CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-93958 D-Link R95 DHMAPI ssi system os command injection 20.09.2026 9.4
CVE-2026-94083 20.09.2026 9.4
CVE-2026-94084 20.09.2026 9.4
CVE-2026-93985 OpenPanel js-runtime JavaScript Template Sandbox Escape RCE 19.09.2026 9.4
CVE-2026-93742 Totolink A3002MU formWsc command injection 19.09.2026 9.4
CVE-2026-93741 Totolink A3002MU formWlWds buffer overflow 19.09.2026 10
CVE-2026-84434 Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field 19.09.2026 9.8
CVE-2026-89274 WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content 19.09.2026 9.1
CVE-2026-92229 Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter 19.09.2026 9.1
CVE-2026-75885 Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint 18.09.2026 9.3
CVE-2026-93740 Totolink A3002MU formWlEncrypt buffer overflow 18.09.2026 10
CVE-2026-93739 Totolink A3002MU formWlAc buffer overflow 18.09.2026 9.4
CVE-2026-93738 Totolink A3002MU formSchedule buffer overflow 18.09.2026 9.4
CVE-2026-58264 FluidSynth: Heap-based buffer overrun 18.09.2026 9.8
CVE-2026-63647 CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` 18.09.2026 9.3
CVE-2026-93868 Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG 18.09.2026 9.2
CVE-2026-84073 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.1
CVE-2026-84075 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-84078 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-84082 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-61781 pg_partman has privilege escalation through SQL injection in create_partition_time() 18.09.2026 9.9
CVE-2026-84064 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-82967 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-84031 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9
CVE-2026-81657 IBM Guardium Data Protection is affected by multiple vulnerabilities. 18.09.2026 9.8
CVE-2026-82340 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-82832 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.6
CVE-2026-75878 IBM Sterling File Gateway is Vulnerable to Authentication Bypass 19.09.2026 9.1
CVE-2026-80441 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.8
CVE-2026-80442 IBM Guardium Data Protection is affected by multiple vulnerabilities. 19.09.2026 9.9
CVE-2026-93839 LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint 18.09.2026 9.3
CVE-2023-54399 Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree 18.09.2026 9.3
CVE-2026-59163 Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass 18.09.2026 9.1
CVE-2026-61550 Icinga 2: Improper access control for JSON-RPC update certificate messages 18.09.2026 9.8
CVE-2025-66455 LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py 18.09.2026 9.8
CVE-2026-92701 Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path 18.09.2026 9.1
CVE-2026-92702 Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path 18.09.2026 9.1
CVE-2026-93762 Data deletion and attribute disclosure via field-name method injection in in-memory queries 18.09.2026 9.2
CVE-2026-77240 WACRM: Database-layer authorization bypasses 18.09.2026 9.9
CVE-2026-81321 CareCam CM2507 Cleartext Storage of Sensitive Information 19.09.2026 9.3
CVE-2026-85497 CareCam CM2507 Use of Password Hash With Insufficient Computational Effort 18.09.2026 9.3
CVE-2026-10858 IBM MQ for HPE NonStop is vulnerable to a denial of service attack 19.09.2026 9.9
CVE-2026-61682 kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace 18.09.2026 9.9
CVE-2026-10747 IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing 19.09.2026 10
CVE-2026-84383 libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items 18.09.2026 9.8
CVE-2025-15399 Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent 19.09.2026 10
CVE-2025-53837 org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 18.09.2026 9.9
CVE-2026-93659 Concrete CMS Community Store before 2.7.8 Stored XSS 18.09.2026 9.3
CVE-2023-5778 Missing Length Check 18.09.2026 9.2
CVE-2026-93603 vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function 18.09.2026 10
CVE-2026-93605 vm2 NodeVM before 3.12.1 Remote Code Execution via child_process 18.09.2026 10
CVE-2026-93606 vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species 18.09.2026 10
CVE-2026-28197 Privilege Escalation via Argument Injection in NetBackup Flex OS Shell 18.09.2026 9.4
CVE-2026-28198 Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell 18.09.2026 9.4
CVE-2026-13639 18.09.2026 9.8
CVE-2026-13684 18.09.2026 9.8
CVE-2026-67100 HCL BigFix Service Management is affected by multiple security vulnerabilities. 18.09.2026 9.8
CVE-2026-67101 HCL BigFix Service Management is affected by multiple security vulnerabilities. 18.09.2026 9.3
