| CVE-2026-3869 |
|
11.09.2026 |
9.2 |
| CVE-2026-89010 |
WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server |
11.09.2026 |
9.3 |
| CVE-2026-38056 |
ST Engineering iDirect iQ-Series Terminals Missing Authorization |
11.09.2026 |
9.4 |
| CVE-2026-87987 |
|
11.09.2026 |
10 |
| CVE-2026-87988 |
|
11.09.2026 |
10 |
| CVE-2026-87983 |
|
11.09.2026 |
9.2 |
| CVE-2026-87984 |
|
11.09.2026 |
9.3 |
| CVE-2026-87985 |
|
11.09.2026 |
10 |
| CVE-2026-87986 |
|
11.09.2026 |
10 |
| CVE-2026-89212 |
XML External Entity in Akana API Platform |
11.09.2026 |
9.2 |
| CVE-2026-80462 |
Privilege Escalation in Progress Chef Automate |
11.09.2026 |
10 |
| CVE-2026-84390 |
|
11.09.2026 |
9.6 |
| CVE-2026-89243 |
WWBN AVideo Stored XSS via UserGroups setGroup_name |
11.09.2026 |
9.2 |
| CVE-2026-89249 |
AVideo YPTWallet Stored XSS via CryptoWallet Configuration |
11.09.2026 |
9.3 |
| CVE-2026-89253 |
AVideo Stored XSS via donationLink in watch page button |
11.09.2026 |
9.3 |
| CVE-2026-89254 |
AVideo CustomizeUser Stored XSS via field_name Parameter |
11.09.2026 |
9.3 |
| CVE-2026-89255 |
AVideo LoginControl Stored XSS via PGP Public Key |
11.09.2026 |
9.3 |
| CVE-2026-89256 |
AVideo Bookmark Plugin Stored XSS via Chapter Names |
11.09.2026 |
9.3 |
| CVE-2026-89258 |
Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get |
11.09.2026 |
9.3 |
| CVE-2026-89259 |
Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS |
11.09.2026 |
9.3 |
| CVE-2026-47839 |
Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin |
11.09.2026 |
9.2 |
| CVE-2026-8778 |
MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload |
11.09.2026 |
9.8 |
| CVE-2026-19646 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
10.09.2026 |
9.1 |
| CVE-2026-78573 |
IBM ContextForge MCP Gateway is affected by use of default credentials |
10.09.2026 |
9.8 |
| CVE-2026-79724 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
10.09.2026 |
9.8 |
| CVE-2026-80424 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
10.09.2026 |
9.1 |
| CVE-2026-81204 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
11.09.2026 |
9.8 |
| CVE-2026-82100 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
11.09.2026 |
9.6 |
| CVE-2026-82107 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
11.09.2026 |
9.6 |
| CVE-2026-45764 |
Suricata http2: protocol-change type confusion can lead to denial of service |
11.09.2026 |
9.1 |
| CVE-2026-75940 |
|
11.09.2026 |
9.3 |
| CVE-2026-85025 |
Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards |
11.09.2026 |
9.8 |
| CVE-2026-89094 |
|
10.09.2026 |
9.9 |
| CVE-2026-89086 |
|
10.09.2026 |
9.1 |
| CVE-2026-88062 |
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) |
10.09.2026 |
9.5 |
| CVE-2026-89042 |
passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification |
10.09.2026 |
9.3 |
| CVE-2026-89043 |
passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending |
10.09.2026 |
9.1 |
| CVE-2026-65638 |
|
10.09.2026 |
9.2 |
| CVE-2026-65639 |
|
10.09.2026 |
9.5 |
| CVE-2026-68487 |
|
10.09.2026 |
9.9 |
| CVE-2026-68488 |
|
10.09.2026 |
9.9 |
| CVE-2026-88044 |
rclone: RC per-server auth-proxy bypass |
10.09.2026 |
9.1 |
| CVE-2026-88018 |
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass |
10.09.2026 |
9.8 |
| CVE-2026-81046 |
|
11.09.2026 |
9.4 |
| CVE-2026-81467 |
|
11.09.2026 |
9.8 |
| CVE-2026-81468 |
|
11.09.2026 |
9.1 |
| CVE-2026-81048 |
|
11.09.2026 |
9.6 |
| CVE-2026-88899 |
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header |
11.09.2026 |
9.3 |
| CVE-2026-88007 |
Traefik HTTP/3 Backend NTLM Connection Reuse |
10.09.2026 |
9.1 |
| CVE-2026-81800 |
WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability |
10.09.2026 |
9.3 |
| CVE-2026-88860 |
Capgo Authorization Bypass via Stale Channel Permission Overrides |
10.09.2026 |
9.3 |
| CVE-2026-88864 |
Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
10.09.2026 |
9.3 |
| CVE-2026-88866 |
WWBN AVideo LoginControl Stored XSS via User-Agent Header |
10.09.2026 |
9.3 |
| CVE-2026-88867 |
WWBN AVideo Stored XSS via Category Name and Icon Class |
10.09.2026 |
9.3 |
| CVE-2026-88868 |
AVideo LiveLinks Stored XSS via title and description fields |
10.09.2026 |
9.3 |
| CVE-2026-88869 |
AVideo AD_Server Stored XSS via log.php label parameter |
10.09.2026 |
9.3 |
| CVE-2026-88877 |
Traefik v3.7.0 Authentication Bypass via from-to-www-redirect |
10.09.2026 |
9.3 |
| CVE-2026-88880 |
Renovate before 44.11.3 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-88881 |
