CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-3869 11.09.2026 9.2
CVE-2026-89010 WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server 11.09.2026 9.3
CVE-2026-38056 ST Engineering iDirect iQ-Series Terminals Missing Authorization 11.09.2026 9.4
CVE-2026-87987 11.09.2026 10
CVE-2026-87988 11.09.2026 10
CVE-2026-87983 11.09.2026 9.2
CVE-2026-87984 11.09.2026 9.3
CVE-2026-87985 11.09.2026 10
CVE-2026-87986 11.09.2026 10
CVE-2026-89212 XML External Entity in Akana API Platform 11.09.2026 9.2
CVE-2026-80462 Privilege Escalation in Progress Chef Automate 11.09.2026 10
CVE-2026-84390 11.09.2026 9.6
CVE-2026-89243 WWBN AVideo Stored XSS via UserGroups setGroup_name 11.09.2026 9.2
CVE-2026-89249 AVideo YPTWallet Stored XSS via CryptoWallet Configuration 11.09.2026 9.3
CVE-2026-89253 AVideo Stored XSS via donationLink in watch page button 11.09.2026 9.3
CVE-2026-89254 AVideo CustomizeUser Stored XSS via field_name Parameter 11.09.2026 9.3
CVE-2026-89255 AVideo LoginControl Stored XSS via PGP Public Key 11.09.2026 9.3
CVE-2026-89256 AVideo Bookmark Plugin Stored XSS via Chapter Names 11.09.2026 9.3
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get 11.09.2026 9.3
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS 11.09.2026 9.3
CVE-2026-47839 Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin 11.09.2026 9.2
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 10.09.2026 9.1
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 10.09.2026 9.8
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 10.09.2026 9.8
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.1
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 11.09.2026 9.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 11.09.2026 9.1
CVE-2026-75940 11.09.2026 9.3
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 11.09.2026 9.8
CVE-2026-89094 10.09.2026 9.9
CVE-2026-89086 10.09.2026 9.1
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 10.09.2026 9.5
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 10.09.2026 9.3
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026 9.1
CVE-2026-65638 10.09.2026 9.2
CVE-2026-65639 10.09.2026 9.5
CVE-2026-68487 10.09.2026 9.9
CVE-2026-68488 10.09.2026 9.9
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 11.09.2026 9.3
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026 9.1
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 10.09.2026 9.3
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026 9.3
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026 9.3
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 10.09.2026 9.3
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026 9.3
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026 9.3
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026 9.3
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026 9.3
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026 9.3
CVE-2026-8323 Open Redirect in Armiya Information Technologies' Access Control System 10.09.2026 9.3
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables 10.09.2026 9.2
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 10.09.2026 9.5
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 10.09.2026 9.2
CVE-2026-88278 GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay 10.09.2026 9.8
CVE-2026-88285 GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service 10.09.2026 9.4
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 11.09.2026 9.9
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026 9.4
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 10.09.2026 9.3
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 10.09.2026 9
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 10.09.2026 9.6
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 09.09.2026 9.3
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026 9.2
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 10.09.2026 9.3
CVE-2026-67401 10.09.2026 9.9
CVE-2026-67403 09.09.2026 9
CVE-2026-68484 09.09.2026 9
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-80172 11.09.2026 9.8
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026 9.1
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026 10
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026 10
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module 09.09.2026 9.1
