| CVE-2026-63374 |
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing |
22.09.2026 |
9.3 |
| CVE-2026-77621 |
Vector: Arbitrary file write in the file sink via templated path (path traversal). |
22.09.2026 |
9.3 |
| CVE-2026-80143 |
Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read |
22.09.2026 |
9.4 |
| CVE-2026-80144 |
Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write |
22.09.2026 |
9.4 |
| CVE-2026-80145 |
Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password |
22.09.2026 |
9.4 |
| CVE-2026-80146 |
Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read |
22.09.2026 |
9.4 |
| CVE-2026-80147 |
Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write |
22.09.2026 |
9.4 |
| CVE-2026-80151 |
Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download |
22.09.2026 |
9.4 |
| CVE-2026-80152 |
Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule |
22.09.2026 |
9.4 |
| CVE-2026-80155 |
Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation |
22.09.2026 |
10 |
| CVE-2026-80156 |
Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass |
22.09.2026 |
9.4 |
| CVE-2026-95654 |
Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token |
22.09.2026 |
9.1 |
| CVE-2026-65113 |
|
22.09.2026 |
9.8 |
| CVE-2026-84388 |
|
22.09.2026 |
9.1 |
| CVE-2026-94127 |
BIG-IP APM OAuth vulnerability |
22.09.2026 |
9.3 |
| CVE-2026-12718 |
SQLi in Karel Electronics' KarelIPS |
22.09.2026 |
9.8 |
| CVE-2026-95675 |
D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface |
22.09.2026 |
9.3 |
| CVE-2026-93616 |
Directory Traversal and File upload allows execution of arbitrary script on the Management Server |
22.09.2026 |
9.8 |
| CVE-2026-74849 |
Remote code execution vulnerability |
22.09.2026 |
9.8 |
| CVE-2026-25254 |
Improper authorization in Qualcomm Software Center |
22.09.2026 |
9.8 |
| CVE-2026-93556 |
Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini |
22.09.2026 |
9.3 |
| CVE-2026-89422 |
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension |
22.09.2026 |
9.3 |
| CVE-2026-93952 |
Security Advisory 0183 |
22.09.2026 |
9.5 |
| CVE-2026-13355 |
Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter |
22.09.2026 |
9.8 |
| CVE-2026-19658 |
Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter |
22.09.2026 |
9.8 |
| CVE-2026-94493 |
Gigatech PDV5701 WebSocket Service index.html missing authentication |
22.09.2026 |
10 |
| CVE-2026-94425 |
Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management |
22.09.2026 |
9.3 |
| CVE-2026-46649 |
Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint |
21.09.2026 |
9.1 |
| CVE-2026-77521 |
MaxKB: Prompt-injectable agent can lead to command execution |
22.09.2026 |
10 |
| CVE-2026-94424 |
Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow |
21.09.2026 |
9.3 |
| CVE-2026-79916 |
MaxKB AWS Bedrock model credential injection leads to remote code execution |
22.09.2026 |
9.1 |
| CVE-2026-94571 |
|
22.09.2026 |
9.4 |
| CVE-2026-94572 |
|
21.09.2026 |
9.4 |
| CVE-2026-58491 |
Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter |
22.09.2026 |
9.3 |
| CVE-2026-94403 |
ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference |
22.09.2026 |
9.3 |
| CVE-2026-79920 |
Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task |
21.09.2026 |
9.9 |
| CVE-2026-61674 |
Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handler |
21.09.2026 |
9.2 |
| CVE-2026-85751 |
Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust |
21.09.2026 |
9.8 |
| CVE-2026-94301 |
Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 |
22.09.2026 |
9.8 |
| CVE-2025-12999 |
|
22.09.2026 |
9.1 |
| CVE-2026-94146 |
BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where |
22.09.2026 |
9.3 |
| CVE-2026-94142 |
BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where |
21.09.2026 |
9.3 |
| CVE-2026-94128 |
BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where |
21.09.2026 |
9.3 |
| CVE-2026-94129 |
BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where |
21.09.2026 |
9.3 |
| CVE-2026-94101 |
Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow |
21.09.2026 |
9.4 |
| CVE-2026-94098 |
Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection |
21.09.2026 |
9.4 |
| CVE-2026-94099 |
Netcore NBR200V2 Backup Restore restore.cgi command injection |
22.09.2026 |
9.4 |
| CVE-2026-94100 |
Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow |
21.09.2026 |
9.4 |
| CVE-2026-94097 |
Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection |
20.09.2026 |
10 |
| CVE-2026-94096 |
Netcore NBR200V2 LAN IP Configuration network_tools command injection |
21.09.2026 |
9.4 |
| CVE-2026-94095 |
Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection |
21.09.2026 |
9.4 |
| CVE-2026-94089 |
D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow |
22.09.2026 |
10 |
| CVE-2026-88857 |
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 |
22.09.2026 |
9.4 |
| CVE-2026-88854 |
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 |
22.09.2026 |
9.3 |
| CVE-2026-88856 |
Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 |
22.09.2026 |
9.4 |
| CVE-2026-90817 |
|
21.09.2026 |
9.8 |
| CVE-2026-94003 |
Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based overflow |
20.09.2026 |
10 |
| CVE-2026-94107 |
NivoCart through 2.4.0 Predictable Administrator Password Reset Token |
21.09.2026 |
9.2 |
| CVE-2026-93958 |
D-Link R95 DHMAPI ssi system os command injection |
21.09.2026 |
9.4 |
| CVE-2026-94083 |
|
22.09.2026 |
9.4 |
| CVE-2026-94084 |
|
20.09.2026 |
9.4 |
| CVE-2026-93985 |
OpenPanel js-runtime JavaScript Template Sandbox Escape RCE |
21.09.2026 |
9.4 |
| CVE-2026-93742 |
Totolink A3002MU formWsc command injection |
21.09.2026 |
9.4 |
| CVE-2026-93741 |
Totolink A3002MU formWlWds buffer overflow |
22.09.2026 |
10 |
| CVE-2026-84434 |
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field |
19.09.2026 |
9.8 |
| CVE-2026-89274 |
WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content |
19.09.2026 |
9.1 |
| CVE-2026-92229 |
Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter |
19.09.2026 |
9.1 |
| CVE-2026-75885 |
Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint |
21.09.2026 |
9.3 |
| CVE-2026-93740 |
Totolink A3002MU formWlEncrypt buffer overflow |
21.09.2026 |
10 |
| CVE-2026-93739 |
Totolink A3002MU formWlAc buffer overflow |
18.09.2026 |
9.4 |
| CVE-2026-93738 |
Totolink A3002MU formSchedule buffer overflow |
22.09.2026 |
9.4 |
| CVE-2026-58264 |
FluidSynth: Heap-based buffer overrun |
21.09.2026 |
9.8 |
| CVE-2026-63647 |
CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` |
18.09.2026 |
9.3 |
| CVE-2026-93868 |
Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
18.09.2026 |
9.2 |
| CVE-2026-84073 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.1 |
| CVE-2026-84075 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-84078 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-84082 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-61781 |
pg_partman has privilege escalation through SQL injection in create_partition_time() |
18.09.2026 |
9.9 |
| CVE-2026-84064 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-82967 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-84031 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9 |
| CVE-2026-81657 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
22.09.2026 |
9.8 |
| CVE-2026-82340 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-82832 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.6 |
| CVE-2026-75878 |
IBM Sterling File Gateway is Vulnerable to Authentication Bypass |
19.09.2026 |
9.1 |
| CVE-2026-80441 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-80442 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-93839 |
LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint |
22.09.2026 |
9.3 |
| CVE-2023-54399 |
Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree |
21.09.2026 |
9.3 |
| CVE-2026-59163 |
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass |
18.09.2026 |
9.1 |
| CVE-2026-61550 |
Icinga 2: Improper access control for JSON-RPC update certificate messages |
21.09.2026 |
9.8 |
| CVE-2025-66455 |
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py |
18.09.2026 |
9.8 |
| CVE-2026-92701 |
Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path |
21.09.2026 |
9.1 |
| CVE-2026-92702 |
Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path |
22.09.2026 |
9.1 |
| CVE-2026-93762 |
Data deletion and attribute disclosure via field-name method injection in in-memory queries |
21.09.2026 |
9.2 |
| CVE-2026-77240 |
WACRM: Database-layer authorization bypasses |
18.09.2026 |
9.9 |
| CVE-2026-81321 |
CareCam CM2507 Cleartext Storage of Sensitive Information |
