CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-93741 Totolink A3002MU formWlWds buffer overflow 19.09.2026 10
CVE-2026-84434 Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field 19.09.2026 9.8
CVE-2026-89274 WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content 19.09.2026 9.1
CVE-2026-92229 Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter 19.09.2026 9.1
CVE-2026-75885 Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint 18.09.2026 9.3
CVE-2026-93740 Totolink A3002MU formWlEncrypt buffer overflow 18.09.2026 10
CVE-2026-93739 Totolink A3002MU formWlAc buffer overflow 18.09.2026 9.4
CVE-2026-93738 Totolink A3002MU formSchedule buffer overflow 18.09.2026 9.4
CVE-2026-58264 FluidSynth: Heap-based buffer overrun 18.09.2026 9.8
CVE-2026-63647 CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` 18.09.2026 9.3
CVE-2026-93868 Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG 18.09.2026 9.2
CVE-2026-84073 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.1
CVE-2026-84075 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-84078 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-84082 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-61781 pg_partman has privilege escalation through SQL injection in create_partition_time() 18.09.2026 9.9
CVE-2026-84064 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-82967 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-84031 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9
CVE-2026-81657 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-82340 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-82832 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.6
CVE-2026-75878 IBM Sterling File Gateway is Vulnerable to Authentication Bypass 18.09.2026 9.1
CVE-2026-80441 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-80442 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-93839 LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint 18.09.2026 9.3
CVE-2023-54399 Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree 18.09.2026 9.3
CVE-2026-59163 Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass 18.09.2026 9.1
CVE-2026-61550 Icinga 2: Improper access control for JSON-RPC update certificate messages 18.09.2026 9.8
CVE-2025-66455 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py 18.09.2026 9.8
CVE-2026-92701 Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path 18.09.2026 9.1
CVE-2026-92702 Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path 18.09.2026 9.1
CVE-2026-93762 Data deletion and attribute disclosure via field-name method injection in in-memory queries 18.09.2026 9.2
CVE-2026-77240 WACRM: Database-layer authorization bypasses 18.09.2026 9.9
CVE-2026-81321 CareCam CM2507 Cleartext Storage of Sensitive Information 18.09.2026 9.3
CVE-2026-85497 CareCam CM2507 Use of Password Hash With Insufficient Computational Effort 18.09.2026 9.3
CVE-2026-10858 IBM MQ for HPE NonStop is vulnerable to a denial of service attack 19.09.2026 9.9
CVE-2026-61682 kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace 18.09.2026 9.9
CVE-2026-10747 IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing 19.09.2026 10
CVE-2026-84383 libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items 18.09.2026 9.8
CVE-2025-15399 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 19.09.2026 10
CVE-2025-53837 org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 18.09.2026 9.9
CVE-2026-93659 Concrete CMS Community Store before 2.7.8 Stored XSS 18.09.2026 9.3
CVE-2023-5778 Missing Length Check 18.09.2026 9.2
CVE-2026-93603 vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function 18.09.2026 10
CVE-2026-93605 vm2 NodeVM before 3.12.1 Remote Code Execution via child_process 18.09.2026 10
CVE-2026-93606 vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species 18.09.2026 10
CVE-2026-28197 Privilege Escalation via Argument Injection in NetBackup Flex OS Shell 18.09.2026 9.4
CVE-2026-28198 Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell 18.09.2026 9.4
CVE-2026-13639 18.09.2026 9.8
CVE-2026-13684 18.09.2026 9.8
CVE-2026-67100 HCL BigFix Service Management is affected by multiple security vulnerabilities. 18.09.2026 9.8
CVE-2026-67101 HCL BigFix Service Management is affected by multiple security vulnerabilities. 18.09.2026 9.3
CVE-2026-93467 HGiga|OAKlouds - Insecure Deserialization 18.09.2026 9.3
CVE-2026-62874 Azure Billing Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-69843 Microsoft Fabric Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-85878 Azure Database for PostgreSQL Elevation of Privilege Vulnerability 19.09.2026 9.9
CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability 18.09.2026 10
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability 18.09.2026 10
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability 19.09.2026 9.3
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability 19.09.2026 9
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability 19.09.2026 9.9
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability 19.09.2026 9.6
CVE-2026-54734 Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction 18.09.2026 10
CVE-2026-76949 Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement 18.09.2026 9.1
CVE-2026-54670 WeGIA: Unauthenticated Auth Bypass + Local File Inclusion 17.09.2026 9.1
CVE-2026-54767 WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php 18.09.2026 9.1
CVE-2026-93393 Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream 18.09.2026 9.2
CVE-2026-45140 Chamilo LMS CStudio upload flow allows unauthenticated remote code execution 18.09.2026 9.8
CVE-2026-45143 Chamilo LMS: Student-to-admin stored XSS in private messages via v-html 17.09.2026 9
CVE-2026-54237 Wavelog: Unauthenticated Remote Code Execution 18.09.2026 9.3
CVE-2026-54460 OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover 17.09.2026 9.8
CVE-2026-54501 Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors 17.09.2026 9.4
CVE-2026-54752 NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request 17.09.2026 9.6
CVE-2026-54618 Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user 17.09.2026 9.4
CVE-2026-54626 SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) 17.09.2026 9.8
CVE-2026-54627 SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) 18.09.2026 9.8
CVE-2026-92943 Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python 17.09.2026 9.2
CVE-2026-54617 GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler 18.09.2026 9.8
CVE-2026-47252 Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) 17.09.2026 9
CVE-2026-54053 Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults 17.09.2026 9.6
CVE-2026-90104 NFSv4.1: zero referring call lists before decoding 18.09.2026 9.8
CVE-2026-90110 inetpeer: randomize RB-tree node comparison using SipHash 18.09.2026 9.4
CVE-2026-90151 NFSv4: remove callback IDR entry on client allocation failure 18.09.2026 9.8
CVE-2026-90173 smb: smbdirect: free completion queues with ib_free_cq() 18.09.2026 9.8
CVE-2026-90230 nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() 18.09.2026 9.1
CVE-2026-90235 sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE 18.09.2026 9.8
CVE-2026-90413 IB/isert: reject login PDUs declaring more data than was received 18.09.2026 9.1
CVE-2026-90414 IB/isert: reject PDUs declaring more data than was received 18.09.2026 9.1
CVE-2026-92489 xfrm: Fix skb double-free in xfrm_dev_direct_output() 18.09.2026 9.8
CVE-2026-86863 pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode 17.09.2026 9.3
CVE-2026-76834 b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key 18.09.2026 9.2
CVE-2026-91039 dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover 17.09.2026 9.1
CVE-2026-79752 CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection 17.09.2026 9.2
CVE-2026-63472 Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification 17.09.2026 9.1
CVE-2026-88952 OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication 17.09.2026 9.1
CVE-2026-92934 vm2 before 3.11.8 Sandbox Escape RCE via AggregateError 17.09.2026 9.5
CVE-2026-92935 vm2 NodeVM Remote Code Execution via Array-Shaped Require 17.09.2026 9.5
CVE-2026-92937 vm2 3.11.6 Remote Code Execution via Promise call/apply 18.09.2026 10
CVE-2026-92938 vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite 19.09.2026 9.4
CVE-2026-92939 vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine 17.09.2026 9.4
CVE-2026-92940 vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent 17.09.2026 10
CVE-2026-92941 vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation 17.09.2026 10
CVE-2026-92944 vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector 19.09.2026 9.3
CVE-2026-92946 vm2 before 3.11.7 Remote Code Execution via require.external 17.09.2026 10