CVE-2026-93467 HGiga|OAKlouds - Insecure Deserialization 18.09.2026 9.3
CVE-2026-62874 Azure Billing Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-69843 Microsoft Fabric Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-85878 Azure Database for PostgreSQL Elevation of Privilege Vulnerability 19.09.2026 9.9
CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability 18.09.2026 10
CVE-2026-69865 Microsoft Container Registry Elevation of Privilege Vulnerability 18.09.2026 10
CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability 19.09.2026 9.3
CVE-2026-70200 Azure Logic Apps Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-77903 Microsoft Dataverse Elevation of Privilege Vulnerability 19.09.2026 9
CVE-2026-83944 Azure Logic Apps Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability 19.09.2026 9.9
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability 19.09.2026 10
CVE-2026-87701 Azure Cosmos DB Elevation of Privilege Vulnerability 19.09.2026 9.6
CVE-2026-54734 Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction 18.09.2026 10
CVE-2026-76949 Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement 18.09.2026 9.1
CVE-2026-54670 WeGIA: Unauthenticated Auth Bypass + Local File Inclusion 17.09.2026 9.1
CVE-2026-54767 WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php 18.09.2026 9.1
CVE-2026-93393 Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream 18.09.2026 9.2
CVE-2026-45140 Chamilo LMS CStudio upload flow allows unauthenticated remote code execution 18.09.2026 9.8
CVE-2026-45143 Chamilo LMS: Student-to-admin stored XSS in private messages via v-html 17.09.2026 9
CVE-2026-54237 Wavelog: Unauthenticated Remote Code Execution 18.09.2026 9.3
CVE-2026-54460 OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover 17.09.2026 9.8
CVE-2026-54501 Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors 17.09.2026 9.4
CVE-2026-54752 NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request 17.09.2026 9.6
CVE-2026-54618 Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user 17.09.2026 9.4
CVE-2026-54626 SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) 17.09.2026 9.8
CVE-2026-54627 SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) 18.09.2026 9.8
CVE-2026-92943 Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python 17.09.2026 9.2
CVE-2026-54617 GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler 18.09.2026 9.8
CVE-2026-47252 Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) 17.09.2026 9
CVE-2026-54053 Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults 17.09.2026 9.6
CVE-2026-90104 NFSv4.1: zero referring call lists before decoding 18.09.2026 9.8
CVE-2026-90110 inetpeer: randomize RB-tree node comparison using SipHash 18.09.2026 9.4
CVE-2026-90151 NFSv4: remove callback IDR entry on client allocation failure 18.09.2026 9.8
CVE-2026-90173 smb: smbdirect: free completion queues with ib_free_cq() 18.09.2026 9.8
CVE-2026-90230 nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() 18.09.2026 9.1
CVE-2026-90235 sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE 18.09.2026 9.8
CVE-2026-90413 IB/isert: reject login PDUs declaring more data than was received 18.09.2026 9.1
CVE-2026-90414 IB/isert: reject PDUs declaring more data than was received 18.09.2026 9.1
CVE-2026-92489 xfrm: Fix skb double-free in xfrm_dev_direct_output() 18.09.2026 9.8
CVE-2026-86863 pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode 17.09.2026 9.3
CVE-2026-76834 b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key 18.09.2026 9.2
CVE-2026-91039 dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover 17.09.2026 9.1
CVE-2026-79752 CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection 17.09.2026 9.2
CVE-2026-63472 Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification 17.09.2026 9.1
CVE-2026-88952 OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication 17.09.2026 9.1
CVE-2026-92934 vm2 before 3.11.8 Sandbox Escape RCE via AggregateError 17.09.2026 9.5
CVE-2026-92935 vm2 NodeVM Remote Code Execution via Array-Shaped Require 17.09.2026 9.5
CVE-2026-92937 vm2 3.11.6 Remote Code Execution via Promise call/apply 18.09.2026 10
CVE-2026-92938 vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite 19.09.2026 9.4
CVE-2026-92939 vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine 17.09.2026 9.4
CVE-2026-92940 vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent 17.09.2026 10
CVE-2026-92941 vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation 17.09.2026 10
CVE-2026-92944 vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector 19.09.2026 9.3
