorization Bypass Vulnerability 16.09.2026 4.3
CVE-2026-20287 Cisco Identity Services Engine Hardening Release - Improper Privlege Management Vulnerabilities 17.09.2026 6.5
CVE-2026-20290 Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability 16.09.2026 5.8
CVE-2026-20295 Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability 16.09.2026 8.6
CVE-2026-20300 Cisco Identity Services Engine SQL Injection Vulnerability 16.09.2026 7.1
CVE-2026-20309 Cisco Identity Services Engine Cross-Site Scripting Vulnerability 16.09.2026 6.1
CVE-2026-20323 Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass Vulnerability 17.09.2026 8.3
CVE-2026-20332 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities 17.09.2026 9.9
CVE-2026-20333 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Comparison Vulnerabilities 17.09.2026 8.8
CVE-2026-20334 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Coding Standards Vulnerabilities 17.09.2026 8.4
CVE-2026-20335 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Calculation Vulnerabilities 16.09.2026 8.1
CVE-2026-20336 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management Vulnerabilities 16.09.2026 8.8
CVE-2026-20340 Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability 16.09.2026 8.8
CVE-2026-20342 Cisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download Vulnerability 16.09.2026 7.7
CVE-2026-20343 Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability 16.09.2026 7.5
CVE-2026-20344 Cisco Secure Firewall Management Center Software SQL Injection Vulnerability 16.09.2026 8.8
CVE-2026-20350 Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability 16.09.2026 4.7
CVE-2026-20352 Cisco Identity Services Engine RADIUS Denial of Service Vulnerability 16.09.2026 8.6
CVE-2026-20360 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure Handling 16.09.2026 8.8
CVE-2026-76409 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Limitation of a Pathname 16.09.2026 8.8
CVE-2026-76412 Cisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root Vulnerability 17.09.2026 8.5
CVE-2026-76413 Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability 16.09.2026 8.2
CVE-2026-76424 Cisco ISE Arbitrary File Access Vulnerability 17.09.2026 7.2
CVE-2026-76425 Cisco ISE SQL Injection Vulnerability 16.09.2026 7.6
CVE-2026-76428 Cisco ISE Profiler SQL Injection Vulnerability 16.09.2026 4.9
CVE-2026-76432 Cisco Identity Services Engine Arbitrary File Write Vulnerability 16.09.2026 4.9
CVE-2026-76433 Cisco Identity Services Engine Information Disclosure Vulnerability 16.09.2026 5.3
CVE-2026-76434 Cisco Identity Services Engine Arbitrary File Read Vulnerability 16.09.2026 4.9
CVE-2026-76438 Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability 16.09.2026 6.5
CVE-2026-76439 Cisco Identity Services Engine Event Injection Vulnerability 16.09.2026 5.3
CVE-2026-76444 Cisco Identity Services Engine Information Disclosure Vulnerability 16.09.2026 5.3
CVE-2026-76446 Cisco Identity Services Engine External Entity Injection Vulnerability 16.09.2026 4.9
CVE-2026-76448 Cisco Identity Services Engine SQL Injection Vulnerability 16.09.2026 4.9
CVE-2026-76449 Cisco Identity Services Engine SQL Injection Vulnerability 16.09.2026 4.9
CVE-2026-76450 Cisco Identity Services Engine SQL Injection Vulnerability 16.09.2026 4.9
CVE-2026-76451 Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability 16.09.2026 4.9
CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-92527 chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery 16.09.2026
CVE-2026-20130 Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities 16.09.2026 10
CVE-2026-20176 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20192 Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities 16.09.2026 10
CVE-2026-20194 Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities 16.09.2026 9.1
CVE-2026-20211 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20237 Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities 16.09.2026 9.1
CVE-2026-20242 Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability 16.09.2026 9.8
CVE-2026-20322 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control 16.09.2026 9.9
CVE-2026-20324 Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability 16.09.2026 9.9
CVE-2026-20325 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command 16.09.2026 9.9
CVE-2026-20326 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function 16.09.2026 9.8
CVE-2026-20329 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities 16.09.2026 9.9
CVE-2026-20330 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities 16.09.2026 9.9
CVE-2026-20341 Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability 16.09.2026 9.1
CVE-2026-20361 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQL Injection 16.09.2026 8.8
CVE-2026-62949 AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION 16.09.2026 6.5
CVE-2026-76423 Cisco ISE API Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-81870 OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs 16.09.2026
CVE-2026-92526 itsourcecode Leave Management System index.php sql injection 16.09.2026
CVE-2026-92808 Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise 16.09.2026
CVE-2026-89083 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 16.09.2026
CVE-2026-89084 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 16.09.2026
CVE-2026-86831 Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS 16.09.2026 8.7
CVE-2026-89082 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 16.09.2026
CVE-2026-92475 GPAC downloader.c wait_for_header_and_parse out-of-bounds 16.09.2026
CVE-2026-86865 Tanium addressed a SQL injection vulnerability in Asset. 16.09.2026 8.8
CVE-2026-87024 Tanium addressed a SQL injection vulnerability in Asset. 16.09.2026 7.2
CVE-2026-87026 Tanium addressed an improper access controls vulnerability in Threat Response. 16.09.2026 3.8
CVE-2026-87076 Tanium addressed an information disclosure vulnerability in Discover. 16.09.2026 6.5
CVE-2026-87105 Tanium addressed a SQL injection vulnerability in Threat Response. 16.09.2026 8.8
CVE-2026-87113 Tanium addressed an improper access controls vulnerability in Threat Response. 16.09.2026 6.3
CVE-2026-87116 Tanium addressed a server-side request forgery vulnerability in Threat Response. 16.09.2026 6.5
CVE-2026-88592 16.09.2026
CVE-2026-70469 Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests 16.09.2026
CVE-2026-81866 Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration 16.09.2026
