CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 05.09.2026 9.8
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 05.09.2026 9.8
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize 04.09.2026 9.4
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action 04.09.2026 9.1
CVE-2026-75925 IXON VPN Client CRLF Injection 04.09.2026 9.4
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server 04.09.2026 9.2
CVE-2026-75430 04.09.2026 9.8
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed 04.09.2026 9.8
CVE-2026-19274 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 9.6
CVE-2026-75431 04.09.2026 9.1
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi 04.09.2026 9.3
CVE-2026-85620 Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function 04.09.2026 9.2
CVE-2026-85625 sift 17.1.3 Prototype Pollution Remote Code Execution via $where 04.09.2026 9.2
CVE-2026-85660 cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution 04.09.2026 9.2
CVE-2026-85661 excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode 04.09.2026 9.3
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch 04.09.2026 9.3
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection 04.09.2026 9.3
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension 04.09.2026 9.3
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer 04.09.2026 9.3
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction 04.09.2026 9.2
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing 04.09.2026 9.3
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename 04.09.2026 9.3
CVE-2026-85595 Traefik before v2.11.55 Authentication Bypass via digestAuth 04.09.2026 9.3
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass 04.09.2026 9.3
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker 04.09.2026 9.2
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes 04.09.2026 9.8
CVE-2026-85184 @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target 04.09.2026 9.1
CVE-2026-15354 ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter 04.09.2026 9.8
CVE-2026-62928 04.09.2026 9.3
CVE-2026-69657 04.09.2026 9.3
CVE-2026-70403 04.09.2026 9.3
CVE-2026-85085 04.09.2026 9.6
CVE-2026-11613 Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter 04.09.2026 9.8
CVE-2026-85506 04.09.2026 9.8
CVE-2026-85507 04.09.2026 9.8
CVE-2026-85508 04.09.2026 9.8
CVE-2026-85509 04.09.2026 9.8
CVE-2026-85504 04.09.2026 9.8
CVE-2026-85146 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-85148 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-75754 04.09.2026 10
CVE-2026-67402 04.09.2026 9.2
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability 05.09.2026 9.1
CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability 05.09.2026 10
CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability 05.09.2026 9.3
CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability 05.09.2026 10
CVE-2026-85424 MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR 05.09.2026 9.3
CVE-2026-85425 MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS 04.09.2026 9.3
CVE-2026-85426 MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names 04.09.2026 9.3
CVE-2026-85427 MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE 04.09.2026 9.2
CVE-2026-85428 MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write 03.09.2026 9.3
CVE-2026-85433 MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration 03.09.2026 9.3
CVE-2026-85434 MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping 05.09.2026 9.3
CVE-2026-85435 MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment 04.09.2026 9.3
CVE-2026-85437 MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders 04.09.2026 9.3
CVE-2026-85438 MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts 03.09.2026 9.3
CVE-2026-85440 MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length 04.09.2026 9.3
CVE-2026-85224 D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection 04.09.2026 9.4
CVE-2026-85223 D-Link DNS-340L CGI dropbox.cgi os command injection 04.09.2026 9.4
CVE-2026-85222 D-Link DNS-340L Add-On Center addon_center.cgi os command injection 04.09.2026 9.4
CVE-2026-85061 MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip 04.09.2026 10
CVE-2026-85391 Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml 03.09.2026 9.3
CVE-2026-85394 python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret 03.09.2026 9.3
CVE-2026-82526 R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint 04.09.2026 9.3
CVE-2026-58400 GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter 04.09.2026 9.1
CVE-2026-84238 WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability 03.09.2026 9.8
CVE-2026-84753 WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability 05.09.2026 9.8
CVE-2026-84768 WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability 03.09.2026 9.3
CVE-2026-84813 WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84814 WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability 03.09.2026 9.8
CVE-2026-84834 WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability 03.09.2026 9.8
CVE-2026-85181 CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum 03.09.2026 9.3
CVE-2026-85183 Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS 03.09.2026 9.3
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials 03.09.2026 9.5
CVE-2026-85109 Tenda HG10 Boa Web Server formLogin buffer overflow 03.09.2026 9.3
CVE-2026-82180 03.09.2026 9.5
CVE-2026-78080 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 03.09.2026 9.3
CVE-2026-78069 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026 9.5
CVE-2026-85154 WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash 05.09.2026 9.3
CVE-2026-76178 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.2
CVE-2026-76174 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.4
CVE-2026-80726 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page 04.09.2026 9.3
CVE-2026-85031 TOTOLINK CP450 cstecgi.cgi buffer overflow 03.09.2026 9.4
CVE-2026-19117 Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability 02.09.2026 9.8
CVE-2026-53670 PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification 02.09.2026 9.3
CVE-2026-53671 PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification 05.09.2026 9.3
CVE-2026-66786 Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets 05.09.2026 9.1
CVE-2026-53649 Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE 04.09.2026 9.6
CVE-2026-20212 Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability 03.09.2026 9.8
CVE-2026-20274 Cisco IOS XR Software Security Hardening Release: September 2026 04.09.2026 9.8
CVE-2026-20279 Cisco IOS XR Software Security Hardening Release: September 2026 04.09.2026 9.8
CVE-2026-53611 Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation 02.09.2026 9.8
CVE-2026-78689 NGINX ngx_http_js_module vulnerablility 03.09.2026 9.2
CVE-2026-82955 02.09.2026 9
CVE-2025-9314 Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload 02.09.2026 9.8
CVE-2026-4357 Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload 02.09.2026 10
CVE-2026-77009 WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console 02.09.2026 9.9
CVE-2026-81294 WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability 02.09.2026 9.8
