CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-85181 CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum 03.09.2026 9.3
CVE-2026-85183 Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS 03.09.2026 9.3
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials 03.09.2026 9.5
CVE-2026-85109 Tenda HG10 Boa Web Server formLogin buffer overflow 03.09.2026 9.3
CVE-2026-82180 03.09.2026 9.5
CVE-2026-78080 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 03.09.2026 9.3
CVE-2026-78069 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026 9.5
CVE-2026-85154 WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash 03.09.2026 9.3
CVE-2026-76178 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.2
CVE-2026-76174 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.4
CVE-2026-85031 TOTOLINK CP450 cstecgi.cgi buffer overflow 03.09.2026 9.4
CVE-2026-19117 Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability 02.09.2026 9.8
CVE-2026-53670 PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification 02.09.2026 9.3
CVE-2026-53671 PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification 02.09.2026 9.3
CVE-2026-66786 Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets 03.09.2026 9.1
CVE-2026-53649 Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE 02.09.2026 9.6
CVE-2026-20212 Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability 03.09.2026 9.8
CVE-2026-20274 Cisco IOS XR Software Security Hardening Release: September 2026 03.09.2026 9.8
CVE-2026-20279 Cisco IOS XR Software Security Hardening Release: September 2026 03.09.2026 9.8
CVE-2026-53611 Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation 02.09.2026 9.8
CVE-2026-78689 NGINX ngx_http_js_module vulnerablility 03.09.2026 9.2
CVE-2026-82955 02.09.2026 9
CVE-2025-9314 Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload 02.09.2026 9.8
CVE-2026-4357 Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload 02.09.2026 10
CVE-2026-77009 WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console 02.09.2026 9.9
CVE-2026-81294 WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability 02.09.2026 9.8
CVE-2026-81286 WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-84795 Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance 02.09.2026 9.2
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field 02.09.2026 9.8
CVE-2026-9055 Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' 02.09.2026 9.8
CVE-2026-84695 BookStack before 26.05.4 Stored XSS via Drawing Upload 02.09.2026 9.3
CVE-2026-84696 Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands 02.09.2026 9.3
CVE-2026-84699 Team Password Manager before 14.184.308 Authentication Bypass in Password Reset 02.09.2026 9.3
CVE-2026-84479 WWBN AVideo Authentication Bypass via User-Agent Header 02.09.2026 9.3
CVE-2026-84480 WWBN AVideo Password Recovery Token Expiration Bypass 02.09.2026 9.3
CVE-2023-54391 Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter 03.09.2026 9.3
CVE-2026-75604 Next.js: Unauthenticated Remote Code Execution on windows-hosted servers 03.09.2026 9
CVE-2026-84372 Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections 02.09.2026 9.8
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 03.09.2026 9.8
CVE-2026-76657 Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access 01.09.2026 10
CVE-2026-76658 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon 01.09.2026 10
CVE-2026-19766 Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer 02.09.2026 9.6
CVE-2026-73700 Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface 02.09.2026 9
CVE-2026-73701 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer 02.09.2026 9
CVE-2026-79687 02.09.2026 9
CVE-2026-18931 Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software 01.09.2026 9.1
CVE-2026-78012 Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack 01.09.2026 9.3
CVE-2026-18210 SQL Injection in TRtek Technological Products's Store 01.09.2026 9.8
CVE-2026-9621 RSLinx Classic® - Multiple Vulnerabilities 01.09.2026 9.2
CVE-2026-18808 Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO 01.09.2026 9.8
CVE-2026-18765 SQL Injection in Teracity Sotware's Teracity E-OSB Platform 01.09.2026 9.8
CVE-2026-84149 Information Disclosure Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2026-84147 Remote Code Execution Vulnerability in Manacle Technologies ERP System 01.09.2026 10
