CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-61534 Yayson: Prototype pollution in the Store/LegacyStore deserialization 14.09.2026 9.1
CVE-2026-90943 parallax filament-comments through 3.0.0 Stored XSS via Comment Body 14.09.2026 9.3
CVE-2026-57124 PraisonAI UI MCP connect endpoint allows unauthenticated local command execution 14.09.2026 9.8
CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set 14.09.2026 9.8
CVE-2026-57131 praisonai: Jobs API exposes agent-execution endpoints with no authentication 14.09.2026 9.8
CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation 14.09.2026 9.1
CVE-2026-57123 PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in 14.09.2026 9.8
CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass 14.09.2026 9.8
CVE-2026-82434 Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs 14.09.2026 10
CVE-2026-90961 MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials 14.09.2026 9.3
CVE-2026-90937 froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL 14.09.2026 9.4
CVE-2026-12258 Inadequate access control in the Hiperdino REST API 14.09.2026 9.2
CVE-2026-90919 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization 14.09.2026 9.3
CVE-2026-21391 Improper Claim Validation in PingAM OIDC Provider 14.09.2026 9.5
CVE-2026-90898 Bifrost unauthenticated remote code execution via MCP stdio client registration 14.09.2026 9.8
CVE-2026-90703 D-Link DWR-M921 formDiskCreateShare system os command injection 14.09.2026 9.4
CVE-2026-90702 D-Link DWR-M921 formDiskFormat system os command injection 14.09.2026 9.4
CVE-2026-90699 D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection 14.09.2026 9.4
CVE-2026-90693 D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow 14.09.2026 9.4
CVE-2026-90692 D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow 14.09.2026 9.4
CVE-2026-85192 Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 14.09.2026 9.4
CVE-2026-90680 D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow 14.09.2026 9.4
CVE-2026-90607 Totolink A3002MU boa formNewSchedule buffer overflow 14.09.2026 9.4
CVE-2026-90608 Totolink A3002MU boa formPortFw buffer overflow 14.09.2026 9.4
CVE-2026-90606 Totolink A3002MU boa formIpv6Setup buffer overflow 13.09.2026 9.4
CVE-2026-90605 Totolink A3002MU boa formFilter buffer overflow 13.09.2026 9.4
CVE-2026-81648 CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router 14.09.2026 10
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG 13.09.2026 9.3
CVE-2026-90562 LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key 13.09.2026 9.2
CVE-2026-90493 Tonec Internet Download Manager Kernel Driver idmwfp.sys access control 13.09.2026 9.3
CVE-2026-90647 12.09.2026 9.1
CVE-2026-90558 sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers 12.09.2026 9.3
CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution 12.09.2026 9.8
CVE-2026-78159 The Events Calendar <= 6.17.3 - Unauthenticated Code Injection to Remote Code Execution via Widget 'classes' Map Callable Invocation 12.09.2026 9.8
CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 12.09.2026 10
CVE-2026-87719 Deserialization of Untrusted Data in GitLab 14.09.2026 9.9
CVE-2026-90456 14.09.2026 9.2
CVE-2026-89697 nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() 14.09.2026 9.1
CVE-2026-89702 nfsd: size fh_verify server sockaddr slot by xpt_locallen 13.09.2026 9.8
CVE-2026-89703 nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations 13.09.2026 9.8
CVE-2026-89708 nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown 13.09.2026 9.8
CVE-2026-89712 NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock 14.09.2026 9.8
CVE-2026-89713 NFSD: check truncate permission under inode lock 13.09.2026 9.1
CVE-2026-80945 crypto: iaa - unmap dst before software fallback on decompress 13.09.2026 9.1
CVE-2026-80976 seg6: reset IP6CB after IPv6 decapsulation 14.09.2026 9.8
CVE-2026-80980 net/smc: stop killed, freed and out_of_sync sharing a byte 13.09.2026 9.8
CVE-2026-80981 net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() 13.09.2026 9.8
CVE-2026-80986 net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages 13.09.2026 9.8
CVE-2026-81002 xdp: fix zero-copy frame layout 14.09.2026 9.8
CVE-2026-89448 iommu/vt-d: Force requesting ACS when tboot is enabled 14.09.2026 9.3
CVE-2026-89478 sctp: drop a chunk if its transport was removed 14.09.2026 9.8
CVE-2026-89479 sctp: stop processing a packet once its association is deleted 14.09.2026 9.8
CVE-2026-89482 nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone 14.09.2026 9.8
CVE-2026-89485 lockd: pin next file across nlm_inspect_file lock-drop 14.09.2026 9.8
CVE-2026-89492 ocfs2: validate directory-index entry counts when reading metadata 13.09.2026 9.8
CVE-2026-89494 ocfs2: validate lengths in dlm_mig_lockres_handler 14.09.2026 9.8
CVE-2026-89495 ocfs2: bound namelen in dlm_migrate_request_handler 14.09.2026 9.8
CVE-2026-89526 svcrdma: Validate Read chunk positions before reconstruction 13.09.2026 9.8
CVE-2026-89530 svcrdma: Reject inline replies that overflow the pull-up buffer 13.09.2026 9.8
CVE-2026-89532 svcrdma: Fix pcl_for_each_segment for empty chunks 14.09.2026 9.1
CVE-2026-89533 svcrdma: Fix offset arithmetic in read_chunk_range 14.09.2026 9.8
CVE-2026-89536 SUNRPC: wait for in-flight client TLS handshake callback 14.09.2026 9.8
CVE-2026-89537 SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 13.09.2026 9.1
CVE-2026-89538 SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field 14.09.2026 9.8