CVE-2026-81286 WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84795 Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance 02.09.2026 9.2
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field 02.09.2026 9.8
CVE-2026-9055 Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' 02.09.2026 9.8
CVE-2026-84695 BookStack before 26.05.4 Stored XSS via Drawing Upload 02.09.2026 9.3
CVE-2026-84696 Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands 02.09.2026 9.3
CVE-2026-84699 Team Password Manager before 14.184.308 Authentication Bypass in Password Reset 02.09.2026 9.3
CVE-2026-84479 WWBN AVideo Authentication Bypass via User-Agent Header 02.09.2026 9.3
CVE-2026-84480 WWBN AVideo Password Recovery Token Expiration Bypass 02.09.2026 9.3
CVE-2023-54391 Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter 03.09.2026 9.3
CVE-2026-75604 Next.js: Unauthenticated Remote Code Execution on windows-hosted servers 04.09.2026 9
CVE-2026-84372 Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections 02.09.2026 9.8
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 03.09.2026 9.8
CVE-2026-76657 Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access 01.09.2026 10
CVE-2026-76658 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon 01.09.2026 10
CVE-2026-19766 Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer 02.09.2026 9.6
CVE-2026-73700 Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface 02.09.2026 9
CVE-2026-73701 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer 02.09.2026 9
CVE-2026-79687 02.09.2026 9
CVE-2026-18931 Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software 01.09.2026 9.1
CVE-2026-78012 Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack 04.09.2026 9.3
CVE-2026-18210 SQL Injection in TRtek Technological Products's Store 01.09.2026 9.8
CVE-2026-9621 RSLinx Classic® - Multiple Vulnerabilities 01.09.2026 9.2
CVE-2026-18808 Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO 01.09.2026 9.8
CVE-2026-18765 SQL Injection in Teracity Sotware's Teracity E-OSB Platform 01.09.2026 9.8
CVE-2026-84149 Information Disclosure Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2026-84147 Remote Code Execution Vulnerability in Manacle Technologies ERP System 01.09.2026 10
CVE-2026-84148 Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites 04.09.2026 9.3
CVE-2026-84189 LibreNMS before 26.7.0 Stored XSS via Oxidized API 04.09.2026 9.2
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions 02.09.2026 9.4
CVE-2026-18550 Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter 02.09.2026 9.8
CVE-2026-4813 Code injection in the Lutece Core 01.09.2026 9.4
CVE-2026-78319 TOCTOU Vulnerability in file exchange 01.09.2026 9.3
CVE-2026-83772 Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection 01.09.2026 9.4
CVE-2026-67394 01.09.2026 9
CVE-2026-75865 WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint 01.09.2026 9.8
CVE-2026-83524 RedPort Optimizer wXa-223 System Clock datetime.php exec command injection 01.09.2026 9.4
CVE-2026-82971 QVidium Opera11 CGI Script net_tr.cgi command injection 01.09.2026 10
CVE-2026-82954 Dokploy Settings application.ts writeTraefikConfigInPath path traversal 02.09.2026 9.4
CVE-2026-81779 WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability 01.09.2026 10
CVE-2026-81293 WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81756 WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-81763 WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81780 WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability 01.09.2026 10
CVE-2026-82226 WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability 01.09.2026 9.8
CVE-2026-82908 MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow 01.09.2026 9.3
CVE-2026-53552 Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers 01.09.2026 9.6
CVE-2026-79748 MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args) 31.08.2026 9.9
CVE-2026-82807 ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management 01.09.2026 9.3
CVE-2026-73819 Ebyte NA111-M Weak Authentication 01.09.2026 9.3
CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm 01.09.2026 9.3
CVE-2026-66047 ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE 02.09.2026 9.2
CVE-2026-82970 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability 31.08.2026 10
CVE-2026-59111 Command Injection vulnerability in eObčanka-Identifikace 31.08.2026 9.3
CVE-2026-82694 Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication 31.08.2026 10
CVE-2026-82695 Tenda AC18 Telnet telnet missing authentication 31.08.2026 10
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82693 Tenda AC1206 Web UI telnet TendaTelnet missing authentication 31.08.2026 10
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection 02.09.2026 9.4
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection 01.09.2026 9.4
CVE-2026-82876 Phison PS3111-S11 Controller Firmware Signature Verification Bypass 02.09.2026 9.3
CVE-2026-49003 Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product 31.08.2026 9.6
CVE-2026-82854 Nodemailer before 8.0.3 SMTP Command Injection via envelope.size 31.08.2026 9.3
CVE-2026-82855 @hulumi/policies before 1.3.2 Evidence Validation Bypass 31.08.2026 9.3
CVE-2026-82856 @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass 02.09.2026 9.3
CVE-2026-82857 hulumi before v1.3.2 Privilege Escalation via IAM Policy 01.09.2026 9.3
CVE-2026-82858 @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance 31.08.2026 9.3
CVE-2026-82859 hulumi before v1.3.2 SCP Template Tag-on-Create Bypass 31.08.2026 9.3
CVE-2026-82860 @hulumi/policies before 1.3.2 Admin Policy Bypass 31.08.2026 9.3
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression 31.08.2026 9.4
CVE-2026-82628 Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management 31.08.2026 9.3
CVE-2026-58574 31.08.2026 9.8
CVE-2026-82616 TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow 01.09.2026 9.4
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow 01.09.2026 9.4
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow 31.08.2026 9.4
CVE-2026-82645 AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token 31.08.2026 9.2
CVE-2026-82653 SiYuan before v3.8.1 Stored XSS via confirmDialog 02.09.2026 9.3
CVE-2026-82654 SiYuan before v3.8.1 Stored XSS via block name 01.09.2026 9.3
CVE-2026-82542 Tenda HG10 Boa Web Server formIPv6Routing buffer overflow 01.09.2026 10
CVE-2026-82539 TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption 01.09.2026 9.4
CVE-2026-15980 MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token 31.08.2026 9.8
CVE-2026-15369 Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout 01.09.2026 9.8
CVE-2026-82460 Cloud Commander before 19.20.2 Directory Traversal via REST and Markdown 31.08.2026 9.3
CVE-2026-82466 Rodauth before 2.46.0 Authentication Bypass via webauthn_login 31.08.2026 9.4
CVE-2026-82452 rust-iot-platform Authentication Bypass via Missing Request Guards 01.09.2026 9.3
CVE-2026-82454 Omnivore before android-0.227.0 Authentication Bypass via Apple Sign-in 31.08.2026 9.3
CVE-2026-82456 argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP 02.09.2026 10