CVE-2026-84148 Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites 01.09.2026 9.3
CVE-2026-84189 LibreNMS before 26.7.0 Stored XSS via Oxidized API 01.09.2026 9.2
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions 02.09.2026 9.4
CVE-2026-18550 Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter 02.09.2026 9.8
CVE-2026-4813 Code injection in the Lutece Core 01.09.2026 9.4
CVE-2026-78319 TOCTOU Vulnerability in file exchange 01.09.2026 9.3
CVE-2026-83772 Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection 01.09.2026 9.4
CVE-2026-67394 01.09.2026 9
CVE-2026-75865 WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint 01.09.2026 9.8
CVE-2026-83524 RedPort Optimizer wXa-223 System Clock datetime.php exec command injection 01.09.2026 9.4
CVE-2026-82971 QVidium Opera11 CGI Script net_tr.cgi command injection 01.09.2026 10
CVE-2026-82954 Dokploy Settings application.ts writeTraefikConfigInPath path traversal 02.09.2026 9.4
CVE-2026-81779 WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability 01.09.2026 10
CVE-2026-81293 WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81756 WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-81763 WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81780 WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability 01.09.2026 10
CVE-2026-82226 WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability 01.09.2026 9.8
CVE-2026-82908 MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow 01.09.2026 9.3
CVE-2026-53552 Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers 01.09.2026 9.6
CVE-2026-79748 MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args) 31.08.2026 9.9
CVE-2026-82807 ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management 01.09.2026 9.3
CVE-2026-73819 Ebyte NA111-M Weak Authentication 01.09.2026 9.3
CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm 01.09.2026 9.3
CVE-2026-66047 ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE 02.09.2026 9.2
CVE-2026-82970 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability 31.08.2026 10
CVE-2026-59111 Command Injection vulnerability in eObčanka-Identifikace 31.08.2026 9.3
CVE-2026-82694 Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication 31.08.2026 10
CVE-2026-82695 Tenda AC18 Telnet telnet missing authentication 31.08.2026 10
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82693 Tenda AC1206 Web UI telnet TendaTelnet missing authentication 31.08.2026 10
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection 02.09.2026 9.4
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection 01.09.2026 9.4
CVE-2026-82876 Phison PS3111-S11 Controller Firmware Signature Verification Bypass 02.09.2026 9.3
CVE-2026-49003 Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product 31.08.2026 9.6
CVE-2026-82854 Nodemailer before 8.0.3 SMTP Command Injection via envelope.size 31.08.2026 9.3
CVE-2026-82855 @hulumi/policies before 1.3.2 Evidence Validation Bypass 31.08.2026 9.3
CVE-2026-82856 @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass 02.09.2026 9.3
CVE-2026-82857 hulumi before v1.3.2 Privilege Escalation via IAM Policy 01.09.2026 9.3
CVE-2026-82858 @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance 31.08.2026 9.3
CVE-2026-82859 hulumi before v1.3.2 SCP Template Tag-on-Create Bypass 31.08.2026 9.3
CVE-2026-82860 @hulumi/policies before 1.3.2 Admin Policy Bypass 31.08.2026 9.3
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression 31.08.2026 9.4
CVE-2026-82628 Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management 31.08.2026 9.3
CVE-2026-58574 31.08.2026 9.8
CVE-2026-82616 TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow 01.09.2026 9.4
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow 01.09.2026 9.4
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow 31.08.2026 9.4
CVE-2026-82645 AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token 31.08.2026 9.2
CVE-2026-82653 SiYuan before v3.8.1 Stored XSS via confirmDialog 02.09.2026 9.3
CVE-2026-82654 SiYuan before v3.8.1 Stored XSS via block name 01.09.2026 9.3
CVE-2026-82542 Tenda HG10 Boa Web Server formIPv6Routing buffer overflow 01.09.2026 10
CVE-2026-82539 TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption 01.09.2026 9.4
CVE-2026-15980 MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token 31.08.2026 9.8
CVE-2026-15369 Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout 01.09.2026 9.8
