| CVE-2026-61534 |
Yayson: Prototype pollution in the Store/LegacyStore deserialization |
14.09.2026 |
9.1 |
| CVE-2026-90943 |
parallax filament-comments through 3.0.0 Stored XSS via Comment Body |
14.09.2026 |
9.3 |
| CVE-2026-57124 |
PraisonAI UI MCP connect endpoint allows unauthenticated local command execution |
14.09.2026 |
9.8 |
| CVE-2026-57127 |
praisonai: recipe serve auth middleware silently disables itself when no secret is set |
14.09.2026 |
9.8 |
| CVE-2026-57131 |
praisonai: Jobs API exposes agent-execution endpoints with no authentication |
14.09.2026 |
9.8 |
| CVE-2026-57145 |
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation |
14.09.2026 |
9.1 |
| CVE-2026-57123 |
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in |
14.09.2026 |
9.8 |
| CVE-2026-57125 |
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass |
14.09.2026 |
9.8 |
| CVE-2026-82434 |
Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs |
14.09.2026 |
10 |
| CVE-2026-90961 |
MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials |
14.09.2026 |
9.3 |
| CVE-2026-90937 |
froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL |
14.09.2026 |
9.4 |
| CVE-2026-12258 |
Inadequate access control in the Hiperdino REST API |
14.09.2026 |
9.2 |
| CVE-2026-90919 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization |
14.09.2026 |
9.3 |
| CVE-2026-21391 |
Improper Claim Validation in PingAM OIDC Provider |
14.09.2026 |
9.5 |
| CVE-2026-90898 |
Bifrost unauthenticated remote code execution via MCP stdio client registration |
14.09.2026 |
9.8 |
| CVE-2026-90703 |
D-Link DWR-M921 formDiskCreateShare system os command injection |
14.09.2026 |
9.4 |
| CVE-2026-90702 |
D-Link DWR-M921 formDiskFormat system os command injection |
14.09.2026 |
9.4 |
| CVE-2026-90699 |
D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection |
14.09.2026 |
9.4 |
| CVE-2026-90693 |
D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow |
14.09.2026 |
9.4 |
| CVE-2026-90692 |
D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow |
14.09.2026 |
9.4 |
| CVE-2026-85192 |
Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 |
14.09.2026 |
9.4 |
| CVE-2026-90680 |
D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow |
14.09.2026 |
9.4 |
| CVE-2026-90607 |
Totolink A3002MU boa formNewSchedule buffer overflow |
14.09.2026 |
9.4 |
| CVE-2026-90608 |
Totolink A3002MU boa formPortFw buffer overflow |
14.09.2026 |
9.4 |
| CVE-2026-90606 |
Totolink A3002MU boa formIpv6Setup buffer overflow |
13.09.2026 |
9.4 |
| CVE-2026-90605 |
Totolink A3002MU boa formFilter buffer overflow |
13.09.2026 |
9.4 |
| CVE-2026-81648 |
CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router |
14.09.2026 |
10 |
| CVE-2026-90561 |
Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG |
13.09.2026 |
9.3 |
| CVE-2026-90562 |
LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key |
13.09.2026 |
9.2 |
| CVE-2026-90493 |
Tonec Internet Download Manager Kernel Driver idmwfp.sys access control |
13.09.2026 |
9.3 |
| CVE-2026-90647 |
|
12.09.2026 |
9.1 |
| CVE-2026-90558 |
sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers |
12.09.2026 |
9.3 |
| CVE-2026-78006 |
The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution |
12.09.2026 |
9.8 |
| CVE-2026-78159 |
The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation |
12.09.2026 |
9.8 |
| CVE-2026-85706 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab |
12.09.2026 |
10 |
| CVE-2026-87719 |
Deserialization of Untrusted Data in GitLab |
14.09.2026 |
9.9 |
| CVE-2026-90456 |
|
14.09.2026 |
9.2 |
| CVE-2026-89697 |
nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() |
