| CVE-2026-105105 |
Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration |
03.10.2026 |
9.8 |
| CVE-2026-71885 |
MLS X.509 credential not bound to the LeafNode signature key |
03.10.2026 |
9.2 |
| CVE-2026-92084 |
Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output |
03.10.2026 |
9.1 |
| CVE-2026-87115 |
VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter |
03.10.2026 |
9.1 |
| CVE-2026-105080 |
|
03.10.2026 |
9.4 |
| CVE-2026-84411 |
MikroTik RouterOS Integer Underflow |
02.10.2026 |
9.3 |
| CVE-2026-95102 |
Monta monta.app Missing Authentication for Critical Function |
02.10.2026 |
9.3 |
| CVE-2026-75937 |
OS Command Injection in Digi Accelerated Linux (DAL OS) |
02.10.2026 |
9.4 |
| CVE-2026-82042 |
UTMStack < 11.2.16 Authentication Bypass via InternalApiKeyFilter |
02.10.2026 |
9.3 |
| CVE-2026-104019 |
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio |
02.10.2026 |
9.3 |
| CVE-2026-103956 |
Missing authentication for critical function in Loom for AWS |
02.10.2026 |
10 |
| CVE-2023-54405 |
H3C CVM Unauthenticated File Upload via fileUpload/upload Token |
02.10.2026 |
9.3 |
| CVE-2026-104848 |
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution |
02.10.2026 |
9.5 |
| CVE-2026-104849 |
Tinypool: Prototype Pollution Gadget to RCE in run() options |
02.10.2026 |
9.5 |
| CVE-2026-103648 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in image-downloader |
02.10.2026 |
9.1 |
| CVE-2026-104846 |
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940) |
02.10.2026 |
9.8 |
| CVE-2026-90970 |
Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway |
02.10.2026 |
9.9 |
| CVE-2026-19652 |
Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter |
02.10.2026 |
9.8 |
| CVE-2026-83632 |
Apache Thrift: C++ THttpTransport grows its line buffer without bound |
02.10.2026 |
9.2 |
| CVE-2026-104610 |
Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow |
02.10.2026 |
10 |
| CVE-2026-104611 |
Tenda AC9 POST Request fast_setting_internet_set stack-based overflow |
02.10.2026 |
9.4 |
| CVE-2026-104467 |
YesWiki before 4.6.7 Authorization Bypass via Public API Mode |
02.10.2026 |
9.2 |
| CVE-2026-91135 |
Apache Thrift: C++ `THeaderTransport::transform()` heap buffer overflow (write direction) |
02.10.2026 |
9.2 |
| CVE-2026-86325 |
|
02.10.2026 |
9.4 |
| CVE-2026-94541 |
WPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' Parameter |
02.10.2026 |
9.8 |
| CVE-2026-97637 |
JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response |
02.10.2026 |
9.8 |
| CVE-2026-63569 |
MTI/A0 DHAgreement does not validate the peer's ephemeral value |
02.10.2026 |
9.1 |
| CVE-2026-93029 |
|
02.10.2026 |
9 |
| CVE-2026-93697 |
|
02.10.2026 |
9 |
| CVE-2026-93698 |
|
02.10.2026 |
9.9 |
| CVE-2026-15896 |
Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter |
02.10.2026 |
9.1 |
| CVE-2026-19660 |
Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter |
02.10.2026 |
9.8 |
| CVE-2026-14378 |
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow |
02.10.2026 |
9.8 |
| CVE-2026-104480 |
Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership |
02.10.2026 |
9.4 |
| CVE-2026-86345 |
389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result |
02.10.2026 |
9 |
| CVE-2026-103764 |
Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport |
02.10.2026 |
9.3 |
| CVE-2026-18397 |
SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability |
02.10.2026 |
9.4 |
| CVE-2026-71449 |
