| CVE-2026-50605 |
Privilege Escalation Vulnerability in NitroSense and PredatorSense Software |
17.09.2026 |
|
| CVE-2026-87829 |
Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated Attachment ID Reparenting |
17.09.2026 |
4.3 |
| CVE-2026-87831 |
Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Address Custom Field |
17.09.2026 |
4.3 |
| CVE-2026-86320 |
Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`) |
17.09.2026 |
|
| CVE-2026-86801 |
To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler |
17.09.2026 |
8.8 |
| CVE-2026-87963 |
Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter |
17.09.2026 |
8.6 |
| CVE-2026-91017 |
Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback |
17.09.2026 |
3.7 |
| CVE-2026-44940 |
Service token exposure and potential privilege escalation in SUSE Observability |
17.09.2026 |
5.7 |
| CVE-2026-90982 |
@fastify/static vulnerable to route guard bypass via path case-folding |
17.09.2026 |
5.3 |
| CVE-2025-15697 |
Dictionary <= 1.0 - Reflected XSS via Multiple Parameters |
17.09.2026 |
|
| CVE-2026-85128 |
Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request |
17.09.2026 |
|
| CVE-2026-85130 |
WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs |
17.09.2026 |
|
| CVE-2026-86446 |
LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST Endpoint |
17.09.2026 |
|
| CVE-2026-86707 |
Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter |
17.09.2026 |
|
| CVE-2026-86709 |
The Pressengine <= 1.0 - Unauthenticated Authentication Bypass |
17.09.2026 |
|
| CVE-2026-86710 |
Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter |
17.09.2026 |
|
| CVE-2026-86788 |
HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag |
17.09.2026 |
|
| CVE-2026-86824 |
Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key |
17.09.2026 |
|
| CVE-2026-87786 |
Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates |
17.09.2026 |
|
| CVE-2026-87836 |
Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export |
17.09.2026 |
|
| CVE-2026-88792 |
Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update |
17.09.2026 |
|
| CVE-2026-88795 |
wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token |
17.09.2026 |
|
| CVE-2026-88904 |
PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation |
17.09.2026 |
|
| CVE-2026-90922 |
Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatch |
17.09.2026 |
|
| CVE-2026-90923 |
Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletion |
17.09.2026 |
|
| CVE-2026-91008 |
Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panel |
17.09.2026 |
|
| CVE-2026-91009 |
Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachment |
17.09.2026 |
|
| CVE-2026-91010 |
Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletion |
17.09.2026 |
|
| CVE-2026-91011 |
EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansion |
17.09.2026 |
|
| CVE-2026-91014 |
Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpoint |
17.09.2026 |
|
| CVE-2026-91015 |
Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expired |
17.09.2026 |
|
| CVE-2026-91016 |
Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure |
17.09.2026 |
|
| CVE-2026-91019 |
Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosure |
17.09.2026 |
|
| CVE-2026-87796 |
Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload |
17.09.2026 |
9.8 |
| CVE-2026-87935 |
Paid Downloads <= 3.15 - Unauthenticated Arbitrary File Upload via 'paiddownloads_update_file' Action |
17.09.2026 |
8.1 |
| CVE-2025-59607 |
Untrusted Pointer Dereference in Windows Compute |
17.09.2026 |
7.8 |
| CVE-2026-24073 |
Out-of-bounds Write in Video |
17.09.2026 |
7.8 |
| CVE-2026-24074 |
Out-of-bounds Write in Video |
17.09.2026 |
7.8 |
| CVE-2026-24075 |
Buffer Over-read in Qualcomm IPC |
17.09.2026 |
7.8 |
| CVE-2026-24081 |
Buffer Over-read in BT Controller |
17.09.2026 |
7.4 |
| CVE-2026-25261 |
Untrusted Pointer Dereference in Camera |
17.09.2026 |
6.7 |
| CVE-2026-25275 |
Buffer Over-read in WLAN Firmware |
17.09.2026 |
7.5 |
| CVE-2026-25278 |
Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Software platform based on QNX |
17.09.2026 |
7.8 |
| CVE-2026-25280 |
Out-of-bounds Write in DSP Service |
17.09.2026 |
7.8 |
| CVE-2026-25281 |
Allocation of Resources Without Limits or Throttling in OOBM |
17.09.2026 |
7.4 |
| CVE-2026-25282 |
Out-of-bounds Read in OOBM |
17.09.2026 |
7.9 |
| CVE-2026-25283 |
Stack-based Buffer Overflow in OOBM |
17.09.2026 |
8.8 |
| CVE-2026-25284 |
Buffer Over-read in OOBM |
17.09.2026 |
7.3 |
| CVE-2026-25290 |
Integer Overflow or Wraparound in OOBM |
17.09.2026 |
7.8 |
| CVE-2026-25294 |
Buffer Over-read in WLAN Firmware |
17.09.2026 |
7.4 |
| CVE-2026-50604 |
Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software |
17.09.2026 |
|
| CVE-2026-50603 |
Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense |
17.09.2026 |
|
| CVE-2026-92839 |
|
17.09.2026 |
4.3 |
| CVE-2026-86311 |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
17.09.2026 |
6.4 |
| CVE-2026-89064 |
All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Insufficient Credential Protection via Authorization Basic Header |
17.09.2026 |
5.3 |
| CVE-2026-81546 |
|
17.09.2026 |
7.7 |
| CVE-2026-92838 |
GeoVision GV-Remote E-Map dll hijacking vulnerability |
17.09.2026 |
7.8 |
| CVE-2026-65388 |
|
16.09.2026 |
|
| CVE-2026-85789 |
|
16.09.2026 |
|
| CVE-2026-61588 |
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client |
16.09.2026 |
6.5 |
| CVE-2026-61589 |
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path |
16.09.2026 |
6.3 |
| CVE-2026-61596 |
djust has broken object-level access control (IDOR) |
16.09.2026 |
7.1 |
| CVE-2026-61599 |
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path |
16.09.2026 |
|
| CVE-2026-61591 |
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection) |
16.09.2026 |
8.1 |
| CVE-2026-61594 |
djust has an authorization bypass on the WebSocket/SSE mount path |
16.09.2026 |
9.1 |
| CVE-2026-61592 |
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack) |
16.09.2026 |
7.4 |
| CVE-2026-61597 |
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags |
16.09.2026 |
|
| CVE-2026-92576 |
HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool |
16.09.2026 |
|
| CVE-2026-92577 |
AVideo through 29.0 API get_api_video Broken Access Control via clean_title |
16.09.2026 |
|
| CVE-2026-92578 |
WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash |
16.09.2026 |
|
| CVE-2026-92579 |
AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision |
16.09.2026 |
|
| CVE-2026-92580 |
AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF |
16.09.2026 |
|
| CVE-2026-92581 |
AVideo through 29.0 Like Counter Desynchronization via Array Parameter |
16.09.2026 |
|
| CVE-2026-92582 |
AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass |
16.09.2026 |
|
| CVE-2026-92583 |
AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment |
16.09.2026 |
|
| CVE-2026-92584 |
AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header |
16.09.2026 |
|
| CVE-2026-92585 |
AVideo through 29.0 Missing Authorization Check via API Like Endpoint |
16.09.2026 |
|
| CVE-2026-92586 |
AVideo through 29.0 Missing Authorization via comment API endpoint |
16.09.2026 |
|
| CVE-2026-92587 |
n8n before 1.123.76 Sandbox Escape via Git Relative URL |
16.09.2026 |
|
| CVE-2026-92588 |
n8n before 1.123.76 Improper Authorization via Source Control Push |
16.09.2026 |
|
| CVE-2026-92589 |
Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder |
16.09.2026 |
|
| CVE-2026-92590 |
Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields |
16.09.2026 |
|
| CVE-2026-92591 |
Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
16.09.2026 |
|
| CVE-2026-92592 |
Craft CMS before 4.18.6 Remote Code Execution via signed cookie |
16.09.2026 |
|
| CVE-2026-92593 |
Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
16.09.2026 |
|
| CVE-2026-92594 |
Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL |
16.09.2026 |
|
| CVE-2026-92595 |
Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent |
16.09.2026 |
|
| CVE-2026-92596 |
Nodemailer before 9.1.0 Denial of Service via addressparser |
16.09.2026 |
|
| CVE-2026-92597 |
Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment |
16.09.2026 |
|
| CVE-2026-92598 |
Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass |
16.09.2026 |
|
| CVE-2026-92599 |
Joi before 17.13.7 and 18.2.6 ReDoS via isoDate |
16.09.2026 |
|
| CVE-2026-89034 |
TCH QRing R20_B006 Unauthenticated BLE Access |
16.09.2026 |
|
| CVE-2026-64684 |
RMCP: Custom HTTP headers leak to cross-origin redirect targets |
16.09.2026 |
6.8 |
| CVE-2026-85469 |
Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope |
16.09.2026 |
|
| CVE-2026-62997 |
Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via unsafe `torch.load` |
16.09.2026 |
|
| CVE-2026-75513 |
Marten: SQL injection in Marten's LINQ provider via unescaped string literals |
16.09.2026 |
9.1 |
| CVE-2026-81871 |
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning |
16.09.2026 |
|
| CVE-2026-81869 |
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation |
16.09.2026 |
|
| CVE-2026-81872 |
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
16.09.2026 |
|
| CVE-2026-20121 |
CIsco FTD Bypass Access List |
16.09.2026 |
5.3 |
| CVE-2026-63506 |
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site |
16.09.2026 |
8.8 |
| CVE-2026-76426 |
Cisco ISE REST API SQL Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76427 |