CVE-2026-92947 vm2 before 3.11.7 Memory Disclosure via Buffer Pool 17.09.2026 10
CVE-2026-92948 vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test 18.09.2026 9.4
CVE-2026-92950 vm2 before 3.11.7 Sandbox Escape via CLI require 17.09.2026 9.3
CVE-2026-92951 vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver 17.09.2026 9.4
CVE-2026-92953 vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray 18.09.2026 9.3
CVE-2026-92954 vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise 17.09.2026 9.2
CVE-2026-92955 vm2 before 3.11.8 Sandbox Escape via NodeVM 17.09.2026 10
CVE-2026-92956 vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming 17.09.2026 10
CVE-2026-92957 vm2 before 3.11.7 Authentication Bypass via node: Prefix 17.09.2026 9.4
CVE-2026-92960 vm2 before 3.11.6 Process-wide State Exposure via os and dns 17.09.2026 10
CVE-2026-62101 WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability 17.09.2026 9.8
CVE-2026-62104 WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability 19.09.2026 10
CVE-2026-62108 WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability 17.09.2026 9.8
CVE-2026-82761 Magic link single-use tokens replayable via TOCTOU race in AshAuthentication 17.09.2026 9.1
CVE-2026-85500 `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication 17.09.2026 9.1
CVE-2026-86533 Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix 17.09.2026 9.1
CVE-2026-90822 17.09.2026 9.8
CVE-2026-90823 17.09.2026 9.8
CVE-2026-92860 rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation 19.09.2026 9.4
CVE-2026-92913 AVideo Weak PRNG Activation Code Authentication Bypass 17.09.2026 9.1
CVE-2026-15688 Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting 17.09.2026 9.2
CVE-2026-87796 Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload 19.09.2026 9.8
CVE-2026-61594 djust has an authorization bypass on the WebSocket/SSE mount path 17.09.2026 9.1
CVE-2026-92576 HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool 17.09.2026 9.2
CVE-2026-92578 WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash 17.09.2026 9.2
CVE-2026-75513 Marten: SQL injection in Marten's LINQ provider via unescaped string literals 19.09.2026 9.1
CVE-2026-92749 SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret 17.09.2026 9.2
CVE-2026-92785 Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes 17.09.2026 9.2
CVE-2026-92787 Feast through 0.66.0 Authentication Bypass via Unverified Token 19.09.2026 9.3
CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard 19.09.2026 9.3
CVE-2026-20284 Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability 18.09.2026 9.1
CVE-2026-20332 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities 18.09.2026 9.9
CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-20130 Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities 18.09.2026 10
CVE-2026-20176 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20192 Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities 18.09.2026 10
CVE-2026-20194 Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities 18.09.2026 9.1
CVE-2026-20211 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20237 Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities 18.09.2026 9.1
CVE-2026-20242 Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability 18.09.2026 9.8
CVE-2026-20322 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control 18.09.2026 9.9
CVE-2026-20324 Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability 18.09.2026 9.9
CVE-2026-20325 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command 18.09.2026 9.9
CVE-2026-20326 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function 18.09.2026 9.8
CVE-2026-20329 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities 18.09.2026 9.9
CVE-2026-20330 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities 18.09.2026 9.9
CVE-2026-20341 Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability 18.09.2026 9.1
CVE-2026-76423 Cisco ISE API Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-92808 Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise 17.09.2026 10
CVE-2026-89083 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 17.09.2026 9.3
CVE-2026-89082 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 17.09.2026 9.3
CVE-2026-73456 Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. 17.09.2026 9.2
CVE-2026-91104 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-91106 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-92717 Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub 16.09.2026 9.3
CVE-2026-92720 Kubero through 3.1.1 Unauthenticated Notifications API Access 17.09.2026 9.3
CVE-2026-20234 Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities 17.09.2026 9.9
CVE-2026-20305 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20306 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.9
CVE-2026-20331 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities 18.09.2026 9.6
CVE-2026-76420 Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability 17.09.2026 9
CVE-2026-92398 Ruijie RG-EW3000GX user_list_note admin os command injection 16.09.2026 9.4
CVE-2026-92397 Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection 16.09.2026 9.4
CVE-2025-59953 LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy 18.09.2026 9.8
CVE-2026-70416 16.09.2026 10
CVE-2026-77411 RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr 16.09.2026 9.5
CVE-2026-77405 RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser 18.09.2026 9.4
CVE-2026-92395 @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 17.09.2026 9.1
CVE-2026-77408 RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow 16.09.2026 9.1
CVE-2026-91843 Stack overflow in login process to the Security Management and Log Servers 17.09.2026 9.8
CVE-2026-73172 17.09.2026 9.3
CVE-2026-40855 Command Injection in T-Mobile 5G Box IDU router via ping functionality 16.09.2026 9.3
CVE-2026-58146 Unauthorized remote code execution in T-Mobile 5G Box IDU routers 16.09.2026 9.4
CVE-2026-58147 Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers 16.09.2026 9.3
CVE-2026-89846 scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read 16.09.2026 9.1
CVE-2026-89847 scsi: qla2xxx: Avoid double completion in async IOCB timeout 16.09.2026 9.8
CVE-2026-89857 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject 16.09.2026 9.8
CVE-2026-89914 KVM: arm64: Sign-extend VA for range-based TLBI invalidation 16.09.2026 9.3
CVE-2026-89915 KVM: arm64: Remove VM-wide VNCR mapping counter 16.09.2026 9.3
CVE-2026-89916 KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry 16.09.2026 9.3
CVE-2026-89918 KVM: arm64: Correctly handle end of VA space TLBI invalidation 16.09.2026 9.3
CVE-2026-89930 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter 16.09.2026 9.3
CVE-2026-89969 nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU 16.09.2026 9.8
CVE-2026-89970 nvmet-auth: Synchronize timeout work during SQ teardown 16.09.2026 9.8
CVE-2026-89972 nvme: add missing SRCU grace period in error path 16.09.2026 9.8
CVE-2026-89990 ceph: lock mutex in ceph_mds_check_access() 16.09.2026 9.8
CVE-2026-90011 scsi: target: iscsi: Reserve a terminator byte for the login payload 16.09.2026 9.1
CVE-2026-90012 spi: Fix DMA mapping ownership on partial map failure 16.09.2026 9.8
CVE-2026-90036 NFSD: Prevent client use-after-free during blocked-lock reaping 16.09.2026 9.8
CVE-2026-90037 NFSD: Prevent client use-after-free during close_lru reaping 16.09.2026 9.8
CVE-2026-90038 NFSD: Prevent client use-after-free during export state revocation 16.09.2026 9.8
CVE-2026-90042 ceph: properly decrypt filenames in vmalloc() buffers 16.09.2026 9.8
CVE-2026-90048 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() 16.09.2026 9.8
CVE-2026-90049 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() 16.09.2026 9.3
CVE-2026-73453 Security Advisory 0174 17.09.2026 9.5
CVE-2026-89778 isofs: fix out-of-bounds page array access on empty zisofs block 16.09.2026 9.8
CVE-2026-89779 fs/ntfs3: validate ef->size covers the record's name and value 16.09.2026 9.1
CVE-2026-89783 xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full 16.09.2026 9.8
CVE-2026-89786 ext4: fix out-of-bounds read in ext4_read_inline_dir() 16.09.2026 9.1
CVE-2026-89788 ksmbd: fix tree connection use-after-free in smb2_tree_connect() 16.09.2026 9.8
CVE-2026-81642 Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY 16.09.2026 9.1
CVE-2026-89775 KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation 16.09.2026 9.3
CVE-2026-73461 Security Advisory 0163 17.09.2026 9.4
CVE-2026-27546 Authentication Bypass in _account_log 16.09.2026 9.8
CVE-2026-27565 Remote code execution via uploading a malicious IODD file 16.09.2026 9.8
CVE-2026-73447 Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request 17.09.2026 9.4