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist 09.09.2026 10
CVE-2026-21095 11.09.2026 9.2
CVE-2026-21096 11.09.2026 9.2
CVE-2026-21102 11.09.2026 9.3
CVE-2026-53939 OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption 09.09.2026 9.1
CVE-2026-53581 ntp: write path traversal 09.09.2026 9
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector 10.09.2026 9
CVE-2026-84197 09.09.2026 9.2
CVE-2026-19232 Adobe Experience Manager | Incorrect Authorization (CWE-863) 10.09.2026 9.9
CVE-2026-86464 09.09.2026 9.9
CVE-2026-48273 ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 09.09.2026 9.9
CVE-2026-75746 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 09.09.2026 9.1
CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 11.09.2026 9.9
CVE-2026-28659 09.09.2026 10
CVE-2026-49883 10.09.2026 10
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 08.09.2026 10
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability 10.09.2026 9.6
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 10.09.2026 9.3
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 10.09.2026 9.1
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability 10.09.2026 9
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability 10.09.2026 9.8
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability 10.09.2026 9.6
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability 10.09.2026 9.9
CVE-2026-82533 DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing 10.09.2026 9.4
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup 08.09.2026 9.2
CVE-2026-86729 WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize 10.09.2026 9.1
CVE-2026-86738 Snipe-IT before 8.7.0 CSS Injection via Custom CSS 08.09.2026 9.3
CVE-2026-12647 09.09.2026 9.9
CVE-2026-12645 09.09.2026 9.9
CVE-2026-12646 09.09.2026 9.9
CVE-2026-12650 09.09.2026 9.9
CVE-2026-12744 09.09.2026 9.8
CVE-2026-12745 09.09.2026 9.8
CVE-2026-61516 Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint 08.09.2026 9.3
CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint 09.09.2026 9.1
CVE-2026-73311 XenForo < 2.3.13 OAuth2 Authorization Code Reuse 10.09.2026 9.1
CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token 09.09.2026 9.1
CVE-2026-77089 Command Center API Authentication Bypass 09.09.2026 9.3
CVE-2026-78234 Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users 08.09.2026 9.9
CVE-2026-62645 08.09.2026 9.3
CVE-2026-62646 10.09.2026 9.1
CVE-2026-62647 08.09.2026 9.3
CVE-2026-67367 09.09.2026 9.2
CVE-2026-71376 OS Command Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71377 Command Argument Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 08.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 09.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 09.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 11.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 09.09.2026 10
CVE-2026-86478 09.09.2026 9.8
CVE-2026-86480 09.09.2026 9.8
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026 9.8
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 09.09.2026 9.8
CVE-2026-80238 08.09.2026 9.3
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 08.09.2026 9.2
CVE-2026-61410 09.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 08.09.2026 9.4
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 08.09.2026 9.8
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 07.09.2026 9.4
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 09.09.2026 9.2
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 08.09.2026 10
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection 08.09.2026 9.4
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection 07.09.2026 9.4
CVE-2026-16876 08.09.2026 9.3
CVE-2026-86259 OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation 11.09.2026 9
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 08.09.2026 9.4
CVE-2026-86165 Tenda HG10 formURL buffer overflow 08.09.2026 9.3
CVE-2026-16310 MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter 07.09.2026 9.8
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier 07.09.2026 9.8
CVE-2026-86218 pre-authentication remote code execution 09.09.2026 10
CVE-2026-86153 Tenda CP3 Redirect.cpp SetRedirectEnable privileges management 08.09.2026 9.4
CVE-2026-86152 Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection 10.09.2026 10
