| CVE-2026-100289 |
|
29.09.2026 |
|
| CVE-2026-77177 |
|
29.09.2026 |
|
| CVE-2026-100287 |
|
29.09.2026 |
|
| CVE-2026-100288 |
|
29.09.2026 |
|
| CVE-2026-102630 |
UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwarded-Host |
29.09.2026 |
|
| CVE-2026-19743 |
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients |
29.09.2026 |
7.8 |
| CVE-2026-92368 |
Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution |
29.09.2026 |
7.8 |
| CVE-2026-92369 |
Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation |
29.09.2026 |
7.3 |
| CVE-2026-92370 |
Remote Session Access Control Bypass Leading to Remote Code Execution |
29.09.2026 |
8.8 |
| CVE-2026-92371 |
Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording |
29.09.2026 |
7 |
| CVE-2026-100286 |
|
29.09.2026 |
|
| CVE-2026-102601 |
Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter |
29.09.2026 |
3.5 |
| CVE-2026-35189 |
Excessive Memory Allocation in Relative CRLDP Processing |
29.09.2026 |
|
| CVE-2026-35191 |
QUIC Unvalidated Amplification Credit may be Over Accounted |
29.09.2026 |
|
| CVE-2026-42772 |
Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC |
29.09.2026 |
|
| CVE-2026-54872 |
Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves |
29.09.2026 |
|
| CVE-2026-54873 |
QUIC STREAM Fragment Metadata DoS |
29.09.2026 |
|
| CVE-2026-54875 |
Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V |
29.09.2026 |
|
| CVE-2026-72897 |
Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake |
29.09.2026 |
|
| CVE-2026-75804 |
QUIC Connection-Level Flow Control is Not Enforced for Streams |
29.09.2026 |
|
| CVE-2026-75805 |
NULL Pointer Dereference in CMP Client Revocation Response Handling |
29.09.2026 |
|
| CVE-2026-75806 |
Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS |
29.09.2026 |
|
| CVE-2026-77696 |
Timing Side-Channel in SM2 Signature Generation |
29.09.2026 |
|
| CVE-2026-84782 |
DTLS Retransmits Handshake Messages From a Stale Buffer Offset |
29.09.2026 |
|
| CVE-2026-84783 |
Use-After-Free in X.509 Extension Cache Under Concurrent Use |
29.09.2026 |
|
| CVE-2026-84784 |
QUIC: Unbounded RETIRE_CONNECTION_ID Backlog |
29.09.2026 |
|
| CVE-2026-93332 |
|
29.09.2026 |
|
| CVE-2026-97687 |
urllib3: HTTPS proxy TLS configuration may be ignored or overridden |
29.09.2026 |
|
| CVE-2026-97688 |
urllib3: Chunked Deflate streaming can enter an infinite loop |
29.09.2026 |
|
| CVE-2026-97689 |
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory |
29.09.2026 |
|
| CVE-2023-54400 |
Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname |
29.09.2026 |
|
| CVE-2026-100308 |
GluonTS arbitrary command execution during model deserialization |
29.09.2026 |
7.8 |
| CVE-2026-102598 |
Werkzeug safe_join() allows Windows special device names |
29.09.2026 |
|
| CVE-2026-102600 |
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup |
29.09.2026 |
7.5 |
| CVE-2026-93330 |
|
29.09.2026 |
|
| CVE-2015-20122 |
Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp |
29.09.2026 |
|
| CVE-2026-49243 |
Webmin: Reflected XSS in the Configuration module |
29.09.2026 |
|
| CVE-2026-63209 |
Integer Overflow or Wraparound and Out-of-bounds Write in compress |
29.09.2026 |
7.5 |
| CVE-2026-68911 |
Nicotine+: Decompression of peer messages can exhaust available memory |
29.09.2026 |
|
| CVE-2026-86035 |
Weblate: Mercurial argument injection via repository filenames allows authenticated command execution |
29.09.2026 |
8.5 |
| CVE-2026-102491 |
mahonelau kykms SqlInjectionUtil QueryGenerator.java QueryGenerator.doMultiFieldsOrder sql injection |
29.09.2026 |
|
| CVE-2026-102566 |
CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin |
29.09.2026 |
|
| CVE-2026-102567 |
CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization |
29.09.2026 |
|
| CVE-2026-102568 |
Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py |
29.09.2026 |
|
| CVE-2026-102569 |
ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter |
