CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 10.09.2026 9.1
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 10.09.2026 9.8
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.1
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.6
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 10.09.2026 9.1
CVE-2026-75940 10.09.2026 9.3
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-89094 10.09.2026 9.9
CVE-2026-89086 10.09.2026 9.1
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 10.09.2026 9.5
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 10.09.2026 9.3
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026 9.1
CVE-2026-65638 10.09.2026 9.2
CVE-2026-65639 10.09.2026 9.5
CVE-2026-68487 10.09.2026 9.9
CVE-2026-68488 10.09.2026 9.9
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 10.09.2026 9.3
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026 9.1
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 10.09.2026 9.3
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026 9.3
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026 9.3
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 10.09.2026 9.3
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026 9.3
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026 9.3
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026 9.3
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026 9.3
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026 9.3
CVE-2026-8323 Open Redirect in Armiya Information Technologies' Access Control System 10.09.2026 9.3
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables 10.09.2026 9.2
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 10.09.2026 9.5
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 10.09.2026 9.2
CVE-2026-88278 GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay 10.09.2026 9.8
CVE-2026-88285 GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service 10.09.2026 9.4
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 11.09.2026 9.9
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026 9.4
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 10.09.2026 9.3
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 10.09.2026 9
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 10.09.2026 9.6
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 09.09.2026 9.3
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026 9.2
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 10.09.2026 9.3
CVE-2026-67401 10.09.2026 9.9
CVE-2026-67403 09.09.2026 9
CVE-2026-68484 09.09.2026 9
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-80172 11.09.2026 9.8
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026 9.1
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026 10
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026 10
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module 09.09.2026 9.1
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist 09.09.2026 10
CVE-2026-21095 11.09.2026 9.2
CVE-2026-21096 11.09.2026 9.2
CVE-2026-21102 11.09.2026 9.3
CVE-2026-53939 OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption 09.09.2026 9.1
CVE-2026-53581 ntp: write path traversal 09.09.2026 9
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector 10.09.2026 9
CVE-2026-84197 09.09.2026 9.2
CVE-2026-19232 Adobe Experience Manager | Incorrect Authorization (CWE-863) 10.09.2026 9.9
CVE-2026-86464 09.09.2026 9.9
CVE-2026-48273 ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 09.09.2026 9.9
CVE-2026-75746 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 09.09.2026 9.1
CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 11.09.2026 9.9
CVE-2026-28659 09.09.2026 10
CVE-2026-49883 10.09.2026 10
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 08.09.2026 10
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability 10.09.2026 9.6
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 10.09.2026 9.3
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 10.09.2026 9.1
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability 10.09.2026 9
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability 10.09.2026 9.8
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability 10.09.2026 9.6
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability 10.09.2026 9.9
CVE-2026-82533 DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing 10.09.2026 9.4
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup 08.09.2026 9.2
CVE-2026-86729 WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize 10.09.2026 9.1
CVE-2026-86738 Snipe-IT before 8.7.0 CSS Injection via Custom CSS 08.09.2026 9.3
CVE-2026-12647 09.09.2026 9.9
CVE-2026-12645 09.09.2026 9.9
CVE-2026-12646 09.09.2026 9.9
CVE-2026-12650 09.09.2026 9.9
CVE-2026-12744 09.09.2026 9.8
CVE-2026-12745 09.09.2026 9.8
CVE-2026-61516 Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint 08.09.2026 9.3
CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint 09.09.2026 9.1
CVE-2026-73311 XenForo < 2.3.13 OAuth2 Authorization Code Reuse 10.09.2026 9.1
CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token 09.09.2026 9.1
CVE-2026-77089 Command Center API Authentication Bypass 09.09.2026 9.3
CVE-2026-78234 Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users 08.09.2026 9.9
CVE-2026-62645 08.09.2026 9.3
CVE-2026-62646 10.09.2026 9.1
