CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-85751 Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust 21.09.2026 9.8
CVE-2026-94301 Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 21.09.2026 9.8
CVE-2025-12999 21.09.2026 9.1
CVE-2026-94146 BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where 21.09.2026 9.3
CVE-2026-94142 BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94128 BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94129 BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94101 Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow 21.09.2026 9.4
CVE-2026-94098 Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection 21.09.2026 9.4
CVE-2026-94099 Netcore NBR200V2 Backup Restore restore.cgi command injection 21.09.2026 9.4
CVE-2026-94100 Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow 21.09.2026 9.4
CVE-2026-94097 Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection 20.09.2026 10
CVE-2026-94096 Netcore NBR200V2 LAN IP Configuration network_tools command injection 21.09.2026 9.4
CVE-2026-94095 Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection 20.09.2026 9.4
CVE-2026-94089 D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow 20.09.2026 10
CVE-2026-88857 Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 20.09.2026 9.4
CVE-2026-88854 Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 21.09.2026 9.3
CVE-2026-88856 Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 21.09.2026 9.4
CVE-2026-90817 21.09.2026 9.8
CVE-2026-94003 Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based overflow 20.09.2026 10
CVE-2026-94107 NivoCart through 2.4.0 Predictable Administrator Password Reset Token 20.09.2026 9.2
CVE-2026-93958 D-Link R95 DHMAPI ssi system os command injection 20.09.2026 9.4
CVE-2026-94083 20.09.2026 9.4
CVE-2026-94084 20.09.2026 9.4
CVE-2026-93985 OpenPanel js-runtime JavaScript Template Sandbox Escape RCE 21.09.2026 9.4
CVE-2026-93742 Totolink A3002MU formWsc command injection 19.09.2026 9.4
CVE-2026-93741 Totolink A3002MU formWlWds buffer overflow 19.09.2026 10
CVE-2026-84434 Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field 19.09.2026 9.8
CVE-2026-89274 WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content 19.09.2026 9.1
CVE-2026-92229 Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter 19.09.2026 9.1
CVE-2026-75885 Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint 18.09.2026 9.3
CVE-2026-93740 Totolink A3002MU formWlEncrypt buffer overflow 18.09.2026 10
CVE-2026-93739 Totolink A3002MU formWlAc buffer overflow 18.09.2026 9.4
CVE-2026-93738 Totolink A3002MU formSchedule buffer overflow 18.09.2026 9.4
CVE-2026-58264 FluidSynth: Heap-based buffer overrun 18.09.2026 9.8
CVE-2026-63647 CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` 18.09.2026 9.3
CVE-2026-93868 Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG 18.09.2026 9.2
CVE-2026-84073 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.1
CVE-2026-84075 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-84078 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-84082 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-61781 pg_partman has privilege escalation through SQL injection in create_partition_time() 18.09.2026 9.9
CVE-2026-84064 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-82967 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-84031 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9
CVE-2026-81657 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-82340 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-82832 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.6
CVE-2026-75878 IBM Sterling File Gateway is Vulnerable to Authentication Bypass 19.09.2026 9.1
CVE-2026-80441 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-80442 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-93839 LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint 18.09.2026 9.3
CVE-2023-54399 Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree 18.09.2026 9.3
CVE-2026-59163 Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass 18.09.2026 9.1
CVE-2026-61550 Icinga 2: Improper access control for JSON-RPC update certificate messages 18.09.2026 9.8
CVE-2025-66455 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py 18.09.2026 9.8
CVE-2026-92701 Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path 21.09.2026 9.1
CVE-2026-92702 Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path 18.09.2026 9.1
CVE-2026-93762 Data deletion and attribute disclosure via field-name method injection in in-memory queries 18.09.2026 9.2
CVE-2026-77240 WACRM: Database-layer authorization bypasses 18.09.2026 9.9
CVE-2026-81321 CareCam CM2507 Cleartext Storage of Sensitive Information 19.09.2026 9.3
CVE-2026-85497 CareCam CM2507 Use of Password Hash With Insufficient Computational Effort 18.09.2026 9.3
CVE-2026-10858 IBM MQ for HPE NonStop is vulnerable to a denial of service attack 19.09.2026 9.9