Cisco ISE XML External Entity Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76431 |
Cisco Identity Services Engine Arbitrary File Deletion Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76447 |
Cisco Identity Services Engine Certificate Reload Vulnerability |
16.09.2026 |
5.3 |
| CVE-2026-92748 |
BC Security Empire before 6.7.1 Path Traversal File Upload RCE |
16.09.2026 |
|
| CVE-2026-92749 |
SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret |
16.09.2026 |
|
| CVE-2026-92750 |
Harness through 3.3.0 Missing Access Control via infraproviders endpoint |
16.09.2026 |
|
| CVE-2026-92751 |
CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter |
16.09.2026 |
|
| CVE-2026-92752 |
metasfresh Unauthorized Access via Document Attachments and Comments Endpoints |
16.09.2026 |
|
| CVE-2026-92753 |
PatrowlManager through 1.8.4 Authorization Bypass via Events API |
16.09.2026 |
|
| CVE-2026-92754 |
PatrowlManager through 1.8.4 Improper Access Control via users API |
16.09.2026 |
|
| CVE-2026-92759 |
SecObserve before 1.59.1 Information Disclosure via API Configuration |
16.09.2026 |
|
| CVE-2026-92760 |
Shlink through 5.1.6 Mercure Token Authorization Bypass |
16.09.2026 |
|
| CVE-2026-92761 |
WebVirtCloud Missing Authorization on Instance Control Actions |
16.09.2026 |
|
| CVE-2026-92762 |
Pelican Panel before 1.0.0-beta35 Authorization Bypass via Startup |
16.09.2026 |
|
| CVE-2026-92763 |
Rundeck through 6.2.1 Authorization Bypass via Project Import |
16.09.2026 |
|
| CVE-2026-92764 |
OpenCVE before 3.1.0 Organization API Ignores Token Scope |
16.09.2026 |
|
| CVE-2026-92765 |
ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList |
16.09.2026 |
|
| CVE-2026-92770 |
Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter |
16.09.2026 |
|
| CVE-2026-92771 |
Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query |
16.09.2026 |
|
| CVE-2026-92772 |
Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX |
16.09.2026 |
|
| CVE-2026-92773 |
Trigger.dev before 4.6.0 GitHub App Installation Takeover |
16.09.2026 |
|
| CVE-2026-92774 |
Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission |
16.09.2026 |
|
| CVE-2026-92775 |
Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch |
16.09.2026 |
|
| CVE-2026-92776 |
Wiki.js through 2.5.314 Path Prefix Matching Authorization Bypass |
16.09.2026 |
|
| CVE-2026-92778 |
CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes |
16.09.2026 |
|
| CVE-2026-92779 |
Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings |
16.09.2026 |
|
| CVE-2026-92780 |
KnowStreaming through 3.4.1 Missing Authorization on the REST API |
16.09.2026 |
|
| CVE-2026-92781 |
Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttributes |
16.09.2026 |
|
| CVE-2026-92782 |
Chroma through 1.5.9 Authorization Bypass via Collection Identifier |
16.09.2026 |
|
| CVE-2026-92783 |
Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion |
16.09.2026 |
|
| CVE-2026-92784 |
@refinedev/inferencer through 7.0.0 Code Injection via API Field Names |
16.09.2026 |
|
| CVE-2026-92785 |
Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes |
16.09.2026 |
|
| CVE-2026-92786 |
LightGBM through 4.7.0 Out-of-Bounds Write via Crafted Model |
16.09.2026 |
|
| CVE-2026-92787 |
Feast through 0.66.0 Authentication Bypass via Unverified Token |
16.09.2026 |
|
| CVE-2026-92788 |
Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node |
16.09.2026 |
|
| CVE-2026-92789 |
Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect |
16.09.2026 |
|
| CVE-2026-92790 |
Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header |
16.09.2026 |
|
| CVE-2026-92791 |
Uber Kraken through 0.1.29 Path Traversal via tag parameter |
16.09.2026 |
|
| CVE-2026-92792 |
OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifier |
16.09.2026 |
|
| CVE-2026-92793 |
GoAdmin through 1.2.26 Authorization Bypass via Query Parameter |
16.09.2026 |
|
| CVE-2026-92794 |
OpenSign through 2.41.3 Information Disclosure via getDocument |
16.09.2026 |
|
| CVE-2026-92795 |
Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin |
16.09.2026 |
|
| CVE-2026-92796 |
Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass |
16.09.2026 |
|
| CVE-2026-92800 |
Docs before 5.4.1 Stale Collaboration Session After Access Revocation |
16.09.2026 |
|
| CVE-2026-92801 |
cc-connect through 1.5.0 User Allowlist Bypass via Feishu Card Actions |
16.09.2026 |
|
| CVE-2026-92802 |
kan through 0.6.0 Authorization Bypass via GitHub Project Import |
16.09.2026 |
|
| CVE-2026-92803 |
LibreTranslate through 1.9.6 Missing Access Check on the download_file Route |
16.09.2026 |
|
| CVE-2026-92804 |
Nango through 0.70.4 Server-Side Request Forgery via Configuration |
16.09.2026 |
|
| CVE-2026-92805 |
UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard |
16.09.2026 |
|
| CVE-2026-92806 |
phpList before 3.6.17 Cross-Site Request Forgery via massremove.php |
16.09.2026 |
|
| CVE-2026-92809 |
PrestaShop psgdpr through 1.4.3 GDPR Log Forgery |
16.09.2026 |
|
| CVE-2026-92810 |
PrestaShop blockwishlist through 3.0.2 Information Disclosure |
16.09.2026 |
|
| CVE-2026-92811 |
browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass |
16.09.2026 |
|
| CVE-2026-92812 |
decap-server Path Traversal via Sibling Directory Prefix Matching |
16.09.2026 |
|
| CVE-2026-92813 |
Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass |
16.09.2026 |
|
| CVE-2026-92814 |
changedetection.io through 0.60.6 Cross-Site Scripting via watch_title |
16.09.2026 |
|
| CVE-2026-92815 |
changedetection.io through 0.60.6 SSRF via browser-step Goto URL |
16.09.2026 |
|
| CVE-2026-92816 |
ComfyUI before 0.30.0 Path Traversal via dataset save nodes |
16.09.2026 |
|
| CVE-2025-56563 |
|
16.09.2026 |
|
| CVE-2025-56565 |
|
16.09.2026 |
|
| CVE-2025-56566 |
|
16.09.2026 |
|
| CVE-2026-20071 |
ISE 802.1x Session Hijack Vulnerability |
16.09.2026 |
3.8 |
| CVE-2026-20072 |
ISE information disclosure |
16.09.2026 |
4.9 |
| CVE-2026-20120 |
Cisco FTD ACL bypass vulnerability |
16.09.2026 |
5.8 |
| CVE-2026-20135 |
Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability |
16.09.2026 |
8.6 |
| CVE-2026-20154 |
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software Logging Denial of Service |
16.09.2026 |
8.6 |
| CVE-2026-20222 |
Cisco Secure Adaptive Security Appliance Software and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability |
16.09.2026 |
7.4 |
| CVE-2026-20235 |
Cisco Identity Services Engine Information Disclosure Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-20247 |
Cisco Identity Services Engine Unauthenticated SQL Injection Vulnerability |
16.09.2026 |
7.5 |
| CVE-2026-20248 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability |
16.09.2026 |
6.8 |
| CVE-2026-20249 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability |
16.09.2026 |
8.6 |
| CVE-2026-20250 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 3100 and 4200 Series DTLS Denial of Service Vulnerability |
16.09.2026 |
8.6 |
| CVE-2026-20282 |
Cisco Identity Services Engine Authenticated Write Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-20283 |
Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability |
17.09.2026 |
6.5 |
| CVE-2026-20284 |
Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20285 |
Cisco Identity Services Engine Authorization Bypass Vulnerability |
16.09.2026 |
4.3 |
| CVE-2026-20286 |
Cisco Identity Services Engine Authorization Bypass Vulnerability |
16.09.2026 |
4.3 |
| CVE-2026-20287 |
Cisco Identity Services Engine Hardening Release - Improper Privlege Management Vulnerabilities |
17.09.2026 |
6.5 |
| CVE-2026-20290 |
Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability |
16.09.2026 |
5.8 |
| CVE-2026-20295 |
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service Vulnerability |
16.09.2026 |
8.6 |
| CVE-2026-20300 |
Cisco Identity Services Engine SQL Injection Vulnerability |
16.09.2026 |
7.1 |
| CVE-2026-20309 |
Cisco Identity Services Engine Cross-Site Scripting Vulnerability |
16.09.2026 |
6.1 |
| CVE-2026-20323 |
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Unauthorized Authentication Bypass Vulnerability |
17.09.2026 |
8.3 |
| CVE-2026-20332 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities |
17.09.2026 |
9.9 |
| CVE-2026-20333 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Comparison Vulnerabilities |
17.09.2026 |
8.8 |
| CVE-2026-20334 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Coding Standards Vulnerabilities |
17.09.2026 |
8.4 |
| CVE-2026-20335 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Incorrect Calculation Vulnerabilities |
16.09.2026 |
8.1 |
| CVE-2026-20336 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Resource Lifetime Management Vulnerabilities |
16.09.2026 |
8.8 |
| CVE-2026-20340 |
Cisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution Vulnerability |
16.09.2026 |
8.8 |
| CVE-2026-20342 |
Cisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download Vulnerability |
16.09.2026 |
7.7 |
| CVE-2026-20343 |
Cisco Secure Firewall Management Center Software Information Disclosure and Disk Denial of Service Vulnerability |
16.09.2026 |
7.5 |
| CVE-2026-20344 |
Cisco Secure Firewall Management Center Software SQL Injection Vulnerability |
16.09.2026 |
8.8 |
| CVE-2026-20350 |
Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability |
16.09.2026 |
4.7 |
| CVE-2026-20352 |
Cisco Identity Services Engine RADIUS Denial of Service Vulnerability |
16.09.2026 |
8.6 |
| CVE-2026-20360 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure Handling |