CVE-2026-62647 08.09.2026 9.3
CVE-2026-67367 09.09.2026 9.2
CVE-2026-71376 OS Command Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71377 Command Argument Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 08.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 09.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 09.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 07.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 09.09.2026 10
CVE-2026-86478 09.09.2026 9.8
CVE-2026-86480 09.09.2026 9.8
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026 9.8
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 09.09.2026 9.8
CVE-2026-80238 08.09.2026 9.3
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 08.09.2026 9.2
CVE-2026-61410 09.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 08.09.2026 9.4
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 08.09.2026 9.8
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 07.09.2026 9.4
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 09.09.2026 9.2
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 08.09.2026 10
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection 08.09.2026 9.4
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection 07.09.2026 9.4
CVE-2026-16876 08.09.2026 9.3
CVE-2026-86259 OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation 08.09.2026 9
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 08.09.2026 9.4
CVE-2026-86165 Tenda HG10 formURL buffer overflow 08.09.2026 9.3
CVE-2026-16310 MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter 07.09.2026 9.8
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier 07.09.2026 9.8
CVE-2026-86218 pre-authentication remote code execution 09.09.2026 10
CVE-2026-86153 Tenda CP3 Redirect.cpp SetRedirectEnable privileges management 08.09.2026 9.4
CVE-2026-86152 Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection 10.09.2026 10
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection 05.09.2026 9.4
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection 08.09.2026 9.4
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection 08.09.2026 9.4
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS 09.09.2026 9.2
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 11.09.2026 9.2
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php 05.09.2026 9.3
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter 08.09.2026 9.3
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route 05.09.2026 9.3
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields 07.09.2026 9.8
CVE-2026-86117 Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching 10.09.2026 9.2
CVE-2026-86119 Webstudio through 0.296.0 SSRF via /cgi proxy routes 05.09.2026 9.2
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control 08.09.2026 9.3
CVE-2026-86123 SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints 08.09.2026 9.4
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server 05.09.2026 9.3
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection 07.09.2026 9.8
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 07.09.2026 9.8
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 07.09.2026 9.8
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize 08.09.2026 9.4
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action 09.09.2026 9.1
CVE-2026-75925 IXON VPN Client CRLF Injection 07.09.2026 9.4
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server 08.09.2026 9.2
CVE-2026-75430 04.09.2026 9.8
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed 10.09.2026 9.8
CVE-2026-19274 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 9.6
CVE-2026-75431 04.09.2026 9.1
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi 04.09.2026 9.3
CVE-2026-85620 Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function 04.09.2026 9.2
CVE-2026-85625 sift 17.1.3 Prototype Pollution Remote Code Execution via $where 04.09.2026 9.2
CVE-2026-85660 cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution 04.09.2026 9.2
CVE-2026-85661 excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode 04.09.2026 9.3
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch 04.09.2026 9.3
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection 08.09.2026 9.3
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension 08.09.2026 9.3
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer 04.09.2026 9.3
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction 08.09.2026 9.2
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing 04.09.2026 9.3
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename 10.09.2026 9.3
CVE-2026-85595 Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth 05.09.2026 9.3
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass 05.09.2026 9.3
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker 04.09.2026 9.2
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes 04.09.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-6640 Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter 11.09.2026 6.4
CVE-2026-6641 Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter 11.09.2026 6.4
CVE-2026-6642 Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import 11.09.2026 6.4
CVE-2026-89175 Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication 11.09.2026
CVE-2026-89176 Howyar|WeenyGenius - Missing Authentication 11.09.2026