CVE-2026-92946 vm2 before 3.11.7 Remote Code Execution via require.external 17.09.2026 10
CVE-2026-92947 vm2 before 3.11.7 Memory Disclosure via Buffer Pool 17.09.2026 10
CVE-2026-92948 vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test 18.09.2026 9.4
CVE-2026-92950 vm2 before 3.11.7 Sandbox Escape via CLI require 17.09.2026 9.3
CVE-2026-92951 vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver 17.09.2026 9.4
CVE-2026-92953 vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray 18.09.2026 9.3
CVE-2026-92954 vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise 17.09.2026 9.2
CVE-2026-92955 vm2 before 3.11.8 Sandbox Escape via NodeVM 17.09.2026 10
CVE-2026-92956 vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming 17.09.2026 10
CVE-2026-92957 vm2 before 3.11.7 Authentication Bypass via node: Prefix 17.09.2026 9.4
CVE-2026-92960 vm2 before 3.11.6 Process-wide State Exposure via os and dns 17.09.2026 10
CVE-2026-62101 WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability 17.09.2026 9.8
CVE-2026-62104 WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability 19.09.2026 10
CVE-2026-62108 WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability 17.09.2026 9.8
CVE-2026-82761 Magic link single-use tokens replayable via TOCTOU race in AshAuthentication 17.09.2026 9.1
CVE-2026-85500 `require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication 17.09.2026 9.1
CVE-2026-86533 Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix 17.09.2026 9.1
CVE-2026-90822 17.09.2026 9.8
CVE-2026-90823 17.09.2026 9.8
CVE-2026-92860 rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation 19.09.2026 9.4
CVE-2026-92913 AVideo Weak PRNG Activation Code Authentication Bypass 17.09.2026 9.1
CVE-2026-15688 Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting 17.09.2026 9.2
CVE-2026-87796 Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload 19.09.2026 9.8
CVE-2026-61594 djust has an authorization bypass on the WebSocket/SSE mount path 17.09.2026 9.1
CVE-2026-92576 HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool 17.09.2026 9.2
CVE-2026-92578 WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash 17.09.2026 9.2
CVE-2026-75513 Marten: SQL injection in Marten's LINQ provider via unescaped string literals 19.09.2026 9.1
CVE-2026-92749 SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret 17.09.2026 9.2
CVE-2026-92785 Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes 17.09.2026 9.2
CVE-2026-92787 Feast through 0.66.0 Authentication Bypass via Unverified Token 19.09.2026 9.3
CVE-2026-92805 UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard 19.09.2026 9.3
CVE-2026-20284 Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability 18.09.2026 9.1
CVE-2026-20332 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities 18.09.2026 9.9
CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-20130 Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities 18.09.2026 10
CVE-2026-20176 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20192 Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities 18.09.2026 10
CVE-2026-20194 Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities 18.09.2026 9.1
CVE-2026-20211 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.1
CVE-2026-20237 Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities 18.09.2026 9.1
CVE-2026-20242 Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability 18.09.2026 9.8
CVE-2026-20322 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control 18.09.2026 9.9
CVE-2026-20324 Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability 18.09.2026 9.9
CVE-2026-20325 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command 18.09.2026 9.9
CVE-2026-20326 Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function 18.09.2026 9.8
CVE-2026-20329 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities 18.09.2026 9.9
CVE-2026-20330 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities 18.09.2026 9.9
CVE-2026-20341 Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability 18.09.2026 9.1
CVE-2026-76423 Cisco ISE API Authentication Bypass Vulnerability 17.09.2026 10
CVE-2026-92808 Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise 17.09.2026 10
CVE-2026-89083 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 17.09.2026 9.3
CVE-2026-89082 HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write 17.09.2026 9.3
CVE-2026-73456 Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. 17.09.2026 9.2
CVE-2026-91104 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-91106 HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities 17.09.2026 9.3
CVE-2026-92717 Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub 16.09.2026 9.3