CVE-2026-89541 SUNRPC: harden gss_unwrap_resp_priv length checks 14.09.2026 9.8
CVE-2026-89542 SUNRPC: harden gss_krb5_unwrap_v2 against short tokens 14.09.2026 9.8
CVE-2026-89546 SUNRPC: close backchannel before destroying callback service 13.09.2026 9.8
CVE-2026-89550 SUNRPC: svcauth_gss: enforce krb5 token minimum length 14.09.2026 9.8
CVE-2026-89551 SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow 14.09.2026 9.8
CVE-2026-89555 mpls: reload header after pskb_may_pull() 14.09.2026 9.8
CVE-2026-89558 md/raid10: fix still_degraded being inverted in raid10_sync_request() 13.09.2026 9.8
CVE-2026-89610 ntfs: verify run length exceeding volume boundary 13.09.2026 9.8
CVE-2026-89611 ntfs: validate non-resident attribute offsets 13.09.2026 9.8
CVE-2026-89612 ntfs: reject invalid MFT LCNs from boot sector 13.09.2026 9.8
CVE-2026-89613 ntfs: reject invalid empty mapping pairs 13.09.2026 9.8
CVE-2026-89614 ntfs: bound the free-cluster bitmap scan to the volume 13.09.2026 9.8
CVE-2026-89630 smb: client: restore the data_offset bound in is_valid_oplock_break() 13.09.2026 9.1
CVE-2026-89631 smb: client: reject a tree connect response whose byte count is too small 13.09.2026 9.1
CVE-2026-89633 smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() 13.09.2026 9.8
CVE-2026-89634 smb: client: fix ALIGN() overflow in symlink_data() error context loop 14.09.2026 9.1
CVE-2026-89635 ksmbd: only rebind the reopened file's own oplock on durable reconnect 13.09.2026 9.8
CVE-2026-89636 smb: client: clear ce->tgthint in free_tgts() 14.09.2026 9.8
CVE-2026-89637 smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 13.09.2026 9.8
CVE-2026-89643 audit: avoid dropping live tree ref on fsnotify rule autoremove 14.09.2026 9.8
CVE-2026-89649 ceph: bound xattr value length in __build_xattrs() 14.09.2026 9.1
CVE-2026-89650 ceph: bound num_export_targets array for mds info v2/v3 14.09.2026 9.1
CVE-2026-89651 ceph: bound MDSCapAuth path and fs_name decode in handle_session() 13.09.2026 9.8
CVE-2026-89652 ceph: bound copied dentry name length in NFS export get_name 14.09.2026 9.8
CVE-2026-89653 ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode 14.09.2026 9.8
CVE-2026-89654 ceph: fix UAF in check_new_map() on session freed during unlock 13.09.2026 9.8
CVE-2026-89655 ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock 14.09.2026 9.8
CVE-2026-89656 libceph: reject buckets with mismatched CRUSH ids 14.09.2026 9.8
CVE-2026-89658 NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup 13.09.2026 9.8
CVE-2026-89659 NFSD: Prevent client use-after-free during delegation revoke 13.09.2026 9.8
CVE-2026-89660 NFSD: Prevent client use-after-free during admin state revocation 13.09.2026 9.8
CVE-2026-89662 NFSD: Prevent lock owner use-after-free during client teardown 14.09.2026 9.8
CVE-2026-89669 nfsd: initialize copy-notify stateid before publishing it 14.09.2026 9.8
CVE-2026-89671 nfsd: gate nfs3 setacl by argp->mask 14.09.2026 9.1
CVE-2026-89672 nfsd: gate nfs2 setacl by argp->mask 14.09.2026 9.1
CVE-2026-89674 nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget 14.09.2026 9.8
CVE-2026-89675 nfsd: fix UAF in async copy cancel and shutdown 13.09.2026 9.8
CVE-2026-89676 nfsd: fix stale s2s_cp_stateids IDR entry for async COPY 13.09.2026 9.8
CVE-2026-89677 nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() 13.09.2026 9.8
CVE-2026-89681 nfsd: fix layout fence worker double-reference race 13.09.2026 9.8
CVE-2026-89686 nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke 13.09.2026 9.8
CVE-2026-89688 nfsd: drop the stateid, not the stateowner, on seqid_op replay retry 13.09.2026 9.8
CVE-2026-89689 nfsd: don't free session slots that are still in use 13.09.2026 9.8
CVE-2026-80926 ksmbd: fix use-after-free in oplock break notification 13.09.2026 9.8
CVE-2026-53952 GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setup Logic Flaw 11.09.2026 9.8
CVE-2026-54072 Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL 11.09.2026 9.3
CVE-2026-62103 WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-62105 WordPress ThemeREX Addons plugin < 2.45.0 - PHP Object Injection vulnerability 11.09.2026 9.8
CVE-2026-82617 Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns 11.09.2026 10
CVE-2026-72709 SPIP < 4.4.18 Missing Authorization via ecrire/action/ editer_auteur 11.09.2026 9.3
CVE-2026-72710 SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection 11.09.2026 9.3
CVE-2026-54047 Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-Side Configuration Manipulation 11.09.2026 9.2
CVE-2026-3869 11.09.2026 9.2
CVE-2026-89010 WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server 11.09.2026 9.3
CVE-2026-38056 ST Engineering iDirect iQ-Series Terminals Missing Authorization 11.09.2026 9.4
CVE-2026-87987 11.09.2026 10
CVE-2026-87988 11.09.2026 10
CVE-2026-87983 11.09.2026 9.2
CVE-2026-87984 11.09.2026 9.3
CVE-2026-87985 11.09.2026 10
CVE-2026-87986 11.09.2026 10
CVE-2026-89212 XML External Entity in Akana API Platform 11.09.2026 9.2
CVE-2026-80462 Privilege Escalation in Progress Chef Automate 11.09.2026 10
CVE-2026-84390 11.09.2026 9.6
CVE-2026-89243 WWBN AVideo Stored XSS via UserGroups setGroup_name 11.09.2026 9.2
CVE-2026-89249 AVideo YPTWallet Stored XSS via CryptoWallet Configuration 11.09.2026 9.3
CVE-2026-89253 AVideo Stored XSS via donationLink in watch page button 11.09.2026 9.3
CVE-2026-89254 AVideo CustomizeUser Stored XSS via field_name Parameter 11.09.2026 9.3
CVE-2026-89255 AVideo LoginControl Stored XSS via PGP Public Key 11.09.2026 9.3