19.09.2026 |
9.3 |
| CVE-2026-85497 |
CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
21.09.2026 |
9.3 |
| CVE-2026-10858 |
IBM MQ for HPE NonStop is vulnerable to a denial of service attack |
19.09.2026 |
9.9 |
| CVE-2026-61682 |
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace |
21.09.2026 |
9.9 |
| CVE-2026-10747 |
IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing |
21.09.2026 |
10 |
| CVE-2026-84383 |
libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items |
18.09.2026 |
9.8 |
| CVE-2025-15399 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
21.09.2026 |
10 |
| CVE-2025-53837 |
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue |
21.09.2026 |
9.9 |
| CVE-2026-93659 |
Concrete CMS Community Store before 2.7.8 Stored XSS |
18.09.2026 |
9.3 |
| CVE-2023-5778 |
Missing Length Check |
18.09.2026 |
9.2 |
| CVE-2026-93603 |
vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function |
22.09.2026 |
10 |
| CVE-2026-93605 |
vm2 NodeVM before 3.12.1 Remote Code Execution via child_process |
21.09.2026 |
10 |
| CVE-2026-93606 |
vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species |
18.09.2026 |
10 |
| CVE-2026-28197 |
Privilege Escalation via Argument Injection in NetBackup Flex OS Shell |
18.09.2026 |
9.4 |
| CVE-2026-28198 |
Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell |
18.09.2026 |
9.4 |
| CVE-2026-13639 |
|
18.09.2026 |
9.8 |
| CVE-2026-13684 |
|
18.09.2026 |
9.8 |
| CVE-2026-67100 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-67101 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
21.09.2026 |
9.3 |
| CVE-2026-93467 |
HGiga|OAKlouds - Insecure Deserialization |
18.09.2026 |
9.3 |
| CVE-2026-62874 |
Azure Billing Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-69843 |
Microsoft Fabric Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-85878 |
Azure Database for PostgreSQL Elevation of Privilege Vulnerability |
21.09.2026 |
9.9 |
| CVE-2026-69399 |
Azure Arc Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-69865 |
Microsoft Container Registry Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-70009 |
Azure Arc Elevation of Privilege Vulnerability |
21.09.2026 |
9.3 |
| CVE-2026-70200 |
Azure Logic Apps Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-77903 |
Microsoft Dataverse Elevation of Privilege Vulnerability |
21.09.2026 |
9 |
| CVE-2026-83944 |
Azure Logic Apps Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-85885 |
Microsoft 365 Copilot Elevation of Privilege Vulnerability |
21.09.2026 |
9.9 |
| CVE-2026-85889 |
Azure AI Foundry Elevation of Privilege Vulnerability |
21.09.2026 |
10 |
| CVE-2026-87701 |
Azure Cosmos DB Elevation of Privilege Vulnerability |
21.09.2026 |
9.6 |
| CVE-2026-54734 |
Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction |
18.09.2026 |
10 |
| CVE-2026-76949 |
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement |
18.09.2026 |
9.1 |
| CVE-2026-54670 |
WeGIA: Unauthenticated Auth Bypass + Local File Inclusion |
17.09.2026 |
9.1 |
| CVE-2026-54767 |
WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php |
18.09.2026 |
9.1 |
| CVE-2026-93393 |
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream |
18.09.2026 |
9.2 |
| CVE-2026-45140 |
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution |
18.09.2026 |
9.8 |
| CVE-2026-45143 |
Chamilo LMS: Student-to-admin stored XSS in private messages via v-html |
17.09.2026 |
9 |
| CVE-2026-54237 |
Wavelog: Unauthenticated Remote Code Execution |
18.09.2026 |
9.3 |
| CVE-2026-54460 |
OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover |
17.09.2026 |
9.8 |
| CVE-2026-54501 |
Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors |
17.09.2026 |
9.4 |
| CVE-2026-54752 |
NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request |
21.09.2026 |
9.6 |
| CVE-2026-54618 |
Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user |
17.09.2026 |
9.4 |
| CVE-2026-54626 |
SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) |
17.09.2026 |
9.8 |
| CVE-2026-54627 |
SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) |
18.09.2026 |
9.8 |
| CVE-2026-92943 |
Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python |
17.09.2026 |
9.2 |
| CVE-2026-54617 |
GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler |
18.09.2026 |
9.8 |
| CVE-2026-47252 |