CVE-2026-82448 Shinobi before commit 5a76c74f Arbitrary Database Query Execution via Hardcoded Child Node Key 31.08.2026 9.3
CVE-2026-14494 Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field 31.08.2026 9.8

Latest Updates

CVE Title Updated Score
CVE-2026-75018 Custom Contact Forms <= 7.16 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters 05.09.2026 4.3
CVE-2026-75586 Unlimited Elements For Elementor <= 2.0.17 - Reflected Cross-Site Scripting via 'formData[id]' Parameter 05.09.2026 6.1
CVE-2026-81543 Abandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation 05.09.2026 8.8
CVE-2026-83625 Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header 05.09.2026 7.2
CVE-2026-85414 Gallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute 05.09.2026 6.4
CVE-2026-14975 WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter 05.09.2026 6.5
CVE-2026-15984 QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters 05.09.2026 7.2
CVE-2026-16649 Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field Value 05.09.2026 7.2
CVE-2026-18406 SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload 05.09.2026 7.2
CVE-2026-18843 Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter 05.09.2026 6.1
CVE-2026-19769 Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key 05.09.2026 7.2
CVE-2026-19887 Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback 05.09.2026 8.8
CVE-2026-3853 Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter 05.09.2026 6.4
CVE-2026-4361 Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter 05.09.2026 5
CVE-2026-77830 Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder 05.09.2026 7.2
CVE-2026-78438 W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator 05.09.2026 7.2
CVE-2025-15693 JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal 05.09.2026
CVE-2025-15694 Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS 05.09.2026
CVE-2026-15247 Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion 05.09.2026
CVE-2026-19858 JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset 05.09.2026
CVE-2026-19861 JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails 05.09.2026
CVE-2026-77826 RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation 05.09.2026
CVE-2026-78149 Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id 05.09.2026
CVE-2026-78150 Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR 05.09.2026
CVE-2026-78362 SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication 05.09.2026
CVE-2026-81348 My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap 05.09.2026
CVE-2026-81404 IPGP Visitors Origin < 1.6 - Reflected XSS 05.09.2026
CVE-2026-81423 Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler 05.09.2026
CVE-2026-81424 Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR 05.09.2026
CVE-2026-82304 Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler 05.09.2026
CVE-2026-82846 Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields 05.09.2026
CVE-2026-83543 Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint 05.09.2026
CVE-2026-83544 Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute 05.09.2026
CVE-2026-84021 Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL 05.09.2026
CVE-2026-84022 Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attributes 05.09.2026
CVE-2026-84221 Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID 05.09.2026
CVE-2026-84225 Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR 05.09.2026
CVE-2026-84745 The Events Calendar &lt; 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API 05.09.2026
CVE-2026-84896 King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget 05.09.2026
CVE-2026-84898 Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta 05.09.2026
CVE-2026-84899 VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix 05.09.2026
CVE-2026-84901 Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization 05.09.2026
CVE-2026-84926 EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route 05.09.2026
CVE-2026-84927 EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification 05.09.2026
CVE-2026-84930 CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute 05.09.2026
CVE-2026-84931 Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute 05.09.2026
CVE-2026-84934 JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override 05.09.2026
CVE-2026-84935 HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings 05.09.2026
CVE-2026-84936 EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat 05.09.2026
CVE-2026-84937 YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax 05.09.2026
CVE-2025-14945 Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes 05.09.2026 5.4
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 05.09.2026 9.8
CVE-2026-18404 Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box 05.09.2026 6.4
CVE-2026-77233 iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite 05.09.2026 7.2
CVE-2026-77263 iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content 05.09.2026 7.2
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 05.09.2026 9.8
CVE-2026-83628 Theme My Login <= 7.1.15 - Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage 05.09.2026 4.3
CVE-2026-8623 Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute 05.09.2026 6.4
CVE-2026-8625 Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML 05.09.2026 6.4
CVE-2026-86145 05.09.2026 8.2
CVE-2026-86144 05.09.2026 5.6
CVE-2026-86139 05.09.2026 6.9
CVE-2026-86140 05.09.2026 8
CVE-2026-86141 05.09.2026 2.9
CVE-2026-86142 05.09.2026 6.9
CVE-2026-86143 05.09.2026 6.9
CVE-2026-86137 05.09.2026 2.9
CVE-2026-86138 05.09.2026 6.9
CVE-2026-52774 Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki 04.09.2026 6.1
CVE-2026-52775 YesWiki Authenticated SQL Injection in ReactionManager 04.09.2026 8.8
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize 04.09.2026
CVE-2026-52762 YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates 04.09.2026
CVE-2026-52763 YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read 04.09.2026 6.5
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action 04.09.2026 9.1
CVE-2026-52767 YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` 04.09.2026 8.2
CVE-2026-52769 YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` 04.09.2026 8.3
CVE-2026-52770 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki 04.09.2026 7.5
CVE-2026-52771 YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) 04.09.2026 8.3
CVE-2026-52772 YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`) 04.09.2026 5.5
CVE-2026-52773 Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki 04.09.2026 6.1
CVE-2026-86100 Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL 04.09.2026
CVE-2026-86095 Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name 04.09.2026
CVE-2026-86096 PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup 04.09.2026
CVE-2026-86097 PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select 04.09.2026
CVE-2026-86098 ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape 04.09.2026
CVE-2026-48019 CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay 04.09.2026 8.9
CVE-2026-46636 Twig: Sandbox method allowlist bypass via `Markup` subclass 04.09.2026