|
02.10.2026 |
9.3 |
| CVE-2026-55393 |
Local File Inclusion in Teledyne FLIR Robots running Aware2 |
01.10.2026 |
10 |
| CVE-2026-55395 |
Hardcoded Passwords in Teledyne FLIR Robots running Aware2 |
01.10.2026 |
9.4 |
| CVE-2026-14984 |
Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2 |
01.10.2026 |
9.4 |
| CVE-2026-102628 |
Cadmos LTI exposure of sensitive information via debug mode |
01.10.2026 |
9.2 |
| CVE-2026-102667 |
Joyland AI WebView command injection |
02.10.2026 |
9 |
| CVE-2026-53953 |
GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover |
01.10.2026 |
9.1 |
| CVE-2026-56660 |
GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction |
01.10.2026 |
9.1 |
| CVE-2026-56662 |
GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request |
01.10.2026 |
9.6 |
| CVE-2026-104286 |
|
02.10.2026 |
9.8 |
| CVE-2026-55083 |
DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE) |
01.10.2026 |
9.1 |
| CVE-2026-103922 |
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path |
01.10.2026 |
9.3 |
| CVE-2026-13043 |
WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access |
01.10.2026 |
9.3 |
| CVE-2026-96658 |
Foreman: safemode bypass leading to rce |
02.10.2026 |
9.9 |
| CVE-2026-96659 |
Foreman: excessive permissions for viewer role on preview |
02.10.2026 |
9.1 |
| CVE-2026-94620 |
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download) |
01.10.2026 |
9.4 |
| CVE-2026-12627 |
Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vulnerability |
01.10.2026 |
9.8 |
| CVE-2026-79898 |
Fortra BoKS Manager crlserver command injection vulnerability |
01.10.2026 |
9.1 |
| CVE-2026-103752 |
WordPress Authorizer plugin <= 3.15.3 - Privilege Escalation vulnerability |
01.10.2026 |
9.8 |
| CVE-2026-62071 |
WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability |
01.10.2026 |
9.3 |
| CVE-2026-79901 |
Predictable Active Directory service-account passwords in BoKS Manager |
01.10.2026 |
9.9 |
| CVE-2026-103244 |
ground-station before 0.8.0 Authentication Bypass via setup.restore |
01.10.2026 |
9.3 |
| CVE-2026-103264 |
Fleet before 4.87.0 Authentication Bypass via Device Identifiers |
01.10.2026 |
9.3 |
| CVE-2026-103655 |
MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period |
01.10.2026 |
9.3 |
| CVE-2026-15989 |
Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter |
01.10.2026 |
9.8 |
| CVE-2026-75957 |
Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter |
01.10.2026 |
9.8 |
| CVE-2025-41753 |
Path traversal in dynamically created BACnet File Objects |
01.10.2026 |
9.3 |
| CVE-2026-82824 |
Path traversal may allow arbitrary files to be viewed, created, modified, or deleted |
01.10.2026 |
9.3 |
| CVE-2026-82825 |
Missing proper authentication for critical APIs may allow sensitive information to be obtained or modified, or unauthorized operations to be performed |
01.10.2026 |
9.3 |
| CVE-2026-82827 |
A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens |
01.10.2026 |
9.3 |
| CVE-2026-82829 |
Hidden accounts or hard-coded credentials may permit unauthorized access without the legitimate authentication process |
01.10.2026 |
9.3 |
| CVE-2026-76142 |
Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface |
01.10.2026 |
9.3 |
| CVE-2026-92966 |
Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field |
01.10.2026 |
9.1 |
| CVE-2026-14157 |
|
02.10.2026 |
9.4 |
| CVE-2026-101283 |
|
01.10.2026 |
9.2 |
| CVE-2026-101276 |
|
01.10.2026 |
9.2 |