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) |
17.09.2026 |
9 |
| CVE-2026-54053 |
Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults |
17.09.2026 |
9.6 |
| CVE-2026-90104 |
NFSv4.1: zero referring call lists before decoding |
18.09.2026 |
9.8 |
| CVE-2026-90110 |
inetpeer: randomize RB-tree node comparison using SipHash |
18.09.2026 |
9.4 |
| CVE-2026-90151 |
NFSv4: remove callback IDR entry on client allocation failure |
18.09.2026 |
9.8 |
| CVE-2026-90173 |
smb: smbdirect: free completion queues with ib_free_cq() |
18.09.2026 |
9.8 |
| CVE-2026-90230 |
nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
18.09.2026 |
9.1 |
| CVE-2026-90235 |
sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
18.09.2026 |
9.8 |
| CVE-2026-90413 |
IB/isert: reject login PDUs declaring more data than was received |
18.09.2026 |
9.1 |
| CVE-2026-90414 |
IB/isert: reject PDUs declaring more data than was received |
18.09.2026 |
9.1 |
| CVE-2026-92489 |
xfrm: Fix skb double-free in xfrm_dev_direct_output() |
18.09.2026 |
9.8 |
| CVE-2026-86863 |
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode |
17.09.2026 |
9.3 |
| CVE-2026-76834 |
b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key |
18.09.2026 |
9.2 |
| CVE-2026-91039 |
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover |
17.09.2026 |
9.1 |
| CVE-2026-79752 |
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection |
17.09.2026 |
9.2 |
| CVE-2026-63472 |
Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification |
17.09.2026 |
9.1 |
| CVE-2026-88952 |
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication |
17.09.2026 |
9.1 |
| CVE-2026-92934 |
vm2 before 3.11.8 Sandbox Escape RCE via AggregateError |
17.09.2026 |
9.5 |
| CVE-2026-92935 |
vm2 NodeVM Remote Code Execution via Array-Shaped Require |
17.09.2026 |
9.5 |
| CVE-2026-92937 |
vm2 3.11.6 Remote Code Execution via Promise call/apply |
18.09.2026 |
10 |
| CVE-2026-92938 |
vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite |
19.09.2026 |
9.4 |
| CVE-2026-92939 |
vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine |
17.09.2026 |
9.4 |
| CVE-2026-92940 |
vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent |
17.09.2026 |
10 |
| CVE-2026-92941 |
vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation |
17.09.2026 |
10 |
| CVE-2026-92944 |
vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector |
19.09.2026 |
9.3 |
| CVE-2026-92946 |
vm2 before 3.11.7 Remote Code Execution via require.external |
17.09.2026 |
10 |
| CVE-2026-92947 |
vm2 before 3.11.7 Memory Disclosure via Buffer Pool |
17.09.2026 |
10 |
| CVE-2026-92948 |
vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test |
18.09.2026 |
9.4 |
| CVE-2026-92950 |
vm2 before 3.11.7 Sandbox Escape via CLI require |
17.09.2026 |
9.3 |
| CVE-2026-92951 |
vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver |
17.09.2026 |
9.4 |
| CVE-2026-92953 |
vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray |
18.09.2026 |
9.3 |
| CVE-2026-92954 |
vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise |
21.09.2026 |
9.2 |
| CVE-2026-92955 |
vm2 before 3.11.8 Sandbox Escape via NodeVM |
17.09.2026 |
10 |
| CVE-2026-92956 |
vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming |
17.09.2026 |
10 |
| CVE-2026-92957 |
vm2 before 3.11.7 Authentication Bypass via node: Prefix |
17.09.2026 |
9.4 |
| CVE-2026-92960 |
vm2 before 3.11.6 Process-wide State Exposure via os and dns |
17.09.2026 |
10 |
| CVE-2026-62101 |
WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability |
17.09.2026 |
9.8 |
| CVE-2026-62104 |
WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability |
19.09.2026 |
10 |
| CVE-2026-62108 |
WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability |
17.09.2026 |
9.8 |
| CVE-2026-82761 |
Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
17.09.2026 |
9.1 |
| CVE-2026-85500 |
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication |
17.09.2026 |
9.1 |
| CVE-2026-86533 |
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix |
17.09.2026 |
9.1 |
| CVE-2026-90822 |
|
17.09.2026 |
9.8 |
| CVE-2026-90823 |
|
17.09.2026 |
9.8 |
| CVE-2026-92860 |
rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation |
19.09.2026 |
9.4 |
| CVE-2026-92913 |
AVideo Weak PRNG Activation Code Authentication Bypass |
17.09.2026 |
9.1 |
| CVE-2026-15688 |
Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting |
17.09.2026 |
9.2 |
| CVE-2026-87796 |
Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload |
19.09.2026 |
9.8 |
| CVE-2026-61594 |
djust has an authorization bypass on the WebSocket/SSE mount path |
17.09.2026 |
9.1 |
| CVE-2026-92576 |
HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool |
17.09.2026 |
9.2 |
| CVE-2026-92578 |
WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash |
17.09.2026 |
9.2 |
| CVE-2026-75513 |
Marten: SQL injection in Marten's LINQ provider via unescaped string literals |
19.09.2026 |
9.1 |
| CVE-2026-92749 |
SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret |
17.09.2026 |
9.2 |
| CVE-2026-92785 |
Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes |
17.09.2026 |
9.2 |
| CVE-2026-92787 |
Feast through 0.66.0 Authentication Bypass via Unverified Token |
19.09.2026 |
9.3 |
| CVE-2026-92805 |
UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard |
19.09.2026 |
9.3 |
| CVE-2026-20284 |
Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability |
18.09.2026 |
9.1 |
| CVE-2026-20332 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities |
18.09.2026 |
9.9 |
| CVE-2026-76460 |
Cisco Identity Services Engine Authentication Bypass Vulnerability |
17.09.2026 |
10 |
| CVE-2026-20130 |
Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities |
18.09.2026 |
10 |
| CVE-2026-20176 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20192 |
Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities |
18.09.2026 |
10 |
| CVE-2026-20194 |
Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities |
18.09.2026 |
9.1 |
| CVE-2026-20211 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20237 |
Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities |
18.09.2026 |
9.1 |
| CVE-2026-20242 |
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability |
18.09.2026 |
9.8 |
| CVE-2026-20322 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control |
18.09.2026 |
9.9 |
| CVE-2026-20324 |
Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability |
18.09.2026 |
9.9 |
| CVE-2026-20325 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command |
18.09.2026 |
9.9 |
| CVE-2026-20326 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function |
18.09.2026 |
9.8 |
| CVE-2026-20329 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities |
18.09.2026 |
9.9 |
| CVE-2026-20330 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities |
18.09.2026 |
9.9 |
| CVE-2026-20341 |
Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability |
18.09.2026 |
9.1 |
| CVE-2026-76423 |
Cisco ISE API Authentication Bypass Vulnerability |
17.09.2026 |
10 |
| CVE-2026-92808 |
Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise |
17.09.2026 |
10 |
| CVE-2026-89083 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
17.09.2026 |
9.3 |
| CVE-2026-89082 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
17.09.2026 |
9.3 |
| CVE-2026-73456 |
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. |
17.09.2026 |
9.2 |
| CVE-2026-91104 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
9.3 |
| CVE-2026-91106 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
9.3 |
| CVE-2026-92717 |
Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub |
21.09.2026 |
9.3 |
| CVE-2026-92720 |
Kubero through 3.1.1 Unauthenticated Notifications API Access |
17.09.2026 |
9.3 |
| CVE-2026-20234 |
Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities |
17.09.2026 |
9.9 |
| CVE-2026-20305 |
Cisco Identity Services Engine Command Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20306 |
Cisco Identity Services Engine Command Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20307 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.9 |
| CVE-2026-20331 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities |
18.09.2026 |
9.6 |
| CVE-2026-76420 |
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability |
17.09.2026 |
9 |
| CVE-2026-92398 |
Ruijie RG-EW3000GX user_list_note admin os command injection |
16.09.2026 |
9.4 |
| CVE-2026-92397 |
Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection |
16.09.2026 |
9.4 |
| CVE-2025-59953 |
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy |
18.09.2026 |
9.8 |
| CVE-2026-70416 |
|
16.09.2026 |
10 |
| CVE-2026-77411 |