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection 05.09.2026 9.4
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection 08.09.2026 9.4
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection 08.09.2026 9.4
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS 09.09.2026 9.2
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 11.09.2026 9.2
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php 05.09.2026 9.3
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter 08.09.2026 9.3
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route 05.09.2026 9.3
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields 07.09.2026 9.8
CVE-2026-86117 Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching 10.09.2026 9.2
CVE-2026-86119 Webstudio through 0.296.0 SSRF via /cgi proxy routes 05.09.2026 9.2
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control 08.09.2026 9.3
CVE-2026-86123 SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints 08.09.2026 9.4
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server 05.09.2026 9.3
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection 07.09.2026 9.8
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 07.09.2026 9.8
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 07.09.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-89013 Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php 11.09.2026
CVE-2026-68497 jackson-databind: unbounded numeric parse in Duration and XMLGregorianCalendar deserialization allows CPU denial of service 11.09.2026 7.5
CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 11.09.2026 8.5
CVE-2026-89012 Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter 11.09.2026
CVE-2026-87122 11.09.2026
CVE-2026-15439 GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection 11.09.2026 6.5
CVE-2026-89260 MoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint 11.09.2026 7.5
CVE-2026-89261 MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints 11.09.2026 6.5
CVE-2026-89262 MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check 11.09.2026 7.5
CVE-2026-89263 MoguBlog through 6.2 Missing Authentication on the Comment Email-Notification Endpoint 11.09.2026 5.3
CVE-2026-89264 MoguBlog through 6.2 Comment Author Spoofing via Request-Body Identity 11.09.2026 4.3
CVE-2026-89265 MoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint 11.09.2026 4.3
CVE-2026-8304 Information Disclosure in TUBITAK BILGEM's Pardus About 11.09.2026 5.5
CVE-2026-3869 11.09.2026
CVE-2026-81861 11.09.2026
CVE-2026-85083 CareCam Pro IP Cameras Use of Hard-coded Credentials 11.09.2026 6.8
CVE-2026-89009 WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server 11.09.2026
CVE-2026-89010 WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server 11.09.2026
CVE-2026-38056 ST Engineering iDirect iQ-Series Terminals Missing Authorization 11.09.2026 8.8
CVE-2026-38058 ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Sphere 11.09.2026 8.1
CVE-2026-8301 OS Command Injection in TUBITAK BILGEM's Pardus-boot-repair 11.09.2026 7.8
CVE-2026-85979 11.09.2026
CVE-2026-87987 11.09.2026
CVE-2026-87988 11.09.2026
CVE-2026-78224 NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference 11.09.2026 8.2
CVE-2026-82578 NextGen Healthcare Mirth Connect Improper Restriction of XML External Entity Reference 11.09.2026 7.5
CVE-2026-87983 11.09.2026
CVE-2026-87984 11.09.2026
CVE-2026-87985 11.09.2026
CVE-2026-87986 11.09.2026
CVE-2026-82583 NextGen Healthcare Mirth Connect SQL Injection 11.09.2026 8.3
CVE-2026-87020 Orthanc DICOM Server Integer Overflow or Wraparound 11.09.2026 8.1
CVE-2026-8303 Privilege Escalation in TUBITAK BILGEM's Pardus-software 11.09.2026 7.8
CVE-2026-15710 Netskope Client Endpoint DLP Kernel Driver Information Leakage 11.09.2026
CVE-2026-71644 11.09.2026
CVE-2026-57842 NetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlen 11.09.2026
CVE-2026-57843 NetBSD mm_open() PK_KMEM Flag Kernel Pointer Information Disclosure 11.09.2026
CVE-2026-71641 11.09.2026
CVE-2026-71416 Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) 11.09.2026 8.8
CVE-2026-89298 Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration get 11.09.2026
CVE-2026-11765 Argument Injection in TUBITAK BILGEM's Pardus Pen 11.09.2026 3.3
CVE-2026-89212 XML External Entity in Akana API Platform 11.09.2026
