CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 08.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 08.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 08.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 07.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 07.09.2026 10
CVE-2026-86478 07.09.2026 9.8
CVE-2026-86480 07.09.2026 9.8
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026 9.8
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 07.09.2026 9.8
CVE-2026-80238 07.09.2026 9.3
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 07.09.2026 9.2
CVE-2026-61410 07.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 07.09.2026 9.4
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 07.09.2026 9.8
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 07.09.2026 9.4
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 07.09.2026 9.2
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 07.09.2026 10
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection 07.09.2026 9.4
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection 07.09.2026 9.4
CVE-2026-16876 07.09.2026 9.3
CVE-2026-86259 OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation 06.09.2026 9
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 06.09.2026 9.4
CVE-2026-86165 Tenda HG10 formURL buffer overflow 06.09.2026 9.3
CVE-2026-16310 MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter 07.09.2026 9.8
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier 07.09.2026 9.8
CVE-2026-86218 pre-authentication remote code execution 08.09.2026 10
CVE-2026-86153 Tenda CP3 Redirect.cpp SetRedirectEnable privileges management 06.09.2026 9.4
CVE-2026-86152 Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection 06.09.2026 10
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection 05.09.2026 9.4
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection 05.09.2026 9.4
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection 05.09.2026 9.4
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS 07.09.2026 9.2
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 05.09.2026 9.2
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php 05.09.2026 9.3
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter 05.09.2026 9.3
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route 05.09.2026 9.3
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields 07.09.2026 9.8
CVE-2026-86117 Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching 05.09.2026 9.2
CVE-2026-86119 Webstudio through 0.296.0 SSRF via /cgi proxy routes 05.09.2026 9.2
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control 05.09.2026 9.3
CVE-2026-86123 SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints 05.09.2026 9.4
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server 05.09.2026 9.3
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection 07.09.2026 9.8
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 07.09.2026 9.8
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 07.09.2026 9.8
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize 04.09.2026 9.4
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action 04.09.2026 9.1
CVE-2026-75925 IXON VPN Client CRLF Injection 07.09.2026 9.4
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server 05.09.2026 9.2
CVE-2026-75430 04.09.2026 9.8
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed 04.09.2026 9.8
CVE-2026-19274 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 9.6
CVE-2026-75431 04.09.2026 9.1
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi 04.09.2026 9.3
CVE-2026-85620 Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function 04.09.2026 9.2
CVE-2026-85625 sift 17.1.3 Prototype Pollution Remote Code Execution via $where 04.09.2026 9.2
CVE-2026-85660 cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution 04.09.2026 9.2
CVE-2026-85661 excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode 04.09.2026 9.3
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch 04.09.2026 9.3
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection 04.09.2026 9.3
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension 04.09.2026 9.3
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer 04.09.2026 9.3
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction 04.09.2026 9.2
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing 04.09.2026 9.3
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename 04.09.2026 9.3
CVE-2026-85595 Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth 05.09.2026 9.3
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass 05.09.2026 9.3