14.09.2026 |
9.1 |
| CVE-2026-89702 |
nfsd: size fh_verify server sockaddr slot by xpt_locallen |
13.09.2026 |
9.8 |
| CVE-2026-89703 |
nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations |
13.09.2026 |
9.8 |
| CVE-2026-89708 |
nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown |
13.09.2026 |
9.8 |
| CVE-2026-89712 |
NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock |
14.09.2026 |
9.8 |
| CVE-2026-89713 |
NFSD: check truncate permission under inode lock |
13.09.2026 |
9.1 |
| CVE-2026-80945 |
crypto: iaa - unmap dst before software fallback on decompress |
13.09.2026 |
9.1 |
| CVE-2026-80976 |
seg6: reset IP6CB after IPv6 decapsulation |
14.09.2026 |
9.8 |
| CVE-2026-80980 |
net/smc: stop killed, freed and out_of_sync sharing a byte |
13.09.2026 |
9.8 |
| CVE-2026-80981 |
net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() |
13.09.2026 |
9.8 |
| CVE-2026-80986 |
net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages |
13.09.2026 |
9.8 |
| CVE-2026-81002 |
xdp: fix zero-copy frame layout |
14.09.2026 |
9.8 |
| CVE-2026-89448 |
iommu/vt-d: Force requesting ACS when tboot is enabled |
14.09.2026 |
9.3 |
| CVE-2026-89478 |
sctp: drop a chunk if its transport was removed |
14.09.2026 |
9.8 |
| CVE-2026-89479 |
sctp: stop processing a packet once its association is deleted |
14.09.2026 |
9.8 |
| CVE-2026-89482 |
nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone |
14.09.2026 |
9.8 |
| CVE-2026-89485 |
lockd: pin next file across nlm_inspect_file lock-drop |
14.09.2026 |
9.8 |
| CVE-2026-89492 |
ocfs2: validate directory-index entry counts when reading metadata |
13.09.2026 |
9.8 |
| CVE-2026-89494 |
ocfs2: validate lengths in dlm_mig_lockres_handler |
14.09.2026 |
9.8 |
| CVE-2026-89495 |
ocfs2: bound namelen in dlm_migrate_request_handler |
14.09.2026 |
9.8 |
| CVE-2026-89526 |
svcrdma: Validate Read chunk positions before reconstruction |
13.09.2026 |
9.8 |
| CVE-2026-89530 |
svcrdma: Reject inline replies that overflow the pull-up buffer |
13.09.2026 |
9.8 |
| CVE-2026-89532 |
svcrdma: Fix pcl_for_each_segment for empty chunks |
14.09.2026 |
9.1 |
| CVE-2026-89533 |
svcrdma: Fix offset arithmetic in read_chunk_range |
14.09.2026 |
9.8 |
| CVE-2026-89536 |
SUNRPC: wait for in-flight client TLS handshake callback |
14.09.2026 |
9.8 |
| CVE-2026-89537 |
SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 |
13.09.2026 |
9.1 |
| CVE-2026-89538 |
SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field |
14.09.2026 |
9.8 |
| CVE-2026-89541 |
SUNRPC: harden gss_unwrap_resp_priv length checks |
14.09.2026 |
9.8 |
| CVE-2026-89542 |
SUNRPC: harden gss_krb5_unwrap_v2 against short tokens |
14.09.2026 |
9.8 |
| CVE-2026-89546 |
SUNRPC: close backchannel before destroying callback service |
13.09.2026 |
9.8 |
| CVE-2026-89550 |
SUNRPC: svcauth_gss: enforce krb5 token minimum length |
14.09.2026 |
9.8 |
| CVE-2026-89551 |
SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow |
14.09.2026 |
9.8 |
| CVE-2026-89555 |
mpls: reload header after pskb_may_pull() |
14.09.2026 |
9.8 |
| CVE-2026-89558 |
md/raid10: fix still_degraded being inverted in raid10_sync_request() |
13.09.2026 |
9.8 |
| CVE-2026-89610 |
ntfs: verify run length exceeding volume boundary |
13.09.2026 |
9.8 |
| CVE-2026-89611 |
ntfs: validate non-resident attribute offsets |
13.09.2026 |
9.8 |
| CVE-2026-89612 |
ntfs: reject invalid MFT LCNs from boot sector |
13.09.2026 |
9.8 |
| CVE-2026-89613 |
ntfs: reject invalid empty mapping pairs |
13.09.2026 |
9.8 |
| CVE-2026-89614 |
ntfs: bound the free-cluster bitmap scan to the volume |
13.09.2026 |