CVE-2026-89256 AVideo Bookmark Plugin Stored XSS via Chapter Names 11.09.2026 9.3
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get 11.09.2026 9.3
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS 11.09.2026 9.3
CVE-2026-47839 Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin 11.09.2026 9.2
CVE-2026-8778 MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload 11.09.2026 9.8
CVE-2026-19646 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 11.09.2026 9.1
CVE-2026-78573 IBM ContextForge MCP Gateway is affected by use of default credentials 11.09.2026 9.8
CVE-2026-79724 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-80424 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 10.09.2026 9.1
CVE-2026-81204 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-82100 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-82107 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 11.09.2026 9.6
CVE-2026-45764 Suricata http2: protocol-change type confusion can lead to denial of service 11.09.2026 9.1
CVE-2026-75940 11.09.2026 9.3
CVE-2026-85025 Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards 12.09.2026 9.8
CVE-2026-89094 14.09.2026 9.9
CVE-2026-89086 10.09.2026 9.1
CVE-2026-88062 OmniRoute ACP Custom-Agent Remote Code Execution (RCE) 11.09.2026 9.5
CVE-2026-89042 passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification 11.09.2026 9.3
CVE-2026-89043 passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending 10.09.2026 9.1
CVE-2026-65638 10.09.2026 9.2
CVE-2026-65639 10.09.2026 9.5
CVE-2026-68487 10.09.2026 9.9
CVE-2026-68488 10.09.2026 9.9
CVE-2026-88044 rclone: RC per-server auth-proxy bypass 10.09.2026 9.1
CVE-2026-88018 rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass 10.09.2026 9.8
CVE-2026-81046 11.09.2026 9.4
CVE-2026-81467 11.09.2026 9.8
CVE-2026-81468 11.09.2026 9.1
CVE-2026-81048 11.09.2026 9.6
CVE-2026-88899 knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header 11.09.2026 9.3
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse 10.09.2026 9.1
CVE-2026-81800 WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability 11.09.2026 9.3
CVE-2026-88860 Capgo Authorization Bypass via Stale Channel Permission Overrides 10.09.2026 9.3
CVE-2026-88864 Capgo SSO Provider Authentication Bypass via PostgREST Direct Write 10.09.2026 9.3
CVE-2026-88866 WWBN AVideo LoginControl Stored XSS via User-Agent Header 10.09.2026 9.3
CVE-2026-88867 WWBN AVideo Stored XSS via Category Name and Icon Class 10.09.2026 9.3
CVE-2026-88868 AVideo LiveLinks Stored XSS via title and description fields 10.09.2026 9.3
CVE-2026-88869 AVideo AD_Server Stored XSS via log.php label parameter 10.09.2026 9.3
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect 10.09.2026 9.3
CVE-2026-88880 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88881 Renovate before 44.11.3 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88882 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-88887 Renovate before 44.11.2 Credential Exfiltration via Link Header 10.09.2026 9.2
CVE-2026-9163 SQLi in GIS Informatics' GisLab Laboratory Management System 10.09.2026 9.8
CVE-2026-78082 Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 11.09.2026 9.3
CVE-2026-8323 Open Redirect in Armiya Information Technologies' Access Control System 10.09.2026 9.3
CVE-2026-13745 Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables 10.09.2026 9.2
CVE-2026-44950 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2 10.09.2026 9.5
CVE-2026-59679 fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2 10.09.2026 9.2
CVE-2026-88278 GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay 10.09.2026 9.8
CVE-2026-88285 GV-LPC2011/LPC2211 - Unauthenticated PTZ Control Service 10.09.2026 9.4
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 11.09.2026 9.9
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026 9.4
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 10.09.2026 9.3
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 10.09.2026 9
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 10.09.2026 9.6
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 14.09.2026 9.3
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026 9.2
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 10.09.2026 9.3
CVE-2026-67401 10.09.2026 9.9
CVE-2026-67403 09.09.2026 9
CVE-2026-68484 09.09.2026 9
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-80172 11.09.2026 9.8
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026 9.1
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026 10
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026 10
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module 09.09.2026 9.1
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist 09.09.2026 10
CVE-2026-21095 11.09.2026 9.2
CVE-2026-21096 11.09.2026 9.2
CVE-2026-21102 11.09.2026 9.3
CVE-2026-53939 OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption 09.09.2026 9.1
CVE-2026-53581 ntp: write path traversal 09.09.2026 9
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector 10.09.2026 9
CVE-2026-84197 09.09.2026 9.2
CVE-2026-19232 Adobe Experience Manager | Incorrect Authorization (CWE-863) 10.09.2026 9.9
CVE-2026-86464 09.09.2026 9.9
CVE-2026-48273 ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 09.09.2026 9.9
CVE-2026-75746 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 09.09.2026 9.1
CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 12.09.2026 9.9
CVE-2026-28659 09.09.2026 10