CVE-2026-86090 ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers 04.09.2026
CVE-2026-86091 ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler 04.09.2026
CVE-2026-75925 IXON VPN Client CRLF Injection 04.09.2026 9.6
CVE-2026-76925 Flatpak: flatpak: toctou race condition allows symlink redirection 04.09.2026
CVE-2026-77393 Inductive Automation Ignition Incorrect Default Permissions 04.09.2026 8.8
CVE-2026-82684 Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization 04.09.2026 8.1
CVE-2026-77847 Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials 04.09.2026 6.5
CVE-2026-82712 Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery 04.09.2026 8.8
CVE-2026-85704 ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition 04.09.2026
CVE-2026-85703 ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources 04.09.2026
CVE-2022-26961 04.09.2026
CVE-2026-75438 04.09.2026
CVE-2026-79423 04.09.2026
CVE-2026-85702 ramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authentication 04.09.2026
CVE-2026-79426 04.09.2026
CVE-2025-67066 04.09.2026
CVE-2026-50894 04.09.2026
CVE-2026-53769 Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy 04.09.2026 6.5
CVE-2026-75439 04.09.2026
CVE-2026-85701 ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authentication 04.09.2026
CVE-2026-85787 An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server 04.09.2026
CVE-2026-79389 04.09.2026
CVE-2026-79390 04.09.2026
CVE-2026-79391 04.09.2026
CVE-2026-53932 wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection') 04.09.2026 8
CVE-2026-71625 04.09.2026
CVE-2026-55513 nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens 04.09.2026 5.4
CVE-2026-61699 nebula-mesh: Certificate revocation is never enforced at the mesh 04.09.2026 8.1
CVE-2026-63464 Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` 04.09.2026 7.7
CVE-2026-71626 04.09.2026
CVE-2026-53602 nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificate 04.09.2026
CVE-2026-53603 nebula-mesh: Operator session tokens stored in plaintext in the database 04.09.2026
CVE-2026-53604 nebula-mesh: CA private key not zeroized on web mobile-bundle error paths 04.09.2026
CVE-2026-55512 nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting 04.09.2026 5.3
CVE-2026-71622 04.09.2026
CVE-2026-71624 04.09.2026
CVE-2026-85786 Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java 04.09.2026
CVE-2026-85643 code-projects Online Shopping System adduser.php mysqli_query sql injection 04.09.2026
CVE-2026-71620 04.09.2026
CVE-2026-85639 jofpin trape Telemetry Endpoint user.py race condition 04.09.2026
CVE-2026-78839 04.09.2026
CVE-2026-85638 jofpin trape user.py authorization 04.09.2026
CVE-2026-85781 Unverified access point ownership in Amazon EFS CSI Driver 04.09.2026
CVE-2026-80118 PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL 04.09.2026
CVE-2026-80119 PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTL 04.09.2026
CVE-2026-80112 PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys 04.09.2026
CVE-2026-80113 PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL 04.09.2026
CVE-2026-80114 PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sys 04.09.2026
CVE-2026-80115 PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL 04.09.2026
CVE-2026-80116 PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL 04.09.2026
CVE-2026-80117 PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via DirectIo64.sys 04.09.2026
CVE-2026-85637 jofpin trape Admin Endpoint sockets.py join_room missing authentication 04.09.2026
CVE-2026-78327 04.09.2026
CVE-2026-78328 04.09.2026
CVE-2026-81939 04.09.2026
CVE-2021-44319 04.09.2026
CVE-2026-53761 Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api 04.09.2026
CVE-2026-85636 jofpin trape Login Endpoint stats.py missing authentication 04.09.2026
CVE-2026-53760 Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests 04.09.2026 5.2
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server 04.09.2026
CVE-2026-53756 Emlog Blind SQL Injection via Authentication Cookie 04.09.2026 4.9
CVE-2026-53757 Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE 04.09.2026
CVE-2026-53758 Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized 04.09.2026
CVE-2026-61608 SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links 04.09.2026 6.8
CVE-2026-61614 SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history 04.09.2026 5.9
CVE-2026-61688 SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props 04.09.2026 6.5
CVE-2026-73848 Emlog: Stored XSS via Tag Name in Article Editor 04.09.2026
CVE-2026-85769 Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize 04.09.2026
CVE-2026-61686 SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop 04.09.2026 7.5
CVE-2026-82538 ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter 04.09.2026
CVE-2026-85656 OS command injection in Amazon log4j-cve-2021-44228-hotpatch 04.09.2026
CVE-2026-18149 undici vulnerable to Denial of Service via orphaned RetryHandler response body 04.09.2026 5.9
CVE-2026-50553 Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) 04.09.2026
CVE-2026-80903 drm/xe/oa: Fix sync entry leak on OA config emit failure 04.09.2026
CVE-2026-80904 net/tls: Fail tls_sw_splice_read() after a failed async decrypt 04.09.2026
CVE-2026-80905 net: tap: fix wrong transport_header when sending VLAN-tagged frame 04.09.2026
CVE-2026-80906 net: packet: fix wrong transport_header when sending VLAN-tagged frame 04.09.2026
CVE-2026-80907 drm/amdgpu: Fix UVD dpb min size calculation for H264 04.09.2026
CVE-2026-80908 drm/amdgpu: Reject UVD message with dimensions above 4096 04.09.2026
CVE-2026-80909 drm/amdgpu: Reject UVD message with invalid number of h265 refs 04.09.2026
CVE-2026-80910 ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses 04.09.2026
CVE-2026-80911 ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() 04.09.2026
CVE-2026-80912 selinux: reject an unclaimed class value in security_get_classes() 04.09.2026
CVE-2026-80913 selinux: require every boolean value to be defined 04.09.2026
CVE-2021-44320 04.09.2026
CVE-2026-18540 undici vulnerable to downstream response splitting via retry interceptor 04.09.2026 3.7
CVE-2026-18745 04.09.2026
CVE-2026-19534 undici vulnerable to Denial of Service via unrequested WebSocket subprotocol 04.09.2026 7.5
CVE-2026-57159 PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance 04.09.2026
CVE-2026-57160 PJSIP: SIP message header buffer overflow 04.09.2026
CVE-2026-57161 PJSIP: Stack overflow handling Service-Route headers in a registration response 04.09.2026
CVE-2026-57162 PJSIP: Stack overflow parsing SDP a=crypto attributes 04.09.2026
CVE-2026-57163 PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend 04.09.2026
CVE-2026-57164 PJSIP: Heap overflow in the HTTP client 04.09.2026
CVE-2026-57165 PJSIP: Pre-authentication overflow in the telnet CLI history 04.09.2026
CVE-2026-57166 PJSIP: Pre-authentication overflow in the telnet CLI error 04.09.2026
CVE-2026-80887 drm/vmwgfx: use check_add_overflow for shader size+offset bound 04.09.2026
CVE-2026-80888 drm/vmwgfx: drop dma_buf reference on foreign-fd prime import 04.09.2026
CVE-2026-80889 can: isotp: fix timer drain order, wakeup handling and tx_gen ordering 04.09.2026