CVE-2026-92720 Kubero through 3.1.1 Unauthenticated Notifications API Access 17.09.2026 9.3
CVE-2026-20234 Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities 17.09.2026 9.9
CVE-2026-20305 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20306 Cisco Identity Services Engine Command Injection Vulnerability 17.09.2026 9.1
CVE-2026-20307 Cisco Identity Services Engine Remote Code Execution Vulnerability 17.09.2026 9.9
CVE-2026-20331 Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities 18.09.2026 9.6
CVE-2026-76420 Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability 17.09.2026 9
CVE-2026-92398 Ruijie RG-EW3000GX user_list_note admin os command injection 16.09.2026 9.4
CVE-2026-92397 Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection 16.09.2026 9.4
CVE-2025-59953 LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy 18.09.2026 9.8
CVE-2026-70416 16.09.2026 10
CVE-2026-77411 RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr 16.09.2026 9.5
CVE-2026-77405 RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser 18.09.2026 9.4
CVE-2026-92395 @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 17.09.2026 9.1
CVE-2026-77408 RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow 16.09.2026 9.1
CVE-2026-91843 Stack overflow in login process to the Security Management and Log Servers 17.09.2026 9.8
CVE-2026-73172 17.09.2026 9.3
CVE-2026-40855 Command Injection in T-Mobile 5G Box IDU router via ping functionality 16.09.2026 9.3
CVE-2026-58146 Unauthorized remote code execution in T-Mobile 5G Box IDU routers 16.09.2026 9.4
CVE-2026-58147 Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers 16.09.2026 9.3
CVE-2026-89846 scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read 16.09.2026 9.1
CVE-2026-89847 scsi: qla2xxx: Avoid double completion in async IOCB timeout 16.09.2026 9.8
CVE-2026-89857 scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject 16.09.2026 9.8
CVE-2026-89914 KVM: arm64: Sign-extend VA for range-based TLBI invalidation 16.09.2026 9.3
CVE-2026-89915 KVM: arm64: Remove VM-wide VNCR mapping counter 16.09.2026 9.3
CVE-2026-89916 KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry 16.09.2026 9.3
CVE-2026-89918 KVM: arm64: Correctly handle end of VA space TLBI invalidation 16.09.2026 9.3
CVE-2026-89930 KVM: nVMX: Service local TLB flushes on failed nested VM-Enter 16.09.2026 9.3
CVE-2026-89969 nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU 16.09.2026 9.8
CVE-2026-89970 nvmet-auth: Synchronize timeout work during SQ teardown 16.09.2026 9.8
CVE-2026-89972 nvme: add missing SRCU grace period in error path 16.09.2026 9.8
CVE-2026-89990 ceph: lock mutex in ceph_mds_check_access() 16.09.2026 9.8
CVE-2026-90011 scsi: target: iscsi: Reserve a terminator byte for the login payload 16.09.2026 9.1
CVE-2026-90012 spi: Fix DMA mapping ownership on partial map failure 16.09.2026 9.8
CVE-2026-90036 NFSD: Prevent client use-after-free during blocked-lock reaping 16.09.2026 9.8
CVE-2026-90037 NFSD: Prevent client use-after-free during close_lru reaping 16.09.2026 9.8
CVE-2026-90038 NFSD: Prevent client use-after-free during export state revocation 16.09.2026 9.8
CVE-2026-90042 ceph: properly decrypt filenames in vmalloc() buffers 16.09.2026 9.8
CVE-2026-90048 fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() 16.09.2026 9.8
CVE-2026-90049 net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() 16.09.2026 9.3
CVE-2026-73453 Security Advisory 0174 17.09.2026 9.5
CVE-2026-89778 isofs: fix out-of-bounds page array access on empty zisofs block 16.09.2026 9.8
CVE-2026-89779 fs/ntfs3: validate ef->size covers the record's name and value 16.09.2026 9.1
CVE-2026-89783 xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full 16.09.2026 9.8
CVE-2026-89786 ext4: fix out-of-bounds read in ext4_read_inline_dir() 16.09.2026 9.1
CVE-2026-89788 ksmbd: fix tree connection use-after-free in smb2_tree_connect() 16.09.2026 9.8
CVE-2026-81642 Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY 16.09.2026 9.1
CVE-2026-89775 KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation 16.09.2026 9.3
CVE-2026-73461 Security Advisory 0163 17.09.2026 9.4
CVE-2026-27546 Authentication Bypass in _account_log 16.09.2026 9.8
CVE-2026-27565 Remote code execution via uploading a malicious IODD file 16.09.2026 9.8
CVE-2026-73447 Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request 17.09.2026 9.4
CVE-2026-12793 JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter 17.09.2026 9.8
CVE-2026-14349 TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action 16.09.2026 9.8
CVE-2026-15638 Cryptographic Padding Oracle 16.09.2026 9.1
