CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG 13.09.2026 9.3
CVE-2026-90562 LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key 13.09.2026 9.2
CVE-2026-90493 Tonec Internet Download Manager Kernel Driver idmwfp.sys access control 13.09.2026 9.3
CVE-2026-90647 12.09.2026 9.1
CVE-2026-90558 sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers 12.09.2026 9.3
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution 12.09.2026 9.8
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation 12.09.2026 9.8
CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 12.09.2026 10
CVE-2026-87719 Deserialization of Untrusted Data in GitLab 12.09.2026 9.9
CVE-2026-90456 11.09.2026 9.2
CVE-2026-89697 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() 13.09.2026 9.1
CVE-2026-89702 nfsd: size fh_verify server sockaddr slot by xpt_locallen 13.09.2026 9.8
CVE-2026-89703 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations 13.09.2026 9.8
CVE-2026-89708 nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown 13.09.2026 9.8
CVE-2026-89712 NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock 13.09.2026 9.8
CVE-2026-89713 NFSD: check truncate permission under inode lock 13.09.2026 9.1
CVE-2026-80945 crypto: iaa - unmap dst before software fallback on decompress 13.09.2026 9.1
CVE-2026-80976 seg6: reset IP6CB after IPv6 decapsulation 13.09.2026 9.8
CVE-2026-80980 net/smc: stop killed, freed and out_of_sync sharing a byte 13.09.2026 9.8
CVE-2026-80981 net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() 13.09.2026 9.8
CVE-2026-80986 net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages 13.09.2026 9.8
CVE-2026-81002 xdp: fix zero-copy frame layout 13.09.2026 9.8
CVE-2026-89448 iommu/vt-d: Force requesting ACS when tboot is enabled 13.09.2026 9.3
CVE-2026-89478 sctp: drop a chunk if its transport was removed 13.09.2026 9.8
CVE-2026-89479 sctp: stop processing a packet once its association is deleted 13.09.2026 9.8
CVE-2026-89482 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone 13.09.2026 9.8
CVE-2026-89485 lockd: pin next file across nlm_inspect_file lock-drop 13.09.2026 9.8
CVE-2026-89492 ocfs2: validate directory-index entry counts when reading metadata 13.09.2026 9.8
CVE-2026-89494 ocfs2: validate lengths in dlm_mig_lockres_handler 13.09.2026 9.8
CVE-2026-89495 ocfs2: bound namelen in dlm_migrate_request_handler 13.09.2026 9.8
CVE-2026-89526 svcrdma: Validate Read chunk positions before reconstruction 13.09.2026 9.8
CVE-2026-89530 svcrdma: Reject inline replies that overflow the pull-up buffer 13.09.2026 9.8
CVE-2026-89532 svcrdma: Fix pcl_for_each_segment for empty chunks 13.09.2026 9.1
CVE-2026-89533 svcrdma: Fix offset arithmetic in read_chunk_range 13.09.2026 9.8
CVE-2026-89536 SUNRPC: wait for in-flight client TLS handshake callback 13.09.2026 9.8
CVE-2026-89537 SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 13.09.2026 9.1
CVE-2026-89538 SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field 13.09.2026 9.8
CVE-2026-89541 SUNRPC: harden gss_unwrap_resp_priv length checks 13.09.2026 9.8
CVE-2026-89542 SUNRPC: harden gss_krb5_unwrap_v2 against short tokens 13.09.2026 9.8
CVE-2026-89546 SUNRPC: close backchannel before destroying callback service 13.09.2026 9.8
CVE-2026-89550 SUNRPC: svcauth_gss: enforce krb5 token minimum length 13.09.2026 9.8
CVE-2026-89551 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow 13.09.2026 9.8
CVE-2026-89555 mpls: reload header after pskb_may_pull() 13.09.2026 9.8
CVE-2026-89558 md/raid10: fix still_degraded being inverted in raid10_sync_request() 13.09.2026 9.8
CVE-2026-89610 ntfs: verify run length exceeding volume boundary 13.09.2026 9.8
CVE-2026-89611 ntfs: validate non-resident attribute offsets 13.09.2026 9.8
CVE-2026-89612 ntfs: reject invalid MFT LCNs from boot sector 13.09.2026 9.8
CVE-2026-89613 ntfs: reject invalid empty mapping pairs 13.09.2026 9.8
CVE-2026-89614 ntfs: bound the free-cluster bitmap scan to the volume 13.09.2026 9.8
CVE-2026-89630 smb: client: restore the data_offset bound in is_valid_oplock_break() 13.09.2026 9.1
CVE-2026-89631 smb: client: reject a tree connect response whose byte count is too small 13.09.2026 9.1
CVE-2026-89633 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() 13.09.2026 9.8
CVE-2026-89634 smb: client: fix ALIGN() overflow in symlink_data() error context loop 13.09.2026 9.1