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker 04.09.2026 9.2
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes 04.09.2026 9.8
CVE-2026-85184 @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target 04.09.2026 9.1
CVE-2026-15354 ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter 04.09.2026 9.8
CVE-2026-62928 04.09.2026 9.3
CVE-2026-69657 04.09.2026 9.3
CVE-2026-70403 04.09.2026 9.3
CVE-2026-85085 04.09.2026 9.6
CVE-2026-11613 Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter 07.09.2026 9.8
CVE-2026-85506 04.09.2026 9.8
CVE-2026-85507 04.09.2026 9.8
CVE-2026-85508 04.09.2026 9.8
CVE-2026-85509 04.09.2026 9.8
CVE-2026-85504 04.09.2026 9.8
CVE-2026-85146 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-85148 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-75754 04.09.2026 10
CVE-2026-67402 04.09.2026 9.2
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability 05.09.2026 9.1
CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability 05.09.2026 10
CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability 05.09.2026 9.3
CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability 05.09.2026 10
CVE-2026-85424 MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR 05.09.2026 9.3
CVE-2026-85425 MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS 04.09.2026 9.3
CVE-2026-85426 MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names 04.09.2026 9.3
CVE-2026-85427 MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE 04.09.2026 9.2
CVE-2026-85428 MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write 03.09.2026 9.3
CVE-2026-85433 MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration 03.09.2026 9.3
CVE-2026-85434 MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping 05.09.2026 9.3
CVE-2026-85435 MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment 04.09.2026 9.3
CVE-2026-85437 MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders 04.09.2026 9.3
CVE-2026-85438 MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts 03.09.2026 9.3
CVE-2026-85440 MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length 04.09.2026 9.3
CVE-2026-85224 D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection 04.09.2026 9.4
CVE-2026-85223 D-Link DNS-340L CGI dropbox.cgi os command injection 04.09.2026 9.4
CVE-2026-85222 D-Link DNS-340L Add-On Center addon_center.cgi os command injection 04.09.2026 9.4
CVE-2026-85061 MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip 04.09.2026 10
CVE-2026-85391 Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml 03.09.2026 9.3
CVE-2026-85394 python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret 03.09.2026 9.3
CVE-2026-82526 R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint 04.09.2026 9.3
CVE-2026-58400 GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter 04.09.2026 9.1
CVE-2026-84238 WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability 07.09.2026 9.8
CVE-2026-84753 WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability 05.09.2026 9.8
CVE-2026-84768 WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability 03.09.2026 9.3
CVE-2026-84813 WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84814 WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability 03.09.2026 9.8
CVE-2026-84834 WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability 07.09.2026 9.8
CVE-2026-85181 CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum 03.09.2026 9.3
CVE-2026-85183 Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS 03.09.2026 9.3
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials 03.09.2026 9.5
CVE-2026-85109 Tenda HG10 Boa Web Server formLogin buffer overflow 03.09.2026 9.3
CVE-2026-82180 03.09.2026 9.5
CVE-2026-78080 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 03.09.2026 9.3
CVE-2026-78069 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026 9.5
CVE-2026-85154 WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash 05.09.2026 9.3
CVE-2026-76178 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.2
CVE-2026-76174 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.4
CVE-2026-80726 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page 04.09.2026 9.3
CVE-2026-85031 TOTOLINK CP450 cstecgi.cgi buffer overflow 03.09.2026 9.4
CVE-2026-19117 Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability 02.09.2026 9.8
CVE-2026-53670 PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification 02.09.2026 9.3
CVE-2026-53671 PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification 05.09.2026 9.3
CVE-2026-66786 Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets 05.09.2026 9.1