CVE-2026-82460 Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown 31.08.2026 9.3
CVE-2026-82466 Rodauth before 2.46.0 Authentication Bypass via webauthn_login 31.08.2026 9.4
CVE-2026-82452 rust-iot-platform Authentication Bypass via Missing Request Guards 01.09.2026 9.3
CVE-2026-82454 Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in 31.08.2026 9.3
CVE-2026-82456 argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP 02.09.2026 10
CVE-2026-82448 Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key 31.08.2026 9.3
CVE-2026-14494 Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field 31.08.2026 9.8
CVE-2026-18527 IBM Application Runtime Expert (ARE) for IBM i is vulnerable to a user gaining elevated privileges and sensitive information [, ]. 31.08.2026 9.9
CVE-2026-19286 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement 01.09.2026 9.8
CVE-2026-19295 Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement 01.09.2026 9.9
CVE-2026-3627 Multiple Vulnerabilities in IBM Concert Software 01.09.2026 9.1
CVE-2026-54745 Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true 31.08.2026 10
CVE-2026-54754 Klever-Go: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) 31.08.2026 9.6
CVE-2026-54755 Klever-Go: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) 31.08.2026 9.6
CVE-2026-55068 free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints 31.08.2026 9.3
CVE-2026-55220 Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column 31.08.2026 9.3
CVE-2026-55247 plone.app.event: Denial of service via iCalendar import 31.08.2026 9.1
CVE-2026-55248 plone.app.portlets: Denial of service via RSS feed portlet 28.08.2026 9.1
CVE-2026-55378 JS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context values 01.09.2026 9.3
CVE-2026-55511 Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` 01.09.2026 9.1
CVE-2026-55559 Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance) 28.08.2026 9.8
CVE-2026-55565 Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`) 31.08.2026 9.9
CVE-2026-55634 Pimcore: Remote Code Execution via DataObject Class-Definition Field Name 28.08.2026 9.9
CVE-2026-82021 Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference 31.08.2026 9
CVE-2026-82266 Redpanda Admin API Unauthenticated Superuser Access via Default Configuration 01.09.2026 9.3
CVE-2026-82277 Argo Rollouts Dashboard Unauthenticated Mutating Operations 31.08.2026 9.3
CVE-2026-82281 Kotaemon Missing Ownership Check in Conversation Functions 03.09.2026 9.1
CVE-2026-82329 Potential authentication bypass leading to administrative access in Artifactory 03.09.2026 9.8
CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector 01.09.2026 9.4
CVE-2026-18918 OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default 31.08.2026 9.1
CVE-2026-42007 28.08.2026 9.1
CVE-2026-82222 WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability 28.08.2026 10
CVE-2026-82244 Budibase before 3.41.3 Remote Code Execution via Plugin eval() 28.08.2026 9.4
CVE-2026-40541 28.08.2026 9
CVE-2026-76581 WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion 28.08.2026 9.8
CVE-2026-78032 28.08.2026 9.3
CVE-2026-80600 batman-adv: dat: acquire ARP hw source only after skb realloc 29.08.2026 9.8
CVE-2026-80603 netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read 29.08.2026 9.1
CVE-2026-80609 qede: fix out-of-bounds check for cqe->len_list[] 29.08.2026 9.8
CVE-2026-80612 net: lwtunnel: Drop skb metadata before LWT encapsulation 29.08.2026 9.8
CVE-2026-80617 net: airoha: fix foe_check_time allocation size 29.08.2026 9.8
CVE-2026-80630 net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen 29.08.2026 9.8
CVE-2026-80634 netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag 29.08.2026 9.8
CVE-2026-80668 netfilter: nf_conntrack_expect: use conntrack GC to reap expectations 29.08.2026 9.8
CVE-2026-80670 perf tools: Use perf_env__get_cpu_topology() in machine__resolve() 29.08.2026 9.1
CVE-2026-80671 perf sched: Fix register_pid() overflow, strcpy, and BUG_ON 29.08.2026 9.3
CVE-2026-80673 ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find() 29.08.2026 9.8
CVE-2026-80674 ntfs: validate resident attribute lists and harden the validator 29.08.2026 9.8
CVE-2026-80681 vxlan: re-fetch eth header after route_shortcircuit() 29.08.2026 9.8
CVE-2026-80684 KVM: s390: pci: Fix NULL dereference on AIBV allocation failure 29.08.2026 9.3