CVE-2026-49883 10.09.2026 10
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 11.09.2026 10
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability 11.09.2026 9.6
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 11.09.2026 9.3
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 11.09.2026 9.1
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability 11.09.2026 9
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability 11.09.2026 9.8
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability 11.09.2026 9.8
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability 11.09.2026 9.6
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability 11.09.2026 9.9
CVE-2026-82533 DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing 10.09.2026 9.4
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup 08.09.2026 9.2
CVE-2026-86729 WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize 10.09.2026 9.1
CVE-2026-86738 Snipe-IT before 8.7.0 CSS Injection via Custom CSS 08.09.2026 9.3
CVE-2026-12647 09.09.2026 9.9
CVE-2026-12645 09.09.2026 9.9
CVE-2026-12646 09.09.2026 9.9
CVE-2026-12650 09.09.2026 9.9
CVE-2026-12744 09.09.2026 9.8
CVE-2026-12745 09.09.2026 9.8
CVE-2026-61516 Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint 08.09.2026 9.3
CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint 09.09.2026 9.1
CVE-2026-73311 XenForo < 2.3.13 OAuth2 Authorization Code Reuse 10.09.2026 9.1
CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token 09.09.2026 9.1
CVE-2026-77089 Command Center API Authentication Bypass 09.09.2026 9.3
CVE-2026-78234 Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users 08.09.2026 9.9
CVE-2026-62645 08.09.2026 9.3
CVE-2026-62646 10.09.2026 9.1
CVE-2026-62647 14.09.2026 9.3
CVE-2026-67367 09.09.2026 9.2
CVE-2026-71376 OS Command Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71377 Command Argument Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 11.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 09.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 09.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 11.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 09.09.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-4103 Cross-Site Scripting via HTML Sanitization in WSO2 Publisher and Developer Portals Allows Malicious Script Execution 14.09.2026 6.4
CVE-2026-53708 ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) 14.09.2026 6.6
CVE-2026-55235 langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication 14.09.2026 5.9
CVE-2026-55795 Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass 14.09.2026
CVE-2026-90994 Sssd: sssd: denial of service via malformed pam v1 requests 14.09.2026
CVE-2026-90995 Sssd: sssd: local denial of service due to null pointer dereference in pam responder 14.09.2026
CVE-2026-90996 Sssd: sssd: denial of service in nss responder via crafted zero-length requests 14.09.2026
CVE-2026-55236 langgraph-api: Incomplete assistant authorization in LangGraph Server run creation 14.09.2026 5.9
CVE-2026-81301 Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access 14.09.2026
CVE-2026-90795 itsourcecode Loan Management System navbar.php cross site scripting 14.09.2026
CVE-2026-47701 OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth 14.09.2026 7.7
CVE-2026-54529 SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list` 14.09.2026 5.3
CVE-2026-54541 Nimiq: Panic in TrieProof::verify via child_index unwrap on equal-length keys 14.09.2026 3.7
CVE-2026-54542 Nimiq: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof 14.09.2026 3.7
CVE-2026-61534 Yayson: Prototype pollution in the Store/LegacyStore deserialization 14.09.2026 9.1
CVE-2026-88819 14.09.2026
CVE-2026-90794 GPAC MP4Box vrml_tools.c gf_sg_script_load use after free 14.09.2026
CVE-2026-90943 parallax filament-comments through 3.0.0 Stored XSS via Comment Body 14.09.2026 8.7
CVE-2025-24890 gix-sec safe.directory protections absent for elevated administrators 14.09.2026 6.8
CVE-2026-87087 14.09.2026
CVE-2026-90463 Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`) 14.09.2026
CVE-2026-90793 GPAC MP4Box base_scenegraph.c gf_node_get_name use after free 14.09.2026
CVE-2026-90947 Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file 14.09.2026
CVE-2026-56839 PraisonAI Code agent tools fail open without a workspace boundary 14.09.2026 7.3
CVE-2026-57119 PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API 14.09.2026 7.5
CVE-2026-57122 PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots) 14.09.2026 8.6
CVE-2026-57124 PraisonAI UI MCP connect endpoint allows unauthenticated local command execution 14.09.2026 9.8
CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set 14.09.2026 9.8
CVE-2026-57131 praisonai: Jobs API exposes agent-execution endpoints with no authentication 14.09.2026 9.8
CVE-2026-57132 PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication 14.09.2026 8.2
CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation 14.09.2026 9.1
CVE-2026-90792 GPAC MP4Box base_scenegraph.c gf_node_list_get_child null pointer dereference 14.09.2026
CVE-2026-57129 PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal 14.09.2026 7.5
CVE-2026-57120 PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder 14.09.2026 6.5
CVE-2026-57123 PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in 14.09.2026 9.8
CVE-2026-57126 praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS 14.09.2026 8.5
CVE-2026-59570 Android ZCC denial of service 14.09.2026 7.5