16.09.2026 |
8.8 |
| CVE-2026-76409 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Limitation of a Pathname |
16.09.2026 |
8.8 |
| CVE-2026-76412 |
Cisco Secure Firewall Management Center Software Authenticated Privilege Escalation to Root Vulnerability |
17.09.2026 |
8.5 |
| CVE-2026-76413 |
Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability |
16.09.2026 |
8.2 |
| CVE-2026-76424 |
Cisco ISE Arbitrary File Access Vulnerability |
17.09.2026 |
7.2 |
| CVE-2026-76425 |
Cisco ISE SQL Injection Vulnerability |
16.09.2026 |
7.6 |
| CVE-2026-76428 |
Cisco ISE Profiler SQL Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76432 |
Cisco Identity Services Engine Arbitrary File Write Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76433 |
Cisco Identity Services Engine Information Disclosure Vulnerability |
16.09.2026 |
5.3 |
| CVE-2026-76434 |
Cisco Identity Services Engine Arbitrary File Read Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76438 |
Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability |
16.09.2026 |
6.5 |
| CVE-2026-76439 |
Cisco Identity Services Engine Event Injection Vulnerability |
16.09.2026 |
5.3 |
| CVE-2026-76444 |
Cisco Identity Services Engine Information Disclosure Vulnerability |
16.09.2026 |
5.3 |
| CVE-2026-76446 |
Cisco Identity Services Engine External Entity Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76448 |
Cisco Identity Services Engine SQL Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76449 |
Cisco Identity Services Engine SQL Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76450 |
Cisco Identity Services Engine SQL Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76451 |
Cisco Identity Services Engine Certificate Management SQL Injection Vulnerability |
16.09.2026 |
4.9 |
| CVE-2026-76460 |
Cisco Identity Services Engine Authentication Bypass Vulnerability |
17.09.2026 |
10 |
| CVE-2026-92527 |
chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery |
16.09.2026 |
|
| CVE-2026-20130 |
Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities |
16.09.2026 |
10 |
| CVE-2026-20176 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20192 |
Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities |
16.09.2026 |
10 |
| CVE-2026-20194 |
Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities |
16.09.2026 |
9.1 |
| CVE-2026-20211 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20237 |
Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities |
16.09.2026 |
9.1 |
| CVE-2026-20242 |
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability |
16.09.2026 |
9.8 |
| CVE-2026-20322 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control |
16.09.2026 |
9.9 |
| CVE-2026-20324 |
Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability |
16.09.2026 |
9.9 |
| CVE-2026-20325 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command |
16.09.2026 |
9.9 |
| CVE-2026-20326 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function |
16.09.2026 |
9.8 |
| CVE-2026-20329 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities |
16.09.2026 |
9.9 |
| CVE-2026-20330 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities |
16.09.2026 |
9.9 |
| CVE-2026-20341 |
Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability |
16.09.2026 |
9.1 |
| CVE-2026-20361 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - SQL Injection |
16.09.2026 |
8.8 |
| CVE-2026-62949 |
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION |
16.09.2026 |
6.5 |
| CVE-2026-76423 |
Cisco ISE API Authentication Bypass Vulnerability |
17.09.2026 |
10 |
| CVE-2026-81870 |
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs |
16.09.2026 |
|
| CVE-2026-92526 |
itsourcecode Leave Management System index.php sql injection |
16.09.2026 |
|
| CVE-2026-92808 |
Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise |
16.09.2026 |
|
| CVE-2026-89083 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
16.09.2026 |
|
| CVE-2026-89084 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
16.09.2026 |
|
| CVE-2026-86831 |
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS |
16.09.2026 |
8.7 |
| CVE-2026-89082 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
16.09.2026 |
|
| CVE-2026-92475 |
GPAC downloader.c wait_for_header_and_parse out-of-bounds |
16.09.2026 |
|
| CVE-2026-86865 |
Tanium addressed a SQL injection vulnerability in Asset. |
16.09.2026 |
8.8 |
| CVE-2026-87024 |
Tanium addressed a SQL injection vulnerability in Asset. |
16.09.2026 |
7.2 |
| CVE-2026-87026 |
Tanium addressed an improper access controls vulnerability in Threat Response. |
16.09.2026 |
3.8 |
| CVE-2026-87076 |
Tanium addressed an information disclosure vulnerability in Discover. |
16.09.2026 |
6.5 |
| CVE-2026-87105 |
Tanium addressed a SQL injection vulnerability in Threat Response. |
16.09.2026 |
8.8 |
| CVE-2026-87113 |
Tanium addressed an improper access controls vulnerability in Threat Response. |
16.09.2026 |
6.3 |
| CVE-2026-87116 |
Tanium addressed a server-side request forgery vulnerability in Threat Response. |
16.09.2026 |
6.5 |
| CVE-2026-88592 |
|
16.09.2026 |
|
| CVE-2026-70469 |
Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests |
16.09.2026 |
|
| CVE-2026-81866 |
Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration |
16.09.2026 |
|
| CVE-2026-82561 |
Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods |
16.09.2026 |
|
| CVE-2026-86089 |
Apache NiFi: Missing Process Group Authorization for Connector Migration |
16.09.2026 |
|
| CVE-2026-87976 |
Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles |
16.09.2026 |
|
| CVE-2026-76646 |
Apache MyFaces: Denial of Service via Unbounded Request Parsing |
16.09.2026 |
|
| CVE-2026-92474 |
GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free |
16.09.2026 |
|
| CVE-2026-63225 |
Redocly CLI: Path traversal when using `split` command |
16.09.2026 |
4.4 |
| CVE-2026-63325 |
Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `respect` |
16.09.2026 |
7.8 |
| CVE-2026-73462 |
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the I |
16.09.2026 |
6.5 |
| CVE-2026-86071 |
Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root |
16.09.2026 |
3.7 |
| CVE-2026-92473 |
GPAC BIFS commands.c gf_sg_command_del use after free |
16.09.2026 |
|
| CVE-2026-73456 |
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. |
17.09.2026 |
10 |
| CVE-2026-73457 |
Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users. |
16.09.2026 |
5.3 |
| CVE-2026-91104 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
|
| CVE-2026-91105 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
|
| CVE-2026-91106 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
|
| CVE-2026-73442 |
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for |
16.09.2026 |
3 |
| CVE-2026-73443 |
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indef |
16.09.2026 |
4.7 |
| CVE-2026-79298 |
|
16.09.2026 |
|
| CVE-2026-81876 |
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service |
16.09.2026 |
7.5 |
| CVE-2026-86043 |
Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix CVE-2026-50197) |
16.09.2026 |
7.5 |
| CVE-2026-91100 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
16.09.2026 |
|
| CVE-2026-91101 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
16.09.2026 |
|
| CVE-2026-91102 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
16.09.2026 |
|
| CVE-2026-91103 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
16.09.2026 |
|
| CVE-2026-59823 |
LiteLLM: Server-side request forgery via the `user_config` request parameter in LiteLLM Proxy |
16.09.2026 |
|
| CVE-2026-68536 |
Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability |
16.09.2026 |
|
| CVE-2026-77360 |
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass |
16.09.2026 |
|
| CVE-2026-81875 |
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service |
16.09.2026 |
7.5 |
| CVE-2026-82399 |
CoreDNS: Unauthenticated memory exhaustion in custom transports |
16.09.2026 |
7.5 |
| CVE-2026-86003 |
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP |
16.09.2026 |
7.5 |
| CVE-2026-91097 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
16.09.2026 |
|
| CVE-2026-91098 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
|
| CVE-2026-91099 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
16.09.2026 |
|
| CVE-2026-92472 |
GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free |
16.09.2026 |
|
| CVE-2026-38999 |
|
16.09.2026 |
|
| CVE-2026-46352 |
Suricata defrag: fragmented encapsulated traffic with fragments can lead to deadlock |
16.09.2026 |
7.5 |
| CVE-2026-75025 |
Mattermost Desktop local network access from server-rendered content |
16.09.2026 |
4.7 |
| CVE-2026-75516 |
RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement |
16.09.2026 |
|
| CVE-2026-81176 |
Svelte devalue: DoS via malformed input |
16.09.2026 |
5.3 |
| CVE-2026-92729 |
SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints |
16.09.2026 |
|
| CVE-2026-63126 |
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799) |
16.09.2026 |
7.5 |
| CVE-2026-92417 |
Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference |
16.09.2026 |
|
| CVE-2026-92418 |
ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting |
16.09.2026 |
|
| CVE-2026-88593 |
|
16.09.2026 |
|
| CVE-2026-69147 |
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation |
16.09.2026 |
6.5 |
| CVE-2026-92416 |
Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion |
16.09.2026 |
|
| CVE-2026-47094 |