CVE-2026-82561 Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods 16.09.2026
CVE-2026-86089 Apache NiFi: Missing Process Group Authorization for Connector Migration 16.09.2026
CVE-2026-87976 Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles 16.09.2026
CVE-2026-76646 Apache MyFaces: Denial of Service via Unbounded Request Parsing 16.09.2026
CVE-2026-92474 GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free 16.09.2026
CVE-2026-63225 Redocly CLI: Path traversal when using `split` command 16.09.2026 4.4
CVE-2026-63325 Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `respect` 16.09.2026 7.8
CVE-2026-73462 On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the I 16.09.2026 6.5
CVE-2026-86071 Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root 16.09.2026 3.7
CVE-2026-92473 GPAC BIFS commands.c gf_sg_command_del use after free 16.09.2026
CVE-2026-73456 Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. 17.09.2026 10
CVE-2026-73457 Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users. 16.09.2026 5.3
CVE-2026-91104 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026
CVE-2026-91105 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026
CVE-2026-91106 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026
CVE-2026-73442 On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for 16.09.2026 3
CVE-2026-73443 On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indef 16.09.2026 4.7
CVE-2026-79298 16.09.2026
CVE-2026-81876 HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service 16.09.2026 7.5
CVE-2026-86043 Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix CVE-2026-50197) 16.09.2026 7.5
CVE-2026-91100 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 16.09.2026
CVE-2026-91101 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 16.09.2026
CVE-2026-91102 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 16.09.2026
CVE-2026-91103 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 16.09.2026
CVE-2026-59823 LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM Proxy 16.09.2026
CVE-2026-68536 Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability 16.09.2026
CVE-2026-77360 oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass 16.09.2026
CVE-2026-81875 HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service 16.09.2026 7.5
CVE-2026-82399 CoreDNS: Unauthenticated memory exhaustion in custom transports 16.09.2026 7.5
CVE-2026-86003 CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP 16.09.2026 7.5
CVE-2026-91097 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 16.09.2026
CVE-2026-91098 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026
CVE-2026-91099 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 16.09.2026
CVE-2026-92472 GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free 16.09.2026
CVE-2026-38999 16.09.2026
CVE-2026-46352 Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock 16.09.2026 7.5
CVE-2026-75025 Mattermost Desktop local network access from server-rendered content 16.09.2026 4.7
CVE-2026-75516 RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement 16.09.2026
CVE-2026-81176 Svelte devalue: DoS via malformed input 16.09.2026 5.3
CVE-2026-92729 SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints 16.09.2026
CVE-2026-63126 Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799) 16.09.2026 7.5
CVE-2026-92417 Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference 16.09.2026
CVE-2026-92418 ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting 16.09.2026
CVE-2026-88593 16.09.2026
CVE-2026-69147 vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation 16.09.2026 6.5
CVE-2026-92416 Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion 16.09.2026
CVE-2026-47094 SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id} 16.09.2026
CVE-2026-51990 16.09.2026
CVE-2026-92413 Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference 16.09.2026
CVE-2026-92604 Scirius through 3.8.0 Arbitrary File Write via PCAP Upload 16.09.2026
CVE-2026-92605 IRIS through 2.4.29 Unauthorized Comment Access via Object ID 16.09.2026
CVE-2026-92716 Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation 16.09.2026
CVE-2026-92717 Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub 16.09.2026
CVE-2026-92718 Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache 16.09.2026
CVE-2026-92719 Quickwit through 0.9.0 SSRF via SQS queue_url Parameter 16.09.2026
CVE-2026-92720 Kubero through 3.1.1 Unauthenticated Notifications API Access 16.09.2026
CVE-2026-84397 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) 16.09.2026 5.4
CVE-2026-18120 Missing Authorization in legacy Express entries search endpoint allows disclosure of Express entry data 16.09.2026
CVE-2026-85387 Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access 16.09.2026
CVE-2026-92406 SourceCodester Inventory and Monitoring System btn_functions.php add sql injection 16.09.2026
CVE-2026-20234 Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities 17.09.2026 9.9
CVE-2026-20305 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20306 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.9
CVE-2026-20331 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities 17.09.2026 9.6
CVE-2026-42784 Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion 16.09.2026
CVE-2026-76420 Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability 17.09.2026 9
CVE-2026-92405 SourceCodester Inventory and Monitoring System index.php sql injection 16.09.2026
CVE-2026-92402 ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization 16.09.2026
CVE-2026-57173 vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions 16.09.2026 6.5
CVE-2026-85385 Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field 16.09.2026
CVE-2026-85386 Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block 16.09.2026
CVE-2026-85756 SSH.NET: ScpClient allows server-side RCE via default SCP path handling 16.09.2026 7.5
CVE-2026-87028 Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields 16.09.2026
CVE-2026-87031 Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation 16.09.2026
CVE-2026-68904 node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion 16.09.2026 7
CVE-2026-71182 16.09.2026 3
CVE-2026-84993 MikroORM: SQL injection via unvalidated order direction in orderBy 16.09.2026 6.5
CVE-2026-85731 oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) 16.09.2026 8.8
CVE-2026-85732 oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing 16.09.2026 4.7