CVE-2026-89177 Howyar|WeenyGenius - Use of Insecure Protocol 11.09.2026
CVE-2026-89178 Howyar|WeenyGenius - Origin Validation Error 11.09.2026
CVE-2026-89179 Howyar|WeenyGenius - Missing Support for Integrity Check 11.09.2026
CVE-2026-89173 Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure 11.09.2026
CVE-2026-89174 Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection 11.09.2026
CVE-2026-73785 HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability 11.09.2026 7.5
CVE-2026-87908 multiparty vulnerable to Denial of Service via unbounded part-header accumulation 11.09.2026 7.5
CVE-2025-15695 GTranslate < 3.0.10 - Admin+ Stored XSS 11.09.2026
CVE-2026-13326 Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module 11.09.2026
CVE-2026-14559 Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover 11.09.2026
CVE-2026-14560 Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload 11.09.2026
CVE-2026-14562 Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure 11.09.2026
CVE-2026-14563 Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover 11.09.2026
CVE-2026-14565 Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration 11.09.2026
CVE-2026-14566 Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tampering 11.09.2026
CVE-2026-73784 HPE IceWall products, Remote Bypass of Security Restrictions 11.09.2026 8.8
CVE-2026-74925 MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator 11.09.2026
CVE-2026-82305 YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title 11.09.2026
CVE-2026-83545 CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON 11.09.2026
CVE-2026-83546 CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute 11.09.2026
CVE-2026-85677 Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content 11.09.2026
CVE-2026-85678 AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript 11.09.2026
CVE-2026-86779 Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart 11.09.2026
CVE-2026-86780 Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text 11.09.2026
CVE-2026-86781 SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure 11.09.2026
CVE-2026-86782 Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR 11.09.2026
CVE-2026-86812 WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API 11.09.2026
CVE-2026-86815 BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes 11.09.2026
CVE-2026-89169 11.09.2026
CVE-2026-89060 Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references 11.09.2026
CVE-2026-89162 11.09.2026 2.9
CVE-2026-89156 11.09.2026 2.9
CVE-2026-89157 11.09.2026 5.7
CVE-2026-89158 11.09.2026 6.5
CVE-2026-89160 11.09.2026 3.7
CVE-2026-89161 11.09.2026 7.4
CVE-2026-11446 Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization 11.09.2026 5.3
CVE-2026-11496 Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure 11.09.2026 6.5
CVE-2026-12215 OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force 11.09.2026 5.3
CVE-2026-15462 Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection 11.09.2026 7.5
CVE-2026-18561 Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection 11.09.2026 7.5
CVE-2026-18562 HUSKY <= 1.4.3 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-18579 WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting 11.09.2026 7.2
CVE-2026-18964 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button <= 3.5.9 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-19985 Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-19991 UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion 11.09.2026 8.1
CVE-2026-77150 Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-78172 Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-7438 Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 11.09.2026 6.4
CVE-2026-81754 Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting 11.09.2026 7.2
CVE-2026-81825 Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting 11.09.2026 7.2
CVE-2026-84960 WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-78135 11.09.2026 5.6
CVE-2026-88260 11.09.2026
CVE-2026-89151 11.09.2026 3.5
CVE-2026-78134 11.09.2026 7.1
CVE-2026-78131 11.09.2026 3.7
CVE-2026-78132 11.09.2026 7.5
CVE-2026-78133 11.09.2026 7.5
CVE-2026-88914 Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser 11.09.2026
CVE-2026-78124 11.09.2026 3.7
CVE-2026-78126 11.09.2026 5.9
CVE-2026-78127 11.09.2026 3.7
CVE-2026-78129 11.09.2026 5.9
CVE-2026-78130 11.09.2026 7.5
CVE-2026-78123 11.09.2026 5.9
CVE-2026-89092 Stack overflow in nscd due to unbounded alloca use 11.09.2026 4.2
CVE-2026-89145 Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory 11.09.2026
CVE-2026-84941 Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read 10.09.2026
CVE-2026-77807 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter 10.09.2026 7.5
CVE-2026-81905 Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another. 10.09.2026
CVE-2026-81906 [UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks 10.09.2026
CVE-2026-17176 OS command injection Vulnerability in Deco BE11000 10.09.2026
CVE-2026-18121 Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}). 10.09.2026
CVE-2026-16174 Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow 10.09.2026
CVE-2026-16172 Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash 10.09.2026
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 10.09.2026 9.1
