| CVE-2026-75018 |
Custom Contact Forms <= 7.16 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Deletion and Post Meta Modification via Nested 'fields[].ID' / 'choices[].ID' Parameters |
05.09.2026 |
4.3 |
| CVE-2026-75586 |
Unlimited Elements For Elementor <= 2.0.17 - Reflected Cross-Site Scripting via 'formData[id]' Parameter |
05.09.2026 |
6.1 |
| CVE-2026-81543 |
Abandoned Cart Pro for WooCommerce <= 10.7.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation |
05.09.2026 |
8.8 |
| CVE-2026-83625 |
Contact Form by Supsystic <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via IP Address Header |
05.09.2026 |
7.2 |
| CVE-2026-85414 |
Gallery : FooGallery <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute |
05.09.2026 |
6.4 |
| CVE-2026-14975 |
WP File Download <= 6.3.8 - Authenticated (Subscriber+) Arbitrary File Read via Path Traversal in 'remoteurl' Parameter |
05.09.2026 |
6.5 |
| CVE-2026-15984 |
QuickCal <= 1.0.20 - Unauthenticated Stored Cross-Site Scripting via Custom Field Parameters |
05.09.2026 |
7.2 |
| CVE-2026-16649 |
Gravity Forms <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via Post Body Field Value |
05.09.2026 |
7.2 |
| CVE-2026-18406 |
SureForms <= 2.12.2 - Unauthenticated Stored Cross-Site Scripting via Text Field Entity-Encoded Payload |
05.09.2026 |
7.2 |
| CVE-2026-18843 |
Beaver Builder Plugin (Pro Version) <= 2.11.0.1 - Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter |
05.09.2026 |
6.1 |
| CVE-2026-19769 |
Ninja Forms <= 3.15.1 - Unauthenticated Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key |
05.09.2026 |
7.2 |
| CVE-2026-19887 |
Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback |
05.09.2026 |
8.8 |
| CVE-2026-3853 |
Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter |
05.09.2026 |
6.4 |
| CVE-2026-4361 |
Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter |
05.09.2026 |
5 |
| CVE-2026-77830 |
Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label Placeholder |
05.09.2026 |
7.2 |
| CVE-2026-78438 |
W3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background Mutator |
05.09.2026 |
7.2 |
| CVE-2025-15693 |
JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal |
05.09.2026 |
|
| CVE-2025-15694 |
Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS |
05.09.2026 |
|
| CVE-2026-15247 |
Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion |
05.09.2026 |
|
| CVE-2026-19858 |
JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure via Dynamic Preset |
05.09.2026 |
|
| CVE-2026-19861 |
JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Emails |
05.09.2026 |
|
| CVE-2026-77826 |
RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation |
05.09.2026 |
|
| CVE-2026-78149 |
Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id |
05.09.2026 |
|
| CVE-2026-78150 |
Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure via saved-templates-duplicate IDOR |
05.09.2026 |
|
| CVE-2026-78362 |
SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Authentication |
05.09.2026 |
|
| CVE-2026-81348 |
My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and Sitemap |
05.09.2026 |
|
| CVE-2026-81404 |
IPGP Visitors Origin < 1.6 - Reflected XSS |
05.09.2026 |
|
| CVE-2026-81423 |
Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler |
05.09.2026 |
|
| CVE-2026-81424 |
Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR |
05.09.2026 |
|
| CVE-2026-82304 |
Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler |
05.09.2026 |
|
| CVE-2026-82846 |
Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields |
05.09.2026 |
|
| CVE-2026-83543 |
Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint |
05.09.2026 |
|
| CVE-2026-83544 |
Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute |
05.09.2026 |
|
| CVE-2026-84021 |
Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_icon URL |
05.09.2026 |
|
| CVE-2026-84022 |
Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attributes |
05.09.2026 |
|
| CVE-2026-84221 |
Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID |
05.09.2026 |
|
| CVE-2026-84225 |
Kirki 6.0.0 - 6.2.5 - Authenticated Collaboration Comment Status Modification via IDOR |
05.09.2026 |
|
| CVE-2026-84745 |
The Events Calendar < 6.17.3.1 - Contributor+ Non-Public Event, Venue and Organizer Content Disclosure via REST API |
05.09.2026 |
|
| CVE-2026-84896 |
King Addons for Elementor < 51.1.77 - Contributor+ Stored XSS via Magazine Grid Widget |
05.09.2026 |
|
| CVE-2026-84898 |
Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta |
05.09.2026 |
|
| CVE-2026-84899 |
VikWidgetsLoader < 1.12.0 - Contributor+ Stored XSS via Gutenberg Block class_suffix |
05.09.2026 |
|
| CVE-2026-84901 |
Eventin < 4.1.22 - Contributor+ Site Homepage Hijack and Event Taxonomy Manipulation via Missing Authorization |
05.09.2026 |
|
| CVE-2026-84926 |
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route |
05.09.2026 |
|
| CVE-2026-84927 |
EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification |
05.09.2026 |
|
| CVE-2026-84930 |
CatFolders Document Gallery < 2.0.7 - Author+ Stored XSS via titleTag Block Attribute |
05.09.2026 |
|
| CVE-2026-84931 |
Joli Table Of Contents < 3.0.3 - Author+ Stored XSS via joli-toc Shortcode Theme Attribute |
05.09.2026 |
|
| CVE-2026-84934 |
JCH Optimize < 6.0.1 - Subscriber+ Stored XSS via getcacheinfo Task Override |
05.09.2026 |
|
| CVE-2026-84935 |
HT Menu < 1.2.7 - Subscriber+ Stored XSS via Menu Settings |
05.09.2026 |
|
| CVE-2026-84936 |
EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat |
05.09.2026 |
|
| CVE-2026-84937 |
YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax |
05.09.2026 |
|
| CVE-2025-14945 |
Events Manager - Calendar, Bookings, Tickets, and more! <= 7.3.3 - Unauthenticated Stored Cross-Site Scripting via Event Attributes |
05.09.2026 |
5.4 |
| CVE-2026-13447 |
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery |
05.09.2026 |
9.8 |
| CVE-2026-18404 |
Social Chat <= 8.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box |
05.09.2026 |
6.4 |
| CVE-2026-77233 |
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite |
05.09.2026 |
7.2 |
| CVE-2026-77263 |
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more <= 3.13.4 - Unauthenticated Stored Cross-Site Scripting via Comment Content |
05.09.2026 |
7.2 |
| CVE-2026-83627 |
Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log |
05.09.2026 |
9.8 |
| CVE-2026-83628 |
Theme My Login <= 7.1.15 - Authenticated (Subscriber+) Missing Authorization to Unauthorized Multisite Subsite Creation via 'gimmeanotherblog' Signup Stage |
05.09.2026 |
4.3 |
| CVE-2026-8623 |
Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.dvcss' Element Class Attribute |
05.09.2026 |
6.4 |
| CVE-2026-8625 |
Dear Flipbook <= 2.4.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via '.df-element' Element Inner HTML |
05.09.2026 |
6.4 |
| CVE-2026-86145 |
|
05.09.2026 |
8.2 |
| CVE-2026-86144 |
|
05.09.2026 |
5.6 |
| CVE-2026-86139 |
|
05.09.2026 |
6.9 |
| CVE-2026-86140 |
|
05.09.2026 |
8 |
| CVE-2026-86141 |
|
05.09.2026 |
2.9 |
| CVE-2026-86142 |
|
05.09.2026 |
6.9 |
| CVE-2026-86143 |
|
05.09.2026 |
6.9 |
| CVE-2026-86137 |
|
05.09.2026 |
2.9 |
| CVE-2026-86138 |
|
05.09.2026 |
6.9 |
| CVE-2026-52774 |
Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki |
04.09.2026 |
6.1 |
| CVE-2026-52775 |
YesWiki Authenticated SQL Injection in ReactionManager |
04.09.2026 |
8.8 |
| CVE-2026-52777 |
YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