SIMAC MyPHR 1.1 IDOR Account Takeover via /api/employes/put/{id} |
16.09.2026 |
|
| CVE-2026-51990 |
|
16.09.2026 |
|
| CVE-2026-92413 |
Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dereference |
16.09.2026 |
|
| CVE-2026-92604 |
Scirius through 3.8.0 Arbitrary File Write via PCAP Upload |
16.09.2026 |
|
| CVE-2026-92605 |
IRIS through 2.4.29 Unauthorized Comment Access via Object ID |
16.09.2026 |
|
| CVE-2026-92716 |
Shuffle through 2.2.1 API Key Reset Cross-Tenant Privilege Escalation |
16.09.2026 |
|
| CVE-2026-92717 |
Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub |
16.09.2026 |
|
| CVE-2026-92718 |
Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache |
16.09.2026 |
|
| CVE-2026-92719 |
Quickwit through 0.9.0 SSRF via SQS queue_url Parameter |
16.09.2026 |
|
| CVE-2026-92720 |
Kubero through 3.1.1 Unauthenticated Notifications API Access |
16.09.2026 |
|
| CVE-2026-84397 |
Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
16.09.2026 |
5.4 |
| CVE-2026-18120 |
Missing Authorization in legacy Express entries search endpoint allows disclosure of Express entry data |
16.09.2026 |
|
| CVE-2026-85387 |
Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authenticated REST API access |
16.09.2026 |
|
| CVE-2026-92406 |
SourceCodester Inventory and Monitoring System btn_functions.php add sql injection |
16.09.2026 |
|
| CVE-2026-20234 |
Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities |
17.09.2026 |
9.9 |
| CVE-2026-20305 |
Cisco Identity Services Engine Command Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20306 |
Cisco Identity Services Engine Command Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20307 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.9 |
| CVE-2026-20331 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities |
17.09.2026 |
9.6 |
| CVE-2026-42784 |
Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion |
16.09.2026 |
|
| CVE-2026-76420 |
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability |
17.09.2026 |
9 |
| CVE-2026-92405 |
SourceCodester Inventory and Monitoring System index.php sql injection |
16.09.2026 |
|
| CVE-2026-92402 |
ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java index authorization |
16.09.2026 |
|
| CVE-2026-57173 |
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions |
16.09.2026 |
6.5 |
| CVE-2026-85385 |
Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field |
16.09.2026 |
|
| CVE-2026-85386 |
Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via unauthenticated XML/XSLT file upload in the Form Block |
16.09.2026 |
|
| CVE-2026-85756 |
SSH.NET: ScpClient allows server-side RCE via default SCP path handling |
16.09.2026 |
7.5 |
| CVE-2026-87028 |
Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 through 9.5.3 Discloses Restricted Page Summary Fields |
16.09.2026 |
|
| CVE-2026-87031 |
Missing authorization in the REST API user creation endpoint in Concrete CMS 9.2.0 through 9.5.3 allows arbitrary account creation |
16.09.2026 |
|
| CVE-2026-68904 |
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion |
16.09.2026 |
7 |
| CVE-2026-71182 |
|
16.09.2026 |
3 |
| CVE-2026-84993 |
MikroORM: SQL injection via unvalidated order direction in orderBy |
16.09.2026 |
6.5 |
| CVE-2026-85731 |
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) |
16.09.2026 |
8.8 |
| CVE-2026-85732 |
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing |
16.09.2026 |
4.7 |
| CVE-2026-86358 |
|
17.09.2026 |
6.5 |
| CVE-2026-86359 |
|
17.09.2026 |
8.5 |
| CVE-2026-92401 |
ChangeWeDer crm improper authentication |
16.09.2026 |
|
| CVE-2026-59944 |
Composer: CVE-2026-59946 fix bypass via symlinked package bin path |
16.09.2026 |
6.1 |
| CVE-2026-59974 |
Stanza: Zip Slip Path Traversal in Model/Resource Extraction |
16.09.2026 |
7.8 |
| CVE-2026-69200 |
node-opcua: Prototype Pollution via internal `fieldsToJson()` implementation (Related to CVE-2024-57086) |
16.09.2026 |
3.7 |
| CVE-2026-71179 |
|
17.09.2026 |
7.3 |
| CVE-2026-71180 |
|
17.09.2026 |
8.2 |
| CVE-2026-71181 |
|
16.09.2026 |
3 |
| CVE-2026-92398 |
Ruijie RG-EW3000GX user_list_note admin os command injection |
16.09.2026 |
|
| CVE-2026-92399 |
GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow |
16.09.2026 |
|
| CVE-2026-92600 |
Guns through 8.3.5 Information Disclosure via Missing Permission Check |
16.09.2026 |
|
| CVE-2026-92601 |
Guns through 8.3.5 Improper Access Control via SysNoticeController |
16.09.2026 |
|
| CVE-2026-92602 |
TDuck survey form through 5.3 Server-Side Request Forgery via Unvalidated Webhook URL |
16.09.2026 |
|
| CVE-2026-92603 |
ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageController |
16.09.2026 |
|
| CVE-2026-61593 |
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session |
16.09.2026 |
8.1 |
| CVE-2026-17526 |
Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts |
16.09.2026 |
|
| CVE-2026-19607 |
Keycloak-services: keycloak-services: broker-originated username collision causes account lockout |
16.09.2026 |
|
| CVE-2026-90999 |
Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment |
16.09.2026 |
|
| CVE-2026-92397 |
Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection |
16.09.2026 |
|
| CVE-2025-59953 |
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy |
16.09.2026 |
9.8 |
| CVE-2026-61595 |
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data |
16.09.2026 |
7.7 |
| CVE-2026-70416 |
|
16.09.2026 |
10 |
| CVE-2026-92615 |
Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed |
16.09.2026 |
|
| CVE-2026-92625 |
Control iD iDSecure Unauthenticated Denial of Service |
16.09.2026 |
7.5 |
| CVE-2026-92626 |
Control iD iDSecure Unauthenticated Denial of Service |
16.09.2026 |
7.5 |
| CVE-2025-43936 |
|
17.09.2026 |
8.1 |
| CVE-2026-26947 |
|
16.09.2026 |
6.7 |
| CVE-2026-76104 |
|
16.09.2026 |
5.5 |
| CVE-2026-92385 |
SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting |
16.09.2026 |
|
| CVE-2026-92627 |
Heap Use-After-Free in H5T__conv_f_f |
16.09.2026 |
|
| CVE-2025-36591 |
|
16.09.2026 |
4.4 |
| CVE-2026-82410 |
Pocketbase: Unhandled panic in worker goroutines |
16.09.2026 |
|
| CVE-2026-92383 |
PbootCMS User Management UserController.php mod cross-site request forgery |
16.09.2026 |
|
| CVE-2026-18212 |
Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state |
16.09.2026 |
|
| CVE-2026-63127 |
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery |
16.09.2026 |
8.2 |
| CVE-2026-74909 |
Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enforcer bypass via percent-encoded uri segments |
16.09.2026 |
|
| CVE-2026-79651 |
Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching |
16.09.2026 |
|
| CVE-2026-84858 |
Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass |
16.09.2026 |
8.8 |
| CVE-2026-84859 |
Scada-LTS Authenticated Blind SQL Injection |
16.09.2026 |
6.5 |
| CVE-2026-84860 |
Scada-LTS DWR Authorization Bypass - Systemic |
16.09.2026 |
8.8 |
| CVE-2026-63128 |
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service |
16.09.2026 |
7.5 |
| CVE-2026-77409 |
RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking |
16.09.2026 |
|
| CVE-2026-77411 |
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr |
16.09.2026 |
|
| CVE-2026-77412 |
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client |
16.09.2026 |
|
| CVE-2026-92381 |
PbootCMS Template Rendering ContentController.php decode_string cross site scripting |
16.09.2026 |
|
| CVE-2026-77403 |
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation |
16.09.2026 |
|
| CVE-2026-77404 |
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection |
16.09.2026 |
|
| CVE-2026-77405 |
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser |
16.09.2026 |
|
| CVE-2026-77406 |
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration |
16.09.2026 |
|
| CVE-2026-77407 |
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields |
16.09.2026 |
|
| CVE-2026-77410 |
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation |
16.09.2026 |
|
| CVE-2026-92395 |
@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
16.09.2026 |
9.1 |
| CVE-2026-92565 |
Rallly before 4.15.0 Information Disclosure via polls.get |
16.09.2026 |
5.3 |
| CVE-2026-92566 |
DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview |
16.09.2026 |
8.2 |
| CVE-2026-92567 |
TDuck survey form through 5.0 Unauthorized Data Modification |
16.09.2026 |
|
| CVE-2026-92568 |
MLRun through 1.11.0 Server-Side Request Forgery via Webhook |
16.09.2026 |
|
| CVE-2026-92569 |
Hippo4j through 1.5.0 SSRF via clientAddress Parameter |
16.09.2026 |
4.3 |
| CVE-2026-92570 |
reNgine through 2.2.0 Unauthorized Configuration File Read |
16.09.2026 |
|
| CVE-2026-92571 |
|
16.09.2026 |
|
| CVE-2026-92616 |
FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance |
16.09.2026 |
|
| CVE-2026-63671 |
@nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration |
16.09.2026 |
8.1 |
| CVE-2026-77401 |
Zope AccessControl: Information disclosure through Python string `format` and `format_map` functions |
16.09.2026 |
6.8 |
| CVE-2026-77408 |
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow |
16.09.2026 |
|
| CVE-2026-92380 |
WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery |
16.09.2026 |
|
| CVE-2026-19033 |
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification |
16.09.2026 |
6.5 |
| CVE-2026-19666 |
Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path |
16.09.2026 |
7.5 |
| CVE-2026-19668 |
Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching |
16.09.2026 |
5.3 |