CVE-2026-89635 ksmbd: only rebind the reopened file's own oplock on durable reconnect 13.09.2026 9.8
CVE-2026-89636 smb: client: clear ce->tgthint in free_tgts() 13.09.2026 9.8
CVE-2026-89637 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 13.09.2026 9.8
CVE-2026-89643 audit: avoid dropping live tree ref on fsnotify rule autoremove 13.09.2026 9.8
CVE-2026-89649 ceph: bound xattr value length in __build_xattrs() 13.09.2026 9.1
CVE-2026-89650 ceph: bound num_export_targets array for mds info v2/v3 13.09.2026 9.1
CVE-2026-89651 ceph: bound MDSCapAuth path and fs_name decode in handle_session() 13.09.2026 9.8
CVE-2026-89652 ceph: bound copied dentry name length in NFS export get_name 13.09.2026 9.8
CVE-2026-89653 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode 13.09.2026 9.8
CVE-2026-89654 ceph: fix UAF in check_new_map() on session freed during unlock 13.09.2026 9.8
CVE-2026-89655 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock 13.09.2026 9.8
CVE-2026-89656 libceph: reject buckets with mismatched CRUSH ids 13.09.2026 9.8
CVE-2026-89658 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup 13.09.2026 9.8
CVE-2026-89659 NFSD: Prevent client use-after-free during delegation revoke 13.09.2026 9.8
CVE-2026-89660 NFSD: Prevent client use-after-free during admin state revocation 13.09.2026 9.8
CVE-2026-89662 NFSD: Prevent lock owner use-after-free during client teardown 13.09.2026 9.8
CVE-2026-89669 nfsd: initialize copy-notify stateid before publishing it 13.09.2026 9.8
CVE-2026-89671 nfsd: gate nfs3 setacl by argp->mask 13.09.2026 9.1
CVE-2026-89672 nfsd: gate nfs2 setacl by argp->mask 13.09.2026 9.1
CVE-2026-89674 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget 13.09.2026 9.8
CVE-2026-89675 nfsd: fix UAF in async copy cancel and shutdown 13.09.2026 9.8
CVE-2026-89676 nfsd: fix stale s2s_cp_stateids IDR entry for async COPY 13.09.2026 9.8
CVE-2026-89677 nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() 13.09.2026 9.8
CVE-2026-89681 nfsd: fix layout fence worker double-reference race 13.09.2026 9.8
CVE-2026-89686 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke 13.09.2026 9.8
CVE-2026-89688 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry 13.09.2026 9.8
CVE-2026-89689 nfsd: don't free session slots that are still in use 13.09.2026 9.8
CVE-2026-80926 ksmbd: fix use-after-free in oplock break notification 13.09.2026 9.8
CVE-2026-53952 GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw 11.09.2026 9.8
CVE-2026-54072 Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL 11.09.2026 9.3
CVE-2026-62103 WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-62105 WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-82617 Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns 11.09.2026 10
CVE-2026-72709 SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur 11.09.2026 9.3
CVE-2026-72710 SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection 11.09.2026 9.3
CVE-2026-54047 Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation 11.09.2026 9.2
CVE-2026-3869 11.09.2026 9.2
CVE-2026-89010 WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server 11.09.2026 9.3
CVE-2026-38056 ST Engineering iDirect iQ-Series Terminals Missing Authorization 11.09.2026 9.4
CVE-2026-87987 11.09.2026 10
CVE-2026-87988 11.09.2026 10
CVE-2026-87983 11.09.2026 9.2
CVE-2026-87984 11.09.2026 9.3
CVE-2026-87985 11.09.2026 10
CVE-2026-87986 11.09.2026 10
CVE-2026-89212 XML External Entity in Akana API Platform 11.09.2026 9.2
CVE-2026-80462 Privilege Escalation in Progress Chef Automate 11.09.2026 10
CVE-2026-84390 11.09.2026 9.6
CVE-2026-89243 WWBN AVideo Stored XSS via UserGroups setGroup_name 11.09.2026 9.2
CVE-2026-89249 AVideo YPTWallet Stored XSS via CryptoWallet Configuration 11.09.2026 9.3
CVE-2026-89253 AVideo Stored XSS via donationLink in watch page button 11.09.2026 9.3
CVE-2026-89254 AVideo CustomizeUser Stored XSS via field_name Parameter 11.09.2026 9.3
CVE-2026-89255 AVideo LoginControl Stored XSS via PGP Public Key 11.09.2026 9.3
CVE-2026-89256 AVideo Bookmark Plugin Stored XSS via Chapter Names 11.09.2026 9.3
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get 11.09.2026 9.3
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS 11.09.2026 9.3
CVE-2026-47839 Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin 11.09.2026 9.2