CVE-2026-12793 JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter 17.09.2026 9.8
CVE-2026-14349 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action 16.09.2026 9.8
CVE-2026-15638 Cryptographic Padding Oracle 16.09.2026 9.1
CVE-2026-15639 Reflected Cross-Site Scripting 16.09.2026 9.3
CVE-2026-15640 Authentication Bypass via SAML Response Manipulation 16.09.2026 9.5
CVE-2026-73807 mySCADA myPRO Manager Missing Authorization 16.09.2026 9.3
CVE-2026-78225 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.5
CVE-2026-81855 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.3
CVE-2026-61560 @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover 16.09.2026 9.8
CVE-2026-61559 @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery 17.09.2026 9.6
CVE-2026-61568 @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport 16.09.2026 9.6
CVE-2026-68491 16.09.2026 9.4
CVE-2026-91939 Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter 16.09.2026 9.3
CVE-2026-66887 Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-54337 Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite 16.09.2026 9.8
CVE-2026-66890 Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-70748 15.09.2026 9.8
CVE-2026-70756 15.09.2026 9.8
CVE-2026-70757 15.09.2026 9.8
CVE-2026-70913 15.09.2026 9.8
CVE-2026-71133 17.09.2026 10
CVE-2026-71163 16.09.2026 9.9
CVE-2026-73940 15.09.2026 9.8
CVE-2026-73944 15.09.2026 9.1
CVE-2026-73945 16.09.2026 9.9
CVE-2026-73946 16.09.2026 9.1
CVE-2026-73947 15.09.2026 9.8
CVE-2026-73948 16.09.2026 9.9
CVE-2026-73950 15.09.2026 9.8
CVE-2026-73952 15.09.2026 9.1
CVE-2026-73953 15.09.2026 9.8
CVE-2026-73956 15.09.2026 9.8
CVE-2026-73957 16.09.2026 9.3
CVE-2026-73961 15.09.2026 9.8
CVE-2026-73962 16.09.2026 9.6
CVE-2026-73963 15.09.2026 9.8
CVE-2026-82994 15.09.2026 9.8
CVE-2026-82995 15.09.2026 9.8
CVE-2026-82997 16.09.2026 9.9
CVE-2026-82998 16.09.2026 9.9
CVE-2026-82999 16.09.2026 9.9
CVE-2026-83000 15.09.2026 9.8
CVE-2026-83001 16.09.2026 9.1
CVE-2026-83006 16.09.2026 9.1
CVE-2026-83020 17.09.2026 10
CVE-2026-83021 17.09.2026 10
CVE-2026-83027 16.09.2026 9.3
CVE-2026-83029 16.09.2026 9.6
CVE-2026-83031 16.09.2026 9.9
CVE-2026-83035 15.09.2026 9.8
CVE-2026-83036 15.09.2026 9.8
CVE-2026-83037 15.09.2026 9.8
CVE-2026-83038 16.09.2026 9.9
CVE-2026-83039 16.09.2026 9.9
CVE-2026-83040 16.09.2026 9.6
CVE-2026-83042 15.09.2026 9.8
CVE-2026-83043 16.09.2026 9.6
CVE-2026-83054 15.09.2026 9.8
CVE-2026-83055 17.09.2026 9.9
CVE-2026-83056 17.09.2026 9.9
CVE-2026-83057 17.09.2026 9.9
CVE-2026-83058 17.09.2026 9.9
CVE-2026-83059 17.09.2026 10
CVE-2026-83060 15.09.2026 9.8
CVE-2026-83061 15.09.2026 9.8
CVE-2026-83062 15.09.2026 9.8
CVE-2026-83064 17.09.2026 9.1
CVE-2026-83066 15.09.2026 9.8
CVE-2026-83094 15.09.2026 9.8
CVE-2026-83095 15.09.2026 9.8
CVE-2026-83098 15.09.2026 9.8
CVE-2026-83099 15.09.2026 10
CVE-2026-83100 15.09.2026 9.8
CVE-2026-83103 17.09.2026 9.1
CVE-2026-83104 15.09.2026 9.1
CVE-2026-83105 17.09.2026 9
CVE-2026-83107 17.09.2026 9.1
CVE-2026-83108 15.09.2026 9.8
CVE-2026-83149 15.09.2026 9.1
CVE-2026-83151 15.09.2026 9.8
CVE-2026-83154 15.09.2026 9.1
CVE-2026-83196 17.09.2026 9.1
CVE-2026-83197 15.09.2026 9.1
CVE-2026-83201 15.09.2026 9.1
CVE-2026-83202 15.09.2026 9.1
CVE-2026-83229 17.09.2026 9.1
CVE-2026-83232 15.09.2026 9.8
CVE-2026-83260 17.09.2026 9.1
CVE-2026-83261 15.09.2026 9.8
CVE-2026-83268 17.09.2026 9.1
CVE-2026-83269 15.09.2026 9.8
CVE-2026-83282 17.09.2026 9.9
CVE-2026-83283 15.09.2026 9.8
CVE-2026-83327 15.09.2026 9.8
CVE-2026-83339 15.09.2026 9.8
CVE-2026-83355 15.09.2026 9.8
CVE-2026-83452 15.09.2026 9.8
CVE-2026-83462 15.09.2026 9.8
CVE-2026-87128 15.09.2026 9.1
CVE-2026-87129 15.09.2026 9.1
CVE-2026-87170 15.09.2026 9.1
CVE-2026-87172 17.09.2026 9.9
CVE-2026-87173 15.09.2026 9.1
CVE-2026-87175 15.09.2026 9.1
CVE-2026-87176 15.09.2026 9.1
CVE-2026-87184 15.09.2026 9.8
CVE-2026-87186 17.09.2026 9.6
CVE-2026-87188 15.09.2026 9.8
CVE-2026-87189 17.09.2026 9.1
CVE-2026-87214 17.09.2026 9.1
CVE-2026-87217 15.09.2026 9.1
CVE-2026-87223 18.09.2026 9.1
CVE-2026-87230 18.09.2026 10
CVE-2026-89040 Tencent Mass Service Engine in Cluster (MSEC) path traversal 15.09.2026 9.3
CVE-2026-73458 On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou 15.09.2026 9.2
CVE-2026-76669 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76670 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76672 Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76673 Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator 15.09.2026 9.8
CVE-2026-76674 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways 15.09.2026 9.8
CVE-2026-76675 Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways 15.09.2026 9.1
CVE-2026-69204 Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) 15.09.2026 9.2
CVE-2026-19773 libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability 16.09.2026 9.8
CVE-2026-45579 DIRAC: RCE in RequestManager due to eval on untrusted input 15.09.2026 9.9
CVE-2026-53459 Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints 17.09.2026 9.3
CVE-2026-61667 DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval 15.09.2026 9.9
CVE-2026-12351 IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection 16.09.2026 9.8
CVE-2023-54398 Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet 15.09.2026 9.3
CVE-2024-58385 Yonyou U8 CRM SQL Injection via fillbacksettingedit.php 15.09.2026 9.3
CVE-2026-46488 motionEye: Authentication possible via password hash 17.09.2026 9.1
CVE-2026-53710 MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server 15.09.2026 10
CVE-2026-89026 Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate 17.09.2026 9.3
CVE-2026-89022 BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion 15.09.2026 9.1
CVE-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts 15.09.2026 9
CVE-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding 15.09.2026 9
CVE-2026-55211 surfio IRAP header size fields cause out-of-bounds reads 17.09.2026 9.8
CVE-2023-54397 Tornado before 6.3.3 HTTP Request Smuggling via Content-Length 17.09.2026 9
CVE-2024-14029 Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding 15.09.2026 9
CVE-2026-91931 Flowise before 3.1.4 Remote Code Execution via Custom MCP npx 17.09.2026 9
CVE-2026-91932 Flowise before 3.1.4 Remote Code Execution via cwd Parameter 15.09.2026 9
CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass 17.09.2026 9.2
CVE-2026-91988 atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP 15.09.2026 9.2
CVE-2026-61549 Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend 16.09.2026 9
CVE-2026-63696 16.09.2026 9.1
CVE-2026-55158 Conflibot: Command injection via crafted pull request branch names under pull_request_target 17.09.2026 9.1
CVE-2026-63695 16.09.2026 9.8
CVE-2026-39919 Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter 15.09.2026 9.3
CVE-2026-46495 OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI 15.09.2026 9.2
CVE-2026-59971 MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) 15.09.2026 10
CVE-2026-77179 Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback 15.09.2026 9.4
CVE-2026-89308 Arbitrary command execution in TrxTimeATTENDANCE 15.09.2026 9.3
CVE-2026-91995 pig before 4.1.0 Unverified Password Change via /register/password 18.09.2026 9.3
CVE-2026-91998 Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp 17.09.2026 9.4
CVE-2026-52824 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover 16.09.2026 9.1
CVE-2026-57147 praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery 17.09.2026 9.8
CVE-2026-57139 PraisonAI MCPServer exposes unauthenticated HTTP tools/call 17.09.2026 9.8
CVE-2026-57140 PraisonAI AgentOS exposes unauthenticated agent listing and invocation 15.09.2026 9.4
CVE-2026-57148 praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) 16.09.2026 9.8
CVE-2026-57138 PraisonAI codeMode sandbox escape via Function constructor 17.09.2026 9.9
CVE-2026-57141 PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool 15.09.2026 9.8
CVE-2026-48717 OpenAM OAuth Authorization Bypass via PKCE Challenge 15.09.2026 9.1
CVE-2026-45051 OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage 15.09.2026 9.2
CVE-2026-46619 OpenAM Authentication Bypass via MSISDN LDAP Injection 15.09.2026 9.3
CVE-2026-62263 OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass 15.09.2026 9.2
CVE-2026-45052 OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints 16.09.2026 9.3
CVE-2026-62379 OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback 15.09.2026 9.8
CVE-2026-90711 proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 15.09.2026 9.1
CVE-2026-91003 D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow 15.09.2026 9.4
CVE-2026-91001 D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow 15.09.2026 9.4
CVE-2026-90847 EFM ipTIME C200E System Setup iux_set.cgi os command injection 15.09.2026 9.4