9.8 |
| CVE-2026-89630 |
smb: client: restore the data_offset bound in is_valid_oplock_break() |
13.09.2026 |
9.1 |
| CVE-2026-89631 |
smb: client: reject a tree connect response whose byte count is too small |
13.09.2026 |
9.1 |
| CVE-2026-89633 |
smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() |
13.09.2026 |
9.8 |
| CVE-2026-89634 |
smb: client: fix ALIGN() overflow in symlink_data() error context loop |
14.09.2026 |
9.1 |
| CVE-2026-89635 |
ksmbd: only rebind the reopened file's own oplock on durable reconnect |
13.09.2026 |
9.8 |
| CVE-2026-89636 |
smb: client: clear ce->tgthint in free_tgts() |
14.09.2026 |
9.8 |
| CVE-2026-89637 |
smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 |
13.09.2026 |
9.8 |
| CVE-2026-89643 |
audit: avoid dropping live tree ref on fsnotify rule autoremove |
14.09.2026 |
9.8 |
| CVE-2026-89649 |
ceph: bound xattr value length in __build_xattrs() |
14.09.2026 |
9.1 |
| CVE-2026-89650 |
ceph: bound num_export_targets array for mds info v2/v3 |
14.09.2026 |
9.1 |
| CVE-2026-89651 |
ceph: bound MDSCapAuth path and fs_name decode in handle_session() |
13.09.2026 |
9.8 |
| CVE-2026-89652 |
ceph: bound copied dentry name length in NFS export get_name |
14.09.2026 |
9.8 |
| CVE-2026-89653 |
ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode |
14.09.2026 |
9.8 |
| CVE-2026-89654 |
ceph: fix UAF in check_new_map() on session freed during unlock |
13.09.2026 |
9.8 |
| CVE-2026-89655 |
ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock |
14.09.2026 |
9.8 |
| CVE-2026-89656 |
libceph: reject buckets with mismatched CRUSH ids |
14.09.2026 |
9.8 |
| CVE-2026-89658 |
NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup |
13.09.2026 |
9.8 |
| CVE-2026-89659 |
NFSD: Prevent client use-after-free during delegation revoke |
13.09.2026 |
9.8 |
| CVE-2026-89660 |
NFSD: Prevent client use-after-free during admin state revocation |
13.09.2026 |
9.8 |
| CVE-2026-89662 |
NFSD: Prevent lock owner use-after-free during client teardown |
14.09.2026 |
9.8 |
| CVE-2026-89669 |
nfsd: initialize copy-notify stateid before publishing it |
14.09.2026 |
9.8 |
| CVE-2026-89671 |
nfsd: gate nfs3 setacl by argp->mask |
14.09.2026 |
9.1 |
| CVE-2026-89672 |
nfsd: gate nfs2 setacl by argp->mask |
14.09.2026 |
9.1 |
| CVE-2026-89674 |
nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget |
14.09.2026 |
9.8 |
| CVE-2026-89675 |
nfsd: fix UAF in async copy cancel and shutdown |
13.09.2026 |
9.8 |
| CVE-2026-89676 |
nfsd: fix stale s2s_cp_stateids IDR entry for async COPY |
13.09.2026 |
9.8 |
| CVE-2026-89677 |
nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() |
13.09.2026 |
9.8 |
| CVE-2026-89681 |
nfsd: fix layout fence worker double-reference race |
13.09.2026 |
9.8 |
| CVE-2026-89686 |
nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke |
13.09.2026 |
9.8 |
| CVE-2026-89688 |
nfsd: drop the stateid, not the stateowner, on seqid_op replay retry |
13.09.2026 |
9.8 |
| CVE-2026-89689 |
nfsd: don't free session slots that are still in use |
13.09.2026 |
9.8 |
| CVE-2026-80926 |
ksmbd: fix use-after-free in oplock break notification |
13.09.2026 |
9.8 |
| CVE-2026-53952 |
GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw |
11.09.2026 |
9.8 |
| CVE-2026-54072 |
Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL |
11.09.2026 |
9.3 |
| CVE-2026-62103 |
WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-62105 |
WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-82617 |
Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns |
11.09.2026 |
10 |
| CVE-2026-72709 |
SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur |
11.09.2026 |
9.3 |
| CVE-2026-72710 |
SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection |
11.09.2026 |
9.3 |
| CVE-2026-54047 |
Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation |
11.09.2026 |
9.2 |
| CVE-2026-3869 |
|
11.09.2026 |
9.2 |
| CVE-2026-89010 |
WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server |
11.09.2026 |
9.3 |
| CVE-2026-38056 |
ST Engineering iDirect iQ-Series Terminals Missing Authorization |
11.09.2026 |
9.4 |
| CVE-2026-87987 |
|
11.09.2026 |
10 |
| CVE-2026-87988 |
|
11.09.2026 |
10 |
| CVE-2026-87983 |
|
11.09.2026 |
9.2 |
| CVE-2026-87984 |
|
11.09.2026 |
9.3 |
| CVE-2026-87985 |
|
11.09.2026 |
10 |
| CVE-2026-87986 |
|
11.09.2026 |
10 |
| CVE-2026-89212 |
XML External Entity in Akana API Platform |
11.09.2026 |
9.2 |
| CVE-2026-80462 |
Privilege Escalation in Progress Chef Automate |
11.09.2026 |
10 |
| CVE-2026-84390 |
|
11.09.2026 |
9.6 |
| CVE-2026-89243 |
WWBN AVideo Stored XSS via UserGroups setGroup_name |
11.09.2026 |
9.2 |
| CVE-2026-89249 |
AVideo YPTWallet Stored XSS via CryptoWallet Configuration |
11.09.2026 |
9.3 |
| CVE-2026-89253 |
AVideo Stored XSS via donationLink in watch page button |
11.09.2026 |
9.3 |
| CVE-2026-89254 |
AVideo CustomizeUser Stored XSS via field_name Parameter |
11.09.2026 |
9.3 |
| CVE-2026-89255 |
AVideo LoginControl Stored XSS via PGP Public Key |
11.09.2026 |
9.3 |
| CVE-2026-89256 |
AVideo Bookmark Plugin Stored XSS via Chapter Names |
11.09.2026 |
9.3 |
| CVE-2026-89258 |
Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get |
11.09.2026 |
9.3 |
| CVE-2026-89259 |
Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS |
11.09.2026 |
9.3 |
| CVE-2026-47839 |
Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin |
11.09.2026 |
9.2 |
| CVE-2026-8778 |
MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload |
11.09.2026 |
9.8 |
| CVE-2026-19646 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
11.09.2026 |
9.1 |
| CVE-2026-78573 |
IBM ContextForge MCP Gateway is affected by use of default credentials |
11.09.2026 |
9.8 |
| CVE-2026-79724 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
12.09.2026 |
9.8 |
| CVE-2026-80424 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
9.1 |
| CVE-2026-81204 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
12.09.2026 |
9.8 |
| CVE-2026-82100 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
11.09.2026 |
9.6 |
| CVE-2026-82107 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
11.09.2026 |
9.6 |
| CVE-2026-45764 |
Suricata http2: protocol-change type confusion can lead to denial of service |
11.09.2026 |
9.1 |
| CVE-2026-75940 |
|
11.09.2026 |
9.3 |
| CVE-2026-85025 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
12.09.2026 |
9.8 |
| CVE-2026-89094 |
|
14.09.2026 |
9.9 |
| CVE-2026-89086 |
|
10.09.2026 |
9.1 |
| CVE-2026-88062 |
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) |
11.09.2026 |
9.5 |
| CVE-2026-89042 |
passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification |
11.09.2026 |
9.3 |
| CVE-2026-89043 |
passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending |
10.09.2026 |
9.1 |
| CVE-2026-65638 |
|
10.09.2026 |
9.2 |
| CVE-2026-65639 |
|
10.09.2026 |
9.5 |
| CVE-2026-68487 |
|
10.09.2026 |
9.9 |
| CVE-2026-68488 |
|
10.09.2026 |
9.9 |
| CVE-2026-88044 |
rclone: RC per-server auth-proxy bypass |
10.09.2026 |
9.1 |
| CVE-2026-88018 |
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass |
10.09.2026 |
9.8 |
| CVE-2026-81046 |
|
11.09.2026 |
9.4 |
| CVE-2026-81467 |
|
11.09.2026 |
9.8 |
| CVE-2026-81468 |
|
11.09.2026 |
9.1 |
| CVE-2026-81048 |
|
11.09.2026 |