04.09.2026 |
|
| CVE-2026-52762 |
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates |
04.09.2026 |
|
| CVE-2026-52763 |
YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read |
04.09.2026 |
6.5 |
| CVE-2026-52766 |
YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
04.09.2026 |
9.1 |
| CVE-2026-52767 |
YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` |
04.09.2026 |
8.2 |
| CVE-2026-52769 |
YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` |
04.09.2026 |
8.3 |
| CVE-2026-52770 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki |
04.09.2026 |
7.5 |
| CVE-2026-52771 |
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) |
04.09.2026 |
8.3 |
| CVE-2026-52772 |
YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`) |
04.09.2026 |
5.5 |
| CVE-2026-52773 |
Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki |
04.09.2026 |
6.1 |
| CVE-2026-86100 |
Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL |
04.09.2026 |
|
| CVE-2026-86095 |
Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name |
04.09.2026 |
|
| CVE-2026-86096 |
PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup |
04.09.2026 |
|
| CVE-2026-86097 |
PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select |
04.09.2026 |
|
| CVE-2026-86098 |
ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape |
04.09.2026 |
|
| CVE-2026-48019 |
CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay |
04.09.2026 |
8.9 |
| CVE-2026-46636 |
Twig: Sandbox method allowlist bypass via `Markup` subclass |
04.09.2026 |
|
| CVE-2026-86090 |
ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers |
04.09.2026 |
|
| CVE-2026-86091 |
ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler |
04.09.2026 |
|
| CVE-2026-75925 |
IXON VPN Client CRLF Injection |
04.09.2026 |
9.6 |
| CVE-2026-76925 |
Flatpak: flatpak: toctou race condition allows symlink redirection |
04.09.2026 |
|
| CVE-2026-77393 |
Inductive Automation Ignition Incorrect Default Permissions |
04.09.2026 |
8.8 |
| CVE-2026-82684 |
Tycon Systems TPDIN-Monitor-WEB3 Missing Authorization |
04.09.2026 |
8.1 |
| CVE-2026-77847 |
Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials |
04.09.2026 |
6.5 |
| CVE-2026-82712 |
Tycon Systems TPDIN-Monitor-WEB3 Cross-Site Request Forgery |
04.09.2026 |
8.8 |
| CVE-2026-85704 |
ramon-victor freegpt-webui Jailbreak Mode config.py getJailbreak race condition |
04.09.2026 |
|
| CVE-2026-85703 |
ramon-victor freegpt-webui Jailbreak Mode backend.py getJailbreak allocation of resources |
04.09.2026 |
|
| CVE-2022-26961 |
|
04.09.2026 |
|
| CVE-2026-75438 |
|
04.09.2026 |
|
| CVE-2026-79423 |
|
04.09.2026 |
|
| CVE-2026-85702 |
ramon-victor freegpt-webui Backend Conversation API backend.py _conversation missing authentication |
04.09.2026 |
|
| CVE-2026-79426 |
|
04.09.2026 |
|
| CVE-2025-67066 |
|
04.09.2026 |
|
| CVE-2026-50894 |
|
04.09.2026 |
|
| CVE-2026-53769 |
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy |
04.09.2026 |
6.5 |
| CVE-2026-75439 |
|
04.09.2026 |
|
| CVE-2026-85701 |
ramon-victor freegpt-webui Authentication Check __init__.py ChatCompletion.create missing authentication |
04.09.2026 |
|
| CVE-2026-85787 |
An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server |
04.09.2026 |
|
| CVE-2026-79389 |
|
04.09.2026 |
|
| CVE-2026-79390 |
|
04.09.2026 |
|
| CVE-2026-79391 |
|
04.09.2026 |
|
| CVE-2026-53932 |
wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection') |
04.09.2026 |
8 |
| CVE-2026-71625 |
|
04.09.2026 |
|
| CVE-2026-55513 |
nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens |
04.09.2026 |
5.4 |
| CVE-2026-61699 |
nebula-mesh: Certificate revocation is never enforced at the mesh |
04.09.2026 |
8.1 |
| CVE-2026-63464 |
