CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 06.09.2026 9.4
CVE-2026-86165 Tenda HG10 formURL buffer overflow 06.09.2026 9.3
CVE-2026-16310 MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter 06.09.2026 9.8
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier 06.09.2026 9.8
CVE-2026-86218 pre-authentication remote code execution 06.09.2026 10
CVE-2026-86153 Tenda CP3 Redirect.cpp SetRedirectEnable privileges management 06.09.2026 9.4
CVE-2026-86152 Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection 06.09.2026 10
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection 05.09.2026 9.4
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection 05.09.2026 9.4
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection 05.09.2026 9.4
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS 05.09.2026 9.2
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 05.09.2026 9.2
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php 05.09.2026 9.3
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter 05.09.2026 9.3
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route 05.09.2026 9.3
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields 05.09.2026 9.8
CVE-2026-86117 Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching 05.09.2026 9.2
CVE-2026-86119 Webstudio through 0.296.0 SSRF via /cgi proxy routes 05.09.2026 9.2
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control 05.09.2026 9.3
CVE-2026-86123 SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints 05.09.2026 9.4
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server 05.09.2026 9.3
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection 05.09.2026 9.8
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 05.09.2026 9.8
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 05.09.2026 9.8
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize 04.09.2026 9.4
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action 04.09.2026 9.1
CVE-2026-75925 IXON VPN Client CRLF Injection 04.09.2026 9.4
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server 05.09.2026 9.2
CVE-2026-75430 04.09.2026 9.8
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed 04.09.2026 9.8
CVE-2026-19274 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 9.6
CVE-2026-75431 04.09.2026 9.1
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi 04.09.2026 9.3
CVE-2026-85620 Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function 04.09.2026 9.2
CVE-2026-85625 sift 17.1.3 Prototype Pollution Remote Code Execution via $where 04.09.2026 9.2
CVE-2026-85660 cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution 04.09.2026 9.2
CVE-2026-85661 excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode 04.09.2026 9.3
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch 04.09.2026 9.3
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection 04.09.2026 9.3
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension 04.09.2026 9.3
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer 04.09.2026 9.3
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction 04.09.2026 9.2
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing 04.09.2026 9.3
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename 04.09.2026 9.3
CVE-2026-85595 Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth 05.09.2026 9.3
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass 05.09.2026 9.3
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker 04.09.2026 9.2
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes 04.09.2026 9.8
CVE-2026-85184 @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target 04.09.2026 9.1
CVE-2026-15354 ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter 04.09.2026 9.8
CVE-2026-62928 04.09.2026 9.3
CVE-2026-69657 04.09.2026 9.3
CVE-2026-70403 04.09.2026 9.3
CVE-2026-85085 04.09.2026 9.6
CVE-2026-11613 Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter 04.09.2026 9.8
CVE-2026-85506 04.09.2026 9.8
CVE-2026-85507 04.09.2026 9.8
CVE-2026-85508 04.09.2026 9.8
CVE-2026-85509 04.09.2026 9.8
CVE-2026-85504 04.09.2026 9.8
CVE-2026-85146 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-85148 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-75754 04.09.2026 10
CVE-2026-67402 04.09.2026 9.2
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability 05.09.2026 9.1
CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability 05.09.2026 10
CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability 05.09.2026 9.3
CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability 05.09.2026 10
CVE-2026-85424 MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR 05.09.2026 9.3
CVE-2026-85425 MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS 04.09.2026 9.3
CVE-2026-85426 MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names 04.09.2026 9.3
CVE-2026-85427 MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE 04.09.2026 9.2
CVE-2026-85428 MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write 03.09.2026 9.3
CVE-2026-85433 MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration 03.09.2026 9.3
CVE-2026-85434 MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping 05.09.2026 9.3
CVE-2026-85435 MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment 04.09.2026 9.3
CVE-2026-85437 MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders 04.09.2026 9.3
CVE-2026-85438 MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts 03.09.2026 9.3
CVE-2026-85440 MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length 04.09.2026 9.3