CVE-2026-61682 kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace 18.09.2026 9.9
CVE-2026-10747 IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing 21.09.2026 10
CVE-2026-84383 libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items 18.09.2026 9.8
CVE-2025-15399 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 21.09.2026 10
CVE-2025-53837 org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 18.09.2026 9.9
CVE-2026-93659 Concrete CMS Community Store before 2.7.8 Stored XSS 18.09.2026 9.3
CVE-2023-5778 Missing Length Check 18.09.2026 9.2
CVE-2026-93603 vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function 18.09.2026 10
CVE-2026-93605 vm2 NodeVM before 3.12.1 Remote Code Execution via child_process 18.09.2026 10
CVE-2026-93606 vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species 18.09.2026 10
CVE-2026-28197 Privilege Escalation via Argument Injection in NetBackup Flex OS Shell 18.09.2026 9.4
CVE-2026-28198 Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell 18.09.2026 9.4
CVE-2026-13639 18.09.2026 9.8
CVE-2026-13684 18.09.2026 9.8
CVE-2026-67100 HCL BigFix Service Management is affected by multiple security vulnerabilities. 18.09.2026 9.8
CVE-2026-67101 HCL BigFix Service Management is affected by multiple security vulnerabilities. 18.09.2026 9.3
CVE-2026-93467 HGiga|OAKlouds - Insecure Deserialization 18.09.2026 9.3
CVE-2026-62874 Azure Billing Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-69843 Microsoft Fabric Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-85878 Azure Database for PostgreSQL Elevation of Privilege Vulnerability 19.09.2026 9.9
CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability 18.09.2026 10
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability 18.09.2026 10
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability 21.09.2026 9.3
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability 19.09.2026 9
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability 19.09.2026 9.9
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability 19.09.2026 9.6
CVE-2026-54734 Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction 18.09.2026 10
CVE-2026-76949 Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement 18.09.2026 9.1
CVE-2026-54670 WeGIA: Unauthenticated Auth Bypass + Local File Inclusion 17.09.2026 9.1
CVE-2026-54767 WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php 18.09.2026 9.1
CVE-2026-93393 Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream 18.09.2026 9.2
CVE-2026-45140 Chamilo LMS CStudio upload flow allows unauthenticated remote code execution 18.09.2026 9.8
CVE-2026-45143 Chamilo LMS: Student-to-admin stored XSS in private messages via v-html 17.09.2026 9
CVE-2026-54237 Wavelog: Unauthenticated Remote Code Execution 18.09.2026 9.3
CVE-2026-54460 OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover 17.09.2026 9.8
CVE-2026-54501 Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors 17.09.2026 9.4
CVE-2026-54752 NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request 17.09.2026 9.6
CVE-2026-54618 Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user 17.09.2026 9.4
CVE-2026-54626 SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) 17.09.2026 9.8
CVE-2026-54627 SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) 18.09.2026 9.8
CVE-2026-92943 Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python 17.09.2026 9.2
CVE-2026-54617 GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler 18.09.2026 9.8
CVE-2026-47252 Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) 17.09.2026 9
CVE-2026-54053 Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults 17.09.2026 9.6
CVE-2026-90104 NFSv4.1: zero referring call lists before decoding 18.09.2026 9.8
CVE-2026-90110 inetpeer: randomize RB-tree node comparison using SipHash 18.09.2026 9.4
CVE-2026-90151 NFSv4: remove callback IDR entry on client allocation failure 18.09.2026 9.8
CVE-2026-90173 smb: smbdirect: free completion queues with ib_free_cq() 18.09.2026 9.8
CVE-2026-90230 nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() 18.09.2026 9.1
CVE-2026-90235 sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE 18.09.2026 9.8
CVE-2026-90413 IB/isert: reject login PDUs declaring more data than was received 18.09.2026 9.1
CVE-2026-90414 IB/isert: reject PDUs declaring more data than was received 18.09.2026 9.1
CVE-2026-92489 xfrm: Fix skb double-free in xfrm_dev_direct_output() 18.09.2026 9.8
CVE-2026-86863 pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode 17.09.2026 9.3
CVE-2026-76834 b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key 18.09.2026 9.2
CVE-2026-91039 dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover 17.09.2026 9.1
CVE-2026-79752 CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection 17.09.2026 9.2
CVE-2026-63472 Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification 17.09.2026 9.1
CVE-2026-88952 OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication 17.09.2026 9.1