| CVE-2026-102105 |
Kiteworks Email Protection Gateway server-side request forgery |
01.10.2026 |
9.1 |
| CVE-2026-102106 |
Kiteworks Email Protection Gateway improper authentication |
01.10.2026 |
9.1 |
| CVE-2026-102095 |
Kiteworks Email Protection Gateway server-side request forgery |
01.10.2026 |
9.1 |
| CVE-2026-102102 |
Kiteworks Email Protection Gateway server-side request forgery |
01.10.2026 |
9.1 |
| CVE-2026-102103 |
Kiteworks Email Protection Gateway server-side request forgery |
01.10.2026 |
9.1 |
| CVE-2026-102104 |
Kiteworks Email Protection Gateway server-side request forgery |
01.10.2026 |
9.1 |
| CVE-2026-102115 |
Kiteworks Core Authentication Bypass in the Password Reset Workflow |
01.10.2026 |
9.8 |
| CVE-2026-102147 |
Kiteworks Core Administrative Account Takeover through Stored Cross-site Scripting (XSS) |
01.10.2026 |
9.3 |
| CVE-2026-102149 |
Kiteworks Email Protection Gateway Improper Access Control |
01.10.2026 |
9.4 |
| CVE-2026-102992 |
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env |
30.09.2026 |
9.2 |
| CVE-2026-103547 |
|
30.09.2026 |
9.2 |
| CVE-2026-100512 |
WordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-103473 |
Deno 2.7.0 through 2.9.7 Command Injection via node:child_process |
02.10.2026 |
9.2 |
| CVE-2026-103475 |
yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure |
30.09.2026 |
9.3 |
| CVE-2026-55107 |
Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) |
30.09.2026 |
10 |
| CVE-2026-55181 |
Tugtainer: OIDC login remains accessible when OIDC_ENABLED is false |
30.09.2026 |
9.4 |
| CVE-2026-55494 |
Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset |
30.09.2026 |
9.8 |
| CVE-2026-62308 |
Tugtainer: Authenticated SSRF via arbitrary notification URLs in test_notification endpoint |
30.09.2026 |
9.1 |
| CVE-2026-55176 |
Soft Machine: Cross-tenant workspace API auth bypass via shared `CONTAINER_SHARED_SECRET` bearer token |
02.10.2026 |
9 |
| CVE-2026-102489 |
Undisclosed RCE in Zammad v6.3 and higher |
03.10.2026 |
9.4 |
| CVE-2026-102490 |
Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha |
03.10.2026 |
9.4 |
| CVE-2026-19445 |
Use-after-free of a server-side SSLContext when sni_callback switches contexts |
03.10.2026 |
9.2 |
| CVE-2026-75969 |
PTZOptics Missing Authentication in Firmware Upload |
30.09.2026 |
9.1 |
| CVE-2026-103470 |
|
30.09.2026 |
9.3 |
| CVE-2026-102427 |
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 |
30.09.2026 |
10 |
| CVE-2026-103395 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Visual-Only RPyC Service |
30.09.2026 |
9.3 |
| CVE-2026-76570 |
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1 |
30.09.2026 |
10 |
| CVE-2026-18782 |
SQL Injection in Trex Digital Manufacturing's Trex MES |
30.09.2026 |
9.8 |
| CVE-2026-93903 |
|
30.09.2026 |
9.4 |
| CVE-2026-82307 |
Multiple Vulnerabilities in Dolusoft Software's SOPLOG |
30.09.2026 |
9.8 |
| CVE-2026-76504 |
Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability |
02.10.2026 |
9.8 |
| CVE-2026-94389 |
WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability |
30.09.2026 |
9 |
| CVE-2026-96349 |
WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability |
30.09.2026 |
10 |
| CVE-2026-96350 |
WordPress Estatik plugin <= 4.3.5 - Privilege Escalation vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-96822 |
WordPress Books Gallery plugin <= 4.8.3 - SQL Injection vulnerability |
30.09.2026 |
9.3 |
| CVE-2026-97248 |