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr |
16.09.2026 |
9.5 |
| CVE-2026-77405 |
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser |
18.09.2026 |
9.4 |
| CVE-2026-92395 |
@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
17.09.2026 |
9.1 |
| CVE-2026-77408 |
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow |
16.09.2026 |
9.1 |
| CVE-2026-91843 |
Stack overflow in login process to the Security Management and Log Servers |
17.09.2026 |
9.8 |
| CVE-2026-73172 |
|
17.09.2026 |
9.3 |
| CVE-2026-40855 |
Command Injection in T-Mobile 5G Box IDU router via ping functionality |
16.09.2026 |
9.3 |
| CVE-2026-58146 |
Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
16.09.2026 |
9.4 |
| CVE-2026-58147 |
Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers |
16.09.2026 |
9.3 |
| CVE-2026-89846 |
scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read |
16.09.2026 |
9.1 |
| CVE-2026-89847 |
scsi: qla2xxx: Avoid double completion in async IOCB timeout |
16.09.2026 |
9.8 |
| CVE-2026-89857 |
scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
16.09.2026 |
9.8 |
| CVE-2026-89914 |
KVM: arm64: Sign-extend VA for range-based TLBI invalidation |
16.09.2026 |
9.3 |
| CVE-2026-89915 |
KVM: arm64: Remove VM-wide VNCR mapping counter |
16.09.2026 |
9.3 |
| CVE-2026-89916 |
KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry |
16.09.2026 |
9.3 |
| CVE-2026-89918 |
KVM: arm64: Correctly handle end of VA space TLBI invalidation |
16.09.2026 |
9.3 |
| CVE-2026-89930 |
KVM: nVMX: Service local TLB flushes on failed nested VM-Enter |
16.09.2026 |
9.3 |
| CVE-2026-89969 |
nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
16.09.2026 |
9.8 |
| CVE-2026-89970 |
nvmet-auth: Synchronize timeout work during SQ teardown |
16.09.2026 |
9.8 |
| CVE-2026-89972 |
nvme: add missing SRCU grace period in error path |
16.09.2026 |
9.8 |
| CVE-2026-89990 |
ceph: lock mutex in ceph_mds_check_access() |
16.09.2026 |
9.8 |
| CVE-2026-90011 |
scsi: target: iscsi: Reserve a terminator byte for the login payload |
16.09.2026 |
9.1 |
| CVE-2026-90012 |
spi: Fix DMA mapping ownership on partial map failure |
16.09.2026 |
9.8 |
| CVE-2026-90036 |
NFSD: Prevent client use-after-free during blocked-lock reaping |
21.09.2026 |
9.8 |
| CVE-2026-90037 |
NFSD: Prevent client use-after-free during close_lru reaping |
21.09.2026 |
9.8 |
| CVE-2026-90038 |
NFSD: Prevent client use-after-free during export state revocation |
16.09.2026 |
9.8 |
| CVE-2026-90042 |
ceph: properly decrypt filenames in vmalloc() buffers |
21.09.2026 |
9.8 |
| CVE-2026-90048 |
fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
16.09.2026 |
9.8 |
| CVE-2026-90049 |
net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() |
16.09.2026 |
9.3 |
| CVE-2026-73453 |
Security Advisory 0174 |
17.09.2026 |
9.5 |
| CVE-2026-89778 |
isofs: fix out-of-bounds page array access on empty zisofs block |
16.09.2026 |
9.8 |
| CVE-2026-89779 |
fs/ntfs3: validate ef->size covers the record's name and value |
16.09.2026 |
9.1 |
| CVE-2026-89783 |
xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
16.09.2026 |
9.8 |
| CVE-2026-89786 |
ext4: fix out-of-bounds read in ext4_read_inline_dir() |
16.09.2026 |
9.1 |
| CVE-2026-89788 |
ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
16.09.2026 |
9.8 |
| CVE-2026-81642 |
Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY |
16.09.2026 |
9.1 |
| CVE-2026-89775 |
KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
16.09.2026 |
9.3 |
| CVE-2026-73461 |
Security Advisory 0163 |
17.09.2026 |
9.4 |
| CVE-2026-27546 |
Authentication Bypass in _account_log |
16.09.2026 |
9.8 |
| CVE-2026-27565 |
Remote code execution via uploading a malicious IODD file |
16.09.2026 |
9.8 |
| CVE-2026-73447 |
Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request |
17.09.2026 |
9.4 |
| CVE-2026-12793 |
JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter |
17.09.2026 |
9.8 |
| CVE-2026-14349 |
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action |
16.09.2026 |
9.8 |
| CVE-2026-15638 |
Cryptographic Padding Oracle |
16.09.2026 |
9.1 |
| CVE-2026-15639 |
Reflected Cross-Site Scripting |
16.09.2026 |
9.3 |
| CVE-2026-15640 |
Authentication Bypass via SAML Response Manipulation |
16.09.2026 |
9.5 |
| CVE-2026-73807 |
mySCADA myPRO Manager Missing Authorization |
16.09.2026 |
9.3 |