| CVE-2026-6640 |
Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter |
11.09.2026 |
6.4 |
| CVE-2026-6641 |
Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter |
11.09.2026 |
6.4 |
| CVE-2026-6642 |
Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import |
11.09.2026 |
6.4 |
| CVE-2026-89175 |
Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication |
11.09.2026 |
|
| CVE-2026-89176 |
Howyar|WeenyGenius - Missing Authentication |
11.09.2026 |
|
| CVE-2026-89177 |
Howyar|WeenyGenius - Use of Insecure Protocol |
11.09.2026 |
|
| CVE-2026-89178 |
Howyar|WeenyGenius - Origin Validation Error |
11.09.2026 |
|
| CVE-2026-89179 |
Howyar|WeenyGenius - Missing Support for Integrity Check |
11.09.2026 |
|
| CVE-2026-89173 |
Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure |
11.09.2026 |
|
| CVE-2026-89174 |
Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection |
11.09.2026 |
|
| CVE-2026-73785 |
HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability |
11.09.2026 |
7.5 |
| CVE-2026-87908 |
multiparty vulnerable to Denial of Service via unbounded part-header accumulation |
11.09.2026 |
7.5 |
| CVE-2025-15695 |
GTranslate < 3.0.10 - Admin+ Stored XSS |
11.09.2026 |
|
| CVE-2026-13326 |
Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module |
11.09.2026 |
|
| CVE-2026-14559 |
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover |
11.09.2026 |
|
| CVE-2026-14560 |
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload |
11.09.2026 |
|
| CVE-2026-14562 |
Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure |
11.09.2026 |
|
| CVE-2026-14563 |
Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover |
11.09.2026 |
|
| CVE-2026-14565 |
Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration |
11.09.2026 |
|
| CVE-2026-14566 |
Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tampering |
11.09.2026 |
|
| CVE-2026-73784 |
HPE IceWall products, Remote Bypass of Security Restrictions |
11.09.2026 |
8.8 |
| CVE-2026-74925 |
MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator |
11.09.2026 |
|
| CVE-2026-82305 |
YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title |
11.09.2026 |
|
| CVE-2026-83545 |
CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON |
11.09.2026 |
|
| CVE-2026-83546 |
CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute |
11.09.2026 |
|
| CVE-2026-85677 |
Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content |
11.09.2026 |
|
| CVE-2026-85678 |
AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript |
11.09.2026 |
|
| CVE-2026-86779 |
Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart |
11.09.2026 |
|
| CVE-2026-86780 |
Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text |
11.09.2026 |
|
| CVE-2026-86781 |
SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure |
11.09.2026 |
|
| CVE-2026-86782 |
Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR |
11.09.2026 |
|
| CVE-2026-86812 |
WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API |
11.09.2026 |
|
| CVE-2026-86815 |
BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes |
11.09.2026 |
|
| CVE-2026-89169 |
|
11.09.2026 |
|
| CVE-2026-89060 |
Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references |
11.09.2026 |
|
| CVE-2026-89162 |
|
11.09.2026 |
2.9 |
| CVE-2026-89156 |
|
11.09.2026 |
2.9 |
| CVE-2026-89157 |
|
11.09.2026 |
5.7 |
| CVE-2026-89158 |
|
11.09.2026 |
6.5 |
| CVE-2026-89160 |
|
11.09.2026 |
3.7 |
| CVE-2026-89161 |
|
11.09.2026 |
7.4 |
| CVE-2026-11446 |
Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization |
11.09.2026 |
5.3 |
| CVE-2026-11496 |
Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure |
11.09.2026 |
6.5 |
| CVE-2026-12215 |
OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force |
11.09.2026 |
5.3 |
| CVE-2026-15462 |
Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection |
11.09.2026 |
7.5 |
| CVE-2026-18561 |
Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection |
11.09.2026 |
7.5 |
| CVE-2026-18562 |
HUSKY <= 1.4.3 - Reflected Cross-Site Scripting |