CVE-2026-80890 sctp: reject stale cookies with mismatched verification tags 04.09.2026
CVE-2026-80891 KVM: s390: pci: Validate AIBV and AISB before pinning guest pages 04.09.2026
CVE-2026-80892 erofs: cap LZMA stream pool size 04.09.2026
CVE-2026-80893 mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() 04.09.2026
CVE-2026-80894 iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace 04.09.2026
CVE-2026-80895 mshv: Order pt_vp_array publish against irqfd assertion path 04.09.2026
CVE-2026-80896 mshv: Fix race in mshv_irqfd_deassign 04.09.2026
CVE-2026-80897 netfs: release readahead folios on iterator preparation failure 04.09.2026
CVE-2026-80898 netfs: clear PG_private_2 on copy-to-cache append failure 04.09.2026
CVE-2026-80899 erofs: remove fscache backend entirely 04.09.2026
CVE-2026-80900 ASoC: SDCA: Make UMP message size check more robust 04.09.2026
CVE-2026-80901 ipvs: fix the checksum validations 04.09.2026
CVE-2026-80902 dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA 04.09.2026
CVE-2026-84890 undici vulnerable to Denial of Service via unbounded decompression of compressed responses 04.09.2026 5.9
CVE-2026-85654 Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server 04.09.2026
CVE-2026-84933 undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches 04.09.2026 6.5
CVE-2026-31020 04.09.2026
CVE-2026-80885 afs: Fix uncancelled rxrpc OOB message handler 04.09.2026
CVE-2026-80886 serial: msm: Disable DMA for kernel console UART 04.09.2026
CVE-2026-84947 undici vulnerable to response truncation via oversized chunked responses in the dump interceptor 04.09.2026 3.7
CVE-2026-13297 Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access 04.09.2026
CVE-2026-14350 Vulnerabilities exists in IBM Cloud Pak for Data System 04.09.2026 5.3
CVE-2026-80865 bpf: Add missing access_ok call to copy_user_syms 04.09.2026
CVE-2026-80866 tipc: avoid busy looping in tipc_exit_net() 04.09.2026
CVE-2026-80867 alpha/PCI: Add security_locked_down() check to pci_mmap_resource() 04.09.2026
CVE-2026-80868 ntfs3: Allocate iomap inline_data using alloc_page 04.09.2026
CVE-2026-80869 ntfs: bound the attribute-list entry in ntfs_read_inode_mount() 04.09.2026
CVE-2026-80870 drm/amdkfd: Validate CRIU-restored IDs before idr_alloc 04.09.2026
CVE-2026-80871 crypto: xilinx-trng - Remove crypto_rng interface 04.09.2026
CVE-2026-80872 ALSA: hda/tas2781: Cancel async firmware request at unbind 04.09.2026
CVE-2026-80873 KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions 04.09.2026
CVE-2026-80874 arm64: dts: renesas: ironhide: Describe inline ECC carveouts 04.09.2026
CVE-2026-80875 ipvs: use parsed transport offset in TCP state lookup 04.09.2026
CVE-2026-80876 ring-buffer: Fix event length with forced 8-byte alignment 04.09.2026
CVE-2026-80877 afs: Fix vllist leak 04.09.2026
CVE-2026-80878 afs: Fix leak of ungot volume 04.09.2026
CVE-2026-80879 ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write 04.09.2026
CVE-2026-80880 IB/mlx5: Properly support implicit ODP rereg_mr 04.09.2026
CVE-2026-80881 ocfs2: fix buffer head management in ocfs2_read_blocks() 04.09.2026
CVE-2026-80882 crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm 04.09.2026
CVE-2026-80883 drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered 04.09.2026
CVE-2026-80884 ntb: Store original DMA address for future release 04.09.2026
CVE-2026-84961 undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool 04.09.2026 7.4
CVE-2026-14470 Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components 04.09.2026 6.5
CVE-2026-16180 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 5.7
CVE-2026-16660 IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] 04.09.2026 5.3
CVE-2026-16689 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 6.2
CVE-2026-16693 IBM i is Affected By Cryptographic Algorithm Weakness in DCM [] 04.09.2026 4.4
CVE-2026-16826 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 5.3
CVE-2026-16892 IBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service [] 04.09.2026 5.4
CVE-2026-16941 IBM i is Affected By An Incorrect Authorization Vulnerability [] 04.09.2026 4.3
CVE-2026-17057 IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] 04.09.2026 6.5
CVE-2026-17207 IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] 04.09.2026 6.5
CVE-2026-17255 IBM i is Affected By Denial of Service Vulnerability [] 04.09.2026 4.3
CVE-2026-17259 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 4.3
CVE-2026-17270 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 4.3
CVE-2026-85008 undici vulnerable to caching and replay of unsafe HTTP method responses 04.09.2026 3.7
CVE-2026-17273 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 6.5
CVE-2026-17274 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 5.4
CVE-2026-17440 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 5.5
CVE-2026-17442 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 5.1
CVE-2026-17443 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 5.3
CVE-2026-17444 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 5.3
CVE-2026-17469 IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ] 04.09.2026 5.3
CVE-2026-17470 IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ] 04.09.2026 5.3
CVE-2026-17483 IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] 04.09.2026 4.3
CVE-2026-17499 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 4.4
CVE-2026-17621 Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components 04.09.2026 5.4
CVE-2026-17622 Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components 04.09.2026 6.5
CVE-2026-17627 Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint 04.09.2026 4.9
CVE-2026-38961 04.09.2026
CVE-2026-78849 04.09.2026
CVE-2026-85014 undici vulnerable to Denial of Service via WebSocketStream unclean close 04.09.2026 5.9
CVE-2026-85152 undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors 04.09.2026 7.4
CVE-2026-17631 Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components 04.09.2026 5
CVE-2026-18073 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 4.4
CVE-2026-18076 IBM i is Affected By Multiple Vulnerabilities in Debug Server 04.09.2026 4.3
CVE-2026-18078 IBM i is Affected By Denial of Service Vulnerability in Save Restore [] 04.09.2026 4.3
CVE-2026-18175 IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] 04.09.2026 8.1
CVE-2026-18221 IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] 04.09.2026 8.1
CVE-2026-18341 IBM i is Affected By Buffer Overflow Vulnerability [] 04.09.2026 6.3
CVE-2026-18486 IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution 04.09.2026 8.8
CVE-2026-18489 IBM ContextForge Translate is affected by cross-client credential context confusion 04.09.2026 7.4
CVE-2026-75430 04.09.2026 9.8
CVE-2026-78745 04.09.2026
CVE-2026-85024 undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression 04.09.2026 5.9
CVE-2026-18567 IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] 04.09.2026 4.4
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed 04.09.2026 9.8
CVE-2026-18858 IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH [] 04.09.2026 3.3
CVE-2026-18887 IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE [] 04.09.2026 6.5
CVE-2026-19298 Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint 04.09.2026 8.8