CVE-2026-86358 17.09.2026 6.5
CVE-2026-86359 17.09.2026 8.5
CVE-2026-92401 ChangeWeDer crm improper authentication 16.09.2026
CVE-2026-59944 Composer: CVE-2026-59946 fix bypass via symlinked package bin path 16.09.2026 6.1
CVE-2026-59974 Stanza: Zip Slip Path Traversal in Model/Resource Extraction 16.09.2026 7.8
CVE-2026-69200 node-opcua: Prototype Pollution via internal `fieldsToJson()` implementation (Related to CVE-2024-57086) 16.09.2026 3.7
CVE-2026-71179 17.09.2026 7.3
CVE-2026-71180 17.09.2026 8.2
CVE-2026-71181 16.09.2026 3
CVE-2026-92398 Ruijie RG-EW3000GX user_list_note admin os command injection 16.09.2026
CVE-2026-92399 GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow 16.09.2026
CVE-2026-92600 Guns through 8.3.5 Information Disclosure via Missing Permission Check 16.09.2026
CVE-2026-92601 Guns through 8.3.5 Improper Access Control via SysNoticeController 16.09.2026
CVE-2026-92602 TDuck survey form through 5.3 Server-Side Request Forgery via Unvalidated Webhook URL 16.09.2026
CVE-2026-92603 ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController 16.09.2026
CVE-2026-61593 djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session 16.09.2026 8.1
CVE-2026-17526 Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts 16.09.2026
CVE-2026-19607 Keycloak-services: keycloak-services: broker-originated username collision causes account lockout 16.09.2026
CVE-2026-90999 Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment 16.09.2026
CVE-2026-92397 Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection 16.09.2026
CVE-2025-59953 LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy 16.09.2026 9.8
CVE-2026-61595 djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data 16.09.2026 7.7
CVE-2026-70416 16.09.2026 10
CVE-2026-92615 Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed 16.09.2026
CVE-2026-92625 Control iD iDSecure Unauthenticated Denial of Service 16.09.2026 7.5
CVE-2026-92626 Control iD iDSecure Unauthenticated Denial of Service 16.09.2026 7.5
CVE-2025-43936 17.09.2026 8.1
CVE-2026-26947 16.09.2026 6.7
CVE-2026-76104 16.09.2026 5.5
CVE-2026-92385 SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting 16.09.2026
CVE-2026-92627 Heap Use-After-Free in H5T__conv_f_f 16.09.2026
CVE-2025-36591 16.09.2026 4.4
CVE-2026-82410 Pocketbase: Unhandled panic in worker goroutines 16.09.2026
CVE-2026-92383 PbootCMS User Management UserController.php mod cross-site request forgery 16.09.2026
CVE-2026-18212 Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state 16.09.2026
CVE-2026-63127 RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery 16.09.2026 8.2
CVE-2026-74909 Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments 16.09.2026
CVE-2026-79651 Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching 16.09.2026
CVE-2026-84858 Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass 16.09.2026 8.8
CVE-2026-84859 Scada-LTS Authenticated Blind SQL Injection 16.09.2026 6.5
CVE-2026-84860 Scada-LTS DWR Authorization Bypass - Systemic 16.09.2026 8.8
CVE-2026-63128 RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service 16.09.2026 7.5
CVE-2026-77409 RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking 16.09.2026
CVE-2026-77411 RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr 16.09.2026
CVE-2026-77412 RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client 16.09.2026
CVE-2026-92381 PbootCMS Template Rendering ContentController.php decode_string cross site scripting 16.09.2026
CVE-2026-77403 RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation 16.09.2026
CVE-2026-77404 RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection 16.09.2026
CVE-2026-77405 RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser 16.09.2026
CVE-2026-77406 RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration 16.09.2026
CVE-2026-77407 RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields 16.09.2026
CVE-2026-77410 RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation 16.09.2026
CVE-2026-92395 @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 16.09.2026 9.1
CVE-2026-92565 Rallly before 4.15.0 Information Disclosure via polls.get 16.09.2026 5.3
CVE-2026-92566 DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview 16.09.2026 8.2
CVE-2026-92567 TDuck survey form through 5.0 Unauthorized Data Modification 16.09.2026
CVE-2026-92568 MLRun through 1.11.0 Server-Side Request Forgery via Webhook 16.09.2026
CVE-2026-92569 Hippo4j through 1.5.0 SSRF via clientAddress Parameter 16.09.2026 4.3
CVE-2026-92570 reNgine through 2.2.0 Unauthorized Configuration File Read 16.09.2026
CVE-2026-92571 16.09.2026
CVE-2026-92616 FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance 16.09.2026
CVE-2026-63671 @nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration 16.09.2026 8.1
CVE-2026-77401 Zope AccessControl: Information disclosure through Python string `format` and `format_map` functions 16.09.2026 6.8
CVE-2026-77408 RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow 16.09.2026
CVE-2026-92380 WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery 16.09.2026
CVE-2026-19033 Unauthenticated IXFR deltas are applied to the live zone before TSIG verification 16.09.2026 6.5
CVE-2026-19666 Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path 16.09.2026 7.5
CVE-2026-19668 Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching 16.09.2026 5.3
CVE-2026-61709 OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user 16.09.2026 5.3
CVE-2026-75029 Message parser retains every identical singleton RDATA, enabling wire-to-work amplification 16.09.2026 5.3
CVE-2026-76163 named aborts on a TKEY query when the user configuration has no global options statement 16.09.2026 7.5
CVE-2026-76825 RestrictedPython: Sandbox escape via string.Formatter field resolution 16.09.2026 8.4
CVE-2026-77119 NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets 16.09.2026 5.9
CVE-2026-80274 Validating resolver can abort while caching a mismatched NOQNAME proof 16.09.2026 7.5
CVE-2026-82964 Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sys 16.09.2026 8.8
CVE-2026-84997 react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU 16.09.2026 7.5
CVE-2026-88064 Backstage: Improper input validation in TechDocs MkDocs configuration 16.09.2026 8.8
CVE-2026-88976 @platejs/core HTML deserialization can trigger browser behavior during parsing 16.09.2026 6.1
CVE-2026-89031 Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post 16.09.2026