11.09.2026 |
6.1 |
| CVE-2026-18579 |
WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting |
11.09.2026 |
7.2 |
| CVE-2026-18964 |
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button <= 3.5.9 - Reflected Cross-Site Scripting |
11.09.2026 |
6.1 |
| CVE-2026-19985 |
Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting |
11.09.2026 |
6.1 |
| CVE-2026-19991 |
UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion |
11.09.2026 |
8.1 |
| CVE-2026-77150 |
Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting |
11.09.2026 |
6.1 |
| CVE-2026-78172 |
Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting |
11.09.2026 |
6.1 |
| CVE-2026-7438 |
Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
11.09.2026 |
6.4 |
| CVE-2026-81754 |
Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting |
11.09.2026 |
7.2 |
| CVE-2026-81825 |
Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting |
11.09.2026 |
7.2 |
| CVE-2026-84960 |
WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting |
11.09.2026 |
6.1 |
| CVE-2026-8778 |
MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload |
11.09.2026 |
9.8 |
| CVE-2026-78135 |
|
11.09.2026 |
5.6 |
| CVE-2026-88260 |
|
11.09.2026 |
|
| CVE-2026-89151 |
|
11.09.2026 |
3.5 |
| CVE-2026-78134 |
|
11.09.2026 |
7.1 |
| CVE-2026-78131 |
|
11.09.2026 |
3.7 |
| CVE-2026-78132 |
|
11.09.2026 |
7.5 |
| CVE-2026-78133 |
|
11.09.2026 |
7.5 |
| CVE-2026-88914 |
Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser |
11.09.2026 |
|
| CVE-2026-78124 |
|
11.09.2026 |
3.7 |
| CVE-2026-78126 |
|
11.09.2026 |
5.9 |
| CVE-2026-78127 |
|
11.09.2026 |
3.7 |
| CVE-2026-78129 |
|
11.09.2026 |
5.9 |
| CVE-2026-78130 |
|
11.09.2026 |
7.5 |
| CVE-2026-78123 |
|
11.09.2026 |
5.9 |
| CVE-2026-89092 |
Stack overflow in nscd due to unbounded alloca use |
11.09.2026 |
4.2 |
| CVE-2026-89145 |
Flextype CMS 0.9.9 through 1.0.0-alpha.3 Stored XSS via Plugin Directory |
11.09.2026 |
|
| CVE-2026-84941 |
Omada Controller XML External Entity (XXE) Injection in SAML IdP Metadata Parsing Leading to Arbitrary Local File Read |
10.09.2026 |
|
| CVE-2026-77807 |
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter |
10.09.2026 |
7.5 |
| CVE-2026-81905 |
Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another. |
10.09.2026 |
|
| CVE-2026-81906 |
[UNREVIEWED] OAuth Callback Login Bypasses Deactivated-Account Checks |
10.09.2026 |
|
| CVE-2026-17176 |
OS command injection Vulnerability in Deco BE11000 |
10.09.2026 |
|
| CVE-2026-18121 |
Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) in the Calendar block's frontend event dialog (/ccm/calendar/view_event/{bID}/{occurrence_id}). |
10.09.2026 |
|
| CVE-2026-16174 |
Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow |
10.09.2026 |
|
| CVE-2026-16172 |
Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash |
10.09.2026 |
|
| CVE-2026-19646 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
10.09.2026 |
9.1 |
| CVE-2026-2310 |
IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data |
10.09.2026 |
7.8 |
| CVE-2025-57231 |
|
10.09.2026 |
|
| CVE-2026-36392 |
|
10.09.2026 |
|
| CVE-2026-49837 |
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries |
10.09.2026 |
5.9 |
| CVE-2026-49838 |
GoBGP confederation validation panics on empty AS_PATH attribute |
10.09.2026 |
5.9 |
| CVE-2026-54054 |
Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects |
10.09.2026 |
6.5 |
| CVE-2026-49836 |
psd-tools: arbitrary file write via smart-object filename |
10.09.2026 |
|
| CVE-2026-71647 |
|
10.09.2026 |
|
| CVE-2026-79590 |
|
10.09.2026 |
|
| CVE-2026-45770 |
Suricata lua: excessive flow variable registration can bypass sandbox |
10.09.2026 |
7.5 |
| CVE-2026-71640 |
|
10.09.2026 |
|
| CVE-2026-71643 |
|
10.09.2026 |
|
| CVE-2026-75624 |
IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service |
10.09.2026 |
8.8 |
| CVE-2026-75777 |
Multiple vulnerabilities in IBM Aspera Enterprise Webapps |
10.09.2026 |
8.8 |