| CVE-2026-61709 |
OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-inclusion) when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user |
16.09.2026 |
5.3 |
| CVE-2026-75029 |
Message parser retains every identical singleton RDATA, enabling wire-to-work amplification |
16.09.2026 |
5.3 |
| CVE-2026-76163 |
named aborts on a TKEY query when the user configuration has no global options statement |
16.09.2026 |
7.5 |
| CVE-2026-76825 |
RestrictedPython: Sandbox escape via string.Formatter field resolution |
16.09.2026 |
8.4 |
| CVE-2026-77119 |
NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets |
16.09.2026 |
5.9 |
| CVE-2026-80274 |
Validating resolver can abort while caching a mismatched NOQNAME proof |
16.09.2026 |
7.5 |
| CVE-2026-82964 |
Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx.sys |
16.09.2026 |
8.8 |
| CVE-2026-84997 |
react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU |
16.09.2026 |
7.5 |
| CVE-2026-88064 |
Backstage: Improper input validation in TechDocs MkDocs configuration |
16.09.2026 |
8.8 |
| CVE-2026-88976 |
@platejs/core HTML deserialization can trigger browser behavior during parsing |
16.09.2026 |
6.1 |
| CVE-2026-89031 |
Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post |
16.09.2026 |
|
| CVE-2026-92087 |
@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth |
16.09.2026 |
8.1 |
| CVE-2026-92366 |
code-projects Matrimonial System Regular Search search.php sql injection |
16.09.2026 |
|
| CVE-2026-61598 |
Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler |
16.09.2026 |
|
| CVE-2026-77692 |
Unauthenticated remote crash of named via a single DoH SIG(0) request |
16.09.2026 |
7.5 |
| CVE-2026-78301 |
Out-of-zone database nodes can become authoritative zone cuts |
16.09.2026 |
5.8 |
| CVE-2026-81563 |
SVCB AliasMode additional-data error leaks qpcache references |
16.09.2026 |
7.5 |
| CVE-2026-89029 |
Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler |
16.09.2026 |
|
| CVE-2026-89030 |
Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user |
16.09.2026 |
|
| CVE-2026-92365 |
vllm-project vllm thinking_budget_state.py algorithmic complexity |
16.09.2026 |
|
| CVE-2026-19662 |
qpcache NOQNAME proof use-after-free crashes recursive resolver |
16.09.2026 |
5.9 |
| CVE-2026-19941 |
checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof |
16.09.2026 |
5.9 |
| CVE-2026-61590 |
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG |
16.09.2026 |
7.4 |
| CVE-2026-92122 |
|
16.09.2026 |
|
| CVE-2026-92123 |
|
16.09.2026 |
|
| CVE-2026-92124 |
|
16.09.2026 |
|
| CVE-2026-92125 |
|
16.09.2026 |
|
| CVE-2026-92126 |
|
16.09.2026 |
|
| CVE-2026-92127 |
|
16.09.2026 |
|
| CVE-2026-92128 |
|
16.09.2026 |
|
| CVE-2026-92129 |
|
16.09.2026 |
|
| CVE-2026-92130 |
|
16.09.2026 |
|
| CVE-2026-92131 |
|
16.09.2026 |
|
| CVE-2026-92132 |
|
16.09.2026 |
|
| CVE-2026-92133 |
|
16.09.2026 |
|
| CVE-2026-92134 |
|
16.09.2026 |
|
| CVE-2026-92135 |
|
16.09.2026 |
|
| CVE-2026-92136 |
|
16.09.2026 |
|
| CVE-2026-92137 |
|
16.09.2026 |
|
| CVE-2026-92138 |
|
16.09.2026 |
|
| CVE-2026-92139 |
|
16.09.2026 |
|
| CVE-2026-92140 |
|
16.09.2026 |
|
| CVE-2026-92141 |
|
16.09.2026 |
|
| CVE-2026-19667 |
Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` |
16.09.2026 |
7.5 |
| CVE-2026-81736 |
Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees |
16.09.2026 |
7.5 |
| CVE-2026-92364 |
itsourcecode Leave Management System index.php sql injection |
16.09.2026 |
|
| CVE-2026-85104 |
Brain stimulation parameters can be modified via Bluetooth in Sooma |
16.09.2026 |
|
| CVE-2026-92363 |
ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption |
16.09.2026 |
|
| CVE-2026-56719 |
MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX |
16.09.2026 |
|
| CVE-2026-73177 |
|
16.09.2026 |
|
| CVE-2026-89028 |
MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX |
16.09.2026 |
|
| CVE-2026-91843 |
Stack overflow in login process to the Security Management and Log Servers |
17.09.2026 |
9.8 |
| CVE-2026-92362 |
ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption |
16.09.2026 |
|
| CVE-2026-92466 |
microservices-platform through 6.0.0 Missing Authorization via Disabled URL Permission Checking |
16.09.2026 |
|
| CVE-2026-92467 |
microservices-platform through 6.0.0 Unverified Password Change via /users/password |
16.09.2026 |
|
| CVE-2026-92468 |
microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via search-center |
16.09.2026 |
|
| CVE-2026-92469 |
microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Ownership Check |
16.09.2026 |
|
| CVE-2026-73172 |
|
16.09.2026 |
|
| CVE-2026-73173 |
|
16.09.2026 |
|
| CVE-2026-73174 |
|
16.09.2026 |
|
| CVE-2026-73175 |
|
16.09.2026 |
|
| CVE-2026-73176 |
|
16.09.2026 |
|
| CVE-2026-92361 |
ag-ui-protocol ag-ui SSE Client client.go resource consumption |
16.09.2026 |
|
| CVE-2026-73165 |
|
16.09.2026 |
|
| CVE-2026-73166 |
|
16.09.2026 |
|
| CVE-2026-73167 |
|
16.09.2026 |
|
| CVE-2026-73169 |
|
16.09.2026 |
|
| CVE-2026-73170 |
|
16.09.2026 |
|
| CVE-2026-73171 |
|
16.09.2026 |
|
| CVE-2026-19535 |
|
16.09.2026 |
|
| CVE-2026-73163 |
|
16.09.2026 |
|
| CVE-2026-73164 |
|
16.09.2026 |
|
| CVE-2026-92360 |
ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation |
16.09.2026 |
|
| CVE-2026-88817 |
Privilege escalation via legacy access group creation endpoint |
16.09.2026 |
|
| CVE-2026-92359 |
ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy |
16.09.2026 |
|
| CVE-2026-40854 |
Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
16.09.2026 |
|
| CVE-2026-40855 |
Command Injection in T-Mobile 5G Box IDU router via ping functionality |
16.09.2026 |
|
| CVE-2026-40856 |
Config disclosure in T-Mobile 5G Box IDU routers |
16.09.2026 |
|
| CVE-2026-40857 |
CSRF token bypass in T-Mobile 5G Box IDU routers |
16.09.2026 |
|
| CVE-2026-58146 |
Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
16.09.2026 |
|
| CVE-2026-58147 |
Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers |
16.09.2026 |
|
| CVE-2026-92465 |
WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability |
16.09.2026 |
7.6 |
| CVE-2026-92455 |
yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endpoints |
16.09.2026 |
|
| CVE-2026-92456 |
yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configuration Endpoints |
16.09.2026 |
|
| CVE-2026-92457 |
yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueInvoice |
16.09.2026 |
|
| CVE-2026-92458 |
yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale |
16.09.2026 |
|
| CVE-2026-92459 |
yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint |
16.09.2026 |
|
| CVE-2026-92460 |
yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing |
16.09.2026 |
|
| CVE-2026-92461 |
yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint |
16.09.2026 |
|
| CVE-2026-92462 |
yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlowStep |
16.09.2026 |
|
| CVE-2026-92463 |
yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on System User Listing |
16.09.2026 |
|
| CVE-2026-92357 |
a2ui-project a2ui Model Processor model-processor.ts information disclosure |
16.09.2026 |
|
| CVE-2026-86107 |
Security Advisory 0180 |
16.09.2026 |
5.9 |
| CVE-2026-89794 |
ksmbd: zero pipe read compound padding |
16.09.2026 |
|
| CVE-2026-89795 |
PCI: Allow per function PCI slots to fix slot reset on s390 |
16.09.2026 |
8.4 |
| CVE-2026-89796 |
mm/damon/core: avoid infinite kdamond_merge_regions() internal loop |
16.09.2026 |
|
| CVE-2026-89797 |
power: supply: ab8500_fg: fix use-after-free on remove |
16.09.2026 |
|
| CVE-2026-89798 |
rpcrdma: arm rn_done before publishing the notification |
16.09.2026 |
|
| CVE-2026-89799 |
bpf: Disable preemption in bpf_get_stackid |
16.09.2026 |
7.8 |
| CVE-2026-89800 |
drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE |
16.09.2026 |
|
| CVE-2026-89801 |
drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE |
16.09.2026 |
7.8 |
| CVE-2026-89802 |
drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op |
16.09.2026 |
|
| CVE-2026-89803 |
drm/nouveau: unsubscribe the channel-kill event before the fence context |
16.09.2026 |
7.8 |
| CVE-2026-89804 |
drm/nouveau/dmem: fix mismatched DMA unmap size for large folios |
16.09.2026 |
8.8 |
| CVE-2026-89805 |
drm/pagemap: Fix folio allocation fallback and use-after-put |
16.09.2026 |
7.8 |
| CVE-2026-89806 |
drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation |
16.09.2026 |
8.4 |
| CVE-2026-89807 |
drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore |
16.09.2026 |
|
| CVE-2026-89808 |
drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram |
16.09.2026 |
7.8 |
| CVE-2026-89809 |
drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds |
16.09.2026 |
|
| CVE-2026-89810 |
drm/amdkfd: Fix error path at svm_migrate_copy_to_ram |
16.09.2026 |
7.8 |
| CVE-2026-89811 |
drm/amdkfd: Add TLB flush after MES queue eviction/suspension |
16.09.2026 |
8.8 |
| CVE-2026-89812 |
drm/amdgpu: force complete the MES ring fences on reset |
16.09.2026 |
|
| CVE-2026-89813 |
drm/amdgpu: force complete the KIQ ring fences on reset |
16.09.2026 |
|
| CVE-2026-89814 |
drm/amdgpu: clamp the isolation index for rings outside a partition |
16.09.2026 |
7.8 |
| CVE-2026-89815 |
drm/ttm: Drop tt->restore after successful restore |
16.09.2026 |
7.8 |
| CVE-2026-89816 |
drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used |
16.09.2026 |
|
| CVE-2026-89817 |
drm/gud: NUL-terminate TV mode names read from the device |
16.09.2026 |
|
| CVE-2026-89818 |
drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check |