WordPress Booking Activities plugin <= 1.18.7.1 - PHP Object Injection vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-97274 |
WordPress OAuth Single Sign On – SSO (OAuth Client) plugin <= 7.1.2 - Bypass vulnerability vulnerability |
30.09.2026 |
9.8 |
| CVE-2026-74864 |
Authentication Bypass in sogo_yhn |
30.09.2026 |
9.3 |
| CVE-2026-74865 |
Authentication Bypass in sogo_yhn |
30.09.2026 |
9.2 |
| CVE-2026-77185 |
Apache MINA SSHD: Asynchronous authentication can bypass signature verification |
30.09.2026 |
9.1 |
| CVE-2026-94053 |
Apache MINA SSHD: LDAP injection in sshd-ldap |
30.09.2026 |
9.1 |
| CVE-2026-94052 |
Apache MINA SSHD: LDAP password authentication ineffective |
30.09.2026 |
9.1 |
| CVE-2026-102455 |
DigiWin|EasyFlow .NET - Insecure Deserialization |
30.09.2026 |
9.3 |
| CVE-2026-102458 |
DigiWin|EasyFlow .NET - Missing Authentication |
30.09.2026 |
9.3 |
| CVE-2026-102508 |
Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate, and silent downgrade |
30.09.2026 |
9.2 |
| CVE-2026-97196 |
WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability |
30.09.2026 |
9.1 |
| CVE-2026-102911 |
zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection |
30.09.2026 |
9.4 |
| CVE-2026-103110 |
|
02.10.2026 |
9.8 |
| CVE-2026-103056 |
AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR |
30.09.2026 |
9.4 |
| CVE-2026-102794 |
Ziroom ZHOME A0101 ping command injection |
30.09.2026 |
9.4 |
| CVE-2026-102793 |
Ziroom ZHOME A0101 set_time_zone command injection |
01.10.2026 |
9.4 |
| CVE-2026-86131 |
Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution |
01.10.2026 |
9.2 |
| CVE-2026-103040 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Router Profiler RPyC Service |
30.09.2026 |
9.3 |
| CVE-2026-103041 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Embed Cache RPyC Service |
30.09.2026 |
9.3 |
| CVE-2026-102792 |
Ziroom ZHOME A0101 set_syslog command injection |
02.10.2026 |
9.4 |
| CVE-2026-70356 |
Toptech TMS7 and TopHAT Unrestricted Upload of File with Dangerous Type |
30.09.2026 |
9.4 |
| CVE-2026-71379 |
Toptech TMS7 and TopHAT Files or Directories Accessible to External Parties |
30.09.2026 |
10 |
| CVE-2026-96587 |
Use of Hard-coded Credentials in Viidure Dashcam Android Application |
29.09.2026 |
10 |
| CVE-2026-53988 |
Dockhand < 1.0.40 Unauthenticated Webhook Trigger via Git Webhook Endpoints |
02.10.2026 |
9.2 |
| CVE-2026-100291 |
Initialization of a resource with an insecure default in Anjvision YSSD-RTMP-H5 |
29.09.2026 |
9.3 |
| CVE-2026-76721 |
Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs |
30.09.2026 |
9.8 |
| CVE-2026-76722 |
Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs |
01.10.2026 |
9.8 |
| CVE-2026-76723 |
Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS |
01.10.2026 |
9.6 |
| CVE-2026-76724 |
Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol |
01.10.2026 |
9.6 |
| CVE-2026-76725 |
Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs |
01.10.2026 |
9.6 |
| CVE-2026-102829 |
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection |
30.09.2026 |
9.2 |
| CVE-2026-102828 |
simple-git unsafe-operation guard does not block trailer command configuration |
30.09.2026 |
9.2 |
| CVE-2026-84436 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
30.09.2026 |
9.1 |
| CVE-2026-102710 |
|
30.09.2026 |
9.3 |
| CVE-2026-102761 |
|
30.09.2026 |
9.3 |
| CVE-2026-102425 |
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 |