9.6 |
| CVE-2026-88899 |
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header |
11.09.2026 |
9.3 |
| CVE-2026-88007 |
Traefik HTTP/3 Backend NTLM Connection Reuse |
10.09.2026 |
9.1 |
| CVE-2026-81800 |
WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability |
11.09.2026 |
9.3 |
| CVE-2026-88860 |
Capgo Authorization Bypass via Stale Channel Permission Overrides |
10.09.2026 |
9.3 |
| CVE-2026-88864 |
Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
10.09.2026 |
9.3 |
| CVE-2026-88866 |
WWBN AVideo LoginControl Stored XSS via User-Agent Header |
10.09.2026 |
9.3 |
| CVE-2026-88867 |
WWBN AVideo Stored XSS via Category Name and Icon Class |
10.09.2026 |
9.3 |
| CVE-2026-88868 |
AVideo LiveLinks Stored XSS via title and description fields |
10.09.2026 |
9.3 |
| CVE-2026-88869 |
AVideo AD_Server Stored XSS via log.php label parameter |
10.09.2026 |
9.3 |
| CVE-2026-88877 |
Traefik v3.7.0 Authentication Bypass via from-to-www-redirect |
10.09.2026 |
9.3 |
| CVE-2026-88880 |
Renovate before 44.11.3 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-88881 |
Renovate before 44.11.3 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-88882 |
Renovate before 44.11.2 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-88887 |
Renovate before 44.11.2 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-9163 |
SQLi in GIS Informatics' GisLab Laboratory Management System |
10.09.2026 |
9.8 |
| CVE-2026-78082 |
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 |
11.09.2026 |
9.3 |
| CVE-2026-8323 |
Open Redirect in Armiya Information Technologies' Access Control System |
10.09.2026 |
9.3 |
| CVE-2026-13745 |
Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables |
10.09.2026 |
9.2 |
| CVE-2026-44950 |
fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 |
10.09.2026 |
9.5 |
| CVE-2026-59679 |
fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 |
10.09.2026 |
9.2 |
| CVE-2026-88278 |
GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay |
10.09.2026 |
9.8 |
| CVE-2026-88285 |
GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service |
10.09.2026 |
9.4 |
| CVE-2026-7188 |
SQLi in Armiya Information Technologies' Access Control System |
10.09.2026 |
9.8 |
| CVE-2026-19583 |
Velociraptor Required Permissions bypass by using client monitoring queries |
11.09.2026 |
9.9 |
| CVE-2026-18351 |
Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter |
10.09.2026 |
9.8 |
| CVE-2026-87931 |
Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow |
10.09.2026 |
9.4 |
| CVE-2026-88069 |
Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis |
10.09.2026 |
9.3 |
| CVE-2026-87911 |
Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server |
10.09.2026 |
9 |
| CVE-2026-54694 |
NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover |
10.09.2026 |
9.6 |
| CVE-2026-87929 |
MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key |
14.09.2026 |
9.3 |
| CVE-2026-87930 |
MaxSite CMS through 109.6 PHP Object Injection via ci_session |
09.09.2026 |
9.2 |
| CVE-2026-47156 |
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator |
10.09.2026 |
9.3 |
| CVE-2026-67401 |
|
10.09.2026 |
9.9 |
| CVE-2026-67403 |
|
09.09.2026 |
9 |
| CVE-2026-68484 |
|
09.09.2026 |
9 |
| CVE-2026-22590 |
Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage |
09.09.2026 |
9.1 |
| CVE-2026-85102 |
Improper Certificate Validation in Quantum Security Gateway |
10.09.2026 |
9.8 |
| CVE-2026-85103 |
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding |
10.09.2026 |
9.8 |
| CVE-2026-80172 |
|
11.09.2026 |
9.8 |
| CVE-2026-87806 |
Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password |