CVE-2026-12944 Incomplete Security Scanner Blocklist Enables Network-Based Code Execution 16.09.2026 9.6
CVE-2026-67399 15.09.2026 9.3
CVE-2026-53713 Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure 16.09.2026 9.1
CVE-2026-54333 UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable 15.09.2026 9.8
CVE-2026-54334 UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen` 16.09.2026 9.8
CVE-2026-50006 Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode 15.09.2026 9.1
CVE-2026-55209 resdata insufficiently validates untrusted GRDECL files 14.09.2026 9.8
CVE-2026-16338 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 14.09.2026 9.9
CVE-2026-59178 ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade 14.09.2026 9.8
CVE-2026-90942 Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints 14.09.2026 9.3
CVE-2026-90945 Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret 16.09.2026 9.3
CVE-2026-57578 DotVVM: Missing authorization in AuthorizeActionFilter 14.09.2026 9.2
CVE-2026-20353 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76440 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76441 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76443 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability 18.09.2026 9.8
CVE-2026-61534 Yayson: Prototype pollution in the Store/LegacyStore deserialization 14.09.2026 9.1
CVE-2026-90943 parallax filament-comments through 3.0.0 Stored XSS via Comment Body 14.09.2026 9.3
CVE-2026-57124 PraisonAI UI MCP connect endpoint allows unauthenticated local command execution 14.09.2026 9.8
CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set 14.09.2026 9.8
CVE-2026-57131 praisonai: Jobs API exposes agent-execution endpoints with no authentication 14.09.2026 9.8
CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation 14.09.2026 9.1
CVE-2026-57123 PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in 14.09.2026 9.8
CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass 14.09.2026 9.8
CVE-2026-82434 Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs 14.09.2026 10
CVE-2026-90961 MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials 14.09.2026 9.3
CVE-2026-90937 froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL 16.09.2026 9.4
CVE-2026-12258 Inadequate access control in the Hiperdino REST API 14.09.2026 9.2
CVE-2026-90919 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization 14.09.2026 9.3
CVE-2026-21391 Improper Claim Validation in PingAM OIDC Provider 14.09.2026 9.5
CVE-2026-90898 Bifrost unauthenticated remote code execution via MCP stdio client registration 14.09.2026 9.8
CVE-2026-90703 D-Link DWR-M921 formDiskCreateShare system os command injection 15.09.2026 9.4
CVE-2026-90702 D-Link DWR-M921 formDiskFormat system os command injection 15.09.2026 9.4
CVE-2026-90699 D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection 14.09.2026 9.4
CVE-2026-90693 D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow 15.09.2026 9.4
CVE-2026-90692 D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow 15.09.2026 9.4
CVE-2026-85192 Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 14.09.2026 9.4
CVE-2026-90680 D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow 16.09.2026 9.4
CVE-2026-90607 Totolink A3002MU boa formNewSchedule buffer overflow 14.09.2026 9.4
CVE-2026-90608 Totolink A3002MU boa formPortFw buffer overflow 16.09.2026 9.4
CVE-2026-90606 Totolink A3002MU boa formIpv6Setup buffer overflow 15.09.2026 9.4
CVE-2026-90605 Totolink A3002MU boa formFilter buffer overflow 15.09.2026 9.4
CVE-2026-81648 CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router 14.09.2026 10
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG 18.09.2026 9.3
CVE-2026-90562 LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key 16.09.2026 9.2
CVE-2026-90493 Tonec Internet Download Manager Kernel Driver idmwfp.sys access control 15.09.2026 9.3
CVE-2026-90647 15.09.2026 9.1
CVE-2026-90558 sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers 14.09.2026 9.3

Latest Updates

CVE Title Updated Score
CVE-2026-11608 WP Customer Reviews <= 3.7.8 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter 19.09.2026 6.1
CVE-2026-11899 PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler 19.09.2026 4.3
CVE-2026-12402 OTP Login & Register Woocommerce <= 2.7.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'fb-config' Setting 19.09.2026 4.4
CVE-2026-13191 Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order_by' Parameter 19.09.2026 6.5
CVE-2026-13200 Create <= 2.5.3 - Authenticated (Author+) SQL Injection via 'order' Parameter 19.09.2026 6.5
CVE-2026-13770 AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler 19.09.2026 6.4
CVE-2026-15098 Real 3D Flipbook <= 5.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightboxtext' Shortcode Attribute 19.09.2026 6.4
CVE-2026-15463 SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' and 'host' Parameters 19.09.2026 6.1
CVE-2026-15664 Quill Forms | Conversational Multi Step Forms, Surveys & quizzes <= 5.7.1 - Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value 19.09.2026 7.2
CVE-2026-15946 Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Whitelabel Password Modification via handle_whitelabel_password_early Function 19.09.2026 4.3
CVE-2026-15947 Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Site-Wide Option Modification via 'metasync_post_types' Parameter 19.09.2026 4.3
CVE-2026-1242 BlockSpare - Gutenberg Site Builder Blocks & Starter Sites <= 4.2.6 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Creation 19.09.2026 4.3
CVE-2026-1641 Wow Elements Addons for Elementor <= 1.11.2 - Authenticated (Contributor+) Server-Side Request Forgery via Changelog File Setting 19.09.2026 6.5
CVE-2026-1984 Ibtana – Ecommerce Product Addons <= 0.4.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'iepa_use_gt_editor' AJAX Action 19.09.2026 5.3
CVE-2026-2278 VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset 19.09.2026 4.3
CVE-2026-2422 WP Composer <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pbwp_raw_shortcode' Shortcode 19.09.2026 6.4
CVE-2026-4327 The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter 19.09.2026 8.8
CVE-2026-4792 Bread <= 2.9.12 - Missing Authorization to Unauthenticated Information Exposure 19.09.2026 5.3
CVE-2026-5400 Redux Framework <= 4.5.13 - Authenticated (Subscriber+) Cross-Site Scripting via User Input 19.09.2026 6.4
CVE-2026-6295 WP Optimizer <= 2.5.0 - Authenticated (Administrator+) SQL Injection via 's' Parameter 19.09.2026 4.9
CVE-2026-75959 GoPay for WooCommerce <= 1.0.36 - Authenticated (Shop Manager+) SQL Injection via 'log_table_filter' Parameter 19.09.2026 4.9
CVE-2026-7527 WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' Parameter 19.09.2026 4.7
CVE-2026-85658 Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) 19.09.2026 8.1
CVE-2026-87917 MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dynamic Content Tag 19.09.2026 6.1
CVE-2026-9232 Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action 19.09.2026 6.5
CVE-2026-9615 Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions 19.09.2026 4.3
CVE-2026-9832 Payment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook Endpoint 19.09.2026 5.3
CVE-2026-9855 Custom Field Template <= 2.7.8 - Authenticated (Contributor+) SQL Injection via 'post_ID' Parameter 19.09.2026 6.5
CVE-2025-15698 Business Name Generator <= 1.3 - Admin+ Stored XSS via Button Color Setting 19.09.2026
CVE-2026-16557 Nimble Builder <= 3.3.8 - Subscriber+ Non-Public Content Disclosure via sek_get_nimble_content_for_seo_plugins 19.09.2026
CVE-2026-19860 JetFormBuilder 3.5.6.2 - 3.6.5.2 - Admin+ Arbitrary File Deletion via Server-Side Validation Callback 19.09.2026
CVE-2026-76554 WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import 19.09.2026
CVE-2026-76790 Estatik < 4.3.5 - Reflected XSS via get_listings hash Parameter 19.09.2026
CVE-2026-84750 Ultimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Field 19.09.2026
CVE-2026-85574 Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains 19.09.2026
CVE-2026-85680 Ultimate Member < 2.13.1 - Unauthenticated Stored XSS via Profile Page Title 19.09.2026
CVE-2026-86591 Botiga Pro < 1.6.5 - Unauthenticated Arbitrary Blog Options Update via Templates Builder REST Route 19.09.2026
CVE-2026-86814 UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email 19.09.2026
CVE-2026-88824 Master Blocks 1.4.1 - 1.4.1.4 - Unauthenticated Stored XSS via White Label Settings 19.09.2026
CVE-2026-88926 VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi 19.09.2026
CVE-2026-91847 Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR 19.09.2026
CVE-2026-92099 WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias Squatting 19.09.2026
CVE-2026-92403 Secure Custom Fields < 6.9.4 - Unauthenticated Post Modification via Front-End Form ID Substitution 19.09.2026