01.10.2026 |
9.5 |
| CVE-2023-54400 |
Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname |
30.09.2026 |
9.3 |
| CVE-2026-22094 |
Weak root password in EVbee DC 80 |
30.09.2026 |
9.3 |
| CVE-2026-7192 |
Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment |
29.09.2026 |
9.3 |
| CVE-2026-82973 |
Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox |
29.09.2026 |
9.4 |
| CVE-2026-85520 |
Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module |
29.09.2026 |
9.3 |
| CVE-2026-15390 |
Out-of-bounds write in Das U-Boot |
29.09.2026 |
9 |
| CVE-2026-8065 |
|
29.09.2026 |
9.1 |
| CVE-2026-8066 |
|
29.09.2026 |
9.1 |
| CVE-2026-96429 |
Flowring Agentflow 4.0 - SQL Injection |
29.09.2026 |
9.3 |
| CVE-2026-96431 |
Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type |
29.09.2026 |
9.3 |
| CVE-2026-96428 |
Flowring Agentflow 4.0 - SQL Injection |
29.09.2026 |
9.3 |
| CVE-2026-84154 |
Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x |
29.09.2026 |
9.9 |
| CVE-2026-102422 |
shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token |
30.09.2026 |
9.2 |
| CVE-2026-102240 |
Netcore NAP930 Network Tools CGI network_tools eval os command injection |
29.09.2026 |
10 |
| CVE-2026-101354 |
FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow |
29.09.2026 |
9.4 |
| CVE-2026-102361 |
mall4j through 4.0 Missing Authentication in Password Update Endpoint |
01.10.2026 |
9.3 |
| CVE-2026-101263 |
Ziroom ZHOME A0101 set_online_client command injection |
29.09.2026 |
9.4 |
| CVE-2026-101264 |
Ziroom ZHOME A0101 set_passwd command injection |
01.10.2026 |
9.4 |
| CVE-2026-101262 |
Ziroom ZHOME A0101 set_online_client command injection |
29.09.2026 |
9.4 |
| CVE-2026-101261 |
Ziroom ZHOME A0101 firstSetup_wifi command injection |
01.10.2026 |
9.4 |
| CVE-2026-101260 |
Ziroom ZHOME A0101 firstLogin command injection |
29.09.2026 |
9.4 |
| CVE-2026-102334 |
Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection |
29.09.2026 |
9.1 |
| CVE-2026-101187 |
Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection |
29.09.2026 |
9.4 |
| CVE-2026-102268 |
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard |
29.09.2026 |
9.1 |
| CVE-2026-100752 |
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 |
30.09.2026 |
9.3 |
| CVE-2026-101108 |
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 |
30.09.2026 |
9.3 |
| CVE-2026-101110 |
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 |
30.09.2026 |
9.3 |
| CVE-2026-49994 |
Bluehood: Missing authentication on Bluehood API routes when web auth is enabled |
28.09.2026 |
9.1 |
| CVE-2026-101891 |
WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access |
28.09.2026 |
9.3 |
| CVE-2026-101894 |
@xhmikosr/decompress: Path traversal via symlink chain |
28.09.2026 |
9.1 |
| CVE-2026-86102 |
WatchGuard AP Command Injection in Internal Management API Allows Command Execution |
28.09.2026 |
9.3 |
| CVE-2026-101081 |
D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow |
28.09.2026 |
9.4 |
| CVE-2026-88804 |
Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher |
28.09.2026 |
9.6 |
| CVE-2026-12342 |
SailPoint IdentityIQ Improper Form Validation Vulnerability |
29.09.2026 |
9.6 |
| CVE-2026-101076 |
Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection |
01.10.2026 |
10 |
| CVE-2026-101077 |
Netcore NR289-GE boa_temp process_request missing authentication |
28.09.2026 |
10 |
| CVE-2026-101075 |