CVE-2026-19301 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components 04.09.2026 5
CVE-2026-19303 Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components 04.09.2026 8.1
CVE-2026-78970 04.09.2026
CVE-2026-18905 IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation 04.09.2026 7.7
CVE-2026-75169 04.09.2026
CVE-2026-75170 04.09.2026
CVE-2026-75171 04.09.2026
CVE-2026-80824 usb: usbfs: fix use-after-free of usb_device in usbdev_release() 04.09.2026
CVE-2026-80825 wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb 04.09.2026
CVE-2026-80826 USB: c67x00: fix use-after-free in c67x00_add_iso_urb() 04.09.2026
CVE-2026-80827 USB: serial: option: fix slab OOB read in interrupt URB callback 04.09.2026
CVE-2026-80828 ALSA: usb-audio: Complete cleanup after system-resume errors 04.09.2026
CVE-2026-80829 ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() 04.09.2026
CVE-2026-80830 usb: core: Add lock to usb_wakeup_notification() 04.09.2026
CVE-2026-80831 crypto: mxs-dcp - fix source scatterlist length access 04.09.2026
CVE-2026-80832 crypto: qce - fix CCM AAD buffer underallocation 04.09.2026
CVE-2026-80833 crypto: sun8i-ss - Remove crypto_rng interface 04.09.2026
CVE-2026-80834 crypto: sun8i-ce - Remove crypto_rng interface 04.09.2026
CVE-2026-80835 crypto: qcom-rng - Remove crypto_rng interface 04.09.2026
CVE-2026-80836 crypto: virtio - bound the akcipher result length 04.09.2026
CVE-2026-80837 netfilter: nf_tables: don't queue packet path object notifications 04.09.2026
CVE-2026-80838 vxlan: keep the last remote linked during FDB flush 04.09.2026
CVE-2026-80839 batman-adv: reject unrepresentable multicast TVLV offsets 04.09.2026
CVE-2026-80840 ipv6: seg6: clear IPv4 control block on IPIP decapsulation 04.09.2026
CVE-2026-80841 net/packet: defer vmalloc TX_RING free until skbs finish 04.09.2026
CVE-2026-80842 net: bridge: mcast: fix use-after-free of a master VLAN's multicast context 04.09.2026
CVE-2026-80843 xfrm: fix xfrm_state_construct() auth-trunc leak 04.09.2026
CVE-2026-80844 xfrm: ah6: validate routing header segments_left 04.09.2026
CVE-2026-80845 xfrm: avoid lock inversion in nat keepalive work 04.09.2026
CVE-2026-80846 xfrm: drop ESP-in-TCP packets with no ingress device 04.09.2026
CVE-2026-80847 tcp: clamp route advmss to TCP_MIN_MSS 04.09.2026
CVE-2026-80848 xfrm: espintcp: fix UAF during close 04.09.2026
CVE-2026-80849 net/tcp-ao: fix use-after-free of current_key on reconnect to another peer 04.09.2026
CVE-2026-80850 tcp: fix AO info use-after-free in tcp_ao_connect_init() 04.09.2026
CVE-2026-80851 gtp: serialize PDP context updates 04.09.2026
CVE-2026-80852 tls: device: fix out-of-bounds write in tls_append_frag() 04.09.2026
CVE-2026-80853 KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts 04.09.2026
CVE-2026-80854 usb: gadget: f_tcm: keep port count until LUN teardown completes 04.09.2026
CVE-2026-80855 fuse: fix invalidate lock leak on open O_TRUNC DAX failure 04.09.2026
CVE-2026-80856 fuse: fix invalidate lock leak on setattr writeback failure 04.09.2026
CVE-2026-80857 fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free 04.09.2026
CVE-2026-80858 fuse: publish io-uring queues with release semantics 04.09.2026
CVE-2026-80859 fuse: fix missing barrier when checking io-uring readiness 04.09.2026
CVE-2026-80860 fuse: fix race between interrupt and resend 04.09.2026
CVE-2026-80861 usb: xhci: bail out of setup if the controller is inaccessible 04.09.2026
CVE-2026-80862 nvme-tcp: fix usage of page_frag_cache 04.09.2026
CVE-2026-80863 RDMA/rxe: Fix OOB in free_rd_atomic_resources() 04.09.2026
CVE-2026-80864 RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp 04.09.2026
CVE-2026-19274 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 9.6
CVE-2026-19283 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 7.7
CVE-2026-19299 Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components 04.09.2026 6.5
CVE-2026-19300 Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows 04.09.2026 7.5
CVE-2026-75166 04.09.2026
CVE-2026-75167 04.09.2026
CVE-2026-75168 04.09.2026
CVE-2026-75431 04.09.2026 9.1
CVE-2026-19302 Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components 04.09.2026 6.5
CVE-2026-75163 04.09.2026
CVE-2026-75164 04.09.2026
CVE-2026-75165 04.09.2026
CVE-2026-75160 04.09.2026
CVE-2026-75161 04.09.2026
CVE-2026-75162 04.09.2026
CVE-2026-75429 04.09.2026
CVE-2026-82911 CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes 04.09.2026
CVE-2022-35497 04.09.2026
CVE-2022-35499 04.09.2026
CVE-2026-19304 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components 04.09.2026 7.7
CVE-2026-19305 Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components 04.09.2026 8.6
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi 04.09.2026
CVE-2026-80821 nvmet: pci-epf: put CQ ref on create_cq mapping failure 04.09.2026
CVE-2026-80822 mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() 04.09.2026
CVE-2026-80823 nfc: st21nfca: validate ATR_REQ length against the received frame 04.09.2026
CVE-2026-19306 Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components 04.09.2026 7.7
CVE-2026-19645 Multiple vulnerabilities in IBM MQ Agent images 04.09.2026 6.5
CVE-2026-19649 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 6.2
CVE-2026-5522 QRadar contains hard-coded credentials 04.09.2026 6.7
CVE-2026-77822 IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpoint 04.09.2026 8.2
CVE-2026-78543 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 5.3
CVE-2026-78658 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability 04.09.2026 6.5
CVE-2026-79418 04.09.2026
CVE-2026-79419 05.09.2026
CVE-2026-80758 futex: Avoid private hash use-after-free on final put 04.09.2026
CVE-2026-80759 Bluetooth: hci_aml: validate firmware segment lengths 04.09.2026
CVE-2026-80760 Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 04.09.2026
CVE-2026-80761 Bluetooth: ISO: zero the sockaddr before returning it in getname 04.09.2026
CVE-2026-80762 Bluetooth: hci_sync: Fix accept list UAF during suspend 04.09.2026
CVE-2026-80763 Bluetooth: hci_event: validate LE Set CIG Parameters response 04.09.2026
CVE-2026-80764 Bluetooth: hci_event: fix LE list UAF on reset 04.09.2026
CVE-2026-80765 HID: hyperv: validate initial device info bounds 04.09.2026
CVE-2026-80766 HID: uclogic: fix use-after-free of inrange_timer on remove 04.09.2026
CVE-2026-80767 HID: sensor: custom: Fix use-after-free in enable_sensor 04.09.2026
CVE-2026-80768 HID: ft260: fix stack-use-after-return write in I2C read race 04.09.2026
CVE-2026-80769 HID: rapoo: fix missing hid_is_usb() check 04.09.2026
CVE-2026-80770 HID: nintendo: stop device IO before hid_hw_stop on probe failure 04.09.2026
CVE-2026-80771 HID: nintendo: register input device after capabilities are set 04.09.2026
CVE-2026-80772 HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() 04.09.2026
CVE-2026-80773 HID: huawei: fix missing hid_is_usb() check 04.09.2026
CVE-2026-80774 HID: asus: fix missing hid_is_usb() check 04.09.2026
CVE-2026-80775 futex: Fix race on the initial mm->futex.phash.ref allocation 04.09.2026
CVE-2026-80776 futex: Fix race in futex_pivot_pending() during private hash resize 04.09.2026