CVE-2026-92404 MgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential Disclosure 19.09.2026
CVE-2026-92420 Hydra Booking < 1.2.2 - Hydra Host+ Cross-Host Booking Deletion and Modification via IDOR 19.09.2026
CVE-2026-92421 Hydra Booking 1.1.0 - < 1.2.3 - Hydra Host+ Host Profile Takeover via IDOR 19.09.2026
CVE-2026-92425 Hydra Booking < 1.2.4 - Hydra Host+ Cross-Host Account Modification and Deletion via IDOR 19.09.2026
CVE-2026-92430 Rede Itaú for WooCommerce < 5.4.7 - Unauthenticated Order Status Manipulation via PIX Webhook 19.09.2026
CVE-2026-92435 Mailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST API 19.09.2026
CVE-2026-93741 Totolink A3002MU formWlWds buffer overflow 19.09.2026
CVE-2026-12042 WP2Social Auto Publish <= 2.4.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'pages' Parameter 19.09.2026 4.4
CVE-2026-13354 Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Unauthenticated Stored Cross-Site Scripting via Comment Content 19.09.2026 7.2
CVE-2026-15660 SEO Booster <= 7.4.7 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() 19.09.2026 4.3
CVE-2026-15760 Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action 19.09.2026 6.5
CVE-2026-84434 Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field 19.09.2026 9.8
CVE-2026-87909 WP Photo Album Plus <= 9.2.09.002 - Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection 19.09.2026 7.5
CVE-2026-88944 Tutor LMS <= 4.0.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'lesson_id' Parameter 19.09.2026 4.3
CVE-2026-89081 Tutor LMS <= 4.0.8 - Reflected Cross-Site Scripting via 'back_url' and 'search' Parameters 19.09.2026 6.1
CVE-2026-89093 Better Messages <= 2.15.33 - Unauthenticated Information Exposure Spoofing via 'X-Real-IP' Header via /guests/register 19.09.2026 5.3
CVE-2026-89274 WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content 19.09.2026 9.1
CVE-2026-89333 Tutor LMS <= 4.0.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Exposure via 'student_id' Parameter 19.09.2026 6.5
CVE-2026-89334 Better Messages <= 2.15.33 - Missing Authorization to Authenticated (Custom+) Chat-Room Transcript Disclosure via '/thread/<id>' REST Endpoint 19.09.2026 6.5
CVE-2026-92229 Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter 19.09.2026 9.1
CVE-2026-92807 Save as PDF Plugin by PDFCrowd <= 4.6.1 - Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute 19.09.2026 8.8
CVE-2026-92967 Pochipp <= 1.20.2 - Reflected Cross-Site Scripting via 'keyword' Parameter 19.09.2026 6.1
CVE-2026-77820 WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute 19.09.2026 6.4
CVE-2026-77875 Hide Photos - Secure vault 4.1.0 - Insecure storage of vault media and wallet records in shared external storage 18.09.2026
CVE-2026-93921 SiYuan through 3.8.4 Access Control Bypass via Dynamic Icon Endpoint 18.09.2026
CVE-2026-93922 SiYuan through 3.8.4 Stored XSS via notebook names 18.09.2026
CVE-2026-93923 SiYuan through 3.8.4 Stored XSS via Heading Style Attribute 18.09.2026
CVE-2026-75885 Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint 18.09.2026
CVE-2026-93740 Totolink A3002MU formWlEncrypt buffer overflow 18.09.2026
CVE-2026-93739 Totolink A3002MU formWlAc buffer overflow 18.09.2026
CVE-2026-93738 Totolink A3002MU formSchedule buffer overflow 18.09.2026
CVE-2026-88097 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 18.09.2026 8.1
CVE-2026-61670 microsandbox: Secret values exposed in world-readable process arguments 18.09.2026 6.5
CVE-2026-68928 Acode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as Acode 18.09.2026 8.6
CVE-2026-85271 Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of CVE-2026-42857) 18.09.2026 6.1
CVE-2026-57223 Suricata windows: unquoted LocalSystem service ImagePath can allow local privilege escalation 18.09.2026 7
CVE-2026-71418 Suricata doh2: crafted HTTP/2 DATA frames can cause quadratic CPU consumption 18.09.2026 7.5
CVE-2026-71855 Suricata flow: IPv4/IPv6 hash collision can reuse wrong flow state 18.09.2026 5.9
CVE-2026-85272 Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation 18.09.2026 4.3
CVE-2026-93894 18.09.2026
CVE-2026-57225 Suricata datasets: NULL pointer dereference in JSON/NDJSON dataset loading 18.09.2026 3.3
CVE-2026-57227 Suricata mqtt: unbounded resource consumption from repeated pubrec and pubrel messages 18.09.2026 7.5
CVE-2026-57228 Suricata smtp/mime: heap out-of-bounds read quoted-printable decoder 18.09.2026 8.2
CVE-2026-57229 Suricata smtp/mime: incomplete state reset allows detection bypass 18.09.2026 5.3
CVE-2026-63446 Suricata app-layer: passed flows can retain transactions, causing resource exhaustion 18.09.2026 7.5
CVE-2026-63447 Suricata ftp: crafted FTP traffic can cause quadratic CPU consumption 18.09.2026 7.5
CVE-2026-63448 Suricata smb: some SMB flows can cause resource exhaustion 18.09.2026 5.9
CVE-2026-63449 Suricata sip: large SIP message bodies can evade detection with frame keyword 18.09.2026 3.7
CVE-2026-63450 Suricata ftp: RETR/STOR before PORT/PASV can disable further IDS app-layer detection 18.09.2026 3.7
CVE-2026-63451 Suricata detect: frame rules without content and with transform can cause heap buffer overflow during rule load 18.09.2026 3.3
CVE-2026-63452 Suricata http1: repeated brotli compression bombs can cause excessive CPU consumption 18.09.2026 7.5
CVE-2026-93562 Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling 18.09.2026
CVE-2026-93574 Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in chunk-size parsing 18.09.2026
CVE-2026-57222 Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6 18.09.2026 5.3
CVE-2026-57224 Suricata dhcp: unbounded transactions in unidirectional traffic can lead to resource exhaustion 18.09.2026 6.5
CVE-2026-57226 Suricata swf: heap buffer overflow in SWF decompression depth handling 18.09.2026 3.7
CVE-2026-58264 FluidSynth: Heap-based buffer overrun 18.09.2026 9.8
CVE-2026-61714 FluidSynth: Heap Buffer Overflow in MIDI Player 18.09.2026 7.8
CVE-2026-61720 FluidSynth: SF2 DMOD Chunk Unsigned Underflow 18.09.2026 6.2
CVE-2026-61721 FluidSynth: Heap-based buffer overrun for DLS samples 18.09.2026 8
CVE-2026-61722 FluidSynth: DLS Articulation Chunk Integer Overflow 18.09.2026 6.8
CVE-2026-61723 FluidSynth: DLS ptbl Chunk Integer Overflow 18.09.2026 6.8
CVE-2026-76899 CordysCRM: Authenticated SQL injection via `sort.name` on `POST /account-pool/page` 18.09.2026 5.7
CVE-2026-76902 CordysCRM: Unauthenticated arbitrary file disclosure via `/attachment/preview/{id}` and `/pic/preview/{id}` 18.09.2026 5
CVE-2026-63646 CordysCRM MCP Form Configuration Endpoint Exposed to Anonymous Users 18.09.2026
CVE-2026-63647 CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` 18.09.2026
CVE-2026-76900 CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime 18.09.2026 6.8
CVE-2026-76901 CordysCRM: Broken object-level authorization in lead pool and account pool detail endpoints exposes arbitrary leads and accounts 18.09.2026 5.8
CVE-2026-84086 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.2
CVE-2026-84089 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.8
CVE-2026-84105 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.7
CVE-2026-84106 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.9
CVE-2026-84108 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.1
CVE-2026-84239 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.6
CVE-2026-84241 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.1
CVE-2026-92708 devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node Buffers 18.09.2026 7.5
CVE-2026-93868 Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG 18.09.2026
CVE-2026-93869 Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex 18.09.2026
CVE-2026-93870 Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler 18.09.2026
CVE-2026-93871 Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix 18.09.2026
CVE-2026-93872 Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter 18.09.2026
CVE-2026-93873 Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin 18.09.2026
CVE-2026-52745 CordysCRM: Customer Public Pool Sorting Field SQL Injection 18.09.2026 5.3
CVE-2026-61817 pg_partman privilege escalation via SQL injection in several functions via time decoder 18.09.2026 8.5
CVE-2026-61818 pg_partman SQL injection in undo partition time encoder 18.09.2026 8.5
CVE-2026-61819 pg_partman privilege escalation via SQL injection in when using pg_jobmon and encountering exception 18.09.2026 8.5
CVE-2026-61820 pg_partman privilege escalation via SQL injection when inheriting template properties 18.09.2026 8.5
CVE-2026-61821 pg_partman authorization bypass to move child tables between schemas during retention 18.09.2026 8.5
CVE-2026-61822 pg_partman disable maintenance for all partition sets 18.09.2026 6.5