CVE-2026-92087 @fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth 16.09.2026 8.1
CVE-2026-92366 code-projects Matrimonial System Regular Search search.php sql injection 16.09.2026
CVE-2026-61598 Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler 16.09.2026
CVE-2026-77692 Unauthenticated remote crash of named via a single DoH SIG(0) request 16.09.2026 7.5
CVE-2026-78301 Out-of-zone database nodes can become authoritative zone cuts 16.09.2026 5.8
CVE-2026-81563 SVCB AliasMode additional-data error leaks qpcache references 16.09.2026 7.5
CVE-2026-89029 Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler 16.09.2026
CVE-2026-89030 Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user 16.09.2026
CVE-2026-92365 vllm-project vllm thinking_budget_state.py algorithmic complexity 16.09.2026
CVE-2026-19662 qpcache NOQNAME proof use-after-free crashes recursive resolver 16.09.2026 5.9
CVE-2026-19941 checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof 16.09.2026 5.9
CVE-2026-61590 djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG 16.09.2026 7.4
CVE-2026-92122 16.09.2026
CVE-2026-92123 16.09.2026
CVE-2026-92124 16.09.2026
CVE-2026-92125 16.09.2026
CVE-2026-92126 16.09.2026
CVE-2026-92127 16.09.2026
CVE-2026-92128 16.09.2026
CVE-2026-92129 16.09.2026
CVE-2026-92130 16.09.2026
CVE-2026-92131 16.09.2026
CVE-2026-92132 16.09.2026
CVE-2026-92133 16.09.2026
CVE-2026-92134 16.09.2026
CVE-2026-92135 16.09.2026
CVE-2026-92136 16.09.2026
CVE-2026-92137 16.09.2026
CVE-2026-92138 16.09.2026
CVE-2026-92139 16.09.2026
CVE-2026-92140 16.09.2026
CVE-2026-92141 16.09.2026
CVE-2026-19667 Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` 16.09.2026 7.5
CVE-2026-81736 Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees 16.09.2026 7.5
CVE-2026-92364 itsourcecode Leave Management System index.php sql injection 16.09.2026
CVE-2026-85104 Brain stimulation parameters can be modified via Bluetooth in Sooma 16.09.2026
CVE-2026-92363 ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption 16.09.2026
CVE-2026-56719 MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX 16.09.2026
CVE-2026-73177 16.09.2026
CVE-2026-89028 MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX 16.09.2026
CVE-2026-91843 Stack overflow in login process to the Security Management and Log Servers 17.09.2026 9.8
CVE-2026-92362 ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption 16.09.2026
CVE-2026-92466 microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking 16.09.2026
CVE-2026-92467 microservices-platform through 6.0.0 Unverified Password Change via /users/password 16.09.2026
CVE-2026-92468 microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center 16.09.2026
CVE-2026-92469 microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check 16.09.2026
CVE-2026-73172 16.09.2026
CVE-2026-73173 16.09.2026
CVE-2026-73174 16.09.2026
CVE-2026-73175 16.09.2026
CVE-2026-73176 16.09.2026
CVE-2026-92361 ag-ui-protocol ag-ui SSE Client client.go resource consumption 16.09.2026
CVE-2026-73165 16.09.2026
CVE-2026-73166 16.09.2026
CVE-2026-73167 16.09.2026
CVE-2026-73169 16.09.2026
CVE-2026-73170 16.09.2026
CVE-2026-73171 16.09.2026
CVE-2026-19535 16.09.2026
CVE-2026-73163 16.09.2026
CVE-2026-73164 16.09.2026
CVE-2026-92360 ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation 16.09.2026
CVE-2026-88817 Privilege escalation via legacy access group creation endpoint 16.09.2026
CVE-2026-92359 ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy 16.09.2026
CVE-2026-40854 Session auth bypass via cookie value in T-Mobile 5G Box IDU routers 16.09.2026
CVE-2026-40855 Command Injection in T-Mobile 5G Box IDU router via ping functionality 16.09.2026
CVE-2026-40856 Config disclosure in T-Mobile 5G Box IDU routers 16.09.2026
CVE-2026-40857 CSRF token bypass in T-Mobile 5G Box IDU routers 16.09.2026
CVE-2026-58146 Unauthorized remote code execution in T-Mobile 5G Box IDU routers 16.09.2026
CVE-2026-58147 Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers 16.09.2026
CVE-2026-92465 WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability 16.09.2026 7.6
CVE-2026-92455 yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints 16.09.2026
CVE-2026-92456 yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints 16.09.2026
CVE-2026-92457 yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice 16.09.2026
CVE-2026-92458 yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale 16.09.2026
CVE-2026-92459 yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint 16.09.2026
CVE-2026-92460 yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing 16.09.2026
CVE-2026-92461 yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint 16.09.2026
CVE-2026-92462 yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep 16.09.2026
CVE-2026-92463 yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listing 16.09.2026
CVE-2026-92357 a2ui-project a2ui Model Processor model-processor.ts information disclosure 16.09.2026
CVE-2026-86107 Security Advisory 0180 16.09.2026 5.9
CVE-2026-89794 ksmbd: zero pipe read compound padding 16.09.2026
CVE-2026-89795 PCI: Allow per function PCI slots to fix slot reset on s390 16.09.2026 8.4
CVE-2026-89796 mm/damon/core: avoid infinite kdamond_merge_regions() internal loop 16.09.2026
CVE-2026-89797 power: supply: ab8500_fg: fix use-after-free on remove 16.09.2026
CVE-2026-89798 rpcrdma: arm rn_done before publishing the notification 16.09.2026
CVE-2026-89799 bpf: Disable preemption in bpf_get_stackid 16.09.2026 7.8
CVE-2026-89800 drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE 16.09.2026
CVE-2026-89801 drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE 16.09.2026 7.8
CVE-2026-89802 drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op 16.09.2026
CVE-2026-89803 drm/nouveau: unsubscribe the channel-kill event before the fence context 16.09.2026 7.8
CVE-2026-89804 drm/nouveau/dmem: fix mismatched DMA unmap size for large folios 16.09.2026 8.8
CVE-2026-89805 drm/pagemap: Fix folio allocation fallback and use-after-put 16.09.2026 7.8
CVE-2026-89806 drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation 16.09.2026 8.4
CVE-2026-89807 drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore 16.09.2026
CVE-2026-89808 drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram 16.09.2026 7.8
CVE-2026-89809 drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds 16.09.2026
CVE-2026-89810 drm/amdkfd: Fix error path at svm_migrate_copy_to_ram 16.09.2026 7.8
CVE-2026-89811 drm/amdkfd: Add TLB flush after MES queue eviction/suspension 16.09.2026 8.8