Netcore NR289-GE Location Time location_time.cgi system os command injection |
28.09.2026 |
10 |
| CVE-2026-101074 |
Netcore NR289-GE Authentication boa password-check stack-based overflow |
28.09.2026 |
9.3 |
| CVE-2026-90924 |
Default Admin Credentials in Innotim Software's Logsign SIEM |
28.09.2026 |
9.8 |
| CVE-2026-101072 |
Netcore NR289-GE CGI ap_ip.cgi system os command injection |
28.09.2026 |
10 |
| CVE-2026-73640 |
Time-based SQL Injection in Dayforce Payroll |
28.09.2026 |
9.3 |
| CVE-2026-73642 |
Path Traversal in Dayforce Payroll |
28.09.2026 |
9.2 |
| CVE-2026-85185 |
Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root |
28.09.2026 |
9.6 |
| CVE-2026-85526 |
Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD |
29.09.2026 |
9.9 |
| CVE-2026-87799 |
Arbitrary file write on LXD host via symlink in migration stream |
29.09.2026 |
9.9 |
| CVE-2026-81867 |
Deserialization of Untrusted Data in Application Integration allows Remote Code Execution |
30.09.2026 |
9.4 |
| CVE-2026-101039 |
FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow |
28.09.2026 |
10 |
| CVE-2026-101038 |
FAST FAC1200R MmtAtePrase stack-based overflow |
28.09.2026 |
9.4 |
| CVE-2026-19759 |
Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution |
28.09.2026 |
9.4 |
| CVE-2026-101037 |
FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow |
01.10.2026 |
9.4 |
| CVE-2026-82384 |
Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint |
29.09.2026 |
9.8 |
| CVE-2026-82377 |
Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers |
29.09.2026 |
9.9 |
| CVE-2026-82378 |
Apache Roller: OAuth authorization endpoint trusts request-supplied identity |
29.09.2026 |
9 |
| CVE-2026-101008 |
aaPanel BaoTa File Merge files.py merge_split_file command injection |
28.09.2026 |
9.4 |
| CVE-2026-101009 |
aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection |
01.10.2026 |
9.3 |
| CVE-2026-101007 |
aaPanel BaoTa Database Backup database.py InputSql os command injection |
28.09.2026 |
9.3 |
| CVE-2026-101002 |
Netcore NBR200V2 Tools Ping network_tools system os command injection |
28.09.2026 |
9.4 |
| CVE-2026-101001 |
Netcore NBR200V2 Web Management network_tools eval os command injection |
28.09.2026 |
10 |
| CVE-2026-101000 |
Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization |
01.10.2026 |
10 |
| CVE-2026-100896 |
TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection |
28.09.2026 |
9.4 |
| CVE-2026-100886 |
Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication |
28.09.2026 |
10 |
| CVE-2026-101065 |
Obot Quickstart Docker Deployment Unauthenticated Admin Access |
30.09.2026 |
9.3 |
| CVE-2026-101084 |
obot before v0.21.1 Authorization Bypass via /mcp-connect |
30.09.2026 |
9.3 |
| CVE-2026-101090 |
Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri |
28.09.2026 |
9.3 |
| CVE-2026-88771 |
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands |
29.09.2026 |
9.5 |
| CVE-2026-88772 |
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service |
28.09.2026 |
9.5 |
| CVE-2026-88773 |
HTTP Request Smuggling |
29.09.2026 |
9.3 |
| CVE-2026-100741 |
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer |
28.09.2026 |
9.8 |
| CVE-2026-100721 |
vm2 before 3.12.2 Authorization Bypass via Custom Resolver |
28.09.2026 |
9.5 |
| CVE-2026-100835 |
Contrast before 1.16.0 Remote Attestation Relay Attack |
30.09.2026 |
9.1 |
| CVE-2026-100740 |
D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write |
28.09.2026 |
9.4 |