CVE-2026-84073 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.1
CVE-2026-84074 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.9
CVE-2026-84075 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-84076 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.6
CVE-2026-84077 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.1
CVE-2026-84078 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-84081 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.1
CVE-2026-84082 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-84083 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.8
CVE-2026-84084 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.8
CVE-2026-84085 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.1
CVE-2026-61781 pg_partman has privilege escalation through SQL injection in create_partition_time() 18.09.2026 9.9
CVE-2026-77528 Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation 18.09.2026 5.3
CVE-2026-84034 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.8
CVE-2026-84036 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.4
CVE-2026-84064 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-84070 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.9
CVE-2026-84071 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.2
CVE-2026-82890 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 5.9
CVE-2026-82892 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.1
CVE-2026-82893 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.8
CVE-2026-82896 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.6
CVE-2026-82967 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-84031 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9
CVE-2026-93031 WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box <= 3.8.3 - Authenticated (Subscriber+) Arbitrary File Upload via Media Import 18.09.2026 8.8
CVE-2026-81623 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 6.3
CVE-2026-81626 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.6
CVE-2026-81656 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.8
CVE-2026-81657 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-81669 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.2
CVE-2026-81933 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.8
CVE-2026-81937 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 7.2
CVE-2026-82340 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-82832 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.6
CVE-2026-82885 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.8
CVE-2026-82887 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 8.8
CVE-2026-11727 IBM MQ for HPE NonStop is vulnerable to a denial of service issue 18.09.2026 8.1
CVE-2026-17262 IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ] 18.09.2026 5.4
CVE-2026-17619 The IBM Platform RTM is affected by an SQL injection vulnerability 18.09.2026 8.6
CVE-2026-18869 IBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ] 18.09.2026 6.4
CVE-2026-75878 IBM Sterling File Gateway is Vulnerable to Authentication Bypass 18.09.2026 9.1
CVE-2026-80441 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-80442 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.9
CVE-2026-91202 Cockpit-files: cockpit-files: arbitrary file ownership change via symlink following in privileged paste 18.09.2026
CVE-2026-91203 Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition 18.09.2026
CVE-2017-20284 Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet 18.09.2026
CVE-2026-11539 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 18.09.2026 5.3
CVE-2026-11540 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 18.09.2026 5.3
CVE-2026-11545 IBM WebSphere Application Server is affected by a privilege escalation 18.09.2026 3.7
CVE-2026-11548 Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. 18.09.2026 4.8
CVE-2026-11549 Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. 18.09.2026 6.5
CVE-2026-11710 IBM WebSphere Application Server is affected by an HTTP request smuggling vulnerability 18.09.2026 6.5
CVE-2026-11711 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 18.09.2026 6.5
CVE-2026-11716 IBM MQ for HPE NonStop is vulnerable to a denial of service attack 18.09.2026 7.5
CVE-2026-11722 Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. 18.09.2026 4.8
CVE-2026-11725 IBM MQ queue manager is vulnerable to privilege escalation 18.09.2026 8.8
CVE-2026-11726 IBM MQ for HPE NonStop is vulnerable to a denial of service issue 18.09.2026 8.1
CVE-2026-75895 Out of bounds read at smpp34_unpack() 18.09.2026
CVE-2026-91205 Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race 18.09.2026
CVE-2026-93838 SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx 18.09.2026
CVE-2026-93839 LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint 18.09.2026
CVE-2026-93840 vLLM before 0.29.0 Cross-Request Logits Corruption via allowed_token_ids 18.09.2026
CVE-2026-93841 vLLM through 0.29.0 Adjacent-Request Sampler State Corruption via Unvalidated Prompt Token IDs 18.09.2026
CVE-2019-25776 Weaver E-cology SQL Injection via SyncUserInfo.jsp 18.09.2026
CVE-2021-48008 Chanjet CRM SQL Injection via get_usedspace.php 18.09.2026
CVE-2023-54399 Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree 18.09.2026
CVE-2026-11538 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 18.09.2026 3.7
CVE-2026-93854 18.09.2026
CVE-2026-75894 Reachable assertion at ranap_handle_co_dt() 18.09.2026
CVE-2026-93852 18.09.2026
CVE-2026-75892 Out of bounds write in PDP ctx GSN-Address decode 18.09.2026
CVE-2026-75893 Heap based buffer overflow at ipaccess_proxy_read_msg() 18.09.2026
CVE-2026-93650 Saleor throttling.py get_client_ip excessive authentication 18.09.2026
CVE-2026-59163 Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass 18.09.2026 9.1
CVE-2026-92745 Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments 18.09.2026
CVE-2026-92747 Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list 18.09.2026
CVE-2026-92768 Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments 18.09.2026
CVE-2026-93432 Io.quarkus.qute:quarkus-core: cross-site scripting (xss) and json injection via qute {#eval} section in quarkus 18.09.2026
CVE-2026-81180 SysReptor: Authenticated RCE by insecure image processing 18.09.2026 8.8
CVE-2026-81181 SysReptor: Session Fixation in Password-Protected Shared Notes 18.09.2026 3.7
CVE-2026-81182 SysReptor: Unauthorized file disclosure by broken access control in writable shared notes 18.09.2026 4.2
CVE-2026-93748 http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale 18.09.2026
CVE-2026-93749 source-map-js through 1.2.1 Event Loop Denial of Service 18.09.2026
CVE-2026-93750 http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard 18.09.2026
CVE-2026-93751 uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars 18.09.2026
CVE-2026-93752 CSSOM through 0.5.0 Denial of Service via length Property 18.09.2026
CVE-2026-93753 deepmerge through 4.3.1 Prototype Poisoning via mergeObject 18.09.2026
CVE-2026-71537 Paymenter: Credit-refund double-spend race condition in service downgrade (doUpgrade) 18.09.2026 6.5
CVE-2026-81178 SysReptor: Anonymous note-share link discloses project member identities and non-shared note activity 18.09.2026 3.5
CVE-2026-81179 SysReptor: Host header injection might allow account takeover 18.09.2026 8.1
CVE-2026-85058 Moquette: Missing Authorization in io.moquette:moquette-broker 18.09.2026 7.5
CVE-2026-32641 Parseable: Unauthenticated Denial of Service via panic in Kinesis header parsing middleware 18.09.2026 7.5
CVE-2026-63199 Perses: Missing authorization in datasource proxy allows cross-scope secret disclosure 18.09.2026
CVE-2026-63445 Perses: Unvalidated project parameter enables filesystem path traversal 18.09.2026
CVE-2026-63458 Perses project query parameter authorization bypass exposes cross-project resources 18.09.2026
CVE-2026-69184 c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains 18.09.2026 7.5
CVE-2026-93759 Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist 18.09.2026
CVE-2026-61550 Icinga 2: Improper access control for JSON-RPC update certificate messages 18.09.2026 9.8
CVE-2026-61551 Icinga 2: Stack overflow via deeply nested JSON objects 18.09.2026 8.6
CVE-2026-61552 Icinga 2 DSL Injection via Unescaped Import Template Name 18.09.2026 7.2
CVE-2026-69186 c-ares: Memory-amplification denial of service via unvalidated DNS header record counts 18.09.2026 5.3
CVE-2026-91127 File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer 18.09.2026 8.2
CVE-2026-93760 NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard 18.09.2026
CVE-2026-93761 Denial of service via unbounded regex matching in Mongoid's in-memory query matcher 18.09.2026
CVE-2025-66455 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py 18.09.2026 9.8