CVE-2026-80777 futex/pi: Plug private futex exec() race 04.09.2026
CVE-2026-80778 futex/pi: Reject cross-mm private futex owners 04.09.2026
CVE-2026-80779 net/ionic: avoid OOB TX partner lookup for hwstamp RXQ 04.09.2026
CVE-2026-80780 HID: pidff: fix OOB write when hid->inputs is empty 04.09.2026
CVE-2026-80781 HID: core: fix OOB read of field->usage in hid_set_field() 04.09.2026
CVE-2026-80782 HID: magicmouse: do not keep a stale msc->input if no input is claimed 04.09.2026
CVE-2026-80783 HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() 04.09.2026
CVE-2026-80784 mptcp: pm: fix memory leak from alloc-during-teardown race 04.09.2026
CVE-2026-80785 fbdev: serialize mode sysfs access with lock_fb_info() 04.09.2026
CVE-2026-80786 fbdev: Wrap user-invoked calls to fb_set_var() in helper 04.09.2026
CVE-2026-80787 nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() 04.09.2026
CVE-2026-80788 nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations 04.09.2026
CVE-2026-80789 nvmet-tcp: bound SGL data length before allocating command buffers 04.09.2026
CVE-2026-80790 nvmet-fc: fix invalid free in LS IOD error path 04.09.2026
CVE-2026-80791 nvmet-auth: zero the AUTH_RECEIVE response buffer 04.09.2026
CVE-2026-80792 ipv6: fix use-after-free in ip6_finish_output2() 04.09.2026
CVE-2026-80793 ipv4: reject undersized MTUs in ip_do_fragment() 04.09.2026
CVE-2026-80794 nfc: nci: fix uninit-value in the RF discover/activated NTF handlers 04.09.2026
CVE-2026-80795 nfc: nci: fix out-of-bounds write in nci_target_auto_activated() 04.09.2026
CVE-2026-80796 nfc: nci: add data_len bound checks to activation parameter extractors 04.09.2026
CVE-2026-80797 nfc: pn533: purge fragmented skbs during cleanup 04.09.2026
CVE-2026-80798 nfc: llcp: reject PDUs shorter than the LLCP header 04.09.2026
CVE-2026-80799 nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers 04.09.2026
CVE-2026-80800 nfc: llcp: bound the connect_sn TLV walk to the skb 04.09.2026
CVE-2026-80801 nfc: microread: validate target discovery payload lengths 04.09.2026
CVE-2026-80802 nfc: fdp: bound the device-reported read length and fix an skb leak 04.09.2026
CVE-2026-80803 nfc: digital: clamp SENSF_RES length to the destination buffer 04.09.2026
CVE-2026-80804 xfs: restore nofs context unconditionally in xfs_trans_roll 04.09.2026
CVE-2026-80805 xfs: validate attr entry pointer before field access 04.09.2026
CVE-2026-80806 ext4: don't enable DAX on new encrypted files 04.09.2026
CVE-2026-80807 nilfs2: reject invalid block index in GC ioctl 04.09.2026
CVE-2026-80808 ext4: stop retrying saturated xattr cache entries 04.09.2026
CVE-2026-80809 ocfs2: fix missing metadata reservation for large xattrs 04.09.2026
CVE-2026-80810 io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() 04.09.2026
CVE-2026-80811 io_uring/cmd: fix iovec leak when the async cmd is not recycled 04.09.2026
CVE-2026-80812 ALSA: dummy: Check card index validity at probe 04.09.2026
CVE-2026-80813 nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() 04.09.2026
CVE-2026-80814 rndis_host: add overflow check in rndis_rx_fixup() 04.09.2026
CVE-2026-80815 ALSA: scarlett2: Use a private URB for the notification endpoint 04.09.2026
CVE-2026-80816 ALSA: FCP: Use a private URB for the notification endpoint 04.09.2026
CVE-2026-80817 iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages 04.09.2026
CVE-2026-80818 iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown 04.09.2026
CVE-2026-80819 Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept 04.09.2026
CVE-2026-80820 xfs: don't livelock in scrub on a circular unlinked list 04.09.2026
CVE-2026-85730 smol-toml: Denial of Service via malformed TOML documents 04.09.2026
CVE-2026-6958 Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe 04.09.2026
CVE-2026-81832 IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs 04.09.2026 7.7
CVE-2026-81859 Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026. 04.09.2026 6.2
CVE-2026-82728 Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS 04.09.2026
CVE-2026-82729 Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS 04.09.2026
CVE-2026-85605 Slink before 1.12.3 Missing Authorization on Image Comment Endpoints 04.09.2026
CVE-2026-85606 firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath 04.09.2026
CVE-2026-85607 Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router 04.09.2026
CVE-2026-85608 Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter 04.09.2026
CVE-2026-85618 ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives 04.09.2026
CVE-2026-85619 AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API 04.09.2026
CVE-2026-85620 Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function 04.09.2026
CVE-2026-85621 LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu 04.09.2026
CVE-2026-85622 AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket 04.09.2026
CVE-2026-85623 goose 1.37.0 Arbitrary Command Execution via Recipe Extensions 04.09.2026
CVE-2026-85624 Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList 04.09.2026
CVE-2026-85625 sift 17.1.3 Prototype Pollution Remote Code Execution via $where 04.09.2026
CVE-2026-85626 git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters 04.09.2026
CVE-2026-85650 Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel 04.09.2026
CVE-2026-85651 Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay 04.09.2026
CVE-2026-85660 cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution 04.09.2026
CVE-2026-85661 excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode 04.09.2026
CVE-2026-85662 Marqo 2.26.0 Server-Side Request Forgery via Media URLs 04.09.2026
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch 04.09.2026
CVE-2026-85664 Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion 04.09.2026
CVE-2026-85665 Bruno 3.4.2 Arbitrary File Read via Unconfined Body File Path 04.09.2026
CVE-2026-85666 ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url 04.09.2026
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection 04.09.2026
CVE-2026-85668 Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register 04.09.2026
CVE-2026-85669 potpie through 2.0.0 Missing Ownership Check via code-changes sync 04.09.2026
CVE-2026-85670 tokenizers BpeBuilder Buffer Overflow via merge token 04.09.2026
CVE-2026-85671 QAnything 2.0.0 Unauthenticated Cross-User File Disclosure 04.09.2026
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension 04.09.2026
CVE-2026-85673 LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding 04.09.2026
CVE-2026-85674 aider 0.86.2 Remote Code Execution via .aider.conf.yml 04.09.2026
CVE-2026-85675 OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching 04.09.2026
CVE-2026-85676 Dub Open Redirect via Unrestricted redir_url Parameter 04.09.2026
CVE-2026-85684 marker through 2.0.0 Path Traversal via upload filename 04.09.2026
CVE-2026-85685 AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill 04.09.2026
CVE-2026-85686 ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs 04.09.2026
CVE-2026-85687 surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server 04.09.2026
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer 04.09.2026
CVE-2026-85689 llmware 0.4.6 SQL Injection via unescaped filter values 04.09.2026