CVE-2026-53649 Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE 04.09.2026 9.6
CVE-2026-20212 Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability 03.09.2026 9.8
CVE-2026-20274 Cisco IOS XR Software Security Hardening Release: September 2026 04.09.2026 9.8
CVE-2026-20279 Cisco IOS XR Software Security Hardening Release: September 2026 04.09.2026 9.8
CVE-2026-53611 Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation 02.09.2026 9.8
CVE-2026-78689 NGINX ngx_http_js_module vulnerablility 03.09.2026 9.2
CVE-2026-82955 02.09.2026 9
CVE-2025-9314 Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload 02.09.2026 9.8
CVE-2026-4357 Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload 02.09.2026 10
CVE-2026-77009 WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console 02.09.2026 9.9
CVE-2026-81294 WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability 02.09.2026 9.8
CVE-2026-81286 WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84795 Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance 02.09.2026 9.2
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field 02.09.2026 9.8
CVE-2026-9055 Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' 02.09.2026 9.8
CVE-2026-84695 BookStack before 26.05.4 Stored XSS via Drawing Upload 02.09.2026 9.3
CVE-2026-84696 Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands 02.09.2026 9.3
CVE-2026-84699 Team Password Manager before 14.184.308 Authentication Bypass in Password Reset 02.09.2026 9.3
CVE-2026-84479 WWBN AVideo Authentication Bypass via User-Agent Header 02.09.2026 9.3
CVE-2026-84480 WWBN AVideo Password Recovery Token Expiration Bypass 02.09.2026 9.3
CVE-2023-54391 Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter 03.09.2026 9.3
CVE-2026-75604 Next.js: Unauthenticated Remote Code Execution on windows-hosted servers 04.09.2026 9
CVE-2026-84372 Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections 02.09.2026 9.8
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 03.09.2026 9.8
CVE-2026-76657 Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access 01.09.2026 10
CVE-2026-76658 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon 01.09.2026 10
CVE-2026-19766 Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer 02.09.2026 9.6
CVE-2026-73700 Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface 02.09.2026 9
CVE-2026-73701 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer 02.09.2026 9
CVE-2026-79687 02.09.2026 9
CVE-2026-18931 Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software 01.09.2026 9.1
CVE-2026-78012 Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack 04.09.2026 9.3
CVE-2026-18210 SQL Injection in TRtek Technological Products's Store 01.09.2026 9.8
CVE-2026-9621 RSLinx Classic® - Multiple Vulnerabilities 01.09.2026 9.2
CVE-2026-18808 Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO 01.09.2026 9.8
CVE-2026-18765 SQL Injection in Teracity Sotware's Teracity E-OSB Platform 01.09.2026 9.8
CVE-2026-84149 Information Disclosure Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2026-84147 Remote Code Execution Vulnerability in Manacle Technologies ERP System 01.09.2026 10
CVE-2026-84148 Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites 04.09.2026 9.3
CVE-2026-84189 LibreNMS before 26.7.0 Stored XSS via Oxidized API 04.09.2026 9.2
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions 02.09.2026 9.4
CVE-2026-18550 Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter 02.09.2026 9.8
CVE-2026-4813 Code injection in the Lutece Core 01.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-76561 Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) 08.09.2026
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-48888 WordPress WooCommerce plugin < 11.1.0 - Denial of Service Attack vulnerability 08.09.2026 7.5
CVE-2026-81781 WordPress Unbounce Landing Pages plugin <= 1.1.4 - Broken Access Control vulnerability 08.09.2026 7.1
CVE-2026-81806 WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerability 08.09.2026 7.2
CVE-2026-81790 WordPress Csomagpontok és szállítási címkék WooCommerce-hez plugin < 4.2.8 - Broken Access Control vulnerability 08.09.2026 7.5
CVE-2026-81792 WordPress Product Catalog Enquiry for WooCommerce by MultiVendorX plugin <= 6.1.4 - Privilege Escalation vulnerability 08.09.2026 6.5
CVE-2026-81798 WordPress Easy Appointments plugin <= 4.0.2.1 - Cross Site Scripting (XSS) vulnerability 08.09.2026 7.1
CVE-2026-81802 WordPress WpEvently plugin <= 5.6.0 - Insecure Direct Object References (IDOR) vulnerability 08.09.2026 6.5