CVE-2026-92934 vm2 before 3.11.8 Sandbox Escape RCE via AggregateError 17.09.2026 9.5
CVE-2026-92935 vm2 NodeVM Remote Code Execution via Array-Shaped Require 17.09.2026 9.5
CVE-2026-92937 vm2 3.11.6 Remote Code Execution via Promise call/apply 18.09.2026 10
CVE-2026-92938 vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite 19.09.2026 9.4
CVE-2026-92939 vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine 17.09.2026 9.4
CVE-2026-92940 vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent 17.09.2026 10
CVE-2026-92941 vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation 17.09.2026 10
CVE-2026-92944 vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector 19.09.2026 9.3
CVE-2026-92946 vm2 before 3.11.7 Remote Code Execution via require.external 17.09.2026 10
CVE-2026-92947 vm2 before 3.11.7 Memory Disclosure via Buffer Pool 17.09.2026 10
CVE-2026-92948 vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test 18.09.2026 9.4
CVE-2026-92950 vm2 before 3.11.7 Sandbox Escape via CLI require 17.09.2026 9.3
CVE-2026-92951 vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver 17.09.2026 9.4
CVE-2026-92953 vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray 18.09.2026 9.3
CVE-2026-92954 vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise 17.09.2026 9.2
CVE-2026-92955 vm2 before 3.11.8 Sandbox Escape via NodeVM 17.09.2026 10
CVE-2026-92956 vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming 17.09.2026 10
CVE-2026-92957 vm2 before 3.11.7 Authentication Bypass via node: Prefix 17.09.2026 9.4
CVE-2026-92960 vm2 before 3.11.6 Process-wide State Exposure via os and dns 17.09.2026 10
CVE-2026-62101 WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability 17.09.2026 9.8
CVE-2026-62104 WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability 19.09.2026 10
CVE-2026-62108 WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability 17.09.2026 9.8
CVE-2026-82761 Magic link single-use tokens replayable via TOCTOU race in AshAuthentication 17.09.2026 9.1
CVE-2026-85500 `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication 17.09.2026 9.1
CVE-2026-86533 Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix 17.09.2026 9.1
CVE-2026-90822 17.09.2026 9.8
CVE-2026-90823 17.09.2026 9.8
CVE-2026-92860 rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation 19.09.2026 9.4
CVE-2026-92913 AVideo Weak PRNG Activation Code Authentication Bypass 17.09.2026 9.1
CVE-2026-15688 Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting 17.09.2026 9.2
CVE-2026-87796 Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload 19.09.2026 9.8
CVE-2026-61594 djust has an authorization bypass on the WebSocket/SSE mount path 17.09.2026 9.1
CVE-2026-92576 HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool 17.09.2026 9.2
CVE-2026-92578 WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash 17.09.2026 9.2
CVE-2026-75513 Marten: SQL injection in Marten's LINQ provider via unescaped string literals 19.09.2026 9.1
CVE-2026-92749 SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret 17.09.2026 9.2
CVE-2026-92785 Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes 17.09.2026 9.2
CVE-2026-92787 Feast through 0.66.0 Authentication Bypass via Unverified Token 19.09.2026 9.3
CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard 19.09.2026 9.3
CVE-2026-20284 Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability 18.09.2026 9.1
CVE-2026-20332 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities 18.09.2026 9.9
CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-20130 Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities 18.09.2026 10
CVE-2026-20176 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20192 Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities 18.09.2026 10
CVE-2026-20194 Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities 18.09.2026 9.1
CVE-2026-20211 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20237 Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities 18.09.2026 9.1
CVE-2026-20242 Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability 18.09.2026 9.8
CVE-2026-20322 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control 18.09.2026 9.9
CVE-2026-20324 Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability 18.09.2026 9.9
CVE-2026-20325 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command 18.09.2026 9.9
CVE-2026-20326 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function 18.09.2026 9.8
CVE-2026-20329 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities 18.09.2026 9.9
CVE-2026-20330 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities 18.09.2026 9.9
CVE-2026-20341 Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability 18.09.2026 9.1
CVE-2026-76423 Cisco ISE API Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-92808 Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise 17.09.2026 10
CVE-2026-89083 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 17.09.2026 9.3