Renovate before 44.11.3 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-88882 |
Renovate before 44.11.2 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-88887 |
Renovate before 44.11.2 Credential Exfiltration via Link Header |
10.09.2026 |
9.2 |
| CVE-2026-9163 |
SQLi in GIS Informatics' GisLab Laboratory Management System |
10.09.2026 |
9.8 |
| CVE-2026-78082 |
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 |
11.09.2026 |
9.3 |
| CVE-2026-8323 |
Open Redirect in Armiya Information Technologies' Access Control System |
10.09.2026 |
9.3 |
| CVE-2026-13745 |
Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables |
10.09.2026 |
9.2 |
| CVE-2026-44950 |
fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 |
10.09.2026 |
9.5 |
| CVE-2026-59679 |
fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 |
10.09.2026 |
9.2 |
| CVE-2026-88278 |
GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay |
10.09.2026 |
9.8 |
| CVE-2026-88285 |
GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service |
10.09.2026 |
9.4 |
| CVE-2026-7188 |
SQLi in Armiya Information Technologies' Access Control System |
10.09.2026 |
9.8 |
| CVE-2026-19583 |
Velociraptor Required Permissions bypass by using client monitoring queries |
11.09.2026 |
9.9 |
| CVE-2026-18351 |
Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter |
10.09.2026 |
9.8 |
| CVE-2026-87931 |
Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow |
10.09.2026 |
9.4 |
| CVE-2026-88069 |
Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis |
10.09.2026 |
9.3 |
| CVE-2026-87911 |
Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server |
10.09.2026 |
9 |
| CVE-2026-54694 |
NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover |
10.09.2026 |
9.6 |
| CVE-2026-87929 |
MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key |
09.09.2026 |
9.3 |
| CVE-2026-87930 |
MaxSite CMS through 109.6 PHP Object Injection via ci_session |
09.09.2026 |
9.2 |
| CVE-2026-47156 |
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator |
10.09.2026 |
9.3 |
| CVE-2026-67401 |
|
10.09.2026 |
9.9 |
| CVE-2026-67403 |
|
09.09.2026 |
9 |
| CVE-2026-68484 |
|
09.09.2026 |
9 |
| CVE-2026-22590 |
Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage |
09.09.2026 |
9.1 |
| CVE-2026-85102 |
Improper Certificate Validation in Quantum Security Gateway |
10.09.2026 |
9.8 |
| CVE-2026-85103 |
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding |
10.09.2026 |
9.8 |
| CVE-2026-80172 |
|
11.09.2026 |
9.8 |
| CVE-2026-87806 |
Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password |
09.09.2026 |
9.1 |
| CVE-2026-87827 |
KGUARD DVR unauthenticated remote command execution vulnerability |
09.09.2026 |
10 |
| CVE-2026-85978 |
Unauthenticated Remote Code Execution in Akana API Platform |
09.09.2026 |
10 |
| CVE-2026-16272 |
Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module |
09.09.2026 |
9.1 |
| CVE-2026-79696 |
Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist |
09.09.2026 |
10 |
| CVE-2026-21095 |
|
11.09.2026 |
9.2 |
| CVE-2026-21096 |
|
11.09.2026 |
9.2 |
| CVE-2026-21102 |
|
11.09.2026 |
9.3 |
| CVE-2026-53939 |
OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption |
09.09.2026 |
9.1 |
| CVE-2026-53581 |
ntp: write path traversal |
09.09.2026 |
9 |
| CVE-2026-85982 |
Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector |
10.09.2026 |
9 |
| CVE-2026-84197 |
|
09.09.2026 |
9.2 |
| CVE-2026-19232 |
Adobe Experience Manager | Incorrect Authorization (CWE-863) |
10.09.2026 |
9.9 |
| CVE-2026-86464 |
|
09.09.2026 |
9.9 |
| CVE-2026-48273 |
ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) |
09.09.2026 |
9.9 |
| CVE-2026-75746 |
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
09.09.2026 |
9.1 |
| CVE-2026-84869 |
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions |
11.09.2026 |
9.9 |
| CVE-2026-28659 |
|
09.09.2026 |
10 |
| CVE-2026-49883 |
|
10.09.2026 |
10 |
| CVE-2026-82004 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
08.09.2026 |
10 |
| CVE-2026-66302 |
Skype for Business Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-76200 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
09.09.2026 |
9.3 |
| CVE-2026-76201 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
09.09.2026 |
9.3 |
| CVE-2026-65669 |
Microsoft SQL Server Elevation of Privilege Vulnerability |
10.09.2026 |
9.6 |
| CVE-2026-68839 |
Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69276 |