CVE-2026-85224 D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection 04.09.2026 9.4
CVE-2026-85223 D-Link DNS-340L CGI dropbox.cgi os command injection 04.09.2026 9.4
CVE-2026-85222 D-Link DNS-340L Add-On Center addon_center.cgi os command injection 04.09.2026 9.4
CVE-2026-85061 MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip 04.09.2026 10
CVE-2026-85391 Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml 03.09.2026 9.3
CVE-2026-85394 python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret 03.09.2026 9.3
CVE-2026-82526 R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint 04.09.2026 9.3
CVE-2026-58400 GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter 04.09.2026 9.1
CVE-2026-84238 WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability 03.09.2026 9.8
CVE-2026-84753 WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability 05.09.2026 9.8
CVE-2026-84768 WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability 03.09.2026 9.3
CVE-2026-84813 WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84814 WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability 03.09.2026 9.8
CVE-2026-84834 WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability 03.09.2026 9.8
CVE-2026-85181 CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum 03.09.2026 9.3
CVE-2026-85183 Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS 03.09.2026 9.3
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials 03.09.2026 9.5
CVE-2026-85109 Tenda HG10 Boa Web Server formLogin buffer overflow 03.09.2026 9.3
CVE-2026-82180 03.09.2026 9.5
CVE-2026-78080 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 03.09.2026 9.3
CVE-2026-78069 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026 9.5
CVE-2026-85154 WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash 05.09.2026 9.3
CVE-2026-76178 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.2
CVE-2026-76174 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.4
CVE-2026-80726 KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page 04.09.2026 9.3
CVE-2026-85031 TOTOLINK CP450 cstecgi.cgi buffer overflow 03.09.2026 9.4
CVE-2026-19117 Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability 02.09.2026 9.8
CVE-2026-53670 PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification 02.09.2026 9.3
CVE-2026-53671 PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification 05.09.2026 9.3
CVE-2026-66786 Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets 05.09.2026 9.1
CVE-2026-53649 Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE 04.09.2026 9.6
CVE-2026-20212 Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability 03.09.2026 9.8
CVE-2026-20274 Cisco IOS XR Software Security Hardening Release: September 2026 04.09.2026 9.8
CVE-2026-20279 Cisco IOS XR Software Security Hardening Release: September 2026 04.09.2026 9.8
CVE-2026-53611 Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation 02.09.2026 9.8
CVE-2026-78689 NGINX ngx_http_js_module vulnerablility 03.09.2026 9.2
CVE-2026-82955 02.09.2026 9
CVE-2025-9314 Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload 02.09.2026 9.8
CVE-2026-4357 Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload 02.09.2026 10
CVE-2026-77009 WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console 02.09.2026 9.9
CVE-2026-81294 WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability 02.09.2026 9.8
CVE-2026-81286 WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84795 Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance 02.09.2026 9.2
CVE-2026-78657 SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field 02.09.2026 9.8
CVE-2026-9055 Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' 02.09.2026 9.8
CVE-2026-84695 BookStack before 26.05.4 Stored XSS via Drawing Upload 02.09.2026 9.3
CVE-2026-84696 Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands 02.09.2026 9.3
CVE-2026-84699 Team Password Manager before 14.184.308 Authentication Bypass in Password Reset 02.09.2026 9.3
CVE-2026-84479 WWBN AVideo Authentication Bypass via User-Agent Header 02.09.2026 9.3
CVE-2026-84480 WWBN AVideo Password Recovery Token Expiration Bypass 02.09.2026 9.3
CVE-2023-54391 Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter 03.09.2026 9.3
CVE-2026-75604 Next.js: Unauthenticated Remote Code Execution on windows-hosted servers 04.09.2026 9
CVE-2026-84372 Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections 02.09.2026 9.8
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX 03.09.2026 9.8
CVE-2026-76657 Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access 01.09.2026 10
CVE-2026-76658 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon 01.09.2026 10
CVE-2026-19766 Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer 02.09.2026 9.6
CVE-2026-73700 Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface 02.09.2026 9
CVE-2026-73701 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer 02.09.2026 9
CVE-2026-79687 02.09.2026 9
CVE-2026-18931 Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software 01.09.2026 9.1
CVE-2026-78012 Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack 04.09.2026 9.3
CVE-2026-18210 SQL Injection in TRtek Technological Products's Store 01.09.2026 9.8
CVE-2026-9621 RSLinx Classic® - Multiple Vulnerabilities 01.09.2026 9.2
CVE-2026-18808 Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO 01.09.2026 9.8
CVE-2026-18765 SQL Injection in Teracity Sotware's Teracity E-OSB Platform 01.09.2026 9.8