CVE-2026-84817 WordPress JetFormBuilder plugin <= 3.6.5.1 - Cross Site Scripting (XSS) vulnerability 08.09.2026 7.1
CVE-2026-84818 WordPress Open User Map plugin <= 1.4.50 - Cross Site Scripting (XSS) vulnerability 08.09.2026 7.1
CVE-2026-84820 WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.17 - Cross Site Scripting (XSS) vulnerability 08.09.2026 7.1
CVE-2026-86519 code-projects Student Crud Operation Backup File card_activation.sql information disclosure 08.09.2026
CVE-2026-86518 code-projects Student Crud Operation edit.php sql injection 08.09.2026
CVE-2026-86517 itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection 08.09.2026
CVE-2026-86516 elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management 08.09.2026
CVE-2026-86515 vgmstream txtp txtp_parser.c add_entry resource consumption 08.09.2026
CVE-2026-86514 vgmstream txth-txtp txth.c sscanf stack-based overflow 08.09.2026
CVE-2026-86513 java-json-tools jackson-coreutils JSON Pointer parser TreePointer.java TreePointer.tokensFromInput allocation of resources 08.09.2026
CVE-2026-12962 08.09.2026
CVE-2026-16003 08.09.2026
CVE-2026-16004 08.09.2026
CVE-2026-16005 08.09.2026
CVE-2026-16006 08.09.2026
CVE-2026-18023 08.09.2026
CVE-2026-19397 08.09.2026
CVE-2026-75808 08.09.2026
CVE-2026-75809 08.09.2026
CVE-2026-75810 08.09.2026
CVE-2026-75811 08.09.2026
CVE-2026-86511 java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption 08.09.2026
CVE-2026-86512 java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control 08.09.2026
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 08.09.2026
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-44766 SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation) 08.09.2026 6.5
CVE-2026-58234 Denial of Service vulnerability in SAP Process Integration (SOAP Adapter) 08.09.2026 2.2
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 08.09.2026 9.8
CVE-2026-66767 Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform 08.09.2026 7.7
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 08.09.2026 9
CVE-2026-76958 XML External Entity (XXE) Vulnerability in SAP Integration Suite 08.09.2026 8.5
CVE-2026-76959 Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) 08.09.2026 4.6
CVE-2026-76960 Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) 08.09.2026 3.5
CVE-2026-76961 Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) 08.09.2026 3.5
CVE-2026-76962 Missing Authorization check in SAP S/4HANA (Manage Bank Chains app) 08.09.2026 4.3
CVE-2026-76963 Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform 08.09.2026 4.3
CVE-2026-76967 Insecure Deserialization in SAP NetWeaver Business Client 08.09.2026 7.8
CVE-2026-76968 Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server 08.09.2026 6.5
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-76971 Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence 08.09.2026 6.5
CVE-2026-76977 Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) 08.09.2026 4.3
CVE-2026-82710 Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata 08.09.2026
CVE-2026-86439 knowns before 0.30.0 Path Traversal via MCP doc and memory tools 07.09.2026
CVE-2026-86538 knowns before 0.30.0 Path Traversal via templateFile parameter 07.09.2026
CVE-2026-86539 knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint 07.09.2026
CVE-2026-86540 knowns before 0.30.0 Arbitrary Code Execution via LSP Binary 07.09.2026
CVE-2026-86541 knowns before 0.30.0 Path Traversal via code.replace MCP action 07.09.2026
CVE-2026-86542 knowns before 0.30.0 Path Traversal via Import Name 07.09.2026
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 07.09.2026
CVE-2026-86544 knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions 07.09.2026
CVE-2026-82584 Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata 07.09.2026
CVE-2026-81638 Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry 07.09.2026
CVE-2026-82586 AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes 07.09.2026
CVE-2026-82756 ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection 07.09.2026
CVE-2026-82757 ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and site-local addresses as public, allowing SSRF 07.09.2026
CVE-2026-82758 ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint 07.09.2026
CVE-2026-82754 ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls 07.09.2026
CVE-2026-82755 ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion 07.09.2026
CVE-2026-82753 Unauthenticated authorize requests create unbounded, never-expiring CIMD client rows and cache entries in ash_authentication_oauth2_server 07.09.2026