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69356 |
Microsoft Exchange Server Spoofing Vulnerability |
10.09.2026 |
9.3 |
| CVE-2026-69408 |
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69431 |
Telnet Client Remote Code Execution Vulnerability |
11.09.2026 |
9.8 |
| CVE-2026-69463 |
Windows NTFS Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69491 |
Microsoft DirectMusic Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69493 |
Windows Event Logging Service Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69496 |
Windows Compressed Folder Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69525 |
Remote Desktop Services Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69579 |
Windows Message Queuing Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69586 |
Microsoft Windows PDF Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69590 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69595 |
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69641 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
10.09.2026 |
9.1 |
| CVE-2026-69715 |
Windows Direct Show Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69730 |
Windows DNS Server Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69768 |
Windows RNDIS Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69769 |
Windows HTTP Print Provider Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69819 |
RPC Runtime Library Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69824 |
Microsoft Standard XPS Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69829 |
Windows Shell Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69845 |
Windows DHCP Server Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-69854 |
Spring Cloud Azure Elevation of Privilege Vulnerability |
10.09.2026 |
9 |
| CVE-2026-69910 |
Windows Hyper-V Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-70296 |
Windows Imaging Component Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-72979 |
Windows DHCP Server Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-72982 |
Windows Netlogon Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-72983 |
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-73009 |
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-73010 |
Microsoft Failover Cluster Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-73025 |
Windows iSCSI Security Feature Bypass Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-77493 |
Windows Graphics Component Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-78445 |
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-78509 |
Microsoft Office Outlook Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-78510 |
Microsoft Word Remote Code Execution Vulnerability |
10.09.2026 |
9.8 |
| CVE-2026-81376 |
Visual Studio Code Security Feature Bypass Vulnerability |
10.09.2026 |
9.6 |
| CVE-2026-83941 |
Entra ID Elevation of Privilege Vulnerability |
10.09.2026 |
9.9 |
| CVE-2026-82533 |
DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing |
10.09.2026 |
9.4 |
| CVE-2026-82067 |
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup |
08.09.2026 |
9.2 |
| CVE-2026-86729 |
WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize |
10.09.2026 |
9.1 |
| CVE-2026-86738 |
Snipe-IT before 8.7.0 CSS Injection via Custom CSS |
08.09.2026 |
9.3 |
| CVE-2026-12647 |
|
09.09.2026 |
9.9 |
| CVE-2026-12645 |
|
09.09.2026 |
9.9 |
| CVE-2026-12646 |
|
09.09.2026 |
9.9 |
| CVE-2026-12650 |
|
09.09.2026 |
9.9 |
| CVE-2026-12744 |
|
09.09.2026 |
9.8 |
| CVE-2026-12745 |
|
09.09.2026 |
9.8 |
| CVE-2026-61516 |
Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint |
08.09.2026 |
9.3 |
| CVE-2026-73309 |
XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint |
09.09.2026 |
9.1 |
| CVE-2026-73311 |
XenForo < 2.3.13 OAuth2 Authorization Code Reuse |
10.09.2026 |
9.1 |
| CVE-2026-73312 |
XenForo < 2.3.13 Refresh Token Replay via Expired Access Token |
09.09.2026 |
9.1 |
| CVE-2026-77089 |
Command Center API Authentication Bypass |
09.09.2026 |
9.3 |
| CVE-2026-78234 |
Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users |
08.09.2026 |
9.9 |
| CVE-2026-62645 |
|
08.09.2026 |
9.3 |
| CVE-2026-62646 |
|
10.09.2026 |
9.1 |
| CVE-2026-62647 |
|
08.09.2026 |
9.3 |
| CVE-2026-67367 |
|
09.09.2026 |
9.2 |
| CVE-2026-71376 |
OS Command Injection Vulnerability in Cosminexus Component Container |
08.09.2026 |
9.8 |
| CVE-2026-71377 |
Command Argument Injection Vulnerability in Cosminexus Component Container |