CVE-2026-89812 drm/amdgpu: force complete the MES ring fences on reset 16.09.2026
CVE-2026-89813 drm/amdgpu: force complete the KIQ ring fences on reset 16.09.2026
CVE-2026-89814 drm/amdgpu: clamp the isolation index for rings outside a partition 16.09.2026 7.8
CVE-2026-89815 drm/ttm: Drop tt->restore after successful restore 16.09.2026 7.8
CVE-2026-89816 drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used 16.09.2026
CVE-2026-89817 drm/gud: NUL-terminate TV mode names read from the device 16.09.2026
CVE-2026-89818 drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check 16.09.2026 7.1
CVE-2026-89819 drm/amd/display: validate plane degamma LUT size for private color prop 16.09.2026 7.8
CVE-2026-89820 drm/amd/display: fix dc_lock leak on GPU reset error paths 16.09.2026
CVE-2026-89821 drm/amd/display: avoid divide-by-zero in __is_lut_linear() 16.09.2026
CVE-2026-89822 drm/i915: Guard against NULL driver_data in i915_pci_probe() 16.09.2026
CVE-2026-89823 drm: fix race between partial drm_dev_register() failure and ioctl 16.09.2026 7.8
CVE-2026-89824 drm/panel-edp: fix i2c adapter leak on probe failure 16.09.2026
CVE-2026-89825 drm/panthor: fix firmware control interface bounds checks 16.09.2026 7.8
CVE-2026-89826 drm/panthor: harden firmware build-info bounds checks 16.09.2026 7.1
CVE-2026-89827 drm/amdgpu: avoid force-completing uninitialized UVD rings 16.09.2026
CVE-2026-89828 drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() 16.09.2026
CVE-2026-89829 f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() 16.09.2026 7.8
CVE-2026-89830 f2fs: fix valid block count leak on data block allocation failure 16.09.2026
CVE-2026-89831 f2fs: protect critical_task_priority updates with s_umount 16.09.2026
CVE-2026-89832 f2fs: fix to clear dirty flag on folio in error path 16.09.2026 7.8
CVE-2026-89833 f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() 16.09.2026
CVE-2026-89834 f2fs: fix to migrate all curseg types during free_segment_range 16.09.2026
CVE-2026-89835 f2fs: avoid NULL checkpoint thread access in sysfs 16.09.2026
CVE-2026-89836 f2fs: fix folio_nr_pages() race after put in large folio invalidate 16.09.2026 7.8
CVE-2026-89837 f2fs: fix dentry folio leak in find_in_level 16.09.2026
CVE-2026-89838 f2fs: limit recovery filename logging to stored length 16.09.2026 7.1
CVE-2026-89839 f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() 16.09.2026
CVE-2026-89840 f2fs: validate MOVE_RANGE destination size 16.09.2026 7.1
CVE-2026-89841 f2fs: only redirty pinned folios in redirty_blocks 16.09.2026 7.8
CVE-2026-89842 scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started 16.09.2026
CVE-2026-89843 scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak 16.09.2026
CVE-2026-89844 scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition 16.09.2026 8.8
CVE-2026-89845 scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() 16.09.2026
CVE-2026-89846 scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read 16.09.2026 9.1
CVE-2026-89847 scsi: qla2xxx: Avoid double completion in async IOCB timeout 16.09.2026 9.8
CVE-2026-89848 scsi: qla2xxx: Quiesce response IRQ before freeing request queue 16.09.2026 8.1
CVE-2026-89849 scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path 16.09.2026 8.8
CVE-2026-89850 scsi: qla2xxx: Don't query firmware state while chip is down 16.09.2026
CVE-2026-89851 scsi: qla2xxx: Fix FCE trace enable parsing in debugfs 16.09.2026
CVE-2026-89852 scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() 16.09.2026
CVE-2026-89853 scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump 16.09.2026
CVE-2026-89854 scsi: qla2xxx: Fix cs84xx use-after-free on host teardown 16.09.2026 7.8
CVE-2026-89855 scsi: qla2xxx: Serialize flash version read in reset handler 16.09.2026
CVE-2026-89856 scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation 16.09.2026 8.4
CVE-2026-89857 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject 16.09.2026 9.8
CVE-2026-89858 scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() 16.09.2026
CVE-2026-89859 scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak 16.09.2026
CVE-2026-89860 scsi: qla2xxx: Initialize NVMe abort_work once at submission 16.09.2026 8.8
CVE-2026-89861 scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() 16.09.2026 8.1
CVE-2026-89862 scsi: qla2xxx: Fix BSG job leak on validate flash image error path 16.09.2026
CVE-2026-89863 scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check 16.09.2026 7.5
CVE-2026-89864 scsi: qla2xxx: Bound i2c->length in I2C bsg handlers 16.09.2026
CVE-2026-89865 scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers 16.09.2026
CVE-2026-89866 media: chips-media: wave5: Resume device before setting EOS flag 16.09.2026
CVE-2026-89867 media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued 16.09.2026
CVE-2026-89868 media: chips-media: wave5: Add timeout while stop_streaming 16.09.2026
CVE-2026-89869 media: qcom: iris: use disable_irq() during power-off 16.09.2026
CVE-2026-89870 media: zoran: Avoid freeing a registered video_device twice 16.09.2026 7.8
CVE-2026-89871 media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure 16.09.2026
CVE-2026-89872 media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link 16.09.2026
CVE-2026-89873 media: v4l2-ctrls: validate HEVC EXT SPS RPS counts 16.09.2026 7.8
CVE-2026-89874 media: v4l2-async: avoid deleting unlinked ASC entry on link error 16.09.2026
CVE-2026-89875 media: ti: vpe: quiesce overflow recovery before freeing streams 16.09.2026 7.8
CVE-2026-89876 media: tda18250: fix possible integer overflow 16.09.2026
CVE-2026-89877 media: saa7164: fix cleanup on resource allocation failure 16.09.2026 8.4
CVE-2026-89878 media: s2255: check firmware size before reading trailing marker 16.09.2026
CVE-2026-89879 media: s2255: bound JPEG frame size before copying into the buffer 16.09.2026
CVE-2026-89880 media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure 16.09.2026 7.8
CVE-2026-89881 media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak 16.09.2026
CVE-2026-89882 media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow 16.09.2026 7.8
CVE-2026-89883 media: rc: sunxi-cir: Unregister rc device on probe failure 16.09.2026 7.8
CVE-2026-89884 media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup 16.09.2026
CVE-2026-89885 media: platform: mtk-mdp3: Fix SCP device refcounting 16.09.2026 8.4
CVE-2026-89886 media: intel/ipu6: fix async notifier cleanup leak on parse error 16.09.2026