29.09.2026 |
|
| CVE-2026-102570 |
ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter |
29.09.2026 |
|
| CVE-2026-22094 |
Weak root password in EVbee DC 80 |
29.09.2026 |
|
| CVE-2026-22101 |
Sensitive information leak through hidden menu |
29.09.2026 |
|
| CVE-2025-33207 |
|
29.09.2026 |
6.8 |
| CVE-2026-102371 |
wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments |
29.09.2026 |
|
| CVE-2026-65102 |
|
29.09.2026 |
7.8 |
| CVE-2026-97395 |
Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials |
29.09.2026 |
|
| CVE-2026-86450 |
Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal |
29.09.2026 |
7.5 |
| CVE-2026-102360 |
lib0 `readUint8Array` performs an unbounded read past the end of the decoder’s view, disclosing adjacent process memory |
29.09.2026 |
8.6 |
| CVE-2026-102521 |
lib0 `readFromDataView` out-of-bounds read |
29.09.2026 |
8.6 |
| CVE-2026-4034 |
TIBCO Administrator Injection Vulnerability |
29.09.2026 |
|
| CVE-2026-71897 |
Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints |
29.09.2026 |
|
| CVE-2026-71898 |
Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions |
29.09.2026 |
|
| CVE-2026-71899 |
Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure |
29.09.2026 |
|
| CVE-2026-78214 |
Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths |
29.09.2026 |
|
| CVE-2026-81569 |
Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution |
29.09.2026 |
|
| CVE-2026-82804 |
Apache DolphinScheduler: Command Injection in the Alert Script Plugin |
29.09.2026 |
|
| CVE-2026-100756 |
Incorrect boundary conditions in the Audio/Video: Playback component |
29.09.2026 |
|
| CVE-2026-100757 |
Use-after-free in the Widget component |
29.09.2026 |
|
| CVE-2026-100758 |
Sandbox escape in the DOM: Navigation component |
29.09.2026 |
|
| CVE-2026-100759 |
Uninitialized memory in the Storage: Quota Manager component |
29.09.2026 |
|
| CVE-2026-100760 |
Sandbox escape in the Security: Process Sandboxing component |
29.09.2026 |
|
| CVE-2026-100761 |
Privilege escalation due to use-after-free in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100762 |
Sandbox escape due to use-after-free in the DOM: Content Processes component |
29.09.2026 |
|
| CVE-2026-100763 |
Incorrect boundary conditions in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100764 |
Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100765 |
Use-after-free in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100766 |
Information disclosure in the Networking: JAR component |
29.09.2026 |
|
| CVE-2026-100767 |
Use-after-free in the Networking: Cache component |
29.09.2026 |
|
| CVE-2026-100768 |
Use-after-free in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100769 |
Use-after-free in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100770 |
Sandbox escape due to use-after-free in the DOM: Content Processes component |
29.09.2026 |
|
| CVE-2026-100771 |
Undefined behavior in the DOM: Streams component |
29.09.2026 |
|
| CVE-2026-100772 |
Use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100773 |
Use-after-free in the Storage: IndexedDB component |
29.09.2026 |
|
| CVE-2026-100774 |
Use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100775 |
Sandbox escape in the Graphics component |
29.09.2026 |
|
| CVE-2026-100776 |
Use-after-free in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100777 |
Use-after-free in the Graphics: Canvas2D component |
29.09.2026 |
|
| CVE-2026-100778 |
Sandbox escape due to use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100779 |
Use-after-free in the XSLT component |
29.09.2026 |
|
| CVE-2026-100780 |
Use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100781 |
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component |
29.09.2026 |
|
| CVE-2026-100782 |
Privilege escalation due to incorrect boundary conditions in the Graphics component |
29.09.2026 |
|
| CVE-2026-100783 |