CVE-2026-15639 Reflected Cross-Site Scripting 16.09.2026 9.3
CVE-2026-15640 Authentication Bypass via SAML Response Manipulation 16.09.2026 9.5
CVE-2026-73807 mySCADA myPRO Manager Missing Authorization 16.09.2026 9.3
CVE-2026-78225 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.5
CVE-2026-81855 Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key 16.09.2026 9.3
CVE-2026-61560 @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover 16.09.2026 9.8
CVE-2026-61559 @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery 17.09.2026 9.6
CVE-2026-61568 @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport 16.09.2026 9.6
CVE-2026-68491 16.09.2026 9.4
CVE-2026-91939 Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter 16.09.2026 9.3
CVE-2026-66887 Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-54337 Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite 16.09.2026 9.8
CVE-2026-66890 Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups 16.09.2026 9.4
CVE-2026-70748 15.09.2026 9.8
CVE-2026-70756 15.09.2026 9.8
CVE-2026-70757 15.09.2026 9.8
CVE-2026-70913 15.09.2026 9.8
CVE-2026-71133 17.09.2026 10
CVE-2026-71163 16.09.2026 9.9
CVE-2026-73940 15.09.2026 9.8
CVE-2026-73944 15.09.2026 9.1
CVE-2026-73945 16.09.2026 9.9
CVE-2026-73946 16.09.2026 9.1
CVE-2026-73947 15.09.2026 9.8
CVE-2026-73948 16.09.2026 9.9
CVE-2026-73950 15.09.2026 9.8
CVE-2026-73952 15.09.2026 9.1
CVE-2026-73953 15.09.2026 9.8
CVE-2026-73956 15.09.2026 9.8
CVE-2026-73957 16.09.2026 9.3
CVE-2026-73961 15.09.2026 9.8
CVE-2026-73962 16.09.2026 9.6
CVE-2026-73963 15.09.2026 9.8
CVE-2026-82994 15.09.2026 9.8
CVE-2026-82995 15.09.2026 9.8
CVE-2026-82997 16.09.2026 9.9
CVE-2026-82998 16.09.2026 9.9
CVE-2026-82999 16.09.2026 9.9
CVE-2026-83000 15.09.2026 9.8
CVE-2026-83001 16.09.2026 9.1
CVE-2026-83006 16.09.2026 9.1
CVE-2026-83020 17.09.2026 10
CVE-2026-83021 17.09.2026 10
CVE-2026-83027 16.09.2026 9.3
CVE-2026-83029 16.09.2026 9.6
CVE-2026-83031 16.09.2026 9.9
CVE-2026-83035 15.09.2026 9.8
CVE-2026-83036 15.09.2026 9.8
CVE-2026-83037 15.09.2026 9.8
CVE-2026-83038 16.09.2026 9.9
CVE-2026-83039 16.09.2026 9.9
CVE-2026-83040 16.09.2026 9.6
CVE-2026-83042 15.09.2026 9.8
CVE-2026-83043 16.09.2026 9.6
CVE-2026-83054 15.09.2026 9.8
CVE-2026-83055 17.09.2026 9.9
CVE-2026-83056 17.09.2026 9.9
CVE-2026-83057 17.09.2026 9.9
CVE-2026-83058 17.09.2026 9.9
CVE-2026-83059 17.09.2026 10
CVE-2026-83060 15.09.2026 9.8
CVE-2026-83061 15.09.2026 9.8
CVE-2026-83062 15.09.2026 9.8
CVE-2026-83064 17.09.2026 9.1
CVE-2026-83066 15.09.2026 9.8
CVE-2026-83094 15.09.2026 9.8
CVE-2026-83095 15.09.2026 9.8
CVE-2026-83098 15.09.2026 9.8
CVE-2026-83099 15.09.2026 10
CVE-2026-83100 15.09.2026 9.8
CVE-2026-83103 17.09.2026 9.1
CVE-2026-83104 15.09.2026 9.1
CVE-2026-83105 17.09.2026 9
CVE-2026-83107 17.09.2026 9.1
CVE-2026-83108 15.09.2026 9.8
CVE-2026-83149 15.09.2026 9.1
CVE-2026-83151 15.09.2026 9.8
CVE-2026-83154 15.09.2026 9.1
CVE-2026-83196 17.09.2026 9.1
CVE-2026-83197 15.09.2026 9.1
CVE-2026-83201 15.09.2026 9.1
CVE-2026-83202 15.09.2026 9.1
CVE-2026-83229 17.09.2026 9.1
CVE-2026-83232 15.09.2026 9.8
CVE-2026-83260 17.09.2026 9.1
CVE-2026-83261 15.09.2026 9.8
CVE-2026-83268 17.09.2026 9.1
CVE-2026-83269 15.09.2026 9.8
CVE-2026-83282 17.09.2026 9.9
CVE-2026-83283 15.09.2026 9.8
CVE-2026-83327 15.09.2026 9.8
CVE-2026-83339 15.09.2026 9.8
CVE-2026-83355 15.09.2026 9.8
CVE-2026-83452 15.09.2026 9.8
CVE-2026-83462 15.09.2026 9.8
CVE-2026-87128 15.09.2026 9.1
CVE-2026-87129 15.09.2026 9.1
CVE-2026-87170 15.09.2026 9.1
CVE-2026-87172 17.09.2026 9.9
CVE-2026-87173 15.09.2026 9.1
CVE-2026-87175 15.09.2026 9.1
CVE-2026-87176 15.09.2026 9.1
CVE-2026-87184 15.09.2026 9.8
CVE-2026-87186 17.09.2026 9.6
CVE-2026-87188 15.09.2026 9.8
CVE-2026-87189 17.09.2026 9.1
CVE-2026-87214 17.09.2026 9.1
CVE-2026-87217 15.09.2026 9.1
CVE-2026-87223 18.09.2026 9.1
CVE-2026-87230 18.09.2026 10
CVE-2026-89040 Tencent Mass Service Engine in Cluster (MSEC) path traversal 15.09.2026 9.3
CVE-2026-73458 On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou 15.09.2026 9.2
CVE-2026-76669 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76670 Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator 15.09.2026 9.9
CVE-2026-76672 Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator 20.09.2026 9.9
CVE-2026-76673 Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator 15.09.2026 9.8
CVE-2026-76674 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways 15.09.2026 9.8
CVE-2026-76675 Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways 15.09.2026 9.1
CVE-2026-69204 Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) 15.09.2026 9.2
CVE-2026-19773 libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability 16.09.2026 9.8