CVE-2026-89887 media: i2c: ov7740: fix use-after-destroy in remove 16.09.2026 7.8
CVE-2026-89888 media: i2c: ov02a10: fix endpoint parsing use-after-free 16.09.2026 7.8
CVE-2026-89889 media: i2c: imx415: Release runtime PM reference on VBLANK error 16.09.2026
CVE-2026-89890 media: go7007: defer the ALSA v4l2 put until card release 16.09.2026 7.8
CVE-2026-89891 media: em28xx: fix use-after-free of dev_next->devlist on disconnect 16.09.2026
CVE-2026-89892 media: em28xx: defer audio-only extension registration 16.09.2026
CVE-2026-89893 media: cx23885: cancel NetUP CI work before teardown 16.09.2026 7.8
CVE-2026-89894 media: cx231xx: reject geometry changes while the VBI queue is busy 16.09.2026 7.8
CVE-2026-89895 media: cobalt: Avoid freeing ALSA private data twice 16.09.2026
CVE-2026-89896 media: cedrus: fix memory leak in cedrus_init_ctrls() 16.09.2026
CVE-2026-89897 media: cec: Serialize exclusive follower delivery 16.09.2026 7.5
CVE-2026-89898 media: cec: extron-da-hd-4k-plus: add sanity check 16.09.2026 8.8
CVE-2026-89899 media: cec: disable delayed work before freeing an interrupted transmit 16.09.2026 7.8
CVE-2026-89900 media: cec: core: Fix kmemleak due to missed rc_free_device() call 16.09.2026
CVE-2026-89901 media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref 16.09.2026
CVE-2026-89902 LoongArch: Avoid preempt count underflow without probe 16.09.2026 7.8
CVE-2026-89903 LoongArch: Do not save/restore percpu base register in rethook trampoline 16.09.2026 7.8
CVE-2026-89904 LoongArch: Fix acpi_package_ids[] array overflow 16.09.2026 8.4
CVE-2026-89905 LoongArch: BPF: Move arena register slot below TCC context 16.09.2026
CVE-2026-89906 LoongArch: BPF: Refactor jump offset calculation in tail call 16.09.2026 7.8
CVE-2026-89907 LoongArch: KVM: Validate MSI data before routing it to EIOINTC 16.09.2026 8.8
CVE-2026-89908 LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY 16.09.2026 8.8
CVE-2026-89909 LoongArch: KVM: Free init resources if kvm_init() fails 16.09.2026
CVE-2026-89910 LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc 16.09.2026 7.3
CVE-2026-89911 KVM: arm64: Correctly cap TLBI Range to the architural limit 16.09.2026 7.9
CVE-2026-89912 KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save 16.09.2026 7.1
CVE-2026-89913 KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables 16.09.2026 8.8
CVE-2026-89914 KVM: arm64: Sign-extend VA for range-based TLBI invalidation 16.09.2026 9.3
CVE-2026-89915 KVM: arm64: Remove VM-wide VNCR mapping counter 16.09.2026 9.3
CVE-2026-89916 KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry 16.09.2026 9.3
CVE-2026-89917 KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping 16.09.2026
CVE-2026-89918 KVM: arm64: Correctly handle end of VA space TLBI invalidation 16.09.2026 9.3
CVE-2026-89919 KVM: s390: keyop: use mmu_lock to read gmap->asce 16.09.2026 7.8
CVE-2026-89920 KVM: s390: Fix memory corruption by not reinjecting CK machine checks 16.09.2026 7.8
CVE-2026-89921 KVM: s390: Zero initialize data structures for inject_pfault_token 16.09.2026
CVE-2026-89922 KVM: s390: Take srcu when importing watchpoint data 16.09.2026 7.8
CVE-2026-89923 KVM: s390: Free guest debug data on vcpu destroy 16.09.2026
CVE-2026-89924 KVM: s390: Fix old_data leak in guest debug error path 16.09.2026
CVE-2026-89925 KVM: s390: Fix memory leak in guest debug handling 16.09.2026
CVE-2026-89926 KVM: s390: Fix length check __import_wp_info() 16.09.2026
CVE-2026-89927 KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock 16.09.2026 7.1
CVE-2026-89928 KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk 16.09.2026 8.8
CVE-2026-89929 KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU 16.09.2026 8.8
CVE-2026-89930 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter 16.09.2026 9.3
CVE-2026-89931 KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit 16.09.2026
CVE-2026-89932 KVM: nVMX: Always flush vpid02 on first use 16.09.2026 8.8
CVE-2026-89933 iio: pressure: dps310: fix NULL pointer dereference on ACPI probe 16.09.2026
CVE-2026-89934 iio: light: ltrf216a: fix runtime PM reference leak in error path 16.09.2026
CVE-2026-89935 iio: light: apds9306: fix PM reference leak in apds9306_read_data() 16.09.2026
CVE-2026-89936 iio: dac: m62332: Fix regulator reference count imbalance 16.09.2026
CVE-2026-89937 iio: chemical: sgp30: Handle IAQ thread creation failure 16.09.2026
CVE-2026-89938 iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF 16.09.2026 7.8
CVE-2026-89939 iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable 16.09.2026
CVE-2026-89940 iio: buffer: Tie IIO dma fence lock lifetime to the fence 16.09.2026 7.8
CVE-2026-89941 iio: buffer: Make IIO DMA fence release RCU-safe 16.09.2026 7.8
CVE-2026-89942 iio: buffer: Fix potential use-after-free in anonymous buffer release 16.09.2026 7.8
CVE-2026-89943 ASoC: loongson: Fix error handling in ACPI property parsing 16.09.2026 8.4
CVE-2026-89944 ASoC: hdac_hda: Fix hlink refcount leak on component registration failure 16.09.2026
CVE-2026-89945 ASoC: cs35l34: drain threaded IRQ before runtime suspend 16.09.2026
CVE-2026-89946 ASoC: cs35l33: drain threaded IRQ before runtime suspend 16.09.2026
CVE-2026-89947 clk: meson: align gxbb_32k_clk_sel number of parents with actual count 16.09.2026 8
CVE-2026-89948 batman-adv: bla: fix freeing of claims on meshif deletion 16.09.2026
CVE-2026-89949 batman-adv: dat: avoid unaligned fault in IP extraction 16.09.2026
CVE-2026-89950 batman-adv: mcast: linearize skbuff for packet generation 16.09.2026
CVE-2026-89951 batman-adv: fix stale receive device on merged fragments 16.09.2026 8.8
CVE-2026-89952 mtd: rawnand: validate ONFI extended parameter page sections 16.09.2026
CVE-2026-89953 mtd: mtdoops: free page bitmap when the backing MTD is removed 16.09.2026
CVE-2026-89954 mtd: afs: validate v2 image info bounds 16.09.2026 8
CVE-2026-89955 s390/vfio-ap: Fix NULL deref in status_show() during queue probe 16.09.2026
CVE-2026-89956 s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects 16.09.2026
CVE-2026-89957 s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed 16.09.2026 8.8
CVE-2026-89958 s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL 16.09.2026
CVE-2026-89959 s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove 16.09.2026 8.8
CVE-2026-89960 s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() 16.09.2026 8.8
CVE-2026-89961 powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population 16.09.2026 7.8
CVE-2026-89962 powerpc/kexec_file: Prevent kexec range truncation 16.09.2026