CVE-2026-85690 Plandex 2.2.1 Path Traversal via ApplyFiles 04.09.2026
CVE-2026-85691 MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url 04.09.2026
CVE-2026-85692 Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding 04.09.2026
CVE-2026-85693 Chatbot UI Cross-User Private File Content Disclosure via Retrieval API 04.09.2026
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction 04.09.2026
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing 04.09.2026
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename 04.09.2026
CVE-2026-85697 Documenso 2.17.0 PDF Route Ignores Document Visibility 04.09.2026
CVE-2026-85698 Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service 04.09.2026
CVE-2026-85699 jina-ai reader server-side request forgery via redirect validation bypass 04.09.2026
CVE-2026-85700 Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints 04.09.2026
CVE-2026-14466 Possible XSS in the SNS web administration panel 04.09.2026 4.3
CVE-2026-8447 Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust 04.09.2026 6.1
CVE-2026-9138 Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components 04.09.2026 6.5
CVE-2026-9186 Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust 04.09.2026 6.5
CVE-2026-19205 User Enumeration in GastroMenum's GastroMenum Web Panel 04.09.2026 7.5
CVE-2026-19727 HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System 04.09.2026 6.1
CVE-2026-19081 Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System 04.09.2026 4.3
CVE-2026-19057 Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System 04.09.2026 5.4
CVE-2026-85522 valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds 04.09.2026
CVE-2026-52691 Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module 04.09.2026
CVE-2026-77818 Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System 04.09.2026 6.1
CVE-2026-12483 LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler 04.09.2026 7.5
CVE-2026-85517 code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql information disclosure 04.09.2026
CVE-2026-85516 code-projects Vehicle Management System busprofile.php sql injection 04.09.2026
CVE-2026-85649 04.09.2026 7.9
CVE-2026-85514 StackStorm st2 API Key auth.py privileges management 04.09.2026
CVE-2026-74235 GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler 04.09.2026
CVE-2026-74236 GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler 04.09.2026
CVE-2026-74237 GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client 04.09.2026
CVE-2026-82309 Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries 04.09.2026
CVE-2026-85513 StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management 04.09.2026
CVE-2026-18198 SQL Injection in TAC Information's GoldenHorn 04.09.2026 8.8
CVE-2026-19051 Plaintext Storage of User Credentials in Menulux Software's Menulux Portal 04.09.2026 7.1
CVE-2026-19080 Username Enumeration in Menulux Software's Menulux Portal 04.09.2026 7.5
CVE-2026-19043 Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Portal 04.09.2026 4.3
CVE-2026-18957 Stored XSS in Menulux Software's Menulux Portal 04.09.2026 5.4
CVE-2026-85577 AVideo userLogin.php Reflected XSS via error parameter 04.09.2026
CVE-2026-85578 SiYuan through 3.8.1 Authorization Bypass via getFile 04.09.2026
CVE-2026-85579 SiYuan before v3.8.2 Information Disclosure via undoState 04.09.2026
CVE-2026-85580 SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch 04.09.2026
CVE-2026-85581 SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration 04.09.2026
CVE-2026-85582 SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth 04.09.2026
CVE-2026-85583 SiYuan before v3.8.2 Path Traversal via symlink in file API 04.09.2026
CVE-2026-85584 SiYuan before v3.8.2 Denial of Service via Auth Throttle 04.09.2026
CVE-2026-85585 SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency 04.09.2026
CVE-2026-85586 phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter 04.09.2026
CVE-2026-85587 phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages 04.09.2026
CVE-2026-85588 phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export 04.09.2026
CVE-2026-85589 phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API 04.09.2026
CVE-2026-85590 phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable 04.09.2026
CVE-2026-85591 phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change 04.09.2026
CVE-2026-85592 phpMyFAQ before 4.1.8 Authorization Bypass via question/create 04.09.2026
CVE-2026-85593 phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode 04.09.2026
CVE-2026-85594 Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware 04.09.2026
CVE-2026-85595 Traefik before v2.11.55 Authentication Bypass via digestAuth 04.09.2026
CVE-2026-85596 Traefik v3.7 Authentication Bypass via TLS Option Conflict 04.09.2026
CVE-2026-85597 Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict 04.09.2026
CVE-2026-85598 Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages 04.09.2026
CVE-2026-85599 Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters 04.09.2026
CVE-2026-85600 Grav Admin before 2.0.21 Stored XSS via username 04.09.2026
CVE-2026-85601 Grav Admin before 2.0.20 Cross-Site Scripting via marked.js 04.09.2026
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass 04.09.2026
CVE-2026-85603 Grav Admin Plugin Path Traversal via Save As Language Code 04.09.2026
CVE-2026-85604 Grav before 2.0.19 Remote Code Execution via sort filter 04.09.2026
CVE-2026-85609 Openpanel before 2.3.0 SSRF via Site Checker Endpoint 04.09.2026
CVE-2026-85610 OpenPanel before 2.3.0 Remote Code Execution via chart formulas 04.09.2026
CVE-2026-85611 OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures 04.09.2026
CVE-2026-85612 OpenPanel before 2.3.0 SSRF via favicon and og endpoints 04.09.2026
CVE-2026-85613 OpenPanel Unauthenticated XSS via SVG Favicon Proxy 04.09.2026
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker 04.09.2026
CVE-2026-85615 Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts 04.09.2026
CVE-2026-85616 Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance 04.09.2026
CVE-2026-85617 snipe-it before 8.6.3 Authorization Bypass via Bulk Delete 04.09.2026
CVE-2026-27347 WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability 04.09.2026 5.3
CVE-2026-84428 fastify vulnerable to header validation bypass via incomplete schema case normalization 04.09.2026 7.5
CVE-2026-4644 Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover 04.09.2026
CVE-2026-79707 Arbitrary File Read in Google Agent Development Kit (ADK) 04.09.2026
CVE-2026-84045 E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart 04.09.2026 5.3
CVE-2026-85512 SourceCodester Class and Exam Timetabling System session.php authorization 04.09.2026
CVE-2026-85534 Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read 04.09.2026
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes 04.09.2026 9.8
CVE-2026-84043 ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypass 04.09.2026 5.3
CVE-2026-84044 Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPN 04.09.2026 5.3
CVE-2026-84469 fastify vulnerable to request validation bypass via skipped boolean false schemas 04.09.2026 7.5