CVE-2026-45579 DIRAC: RCE in RequestManager due to eval on untrusted input 15.09.2026 9.9
CVE-2026-53459 Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints 17.09.2026 9.3
CVE-2026-61667 DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval 15.09.2026 9.9
CVE-2026-12351 IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection 16.09.2026 9.8
CVE-2023-54398 Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet 15.09.2026 9.3
CVE-2024-58385 Yonyou U8 CRM SQL Injection via fillbacksettingedit.php 15.09.2026 9.3
CVE-2026-46488 motionEye: Authentication possible via password hash 17.09.2026 9.1
CVE-2026-53710 MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server 15.09.2026 10
CVE-2026-89026 Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate 17.09.2026 9.3
CVE-2026-89022 BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion 15.09.2026 9.1
CVE-2026-77866 SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts 15.09.2026 9
CVE-2026-77972 safeurl validated address is not bound to the request, allowing DNS rebinding 15.09.2026 9
CVE-2026-55211 surfio IRAP header size fields cause out-of-bounds reads 17.09.2026 9.8
CVE-2023-54397 Tornado before 6.3.3 HTTP Request Smuggling via Content-Length 17.09.2026 9
CVE-2024-14029 Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding 15.09.2026 9
CVE-2026-91931 Flowise before 3.1.4 Remote Code Execution via Custom MCP npx 17.09.2026 9
CVE-2026-91932 Flowise before 3.1.4 Remote Code Execution via cwd Parameter 15.09.2026 9
CVE-2026-91949 FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass 17.09.2026 9.2
CVE-2026-91988 atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP 15.09.2026 9.2
CVE-2026-61549 Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend 16.09.2026 9
CVE-2026-63696 16.09.2026 9.1
CVE-2026-55158 Conflibot: Command injection via crafted pull request branch names under pull_request_target 17.09.2026 9.1
CVE-2026-63695 16.09.2026 9.8
CVE-2026-39919 Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter 20.09.2026 9.3
CVE-2026-46495 OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI 15.09.2026 9.2
CVE-2026-59971 MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) 15.09.2026 10
CVE-2026-77179 Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback 15.09.2026 9.4
CVE-2026-89308 Arbitrary command execution in TrxTimeATTENDANCE 15.09.2026 9.3
CVE-2026-91995 pig before 4.1.0 Unverified Password Change via /register/password 18.09.2026 9.3
CVE-2026-91998 Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp 17.09.2026 9.4
CVE-2026-52824 Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover 16.09.2026 9.1
CVE-2026-57147 praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery 17.09.2026 9.8
CVE-2026-57139 PraisonAI MCPServer exposes unauthenticated HTTP tools/call 17.09.2026 9.8
CVE-2026-57140 PraisonAI AgentOS exposes unauthenticated agent listing and invocation 15.09.2026 9.4
CVE-2026-57148 praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) 16.09.2026 9.8
CVE-2026-57138 PraisonAI codeMode sandbox escape via Function constructor 17.09.2026 9.9
CVE-2026-57141 PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool 15.09.2026 9.8
CVE-2026-48717 OpenAM OAuth Authorization Bypass via PKCE Challenge 15.09.2026 9.1
CVE-2026-45051 OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage 15.09.2026 9.2
CVE-2026-46619 OpenAM Authentication Bypass via MSISDN LDAP Injection 15.09.2026 9.3
CVE-2026-62263 OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass 15.09.2026 9.2
CVE-2026-45052 OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints 16.09.2026 9.3
CVE-2026-62379 OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback 15.09.2026 9.8
CVE-2026-90711 proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet 15.09.2026 9.1
CVE-2026-91003 D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow 15.09.2026 9.4
CVE-2026-91001 D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow 15.09.2026 9.4
CVE-2026-90847 EFM ipTIME C200E System Setup iux_set.cgi os command injection 15.09.2026 9.4
CVE-2026-12944 Incomplete Security Scanner Blocklist Enables Network-Based Code Execution 16.09.2026 9.6
CVE-2026-67399 15.09.2026 9.3
CVE-2026-53713 Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure 16.09.2026 9.1
CVE-2026-54333 UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable 15.09.2026 9.8
CVE-2026-54334 UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen` 16.09.2026 9.8
CVE-2026-50006 Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode 15.09.2026 9.1
CVE-2026-55209 resdata insufficiently validates untrusted GRDECL files 14.09.2026 9.8