CVE-2026-80693 idpf: bound interrupt-vector register fill to the allocated array 29.08.2026 9.3
CVE-2026-80694 net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller 29.08.2026 9.8
CVE-2026-80714 ipvs: do not propagate one-packet flag to synced conns 29.08.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-85138 SeaCMS WeChat index.php addslashes sql injection 03.09.2026
CVE-2026-85239 MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service 03.09.2026
CVE-2026-48486 Signum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary miner reward inflation 03.09.2026 7.5
CVE-2026-50554 Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books in note-mark 03.09.2026 5.3
CVE-2026-53720 pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small 03.09.2026
CVE-2026-83961 ColdFusion | Improper Authentication (CWE-287) 03.09.2026 7.1
CVE-2026-85237 Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass 03.09.2026
CVE-2026-85238 Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking 03.09.2026
CVE-2026-53924 Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes 03.09.2026
CVE-2026-55658 Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the permissionless claim() 03.09.2026 7.7
CVE-2026-57445 Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve 03.09.2026
CVE-2026-71963 Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection 03.09.2026
CVE-2026-75034 Rancher: SAML Assertion Replay 03.09.2026 7.4
CVE-2026-75035 Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass 03.09.2026 7.7
CVE-2026-75036 Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing 03.09.2026
CVE-2026-82525 Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing 03.09.2026
CVE-2026-84962 Authenticated KMS request forgery via CRLF injection in GCP key identifier strings 03.09.2026
CVE-2026-84963 Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser 03.09.2026
CVE-2026-84964 Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client 03.09.2026
CVE-2026-84965 Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds 03.09.2026
CVE-2026-84966 BSON element injection via NUL-embedded document keys in builder append 03.09.2026
CVE-2026-84967 Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal 03.09.2026
CVE-2026-85137 SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection 03.09.2026
CVE-2026-85236 MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request 03.09.2026
CVE-2026-75033 Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing 03.09.2026 7.7
CVE-2026-84969 Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output 03.09.2026
CVE-2026-84970 Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser 03.09.2026
CVE-2026-84971 Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path 03.09.2026
CVE-2026-71404 Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole 03.09.2026 8.7
CVE-2026-85230 MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection 03.09.2026
CVE-2026-71403 Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind 03.09.2026 6.1
CVE-2026-84989 ntopng's Missing Authorization in REST API Allows Non-Admin Users to Delete and Rename Arbitrary Tags 03.09.2026 7.1
CVE-2026-85227 Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAttachedAttributes Parameters 03.09.2026
CVE-2026-85226 MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Correlations 03.09.2026
CVE-2026-56126 pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php 03.09.2026
CVE-2026-56127 pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php 03.09.2026
CVE-2026-56128 pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php 03.09.2026
CVE-2026-63694 03.09.2026 5
CVE-2026-35160 03.09.2026 5
CVE-2026-85135 ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted upload 03.09.2026
CVE-2026-85176 DbGate through 7.2.6 Arbitrary File Read and Write via file:// jslid 03.09.2026
CVE-2026-85177 CRMEB through 6.0.0 Unauthorized Message Modification via edit_message 03.09.2026
CVE-2026-85178 Helicone Cross-Tenant Provider Key Disclosure via Missing Organization Filter 03.09.2026
CVE-2026-85179 Label Studio through 1.23.0 SSRF via Unvalidated Webhook URL 03.09.2026
CVE-2026-85180 Ollama 0.30.0 through 0.33.2 SSRF via Cross-Host Tensor Blob Redirect 03.09.2026
CVE-2026-85181 CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum 03.09.2026
CVE-2026-85182 vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change 03.09.2026