Uninitialized memory in the Audio/Video component |
29.09.2026 |
|
| CVE-2026-100784 |
Use-after-free in the Layout: Text and Fonts component |
29.09.2026 |
|
| CVE-2026-100785 |
Use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100786 |
Sandbox escape due to use-after-free in the Graphics component |
29.09.2026 |
|
| CVE-2026-100787 |
Sandbox escape in the XUL component |
29.09.2026 |
|
| CVE-2026-100788 |
Invalid pointer in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100789 |
Use-after-free in the Graphics: Canvas2D component |
29.09.2026 |
|
| CVE-2026-100790 |
Use-after-free in the XSLT component |
29.09.2026 |
|
| CVE-2026-100791 |
Use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100792 |
JIT miscompilation in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100793 |
JIT miscompilation in the JavaScript Engine component |
29.09.2026 |
|
| CVE-2026-100794 |
Sandbox escape due to incorrect boundary conditions in the Internationalization component |
29.09.2026 |
|
| CVE-2026-100795 |
Denial-of-service in the Networking component |
29.09.2026 |
|
| CVE-2026-100796 |
Use-after-free in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100797 |
Privilege escalation due to use-after-free in the Graphics: WebRender component |
29.09.2026 |
|
| CVE-2026-100798 |
Cryptography misuse in Storage: Quota Manager component |
29.09.2026 |
|
| CVE-2026-100799 |
Uninitialized memory in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100800 |
Sandbox escape due to use-after-free in the Disability Access APIs component |
29.09.2026 |
|
| CVE-2026-100801 |
Privilege escalation in the DLL Services component |
29.09.2026 |
|
| CVE-2026-100802 |
Uninitialized memory in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100803 |
Same-origin policy bypass in the WebExtensions component |
29.09.2026 |
|
| CVE-2026-100804 |
Sandbox escape due to use-after-free in the Preferences: Backend component |
29.09.2026 |
|
| CVE-2026-100805 |
Race condition, use-after-free in the Audio/Video component |
29.09.2026 |
|
| CVE-2026-100806 |
Uninitialized memory in the Graphics: WebGPU component |
29.09.2026 |
|
| CVE-2026-100807 |
Privilege escalation in the DOM: Service Workers component |
29.09.2026 |
|
| CVE-2026-100808 |
Mitigation bypass in the DOM: Service Workers component |
29.09.2026 |
|
| CVE-2026-100809 |
Same-origin policy bypass in the DevTools component |
29.09.2026 |
|
| CVE-2026-100810 |
Other issue in the DevTools component |
29.09.2026 |
|
| CVE-2026-100811 |
Sandbox escape due to use-after-free in the DOM: Core & HTML component |
29.09.2026 |
|
| CVE-2026-100812 |
Denial-of-service in the Graphics component |
29.09.2026 |
|
| CVE-2026-100813 |
Invalid pointer in the JavaScript Engine: JIT component |
29.09.2026 |
|
| CVE-2026-100814 |
Incorrect boundary conditions in the JavaScript Engine: JIT component |
29.09.2026 |
|
| CVE-2026-100815 |
Use-after-free in the CSS Parsing and Computation component |
29.09.2026 |
|
| CVE-2026-100816 |
Site isolation issue in the DOM: Networking component |
29.09.2026 |
|
| CVE-2026-100817 |
Other issue in the JavaScript: WebAssembly component |
29.09.2026 |
|
| CVE-2026-100818 |
Sandbox escape due to use-after-free in the Widget: Gtk component |
29.09.2026 |
|
| CVE-2026-100819 |
Sandbox escape due to incorrect boundary conditions in the XPCOM component |
29.09.2026 |
|
| CVE-2026-100820 |
Privilege escalation in the Address Bar component |
29.09.2026 |
|
| CVE-2026-100821 |
Site isolation issue in the Panning and Zooming component |
29.09.2026 |
|
| CVE-2026-100822 |
Spoofing issue in the Networking: HTTP component |
29.09.2026 |
|
| CVE-2026-100823 |
Spoofing issue in the Downloads component in Firefox for Android |
29.09.2026 |
|
| CVE-2026-100824 |
Privilege escalation in the Places component |
29.09.2026 |
|
| CVE-2026-100825 |
Use-after-free in the JavaScript Engine: JIT component |
29.09.2026 |
|
| CVE-2026-100826 |