CVE-2026-16338 DataStage on Cloud Pak for Data has several vulnerabilities due to open source software 14.09.2026 9.9
CVE-2026-59178 ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade 14.09.2026 9.8
CVE-2026-90942 Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints 14.09.2026 9.3
CVE-2026-90945 Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret 16.09.2026 9.3
CVE-2026-57578 DotVVM: Missing authorization in AuthorizeActionFilter 14.09.2026 9.2
CVE-2026-20353 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76440 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76441 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76443 Cisco Secure Email Gateway Security Hardening Release 15.09.2026 9.8
CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability 18.09.2026 9.8
CVE-2026-61534 Yayson: Prototype pollution in the Store/LegacyStore deserialization 14.09.2026 9.1
CVE-2026-90943 parallax filament-comments through 3.0.0 Stored XSS via Comment Body 14.09.2026 9.3
CVE-2026-57124 PraisonAI UI MCP connect endpoint allows unauthenticated local command execution 14.09.2026 9.8
CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set 14.09.2026 9.8
CVE-2026-57131 praisonai: Jobs API exposes agent-execution endpoints with no authentication 14.09.2026 9.8
CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation 14.09.2026 9.1
CVE-2026-57123 PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in 14.09.2026 9.8
CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass 14.09.2026 9.8
CVE-2026-82434 Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs 14.09.2026 10
CVE-2026-90961 MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials 14.09.2026 9.3
CVE-2026-90937 froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL 16.09.2026 9.4
CVE-2026-12258 Inadequate access control in the Hiperdino REST API 14.09.2026 9.2
CVE-2026-90919 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization 14.09.2026 9.3
CVE-2026-21391 Improper Claim Validation in PingAM OIDC Provider 14.09.2026 9.5
CVE-2026-90898 Bifrost unauthenticated remote code execution via MCP stdio client registration 14.09.2026 9.8
CVE-2026-90703 D-Link DWR-M921 formDiskCreateShare system os command injection 15.09.2026 9.4
CVE-2026-90702 D-Link DWR-M921 formDiskFormat system os command injection 15.09.2026 9.4
CVE-2026-90699 D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection 14.09.2026 9.4
CVE-2026-90693 D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow 15.09.2026 9.4
CVE-2026-90692 D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow 15.09.2026 9.4
CVE-2026-85192 Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 14.09.2026 9.4
CVE-2026-90680 D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow 16.09.2026 9.4
CVE-2026-90607 Totolink A3002MU boa formNewSchedule buffer overflow 14.09.2026 9.4
CVE-2026-90608 Totolink A3002MU boa formPortFw buffer overflow 16.09.2026 9.4
CVE-2026-90606 Totolink A3002MU boa formIpv6Setup buffer overflow 15.09.2026 9.4
CVE-2026-90605 Totolink A3002MU boa formFilter buffer overflow 15.09.2026 9.4
CVE-2026-81648 CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router 14.09.2026 10
CVE-2026-90561 Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG 18.09.2026 9.3
CVE-2026-90562 LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key 16.09.2026 9.2

Latest Updates

CVE Title Updated Score
CVE-2026-86554 Email enumeration and account ID leakage vulnerabilities in ZTE SmartLife APP 20.09.2026 4.3
CVE-2026-93972 SourceCodester Online Reviewer Management System btn_functions.php sql injection 20.09.2026
CVE-2026-93971 aiyiyi121 SxDevOps settings.py information disclosure 20.09.2026
CVE-2026-93970 aiyiyi121 SxDevOps Settings settings.py hard-coded credentials 20.09.2026
CVE-2026-93969 aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials 20.09.2026
CVE-2026-93968 aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management 20.09.2026
CVE-2026-14844 Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes 20.09.2026
CVE-2026-16542 Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar 20.09.2026
CVE-2026-81650 NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import 20.09.2026
CVE-2026-81651 NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR 20.09.2026
CVE-2026-81652 NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR 20.09.2026
CVE-2026-81653 NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR 20.09.2026
CVE-2026-81654 NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update 20.09.2026
CVE-2026-82842 SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching 20.09.2026
CVE-2026-84223 Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload 20.09.2026