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 11.09.2026 9.1
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 11.09.2026 9.8
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.1
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 11.09.2026 9.1
CVE-2026-75940 11.09.2026 9.3
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-89094 10.09.2026 9.9
CVE-2026-89086 10.09.2026 9.1
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 11.09.2026 9.5
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 11.09.2026 9.3
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026 9.1
CVE-2026-65638 10.09.2026 9.2
CVE-2026-65639 10.09.2026 9.5
CVE-2026-68487 10.09.2026 9.9
CVE-2026-68488 10.09.2026 9.9
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 11.09.2026 9.3
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026 9.1
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 11.09.2026 9.3
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026 9.3
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026 9.3
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 10.09.2026 9.3
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026 9.3
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026 9.3
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026 9.3
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026 9.3
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026 9.3
CVE-2026-8323 Open Redirect in Armiya Information Technologies' Access Control System 10.09.2026 9.3
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables 10.09.2026 9.2
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 10.09.2026 9.5
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 10.09.2026 9.2
CVE-2026-88278 GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay 10.09.2026 9.8
CVE-2026-88285 GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service 10.09.2026 9.4
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 11.09.2026 9.9
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026 9.4
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 10.09.2026 9.3
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 10.09.2026 9
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 10.09.2026 9.6
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 09.09.2026 9.3
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026 9.2
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 10.09.2026 9.3
CVE-2026-67401 10.09.2026 9.9
CVE-2026-67403 09.09.2026 9
CVE-2026-68484 09.09.2026 9
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-80172 11.09.2026 9.8
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026 9.1
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026 10
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026 10
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module 09.09.2026 9.1
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist 09.09.2026 10
CVE-2026-21095 11.09.2026 9.2
CVE-2026-21096 11.09.2026 9.2
CVE-2026-21102 11.09.2026 9.3
CVE-2026-53939 OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption 09.09.2026 9.1
CVE-2026-53581 ntp: write path traversal 09.09.2026 9
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector 10.09.2026 9
CVE-2026-84197 09.09.2026 9.2
CVE-2026-19232 Adobe Experience Manager | Incorrect Authorization (CWE-863) 10.09.2026 9.9
CVE-2026-86464 09.09.2026 9.9
CVE-2026-48273 ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 09.09.2026 9.9
CVE-2026-75746 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 09.09.2026 9.1
CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 12.09.2026 9.9
CVE-2026-28659 09.09.2026 10
CVE-2026-49883 10.09.2026 10
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 11.09.2026 10
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability 11.09.2026 9.6
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 11.09.2026 9.3
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 11.09.2026 9.1
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability 11.09.2026 9
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability 11.09.2026 9.8
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability 11.09.2026 9.6
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability 11.09.2026 9.9
CVE-2026-82533 DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing 10.09.2026 9.4