Denial-of-service in the Storage: StorageManager component |
29.09.2026 |
|
| CVE-2026-100828 |
Mitigation bypass in the Bookmarks & History component |
29.09.2026 |
|
| CVE-2026-100829 |
Mitigation bypass in the DOM: Security component |
29.09.2026 |
|
| CVE-2026-100830 |
Mitigation bypass in the DOM: Navigation component |
29.09.2026 |
|
| CVE-2026-100831 |
Use-after-free in the DOM: UI Events & Focus Handling component |
29.09.2026 |
|
| CVE-2026-100832 |
Use-after-free in the Graphics: Canvas2D component |
29.09.2026 |
|
| CVE-2026-76875 |
PyPy pyexpat ExternalEntityParserCreate Use-After-Free |
29.09.2026 |
|
| CVE-2026-96869 |
Information disclosure in the Networking component |
29.09.2026 |
|
| CVE-2026-101267 |
Revenue information leak |
29.09.2026 |
|
| CVE-2026-101268 |
Customer session fixation |
29.09.2026 |
|
| CVE-2026-101269 |
Incorrect session validation for API-uploaded files |
29.09.2026 |
|
| CVE-2026-101270 |
HTML injection |
29.09.2026 |
|
| CVE-2026-101271 |
OAuth credentials not disabled when application is disabled |
29.09.2026 |
|
| CVE-2026-102437 |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in DeepSeek-Reasonix |
29.09.2026 |
7.8 |
| CVE-2026-73598 |
|
29.09.2026 |
7.8 |
| CVE-2026-73599 |
|
29.09.2026 |
5.4 |
| CVE-2026-76114 |
|
29.09.2026 |
5.9 |
| CVE-2026-7192 |
Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment |
29.09.2026 |
|
| CVE-2026-7193 |
Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment |
29.09.2026 |
|
| CVE-2026-82973 |
Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox |
29.09.2026 |
9.4 |
| CVE-2026-98164 |
KVM: x86/mmu: Check write tracking in all address spaces |
29.09.2026 |
|
| CVE-2026-101266 |
Checkout validation bypass |
29.09.2026 |
|
| CVE-2026-73596 |
|
29.09.2026 |
3.8 |
| CVE-2026-73597 |
|
29.09.2026 |
6.5 |
| CVE-2026-102507 |
Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC |
29.09.2026 |
|
| CVE-2026-66083 |
Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource |
29.09.2026 |
|
| CVE-2026-87748 |
Privilege Escalation via Account Takeover in Interprobe's Qorela DC |
29.09.2026 |
8.8 |
| CVE-2026-102495 |
Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes |
29.09.2026 |
|
| CVE-2026-102496 |
Apache XMLSchema: Denial of service through deeply nested schema structures |
29.09.2026 |
|
| CVE-2026-102497 |
Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker |
29.09.2026 |
|
| CVE-2026-41875 |
Cross-Site Request Forgery in admin panel of Quick.Cart |
29.09.2026 |
|
| CVE-2026-73595 |
|
29.09.2026 |
4.7 |
| CVE-2026-73593 |
|
29.09.2026 |
3 |
| CVE-2026-73594 |
|
29.09.2026 |
6.4 |
| CVE-2026-85520 |
Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module |
29.09.2026 |
|
| CVE-2026-95520 |
Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages |
29.09.2026 |
|
| CVE-2026-95509 |
Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs |
29.09.2026 |
|
| CVE-2026-15390 |
Out-of-bounds write in Das U-Boot |
29.09.2026 |
|
| CVE-2026-19547 |
Local Privilege Escalation in Ghostscript for Windows |
29.09.2026 |
|
| CVE-2026-76719 |
HPE OneView - Cross-site scripting vulnerability |
29.09.2026 |
8.2 |
| CVE-2026-76720 |
HPE OneView - URL Redirect vulnerability |
29.09.2026 |
4.3 |
| CVE-2026-81862 |
Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs |
29.09.2026 |
|
| CVE-2026-81930 |
Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain |
29.09.2026 |
|
| CVE-2026-86843 |
Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag |
29.09.2026 |
|
| CVE-2026-76718 |
HPE OneView - Cross-site scripting vulnerability |
29.09.2026 |
8.2 |
| CVE-2026-81914 |
Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names |
29.09.2026 |
|
| CVE-2026-11796 |
|
29.09.2026 |
|
| CVE-2026-7395 |
|
29.09.2026 |
|
| CVE-2026-10518 |
Incorrect Authorization in GitLab |
29.09.2026 |
4.3 |
| CVE-2026-4523 |
Missing Authorization in GitLab |
29.09.2026 |
3.7 |
| CVE-2026-84739 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab |
29.09.2026 |
8.7 |
| CVE-2026-8067 |
|
29.09.2026 |
6.5 |
| CVE-2026-8937 |
Missing Authorization in GitLab |
29.09.2026 |
4.3 |
| CVE-2026-95386 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-95387 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
8.1 |
| CVE-2026-95388 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-95389 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
8.1 |
| CVE-2026-95390 |
NULL Pointer Dereference in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-95391 |
Use After Free in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-95392 |
Buffer Over-read in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-95393 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
4.7 |
| CVE-2026-95394 |
Unchecked Input for Loop Condition in Wireshark |
29.09.2026 |
4.7 |
| CVE-2026-95395 |
Missing Release of Memory after Effective Lifetime in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96415 |
Stack-based Buffer Overflow in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96416 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96417 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96418 |
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96419 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96420 |
Buffer Over-read in Wireshark |
29.09.2026 |
4.7 |
| CVE-2026-96421 |
Improperly Controlled Sequential Memory Allocation in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96422 |
Reachable Assertion in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-96423 |
Heap-based Buffer Overflow in Wireshark |
29.09.2026 |
5.5 |
| CVE-2026-102473 |
Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled |
29.09.2026 |
|
| CVE-2026-102474 |
Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservation |
29.09.2026 |
|
| CVE-2026-8065 |
|
29.09.2026 |
9.1 |
| CVE-2026-8066 |
|
29.09.2026 |
9.1 |
| CVE-2026-92142 |
Apache Karaf: Authorization bypass in JMX MBean lifecycle operations |
29.09.2026 |
|
| CVE-2026-96440 |
Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) |
29.09.2026 |
|
| CVE-2026-91012 |
Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation |
29.09.2026 |
|
| CVE-2026-91048 |
Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create |
29.09.2026 |
|
| CVE-2026-91085 |
Apache Karaf: config:install missing ACL entry allows privilege escalation to admin |
29.09.2026 |
|
| CVE-2026-96429 |
Flowring Agentflow 4.0 - SQL Injection |
29.09.2026 |
|
| CVE-2026-96430 |
Flowring Agentflow 4.0 - Exposed Dangerous Method or Function |
29.09.2026 |
|
| CVE-2026-96431 |
Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type |
29.09.2026 |
|
| CVE-2026-96428 |
Flowring Agentflow 4.0 - SQL Injection |
29.09.2026 |
|
| CVE-2026-101169 |
|
29.09.2026 |
|
| CVE-2026-84154 |
Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x |
29.09.2026 |
9.9 |
| CVE-2026-86157 |
Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere |
29.09.2026 |
5.6 |
| CVE-2026-86158 |
Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere |
29.09.2026 |
7.7 |
| CVE-2026-102292 |
coolbeans1212 MateisHomePage-Website users.php cross site scripting |
29.09.2026 |
|
| CVE-2026-102293 |
realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServiceImpl.add improper authorization |
29.09.2026 |
|
| CVE-2026-102290 |
CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting |
29.09.2026 |
|
| CVE-2026-102264 |
mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting |
29.09.2026 |
|
| CVE-2026-102261 |
owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization |
29.09.2026 |
|
| CVE-2026-102263 |
mwasikz robo-cafe-rms manage-food.php unrestricted upload |
29.09.2026 |
|
| CVE-2026-102249 |
REBUILD file-editor-save authorization |
29.09.2026 |
|
| CVE-2026-102414 |
pbkdf2 rehashes long passwords on every iteration, enabling denial of service |
29.09.2026 |
|
| CVE-2026-102422 |
shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token |