CVE-2026-33625 LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading 18.09.2026 8.8
CVE-2026-62278 LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to Write Files Outside Data Directory 18.09.2026 8.1
CVE-2026-62279 LubeLogger: IDOR in DuplicateRecordsToOtherVehicles Allows Copying Records from Any User's Vehicle Without Ownership Check 18.09.2026 7.1
CVE-2026-64847 AnyIO process-pool workers can block indefinitely on undrained stderr 18.09.2026
CVE-2026-77385 Kyoo: Transcoder serves uncataloged files from the media directory 18.09.2026 4.3
CVE-2026-77386 Kyoo: OIDC login token can be redirected to an attacker-controlled URL 18.09.2026 6.5
CVE-2026-77396 PJSIP: Heap buffer overflow in the AVI parser 18.09.2026
CVE-2026-84975 PJSIP: TLS server identity (hostname) verification bypass via embedded NUL in certificate SubjectAltName (OpenSSL and GnuTLS backends) 18.09.2026 7.4
CVE-2026-84992 md-editor-v3: XSS via fenced-code language rendering bypass 18.09.2026 6.1
CVE-2026-92701 Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path 18.09.2026 9.1
CVE-2026-92702 Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path 18.09.2026 9.1
CVE-2026-93762 Data deletion and attribute disclosure via field-name method injection in in-memory queries 18.09.2026
CVE-2026-93763 Silent plaintext persistence via unresolved callable database name in encryption schema map 18.09.2026
CVE-2026-93764 Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation 18.09.2026
CVE-2026-63349 AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups 18.09.2026
CVE-2026-77616 Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token 18.09.2026 6.1
CVE-2026-93758 Cross-principal document update, theft, and deletion via unvalidated id in nested attributes 18.09.2026
CVE-2026-93765 Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation 18.09.2026
CVE-2026-55556 Rsyslog: Heap buffer overflow in imhttp plugin Basic Authentication handling 18.09.2026
CVE-2026-61548 Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data 18.09.2026 8.1
CVE-2026-61833 zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion 18.09.2026 8.1
CVE-2026-63406 AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets 18.09.2026 5.9
CVE-2026-77607 Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS 18.09.2026 6.1
CVE-2026-77609 Semantic MediaWiki has an open redirect in Special:URIResolver 18.09.2026 6.1
CVE-2026-77610 Semantic MediaWiki has a query debug output XSS (`DebugFormatter`) 18.09.2026 6.1
CVE-2026-46655 virtio-win: Integer overflow causing a heap overflow in Viosock driver 18.09.2026 7.8
CVE-2026-63405 AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body 18.09.2026 5.9
CVE-2026-77239 WACRM: Service-role routes missing a role check 18.09.2026 8.1
CVE-2026-93559 Forget-C Jellyfish AI Short Drama Studio FastAPI dependencies.py missing authentication 18.09.2026
CVE-2026-77240 WACRM: Database-layer authorization bypasses 18.09.2026 9.9
CVE-2026-77301 adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) 18.09.2026 7.5
CVE-2026-77339 Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools 18.09.2026
CVE-2026-77606 Semantic MediaWiki has reflected XSS in Special:Ask plain table headers 18.09.2026 6.1
CVE-2026-77608 Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters) 18.09.2026 6.1
CVE-2026-91142 Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds 18.09.2026
CVE-2026-91147 Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash 18.09.2026
CVE-2026-91149 Cockpit: cockpit: denial of service via unbounded connection thread spawning 18.09.2026
CVE-2026-93579 Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough) 18.09.2026
CVE-2026-58197 ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement 18.09.2026 8.8
CVE-2026-61672 Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement 18.09.2026 7.1
CVE-2026-61795 Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation 18.09.2026 6.8
CVE-2026-93534 spatie Scotty Self Update SelfUpdater.php update code download 18.09.2026
CVE-2026-44639 NanoMQ: O(N²) Denial of Service in MQTT v5 Property Parsing 18.09.2026 3.7
CVE-2026-61633 NanoMQ: Infinite Loop in UNSUBSCRIBE Decoder Leading to Remote DoS 18.09.2026 2
CVE-2026-61794 Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic 18.09.2026 6.8
CVE-2026-62943 btrbk: SSH Command Filter Bypass in ssh_filter_btrbk.sh 18.09.2026
CVE-2026-73863 NanoMQ: Heap-Buffer-Overflow in `nmq_subinfo_decode()` During MQTT v5 SUBSCRIBE Parsing 18.09.2026
CVE-2026-81321 CareCam CM2507 Cleartext Storage of Sensitive Information 18.09.2026 9.8
CVE-2026-81505 Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials 18.09.2026
CVE-2026-85478 CareCam CM2507 Missing Authentication for Critical Function 18.09.2026 3.5
CVE-2026-85497 CareCam CM2507 Use of Password Hash With Insufficient Computational Effort 18.09.2026 9.8
CVE-2026-93338 Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community String 18.09.2026
CVE-2026-93533 spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection 18.09.2026
CVE-2025-61682 Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes 18.09.2026 8.6
CVE-2026-10841 Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced. 18.09.2026 4.2
CVE-2026-10853 IBM MQ queue manager is vulnerable to remote code execution 19.09.2026 7.5
CVE-2026-10858 IBM MQ for HPE NonStop is vulnerable to a denial of service attack 19.09.2026 9.9
CVE-2026-11375 IBM MQ queue manager is vulnerable to remote code execution 19.09.2026 8.8
CVE-2026-11378 IBM MQ queue manager is vulnerable to remote code execution 19.09.2026 8.8
CVE-2026-11381 IBM MQ for HPE NonStop is vulnerable to a denial of service issue 19.09.2026 8.8
CVE-2026-11537 IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities 18.09.2026 4.3
CVE-2026-54147 http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI 18.09.2026 6.5
CVE-2026-54148 http4k: `DigestAuthProvider.verify` did not bind to request URI 18.09.2026 8.1
CVE-2026-61682 kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace 18.09.2026 9.9
CVE-2026-68914 Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data 18.09.2026
CVE-2026-77568 Mojolicious: CSRF tokens are vulnerable to BREACH attacks 18.09.2026 4.2
CVE-2026-81305 CareCam CM2507 Inclusion of Functionality from Untrusted Control Sphere 18.09.2026 6.8
CVE-2026-84398 CareCam CM2507 Empty Password in Configuration File 18.09.2026 7.5
CVE-2026-84400 CareCam CM2507 Missing Authentication for Critical Function 18.09.2026 3.1
CVE-2026-84447 libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS 18.09.2026 7.5
CVE-2026-84449 libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV 18.09.2026 3.7
CVE-2026-84450 libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289) 18.09.2026 4.3
CVE-2026-84451 libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read 18.09.2026 6.5
CVE-2026-88259 CareCam CM2507 Missing Authentication for Critical Function 18.09.2026 7.5
CVE-2026-93736 Mealie before 3.21.0 Information Disclosure via Ratings Endpoint 18.09.2026
CVE-2026-93737 Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet 18.09.2026
CVE-2026-10575 IBM MQ queue manager is vulnerable to remote code execution 19.09.2026 8.8
CVE-2026-10744 IBM MQ for HPE NonStop is vulnerable to a issue in MQINQ request validation 19.09.2026 7.5
CVE-2026-10747 IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing 19.09.2026 10
CVE-2026-10751 IBM MQ Java messaging is vulnerable to remote code execution 19.09.2026 7.5
CVE-2026-84383 libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items 18.09.2026 9.8
CVE-2026-84384 libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS 18.09.2026 7.5
CVE-2026-84444 libheif uncompressed tiled image encoding allows out-of-bounds write 18.09.2026 7.4
CVE-2026-84446 libheif: Sequence decode timing-table initialization allows non-terminating loops and unbounded memory, bypassing max_sequence_frames 18.09.2026 7.5
CVE-2026-84448 libheif: Heap out-of-bounds read in libheif inline-mask region API (heif_region_item_add_region_inline_mask_data / heif_region_get_mask_image) 18.09.2026 4
CVE-2026-10030 IBM MQ Console is vulnerable to privilege escalation 18.09.2026 7.1
CVE-2026-1025 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 18.09.2026 6.1
CVE-2026-1029 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 18.09.2026 5.4
CVE-2026-1030 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 18.09.2026 4.3
CVE-2026-1031 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 18.09.2026 6.1
CVE-2026-1037 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 18.09.2026 6.1
CVE-2026-63419 OpenImageIO: IFF ZBUFFER tile read writes past caller tile buffer 18.09.2026 7.8
CVE-2026-63638 OpenImageIO: Cineon invalid bit depth heap out-of-bounds write 18.09.2026 8.3
CVE-2026-65969 OpenImageIO: TGA-to-GIF palette split signed overflow causes SIGSEGV 18.09.2026 5.5