CVE-2026-25687 ZCC race condition in ZPA tunnel handler 14.09.2026 8.1
CVE-2026-59569 Android ZCC VPN API method privilege escalation 14.09.2026 8.1
CVE-2026-90791 GPAC MP4Box base_scenegraph.c gf_node_unregister use after free 14.09.2026
CVE-2026-57128 PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint 14.09.2026 4.3
CVE-2026-57130 PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters 14.09.2026 8.1
CVE-2026-90790 a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch_notification server-side request forgery 14.09.2026
CVE-2026-12985 Mattermost DCR redirect URI allowlist bypass via improper URL component validation 14.09.2026 6.8
CVE-2026-15600 SQL Injection in Alior Bank raty PrestaShop module 14.09.2026
CVE-2026-57115 PraisonAI: SpiderTools redirect-target SSRF protection bypass 14.09.2026 6.5
CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass 14.09.2026 9.8
CVE-2026-7848 SQL Injection in Alior Bank raty PrestaShop module 14.09.2026
CVE-2026-82019 TripleLift video-bundle.js DOM-based XSS via postMessage 14.09.2026
CVE-2026-82426 Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location 14.09.2026
CVE-2026-82427 Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name 14.09.2026
CVE-2026-82428 Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys 14.09.2026
CVE-2026-82429 Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher 14.09.2026
CVE-2026-82430 Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant 14.09.2026
CVE-2026-82431 Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users 14.09.2026
CVE-2026-82432 Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides 14.09.2026
CVE-2026-82433 Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI 14.09.2026
CVE-2026-82434 Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs 14.09.2026
CVE-2026-82435 Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder 14.09.2026
CVE-2026-82437 Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer 14.09.2026
CVE-2026-82438 Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins 14.09.2026
CVE-2026-90789 itsourcecode Leave Management System login.php sql injection 14.09.2026
CVE-2026-82439 Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC 14.09.2026
CVE-2026-82441 Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys 14.09.2026
CVE-2026-82920 Mattermost ABAC parent policy bypass via policy update endpoint 14.09.2026 5.5
CVE-2026-84179 Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page 14.09.2026
CVE-2026-90788 magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection 14.09.2026
CVE-2026-90939 novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint 14.09.2026 6.5
CVE-2026-90940 novel-plus through 5.3.3 Default Cache Management Password in the Front Portal 14.09.2026 5.3
CVE-2026-90941 novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint 14.09.2026 4.3
CVE-2026-86348 MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin process 14.09.2026 4.3
CVE-2026-86349 Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting 14.09.2026 4.3
CVE-2026-90787 Soarkey StudentManagement Registration Workflow register.html RegisterServlet.doPost privileges management 14.09.2026
CVE-2026-90786 Dvidelabs flatcc Duplicate Symbol semantics.c align_order_members assertion 14.09.2026
CVE-2026-73191 Apache Syncope: CAS service URL injection via Forwarded HTTP headers 14.09.2026
CVE-2026-73195 Apache Syncope: CSV export spreadsheet formula injection 14.09.2026
CVE-2026-73236 Apache Syncope: Cross-Realm authorization bypass in delegated administration 14.09.2026
CVE-2026-73370 Apache Syncope: Cross-Realm boundaries reconciliation bypass 14.09.2026
CVE-2026-7208 Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion 14.09.2026
CVE-2026-90785 Dvidelabs flatcc Struct Analysis semantics.c analyze_struct assertion 14.09.2026
CVE-2026-90948 Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions 14.09.2026
CVE-2026-90949 Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch 14.09.2026
CVE-2026-90961 MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials 14.09.2026
CVE-2026-73178 Apache Syncope: JWT Access Token takeover 14.09.2026
CVE-2026-73470 Apache Syncope: Delegating users can grant unowned Roles 14.09.2026
CVE-2026-78299 14.09.2026
CVE-2026-90784 Dvidelabs flatcc semantics.c fb_clear_parser memory leak 14.09.2026
CVE-2026-90957 MISP: Stored XSS via Inline-Served SVG Organisation Logos and Report Pictures 14.09.2026
CVE-2024-58383 Froxlor before 2.2.0 Insecure File Permissions mysql.conf 14.09.2026
CVE-2026-73579 Apache Syncope: Non-recursive Any search could skip Realms restrictions 14.09.2026
CVE-2026-73668 Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values 14.09.2026
CVE-2026-75015 Apache Syncope: Nested secrets leak cleartext into audit records readable 14.09.2026
CVE-2026-75030 Apache Syncope: Incomplete authorization checks for Group members deprovisioning 14.09.2026
CVE-2026-77051 Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search 14.09.2026
CVE-2026-77147 Apache Syncope: Groovy Sandbox escape for empty CommandArgs 14.09.2026
CVE-2026-77181 Apache Syncope: ClientApp update entitlement not effective 14.09.2026
CVE-2026-90716 marcobambini Gravity Number gravity_parser.c parse_number_expression out-of-bounds 14.09.2026
CVE-2026-90927 filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message 14.09.2026
CVE-2026-90928 File Browser through 2.63.23 Memory Exhaustion via subtitle endpoint 14.09.2026
CVE-2026-90929 File Browser 2.5.0 Directory Deletion via Upload Failure Cleanup 14.09.2026