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup 08.09.2026 9.2
CVE-2026-86729 WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize 10.09.2026 9.1
CVE-2026-86738 Snipe-IT before 8.7.0 CSS Injection via Custom CSS 08.09.2026 9.3
CVE-2026-12647 09.09.2026 9.9
CVE-2026-12645 09.09.2026 9.9
CVE-2026-12646 09.09.2026 9.9
CVE-2026-12650 09.09.2026 9.9
CVE-2026-12744 09.09.2026 9.8
CVE-2026-12745 09.09.2026 9.8
CVE-2026-61516 Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint 08.09.2026 9.3
CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint 09.09.2026 9.1
CVE-2026-73311 XenForo < 2.3.13 OAuth2 Authorization Code Reuse 10.09.2026 9.1
CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token 09.09.2026 9.1
CVE-2026-77089 Command Center API Authentication Bypass 09.09.2026 9.3
CVE-2026-78234 Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users 08.09.2026 9.9
CVE-2026-62645 08.09.2026 9.3
CVE-2026-62646 10.09.2026 9.1
CVE-2026-62647 08.09.2026 9.3
CVE-2026-67367 09.09.2026 9.2
CVE-2026-71376 OS Command Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71377 Command Argument Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 11.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 09.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 09.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 11.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 09.09.2026 10
CVE-2026-86478 09.09.2026 9.8
CVE-2026-86480 09.09.2026 9.8
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026 9.8
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 09.09.2026 9.8
CVE-2026-80238 08.09.2026 9.3
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 08.09.2026 9.2
CVE-2026-61410 09.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 08.09.2026 9.4
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 08.09.2026 9.8
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 11.09.2026 9.4
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 09.09.2026 9.2
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 08.09.2026 10
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection 08.09.2026 9.4
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection 11.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-90566 Rizwan17 inventory-management-system Registration register.php createUserAccount improper authorization 13.09.2026
CVE-2026-90565 Rizwan17 inventory-management-system dashboard.php access control 13.09.2026
CVE-2026-90564 quequnlong shiyi-blog chat sendMsg Endpoint index.vue SysChatMsgMapper.getChatMsgList cross site scripting 13.09.2026
CVE-2026-90563 maliangnansheng bbs-springboot ArticleController.java utils.toToc cross site scripting 13.09.2026
CVE-2026-90529 DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting 13.09.2026
CVE-2026-90528 TDuckApp tduck-platform Form Write View index.vue cross site scripting 13.09.2026
CVE-2026-90527 quequnlong shiyi-blog Add Message API index.vue cross site scripting 13.09.2026
CVE-2026-90526 SourceCodester School Registration and Fee System save_class.php sql injection 13.09.2026
CVE-2026-90525 itsourcecode Sales and Inventory System cust_pos_trans.php sql injection 13.09.2026
CVE-2026-90524 jaychouchannel Tourism-Management-System Update Endpoint missing authentication 13.09.2026
CVE-2026-90523 jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privileges management 13.09.2026
CVE-2026-90522 jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery 13.09.2026
CVE-2026-90521 jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization 13.09.2026
CVE-2026-90519 PHPGurukul Bank Locker Management System add-locker-form.php unrestricted upload 13.09.2026
CVE-2026-90520 jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationInterceptor.java improper authorization 13.09.2026
CVE-2026-90781 alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii_elem_id_parse() 13.09.2026
CVE-2026-90782 S2OPC through 1.7.3 NULL Pointer Dereference in alloc_notification_message_items() 13.09.2026 5.3
CVE-2026-90783 MKVToolNix through 101.0 Heap Buffer Overflow via avilib ODML Superindex Integer Wraparound 13.09.2026 7.8
CVE-2026-90518 PHPGurukul Bank Locker Management System sidebar.php access control 13.09.2026
CVE-2026-90517 PHPGurukul Bank Locker Management System view-assign-locker.php authorization 13.09.2026