CVE-2026-2310 IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data 10.09.2026 7.8
CVE-2025-57231 10.09.2026
CVE-2026-36392 10.09.2026
CVE-2026-49837 GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries 10.09.2026 5.9
CVE-2026-49838 GoBGP confederation validation panics on empty AS_PATH attribute 10.09.2026 5.9
CVE-2026-54054 Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects 10.09.2026 6.5
CVE-2026-49836 psd-tools: arbitrary file write via smart-object filename 10.09.2026
CVE-2026-71647 10.09.2026
CVE-2026-79590 10.09.2026
CVE-2026-45770 Suricata lua: excessive flow variable registration can bypass sandbox 10.09.2026 7.5
CVE-2026-71640 10.09.2026
CVE-2026-71643 10.09.2026
CVE-2026-75624 IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service 10.09.2026 8.8
CVE-2026-75777 Multiple vulnerabilities in IBM Aspera Enterprise Webapps 10.09.2026 8.8
CVE-2026-76059 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-78569 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-78571 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 10.09.2026 9.8
CVE-2026-78575 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-79723 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches 10.09.2026 5
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-45767 Suricata datasets: save to absolute filename can be bypassed when combined with load command 10.09.2026 4.4
CVE-2026-45768 Suricata ldap: unbounded responses per transaction can lead to resource exhaustion 10.09.2026 7.5
CVE-2026-45769 ikev2: unbounded client transform storage can lead to resource exhaustion 10.09.2026 7.5
CVE-2026-71642 10.09.2026
CVE-2026-71645 10.09.2026
CVE-2026-79725 Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation 10.09.2026 6.5
CVE-2026-79742 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-80378 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.5
CVE-2026-80380 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 7.1
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.1
CVE-2026-80434 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 7.4
CVE-2026-80436 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.5
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-81207 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.5
CVE-2026-81210 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 7.7
CVE-2026-81211 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-81213 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches 10.09.2026 8.6
CVE-2026-81265 Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches 10.09.2026 7.5
CVE-2026-81268 Langflow is vulnerable to authentication bypass and insufficient session expiration 10.09.2026 8.1
CVE-2026-81540 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.5
CVE-2026-81941 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-45765 Suricata dnp3: unbounded reassembly can lead to resource exhaustion 10.09.2026 7.5
CVE-2026-45766 Suricata nfs: unbounded stateful structures can lead to resource exhaustion 10.09.2026 7.5
CVE-2026-81550 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-81551 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-81554 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-81940 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 8.8
CVE-2026-82092 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-82095 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-82097 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-82098 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-82099 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 8.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.6
CVE-2026-84889 A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem 10.09.2026 8.8
CVE-2026-86087 IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system 10.09.2026 4.3
CVE-2026-86093 IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions 10.09.2026 7.5
CVE-2026-87958 IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions 10.09.2026 8.1
CVE-2026-45762 Suricata defrag: missing address-family check can lead to remote crash 10.09.2026 7.5
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 10.09.2026 9.1
CVE-2026-57844 10.09.2026
CVE-2026-9768 10.09.2026
CVE-2026-11813 10.09.2026
CVE-2026-18994 10.09.2026
CVE-2026-19136 10.09.2026
CVE-2026-45759 Suricata http1: quadratic Content-Disposition processing can lead to denial of service 10.09.2026 7.5
CVE-2026-45761 Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load 10.09.2026 3.3
CVE-2026-63427 10.09.2026
CVE-2026-75940 10.09.2026
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-9667 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 10.09.2026 5.3
CVE-2026-9176 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 10.09.2026 6.7
CVE-2026-9225 Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation 10.09.2026 6.5
CVE-2026-3096 Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft 10.09.2026 4.7
CVE-2026-79591 10.09.2026
CVE-2026-89094 10.09.2026 9.9
CVE-2026-9327 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 10.09.2026 6.3
CVE-2022-26962 10.09.2026
CVE-2026-45752 Suricata detect/transform: use-after-free in decompress transforms 10.09.2026 5.9
CVE-2026-79592 10.09.2026
CVE-2026-89089 OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER) 10.09.2026 6.5