CVE-2026-89082 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 17.09.2026 9.3
CVE-2026-73456 Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. 17.09.2026 9.2
CVE-2026-91104 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-91106 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-92717 Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub 16.09.2026 9.3
CVE-2026-92720 Kubero through 3.1.1 Unauthenticated Notifications API Access 17.09.2026 9.3
CVE-2026-20234 Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities 17.09.2026 9.9
CVE-2026-20305 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20306 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.9
CVE-2026-20331 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities 18.09.2026 9.6
CVE-2026-76420 Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability 17.09.2026 9
CVE-2026-92398 Ruijie RG-EW3000GX user_list_note admin os command injection 16.09.2026 9.4
CVE-2026-92397 Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection 16.09.2026 9.4
CVE-2025-59953 LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy 18.09.2026 9.8
CVE-2026-70416 16.09.2026 10
CVE-2026-77411 RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr 16.09.2026 9.5
CVE-2026-77405 RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser 18.09.2026 9.4
CVE-2026-92395 @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 17.09.2026 9.1
CVE-2026-77408 RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow 16.09.2026 9.1
CVE-2026-91843 Stack overflow in login process to the Security Management and Log Servers 17.09.2026 9.8
CVE-2026-73172 17.09.2026 9.3
CVE-2026-40855 Command Injection in T-Mobile 5G Box IDU router via ping functionality 16.09.2026 9.3
CVE-2026-58146 Unauthorized remote code execution in T-Mobile 5G Box IDU routers 16.09.2026 9.4
CVE-2026-58147 Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers 16.09.2026 9.3
CVE-2026-89846 scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read 16.09.2026 9.1
CVE-2026-89847 scsi: qla2xxx: Avoid double completion in async IOCB timeout 16.09.2026 9.8
CVE-2026-89857 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject 16.09.2026 9.8
CVE-2026-89914 KVM: arm64: Sign-extend VA for range-based TLBI invalidation 16.09.2026 9.3
CVE-2026-89915 KVM: arm64: Remove VM-wide VNCR mapping counter 16.09.2026 9.3
CVE-2026-89916 KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry 16.09.2026 9.3
CVE-2026-89918 KVM: arm64: Correctly handle end of VA space TLBI invalidation 16.09.2026 9.3
CVE-2026-89930 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter 16.09.2026 9.3
CVE-2026-89969 nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU 16.09.2026 9.8
CVE-2026-89970 nvmet-auth: Synchronize timeout work during SQ teardown 16.09.2026 9.8
CVE-2026-89972 nvme: add missing SRCU grace period in error path 16.09.2026 9.8
CVE-2026-89990 ceph: lock mutex in ceph_mds_check_access() 16.09.2026 9.8
CVE-2026-90011 scsi: target: iscsi: Reserve a terminator byte for the login payload 16.09.2026 9.1
CVE-2026-90012 spi: Fix DMA mapping ownership on partial map failure 16.09.2026 9.8
CVE-2026-90036 NFSD: Prevent client use-after-free during blocked-lock reaping 21.09.2026 9.8
CVE-2026-90037 NFSD: Prevent client use-after-free during close_lru reaping 21.09.2026 9.8
CVE-2026-90038 NFSD: Prevent client use-after-free during export state revocation 16.09.2026 9.8
CVE-2026-90042 ceph: properly decrypt filenames in vmalloc() buffers 21.09.2026 9.8
CVE-2026-90048 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() 16.09.2026 9.8
CVE-2026-90049 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() 16.09.2026 9.3
CVE-2026-73453 Security Advisory 0174 17.09.2026 9.5
CVE-2026-89778 isofs: fix out-of-bounds page array access on empty zisofs block 16.09.2026 9.8
CVE-2026-89779 fs/ntfs3: validate ef->size covers the record's name and value 16.09.2026 9.1
CVE-2026-89783 xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full 16.09.2026 9.8
CVE-2026-89786 ext4: fix out-of-bounds read in ext4_read_inline_dir() 16.09.2026 9.1
CVE-2026-89788 ksmbd: fix tree connection use-after-free in smb2_tree_connect() 16.09.2026 9.8
CVE-2026-81642 Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY 16.09.2026 9.1
CVE-2026-89775 KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation 16.09.2026 9.3
CVE-2026-73461 Security Advisory 0163 17.09.2026 9.4
CVE-2026-27546 Authentication Bypass in _account_log 16.09.2026 9.8
CVE-2026-27565 Remote code execution via uploading a malicious IODD file 16.09.2026 9.8
CVE-2026-73447 Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request 17.09.2026 9.4
CVE-2026-12793 JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter 17.09.2026 9.8
CVE-2026-14349 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action 16.09.2026 9.8
CVE-2026-15638 Cryptographic Padding Oracle 16.09.2026 9.1
CVE-2026-15639 Reflected Cross-Site Scripting 16.09.2026 9.3