CVE-2026-85183 Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS 03.09.2026
CVE-2026-85199 03.09.2026
CVE-2026-85210 Oppia through 3.5.2 Missing Authorization on AdminRoleHandler GET 03.09.2026
CVE-2026-85211 Label Studio through 1.23.0 Cross-Organization Storage URI Resolution 03.09.2026
CVE-2026-85212 CRMEB through 6.0.0 Missing Authorization via Inert verifyAuth Role Check 03.09.2026
CVE-2026-85213 Kill Bill through 0.24.21 Missing Authorization on AdminResource Endpoints 03.09.2026
CVE-2026-85214 vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite 03.09.2026
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials 03.09.2026
CVE-2026-85221 MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attacks 03.09.2026
CVE-2026-85110 Tenda HG10 Boa Web Server formWlanSetup buffer overflow 03.09.2026
CVE-2026-80515 03.09.2026
CVE-2026-84815 WordPress Enfold theme <= 8.0 - Cross Site Scripting (XSS) vulnerability 03.09.2026 5.8
CVE-2026-85109 Tenda HG10 Boa Web Server formLogin buffer overflow 03.09.2026
CVE-2025-12737 Arbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code Execution 03.09.2026 8.4
CVE-2026-6071 Code Execution Vulnerability in Arena® 03.09.2026
CVE-2026-82180 03.09.2026
CVE-2026-82918 03.09.2026 5.5
CVE-2026-85107 NousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resources 03.09.2026
CVE-2026-3416 Predictable Pseudorandom Number Generation via Webhook HMAC Secret Generation in Multiple WSO2 Products Allows Forged Event Payloads 03.09.2026 5.9
CVE-2026-71219 Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal 03.09.2026
CVE-2026-71220 Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit 03.09.2026
CVE-2026-71221 Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta 03.09.2026
CVE-2026-71222 Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing 03.09.2026
CVE-2026-71224 Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk 03.09.2026
CVE-2026-78080 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 03.09.2026
CVE-2026-78000 Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 03.09.2026
CVE-2026-78065 Joomla Extension - j2commerce.com - Guest checkout address disclosure to any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026
CVE-2026-78069 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026
CVE-2026-77999 Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026
CVE-2026-78064 Joomla Extension - j2commerce.com - Anonymous cart-record tampering via inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026
CVE-2026-85106 NousResearch hermes-agent Link Title Fetch index.tsx fetchLinkTitle server-side request forgery 03.09.2026
CVE-2026-79679 Use of Weak Credentials 03.09.2026 8.7
CVE-2026-80465 03.09.2026 8.7
CVE-2026-85154 WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash 03.09.2026
CVE-2026-85155 WWBN AVideo SQL Injection via get.json.php APIName channels 03.09.2026
CVE-2026-85156 WWBN AVideo Broken Access Control via Channel Page 03.09.2026
CVE-2026-85157 WWBN AVideo Broken Access Control via feed/index.php program_id 03.09.2026
CVE-2026-85158 AVideo Reflected XSS via videoEmbeded.php link parameter 03.09.2026
CVE-2026-85159 AVideo Reflected XSS via cancelUri in userLogin.php 03.09.2026
CVE-2026-85160 AVideo through c91b5975d CSRF and Path Traversal via stopLive.php 03.09.2026
CVE-2026-85161 AVideo removePoster.php Cross-Site Request Forgery File Deletion 03.09.2026
CVE-2026-85162 AVideo through c91b5975d CSRF via saveLive.php 03.09.2026
CVE-2026-85163 AVideo Server-Side Request Forgery via epg_link parameter 03.09.2026
CVE-2026-85164 WWBN AVideo Server-Side Request Forgery via set_api_userImages 03.09.2026
CVE-2026-85165 n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement 03.09.2026
CVE-2026-85166 n8n before 2.36.2 Credential Exfiltration via Workflow Tool Node 03.09.2026
CVE-2026-85167 n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes 03.09.2026
CVE-2026-85168 n8n before 1.123.73 Remote Code Execution via Git Node 03.09.2026
CVE-2026-85169 n8n before 1.123.73 Remote Code Execution via $fromAI Prototype Leak 03.09.2026
CVE-2026-85170 n8n before 1.123.73 Local File Read and SSRF via Gmail and Brevo nodes 03.09.2026
CVE-2026-85171 n8n before 1.123.73 Credential Exposure via Error Logging 03.09.2026
CVE-2026-85172 n8n before 2.34.1 SSRF via Request Helper URI Validation Bypass 03.09.2026