CVE-2026-86436 Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Upload Endpoints 07.09.2026
CVE-2026-86437 Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload 07.09.2026
CVE-2026-86438 Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action 07.09.2026
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 07.09.2026 10
CVE-2026-16028 Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table 07.09.2026
CVE-2026-86287 Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths 07.09.2026
CVE-2026-80166 07.09.2026 7.8
CVE-2026-79639 07.09.2026 7.6
CVE-2026-80125 07.09.2026 5.9
CVE-2026-80176 07.09.2026 4.7
CVE-2026-86478 07.09.2026 9.8
CVE-2026-86479 07.09.2026 8
CVE-2026-86480 07.09.2026 9.8
CVE-2026-86481 07.09.2026 4.3
CVE-2026-86482 07.09.2026 8.8
CVE-2026-86483 07.09.2026 5.4
CVE-2026-86484 07.09.2026 4.6
CVE-2026-86485 07.09.2026 3.5
CVE-2026-86486 07.09.2026 3.7
CVE-2026-86487 07.09.2026 3.1
CVE-2026-86488 07.09.2026 6.5
CVE-2026-86489 07.09.2026 6.5
CVE-2026-86490 07.09.2026 6.5
CVE-2026-86491 07.09.2026 3.5
CVE-2026-86492 07.09.2026 8.5
CVE-2026-86493 07.09.2026 6.5
CVE-2026-86494 07.09.2026 7.7
CVE-2026-86495 07.09.2026 6.5
CVE-2026-86496 07.09.2026 4.3
CVE-2026-86497 07.09.2026 6.8
CVE-2026-86498 07.09.2026 7.7
CVE-2026-86499 07.09.2026 4.3
CVE-2026-86500 07.09.2026 5.5
CVE-2026-86501 07.09.2026 2.8
CVE-2026-86502 07.09.2026 8.4
CVE-2026-86503 07.09.2026 3.3
CVE-2026-86504 07.09.2026 7.8
CVE-2026-86505 07.09.2026 3.3
CVE-2026-86506 07.09.2026 5.9
CVE-2026-79975 07.09.2026 5.5
CVE-2026-80058 07.09.2026 5.5
CVE-2026-80126 07.09.2026 6.5
CVE-2026-80167 07.09.2026 5.5
CVE-2026-80127 07.09.2026 7.2
CVE-2026-86469 Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path 07.09.2026
CVE-2026-79642 07.09.2026 5.6
CVE-2026-79943 07.09.2026 4.8
CVE-2026-79691 07.09.2026 7.3
CVE-2026-79643 07.09.2026 7.3
CVE-2026-80054 07.09.2026 5.5
CVE-2026-86321 java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.fromURL server-side request forgery 07.09.2026
CVE-2026-86319 java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consumption 07.09.2026
CVE-2026-86318 java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fromJson stack-based overflow 07.09.2026
CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet() 08.09.2026
CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search 08.09.2026
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026
CVE-2026-19843 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor 08.09.2026
CVE-2026-6377 Path Traversal in Next4Biz's CSM (Customer Service Management) 07.09.2026 7.5
CVE-2026-78480 07.09.2026 7.5
CVE-2026-78488 07.09.2026 6.5
CVE-2026-79644 07.09.2026 7.4
CVE-2026-79645 07.09.2026 8.2
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 07.09.2026 9.8
CVE-2026-80056 07.09.2026 5.5
CVE-2026-80057 07.09.2026 5.5
CVE-2026-86317 ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion 07.09.2026
CVE-2026-80170 07.09.2026 6.5
CVE-2026-86310 itsourcecode Sales and Inventory System cust_edit1.php sql injection 07.09.2026
CVE-2026-79734 07.09.2026 5.9
CVE-2026-78487 07.09.2026 5.5
CVE-2026-86309 itsourcecode Sales and Inventory System pro_searchfrm.php sql injection 07.09.2026
CVE-2026-80128 07.09.2026 6.4
CVE-2026-80130 07.09.2026 7.1
CVE-2026-12757 Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field 07.09.2026 6.5
CVE-2026-14444 WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter 07.09.2026 7.5
CVE-2026-80129 07.09.2026 6.5
CVE-2026-80131 07.09.2026 7.4
CVE-2026-80164 07.09.2026 7.4
CVE-2026-86308 light0011 cms Debug Mode config.php information disclosure 07.09.2026
CVE-2026-76560 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn 08.09.2026
CVE-2026-86307 light0011 cms cross-site request forgery 07.09.2026
CVE-2026-86452 MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding 07.09.2026
CVE-2022-51010 PocketMine-MP before 4.4.2 Server Crash via Item ID 07.09.2026
CVE-2022-51011 PocketMine-MP before 4.2.10 Denial of Service via Chat Messages 07.09.2026
CVE-2022-51012 PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization 07.09.2026
CVE-2022-51013 PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata 07.09.2026
CVE-2022-51014 PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding 07.09.2026
CVE-2022-51015 PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket 07.09.2026
CVE-2022-51016 PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay 07.09.2026
CVE-2022-51017 PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data 07.09.2026
CVE-2022-51018 PocketMine-MP before 3.26.5 Input Validation via Book Pages 07.09.2026
CVE-2026-80238 07.09.2026 9.3