CVE-2026-15640 Authentication Bypass via SAML Response Manipulation 16.09.2026 9.5
CVE-2026-73807 mySCADA myPRO Manager Missing Authorization 16.09.2026 9.3
CVE-2026-78225 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.5
CVE-2026-81855 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.3
CVE-2026-61560 @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover 16.09.2026 9.8
CVE-2026-61559 @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery 17.09.2026 9.6
CVE-2026-61568 @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport 16.09.2026 9.6
CVE-2026-68491 16.09.2026 9.4
CVE-2026-91939 Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter 16.09.2026 9.3
CVE-2026-66887 Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-54337 Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite 16.09.2026 9.8
CVE-2026-66890 Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-70748 15.09.2026 9.8
CVE-2026-70756 15.09.2026 9.8
CVE-2026-70757 15.09.2026 9.8
CVE-2026-70913 15.09.2026 9.8
CVE-2026-71133 17.09.2026 10
CVE-2026-71163 16.09.2026 9.9
CVE-2026-73940 15.09.2026 9.8
CVE-2026-73944 15.09.2026 9.1
CVE-2026-73945 16.09.2026 9.9
CVE-2026-73946 16.09.2026 9.1
CVE-2026-73947 15.09.2026 9.8
CVE-2026-73948 16.09.2026 9.9
CVE-2026-73950 15.09.2026 9.8
CVE-2026-73952 15.09.2026 9.1
CVE-2026-73953 15.09.2026 9.8
CVE-2026-73956 15.09.2026 9.8
CVE-2026-73957 16.09.2026 9.3
CVE-2026-73961 15.09.2026 9.8
CVE-2026-73962 16.09.2026 9.6
CVE-2026-73963 15.09.2026 9.8
CVE-2026-82994 15.09.2026 9.8
CVE-2026-82995 15.09.2026 9.8
CVE-2026-82997 16.09.2026 9.9
CVE-2026-82998 16.09.2026 9.9
CVE-2026-82999 16.09.2026 9.9
CVE-2026-83000 15.09.2026 9.8
CVE-2026-83001 16.09.2026 9.1
CVE-2026-83006 16.09.2026 9.1
CVE-2026-83020 17.09.2026 10
CVE-2026-83021 17.09.2026 10
CVE-2026-83027 16.09.2026 9.3
CVE-2026-83029 16.09.2026 9.6
CVE-2026-83031 16.09.2026 9.9
CVE-2026-83035 15.09.2026 9.8
CVE-2026-83036 15.09.2026 9.8
CVE-2026-83037 15.09.2026 9.8
CVE-2026-83038 16.09.2026 9.9
CVE-2026-83039 16.09.2026 9.9
CVE-2026-83040 16.09.2026 9.6
CVE-2026-83042 15.09.2026 9.8
CVE-2026-83043 16.09.2026 9.6
CVE-2026-83054 15.09.2026 9.8
CVE-2026-83055 17.09.2026 9.9
CVE-2026-83056 17.09.2026 9.9
CVE-2026-83057 17.09.2026 9.9
CVE-2026-83058 17.09.2026 9.9
CVE-2026-83059 17.09.2026 10
CVE-2026-83060 15.09.2026 9.8
CVE-2026-83061 15.09.2026 9.8
CVE-2026-83062 15.09.2026 9.8
CVE-2026-83064 17.09.2026 9.1
CVE-2026-83066 15.09.2026 9.8
CVE-2026-83094 15.09.2026 9.8
CVE-2026-83095 15.09.2026 9.8
CVE-2026-83098 15.09.2026 9.8
CVE-2026-83099 15.09.2026 10
CVE-2026-83100 15.09.2026 9.8
CVE-2026-83103 17.09.2026 9.1
CVE-2026-83104 15.09.2026 9.1
CVE-2026-83105 17.09.2026 9
CVE-2026-83107 17.09.2026 9.1
CVE-2026-83108 15.09.2026 9.8
CVE-2026-83149 15.09.2026 9.1
CVE-2026-83151 15.09.2026 9.8
CVE-2026-83154 15.09.2026 9.1
CVE-2026-83196 17.09.2026 9.1
CVE-2026-83197 15.09.2026 9.1
CVE-2026-83201 15.09.2026 9.1
CVE-2026-83202 15.09.2026 9.1
CVE-2026-83229 17.09.2026 9.1
CVE-2026-83232 15.09.2026 9.8
CVE-2026-83260 17.09.2026 9.1
CVE-2026-83261 15.09.2026 9.8
CVE-2026-83268 17.09.2026 9.1
CVE-2026-83269 15.09.2026 9.8
CVE-2026-83282 17.09.2026 9.9
CVE-2026-83283 15.09.2026 9.8
CVE-2026-83327 15.09.2026 9.8
CVE-2026-83339 15.09.2026 9.8
CVE-2026-83355 15.09.2026 9.8
CVE-2026-83452 15.09.2026 9.8
CVE-2026-83462 15.09.2026 9.8
CVE-2026-87128 15.09.2026 9.1
CVE-2026-87129 15.09.2026 9.1
CVE-2026-87170 15.09.2026 9.1
CVE-2026-87172 17.09.2026 9.9
CVE-2026-87173 15.09.2026 9.1
CVE-2026-87175 15.09.2026 9.1
CVE-2026-87176 15.09.2026 9.1
CVE-2026-87184 15.09.2026 9.8
CVE-2026-87186 17.09.2026 9.6
CVE-2026-87188 15.09.2026 9.8
CVE-2026-87189 17.09.2026 9.1
CVE-2026-87214 17.09.2026 9.1
CVE-2026-87217 15.09.2026 9.1
CVE-2026-87223 18.09.2026 9.1
CVE-2026-87230 18.09.2026 10
CVE-2026-89040 Tencent Mass Service Engine in Cluster (MSEC) path traversal 15.09.2026 9.3
CVE-2026-73458 On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou 15.09.2026 9.2
CVE-2026-76669 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76670 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76672 Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator 20.09.2026 9.9
CVE-2026-76673 Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator 15.09.2026 9.8
CVE-2026-76674 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways 15.09.2026 9.8
CVE-2026-76675 Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways 15.09.2026 9.1
CVE-2026-69204 Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) 15.09.2026 9.2
CVE-2026-19773 libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability 16.09.2026 9.8
CVE-2026-45579 DIRAC: RCE in RequestManager due to eval on untrusted input 15.09.2026 9.9
CVE-2026-53459 Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints 17.09.2026 9.3
CVE-2026-61667 DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval 15.09.2026 9.9
CVE-2026-12351 IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection 16.09.2026 9.8