CVE-2026-80462 Privilege Escalation in Progress Chef Automate 11.09.2026 10
CVE-2026-84390 11.09.2026 9.6
CVE-2026-86793 CVE-2026-86793 11.09.2026
CVE-2024-12145 BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion 11.09.2026 4.3
CVE-2026-87776 compression vulnerable to Denial of Service via memory leak on premature response close 11.09.2026 7.5
CVE-2026-89148 AVideo Open Redirect via playlistSort.php Referer Header 11.09.2026
CVE-2026-89239 WWBN AVideo Reflected XSS via Referer Header Comment Breakout 11.09.2026
CVE-2026-89240 WWBN AVideo Reflected XSS via confirmLivePassword.php 11.09.2026
CVE-2026-89241 WWBN AVideo Reflected XSS via confirmLivePassword.php 11.09.2026
CVE-2026-89242 WWBN AVideo Unauthenticated SSRF via login.json.php 11.09.2026
CVE-2026-89243 WWBN AVideo Stored XSS via UserGroups setGroup_name 11.09.2026
CVE-2026-89244 WWBN AVideo Reflected XSS via Gallery Category getBackURL 11.09.2026
CVE-2026-89245 WWBN AVideo Cross-Site Request Forgery via playlistRemove.php 11.09.2026
CVE-2026-89246 WWBN AVideo CSV Formula Injection via myComments.download.php 11.09.2026
CVE-2026-89247 WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php 11.09.2026
CVE-2026-89248 AVideo WebRTC Plugin Information Disclosure via status.json.php 11.09.2026
CVE-2026-89249 AVideo YPTWallet Stored XSS via CryptoWallet Configuration 11.09.2026
CVE-2026-89250 WWBN AVideo Unauthenticated File Read via getRecordedFile.php 11.09.2026
CVE-2026-89251 AVideo Missing Authorization via AD_Server log.php Wallet Credit 11.09.2026
CVE-2026-89252 AVideo Missing Authorization in addLiveLink.php LiveLink Update 11.09.2026
CVE-2026-89253 AVideo Stored XSS via donationLink in watch page button 11.09.2026
CVE-2026-89254 AVideo CustomizeUser Stored XSS via field_name Parameter 11.09.2026
CVE-2026-89255 AVideo LoginControl Stored XSS via PGP Public Key 11.09.2026
CVE-2026-89256 AVideo Bookmark Plugin Stored XSS via Chapter Names 11.09.2026
CVE-2026-89257 AVideo through 29.0 Cross-User Category Asset Deletion via Missing Ownership Check 11.09.2026
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get 11.09.2026
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS 11.09.2026
CVE-2026-82213 Nexi XPay Build 7.6.1 - 7.6.2 - Unauthenticated Saved Payment Token Disclosure via IDOR 11.09.2026 5.3
CVE-2026-82215 WC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified Webhook 11.09.2026 5.9
CVE-2026-85116 Simple CAPTCHA with Cloudflare Turnstile 1.2.2 - 1.42.1 - Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation 11.09.2026 6.5
CVE-2026-86809 Persian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority Bypass 11.09.2026 5.3
CVE-2026-86813 MetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-To 11.09.2026 4.8
CVE-2026-89146 libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration TTL in Discovery Responses 11.09.2026 7.5
CVE-2026-89147 Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX Read 11.09.2026 7.5
CVE-2026-77159 Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink 11.09.2026
CVE-2026-87123 hbs vulnerable to Denial of Service via unhandled exception in async helper output escaping 11.09.2026 5.9
CVE-2026-17037 Kirki <= 6.2.0 - Unauthenticated Stored Cross-Site Scripting via 'comment' Parameter 11.09.2026 7.2
CVE-2026-47839 Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin 11.09.2026
CVE-2026-87859 morgan vulnerable to Log Injection via unescaped double quote in quoted log fields 11.09.2026 5.3
CVE-2025-15679 BMC root account active without password on BullSequana XH3406 and XH3515 11.09.2026
CVE-2026-19486 SSRF in Gemini Enterprise Agent Platform App Builder 11.09.2026
CVE-2026-80469 CVE-2026-80469 11.09.2026 8.3
CVE-2026-87727 11.09.2026
CVE-2026-6640 Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_link_attributes Parameter 11.09.2026 6.4
CVE-2026-6641 Media Library Assistant <= 3.35 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mla_link_href' Shortcode Parameter 11.09.2026 6.4
CVE-2026-6642 Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import 11.09.2026 6.4
CVE-2026-89175 Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication 11.09.2026
CVE-2026-89176 Howyar|WeenyGenius - Missing Authentication 11.09.2026
CVE-2026-89177 Howyar|WeenyGenius - Use of Insecure Protocol 11.09.2026
CVE-2026-89178 Howyar|WeenyGenius - Origin Validation Error 11.09.2026