08.09.2026 |
9.8 |
| CVE-2026-71374 |
Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container |
08.09.2026 |
9.8 |
| CVE-2026-86510 |
D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write |
08.09.2026 |
9.4 |
| CVE-2026-86509 |
D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow |
08.09.2026 |
9.4 |
| CVE-2026-44756 |
Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing |
08.09.2026 |
10 |
| CVE-2026-58240 |
Missing Authentication check in SAP NetWeaver (Message Server) |
09.09.2026 |
9.8 |
| CVE-2026-66768 |
Improper Access Control in SAP NetWeaver (SAP GUI for Java) |
09.09.2026 |
9 |
| CVE-2026-76969 |
Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) |
08.09.2026 |
9.4 |
| CVE-2026-86543 |
knowns before 0.30.0 Unauthenticated Management API Exposure |
11.09.2026 |
9.3 |
| CVE-2026-75650 |
Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) |
09.09.2026 |
10 |
| CVE-2026-86478 |
|
09.09.2026 |
9.8 |
| CVE-2026-86480 |
|
09.09.2026 |
9.8 |
| CVE-2026-18922 |
389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property |
08.09.2026 |
9.8 |
| CVE-2026-7861 |
Code Injection in Next4Biz's CSM (Customer Service Management) |
09.09.2026 |
9.8 |
| CVE-2026-80238 |
|
08.09.2026 |
9.3 |
| CVE-2026-86426 |
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion |
08.09.2026 |
9.2 |
| CVE-2026-61410 |
|
09.09.2026 |
9.4 |
| CVE-2026-6223 |
OTP Bypass in Bahçelievler Muncipality's BiHayat App |
08.09.2026 |
9.4 |
| CVE-2026-76578 |
Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci |
08.09.2026 |
9.8 |
| CVE-2026-86299 |
Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection |
07.09.2026 |
9.4 |
| CVE-2026-86297 |
D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one |
09.09.2026 |
9.2 |
| CVE-2026-86296 |
D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow |
08.09.2026 |
10 |
| CVE-2026-79697 |
Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection |
08.09.2026 |
9.4 |
| CVE-2026-79698 |
Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection |
07.09.2026 |
9.4 |
| CVE-2026-16876 |
|
08.09.2026 |
9.3 |
| CVE-2026-86259 |
OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation |
11.09.2026 |
9 |
| CVE-2026-86167 |
Tenda HG10 Boa formgponConf os command injection |
08.09.2026 |
9.4 |
| CVE-2026-86165 |
Tenda HG10 formURL buffer overflow |
08.09.2026 |
9.3 |
| CVE-2026-16310 |
MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter |
07.09.2026 |
9.8 |
| CVE-2026-75816 |
Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier |
07.09.2026 |
9.8 |
| CVE-2026-86218 |
pre-authentication remote code execution |
09.09.2026 |
10 |
| CVE-2026-86153 |
Tenda CP3 Redirect.cpp SetRedirectEnable privileges management |
08.09.2026 |
9.4 |
| CVE-2026-86152 |
Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection |
10.09.2026 |
10 |
| CVE-2026-86151 |
Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection |
05.09.2026 |
9.4 |
| CVE-2026-86149 |
Tenda CP3 NetCheckPing.cpp os command injection |
08.09.2026 |
9.4 |
| CVE-2026-86148 |
Tenda CP3 Kylin system.c SystemAsh os command injection |
08.09.2026 |
9.4 |
| CVE-2026-67276 |
SSH user impersonation possible in Mikrotik RouterOS |
09.09.2026 |
9.2 |
| CVE-2026-86060 |
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
11.09.2026 |
9.2 |
| CVE-2026-86189 |
WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php |
05.09.2026 |
9.3 |
| CVE-2026-86190 |
WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter |
08.09.2026 |
9.3 |
| CVE-2026-86184 |
Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route |
05.09.2026 |
9.3 |
| CVE-2026-10196 |
Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields |
07.09.2026 |
9.8 |
| CVE-2026-86117 |
Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching |
10.09.2026 |
9.2 |
| CVE-2026-86119 |
Webstudio through 0.296.0 SSRF via /cgi proxy routes |
05.09.2026 |
9.2 |
| CVE-2026-86121 |
Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control |
08.09.2026 |
9.3 |
| CVE-2026-86123 |
SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints |
08.09.2026 |
9.4 |
| CVE-2026-86124 |
AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server |
05.09.2026 |
9.3 |
| CVE-2024-11080 |
Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection |
07.09.2026 |
9.8 |
| CVE-2026-13447 |
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery |
07.09.2026 |
9.8 |
| CVE-2026-83627 |
Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log |
07.09.2026 |
9.8 |