CVE-2026-90930 File Browser through 2.63.23 Path Traversal via Symlink Alias 14.09.2026
CVE-2026-90931 LaraDashboard 0.9.0 through 1.2.2 Stored XSS via SVG Upload 14.09.2026
CVE-2026-90932 LaraDashboard 0.9.2 through 1.2.2 Path Traversal RCE 14.09.2026
CVE-2026-90933 laradashboard through 1.2.2 Missing Authorization via License API 14.09.2026
CVE-2026-90934 EspoCRM before 10.0.4 Field-level Security Bypass via Attendees 14.09.2026
CVE-2026-90935 Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API 14.09.2026
CVE-2026-90936 Froxlor before 2.3.7 Information Disclosure via customer_email.php 14.09.2026
CVE-2026-90937 froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL 14.09.2026
CVE-2026-90938 LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket 14.09.2026
CVE-2026-77883 Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist 14.09.2026
CVE-2026-78318 Apache Syncope: Unauthenticated reflected XSS in Console and Enduser 14.09.2026
CVE-2026-78330 Apache Syncope: Privilege escalation for admin user via JWT authentication 14.09.2026
CVE-2026-78336 Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user 14.09.2026
CVE-2026-90715 marcobambini Gravity udp json-parser gravity_json.c integer overflow 14.09.2026
CVE-2026-90955 MISP CLI Shell Audit Logs Lose User Identity and CLI Marker After First Lazy Model Load 14.09.2026
CVE-2026-12258 Inadequate access control in the Hiperdino REST API 14.09.2026
CVE-2026-90713 vllm-project vLLM tiktoken vocab File mod.rs new denial of service 14.09.2026
CVE-2026-90714 marcobambini Gravity JSON parser gravity_json.c memory corruption 14.09.2026
CVE-2026-90712 Gitlawb openclaude xAI OAuth Callback xaiOAuthCallback.ts waitForCallback denial of service 14.09.2026
CVE-2026-90919 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization 14.09.2026
CVE-2026-90710 taisan tarzan-cms Theme Download Function ThemeService.java openConnection server-side request forgery 14.09.2026
CVE-2026-21391 Improper Claim Validation in PingAM OIDC Provider 14.09.2026
CVE-2026-79701 Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 14.09.2026
CVE-2026-90709 Yot CMS Admin Console admin.php eval code injection 14.09.2026
CVE-2026-78375 Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 14.09.2026
CVE-2026-79700 Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 14.09.2026
CVE-2026-81564 Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 14.09.2026
CVE-2026-81565 Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 14.09.2026
CVE-2026-81566 Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 14.09.2026
CVE-2026-90708 Yot CMS Cookie global.php login sql injection 14.09.2026
CVE-2026-10556 Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin. 14.09.2026 5.3
CVE-2026-13417 Boards plugin denial of service via unvalidated block fields.properties 14.09.2026 4.3
CVE-2026-82232 Apache Syncope: SQL injection via sort parameter in Task search 14.09.2026
CVE-2026-90707 Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free 14.09.2026
CVE-2026-10542 Playbooks channel action update validation issue 14.09.2026 5
CVE-2026-15814 Uploading a crafted image causes excessive memory allocation in the Mattermost Server 14.09.2026 6.5
CVE-2026-20773 Improper Authorization in PingFederate Administrative Expression Evaluation Endpoint 14.09.2026
CVE-2026-5132 Unbounded zlib decompression in Calls SDP WebSocket messages 14.09.2026 6.5
CVE-2026-86460 Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence 14.09.2026
CVE-2026-87779 Apache Syncope: AES Secret Key disclosure via log output 14.09.2026
CVE-2026-87785 Apache Syncope: JWT subject spoofing 14.09.2026
CVE-2026-8821 Playbooks run owner channel membership permission bypass 14.09.2026 7.1
CVE-2026-90890 ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference 14.09.2026
CVE-2026-90891 ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control 14.09.2026
CVE-2026-9812 Missing property field ownership validation in Playbooks run property update endpoint 14.09.2026 6.5
CVE-2026-11993 Fix authenticated members disabling file content indexing server-wide via extraction pool exhaustion 14.09.2026 4.3
CVE-2026-12882 Mattermost Markdown autolink parsing denial of service 14.09.2026 4.3
CVE-2026-14259 Board archive import bypasses team board creation permissions 14.09.2026 4.3
CVE-2026-14344 Inconsistent authorization checks in Mattermost Boards endpoints 14.09.2026 4.3
CVE-2026-89180 Thinking Software Technology|EFence - SQL Injection 14.09.2026
CVE-2026-90706 D-Link DWR-M921 formWsc os command injection 14.09.2026
CVE-2026-87802 Apache Syncope: SRA OAuth2 JWT signature verification bypass 14.09.2026
CVE-2026-90705 D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection 14.09.2026
CVE-2026-90898 Bifrost unauthenticated remote code execution via MCP stdio client registration 14.09.2026 9.8
CVE-2026-68570 Apache Doris: Authorization bypass leading to unauthorized data access 14.09.2026
CVE-2026-72524 Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables 14.09.2026
CVE-2026-90704 D-Link DWR-M921 formDiskPartition system command injection 14.09.2026
CVE-2026-90894 Parallels Desktop local privilege escalation via appliance extract argument injection 14.09.2026 7.8
CVE-2026-90703 D-Link DWR-M921 formDiskCreateShare system os command injection 14.09.2026
CVE-2026-90702 D-Link DWR-M921 formDiskFormat system os command injection 14.09.2026
CVE-2026-90895 MISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal Injection 14.09.2026