| CVE-2026-76059 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-78569 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-78571 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-78573 |
IBM ContextForge MCP Gateway is affected by use of default credentials |
10.09.2026 |
9.8 |
| CVE-2026-78575 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-79723 |
Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches |
10.09.2026 |
5 |
| CVE-2026-79724 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
9.8 |
| CVE-2026-45767 |
Suricata datasets: save to absolute filename can be bypassed when combined with load command |
10.09.2026 |
4.4 |
| CVE-2026-45768 |
Suricata ldap: unbounded responses per transaction can lead to resource exhaustion |
10.09.2026 |
7.5 |
| CVE-2026-45769 |
ikev2: unbounded client transform storage can lead to resource exhaustion |
10.09.2026 |
7.5 |
| CVE-2026-71642 |
|
10.09.2026 |
|
| CVE-2026-71645 |
|
10.09.2026 |
|
| CVE-2026-79725 |
Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation |
10.09.2026 |
6.5 |
| CVE-2026-79742 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-80378 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.5 |
| CVE-2026-80380 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
7.1 |
| CVE-2026-80424 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
9.1 |
| CVE-2026-80434 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
7.4 |
| CVE-2026-80436 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.5 |
| CVE-2026-81204 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
9.8 |
| CVE-2026-81207 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.5 |
| CVE-2026-81210 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
7.7 |
| CVE-2026-81211 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-81213 |
Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches |
10.09.2026 |
8.6 |
| CVE-2026-81265 |
Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches |
10.09.2026 |
7.5 |
| CVE-2026-81268 |
Langflow is vulnerable to authentication bypass and insufficient session expiration |
10.09.2026 |
8.1 |
| CVE-2026-81540 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.5 |
| CVE-2026-81941 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-45765 |
Suricata dnp3: unbounded reassembly can lead to resource exhaustion |
10.09.2026 |
7.5 |
| CVE-2026-45766 |
Suricata nfs: unbounded stateful structures can lead to resource exhaustion |
10.09.2026 |
7.5 |
| CVE-2026-81550 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-81551 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-81554 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-81940 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
8.8 |
| CVE-2026-82092 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-82095 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-82097 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-82098 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-82099 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
8.8 |
| CVE-2026-82100 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
9.6 |
| CVE-2026-82107 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
9.6 |
| CVE-2026-84889 |
A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem |
10.09.2026 |
8.8 |
| CVE-2026-86087 |
IBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the system |
10.09.2026 |
4.3 |
| CVE-2026-86093 |
IBM® Db2® federated server could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands under certain conditions |
10.09.2026 |
7.5 |
| CVE-2026-87958 |
IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions |
10.09.2026 |
8.1 |
| CVE-2026-45762 |
Suricata defrag: missing address-family check can lead to remote crash |
10.09.2026 |
7.5 |
| CVE-2026-45764 |
Suricata http2: protocol-change type confusion can lead to denial of service |
10.09.2026 |
9.1 |
| CVE-2026-57844 |
|
10.09.2026 |
|
| CVE-2026-9768 |
|
10.09.2026 |
|
| CVE-2026-11813 |
|
10.09.2026 |
|
| CVE-2026-18994 |
|
10.09.2026 |
|
| CVE-2026-19136 |
|
10.09.2026 |
|
| CVE-2026-45759 |
Suricata http1: quadratic Content-Disposition processing can lead to denial of service |