CVE-2026-45751 Suricata detect/transform: use-after-free in dotprefix transform 10.09.2026 5.9
CVE-2026-19596 OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host 10.09.2026 5.9
CVE-2026-76652 Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600 10.09.2026
CVE-2026-76653 Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600 10.09.2026
CVE-2026-89011 isomorphic-git < 1.42.0 Prototype Pollution via getRemoteInfo 10.09.2026
CVE-2026-89086 10.09.2026 9.1
CVE-2026-89087 10.09.2026 7.3
CVE-2026-89054 OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes 10.09.2026 8.2
CVE-2026-84432 Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller 10.09.2026
CVE-2026-88061 career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution 10.09.2026
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 10.09.2026
CVE-2026-87107 Consul vulnerable to an authorization bypass in the catalog deregistration path 10.09.2026 5.4
CVE-2026-87993 Consul-template vulnerable to an information disclosure issue in error handling 10.09.2026 7.7
CVE-2026-88021 Consul vulnerable to an authorization bypass in the Connect service mesh 10.09.2026 7.5
CVE-2026-88059 Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` 10.09.2026 4
CVE-2026-88060 Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements 10.09.2026
CVE-2026-87090 Consul vulnerable to an authorization bypass in the catalog node-write path 10.09.2026 8.3
CVE-2026-87106 Consul vulnerable to a denial of service in the native RPC listener 10.09.2026 6.5
CVE-2026-88058 Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements 10.09.2026
CVE-2026-88057 Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler 10.09.2026
CVE-2026-9336 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 10.09.2026 6.5
CVE-2026-88056 Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR 10.09.2026
CVE-2026-89049 Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent 10.09.2026 9.9
CVE-2026-9338 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 10.09.2026 5.3
CVE-2026-68527 Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog 10.09.2026
CVE-2026-88032 Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver 10.09.2026
CVE-2026-88033 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java Driver 10.09.2026
CVE-2026-88034 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ Driver 10.09.2026
CVE-2026-88035 Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver 10.09.2026
CVE-2026-88036 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver 10.09.2026
CVE-2026-88029 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python Driver 10.09.2026
CVE-2026-88030 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby Driver 10.09.2026
CVE-2026-88031 GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver 10.09.2026
CVE-2026-88027 Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for Laravel 10.09.2026
CVE-2026-88028 Unauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB integration for Laravel 10.09.2026
CVE-2026-88055 AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator 10.09.2026 5.5
CVE-2026-88024 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust Driver 10.09.2026
CVE-2026-88025 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver 10.09.2026
CVE-2026-88026 Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver 10.09.2026
CVE-2026-88023 GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP Library 10.09.2026
CVE-2026-88052 Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronization 10.09.2026 7.8
CVE-2026-88053 Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddata 10.09.2026
CVE-2026-88054 Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load 10.09.2026
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 10.09.2026
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026
CVE-2026-89044 Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding 10.09.2026
CVE-2026-89045 zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length 10.09.2026
CVE-2026-89046 zstd-jni 1.5.5-6 through 1.5.7-13 Out-of-Bounds Read via Negative Offset 10.09.2026
CVE-2026-88022 Unauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for Laravel 10.09.2026
CVE-2026-88051 Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fields 10.09.2026
CVE-2026-68006 10.09.2026
CVE-2026-15417 CP210x Denial of Service 10.09.2026
CVE-2026-15418 CP210x Memory Leakage 10.09.2026
CVE-2026-15419 CP210x Driver Memory Corruption results in Arbitrary Code Execution 10.09.2026
CVE-2026-85228 Integer overflow in tensor buffer validation in Deep Java Library 10.09.2026 9.1
CVE-2026-73694 FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition 10.09.2026
CVE-2026-73698 FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action 10.09.2026
CVE-2026-73699 FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms() 10.09.2026
CVE-2026-65638 10.09.2026
CVE-2026-65639 10.09.2026
CVE-2026-68487 10.09.2026
CVE-2026-68488 10.09.2026
CVE-2026-73693 FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler 10.09.2026
CVE-2026-88049 Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch 10.09.2026
CVE-2026-88050 Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values 10.09.2026
CVE-2026-52097 10.09.2026
CVE-2026-52098 10.09.2026
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88045 rclone: S3 multipart declared-length memory exhaustion 10.09.2026 7.5