CVE-2023-54398 Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet 15.09.2026 9.3
CVE-2024-58385 Yonyou U8 CRM SQL Injection via fillbacksettingedit.php 15.09.2026 9.3
CVE-2026-46488 motionEye: Authentication possible via password hash 17.09.2026 9.1
CVE-2026-53710 MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server 15.09.2026 10
CVE-2026-89026 Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate 17.09.2026 9.3
CVE-2026-89022 BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion 15.09.2026 9.1
CVE-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts 15.09.2026 9
CVE-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding 15.09.2026 9
CVE-2026-55211 surfio IRAP header size fields cause out-of-bounds reads 17.09.2026 9.8
CVE-2023-54397 Tornado before 6.3.3 HTTP Request Smuggling via Content-Length 17.09.2026 9
CVE-2024-14029 Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding 15.09.2026 9
CVE-2026-91931 Flowise before 3.1.4 Remote Code Execution via Custom MCP npx 17.09.2026 9
CVE-2026-91932 Flowise before 3.1.4 Remote Code Execution via cwd Parameter 15.09.2026 9
CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass 17.09.2026 9.2
CVE-2026-91988 atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP 15.09.2026 9.2
CVE-2026-61549 Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend 16.09.2026 9
CVE-2026-63696 16.09.2026 9.1
CVE-2026-55158 Conflibot: Command injection via crafted pull request branch names under pull_request_target 17.09.2026 9.1
CVE-2026-63695 16.09.2026 9.8
CVE-2026-39919 Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter 20.09.2026 9.3
CVE-2026-46495 OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI 15.09.2026 9.2
CVE-2026-59971 MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) 15.09.2026 10
CVE-2026-77179 Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback 15.09.2026 9.4
CVE-2026-89308 Arbitrary command execution in TrxTimeATTENDANCE 15.09.2026 9.3
CVE-2026-91995 pig before 4.1.0 Unverified Password Change via /register/password 18.09.2026 9.3
CVE-2026-91998 Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp 17.09.2026 9.4
CVE-2026-52824 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover 16.09.2026 9.1
CVE-2026-57147 praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery 17.09.2026 9.8
CVE-2026-57139 PraisonAI MCPServer exposes unauthenticated HTTP tools/call 17.09.2026 9.8
CVE-2026-57140 PraisonAI AgentOS exposes unauthenticated agent listing and invocation 15.09.2026 9.4
CVE-2026-57148 praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) 16.09.2026 9.8
CVE-2026-57138 PraisonAI codeMode sandbox escape via Function constructor 17.09.2026 9.9
CVE-2026-57141 PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool 15.09.2026 9.8
CVE-2026-48717 OpenAM OAuth Authorization Bypass via PKCE Challenge 15.09.2026 9.1
CVE-2026-45051 OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage 15.09.2026 9.2
CVE-2026-46619 OpenAM Authentication Bypass via MSISDN LDAP Injection 15.09.2026 9.3
CVE-2026-62263 OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass 15.09.2026 9.2
CVE-2026-45052 OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints 16.09.2026 9.3
CVE-2026-62379 OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback 15.09.2026 9.8
CVE-2026-90711 proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 15.09.2026 9.1
CVE-2026-91003 D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow 15.09.2026 9.4
CVE-2026-91001 D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow 15.09.2026 9.4
CVE-2026-90847 EFM ipTIME C200E System Setup iux_set.cgi os command injection 15.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-55563 Feast: `pull_request_target` integration tests run untrusted fork code with production cloud secrets; the `ok-to-test` label guard is bypassable via label persistence on `synchronize` 21.09.2026
CVE-2026-88978 Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter 21.09.2026 4.3
CVE-2026-61681 Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler 21.09.2026 4.1
CVE-2026-61687 hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState 21.09.2026 7.1
CVE-2026-63342 Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check 21.09.2026 6.3
CVE-2026-84298 Hatchet: Cross-tenant durable callback payload disclosure in Hatchet V1 Dispatcher 21.09.2026 3.1
CVE-2026-53940 Conda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementation 21.09.2026 8.8
CVE-2026-85751 Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust 21.09.2026 9.8
CVE-2026-36467 21.09.2026
CVE-2026-36468 21.09.2026
CVE-2026-36469 21.09.2026
CVE-2026-36470 21.09.2026
CVE-2026-36471 21.09.2026
CVE-2026-36472 21.09.2026
CVE-2026-77165 21.09.2026
CVE-2026-77166 21.09.2026
CVE-2026-52740 GoCD is vulnerable to pipeline template view API authorization bypass 21.09.2026
CVE-2026-52742 GoCD is vulnerable to historical server configuration API authorization bypass 21.09.2026