CVE-2026-67549 OpenImageIO: TIFF 1-bit CMYK bit conversion heap out-of-bounds write 18.09.2026 7.6
CVE-2026-77960 Use of Hard-coded Credentials in Bransys ELD 18.09.2026 5.3
CVE-2026-86689 Cleartext Transmission of Sensitive Information in Bransys ELD 18.09.2026 5.9
CVE-2025-36045 TS4300 Tape Library addresses security vulnerability 18.09.2026 4.3
CVE-2025-36076 IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities 18.09.2026 4.3
CVE-2025-36147 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting. 18.09.2026 6.1
CVE-2025-36178 Multiple vulnerabilities in IBM Controller 18.09.2026 5.4
CVE-2025-36421 Multiple vulnerabilities in IBM Controller 18.09.2026 5.9
CVE-2026-10027 IBM MQ queue manager is vulnerable to unauthenticated remote code execution 19.09.2026 8.1
CVE-2026-65970 OpenImageIO: TIFF multithreaded scanline read use-after-scope in `TIFFInput::read_native_scanlines` 18.09.2026 5.3
CVE-2026-86520 Use of Hard-coded Credentials in Bransys ELD 18.09.2026 7.5
CVE-2026-93532 gedelumbung HospitalManagement Password Change password.php simpan improper authentication 18.09.2026
CVE-2025-15399 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 19.09.2026 10
CVE-2025-33141 IBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment. 18.09.2026 6.5
CVE-2025-33147 IBM Cognos Analytics versions 12.0.4 and 12.1.3 is affected by security vulnerabilities 18.09.2026 5.9
CVE-2026-59156 OpenImageIO: Unbounded recursion in FITS header parser leads to stack overflow 18.09.2026 6.5
CVE-2026-59181 OpenImageIO: Stack buffer overflow in OpenImageIO Cineon reader via unchecked numberOfElements 18.09.2026 6.1
CVE-2026-59956 OpenImageIO: Heap-buffer-overread in IffInput::readimg() when ZBUFFER flag is set 18.09.2026 6.1
CVE-2026-63420 OpenImageIO: PSD RawColor indexed image out-of-bounds read in `interleave_row` 18.09.2026 5.5
CVE-2026-63422 OpenImageIO OpenEXR plugin partial edge tile heap out-of-bounds write 18.09.2026 7.8
CVE-2026-63635 OpenImageIO: PSD RawColor invalid color mode causes global out-of-bounds read and allocation DoS 18.09.2026 5.5
CVE-2025-14753 IBM Cloud Pak for Data is vulnerable to path traversal 18.09.2026 7.5
CVE-2025-14754 IBM Cloud Pak for Data is vulnerable to OS command injection 18.09.2026 8.8
CVE-2026-75031 18.09.2026
CVE-2026-75883 PPPD buffer overflow in PEAP response code 18.09.2026 6.8
CVE-2026-81946 PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 Algorithm 18.09.2026
CVE-2025-53837 org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 18.09.2026 9.9
CVE-2026-60115 18.09.2026
CVE-2026-7006 Sublime Text 4192/3207 Local Privilege Escalation via Update Staging Mechanism 18.09.2026
CVE-2026-81942 PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web Server 18.09.2026
CVE-2026-81943 PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCE 18.09.2026
CVE-2026-81944 PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web Server 18.09.2026
CVE-2026-81945 PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web Server 18.09.2026
CVE-2026-93531 gedelumbung HospitalManagement cross-site request forgery 18.09.2026
CVE-2026-93687 braces through 3.0.3 Stack Overflow via Deeply Nested Patterns 18.09.2026
CVE-2026-93688 SGLang through 0.5.19 Unbounded Memory Allocation via bootstrap_room 18.09.2026
CVE-2026-93689 WinFsp through 2.2.26215 NULL Pointer Dereference via Fast I/O 18.09.2026
CVE-2026-93690 uri-js through 4.4.1 Denial of Service via removeDotSegments 18.09.2026
CVE-2026-93506 SveltyCMS File Upload Endpoint upload-media server-side request forgery 18.09.2026
CVE-2026-93573 Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked validation and enable request smuggling 18.09.2026
CVE-2026-93685 Multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.newcontrollercommandconfig (confirmed exposed by engineering) 18.09.2026
CVE-2025-13882 Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager. 18.09.2026 5.3
CVE-2025-1350 Multiple vulnerabilities in IBM Controller 18.09.2026 5.3
CVE-2026-93568 Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended connect requests are downgraded as regular connect requests 18.09.2026
CVE-2026-93576 Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419) 18.09.2026
CVE-2026-93652 Integer Overflow or Wraparound in µD3TN 18.09.2026 7.5
CVE-2024-56344 IBM Cognos Analytics 12.0.4 and 12.1.3 versions are affected by security vulnerabilities 18.09.2026 5.9
CVE-2026-16512 Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames 18.09.2026 3.1
CVE-2026-16514 Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved 18.09.2026 4.3
CVE-2026-16515 ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack 18.09.2026 4.7
CVE-2026-77929 ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint 18.09.2026
CVE-2026-85511 Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2 18.09.2026
CVE-2026-93567 Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/2 connect with host-controlled :authority 18.09.2026
CVE-2026-93569 Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :authority, overriding the request-target authority 18.09.2026
CVE-2026-93657 hickory-resolver before 0.26.2 DNSSEC Validation Bypass 18.09.2026
CVE-2026-93658 uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid 18.09.2026
CVE-2026-93659 Concrete CMS Community Store before 2.7.8 Stored XSS 18.09.2026
CVE-2026-93660 SQLBot through 1.10.1 Improper Access Control via Dashboard Update 18.09.2026
CVE-2026-10832 Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload 18.09.2026
CVE-2026-25684 File Type Control rule bypass 18.09.2026 4.4
CVE-2026-77927 ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint 18.09.2026
CVE-2026-77928 ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint 18.09.2026
CVE-2026-93505 SveltyCMS SVG Media Upload media-service.server.ts cross site scripting 18.09.2026
CVE-2026-93558 Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service 18.09.2026
CVE-2026-93564 Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881) 18.09.2026
CVE-2026-93565 Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte 18.09.2026
CVE-2026-93566 Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line 18.09.2026
CVE-2026-93653 Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service) 18.09.2026
CVE-2026-93676 Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks 18.09.2026
CVE-2026-93018 Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p 18.09.2026
CVE-2026-93019 Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read 18.09.2026
CVE-2026-62282 OpenCVE: Server-Side Request Forgery (SSRF) in notifications 18.09.2026 6.5
CVE-2026-79294 18.09.2026
CVE-2026-93560 Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos 18.09.2026
CVE-2026-88622 18.09.2026
CVE-2026-88623 18.09.2026
CVE-2023-5778 Missing Length Check 18.09.2026 7.5
CVE-2026-93504 SveltyCMS User Attribute Update Endpoint +server.ts access control 18.09.2026
CVE-2026-93586 ImageMagick before 7.1.2-31 Use After Free via ImagesToBlob 18.09.2026
CVE-2026-93587 ImageMagick before 7.1.2-31 Policy Bypass via PCD decoder 18.09.2026
CVE-2026-93588 ImageMagick before 7.1.2-31 Null Pointer Dereference via PNM 18.09.2026
CVE-2026-93589 ImageMagick before 7.1.2-31 Division by Zero in FLIF encoder 18.09.2026
CVE-2026-93590 ImageMagick before 7.1.2-31 Policy Bypass in UHDR encoder 18.09.2026
CVE-2026-93591 SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go 18.09.2026
CVE-2026-93592 vLLM before 0.28.0 Denial of Service via negative token ID 18.09.2026
CVE-2026-93593 ArcadeDB before 26.9.1 TimeSeries ACL Bypass via Type Permission 18.09.2026
CVE-2026-93594 ArcadeDB before 26.9.1 ACL Bypass via Index and TimeSeries 18.09.2026
CVE-2026-93595 ArcadeDB before 26.9.1 ACL Bypass via query_database Tool 18.09.2026
CVE-2026-93596 ArcadeDB before 26.9.1 Authorization Bypass via Batch Edge Connect 18.09.2026
CVE-2026-93597 ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses 18.09.2026
CVE-2026-93598 ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle 18.09.2026
CVE-2026-93599 rustls-webpki before 0.103.13 Panic via empty BIT STRING 18.09.2026
CVE-2026-93600 rustls webpki Name Constraints URI Validation Bypass 18.09.2026
CVE-2026-93601 rustls webpki 0.101.0 before 0.103.12 Name Constraint Bypass 18.09.2026
CVE-2026-93602 rustls-webpki before 0.103.10 CRL Revocation Check Bypass 18.09.2026
CVE-2026-93603 vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function 18.09.2026
CVE-2026-93604 vm2 3.11.8 Sandbox Escape via crypto.setFips 18.09.2026
CVE-2026-93605 vm2 NodeVM before 3.12.1 Remote Code Execution via child_process 18.09.2026
CVE-2026-93606 vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species 18.09.2026
CVE-2026-93491 Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 pipeline queue 18.09.2026
CVE-2026-93492 Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size 18.09.2026