10.09.2026 |
7.5 |
| CVE-2026-45761 |
Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load |
10.09.2026 |
3.3 |
| CVE-2026-63427 |
|
10.09.2026 |
|
| CVE-2026-75940 |
|
10.09.2026 |
|
| CVE-2026-85025 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
9.8 |
| CVE-2026-9667 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
10.09.2026 |
5.3 |
| CVE-2026-9176 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
10.09.2026 |
6.7 |
| CVE-2026-9225 |
Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation |
10.09.2026 |
6.5 |
| CVE-2026-3096 |
Reverse Tabnabbing via New Tab Navigation in Multiple WSO2 Products Allows Phishing and Credential Theft |
10.09.2026 |
4.7 |
| CVE-2026-79591 |
|
10.09.2026 |
|
| CVE-2026-89094 |
|
10.09.2026 |
9.9 |
| CVE-2026-9327 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
10.09.2026 |
6.3 |
| CVE-2022-26962 |
|
10.09.2026 |
|
| CVE-2026-45752 |
Suricata detect/transform: use-after-free in decompress transforms |
10.09.2026 |
5.9 |
| CVE-2026-79592 |
|
10.09.2026 |
|
| CVE-2026-89089 |
OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER) |
10.09.2026 |
6.5 |
| CVE-2026-45751 |
Suricata detect/transform: use-after-free in dotprefix transform |
10.09.2026 |
5.9 |
| CVE-2026-19596 |
OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host |
10.09.2026 |
5.9 |
| CVE-2026-76652 |
Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600 |
10.09.2026 |
|
| CVE-2026-76653 |
Missing Authentication in VPN Configuration Management in TP-Link TL-MR6400 and Archer MR600 |
10.09.2026 |
|
| CVE-2026-89011 |
isomorphic-git < 1.42.0 Prototype Pollution via getRemoteInfo |
10.09.2026 |
|
| CVE-2026-89086 |
|
10.09.2026 |
9.1 |
| CVE-2026-89087 |
|
10.09.2026 |
7.3 |
| CVE-2026-89054 |
OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes |
10.09.2026 |
8.2 |
| CVE-2026-84432 |
Concrete CMS 9 through 9.5.2 is vulnerable to CSRFin the Boards custom slot dialog controller |
10.09.2026 |
|
| CVE-2026-88061 |
career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution |
10.09.2026 |
|
| CVE-2026-88062 |
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) |
10.09.2026 |
|
| CVE-2026-87107 |
Consul vulnerable to an authorization bypass in the catalog deregistration path |
10.09.2026 |
5.4 |
| CVE-2026-87993 |
Consul-template vulnerable to an information disclosure issue in error handling |
10.09.2026 |
7.7 |
| CVE-2026-88021 |
Consul vulnerable to an authorization bypass in the Connect service mesh |
10.09.2026 |
7.5 |
| CVE-2026-88059 |
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` |
10.09.2026 |
4 |
| CVE-2026-88060 |
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements |
10.09.2026 |
|
| CVE-2026-87090 |
Consul vulnerable to an authorization bypass in the catalog node-write path |
10.09.2026 |
8.3 |
| CVE-2026-87106 |
Consul vulnerable to a denial of service in the native RPC listener |
10.09.2026 |
6.5 |
| CVE-2026-88058 |
Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements |
10.09.2026 |
|
| CVE-2026-88057 |
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler |
10.09.2026 |
|
| CVE-2026-9336 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
10.09.2026 |
6.5 |
| CVE-2026-88056 |
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR |
10.09.2026 |
|
| CVE-2026-89049 |
Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent |
10.09.2026 |
9.9 |
| CVE-2026-9338 |
IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities |
10.09.2026 |
5.3 |
| CVE-2026-68527 |
Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog |
10.09.2026 |
|
| CVE-2026-88032 |
Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver |
10.09.2026 |
|
| CVE-2026-88033 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java Driver |
10.09.2026 |
|
| CVE-2026-88034 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ Driver |
10.09.2026 |
|
| CVE-2026-88035 |
Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver |
10.09.2026 |
|
| CVE-2026-88036 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C Driver |