CVE-2026-90776 Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing 13.09.2026
CVE-2026-90777 ESPnet before 202609 Remote Code Execution via Unsafe Deserialization 13.09.2026
CVE-2026-90778 SIPp through 3.7.7 Buffer Overflow via SIP To Header Tag 13.09.2026
CVE-2026-90779 SIPp through 3.7.7 Stack Buffer Overflow via createAuthHeader Algorithm Parameter 13.09.2026
CVE-2026-90780 SIPp through 3.7.7 Buffer Overflow via Oversized SIP Header Content 13.09.2026
CVE-2026-90516 SourceCodester School Registration and Fee System pay_report.php sql injection 13.09.2026
CVE-2026-90515 SourceCodester School Registration and Fee System delete_stud.php sql injection 13.09.2026
CVE-2026-90775 PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight 13.09.2026
CVE-2026-90514 SourceCodester School Registration and Fee System save_stud.php sql injection 13.09.2026
CVE-2026-90513 simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authentication 13.09.2026
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG 13.09.2026
CVE-2026-90562 LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key 13.09.2026
CVE-2026-90767 Froxlor before 2.3.12 SSH Key Injection via authorized_keys 13.09.2026
CVE-2026-90768 CAPEv2 through commit 471ee4b REST API Task Endpoints Missing Ownership Check 13.09.2026
CVE-2026-90769 Open Notebook before 1.11.0 Server-Side Request Forgery via link-source 13.09.2026
CVE-2026-90770 Spug through 3.4.0 Remote Code Execution via ping_check 13.09.2026
CVE-2026-90771 joi before 17.13.8 and 18.2.9 Prototype Pollution via messages 13.09.2026
CVE-2026-90772 Amundsen Frontend through 4.3.0 Stored XSS via Description 13.09.2026
CVE-2026-90773 procs through 0.14.12 Terminal Escape Sequence Injection via Command 13.09.2026
CVE-2026-90774 rustypaste before 0.18.1 Path Traversal via filename header 13.09.2026
CVE-2026-90511 GongShengyue OnlineBooks listSplit BooksServlet.java sql injection 13.09.2026
CVE-2026-90510 dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded key 13.09.2026
CVE-2026-90508 Chengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorization 13.09.2026
CVE-2026-90509 dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials 13.09.2026
CVE-2026-90504 vvbbnn00 WARP-Clash-API authorized missing authentication 13.09.2026
CVE-2026-90505 vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition 13.09.2026
CVE-2026-90506 vvbbnn00 WARP-Clash-API Save Account Job race condition 13.09.2026
CVE-2026-90507 vvbbnn00 WARP-Clash-API Subscription subscription.py get_surge_subscription access control 13.09.2026
CVE-2026-90502 stilleshan ServerStatus Stats Generation main.cpp cross site scripting 13.09.2026
CVE-2026-90503 Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure 13.09.2026
CVE-2026-90501 lenve vhr HrMapper.xml HrInfoController.updateHr privileges management 13.09.2026
CVE-2026-90500 lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload 13.09.2026
CVE-2026-90499 lenve vhr Password Update pass HrInfoController.updatePass improper authorization 13.09.2026
CVE-2026-90498 lenve vhr vhr.sql default credentials 13.09.2026
CVE-2026-77773 Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entry 13.09.2026
CVE-2026-80071 User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator 13.09.2026
CVE-2026-80072 User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect Parameters 13.09.2026
CVE-2026-86406 User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership Purchase 13.09.2026
CVE-2026-86407 User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membership Thank You Page 13.09.2026
CVE-2026-88764 Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref 13.09.2026
CVE-2026-88912 rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Privacy Modification via IDOR 13.09.2026
CVE-2026-88995 Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check 13.09.2026
CVE-2026-89080 Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demotion 13.09.2026
CVE-2026-90497 Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting 13.09.2026
CVE-2026-90496 Fengoffice Feng Office Reorder Handlers MoreController.class.php update_dimension_order sql injection 13.09.2026
CVE-2026-90679 13.09.2026 4.3
CVE-2026-90678 13.09.2026 7.5
CVE-2026-90495 Fengoffice Feng Office Legacy API CompanyWebsite.class.php instance->findAll sql injection 13.09.2026