CVE-2026-86306 light0011 cms Cookie Helper UserModel.class.php improper authentication 07.09.2026
CVE-2026-86451 MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects 07.09.2026
CVE-2026-80135 07.09.2026 7.5
CVE-2026-80178 07.09.2026 5.5
CVE-2026-86305 light0011 cms Upload.class.php upload unrestricted upload 07.09.2026
CVE-2026-86420 ImageMagick before 7.1.2-30 Denial of Service Memory Budget 07.09.2026
CVE-2026-86421 ImageMagick before 7.1.2-30 Memory Leak via MSL decoder 07.09.2026
CVE-2026-86422 ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race 07.09.2026
CVE-2026-86423 ImageMagick before 7.1.2-30 Heap-use-after-free via GetList 07.09.2026
CVE-2026-86424 ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race 07.09.2026
CVE-2026-86425 ImageMagick before 7.1.2-30 Heap-use-after-free via Layer 07.09.2026
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 07.09.2026
CVE-2026-86427 LibreNMS before 26.8.0 Argument Injection via graph_title 07.09.2026
CVE-2026-86428 commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes 07.09.2026
CVE-2026-86429 commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes 07.09.2026
CVE-2026-86430 league/commonmark before 2.9.1 Denial of Service via parsing 07.09.2026
CVE-2026-86431 commonmark before 2.9.1 XSS via AttributesExtension form feed bypass 07.09.2026
CVE-2026-86432 commonmark 2.0.0 before 2.8.4 Denial of Service via XML 07.09.2026
CVE-2026-86433 commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes 07.09.2026
CVE-2026-86434 commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision 07.09.2026
CVE-2026-86435 commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote 07.09.2026
CVE-2026-12853 Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Unauthorized Tag Information Disclosure via wp.getTerms and ajax-tag-search 07.09.2026 5.4
CVE-2026-4945 Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypass 07.09.2026 5.3
CVE-2026-61410 07.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 07.09.2026 9.4
CVE-2026-6431 User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field 07.09.2026 7.2
CVE-2026-80132 07.09.2026 8.1
CVE-2026-80133 07.09.2026 7.4
CVE-2026-80134 07.09.2026 7.7
CVE-2026-86416 ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Action Methods 07.09.2026
CVE-2026-86419 MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery 07.09.2026
CVE-2026-86440 MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs 07.09.2026
CVE-2026-86441 MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data 07.09.2026
CVE-2026-8279 Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion 07.09.2026 5.3
CVE-2026-61409 07.09.2026 7.3
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 07.09.2026
CVE-2026-79678 Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service 07.09.2026
CVE-2026-86302 code-projects Hospital Information System SQL Database Backup File his.sql information disclosure 07.09.2026
CVE-2026-86303 92181 markdown md.c lds out-of-bounds 07.09.2026
CVE-2026-86408 MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected Events 07.09.2026
CVE-2026-86417 MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users 07.09.2026
CVE-2026-86418 MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users 07.09.2026
CVE-2026-78325 XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import 07.09.2026
CVE-2026-86301 code-projects Hospital Information System Patient Management editPatient.php cross site scripting 07.09.2026
CVE-2026-86404 Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default 07.09.2026
CVE-2026-2390 Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lazy Load Image Processing 07.09.2026 6.4
CVE-2026-86300 Tenda AC9 Web Management R7WebsSecurityHandler improper authentication 07.09.2026
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 07.09.2026
CVE-2026-82325 07.09.2026
CVE-2026-86298 SourceCodester Class and Exam Timetabling System delete_subject.php sql injection 07.09.2026
CVE-2026-77697 Privilege Escalation 07.09.2026 6.3
CVE-2026-85640 Privilege Escalation 07.09.2026 6.3
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 07.09.2026
CVE-2025-52651 HCL MyXalytics is affected by multiple security vulnerabilities. 07.09.2026 3.5
CVE-2025-52652 HCL MyXalytics is affected by multiple security vulnerabilities. 07.09.2026 3.5
CVE-2025-52657 HCL MyXalytics is affected by multiple security vulnerabilities. 07.09.2026 3.5
CVE-2026-19204 07.09.2026
CVE-2026-77699 Privilege Escalation 08.09.2026 5
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 07.09.2026
CVE-2026-86295 D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection 07.09.2026