CVE-2026-85017 Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection 20.09.2026
CVE-2026-87067 Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection 20.09.2026
CVE-2026-87068 Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import 20.09.2026
CVE-2026-87839 Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion 20.09.2026
CVE-2026-87840 Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering 20.09.2026
CVE-2026-92410 Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF 20.09.2026
CVE-2026-92422 Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route 20.09.2026
CVE-2026-92423 Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts 20.09.2026
CVE-2026-92540 Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via caller_can_promote_users 20.09.2026
CVE-2026-92541 Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer 20.09.2026
CVE-2026-92965 TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption 20.09.2026
CVE-2026-93966 aiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injection 20.09.2026
CVE-2026-93967 aiyiyi121 SxDevOps Command services.py generate_host_task command injection 20.09.2026
CVE-2026-93965 aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection 20.09.2026
CVE-2026-93964 NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication 20.09.2026
CVE-2026-93963 itsourcecode Leave Management System controller.php sql injection 20.09.2026
CVE-2026-93962 Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow 20.09.2026
CVE-2026-93961 Dromara UJCMS UserController UserController.java usernameExist improper authorization 20.09.2026
CVE-2026-86552 A vulnerability that skips email ownership verification for account registration in ZTE SmartLife APP 20.09.2026 5.4
CVE-2026-86553 A password reset vulnerability in ZTE SmartLife APP 20.09.2026 8.8
CVE-2026-93960 Pixelfed OAuth Scope ApiV1Controller.php instancePeers missing authentication 20.09.2026
CVE-2026-93959 SourceCodester Online Reviewer Management System btn_functions.php sql injection 20.09.2026
CVE-2026-86551 Wi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX741J) product 20.09.2026 3.3
CVE-2026-93957 olivier-ls PHP-FTS Filter Matching SearchEngine.php matchesSingleFilter comparison 20.09.2026
CVE-2026-93958 D-Link R95 DHMAPI ssi system os command injection 20.09.2026
CVE-2026-94083 20.09.2026 9.4
CVE-2026-94084 20.09.2026 9.4
CVE-2026-93956 olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting 19.09.2026
CVE-2026-93988 QloApps through 1.7.0 Arbitrary File Read via getEmailHTML 19.09.2026
CVE-2026-93989 vLLM through 0.29.0 Cross-Request Logits Corruption via bad_words 19.09.2026
CVE-2026-93990 Expat through 2.8.4 Malformed UTF-16 Acceptance via Unchecked Surrogate 19.09.2026
CVE-2026-93991 Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector 19.09.2026
CVE-2026-93992 Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal 19.09.2026
CVE-2026-93993 Mistral Vibe before 2.25.5 Remote Code Execution via git post-checkout 19.09.2026
CVE-2026-94056 19.09.2026 7.5
CVE-2026-94057 19.09.2026 4
CVE-2026-94055 19.09.2026 3.7
CVE-2026-94054 19.09.2026 7
CVE-2026-89155 19.09.2026
CVE-2026-93955 grimmory-tools grimmory Download Endpoint KoboController.java streamFileToResponse authorization 19.09.2026
CVE-2026-93954 grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization 19.09.2026
CVE-2026-82672 Unvalidated chunk-size line tail in Mint HTTP/1 client enables response smuggling against strict intermediaries on pooled connections 19.09.2026
CVE-2026-82560 Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width 19.09.2026
CVE-2026-93999 Keycloak-services: keycloak-services: token refresh continues issuing tokens for disabled audience clients 19.09.2026
CVE-2026-94000 Keycloak-services: keycloak-services: delegated admin with manage-users can escalate to realm-admin via group membership 19.09.2026
CVE-2026-94001 Keycloak-services: keycloak-services: admin credential delete bypasses denied reset-password permission 19.09.2026
CVE-2026-93981 hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings 19.09.2026
CVE-2026-93982 OpenPanel MCP Authentication Token in Query Parameter Logged Plaintext 19.09.2026
CVE-2026-93983 OpenPanel SQL Injection via ClickHouse Property Key Filter 19.09.2026
CVE-2026-93984 OpenPanel API Authentication Bypass via Unverified Client Secret 19.09.2026
CVE-2026-93985 OpenPanel js-runtime JavaScript Template Sandbox Escape RCE 19.09.2026
CVE-2026-93986 rclone before 1.75.1 Path Traversal via Directory Listing Names 19.09.2026
CVE-2026-93987 rclone serve docker Path Traversal via Volume Name 19.09.2026
CVE-2026-78030 DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM 20.09.2026