16.09.2026 |
7.1 |
| CVE-2026-89819 |
drm/amd/display: validate plane degamma LUT size for private color prop |
16.09.2026 |
7.8 |
| CVE-2026-89820 |
drm/amd/display: fix dc_lock leak on GPU reset error paths |
16.09.2026 |
|
| CVE-2026-89821 |
drm/amd/display: avoid divide-by-zero in __is_lut_linear() |
16.09.2026 |
|
| CVE-2026-89822 |
drm/i915: Guard against NULL driver_data in i915_pci_probe() |
16.09.2026 |
|
| CVE-2026-89823 |
drm: fix race between partial drm_dev_register() failure and ioctl |
16.09.2026 |
7.8 |
| CVE-2026-89824 |
drm/panel-edp: fix i2c adapter leak on probe failure |
16.09.2026 |
|
| CVE-2026-89825 |
drm/panthor: fix firmware control interface bounds checks |
16.09.2026 |
7.8 |
| CVE-2026-89826 |
drm/panthor: harden firmware build-info bounds checks |
16.09.2026 |
7.1 |
| CVE-2026-89827 |
drm/amdgpu: avoid force-completing uninitialized UVD rings |
16.09.2026 |
|
| CVE-2026-89828 |
drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() |
16.09.2026 |
|
| CVE-2026-89829 |
f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() |
16.09.2026 |
7.8 |
| CVE-2026-89830 |
f2fs: fix valid block count leak on data block allocation failure |
16.09.2026 |
|
| CVE-2026-89831 |
f2fs: protect critical_task_priority updates with s_umount |
16.09.2026 |
|
| CVE-2026-89832 |
f2fs: fix to clear dirty flag on folio in error path |
16.09.2026 |
7.8 |
| CVE-2026-89833 |
f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() |
16.09.2026 |
|
| CVE-2026-89834 |
f2fs: fix to migrate all curseg types during free_segment_range |
16.09.2026 |
|
| CVE-2026-89835 |
f2fs: avoid NULL checkpoint thread access in sysfs |
16.09.2026 |
|
| CVE-2026-89836 |
f2fs: fix folio_nr_pages() race after put in large folio invalidate |
16.09.2026 |
7.8 |
| CVE-2026-89837 |
f2fs: fix dentry folio leak in find_in_level |
16.09.2026 |
|
| CVE-2026-89838 |
f2fs: limit recovery filename logging to stored length |
16.09.2026 |
7.1 |
| CVE-2026-89839 |
f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() |
16.09.2026 |
|
| CVE-2026-89840 |
f2fs: validate MOVE_RANGE destination size |
16.09.2026 |
7.1 |
| CVE-2026-89841 |
f2fs: only redirty pinned folios in redirty_blocks |
16.09.2026 |
7.8 |
| CVE-2026-89842 |
scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started |
16.09.2026 |
|
| CVE-2026-89843 |
scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak |
16.09.2026 |
|
| CVE-2026-89844 |
scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition |
16.09.2026 |
8.8 |
| CVE-2026-89845 |
scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() |
16.09.2026 |
|
| CVE-2026-89846 |
scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read |
16.09.2026 |
9.1 |
| CVE-2026-89847 |
scsi: qla2xxx: Avoid double completion in async IOCB timeout |
16.09.2026 |
9.8 |
| CVE-2026-89848 |
scsi: qla2xxx: Quiesce response IRQ before freeing request queue |
16.09.2026 |
8.1 |
| CVE-2026-89849 |
scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path |
16.09.2026 |
8.8 |
| CVE-2026-89850 |
scsi: qla2xxx: Don't query firmware state while chip is down |
16.09.2026 |
|
| CVE-2026-89851 |
scsi: qla2xxx: Fix FCE trace enable parsing in debugfs |
16.09.2026 |
|
| CVE-2026-89852 |
scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() |
16.09.2026 |
|
| CVE-2026-89853 |
scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump |
16.09.2026 |
|
| CVE-2026-89854 |
scsi: qla2xxx: Fix cs84xx use-after-free on host teardown |
16.09.2026 |
7.8 |
| CVE-2026-89855 |
scsi: qla2xxx: Serialize flash version read in reset handler |
16.09.2026 |
|
| CVE-2026-89856 |
scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation |
16.09.2026 |
8.4 |
| CVE-2026-89857 |
scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
16.09.2026 |
9.8 |
| CVE-2026-89858 |
scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() |
16.09.2026 |
|
| CVE-2026-89859 |
scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak |
16.09.2026 |
|
| CVE-2026-89860 |
scsi: qla2xxx: Initialize NVMe abort_work once at submission |
16.09.2026 |
8.8 |
| CVE-2026-89861 |
scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() |
16.09.2026 |
8.1 |
| CVE-2026-89862 |
scsi: qla2xxx: Fix BSG job leak on validate flash image error path |
16.09.2026 |
|
| CVE-2026-89863 |
scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check |
16.09.2026 |
7.5 |
| CVE-2026-89864 |
scsi: qla2xxx: Bound i2c->length in I2C bsg handlers |
16.09.2026 |
|
| CVE-2026-89865 |
scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers |
16.09.2026 |
|
| CVE-2026-89866 |
media: chips-media: wave5: Resume device before setting EOS flag |
16.09.2026 |
|
| CVE-2026-89867 |
media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued |
16.09.2026 |
|
| CVE-2026-89868 |
media: chips-media: wave5: Add timeout while stop_streaming |
16.09.2026 |
|
| CVE-2026-89869 |
media: qcom: iris: use disable_irq() during power-off |
16.09.2026 |
|
| CVE-2026-89870 |
media: zoran: Avoid freeing a registered video_device twice |
16.09.2026 |
7.8 |
| CVE-2026-89871 |
media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure |
16.09.2026 |
|
| CVE-2026-89872 |
media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link |
16.09.2026 |
|
| CVE-2026-89873 |
media: v4l2-ctrls: validate HEVC EXT SPS RPS counts |
16.09.2026 |
7.8 |
| CVE-2026-89874 |
media: v4l2-async: avoid deleting unlinked ASC entry on link error |
16.09.2026 |
|
| CVE-2026-89875 |
media: ti: vpe: quiesce overflow recovery before freeing streams |
16.09.2026 |
7.8 |
| CVE-2026-89876 |
media: tda18250: fix possible integer overflow |
16.09.2026 |
|
| CVE-2026-89877 |
media: saa7164: fix cleanup on resource allocation failure |
16.09.2026 |
8.4 |
| CVE-2026-89878 |
media: s2255: check firmware size before reading trailing marker |
16.09.2026 |
|
| CVE-2026-89879 |
media: s2255: bound JPEG frame size before copying into the buffer |
16.09.2026 |
|
| CVE-2026-89880 |
media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure |
16.09.2026 |
7.8 |
| CVE-2026-89881 |
media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak |
16.09.2026 |
|
| CVE-2026-89882 |
media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow |
16.09.2026 |
7.8 |
| CVE-2026-89883 |
media: rc: sunxi-cir: Unregister rc device on probe failure |
16.09.2026 |
7.8 |
| CVE-2026-89884 |
media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup |
16.09.2026 |
|
| CVE-2026-89885 |
media: platform: mtk-mdp3: Fix SCP device refcounting |
16.09.2026 |
8.4 |
| CVE-2026-89886 |
media: intel/ipu6: fix async notifier cleanup leak on parse error |
16.09.2026 |
|
| CVE-2026-89887 |
media: i2c: ov7740: fix use-after-destroy in remove |
16.09.2026 |
7.8 |
| CVE-2026-89888 |
media: i2c: ov02a10: fix endpoint parsing use-after-free |
16.09.2026 |
7.8 |
| CVE-2026-89889 |
media: i2c: imx415: Release runtime PM reference on VBLANK error |
16.09.2026 |
|
| CVE-2026-89890 |
media: go7007: defer the ALSA v4l2 put until card release |
16.09.2026 |
7.8 |
| CVE-2026-89891 |
media: em28xx: fix use-after-free of dev_next->devlist on disconnect |
16.09.2026 |
|
| CVE-2026-89892 |
media: em28xx: defer audio-only extension registration |
16.09.2026 |
|
| CVE-2026-89893 |
media: cx23885: cancel NetUP CI work before teardown |
16.09.2026 |
7.8 |
| CVE-2026-89894 |
media: cx231xx: reject geometry changes while the VBI queue is busy |
16.09.2026 |
7.8 |
| CVE-2026-89895 |
media: cobalt: Avoid freeing ALSA private data twice |
16.09.2026 |
|
| CVE-2026-89896 |
media: cedrus: fix memory leak in cedrus_init_ctrls() |
16.09.2026 |
|
| CVE-2026-89897 |
media: cec: Serialize exclusive follower delivery |
16.09.2026 |
7.5 |
| CVE-2026-89898 |
media: cec: extron-da-hd-4k-plus: add sanity check |
16.09.2026 |
8.8 |
| CVE-2026-89899 |
media: cec: disable delayed work before freeing an interrupted transmit |
16.09.2026 |
7.8 |
| CVE-2026-89900 |
media: cec: core: Fix kmemleak due to missed rc_free_device() call |
16.09.2026 |
|
| CVE-2026-89901 |
media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref |
16.09.2026 |
|
| CVE-2026-89902 |
LoongArch: Avoid preempt count underflow without probe |
16.09.2026 |
7.8 |
| CVE-2026-89903 |
LoongArch: Do not save/restore percpu base register in rethook trampoline |
16.09.2026 |
7.8 |
| CVE-2026-89904 |
LoongArch: Fix acpi_package_ids[] array overflow |
16.09.2026 |
8.4 |
| CVE-2026-89905 |
LoongArch: BPF: Move arena register slot below TCC context |
16.09.2026 |
|
| CVE-2026-89906 |
LoongArch: BPF: Refactor jump offset calculation in tail call |
16.09.2026 |
7.8 |
| CVE-2026-89907 |
LoongArch: KVM: Validate MSI data before routing it to EIOINTC |
16.09.2026 |
8.8 |
| CVE-2026-89908 |
LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY |
16.09.2026 |
8.8 |
| CVE-2026-89909 |
LoongArch: KVM: Free init resources if kvm_init() fails |
16.09.2026 |
|
| CVE-2026-89910 |
LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc |
16.09.2026 |
7.3 |
| CVE-2026-89911 |
KVM: arm64: Correctly cap TLBI Range to the architural limit |
16.09.2026 |
7.9 |
| CVE-2026-89912 |
KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save |
16.09.2026 |
7.1 |
| CVE-2026-89913 |
KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables |
16.09.2026 |
8.8 |
| CVE-2026-89914 |
KVM: arm64: Sign-extend VA for range-based TLBI invalidation |
16.09.2026 |
9.3 |
| CVE-2026-89915 |
KVM: arm64: Remove VM-wide VNCR mapping counter |
16.09.2026 |
9.3 |
| CVE-2026-89916 |
KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry |
16.09.2026 |
9.3 |
| CVE-2026-89917 |
KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping |
16.09.2026 |
|
| CVE-2026-89918 |
KVM: arm64: Correctly handle end of VA space TLBI invalidation |
16.09.2026 |
9.3 |
| CVE-2026-89919 |
KVM: s390: keyop: use mmu_lock to read gmap->asce |
16.09.2026 |
7.8 |
| CVE-2026-89920 |
KVM: s390: Fix memory corruption by not reinjecting CK machine checks |
16.09.2026 |
7.8 |
| CVE-2026-89921 |
KVM: s390: Zero initialize data structures for inject_pfault_token |
16.09.2026 |
|
| CVE-2026-89922 |
KVM: s390: Take srcu when importing watchpoint data |
16.09.2026 |
7.8 |
| CVE-2026-89923 |
KVM: s390: Free guest debug data on vcpu destroy |
16.09.2026 |
|
| CVE-2026-89924 |
KVM: s390: Fix old_data leak in guest debug error path |
16.09.2026 |
|
| CVE-2026-89925 |
KVM: s390: Fix memory leak in guest debug handling |
16.09.2026 |
|
| CVE-2026-89926 |
KVM: s390: Fix length check __import_wp_info() |
16.09.2026 |
|
| CVE-2026-89927 |
KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock |
16.09.2026 |
7.1 |
| CVE-2026-89928 |
KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk |
16.09.2026 |
8.8 |
| CVE-2026-89929 |
KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU |
16.09.2026 |
8.8 |
| CVE-2026-89930 |
KVM: nVMX: Service local TLB flushes on failed nested VM-Enter |
16.09.2026 |
9.3 |
| CVE-2026-89931 |
KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit |
16.09.2026 |
|
| CVE-2026-89932 |
KVM: nVMX: Always flush vpid02 on first use |
16.09.2026 |
8.8 |
| CVE-2026-89933 |
iio: pressure: dps310: fix NULL pointer dereference on ACPI probe |
16.09.2026 |
|
| CVE-2026-89934 |
iio: light: ltrf216a: fix runtime PM reference leak in error path |
16.09.2026 |
|
| CVE-2026-89935 |
iio: light: apds9306: fix PM reference leak in apds9306_read_data() |
16.09.2026 |
|
| CVE-2026-89936 |
iio: dac: m62332: Fix regulator reference count imbalance |
16.09.2026 |
|
| CVE-2026-89937 |
iio: chemical: sgp30: Handle IAQ thread creation failure |
16.09.2026 |
|
| CVE-2026-89938 |
iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF |
16.09.2026 |
7.8 |
| CVE-2026-89939 |
iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable |
16.09.2026 |
|
| CVE-2026-89940 |
iio: buffer: Tie IIO dma fence lock lifetime to the fence |
16.09.2026 |
7.8 |
| CVE-2026-89941 |
iio: buffer: Make IIO DMA fence release RCU-safe |
16.09.2026 |
7.8 |
| CVE-2026-89942 |
iio: buffer: Fix potential use-after-free in anonymous buffer release |
16.09.2026 |
7.8 |
| CVE-2026-89943 |
ASoC: loongson: Fix error handling in ACPI property parsing |
16.09.2026 |
8.4 |
| CVE-2026-89944 |
ASoC: hdac_hda: Fix hlink refcount leak on component registration failure |
16.09.2026 |
|
| CVE-2026-89945 |
ASoC: cs35l34: drain threaded IRQ before runtime suspend |
16.09.2026 |
|
| CVE-2026-89946 |
ASoC: cs35l33: drain threaded IRQ before runtime suspend |
16.09.2026 |
|
| CVE-2026-89947 |
clk: meson: align gxbb_32k_clk_sel number of parents with actual count |
16.09.2026 |
8 |
| CVE-2026-89948 |
batman-adv: bla: fix freeing of claims on meshif deletion |
16.09.2026 |
|
| CVE-2026-89949 |
batman-adv: dat: avoid unaligned fault in IP extraction |
16.09.2026 |
|
| CVE-2026-89950 |
batman-adv: mcast: linearize skbuff for packet generation |
16.09.2026 |
|
| CVE-2026-89951 |
batman-adv: fix stale receive device on merged fragments |
16.09.2026 |
8.8 |
| CVE-2026-89952 |
mtd: rawnand: validate ONFI extended parameter page sections |
16.09.2026 |
|
| CVE-2026-89953 |
mtd: mtdoops: free page bitmap when the backing MTD is removed |
16.09.2026 |
|
| CVE-2026-89954 |
mtd: afs: validate v2 image info bounds |
16.09.2026 |
8 |
| CVE-2026-89955 |
s390/vfio-ap: Fix NULL deref in status_show() during queue probe |
16.09.2026 |
|
| CVE-2026-89956 |
s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects |
16.09.2026 |
|
| CVE-2026-89957 |
s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed |
16.09.2026 |
8.8 |
| CVE-2026-89958 |
s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL |
16.09.2026 |
|
| CVE-2026-89959 |
s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove |
16.09.2026 |
8.8 |
| CVE-2026-89960 |
s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() |
16.09.2026 |
8.8 |
| CVE-2026-89961 |
powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population |
16.09.2026 |
7.8 |
| CVE-2026-89962 |
powerpc/kexec_file: Prevent kexec range truncation |
16.09.2026 |
|
| CVE-2026-89963 |
powerpc/kexec_file: Fix null-ptr-def in extra size calculation |
16.09.2026 |
|
| CVE-2026-89964 |
parisc: eisa: Fix infinite loop when parsing invalid IRQ value |
16.09.2026 |
|
| CVE-2026-89965 |
nvdimm/btt: reject an arena whose nfree is below the lane count |
16.09.2026 |
7.8 |
| CVE-2026-89966 |
mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio |
16.09.2026 |
|
| CVE-2026-89967 |
mm/migrate_device: avoid out-of-bounds writes for compound folios |
16.09.2026 |
7.8 |
| CVE-2026-89968 |
nvmet-tcp: reject unsolicited H2CData PDUs |
16.09.2026 |
7.5 |
| CVE-2026-89969 |
nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
16.09.2026 |
9.8 |
| CVE-2026-89970 |
nvmet-auth: Synchronize timeout work during SQ teardown |
16.09.2026 |
9.8 |
| CVE-2026-89971 |
nvme: skip the zoned limits update if the zone info query failed |
16.09.2026 |
7.5 |
| CVE-2026-89972 |
nvme: add missing SRCU grace period in error path |
16.09.2026 |
9.8 |
| CVE-2026-89973 |
nvme-tcp: check the data direction of a C2HData PDU |
16.09.2026 |
8.2 |
| CVE-2026-89974 |
nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails |
16.09.2026 |
7.5 |
| CVE-2026-89975 |
nvme-fabrics: fix DHCHAP secret leak on parse failure |
16.09.2026 |
|
| CVE-2026-89976 |
accel/ethosu: fix job completion fence cleanup |
16.09.2026 |
|
| CVE-2026-89977 |
accel/ethosu: check MMIO mapping errors in probe |
16.09.2026 |
|
| CVE-2026-89978 |
accel/amdxdna: return early from a zero-length flush |
16.09.2026 |
|
| CVE-2026-89979 |
ALSA: pcm: Fix race between non-atomic ops and trigger-start |
16.09.2026 |
7.8 |
| CVE-2026-89980 |
ALSA: harmony: initialize locks before requesting IRQ |
16.09.2026 |
8.4 |
| CVE-2026-89981 |
arm64: Don't read GMID_EL1 when MTE is disabled |
16.09.2026 |
|
| CVE-2026-89982 |
i2c: mux: Fix channel node leak on adapter add failure |
16.09.2026 |
|
| CVE-2026-89983 |
i2c: core: fix debugfs UAF on adapter removal |
16.09.2026 |
|
| CVE-2026-89984 |
perf/x86/intel: Fix kernel address leakages in LBR stack |
16.09.2026 |
|
| CVE-2026-89985 |
memcg: keep folio's objcg same as its node |
16.09.2026 |
7.8 |
| CVE-2026-89986 |
mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() |
16.09.2026 |
7.8 |
| CVE-2026-89987 |
mm/huge_memory: transfer the pmd dirty bit to the folio on zap |
16.09.2026 |
|
| CVE-2026-89988 |
kprobes: Protect kprobe_blacklist with RCU |
16.09.2026 |
7.8 |
| CVE-2026-89989 |
ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() |
16.09.2026 |
|
| CVE-2026-89990 |
ceph: lock mutex in ceph_mds_check_access() |
16.09.2026 |
9.8 |
| CVE-2026-89991 |
bpf: Fix infinite loop in pcpu_freelist push with one possible CPU |
16.09.2026 |
|
| CVE-2026-89992 |
cpuidle: dt_idle_genpd: kfree() the original name allocation |
16.09.2026 |
8.4 |
| CVE-2026-89993 |
dmaengine: dw-edma: Initialize IRQ data before requesting IRQs |
16.09.2026 |
|
| CVE-2026-89994 |
dmaengine: fsl-edma: tracing: no ptr dereference during log output |
16.09.2026 |
7.8 |
| CVE-2026-89995 |
dma-direct: return struct page from dma_direct_alloc_from_pool() |
16.09.2026 |
8.8 |
| CVE-2026-89996 |
dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds |
16.09.2026 |
|
| CVE-2026-89997 |
dm: fix resume-vs-remove race |
16.09.2026 |
7.8 |
| CVE-2026-89998 |
dm: fix race when loading and unloading a table |
16.09.2026 |
7.8 |
| CVE-2026-89999 |
HID: wacom: validate report length in wacom_intuos_pro2_bt_irq |
16.09.2026 |
8.1 |
| CVE-2026-90000 |
HID: rmi: fix OOB access with undersized RMI reports |
16.09.2026 |
8.8 |
| CVE-2026-90001 |
HID: bpf: serialize device reference release in struct_ops destroy path |
16.09.2026 |
7.8 |
| CVE-2026-90002 |
ftrace: Take trace_array reference before accessing its ftrace_ops |
16.09.2026 |
7.8 |
| CVE-2026-90003 |
futex: Prevent rcuwait use-after-free during requeue PI |
16.09.2026 |
7.8 |
| CVE-2026-90004 |
mm/damon/core: handle region split failure in apply_min_nr_regions() |
16.09.2026 |
|
| CVE-2026-90005 |
samples/damon/wsse: handle damon_start() failure |
16.09.2026 |
|
| CVE-2026-90006 |
samples/damon/mtier: handle damon_stop() failure |
16.09.2026 |
|
| CVE-2026-90007 |
scsi: pm8001: Use rollback index when freeing MSI-X vectors |
16.09.2026 |
7.8 |
| CVE-2026-90008 |
scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame |
16.09.2026 |
7.8 |
| CVE-2026-90009 |
scsi: bsg: Fix TOCTOU in io_uring passthrough command setup |
16.09.2026 |
7.8 |
| CVE-2026-90010 |
scsi: bsg: Cap io_uring sense copy to max_response_len |
16.09.2026 |
7.8 |
| CVE-2026-90011 |
scsi: target: iscsi: Reserve a terminator byte for the login payload |
16.09.2026 |
9.1 |
| CVE-2026-90012 |
spi: Fix DMA mapping ownership on partial map failure |
16.09.2026 |
9.8 |
| CVE-2026-90013 |
tracing: Take trace_array reference when opening options file |
16.09.2026 |
7.8 |
| CVE-2026-90014 |
tracing: Have show_event_filters/triggers files take trace array ref |
16.09.2026 |
7.8 |
| CVE-2026-90015 |
xhci: fix lost bounce buffers on TDs spanning several ring segments |
16.09.2026 |
|
| CVE-2026-90016 |
staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() |
16.09.2026 |
7.1 |
| CVE-2026-90017 |
staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() |
16.09.2026 |
7.1 |
| CVE-2026-90018 |
staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() |
16.09.2026 |
8.8 |
| CVE-2026-90019 |
usb: gadget: fix null pointer dereference in usb_put_function_instance() |
16.09.2026 |
|
| CVE-2026-90020 |
USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() |
16.09.2026 |
|
| CVE-2026-90021 |
usb: gadget: f_midi: initialize work in f_midi_alloc() |
16.09.2026 |
|
| CVE-2026-90022 |
usb: gadget: f_midi2: fix use-after-free in string attribute show path |
16.09.2026 |
7.8 |
| CVE-2026-90023 |
usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() |
16.09.2026 |
|
| CVE-2026-90024 |
usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs |
16.09.2026 |
|
| CVE-2026-90025 |
usb: typec: ucsi: displayport: Fix OOB altmode array index |
16.09.2026 |
7.7 |
| CVE-2026-90026 |
usb: typec: qcom-pmic: cancel reset_work on stop |
16.09.2026 |
7.8 |
| CVE-2026-90027 |
usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop |
16.09.2026 |
7.8 |
| CVE-2026-90028 |
usb: typec: hd3ss3220: track VBUS enable state per consumer |
16.09.2026 |
|
| CVE-2026-90029 |
usb: storage: realtek_cr: fix use-after-free on disconnect |
16.09.2026 |
|
| CVE-2026-90030 |
usb: dwc3: clear forceRM when issuing EndTransfer |
16.09.2026 |
7.8 |
| CVE-2026-90031 |
usb-storage: ene_ub6250: fix race between scan work and probe |
16.09.2026 |
|
| CVE-2026-90032 |
media: usbtv: keep device alive while ALSA card exists |
16.09.2026 |
7.8 |
| CVE-2026-90033 |
ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() |
16.09.2026 |
|
| CVE-2026-90034 |
usb: image: mdc800: change kmalloc() to kzalloc() |
16.09.2026 |
|
| CVE-2026-90035 |
drm/amd/display: fix division by zero in get_estimated_bw() |
16.09.2026 |
|
| CVE-2026-90036 |
NFSD: Prevent client use-after-free during blocked-lock reaping |
16.09.2026 |
9.8 |
| CVE-2026-90037 |
NFSD: Prevent client use-after-free during close_lru reaping |
16.09.2026 |
9.8 |
| CVE-2026-90038 |
NFSD: Prevent client use-after-free during export state revocation |
16.09.2026 |
9.8 |
| CVE-2026-90039 |
NFSD: Guard admin state-revocation walks with NFSD_NET_UP |
16.09.2026 |
|
| CVE-2026-90040 |
KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped |
16.09.2026 |
|
| CVE-2026-90041 |
HID: sony: clean up device list on probe failure |
16.09.2026 |
8.8 |
| CVE-2026-90042 |
ceph: properly decrypt filenames in vmalloc() buffers |
16.09.2026 |
9.8 |
| CVE-2026-90043 |
zram: fix slot lock bit position on big-endian 64-bit |
16.09.2026 |
7.8 |
| CVE-2026-90044 |
usb: gadget: f_fs: Fix Use-After-Free in AIO error path |
16.09.2026 |
7.8 |
| CVE-2026-90045 |
USB: gadget: ffs: fix mm lifetime handling |
16.09.2026 |
7.8 |
| CVE-2026-90046 |
mm/page_alloc: don't spin_trylock() in NMI on UP |
16.09.2026 |
7.8 |
| CVE-2026-90047 |
drm/xe: Don't hand out the flat CCS storage as usable VRAM |
16.09.2026 |
7.8 |
| CVE-2026-90048 |
fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
16.09.2026 |
9.8 |
| CVE-2026-90049 |
net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() |
16.09.2026 |
9.3 |
| CVE-2026-14916 |
Kong API Gateway Enterprise: JWT Algorithm-Confusion |
16.09.2026 |
|
| CVE-2026-86106 |
Security Advisory 0179 |
16.09.2026 |
9.6 |
| CVE-2026-86585 |
Improper Verification of the Firmware Signature vulnerability |
16.09.2026 |
|
| CVE-2026-8462 |
OpenMeter SQL Injection in ClickHouse-backed Meter Definitions |
16.09.2026 |
|
| CVE-2026-92356 |
a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption |
16.09.2026 |
|
| CVE-2026-14917 |
Kong API Gateway Enterprise: SAML Authentication bypass |
16.09.2026 |
|
| CVE-2026-76151 |
Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module) |
16.09.2026 |
|
| CVE-2026-77190 |
Security Advisory 0177 |
16.09.2026 |
6.5 |
| CVE-2026-86474 |
Improper Certificate Validation in the Firmware Download vulnerability |
16.09.2026 |
|
| CVE-2026-73440 |
Security Advisory 0178 |
16.09.2026 |
4.2 |
| CVE-2026-73468 |
Security Advisory 0175 |
16.09.2026 |
6.5 |
| CVE-2026-73469 |
Security Advisory 0176 |
16.09.2026 |
5.8 |
| CVE-2026-89793 |
ublk: clear VM_MAYWRITE on read-only ublk char device mmap |
16.09.2026 |
7.8 |
| CVE-2026-73453 |
Security Advisory 0174 |
17.09.2026 |
10 |
| CVE-2026-73455 |
Security Advisory 0173 |
16.09.2026 |
7.5 |
| CVE-2026-73438 |
Security Advisory 0172 |
16.09.2026 |
5.3 |
| CVE-2026-85628 |
Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability |
16.09.2026 |
|
| CVE-2026-59739 |
Apache ZooKeeper: Information disclosure via SetWatches reconnect replay |
16.09.2026 |
|
| CVE-2026-59969 |
Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode |
16.09.2026 |
|
| CVE-2026-79993 |
Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode |
16.09.2026 |
|
| CVE-2026-84439 |
Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources |
16.09.2026 |
|
| CVE-2026-84501 |
Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider |
16.09.2026 |
|
| CVE-2026-19640 |
Security Advisory 0170 |
16.09.2026 |
4.2 |
| CVE-2026-73435 |
Security Advisory 0171 |
16.09.2026 |
8.2 |
| CVE-2026-73436 |
Security Advisory 0171 |
16.09.2026 |
6.5 |
| CVE-2026-76186 |
Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity |
16.09.2026 |
|
| CVE-2026-76187 |
Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT |
16.09.2026 |
|
| CVE-2026-82310 |
Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access |
16.09.2026 |
|
| CVE-2026-86443 |
Cleartext Storage of Sensitive Information Vulnerability |
16.09.2026 |
|
| CVE-2026-86466 |
Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated |
16.09.2026 |
|
| CVE-2026-86792 |
Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration |
16.09.2026 |
|
| CVE-2026-73445 |
Security Advisory 0167 |
16.09.2026 |
4.9 |
| CVE-2026-73463 |
Security Advisory 0169 |
16.09.2026 |
5.3 |
| CVE-2026-82311 |
Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false |
16.09.2026 |
|
| CVE-2026-86462 |
Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions |
16.09.2026 |
|
| CVE-2026-86465 |
Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key |
16.09.2026 |
|
| CVE-2026-92081 |
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses |
16.09.2026 |
5.9 |
| CVE-2026-2380 |
Security Advisory 0168 |
16.09.2026 |
7.4 |
| CVE-2026-89776 |
vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes |
16.09.2026 |
|
| CVE-2026-89777 |
vfio/pci: clear vdev->msi_perm after freeing it on init failure |
16.09.2026 |
8.8 |
| CVE-2026-89778 |
isofs: fix out-of-bounds page array access on empty zisofs block |
16.09.2026 |
9.8 |
| CVE-2026-89779 |
fs/ntfs3: validate ef->size covers the record's name and value |
16.09.2026 |
9.1 |
| CVE-2026-89780 |
net: qualcomm: rmnet: restore skb->dev on deaggregated frames |
16.09.2026 |
|
| CVE-2026-89781 |
fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() |
16.09.2026 |
8.4 |
| CVE-2026-89782 |
fs/ntfs3: reject restart table growth beyond U16_MAX entries |
16.09.2026 |
8.4 |
| CVE-2026-89783 |
xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
16.09.2026 |
9.8 |
| CVE-2026-89784 |
SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6 |
16.09.2026 |
|
| CVE-2026-89785 |
fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init |
16.09.2026 |
|
| CVE-2026-89786 |
ext4: fix out-of-bounds read in ext4_read_inline_dir() |
16.09.2026 |
9.1 |
| CVE-2026-89787 |
ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() |
16.09.2026 |
|
| CVE-2026-89788 |
ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
16.09.2026 |
9.8 |
| CVE-2026-89789 |
gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free |
16.09.2026 |
7.8 |
| CVE-2026-89790 |
ipv6: avoid divide by zero in rt6_multipath_rebalance |
16.09.2026 |
|
| CVE-2026-89791 |
perf: Fix use-after-free when perf mmap() revival races with the last munmap() |
16.09.2026 |
7.8 |
| CVE-2026-89792 |
ksmbd: prevent out-of-bounds reads in share config responses |
16.09.2026 |
7.1 |
| CVE-2026-73464 |
Security Advisory 0166 |
17.09.2026 |
8.8 |
| CVE-2026-77860 |
'serve-expired' can bypass Unbound 'wait-limit' |
16.09.2026 |
3.7 |
| CVE-2026-77955 |
Possible ZONEMD verification bypass window |
16.09.2026 |
4.4 |
| CVE-2026-78227 |
Use-after-free in DoQ stream output buffer on reset re-transmission |
16.09.2026 |
6.5 |
| CVE-2026-80225 |
Possible degradation of service from continuous queries on the same TCP/DoT connection |
16.09.2026 |
5.3 |
| CVE-2026-81634 |
Possible heap buffer overflow during DNSSEC canonicalization |
16.09.2026 |
7.5 |
| CVE-2026-81642 |
Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY |
16.09.2026 |
|
| CVE-2026-82717 |
CNAME synthesis could lead to heap corruption |
16.09.2026 |
|
| CVE-2026-82720 |
Use-after-free in DoH stream cleanup code path |
16.09.2026 |
5.9 |
| CVE-2026-85501 |
Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC |
16.09.2026 |
5.3 |
| CVE-2026-86338 |
Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an information-disclosure oracle |
16.09.2026 |
|
| CVE-2026-89775 |
KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
16.09.2026 |
9.3 |
| CVE-2026-73454 |
Security Advisory 0165 |
17.09.2026 |
8.1 |
| CVE-2026-88255 |
mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot |
16.09.2026 |
|
| CVE-2026-89186 |
mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches |
16.09.2026 |
|
| CVE-2026-89774 |
Bluetooth: SCO: hold sk properly in sco_conn_ready |
16.09.2026 |
8.8 |