CVE-2026-89963 powerpc/kexec_file: Fix null-ptr-def in extra size calculation 16.09.2026
CVE-2026-89964 parisc: eisa: Fix infinite loop when parsing invalid IRQ value 16.09.2026
CVE-2026-89965 nvdimm/btt: reject an arena whose nfree is below the lane count 16.09.2026 7.8
CVE-2026-89966 mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio 16.09.2026
CVE-2026-89967 mm/migrate_device: avoid out-of-bounds writes for compound folios 16.09.2026 7.8
CVE-2026-89968 nvmet-tcp: reject unsolicited H2CData PDUs 16.09.2026 7.5
CVE-2026-89969 nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU 16.09.2026 9.8
CVE-2026-89970 nvmet-auth: Synchronize timeout work during SQ teardown 16.09.2026 9.8
CVE-2026-89971 nvme: skip the zoned limits update if the zone info query failed 16.09.2026 7.5
CVE-2026-89972 nvme: add missing SRCU grace period in error path 16.09.2026 9.8
CVE-2026-89973 nvme-tcp: check the data direction of a C2HData PDU 16.09.2026 8.2
CVE-2026-89974 nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails 16.09.2026 7.5
CVE-2026-89975 nvme-fabrics: fix DHCHAP secret leak on parse failure 16.09.2026
CVE-2026-89976 accel/ethosu: fix job completion fence cleanup 16.09.2026
CVE-2026-89977 accel/ethosu: check MMIO mapping errors in probe 16.09.2026
CVE-2026-89978 accel/amdxdna: return early from a zero-length flush 16.09.2026
CVE-2026-89979 ALSA: pcm: Fix race between non-atomic ops and trigger-start 16.09.2026 7.8
CVE-2026-89980 ALSA: harmony: initialize locks before requesting IRQ 16.09.2026 8.4
CVE-2026-89981 arm64: Don't read GMID_EL1 when MTE is disabled 16.09.2026
CVE-2026-89982 i2c: mux: Fix channel node leak on adapter add failure 16.09.2026
CVE-2026-89983 i2c: core: fix debugfs UAF on adapter removal 16.09.2026
CVE-2026-89984 perf/x86/intel: Fix kernel address leakages in LBR stack 16.09.2026
CVE-2026-89985 memcg: keep folio's objcg same as its node 16.09.2026 7.8
CVE-2026-89986 mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() 16.09.2026 7.8
CVE-2026-89987 mm/huge_memory: transfer the pmd dirty bit to the folio on zap 16.09.2026
CVE-2026-89988 kprobes: Protect kprobe_blacklist with RCU 16.09.2026 7.8
CVE-2026-89989 ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() 16.09.2026
CVE-2026-89990 ceph: lock mutex in ceph_mds_check_access() 16.09.2026 9.8
CVE-2026-89991 bpf: Fix infinite loop in pcpu_freelist push with one possible CPU 16.09.2026
CVE-2026-89992 cpuidle: dt_idle_genpd: kfree() the original name allocation 16.09.2026 8.4
CVE-2026-89993 dmaengine: dw-edma: Initialize IRQ data before requesting IRQs 16.09.2026
CVE-2026-89994 dmaengine: fsl-edma: tracing: no ptr dereference during log output 16.09.2026 7.8
CVE-2026-89995 dma-direct: return struct page from dma_direct_alloc_from_pool() 16.09.2026 8.8
CVE-2026-89996 dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds 16.09.2026
CVE-2026-89997 dm: fix resume-vs-remove race 16.09.2026 7.8
CVE-2026-89998 dm: fix race when loading and unloading a table 16.09.2026 7.8
CVE-2026-89999 HID: wacom: validate report length in wacom_intuos_pro2_bt_irq 16.09.2026 8.1
CVE-2026-90000 HID: rmi: fix OOB access with undersized RMI reports 16.09.2026 8.8
CVE-2026-90001 HID: bpf: serialize device reference release in struct_ops destroy path 16.09.2026 7.8
CVE-2026-90002 ftrace: Take trace_array reference before accessing its ftrace_ops 16.09.2026 7.8
CVE-2026-90003 futex: Prevent rcuwait use-after-free during requeue PI 16.09.2026 7.8
CVE-2026-90004 mm/damon/core: handle region split failure in apply_min_nr_regions() 16.09.2026
CVE-2026-90005 samples/damon/wsse: handle damon_start() failure 16.09.2026
CVE-2026-90006 samples/damon/mtier: handle damon_stop() failure 16.09.2026
CVE-2026-90007 scsi: pm8001: Use rollback index when freeing MSI-X vectors 16.09.2026 7.8
CVE-2026-90008 scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame 16.09.2026 7.8
CVE-2026-90009 scsi: bsg: Fix TOCTOU in io_uring passthrough command setup 16.09.2026 7.8
CVE-2026-90010 scsi: bsg: Cap io_uring sense copy to max_response_len 16.09.2026 7.8
CVE-2026-90011 scsi: target: iscsi: Reserve a terminator byte for the login payload 16.09.2026 9.1
CVE-2026-90012 spi: Fix DMA mapping ownership on partial map failure 16.09.2026 9.8
CVE-2026-90013 tracing: Take trace_array reference when opening options file 16.09.2026 7.8
CVE-2026-90014 tracing: Have show_event_filters/triggers files take trace array ref 16.09.2026 7.8
CVE-2026-90015 xhci: fix lost bounce buffers on TDs spanning several ring segments 16.09.2026
CVE-2026-90016 staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() 16.09.2026 7.1
CVE-2026-90017 staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() 16.09.2026 7.1
CVE-2026-90018 staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() 16.09.2026 8.8
CVE-2026-90019 usb: gadget: fix null pointer dereference in usb_put_function_instance() 16.09.2026
CVE-2026-90020 USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() 16.09.2026
CVE-2026-90021 usb: gadget: f_midi: initialize work in f_midi_alloc() 16.09.2026
CVE-2026-90022 usb: gadget: f_midi2: fix use-after-free in string attribute show path 16.09.2026 7.8
CVE-2026-90023 usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() 16.09.2026
CVE-2026-90024 usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs 16.09.2026
CVE-2026-90025 usb: typec: ucsi: displayport: Fix OOB altmode array index 16.09.2026 7.7
CVE-2026-90026 usb: typec: qcom-pmic: cancel reset_work on stop 16.09.2026 7.8
CVE-2026-90027 usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop 16.09.2026 7.8
CVE-2026-90028 usb: typec: hd3ss3220: track VBUS enable state per consumer 16.09.2026
CVE-2026-90029 usb: storage: realtek_cr: fix use-after-free on disconnect 16.09.2026
CVE-2026-90030 usb: dwc3: clear forceRM when issuing EndTransfer 16.09.2026 7.8
CVE-2026-90031 usb-storage: ene_ub6250: fix race between scan work and probe 16.09.2026
CVE-2026-90032 media: usbtv: keep device alive while ALSA card exists 16.09.2026 7.8
CVE-2026-90033 ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() 16.09.2026
CVE-2026-90034 usb: image: mdc800: change kmalloc() to kzalloc() 16.09.2026
CVE-2026-90035 drm/amd/display: fix division by zero in get_estimated_bw() 16.09.2026
CVE-2026-90036 NFSD: Prevent client use-after-free during blocked-lock reaping 16.09.2026 9.8
CVE-2026-90037 NFSD: Prevent client use-after-free during close_lru reaping 16.09.2026 9.8
CVE-2026-90038 NFSD: Prevent client use-after-free during export state revocation 16.09.2026 9.8