CVE-2026-85173 n8n before 2.36.2 Missing Authorization via Insights API 03.09.2026
CVE-2026-85174 SiYuan before v3.8.2 API Token Exposure via Log File 03.09.2026
CVE-2026-85175 SiYuan before v3.8.2 TLS Private Key Disclosure via getFile 03.09.2026
CVE-2026-85105 NousResearch hermes-agent Session Management s71.py _sess_nowait authorization 03.09.2026
CVE-2026-76642 util-linux libmount Privilege Escalation via Failed Mount Helper 03.09.2026
CVE-2026-85124 @fastify/http-proxy vulnerable to prefix escape via backslash dot-segments 03.09.2026 7.5
CVE-2026-85150 Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header 03.09.2026
CVE-2026-15926 03.09.2026
CVE-2026-15933 Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise) 03.09.2026
CVE-2026-76178 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026
CVE-2026-76175 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026
CVE-2026-76176 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026
CVE-2026-76177 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026
CVE-2026-85100 2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumption 03.09.2026
CVE-2026-76174 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026
CVE-2026-80253 03.09.2026
CVE-2026-80254 03.09.2026
CVE-2026-84830 OS command injection in privileged configuration handling 03.09.2026
CVE-2026-84831 Mandatory MFA bypass before enrollment 03.09.2026
CVE-2026-84832 Unsafe deserialization in the REST interface 03.09.2026
CVE-2026-3852 Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter 03.09.2026 6.4
CVE-2026-68860 03.09.2026 6.8
CVE-2026-73600 03.09.2026 7.8
CVE-2026-74768 03.09.2026 4.1
CVE-2026-74769 03.09.2026 6.5
CVE-2026-80726 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page 03.09.2026
CVE-2026-80727 x86/mce: Set up the polling timer before CMCI discovery 03.09.2026
CVE-2026-80728 Revert "drm/amdgpu: fix aperture mapping leak" 03.09.2026
CVE-2026-80729 mm/huge_memory: initialise workingset state before folio split 03.09.2026
CVE-2026-80730 ring-buffer: Fix crash passing ERR_PTR to kthread_stop() 03.09.2026
CVE-2026-80731 net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header 03.09.2026
CVE-2026-80732 ata: pata_sl82c105: fix bridge revision use-after-free 03.09.2026
CVE-2026-80733 net: remove WARN_ON_ONCE() from sk_mc_loop() 03.09.2026
CVE-2026-80734 btrfs: initialize inode mapping flags for cached inodes 03.09.2026
CVE-2026-80735 ovpn: ensure socket is owned by ovpn before deref sk_user_data 03.09.2026
CVE-2026-80736 thunderbolt: Fix bandwidth group reservation indexing 03.09.2026
CVE-2026-80737 serial: amba-pl011: synchronize DMA teardown 03.09.2026
CVE-2026-80738 bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie 03.09.2026
CVE-2026-80739 net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock 03.09.2026
CVE-2026-80740 drm/log: Fix infinite loop when scale is too large for display 03.09.2026
CVE-2026-80741 drm/log: Fix out-of-bounds read on empty message length 03.09.2026
CVE-2026-80742 af_packet: Don't send zero-byte data in tpacket_snd(). 03.09.2026
CVE-2026-80743 ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers 03.09.2026
CVE-2026-80744 netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path 03.09.2026
CVE-2026-80745 regulator: fp9931: Fix VPOS/VNEG voltage selector table 03.09.2026
CVE-2026-80746 clk: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK 03.09.2026
CVE-2026-80747 drm/amdkfd: Add bounds check for CRAT subtype length 03.09.2026
CVE-2026-80748 mmc: loongson2: Fix sg iteration in data reorder functions 03.09.2026
CVE-2026-80749 drm/connector/hdmi: Fix out of bounds memory read 03.09.2026
CVE-2026-80750 pmdomain: mediatek: fix remaining %pOF after of_node_put() 03.09.2026
CVE-2026-80751 pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev() 03.09.2026
CVE-2026-80752 Input: psxpad-spi - set driver data before use 03.09.2026
CVE-2026-80753 ovpn: run deferred work on a module-owned workqueue 03.09.2026
CVE-2026-80754 Input: synaptics-rmi4 - fix F55 transmitter electrode count typo 03.09.2026
CVE-2026-80755 selinux: reject a permission value exceeding the class permission count 03.09.2026
CVE-2026-80756 selinux: do not cancel a policy conversion that never started 03.09.2026
CVE-2026-80757 selinux: reject a class permission count below its inherited common 03.09.2026
CVE-2026-17539 03.09.2026 5.9
CVE-2026-9852 03.09.2026
CVE-2026-9853 03.09.2026
CVE-2026-9854 03.09.2026