CVE-2026-88046 rclone: source object names can escape the configured root on upload 10.09.2026 5.3
CVE-2026-88047 Tesseract: ReadNormProtos stack buffer overflow 10.09.2026
CVE-2026-88048 Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch 10.09.2026
CVE-2026-79987 Low-privilege RCE through element-search eager loading 11.09.2026
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-88016 rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination 10.09.2026 7.1
CVE-2026-88017 rclone: FTP cross-session auth-proxy backend confusion 10.09.2026 7.3
CVE-2026-88014 rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace 10.09.2026 6.3
CVE-2026-88015 rclone local: crafted Range request against a translated symlink panics (DoS) 10.09.2026 5.3
CVE-2026-4130 Storage of Sensitive Information in Cleartext in NI SystemLink 10.09.2026 7.1
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81049 11.09.2026 4.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-87912 Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops 10.09.2026 5.9
CVE-2026-87913 Missing S3 bucket ownership verification in the AWS Security Agent MCP server 10.09.2026 5.9
CVE-2026-88013 rclone: http backend forwards custom/auth headers to a different host on redirect 10.09.2026 3.7
CVE-2026-88959 Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints 10.09.2026 8.8
CVE-2026-4129 Improper Access Controls in NI SystemLink 10.09.2026 8.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-81051 10.09.2026 6.6
CVE-2026-81052 10.09.2026 6.8
CVE-2026-88011 Traefik: ForwardAuth identity spoofing via dot-form header alias 10.09.2026
CVE-2026-88012 Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded 10.09.2026 5.3
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 10.09.2026
CVE-2026-88937 knowns through 0.33.0 Path Traversal via Template Engine 10.09.2026
CVE-2026-88938 knowns through 0.33.0 Path Traversal via code.find MCP tool 10.09.2026
CVE-2026-88939 knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption 10.09.2026
CVE-2026-88940 knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint 10.09.2026
CVE-2026-88009 Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging 10.09.2026
CVE-2026-88008 Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization 10.09.2026
CVE-2026-88006 Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange 10.09.2026 6.5
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026
CVE-2026-88897 Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String 10.09.2026
CVE-2026-88898 AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint 10.09.2026
CVE-2026-15461 Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input 10.09.2026 5.3
CVE-2026-88004 Traefik entrypoint header-name sanitization bypassed via request trailers 10.09.2026
CVE-2026-88005 Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange 10.09.2026 6.5
CVE-2026-88924 Gvfs: gvfs-admin socket ownership race permits local root 10.09.2026
CVE-2026-66632 WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Content Injection vulnerability 10.09.2026 6.5
CVE-2026-66674 WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability 10.09.2026 5.6
CVE-2026-78536 WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Control vulnerability 10.09.2026 6.5
CVE-2026-81275 WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability 10.09.2026 6.5
CVE-2026-81782 WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability 10.09.2026 6.5
CVE-2026-81783 WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerability 10.09.2026 7.1
CVE-2026-81784 WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability 10.09.2026 8.1
CVE-2026-81785 WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability 10.09.2026 6.5
CVE-2026-81786 WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability 10.09.2026 7.5
CVE-2026-81787 WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability 10.09.2026 6.5
CVE-2026-81788 WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability 10.09.2026 6.3
CVE-2026-81789 WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability 10.09.2026 8.6
CVE-2026-81791 WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability 10.09.2026 6.5
CVE-2026-81793 WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability 10.09.2026 6.5
CVE-2026-81794 WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability 10.09.2026 7.5
CVE-2026-81795 WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability 10.09.2026 7.1
CVE-2026-81796 WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability 10.09.2026 7.3
CVE-2026-81799 WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability 10.09.2026 7.5
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 10.09.2026 9.3
CVE-2026-81801 WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability 10.09.2026 8.1
CVE-2026-81803 WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability 10.09.2026 7.5
CVE-2026-81804 WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability 10.09.2026 7.5
CVE-2026-81805 WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability 10.09.2026 8.1
CVE-2026-84816 WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability 10.09.2026 7.1
CVE-2026-84819 WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability 10.09.2026 7.1
CVE-2026-84821 WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability 10.09.2026 7.5