CVE-2026-84149 Information Disclosure Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2026-84147 Remote Code Execution Vulnerability in Manacle Technologies ERP System 01.09.2026 10
CVE-2026-84148 Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System 01.09.2026 9.2
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites 04.09.2026 9.3
CVE-2026-84189 LibreNMS before 26.7.0 Stored XSS via Oxidized API 04.09.2026 9.2
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions 02.09.2026 9.4
CVE-2026-18550 Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter 02.09.2026 9.8
CVE-2026-4813 Code injection in the Lutece Core 01.09.2026 9.4
CVE-2026-78319 TOCTOU Vulnerability in file exchange 01.09.2026 9.3
CVE-2026-83772 Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection 01.09.2026 9.4
CVE-2026-67394 01.09.2026 9
CVE-2026-75865 WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint 01.09.2026 9.8
CVE-2026-83524 RedPort Optimizer wXa-223 System Clock datetime.php exec command injection 01.09.2026 9.4
CVE-2026-82971 QVidium Opera11 CGI Script net_tr.cgi command injection 01.09.2026 10
CVE-2026-82954 Dokploy Settings application.ts writeTraefikConfigInPath path traversal 02.09.2026 9.4
CVE-2026-81779 WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability 01.09.2026 10
CVE-2026-81293 WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81756 WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability 02.09.2026 9.3
CVE-2026-81763 WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability 01.09.2026 9.3
CVE-2026-81780 WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability 01.09.2026 10
CVE-2026-82226 WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability 01.09.2026 9.8
CVE-2026-82908 MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow 01.09.2026 9.3
CVE-2026-53552 Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers 01.09.2026 9.6
CVE-2026-79748 MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args) 31.08.2026 9.9
CVE-2026-82807 ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management 01.09.2026 9.3
CVE-2026-73819 Ebyte NA111-M Weak Authentication 01.09.2026 9.3
CVE-2026-76133 Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm 01.09.2026 9.3
CVE-2026-66047 ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE 02.09.2026 9.2
CVE-2026-82970 WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability 31.08.2026 10
CVE-2026-59111 Command Injection vulnerability in eObčanka-Identifikace 31.08.2026 9.3
CVE-2026-82694 Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication 31.08.2026 10
CVE-2026-82695 Tenda AC18 Telnet telnet missing authentication 31.08.2026 10
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82693 Tenda AC1206 Web UI telnet TendaTelnet missing authentication 31.08.2026 10
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection 02.09.2026 9.4
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection 31.08.2026 9.4
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection 01.09.2026 9.4
CVE-2026-82876 Phison PS3111-S11 Controller Firmware Signature Verification Bypass 02.09.2026 9.3
CVE-2026-49003 Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product 31.08.2026 9.6
CVE-2026-82854 Nodemailer before 8.0.3 SMTP Command Injection via envelope.size 31.08.2026 9.3
CVE-2026-82855 @hulumi/policies before 1.3.2 Evidence Validation Bypass 31.08.2026 9.3
CVE-2026-82856 @hulumi/policies before 1.3.2 OIDC Trust Policy Bypass 02.09.2026 9.3
CVE-2026-82857 hulumi before v1.3.2 Privilege Escalation via IAM Policy 01.09.2026 9.3
CVE-2026-82858 @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance 31.08.2026 9.3
CVE-2026-82859 hulumi before v1.3.2 SCP Template Tag-on-Create Bypass 31.08.2026 9.3
CVE-2026-82860 @hulumi/policies before 1.3.2 Admin Policy Bypass 31.08.2026 9.3
CVE-2026-19410 Google Cloud Build Comment Control Bypass via Webhook Suppression 31.08.2026 9.4
CVE-2026-82628 Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management 31.08.2026 9.3
CVE-2026-58574 31.08.2026 9.8
CVE-2026-82616 TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow 01.09.2026 9.4
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow 01.09.2026 9.4
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow 31.08.2026 9.4
CVE-2026-82645 AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token 31.08.2026 9.2
CVE-2026-82653 SiYuan before v3.8.1 Stored XSS via confirmDialog 02.09.2026 9.3
CVE-2026-82654 SiYuan before v3.8.1 Stored XSS via block name 01.09.2026 9.3
CVE-2026-82542 Tenda HG10 Boa Web Server formIPv6Routing buffer overflow 01.09.2026 10
CVE-2026-82539 TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption 01.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-86179 code-projects Daily Expense Manager Database Backup exp_ak.sql information disclosure 06.09.2026
CVE-2026-86172 DefaultFuction CRM delete.php sql injection 06.09.2026
CVE-2026-13159 Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation 06.09.2026
CVE-2026-18480 SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover 06.09.2026
CVE-2026-75793 SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login 06.09.2026
CVE-2026-84028 Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settings 06.09.2026
CVE-2026-84219 Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding 06.09.2026
CVE-2026-85038 B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role Selection 06.09.2026
CVE-2026-86171 DefaultFuction CRM delete.php sql injection 06.09.2026