10.09.2026 |
|
| CVE-2026-88029 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python Driver |
10.09.2026 |
|
| CVE-2026-88030 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby Driver |
10.09.2026 |
|
| CVE-2026-88031 |
GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver |
10.09.2026 |
|
| CVE-2026-88027 |
Mass deletion and overwrite of embedded documents via query-operator injection in embedded record keys in MongoDB integration for Laravel |
10.09.2026 |
|
| CVE-2026-88028 |
Unauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB integration for Laravel |
10.09.2026 |
|
| CVE-2026-88055 |
AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator |
10.09.2026 |
5.5 |
| CVE-2026-88024 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust Driver |
10.09.2026 |
|
| CVE-2026-88025 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# Driver |
10.09.2026 |
|
| CVE-2026-88026 |
Regular expression injection via unescaped characters in LINQ query translation in MongoDB C# Driver |
10.09.2026 |
|
| CVE-2026-88023 |
GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP Library |
10.09.2026 |
|
| CVE-2026-88052 |
Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronization |
10.09.2026 |
7.8 |
| CVE-2026-88053 |
Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted .traineddata |
10.09.2026 |
|
| CVE-2026-88054 |
Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load |
10.09.2026 |
|
| CVE-2026-89042 |
passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification |
10.09.2026 |
|
| CVE-2026-89043 |
passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending |
10.09.2026 |
|
| CVE-2026-89044 |
Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding |
10.09.2026 |
|
| CVE-2026-89045 |
zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length |
10.09.2026 |
|
| CVE-2026-89046 |
zstd-jni 1.5.5-6 through 1.5.7-13 Out-of-Bounds Read via Negative Offset |
10.09.2026 |
|
| CVE-2026-88022 |
Unauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for Laravel |
10.09.2026 |
|
| CVE-2026-88051 |
Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fields |
10.09.2026 |
|
| CVE-2026-68006 |
|
10.09.2026 |
|
| CVE-2026-15417 |
CP210x Denial of Service |
10.09.2026 |
|
| CVE-2026-15418 |
CP210x Memory Leakage |
10.09.2026 |
|
| CVE-2026-15419 |
CP210x Driver Memory Corruption results in Arbitrary Code Execution |
10.09.2026 |
|
| CVE-2026-85228 |
Integer overflow in tensor buffer validation in Deep Java Library |
10.09.2026 |
9.1 |
| CVE-2026-73694 |
FileRun < 2026.3.0 OS Command Injection via escapeshellcmd() No-Op Redefinition |
10.09.2026 |
|
| CVE-2026-73698 |
FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action |
10.09.2026 |
|
| CVE-2026-73699 |
FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms() |
10.09.2026 |
|
| CVE-2026-65638 |
|
10.09.2026 |
|
| CVE-2026-65639 |
|
10.09.2026 |
|
| CVE-2026-68487 |
|
10.09.2026 |
|
| CVE-2026-68488 |
|
10.09.2026 |
|
| CVE-2026-73693 |
FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler |
10.09.2026 |
|
| CVE-2026-88049 |
Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch |
10.09.2026 |
|
| CVE-2026-88050 |
Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values |
10.09.2026 |
|
| CVE-2026-52097 |
|
10.09.2026 |
|
| CVE-2026-52098 |
|
10.09.2026 |
|
| CVE-2026-88044 |
rclone: RC per-server auth-proxy bypass |
10.09.2026 |
9.1 |
| CVE-2026-88045 |
rclone: S3 multipart declared-length memory exhaustion |
10.09.2026 |
7.5 |
| CVE-2026-88046 |
rclone: source object names can escape the configured root on upload |
10.09.2026 |
5.3 |
| CVE-2026-88047 |
Tesseract: ReadNormProtos stack buffer overflow |
10.09.2026 |
|
| CVE-2026-88048 |
Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch |
10.09.2026 |
|
| CVE-2026-79987 |
Low-privilege RCE through element-search eager loading |
11.09.2026 |
|
| CVE-2026-88018 |
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass |
10.09.2026 |
9.8 |
| CVE-2026-88016 |
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination |
10.09.2026 |
7.1 |