09.09.2026 |
9.1 |
| CVE-2026-87827 |
KGUARD DVR unauthenticated remote command execution vulnerability |
09.09.2026 |
10 |
| CVE-2026-85978 |
Unauthenticated Remote Code Execution in Akana API Platform |
09.09.2026 |
10 |
| CVE-2026-16272 |
Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module |
09.09.2026 |
9.1 |
| CVE-2026-79696 |
Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist |
09.09.2026 |
10 |
| CVE-2026-21095 |
|
11.09.2026 |
9.2 |
| CVE-2026-21096 |
|
11.09.2026 |
9.2 |
| CVE-2026-21102 |
|
11.09.2026 |
9.3 |
| CVE-2026-53939 |
OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption |
09.09.2026 |
9.1 |
| CVE-2026-53581 |
ntp: write path traversal |
09.09.2026 |
9 |
| CVE-2026-85982 |
Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector |
10.09.2026 |
9 |
| CVE-2026-84197 |
|
09.09.2026 |
9.2 |
| CVE-2026-19232 |
Adobe Experience Manager | Incorrect Authorization (CWE-863) |
10.09.2026 |
9.9 |
| CVE-2026-86464 |
|
09.09.2026 |
9.9 |
| CVE-2026-48273 |
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) |
09.09.2026 |
9.9 |
| CVE-2026-75746 |
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
09.09.2026 |
9.1 |
| CVE-2026-84869 |
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions |
12.09.2026 |
9.9 |
| CVE-2026-28659 |
|
09.09.2026 |
10 |
| CVE-2026-49883 |
|
10.09.2026 |
10 |
| CVE-2026-82004 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
11.09.2026 |
10 |
| CVE-2026-66302 |
Skype for Business Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-76200 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
09.09.2026 |
9.3 |
| CVE-2026-76201 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
09.09.2026 |
9.3 |
| CVE-2026-65669 |
Microsoft SQL Server Elevation of Privilege Vulnerability |
11.09.2026 |
9.6 |
| CVE-2026-68839 |
Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69276 |
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69356 |
Microsoft Exchange Server Spoofing Vulnerability |
11.09.2026 |
9.3 |
| CVE-2026-69408 |
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69431 |
Telnet Client Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69463 |
Windows NTFS Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69491 |
Microsoft DirectMusic Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69493 |
Windows Event Logging Service Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69496 |
Windows Compressed Folder Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69525 |
Remote Desktop Services Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69579 |
Windows Message Queuing Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69586 |
Microsoft Windows PDF Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69590 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69595 |
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69641 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
11.09.2026 |
9.1 |
| CVE-2026-69715 |
Windows Direct Show Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69730 |
Windows DNS Server Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69768 |
Windows RNDIS Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69769 |
Windows HTTP Print Provider Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69819 |
RPC Runtime Library Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69824 |
Microsoft Standard XPS Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69829 |
Windows Shell Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69845 |
Windows DHCP Server Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69854 |