CVE-2026-55625 GoCD is vulnerable to authorization bypass via material connection test APIs 21.09.2026 4.9
CVE-2026-55870 GoCD is vulnerable to credential exposure when admins insecurely configure material URLs 21.09.2026
CVE-2026-71543 OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters 21.09.2026
CVE-2026-52741 GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages 21.09.2026
CVE-2026-55060 GoCD is vulnerable to authorization bypass via support process list API 21.09.2026 3.7
CVE-2026-68919 GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages 21.09.2026
CVE-2026-61628 nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition 21.09.2026 8.1
CVE-2026-94301 Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 21.09.2026 9.8
CVE-2026-52743 GoCD before 26.1.0 is vulnerable to authorization bypass via job status API 21.09.2026 4.3
CVE-2026-55074 Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) 21.09.2026
CVE-2026-75158 Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter 21.09.2026
CVE-2026-82355 Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation 21.09.2026
CVE-2026-86473 Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry 21.09.2026
CVE-2026-93339 Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute 21.09.2026
CVE-2026-54584 mport trusts environment-controlled temporary directories in privileged metadata extraction 21.09.2026
CVE-2026-55071 MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` 21.09.2026 8.4
CVE-2026-55567 BleachBit: Exploit File Delete to Escalate Privilege 21.09.2026 7.8
CVE-2026-61629 nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware 21.09.2026 7.5
CVE-2026-61630 nginx ignition has TOTP Reuse During Validity Window 21.09.2026 4.2
CVE-2026-75939 Openshift/oc-mirror: release signature verification: openpgp signatureerror checked before signed body is consumed 21.09.2026
CVE-2026-80110 Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpoint 21.09.2026
CVE-2026-94184 Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01) 21.09.2026
CVE-2026-88807 libXrender RenderQueryPictFormats Reply Heap-based Buffer Overflow 21.09.2026
CVE-2026-94404 MISP CSRF vulnerability allows unauthorized attribute modification 21.09.2026
CVE-2025-71419 UVdesk core-framework before 1.1.7 Stored XSS via SwiftMailer 21.09.2026
CVE-2025-71420 UVdesk core-framework before 1.1.7 Authorization Bypass via Saved Reply 21.09.2026
CVE-2025-71421 UVdesk core-framework before 1.1.7 Privilege Escalation via editAgent 21.09.2026
CVE-2026-94387 Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log 21.09.2026
CVE-2026-88806 libX11 XkbGetMap Reply Heap-based Buffer Overflow 21.09.2026 7.5
CVE-2026-94401 MISP Arbitrary Local File Read and SSRF via MISP Export Upload 21.09.2026
CVE-2026-93884 21.09.2026
CVE-2026-94394 MISP ObjectReferencesController: Granular Distribution and Sharing Group Restrictions Bypassed When Adding Object References 21.09.2026
CVE-2026-85220 Denial-of-Service in the Thinkst Canary Redis service 21.09.2026 3.7
CVE-2026-94382 Beszel before 0.19.0 Insecure Direct Object Reference via user-alerts 21.09.2026
CVE-2026-94393 MISP Event Report Cross-Event Reparenting via Unscoped UUID Resolution in editReport 21.09.2026
CVE-2026-94216 ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Header webserver authorize redirect 21.09.2026
CVE-2026-94381 MISP Privilege Escalation: Read-Only API Key User Can Regain Full Role via updateLoginTime 21.09.2026
CVE-2026-94383 MISP Blocklist Workflow Module: Arbitrary Script Execution via Unrestricted File Extension 21.09.2026
CVE-2026-94374 MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparenting and Overwriting of Other Events' Reports 21.09.2026
CVE-2026-94379 MISP: HTTP Method Bypass of Login Security Controls (Bruteforce Protection and Email OTP) 21.09.2026
CVE-2026-84285 OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 21.09.2026 8.8
CVE-2026-94211 Hyve5 Leantime Project Dashboard show.blade.php cross site scripting 21.09.2026
CVE-2026-94214 ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect 21.09.2026
CVE-2026-94372 Stored Cross-Site Scripting via Unescaped Galaxy Cluster Tag Names in MISP Default Theme Galaxies Index 21.09.2026
CVE-2026-94373 MISP DOM-based Cross-Site Scripting via innerHTML in Contextual Menu 21.09.2026
CVE-2026-94368 Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-copy-source header 21.09.2026
CVE-2026-16651 temporalio/sqlparser malformed MySQL version comments can cause a panic 21.09.2026
CVE-2026-65651 temporalio/sqlparser deeply nested unary expressions can cause a fatal stack overflow during AST traversal 21.09.2026
CVE-2026-65652 temporalio/tchannel-go malformed checksum type causes process termination 21.09.2026
CVE-2026-65653 temporalio/tchannel-go zero-chunk call fragment causes process termination 21.09.2026
CVE-2026-65654 temporalio/ringpop-go fails to enforce configured label limits on inbound membership gossip 21.09.2026