| CVE-2026-88017 |
rclone: FTP cross-session auth-proxy backend confusion |
10.09.2026 |
7.3 |
| CVE-2026-88014 |
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace |
10.09.2026 |
6.3 |
| CVE-2026-88015 |
rclone local: crafted Range request against a translated symlink panics (DoS) |
10.09.2026 |
5.3 |
| CVE-2026-4130 |
Storage of Sensitive Information in Cleartext in NI SystemLink |
10.09.2026 |
7.1 |
| CVE-2026-81046 |
|
11.09.2026 |
9.4 |
| CVE-2026-81049 |
|
11.09.2026 |
4.4 |
| CVE-2026-81467 |
|
11.09.2026 |
9.8 |
| CVE-2026-81468 |
|
11.09.2026 |
9.1 |
| CVE-2026-87912 |
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops |
10.09.2026 |
5.9 |
| CVE-2026-87913 |
Missing S3 bucket ownership verification in the AWS Security Agent MCP server |
10.09.2026 |
5.9 |
| CVE-2026-88013 |
rclone: http backend forwards custom/auth headers to a different host on redirect |
10.09.2026 |
3.7 |
| CVE-2026-88959 |
Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints |
10.09.2026 |
8.8 |
| CVE-2026-4129 |
Improper Access Controls in NI SystemLink |
10.09.2026 |
8.1 |
| CVE-2026-81048 |
|
11.09.2026 |
9.6 |
| CVE-2026-81051 |
|
10.09.2026 |
6.6 |
| CVE-2026-81052 |
|
10.09.2026 |
6.8 |
| CVE-2026-88011 |
Traefik: ForwardAuth identity spoofing via dot-form header alias |
10.09.2026 |
|
| CVE-2026-88012 |
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded |
10.09.2026 |
5.3 |
| CVE-2026-88899 |
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header |
10.09.2026 |
|
| CVE-2026-88937 |
knowns through 0.33.0 Path Traversal via Template Engine |
10.09.2026 |
|
| CVE-2026-88938 |
knowns through 0.33.0 Path Traversal via code.find MCP tool |
10.09.2026 |
|
| CVE-2026-88939 |
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption |
10.09.2026 |
|
| CVE-2026-88940 |
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint |
10.09.2026 |
|
| CVE-2026-88009 |
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging |
10.09.2026 |
|
| CVE-2026-88008 |
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization |
10.09.2026 |
|
| CVE-2026-88006 |
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange |
10.09.2026 |
6.5 |
| CVE-2026-88007 |
Traefik HTTP/3 Backend NTLM Connection Reuse |
10.09.2026 |
|
| CVE-2026-88897 |
Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String |
10.09.2026 |
|
| CVE-2026-88898 |
AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint |
10.09.2026 |
|
| CVE-2026-15461 |
Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input |
10.09.2026 |
5.3 |
| CVE-2026-88004 |
Traefik entrypoint header-name sanitization bypassed via request trailers |
10.09.2026 |
|
| CVE-2026-88005 |
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange |
10.09.2026 |
6.5 |
| CVE-2026-88924 |
Gvfs: gvfs-admin socket ownership race permits local root |
10.09.2026 |
|
| CVE-2026-66632 |
WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Content Injection vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-66674 |
WordPress Simple Cloudflare Turnstile plugin <= 1.42.1 - Captcha Bypass vulnerability |
10.09.2026 |
5.6 |
| CVE-2026-78536 |
WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Control vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81275 |
WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81782 |
WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81783 |
WordPress MailMunch – Grow your Email List plugin <= 3.2.5 - Broken Authentication vulnerability |
10.09.2026 |
7.1 |
| CVE-2026-81784 |
WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability |
10.09.2026 |
8.1 |
| CVE-2026-81785 |
WordPress BuddyForms plugin <= 2.9.0 - Broken Access Control vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81786 |
WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability |
10.09.2026 |
7.5 |
| CVE-2026-81787 |
WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81788 |
WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Access Control vulnerability |
10.09.2026 |
6.3 |
| CVE-2026-81789 |
WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability |
10.09.2026 |
8.6 |
| CVE-2026-81791 |
WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81793 |
WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-81794 |
WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability |
10.09.2026 |
7.5 |
| CVE-2026-81795 |
WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability |
10.09.2026 |
7.1 |
| CVE-2026-81796 |
WordPress WP Travel plugin <= 12.0.3 - Broken Authentication vulnerability |
10.09.2026 |
7.3 |
| CVE-2026-81799 |
WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability |
10.09.2026 |
7.5 |
| CVE-2026-81800 |
WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability |
10.09.2026 |
9.3 |
| CVE-2026-81801 |
WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability |
10.09.2026 |
8.1 |
| CVE-2026-81803 |
WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability |
10.09.2026 |
7.5 |
| CVE-2026-81804 |
WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability |
10.09.2026 |
7.5 |
| CVE-2026-81805 |
WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability |
10.09.2026 |
8.1 |
| CVE-2026-84816 |
WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability |
10.09.2026 |
7.1 |
| CVE-2026-84819 |
WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability |
10.09.2026 |
7.1 |
| CVE-2026-84821 |
WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability |
10.09.2026 |
7.5 |
| CVE-2026-85310 |
WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability |
10.09.2026 |
6.5 |
| CVE-2026-45747 |
Suricata lua/tls: null dereference in TlsGetCertInfo |
10.09.2026 |
7.5 |
| CVE-2026-46387 |
Suricata http2: decompression bomb can cause denial of service in Suricata |
10.09.2026 |
7.5 |
| CVE-2026-88790 |
proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal |
10.09.2026 |
|
| CVE-2026-64836 |
ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement |
10.09.2026 |
|
| CVE-2026-64837 |
ICEcoder through 8.1 OS Command Injection via lib/properties.php |
10.09.2026 |
|
| CVE-2026-64838 |
ICEcoder through 8.1 Path Traversal via oldFileName Parameter |
10.09.2026 |
|
| CVE-2026-75584 |
ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion |
10.09.2026 |
|
| CVE-2026-12682 |
Stored XSS in Ankaref's LIBRID/LIBREF |
10.09.2026 |
5.4 |
| CVE-2026-88921 |
MISP: Unescaped HTML Injection in PDF Report Element Rendering |
10.09.2026 |
|
| CVE-2026-38626 |
|
10.09.2026 |
|
| CVE-2026-6285 |
Improper Authentication in Ankaref's LIBRID/LIBREF |
10.09.2026 |
7.5 |
| CVE-2026-85217 |
Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop |
11.09.2026 |
8.6 |
| CVE-2026-12683 |
Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF |
10.09.2026 |
5.4 |
| CVE-2026-45763 |
Suricata lua: sandbox allocation limit not enforced for new allocations |
10.09.2026 |
5.9 |
| CVE-2026-88860 |
Capgo Authorization Bypass via Stale Channel Permission Overrides |
10.09.2026 |
|
| CVE-2026-88861 |
Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization |
10.09.2026 |
|
| CVE-2026-88862 |
Capgo API Key Manager Authentication Bypass via x-limited-key-id |
10.09.2026 |
|
| CVE-2026-88863 |
capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org |
10.09.2026 |
|
| CVE-2026-88864 |
Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
10.09.2026 |
|
| CVE-2026-88865 |
AVideo Missing Authorization via getRestream.json.php |
10.09.2026 |
|
| CVE-2026-88866 |
WWBN AVideo LoginControl Stored XSS via User-Agent Header |
10.09.2026 |
|
| CVE-2026-88867 |
WWBN AVideo Stored XSS via Category Name and Icon Class |
10.09.2026 |
|
| CVE-2026-88868 |
AVideo LiveLinks Stored XSS via title and description fields |
10.09.2026 |
|
| CVE-2026-88869 |
AVideo AD_Server Stored XSS via log.php label parameter |
10.09.2026 |
|
| CVE-2026-88870 |
WWBN AVideo LoginControl PGP Key CSRF via GET Request |
10.09.2026 |
|
| CVE-2026-88871 |
WWBN AVideo CustomizeUser setSubscribers CSRF via GET |
10.09.2026 |
|
| CVE-2026-88872 |
AVideo CustomizeUser setPassword.json.php CSRF |
10.09.2026 |
|
| CVE-2026-88873 |