CVE-2026-90039 NFSD: Guard admin state-revocation walks with NFSD_NET_UP 16.09.2026
CVE-2026-90040 KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped 16.09.2026
CVE-2026-90041 HID: sony: clean up device list on probe failure 16.09.2026 8.8
CVE-2026-90042 ceph: properly decrypt filenames in vmalloc() buffers 16.09.2026 9.8
CVE-2026-90043 zram: fix slot lock bit position on big-endian 64-bit 16.09.2026 7.8
CVE-2026-90044 usb: gadget: f_fs: Fix Use-After-Free in AIO error path 16.09.2026 7.8
CVE-2026-90045 USB: gadget: ffs: fix mm lifetime handling 16.09.2026 7.8
CVE-2026-90046 mm/page_alloc: don't spin_trylock() in NMI on UP 16.09.2026 7.8
CVE-2026-90047 drm/xe: Don't hand out the flat CCS storage as usable VRAM 16.09.2026 7.8
CVE-2026-90048 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() 16.09.2026 9.8
CVE-2026-90049 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() 16.09.2026 9.3
CVE-2026-14916 Kong API Gateway Enterprise: JWT Algorithm-Confusion 16.09.2026
CVE-2026-86106 Security Advisory 0179 16.09.2026 9.6
CVE-2026-86585 Improper Verification of the Firmware Signature vulnerability 16.09.2026
CVE-2026-8462 OpenMeter SQL Injection in ClickHouse-backed Meter Definitions 16.09.2026
CVE-2026-92356 a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption 16.09.2026
CVE-2026-14917 Kong API Gateway Enterprise: SAML Authentication bypass 16.09.2026
CVE-2026-76151 Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module) 16.09.2026
CVE-2026-77190 Security Advisory 0177 16.09.2026 6.5
CVE-2026-86474 Improper Certificate Validation in the Firmware Download vulnerability 16.09.2026
CVE-2026-73440 Security Advisory 0178 16.09.2026 4.2
CVE-2026-73468 Security Advisory 0175 16.09.2026 6.5
CVE-2026-73469 Security Advisory 0176 16.09.2026 5.8
CVE-2026-89793 ublk: clear VM_MAYWRITE on read-only ublk char device mmap 16.09.2026 7.8
CVE-2026-73453 Security Advisory 0174 17.09.2026 10
CVE-2026-73455 Security Advisory 0173 16.09.2026 7.5
CVE-2026-73438 Security Advisory 0172 16.09.2026 5.3
CVE-2026-85628 Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability 16.09.2026
CVE-2026-59739 Apache ZooKeeper: Information disclosure via SetWatches reconnect replay 16.09.2026
CVE-2026-59969 Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode 16.09.2026
CVE-2026-79993 Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode 16.09.2026
CVE-2026-84439 Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources 16.09.2026
CVE-2026-84501 Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider 16.09.2026
CVE-2026-19640 Security Advisory 0170 16.09.2026 4.2
CVE-2026-73435 Security Advisory 0171 16.09.2026 8.2
CVE-2026-73436 Security Advisory 0171 16.09.2026 6.5
CVE-2026-76186 Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity 16.09.2026
CVE-2026-76187 Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT 16.09.2026
CVE-2026-82310 Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access 16.09.2026
CVE-2026-86443 Cleartext Storage of Sensitive Information Vulnerability 16.09.2026
CVE-2026-86466 Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated 16.09.2026
CVE-2026-86792 Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration 16.09.2026
CVE-2026-73445 Security Advisory 0167 16.09.2026 4.9
CVE-2026-73463 Security Advisory 0169 16.09.2026 5.3
CVE-2026-82311 Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false 16.09.2026
CVE-2026-86462 Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions 16.09.2026
CVE-2026-86465 Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key 16.09.2026
CVE-2026-92081 fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses 16.09.2026 5.9
CVE-2026-2380 Security Advisory 0168 16.09.2026 7.4
CVE-2026-89776 vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes 16.09.2026
CVE-2026-89777 vfio/pci: clear vdev->msi_perm after freeing it on init failure 16.09.2026 8.8
CVE-2026-89778 isofs: fix out-of-bounds page array access on empty zisofs block 16.09.2026 9.8
CVE-2026-89779 fs/ntfs3: validate ef->size covers the record's name and value 16.09.2026 9.1
CVE-2026-89780 net: qualcomm: rmnet: restore skb->dev on deaggregated frames 16.09.2026
CVE-2026-89781 fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() 16.09.2026 8.4
CVE-2026-89782 fs/ntfs3: reject restart table growth beyond U16_MAX entries 16.09.2026 8.4
CVE-2026-89783 xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full 16.09.2026 9.8
CVE-2026-89784 SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 16.09.2026
CVE-2026-89785 fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init 16.09.2026
CVE-2026-89786 ext4: fix out-of-bounds read in ext4_read_inline_dir() 16.09.2026 9.1
CVE-2026-89787 ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() 16.09.2026
CVE-2026-89788 ksmbd: fix tree connection use-after-free in smb2_tree_connect() 16.09.2026 9.8
CVE-2026-89789 gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free 16.09.2026 7.8
CVE-2026-89790 ipv6: avoid divide by zero in rt6_multipath_rebalance 16.09.2026
CVE-2026-89791 perf: Fix use-after-free when perf mmap() revival races with the last munmap() 16.09.2026 7.8
CVE-2026-89792 ksmbd: prevent out-of-bounds reads in share config responses 16.09.2026 7.1
CVE-2026-73464 Security Advisory 0166 17.09.2026 8.8
CVE-2026-77860 'serve-expired' can bypass Unbound 'wait-limit' 16.09.2026 3.7
CVE-2026-77955 Possible ZONEMD verification bypass window 16.09.2026 4.4
CVE-2026-78227 Use-after-free in DoQ stream output buffer on reset re-transmission 16.09.2026 6.5
CVE-2026-80225 Possible degradation of service from continuous queries on the same TCP/DoT connection 16.09.2026 5.3
CVE-2026-81634 Possible heap buffer overflow during DNSSEC canonicalization 16.09.2026 7.5
CVE-2026-81642 Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY 16.09.2026
CVE-2026-82717 CNAME synthesis could lead to heap corruption 16.09.2026
CVE-2026-82720 Use-after-free in DoH stream cleanup code path 16.09.2026 5.9
CVE-2026-85501 Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC 16.09.2026 5.3
CVE-2026-86338 Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle 16.09.2026
CVE-2026-89775 KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation 16.09.2026 9.3
CVE-2026-73454 Security Advisory 0165 17.09.2026 8.1
CVE-2026-88255 mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot 16.09.2026
CVE-2026-89186 mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches 16.09.2026
CVE-2026-89774 Bluetooth: SCO: hold sk properly in sco_conn_ready 16.09.2026 8.8