CVE-2026-90701 subhajitkhan online-clinic-management-system listdoctor.php sql injection 14.09.2026
CVE-2026-90893 MISP UserSettingsController CSRF Protection Bypass on setTheme, setHomePage, and eventIndexColumnToggle Endpoints 14.09.2026
CVE-2026-90700 itsourcecode Sales and Inventory System pro_edit1.php sql injection 14.09.2026
CVE-2026-88932 multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads 14.09.2026 5.3
CVE-2026-90699 D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection 14.09.2026
CVE-2026-90698 memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds 14.09.2026
CVE-2026-89321 14.09.2026 4.3
CVE-2026-90696 SourceCodester Inventory Management System Product Management products_handler.php cross site scripting 14.09.2026
CVE-2026-90697 SourceCodester Inventory Management System invoice.php authorization 14.09.2026
CVE-2026-90695 SourceCodester Inventory Management System Vendor Management vendors_handler.php cross site scripting 14.09.2026
CVE-2026-12518 Local privilege escalation in the Logi Options+ updater service on Windows 14.09.2026
CVE-2026-90693 D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow 14.09.2026
CVE-2026-90694 SourceCodester Inventory Management System Customer Management customers_handler.php cross site scripting 14.09.2026
CVE-2026-71198 14.09.2026
CVE-2026-90692 D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow 14.09.2026
CVE-2023-51769 14.09.2026 6.1
CVE-2024-23176 14.09.2026 5.4
CVE-2025-26790 14.09.2026 3.7
CVE-2026-25832 14.09.2026 3.7
CVE-2026-68955 14.09.2026
CVE-2026-82762 14.09.2026 8.8
CVE-2026-82763 14.09.2026 5.4
CVE-2026-82764 14.09.2026
CVE-2026-82765 14.09.2026 8.1
CVE-2026-82766 14.09.2026 8.8
CVE-2026-82767 14.09.2026 5.2
CVE-2026-82768 14.09.2026 8.1
CVE-2026-82769 14.09.2026 5.4
CVE-2026-82770 14.09.2026 8.8
CVE-2026-82771 14.09.2026 5.4
CVE-2026-82772 14.09.2026 8.8
CVE-2026-82773 14.09.2026 6.1
CVE-2026-82774 14.09.2026 8.8
CVE-2026-82775 14.09.2026 4.3
CVE-2026-82776 14.09.2026 6.1
CVE-2026-82777 14.09.2026 8.8
CVE-2026-82778 14.09.2026 4.3
CVE-2026-82779 14.09.2026 8.8
CVE-2026-82780 14.09.2026 8.8
CVE-2026-82781 14.09.2026 5.4
CVE-2026-82782 14.09.2026 4.3
CVE-2026-82783 14.09.2026 4.2
CVE-2026-82784 14.09.2026 6.5
CVE-2026-82785 14.09.2026 4.3
CVE-2026-82786 14.09.2026 6.3
CVE-2026-82787 14.09.2026 9.8
CVE-2026-82788 14.09.2026 6.1
CVE-2026-82789 14.09.2026 8.8
CVE-2026-82790 14.09.2026 5.4
CVE-2026-82791 14.09.2026 8.8
CVE-2026-82792 14.09.2026 5.2
CVE-2026-82793 14.09.2026 7.2
CVE-2026-82794 14.09.2026 8.8
CVE-2026-82795 14.09.2026 5.4
CVE-2026-82796 14.09.2026 5.4
CVE-2026-85125 14.09.2026
CVE-2026-85189 Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 14.09.2026
CVE-2026-85190 Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 14.09.2026
CVE-2026-85192 Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 14.09.2026
CVE-2026-85196 Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 14.09.2026
CVE-2026-88852 Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 14.09.2026
CVE-2026-90689 Tenda W20E formDelWebAuthWhiteUser stack-based overflow 14.09.2026
CVE-2026-90690 0x4m4 HexStrike AI API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection 14.09.2026
CVE-2026-90691 0x4m4 HexStrike AI API Files Endpoint hexstrike_server.py FileOperationsManager path traversal 14.09.2026
CVE-2023-50459 14.09.2026 5.4
CVE-2023-50460 14.09.2026 5.4
CVE-2023-50461 14.09.2026 8.8
CVE-2023-50462 14.09.2026 5.3
CVE-2026-85188 Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla 14.09.2026
CVE-2026-85191 Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 14.09.2026
CVE-2026-85195 Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 14.09.2026
CVE-2026-88853 Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 14.09.2026
CVE-2026-90688 Tenda W20E HTTP formIPMacBindAdd stack-based overflow 14.09.2026
CVE-2023-46273 14.09.2026 8.8
CVE-2026-16726 14.09.2026
CVE-2026-90687 GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free 14.09.2026
CVE-2023-45858 14.09.2026 8.6
CVE-2023-46035 14.09.2026 5.9
CVE-2023-40772 14.09.2026 4.3
CVE-2023-45023 14.09.2026 4.2
CVE-2026-90686 GPAC MP4Box loader_bt.c gf_bt_report memory corruption 14.09.2026
CVE-2023-37253 14.09.2026 3.1
CVE-2023-37366 14.09.2026 2.8
CVE-2026-90685 GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion 14.09.2026
CVE-2023-34854 14.09.2026 6.6
CVE-2023-37252 14.09.2026 3.1
CVE-2026-90684 GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion 14.09.2026
CVE-2023-32803 14.09.2026 7.5
CVE-2023-32778 14.09.2026 3.3
CVE-2026-90683 GPAC MP4Box base_scenegraph.c gf_node_unregister assertion 14.09.2026
CVE-2023-28148 14.09.2026 7.2
CVE-2023-29377 14.09.2026 6.6
CVE-2026-90682 Matthias-Wandel jhead WebP EXIF gpsinfo.c ProcessGpsInfo heap-based overflow 14.09.2026
CVE-2023-24284 14.09.2026 2.9
CVE-2023-24285 14.09.2026 2.9
CVE-2023-24286 14.09.2026 2.9
CVE-2023-24287 14.09.2026 2.9
CVE-2023-24288 14.09.2026 2.9
CVE-2023-24291 14.09.2026 2.9
CVE-2026-90681 Matthias-Wandel jhead EXIF Parsing exif.c Get16u out-of-bounds 14.09.2026
CVE-2023-24283 14.09.2026 2.9
CVE-2026-90680 D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow 14.09.2026
CVE-2023-22632 14.09.2026 2.7
CVE-2023-24034 14.09.2026 3.1
CVE-2023-24035 14.09.2026 3.5
CVE-2026-90623 andreashappe cochise SSH Host Key ssh_connection.py asyncssh.connect certificate validation 14.09.2026
CVE-2023-22631 14.09.2026 2.7
CVE-2026-90621 ipa-lab HackingBuddyGPT ssh_run_command.py ssh_run_command os command injection 14.09.2026