Spring Cloud Azure Elevation of Privilege Vulnerability |
11.09.2026 |
9 |
| CVE-2026-69910 |
Windows Hyper-V Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-70296 |
Windows Imaging Component Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-72979 |
Windows DHCP Server Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-72982 |
Windows Netlogon Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-72983 |
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-73009 |
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-73010 |
Microsoft Failover Cluster Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-73025 |
Windows iSCSI Security Feature Bypass Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-77493 |
Windows Graphics Component Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-78445 |
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-78509 |
Microsoft Office Outlook Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-78510 |
Microsoft Word Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-81376 |
Visual Studio Code Security Feature Bypass Vulnerability |
11.09.2026 |
9.6 |
| CVE-2026-83941 |
Entra ID Elevation of Privilege Vulnerability |
11.09.2026 |
9.9 |
| CVE-2026-82533 |
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing |
10.09.2026 |
9.4 |
| CVE-2026-82067 |
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup |
08.09.2026 |
9.2 |
| CVE-2026-86729 |
WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
10.09.2026 |
9.1 |
| CVE-2026-86738 |
Snipe-IT before 8.7.0 CSS Injection via Custom CSS |
08.09.2026 |
9.3 |
| CVE-2026-12647 |
|
09.09.2026 |
9.9 |
| CVE-2026-12645 |
|
09.09.2026 |
9.9 |
| CVE-2026-12646 |
|
09.09.2026 |
9.9 |
| CVE-2026-12650 |
|
09.09.2026 |
9.9 |
| CVE-2026-12744 |
|
09.09.2026 |
9.8 |
| CVE-2026-12745 |
|
09.09.2026 |
9.8 |
| CVE-2026-61516 |
Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint |
08.09.2026 |
9.3 |
| CVE-2026-73309 |
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint |
09.09.2026 |
9.1 |
| CVE-2026-73311 |
XenForo < 2.3.13 OAuth2 Authorization Code Reuse |
10.09.2026 |
9.1 |
| CVE-2026-73312 |
XenForo < 2.3.13 Refresh Token Replay via Expired Access Token |
09.09.2026 |
9.1 |
| CVE-2026-77089 |
Command Center API Authentication Bypass |
09.09.2026 |
9.3 |
| CVE-2026-78234 |
Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users |
08.09.2026 |
9.9 |
| CVE-2026-62645 |
|
08.09.2026 |
9.3 |
| CVE-2026-62646 |
|
10.09.2026 |
9.1 |
| CVE-2026-62647 |
|
14.09.2026 |
9.3 |
| CVE-2026-67367 |
|
09.09.2026 |
9.2 |
| CVE-2026-71376 |
OS Command Injection Vulnerability in Cosminexus Component Container |
08.09.2026 |
9.8 |
| CVE-2026-71377 |
Command Argument Injection Vulnerability in Cosminexus Component Container |
08.09.2026 |
9.8 |
| CVE-2026-71374 |
Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container |
08.09.2026 |
9.8 |
| CVE-2026-86510 |
D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write |
08.09.2026 |
9.4 |
| CVE-2026-86509 |
D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow |
11.09.2026 |
9.4 |
| CVE-2026-44756 |
Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing |
08.09.2026 |
10 |
| CVE-2026-58240 |
Missing Authentication check in SAP NetWeaver (Message Server) |
09.09.2026 |
9.8 |
| CVE-2026-66768 |
Improper Access Control in SAP NetWeaver (SAP GUI for Java) |
09.09.2026 |
9 |
| CVE-2026-76969 |
Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) |
08.09.2026 |
9.4 |
| CVE-2026-86543 |
knowns before 0.30.0 Unauthenticated Management API Exposure |
11.09.2026 |
9.3 |
| CVE-2026-75650 |
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) |
09.09.2026 |
10 |