CVE-2026-86170 DefaultFuction CRM edit.php sql injection 06.09.2026
CVE-2026-86168 code-projects Content Management System login.php sql injection 06.09.2026
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 06.09.2026
CVE-2026-86166 Tenda HG10 Boa Web Server formWanRedirect buffer overflow 06.09.2026
CVE-2026-86165 Tenda HG10 formURL buffer overflow 06.09.2026
CVE-2026-86163 itsourcecode Sales and Inventory System pro_del.php sql injection 06.09.2026
CVE-2026-86164 itsourcecode Sales and Inventory System trans_view.php sql injection 06.09.2026
CVE-2026-86162 SourceCodester Online Voting System ajax.php login sql injection 06.09.2026
CVE-2026-16310 MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter 06.09.2026 9.8
CVE-2026-18056 HivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook Authenticator 06.09.2026 7.5
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier 06.09.2026 9.8
CVE-2026-86161 SourceCodester Online Voting System ajax.php delete_category sql injection 06.09.2026
CVE-2026-86159 SourceCodester Online Voting System ajax.php save_user sql injection 06.09.2026
CVE-2026-86160 SourceCodester Online Voting System ajax.php delete_voting sql injection 06.09.2026
CVE-2026-86218 pre-authentication remote code execution 06.09.2026
CVE-2026-86153 Tenda CP3 Redirect.cpp SetRedirectEnable privileges management 06.09.2026
CVE-2026-86152 Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection 06.09.2026
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection 05.09.2026
CVE-2026-86150 Tenda CP3 hostapd hard-coded credentials 05.09.2026
CVE-2026-76160 05.09.2026
CVE-2026-76161 05.09.2026
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection 05.09.2026
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection 05.09.2026
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS 05.09.2026
CVE-2026-67277 Kernel memory disclosure and denial of service in MikroTik RouterOS btest service 05.09.2026
CVE-2026-67278 TLS server impersonation possible in Mikrotik RouterOS 05.09.2026
CVE-2026-67279 SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS 05.09.2026
CVE-2026-67281 Unauthenticated file read in Mikrotik RouterOS 05.09.2026
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 05.09.2026
CVE-2026-86206 Access control filter bypass allows unauthorised access to APIs 05.09.2026
CVE-2026-86207 Authentication bypass leads to unauthorised access to N-central 05.09.2026
CVE-2026-0799 OOBR and OOBW in libpcap before 1.10.7 05.09.2026 8.7
CVE-2026-18238 OOBR in rpcap client in libpcap before 1.10.7 05.09.2026 5
CVE-2026-18313 rpcapd memory leak in libpcap before 1.10.7 05.09.2026 4.3
CVE-2026-31911 abort() in libpcap before 1.10.7 on an invalid BPF opcode 05.09.2026 5.5
CVE-2026-31912 OOBR in libpcap before 1.10.7 05.09.2026 5.5
CVE-2026-6244 division by zero in libpcap before 1.10.7 05.09.2026 5.5
CVE-2026-6554 infinte loop in libpcap before 1.10.7 05.09.2026 5.5
CVE-2026-82752 Ash string length constraints count graphemes, so a combining-mark string of any size passes max_length 05.09.2026
CVE-2026-86186 AVideo API Rate Limit Bypass via Bot User-Agent Header 05.09.2026
CVE-2026-86187 WWBN AVideo Weak PRNG Password Generation via External Login 05.09.2026
CVE-2026-86188 AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting 05.09.2026
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php 05.09.2026
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter 05.09.2026
CVE-2026-86191 SiYuan before v3.8.2 Private Attribute View Key Enumeration 05.09.2026
CVE-2026-86192 SiYuan before v3.8.2 Information Disclosure via Attribute-View 05.09.2026
CVE-2026-86193 Grav API Plugin Authentication Bypass via Group-Inherited Super 05.09.2026
CVE-2026-86194 Grav Form Plugin before 9.1.22 Cross-Page Form Execution 05.09.2026
CVE-2026-86195 grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag 05.09.2026
CVE-2026-86196 Grav API Plugin before 1.0.20 Authentication Bypass via Host Header 05.09.2026
CVE-2026-86197 Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox 05.09.2026
CVE-2025-15614 ugrep before 7.6.0 Heap Buffer Over-read via .Z decompression 05.09.2026
CVE-2025-15647 CDT before 1.4.5 Out-of-Bounds Read via opposedVertexInd 05.09.2026
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route 05.09.2026
CVE-2026-86185 Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification Bypass 05.09.2026 8
CVE-2025-9049 Nokri – Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authenticated (Subscriber +) Privilege Escalation via Account Takeover 05.09.2026 8.8
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields 05.09.2026 9.8
CVE-2026-12843 LearnDash LMS 4.25.0 - 5.1.6 - Unauthenticated Arbitrary Course Enrollment via REST Endpoint 05.09.2026 5.4
CVE-2026-15550 Ninja Forms - Save Progress <= 3.0.30 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Data Deletion via admin-ajax.php with admin_init Hook 05.09.2026 4.3
CVE-2026-86169 Axolotl through 0.18.0 Remote Code Execution via Multipack Patching 05.09.2026
CVE-2026-86173 MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler 05.09.2026
CVE-2026-86174 Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board 05.09.2026
CVE-2026-86175 NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs 05.09.2026 6.5
CVE-2026-86176 NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs 05.09.2026 4.3
CVE-2026-86177 Pterodactyl Panel before 1.14.1 Privilege Escalation via Schedule Tasks 05.09.2026
CVE-2026-86178 Pixelfed through 0.12.9 Unauthorized Story Access via API 05.09.2026 5.4