CVE-2026-90622 GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference 14.09.2026
CVE-2026-90620 0x4m4 HexStrike AI API Command Endpoint hexstrike_server.py missing authentication 14.09.2026
CVE-2026-38924 14.09.2026 2.9
CVE-2026-90619 0x4m4 HexStrike AI Execute Endpoint hexstrike_server.py os command injection 14.09.2026
CVE-2026-33966 14.09.2026 2.8
CVE-2026-33967 14.09.2026 2.8
CVE-2026-33968 14.09.2026 2.8
CVE-2026-33970 14.09.2026 3.5
CVE-2026-90617 GH05TCREW PentestAgent MCP HTTP Server main.py run_task os command injection 14.09.2026
CVE-2026-90618 GH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injection 14.09.2026
CVE-2026-33960 14.09.2026 2.8
CVE-2026-33962 14.09.2026 2.8
CVE-2026-33963 14.09.2026 7.5
CVE-2026-33964 14.09.2026 6.4
CVE-2026-90614 FedML-AI FedML MQTT+S3 Communication Backend remote_storage.py S3Storage.read_model deserialization 14.09.2026
CVE-2026-90615 SourceCodester Class and Exam Timetabling System subject1.php cross site scripting 14.09.2026
CVE-2026-23793 14.09.2026 3.5
CVE-2026-31278 14.09.2026 7.7
CVE-2026-33956 14.09.2026 2.8
CVE-2026-33957 14.09.2026 4.2
CVE-2026-90613 GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion 14.09.2026
CVE-2026-23788 14.09.2026 4.2
CVE-2026-23789 14.09.2026 7.8
CVE-2026-23790 14.09.2026 4.2
CVE-2026-23791 14.09.2026 4.2
CVE-2026-23792 14.09.2026 4
CVE-2026-90610 GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read 14.09.2026
CVE-2026-90611 GPAC MP4Box loader_xmt.c xmt_parse_element assertion 14.09.2026
CVE-2026-90612 GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion 14.09.2026
CVE-2025-64031 14.09.2026 2.5
CVE-2025-68624 14.09.2026 4.3
CVE-2026-23786 14.09.2026 2.8
CVE-2026-23787 14.09.2026 4.2
CVE-2026-90607 Totolink A3002MU boa formNewSchedule buffer overflow 14.09.2026
CVE-2026-90608 Totolink A3002MU boa formPortFw buffer overflow 14.09.2026
CVE-2026-90609 GPAC MP4Box vrml_tools.c null pointer dereference 14.09.2026
CVE-2025-63842 14.09.2026 5.4
CVE-2026-90606 Totolink A3002MU boa formIpv6Setup buffer overflow 13.09.2026
CVE-2024-53922 13.09.2026 5.7
CVE-2026-90605 Totolink A3002MU boa formFilter buffer overflow 13.09.2026
CVE-2022-42917 13.09.2026 6.7
CVE-2026-90604 Totolink A3002MU Anchor Tag cross site scripting 14.09.2026
CVE-2026-90603 Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload 13.09.2026
CVE-2026-15891 NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway 14.09.2026 7.5
CVE-2026-15892 Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service 14.09.2026 5.3
CVE-2026-90602 Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting 13.09.2026
CVE-2026-90601 getzep graphiti REST API main.py improper authentication 13.09.2026
CVE-2026-90600 itsourcecode Sales and Inventory System inv_edit1.php sql injection 13.09.2026
CVE-2026-52297 13.09.2026 2.9
CVE-2026-90599 Rizwan17 inventory-management-system process.php cross-site request forgery 14.09.2026
CVE-2026-52296 13.09.2026 2.9
CVE-2026-90598 jaygajera17 E-commerce-project-springBoot UserController.java UserController.updateUser authorization 13.09.2026
CVE-2026-35867 14.09.2026 3.1
CVE-2026-90597 itsourcecode Sales and Inventory System sup_edit1.php sql injection 13.09.2026
CVE-2026-90596 embedded-graphics image_raw.rs new/bytes_per_row integer overflow 13.09.2026
CVE-2026-49030 13.09.2026
CVE-2026-90595 wxiaoqi Spring-Cloud-Platform OnlineController.java OnlineController.getOnlineInfo authorization 13.09.2026
CVE-2026-38332 13.09.2026 2.9
CVE-2026-90594 wxiaoqi Spring-Cloud-Platform Permission Service PermissionService.java PermissionService.checkUserPermission authorization 13.09.2026
CVE-2026-37008 13.09.2026 8.1
CVE-2026-90593 embedded-graphics image_raw.rs draw_sub_image integer overflow 13.09.2026
CVE-2026-36453 14.09.2026 7.4
CVE-2026-36989 13.09.2026 5.8
CVE-2026-74933 GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite 14.09.2026 8.8
CVE-2026-81648 CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router 14.09.2026 10
CVE-2026-85129 Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import 14.09.2026 8.8
CVE-2026-88793 YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server 14.09.2026 8.8
CVE-2026-88802 MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion 14.09.2026 7.5
CVE-2026-89050 Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URL 14.09.2026 4.3
CVE-2026-90584 TooTallNate Java-WebSocket Fragmentation Draft_6455.java processFrameContinuousAndNonFin allocation of resources 13.09.2026
CVE-2026-90583 kagisearch smallweb Query String Rendering sw.py index cross site scripting 13.09.2026
CVE-2026-29812 13.09.2026 4.3
CVE-2026-90582 evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumption 13.09.2026
CVE-2026-29811 13.09.2026 7.7
CVE-2026-90581 cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection 14.09.2026
CVE-2026-29810 13.09.2026 4.3
CVE-2025-70820 13.09.2026 3.5
CVE-2026-90580 FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery 13.09.2026
CVE-2025-70819 14.09.2026 6.3
CVE-2026-90579 cheshire-cat-ai Cheshire Cat AI custom_auth_handler.py _authorize_http_key missing authentication 13.09.2026
CVE-2025-64059 13.09.2026 1.8
CVE-2026-90578 GPAC MP4Box list.c gf_list_count use after free 13.09.2026
CVE-2025-45480 13.09.2026 3
CVE-2026-90577 GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow 13.09.2026
CVE-2020-15875 14.09.2026 5
CVE-2026-90576 GPAC MP4Box base_scenegraph.c gf_node_list_add_child null pointer dereference 14.09.2026
CVE-2026-90575 PHPGurukul Small CRM Login Success login.php unserialize deserialization 13.09.2026