WWBN AVideo Cross-Site Request Forgery via logArchive.json.php |
10.09.2026 |
|
| CVE-2026-88874 |
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass |
10.09.2026 |
|
| CVE-2026-88875 |
AVideo Incomplete API Sanitization Information Disclosure |
10.09.2026 |
|
| CVE-2026-88876 |
AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD |
10.09.2026 |
|
| CVE-2026-88877 |
Traefik v3.7.0 Authentication Bypass via from-to-www-redirect |
10.09.2026 |
|
| CVE-2026-88878 |
Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass |
10.09.2026 |
|
| CVE-2026-88879 |
Traefik before v2.11.56 Identity Spoofing via Header Alias |
10.09.2026 |
|
| CVE-2026-88880 |
Renovate before 44.11.3 Credential Exfiltration via Link Header |
10.09.2026 |
|
| CVE-2026-88881 |
Renovate before 44.11.3 Credential Exfiltration via Link Header |
10.09.2026 |
|
| CVE-2026-88882 |
Renovate before 44.11.2 Credential Exfiltration via Link Header |
10.09.2026 |
|
| CVE-2026-88883 |
Renovate before 44.14.4 TLS Private Key Log Sanitisation |
10.09.2026 |
|
| CVE-2026-88884 |
Renovate before 44.3.1 Authentication Bypass via Digest Updates |
10.09.2026 |
|
| CVE-2026-88885 |
Renovate before 44.14.7 Command Injection via depName |
10.09.2026 |
|
| CVE-2026-88886 |
Renovate before 44.14.7 Command Injection via gradle-wrapper |
10.09.2026 |
|
| CVE-2026-88887 |
Renovate before 44.11.2 Credential Exfiltration via Link Header |
10.09.2026 |
|
| CVE-2026-88888 |
Renovate before 44.14.7 Command Injection via Mix organization |
10.09.2026 |
|
| CVE-2026-88889 |
Renovate before 44.14.7 Command Injection via distributionType |
10.09.2026 |
|
| CVE-2026-88890 |
OpenPanel SQL Injection via unvalidated profile filter column identifier |
10.09.2026 |
|
| CVE-2026-88891 |
OpenPanel Read-Only Access Level Enforcement Bypass via Mutations |
10.09.2026 |
|
| CVE-2026-88892 |
OpenPanel SSRF via Unguarded Importer File URL Fetch |
10.09.2026 |
|
| CVE-2026-88893 |
OpenPanel Unauthenticated Share Lookup Information Disclosure |
10.09.2026 |
|
| CVE-2026-88894 |
Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout |
10.09.2026 |
|
| CVE-2026-88895 |
CyberPanel before 3.0.5 Authentication Bypass via API |
10.09.2026 |
|
| CVE-2026-88896 |
EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass |
10.09.2026 |
|
| CVE-2026-88915 |
MISP Event Template Instantiation Bypasses Sharing Group and Tagging Authorization |
10.09.2026 |
|
| CVE-2026-85543 |
|
10.09.2026 |
4.3 |
| CVE-2026-85544 |
|
10.09.2026 |
5.2 |
| CVE-2026-85545 |
|
10.09.2026 |
7.1 |
| CVE-2026-17038 |
Use of Hard-coded Credentials in drEryk Gabinet |
10.09.2026 |
|
| CVE-2026-88038 |
cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options |
10.09.2026 |
4.8 |
| CVE-2026-9161 |
User Enumeration in DernekPlus' Website Template |
10.09.2026 |
5.3 |
| CVE-2026-9163 |
SQLi in GIS Informatics' GisLab Laboratory Management System |
10.09.2026 |
9.8 |
| CVE-2026-9166 |
LFI in GIS Informatics' GisLab Laboratory Management System |
10.09.2026 |
7.5 |
| CVE-2026-84828 |
Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token |
10.09.2026 |
|
| CVE-2026-88859 |
Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction |
10.09.2026 |
|
| CVE-2026-87961 |
ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header |
10.09.2026 |
|
| CVE-2026-87962 |
t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in MergingDigest.fromBytes |
10.09.2026 |
|
| CVE-2026-78085 |
Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 |
11.09.2026 |
|
| CVE-2026-78082 |
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 |
11.09.2026 |
|
| CVE-2026-78083 |
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 |
11.09.2026 |
|
| CVE-2026-78084 |
Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 |
11.09.2026 |
|
| CVE-2026-78302 |
Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 |
11.09.2026 |
|
| CVE-2026-78374 |
Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 |
11.09.2026 |
|
| CVE-2026-78303 |
Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 |
11.09.2026 |
|
| CVE-2026-87803 |
|
10.09.2026 |
7.1 |