CVE-2026-85310 WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability 10.09.2026 6.5
CVE-2026-45747 Suricata lua/tls: null dereference in TlsGetCertInfo 10.09.2026 7.5
CVE-2026-46387 Suricata http2: decompression bomb can cause denial of service in Suricata 10.09.2026 7.5
CVE-2026-88790 proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal 10.09.2026
CVE-2026-64836 ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement 10.09.2026
CVE-2026-64837 ICEcoder through 8.1 OS Command Injection via lib/properties.php 10.09.2026
CVE-2026-64838 ICEcoder through 8.1 Path Traversal via oldFileName Parameter 10.09.2026
CVE-2026-75584 ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion 10.09.2026
CVE-2026-12682 Stored XSS in Ankaref's LIBRID/LIBREF 10.09.2026 5.4
CVE-2026-88921 MISP: Unescaped HTML Injection in PDF Report Element Rendering 10.09.2026
CVE-2026-38626 10.09.2026
CVE-2026-6285 Improper Authentication in Ankaref's LIBRID/LIBREF 10.09.2026 7.5
CVE-2026-85217 Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop 11.09.2026 8.6
CVE-2026-12683 Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF 10.09.2026 5.4
CVE-2026-45763 Suricata lua: sandbox allocation limit not enforced for new allocations 10.09.2026 5.9
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026
CVE-2026-88861 Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization 10.09.2026
CVE-2026-88862 Capgo API Key Manager Authentication Bypass via x-limited-key-id 10.09.2026
CVE-2026-88863 capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org 10.09.2026
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026
CVE-2026-88865 AVideo Missing Authorization via getRestream.json.php 10.09.2026
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 10.09.2026
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026
CVE-2026-88870 WWBN AVideo LoginControl PGP Key CSRF via GET Request 10.09.2026
CVE-2026-88871 WWBN AVideo CustomizeUser setSubscribers CSRF via GET 10.09.2026
CVE-2026-88872 AVideo CustomizeUser setPassword.json.php CSRF 10.09.2026
CVE-2026-88873 WWBN AVideo Cross-Site Request Forgery via logArchive.json.php 10.09.2026
CVE-2026-88874 AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass 10.09.2026
CVE-2026-88875 AVideo Incomplete API Sanitization Information Disclosure 10.09.2026
CVE-2026-88876 AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD 10.09.2026
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026
CVE-2026-88878 Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass 10.09.2026
CVE-2026-88879 Traefik before v2.11.56 Identity Spoofing via Header Alias 10.09.2026
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026
CVE-2026-88883 Renovate before 44.14.4 TLS Private Key Log Sanitisation 10.09.2026
CVE-2026-88884 Renovate before 44.3.1 Authentication Bypass via Digest Updates 10.09.2026
CVE-2026-88885 Renovate before 44.14.7 Command Injection via depName 10.09.2026
CVE-2026-88886 Renovate before 44.14.7 Command Injection via gradle-wrapper 10.09.2026
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026
CVE-2026-88888 Renovate before 44.14.7 Command Injection via Mix organization 10.09.2026
CVE-2026-88889 Renovate before 44.14.7 Command Injection via distributionType 10.09.2026
CVE-2026-88890 OpenPanel SQL Injection via unvalidated profile filter column identifier 10.09.2026
CVE-2026-88891 OpenPanel Read-Only Access Level Enforcement Bypass via Mutations 10.09.2026
CVE-2026-88892 OpenPanel SSRF via Unguarded Importer File URL Fetch 10.09.2026
CVE-2026-88893 OpenPanel Unauthenticated Share Lookup Information Disclosure 10.09.2026
CVE-2026-88894 Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout 10.09.2026
CVE-2026-88895 CyberPanel before 3.0.5 Authentication Bypass via API 10.09.2026
CVE-2026-88896 EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass 10.09.2026
CVE-2026-88915 MISP Event Template Instantiation Bypasses Sharing Group and Tagging Authorization 10.09.2026
CVE-2026-85543 10.09.2026 4.3
CVE-2026-85544 10.09.2026 5.2
CVE-2026-85545 10.09.2026 7.1
CVE-2026-17038 Use of Hard-coded Credentials in drEryk Gabinet 10.09.2026
CVE-2026-88038 cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options 10.09.2026 4.8
CVE-2026-9161 User Enumeration in DernekPlus' Website Template 10.09.2026 5.3
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-9166 LFI in GIS Informatics' GisLab Laboratory Management System 10.09.2026 7.5
CVE-2026-84828 Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token 10.09.2026
CVE-2026-88859 Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction 10.09.2026
CVE-2026-87961 ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header 10.09.2026
CVE-2026-87962 t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in MergingDigest.fromBytes 10.09.2026
CVE-2026-78085 Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 11.09.2026
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026
CVE-2026-78083 Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 11.09.2026
CVE-2026-78084 Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 11.09.2026
CVE-2026-78302 Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 11.09.2026
CVE-2026-78374 Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 11.09.2026
CVE-2026-78303 Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 11.09.2026
CVE-2026-87803 10.09.2026 7.1