29.09.2026 |
8.1 |
| CVE-2026-97029 |
Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group |
29.09.2026 |
|
| CVE-2026-102248 |
Rebuild Login Endpoint login improper authentication |
29.09.2026 |
|
| CVE-2026-97024 |
Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc |
29.09.2026 |
|
| CVE-2026-102245 |
MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication |
29.09.2026 |
|
| CVE-2026-102247 |
FastAdmin Database Management database.php unnecessary privileges |
29.09.2026 |
|
| CVE-2026-102244 |
MODSetter SurfSense Document Export Feature editor_routes.py server-side request forgery |
29.09.2026 |
|
| CVE-2026-102241 |
Netcore NAP930 Backup/Restore backup_common.sh hard-coded key |
29.09.2026 |
|
| CVE-2026-102243 |
MODSetter SurfSense MCP Connector Integration test command injection |
29.09.2026 |
|
| CVE-2026-97685 |
LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations |
29.09.2026 |
|
| CVE-2026-101878 |
Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier Truncation |
29.09.2026 |
|
| CVE-2026-102240 |
Netcore NAP930 Network Tools CGI network_tools eval os command injection |
29.09.2026 |
|
| CVE-2026-101859 |
RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection |
29.09.2026 |
|
| CVE-2026-101860 |
RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management |
29.09.2026 |
|
| CVE-2026-96326 |
HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenticated Stored Cross-Site Scripting via Rich Text Editor Field |
29.09.2026 |
7.2 |
| CVE-2026-101354 |
FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow |
29.09.2026 |
|
| CVE-2026-101858 |
RaspAP raspap-webgui SSID Processing WiFiManager.php writeWpaSupplicant os command injection |
29.09.2026 |
|
| CVE-2026-101278 |
Trusted Domain Project OpenDMARC PSL Wildcard opendmarc_tld.c : opendmarc_get_tld origin validation |
29.09.2026 |
|
| CVE-2026-101279 |
Trusted Domain Project OpenDMARC opendmarc_policy.c integer overflow |
29.09.2026 |
|
| CVE-2026-101280 |
Trusted Domain Project OpenDMARC Multi-Record Set opendmarc_policy_query_dmarc authentication spoofing |
29.09.2026 |
|
| CVE-2026-101281 |
Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_domain improper authentication |
29.09.2026 |
|
| CVE-2026-102372 |
GestSup before 3.2.62 Stored XSS via Email Body in LOGIN IMAP Connector |
29.09.2026 |
|
| CVE-2026-102373 |
GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter |
29.09.2026 |
|
| CVE-2026-102374 |
GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IMAP Connector |
29.09.2026 |
|
| CVE-2026-101277 |
Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source |
28.09.2026 |
|
| CVE-2026-102361 |
mall4j through 4.0 Missing Authentication in Password Update Endpoint |
28.09.2026 |
|
| CVE-2026-102362 |
mall4j through 4.0 Missing Authentication in Product Review Deletion |
29.09.2026 |
|
| CVE-2026-102363 |
mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number |
28.09.2026 |
|
| CVE-2026-102364 |
mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API |
28.09.2026 |
|
| CVE-2026-102365 |
mall4j through 4.0 Missing Authorization in Admin User Address Endpoints |
28.09.2026 |
|
| CVE-2026-102366 |
mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints |
29.09.2026 |
|
| CVE-2026-102367 |
mall4j through 4.0 Insufficient Session Expiration via Token Refresh |
28.09.2026 |
|
| CVE-2026-101265 |
Intelbras TIP 125i Básico sensitive information in source |
29.09.2026 |
|
| CVE-2026-18417 |
Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asynchronous error |
28.09.2026 |
6.5 |
| CVE-2026-18746 |
NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted |
28.09.2026 |
5.9 |
| CVE-2026-18747 |
Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read |
28.09.2026 |
6.8 |
| CVE-2026-101263 |
Ziroom ZHOME A0101 set_online_client command injection |
28.09.2026 |
|
| CVE-2026-101264 |
Ziroom ZHOME A0101 set_passwd command injection |
28.09.2026 |
|