CVE-2026-87858 Temporal Server completion callback source header can direct attacker-chosen requests to the internal frontend with administrator authorization 21.09.2026
CVE-2026-89139 Temporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service host 21.09.2026
CVE-2026-16652 Temporal Server Schedule exclusion search can cause excessive CPU consumption 21.09.2026
CVE-2026-91863 Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of service 21.09.2026
CVE-2026-91864 Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion 21.09.2026
CVE-2026-91865 Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to denial of service 21.09.2026
CVE-2026-91866 Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service 21.09.2026
CVE-2026-91867 Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request indefinitely 21.09.2026
CVE-2026-94210 Hyve5 Leantime Kanban Board Tickets.php getAllGrouped cross site scripting 21.09.2026
CVE-2026-77021 Missing decompression size limit in agent receiver allows memory exhaustion via push agent data 21.09.2026
CVE-2026-92612 21.09.2026
CVE-2026-92574 Cri-o: cri-o checkpoint restore bypasses destination security context 21.09.2026
CVE-2026-91921 Cross-Site Scripting (XSS) in 1millionbot’s AI chatbot platform 21.09.2026
CVE-2026-94277 Stored Cross-Site Scripting in MISP Galaxy Matrix Statistics via Unescaped Galaxy Name 21.09.2026
CVE-2025-12999 21.09.2026
CVE-2026-85010 RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons 21.09.2026 5.3
CVE-2026-85113 GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name 21.09.2026 6.5
CVE-2026-86802 To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import 21.09.2026 3.7
CVE-2026-92400 Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion 21.09.2026 5.3
CVE-2026-94152 Omega Solution FBP Fulfillment by People User Profile API user authorization 21.09.2026
CVE-2026-15801 Cri-o: cri-o: insufficient validation during container checkpoint restore 21.09.2026
CVE-2026-94150 Omega Solution HRM OS SVG File Upload view cross site scripting 21.09.2026
CVE-2026-94151 Omega Solution HRM OS Role Permission API permission missing authentication 21.09.2026
CVE-2026-47321 Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate 21.09.2026 7.5
CVE-2026-94149 Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection 21.09.2026
CVE-2026-94148 ScadaBR Export Project Endpoint export_project.htm EmportDwr.createExportJSON information disclosure 21.09.2026
CVE-2026-90860 21.09.2026 7.1
CVE-2026-94144 drogonframework drogon ORM Criteria.cc makeCriteria sql injection 21.09.2026
CVE-2026-94145 xuxueli xxl-job Task Management JobInfoController.java cross site scripting 21.09.2026
CVE-2026-94146 BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where 21.09.2026
CVE-2026-94217 Keycloak-services: keycloak-services: uma scope merge across resource owners via resource name collision 21.09.2026
CVE-2026-94218 Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication session restart endpoint 21.09.2026
CVE-2026-82187 WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Upload 21.09.2026
CVE-2026-94213 Keycloak-services: keycloak-services: authorization services policy evaluation endpoint leaks user identity 21.09.2026
CVE-2026-94215 Keycloak-services: keycloak-services: cross-realm client read/write via request-level cache missing realm ownership check 21.09.2026
CVE-2026-94143 drogonframework drogon ORM Mapper Mapper.h orderBy sql injection 21.09.2026
CVE-2026-90839 21.09.2026
CVE-2026-94142 BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where 21.09.2026
CVE-2026-94139 Chengdu Feiyuxing Technology Feiyu Star Router Cookie send_order.cgi command injection 21.09.2026
CVE-2026-94138 Chengdu Feiyuxing Technology Feiyu Star Router send_order.cgi command injection 21.09.2026
CVE-2026-94137 Hangzhou Shunwang Technology shzh IRP_MJ_DEVICE_CONTROL shdrv_x64.sys sub_180004AC0 denial of service 21.09.2026
CVE-2026-94185 nvm alias resolution follows `..` and discloses files outside $NVM_DIR/alias 21.09.2026 5.5
CVE-2026-94128 BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where 21.09.2026
CVE-2026-94129 BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where 21.09.2026
CVE-2026-94110 QCMS Content Detail Controllers.php self_Tmp sql injection 21.09.2026
CVE-2026-94101 Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow 21.09.2026
CVE-2026-94102 WuzhiCMS Login index.php redirect 21.09.2026
CVE-2026-94103 RooCMS Frontend Rendering site_pagePHP.php eval code injection 21.09.2026
CVE-2026-94098 Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection 21.09.2026
CVE-2026-94099 Netcore NBR200V2 Backup Restore restore.cgi command injection 21.09.2026
CVE-2026-94100 Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow 21.09.2026
CVE-2026-94097 Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection 20.09.2026
CVE-2026-94096 Netcore NBR200V2 LAN IP Configuration network_tools command injection 21.09.2026
CVE-2026-94095 Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection 20.09.2026