CVE-2026-89179 Howyar|WeenyGenius - Missing Support for Integrity Check 11.09.2026
CVE-2026-89173 Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure 11.09.2026
CVE-2026-89174 Kingdom Communication Associated|Smart Video Intercom System - Missing Burte-force Protection 11.09.2026
CVE-2026-73785 HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability 11.09.2026 7.5
CVE-2026-87908 multiparty vulnerable to Denial of Service via unbounded part-header accumulation 11.09.2026 7.5
CVE-2025-15695 GTranslate < 3.0.10 - Admin+ Stored XSS 11.09.2026
CVE-2026-13326 Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module 11.09.2026
CVE-2026-14559 Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account Takeover 11.09.2026
CVE-2026-14560 Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Arbitrary File Upload 11.09.2026
CVE-2026-14562 Teddy Bear Customize Addon <= 1.0.5 - Unauthenticated Order Data Disclosure 11.09.2026
CVE-2026-14563 Advanced Customized Prompts <= 1.0.1 - Unauthenticated Account Takeover 11.09.2026
CVE-2026-14565 Advanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup Configuration 11.09.2026
CVE-2026-14566 Advanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata Tampering 11.09.2026
CVE-2026-73784 HPE IceWall products, Remote Bypass of Security Restrictions 11.09.2026 8.8
CVE-2026-74925 MultiVendorX 5.0.0 - 5.0.15 - Store Owner+ Privilege Escalation to Administrator 11.09.2026
CVE-2026-82305 YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title 11.09.2026
CVE-2026-83545 CoolClock < 4.3.8 - Contributor+ Stored XSS via Custom Skin JSON 11.09.2026
CVE-2026-83546 CoolClock < 4.3.8 - Contributor+ Stored XSS via Skin Class Attribute 11.09.2026
CVE-2026-85677 Gutenverse News < 3.3.3 - Unauthenticated Stored XSS via Comment Content 11.09.2026
CVE-2026-85678 AI Builder 2.4.1 - 2.7.7 - Contributor+ Stored XSS via Post JavaScript 11.09.2026
CVE-2026-86779 Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart 11.09.2026
CVE-2026-86780 Featured Image with URL < 1.0.6 - Contributor+ Stored XSS via Image Alt Text 11.09.2026
CVE-2026-86781 SSL Zen < 4.7.40 - Subscriber+ TLS Private Key Disclosure 11.09.2026
CVE-2026-86782 Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR 11.09.2026
CVE-2026-86812 WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API 11.09.2026
CVE-2026-86815 BackWPup 5.2.2 - 5.7.4 - BackWPup Jobs Checker+ Database Backup Exfiltration via Missing Authorization on Job REST Routes 11.09.2026
CVE-2026-89169 11.09.2026
CVE-2026-89060 Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references 11.09.2026
CVE-2026-89162 11.09.2026 2.9
CVE-2026-89156 11.09.2026 2.9
CVE-2026-89157 11.09.2026 5.7
CVE-2026-89158 11.09.2026 6.5
CVE-2026-89160 11.09.2026 3.7
CVE-2026-89161 11.09.2026 7.4
CVE-2026-11446 Booktics – Booking Calendar for Appointments and Service Businesses <= 1.0.23 - Missing Authorization 11.09.2026 5.3
CVE-2026-11496 Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure 11.09.2026 6.5
CVE-2026-12215 OTP Login & Register Woocommerce <= 2.7.2 - Unauthenticated Authentication Bypass via Brute Force 11.09.2026 5.3
CVE-2026-15462 Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection 11.09.2026 7.5
CVE-2026-18561 Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection 11.09.2026 7.5
CVE-2026-18562 HUSKY <= 1.4.3 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-18579 WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting 11.09.2026 7.2
CVE-2026-18964 Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button <= 3.5.9 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-19985 Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-19991 UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion 11.09.2026 8.1
CVE-2026-77150 Unlimited Elements For Elementor <= 2.0.16 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-78172 Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-7438 Bold Timeline Lite <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes 11.09.2026 6.4
CVE-2026-81754 Vigilant <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting 11.09.2026 7.2
CVE-2026-81825 Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting 11.09.2026 7.2
CVE-2026-84960 WP-Members Membership Plugin <= 3.5.6 - Reflected Cross-Site Scripting 11.09.2026 6.1
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8