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` |
04.09.2026 |
7.7 |
| CVE-2026-71626 |
|
04.09.2026 |
|
| CVE-2026-53602 |
nebula-mesh - Host revocation is not durable: blocked/offboarded hosts can regain a valid certificate |
04.09.2026 |
|
| CVE-2026-53603 |
nebula-mesh: Operator session tokens stored in plaintext in the database |
04.09.2026 |
|
| CVE-2026-53604 |
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths |
04.09.2026 |
|
| CVE-2026-55512 |
nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting |
04.09.2026 |
5.3 |
| CVE-2026-71622 |
|
04.09.2026 |
|
| CVE-2026-71624 |
|
04.09.2026 |
|
| CVE-2026-85786 |
Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java |
04.09.2026 |
|
| CVE-2026-85643 |
code-projects Online Shopping System adduser.php mysqli_query sql injection |
04.09.2026 |
|
| CVE-2026-71620 |
|
04.09.2026 |
|
| CVE-2026-85639 |
jofpin trape Telemetry Endpoint user.py race condition |
04.09.2026 |
|
| CVE-2026-78839 |
|
04.09.2026 |
|
| CVE-2026-85638 |
jofpin trape user.py authorization |
04.09.2026 |
|
| CVE-2026-85781 |
Unverified access point ownership in Amazon EFS CSI Driver |
04.09.2026 |
|
| CVE-2026-80118 |
PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL |
04.09.2026 |
|
| CVE-2026-80119 |
PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via DirectIo64.sys IOCTL |
04.09.2026 |
|
| CVE-2026-80112 |
PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys |
04.09.2026 |
|
| CVE-2026-80113 |
PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL |
04.09.2026 |
|
| CVE-2026-80114 |
PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sys |
04.09.2026 |
|
| CVE-2026-80115 |
PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL |
04.09.2026 |
|
| CVE-2026-80116 |
PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL |
04.09.2026 |
|
| CVE-2026-80117 |
PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via DirectIo64.sys |
04.09.2026 |
|
| CVE-2026-85637 |
jofpin trape Admin Endpoint sockets.py join_room missing authentication |
04.09.2026 |
|
| CVE-2026-78327 |
|
04.09.2026 |
|
| CVE-2026-78328 |
|
04.09.2026 |
|
| CVE-2026-81939 |
|
04.09.2026 |
|
| CVE-2021-44319 |
|
04.09.2026 |
|
| CVE-2026-53761 |
Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api |
04.09.2026 |
|
| CVE-2026-85636 |
jofpin trape Login Endpoint stats.py missing authentication |
04.09.2026 |
|
| CVE-2026-53760 |
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests |
04.09.2026 |
5.2 |
| CVE-2026-9317 |
Nango < 0.71.6 Missing Authentication RCE via runner tRPC server |
04.09.2026 |
|
| CVE-2026-53756 |
Emlog Blind SQL Injection via Authentication Cookie |
04.09.2026 |
4.9 |
| CVE-2026-53757 |
Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE |
04.09.2026 |
|
| CVE-2026-53758 |
Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized |
04.09.2026 |
|
| CVE-2026-61608 |
SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links |
04.09.2026 |
6.8 |
| CVE-2026-61614 |
SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history |
04.09.2026 |
5.9 |
| CVE-2026-61688 |
SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props |
04.09.2026 |
6.5 |
| CVE-2026-73848 |
Emlog: Stored XSS via Tag Name in Article Editor |
04.09.2026 |
|
| CVE-2026-85769 |
Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize |
04.09.2026 |
|
| CVE-2026-61686 |
SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop |
04.09.2026 |
7.5 |
| CVE-2026-82538 |
ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter |
04.09.2026 |
|
| CVE-2026-85656 |
OS command injection in Amazon log4j-cve-2021-44228-hotpatch |
04.09.2026 |
|
| CVE-2026-18149 |
undici vulnerable to Denial of Service via orphaned RetryHandler response body |
04.09.2026 |
5.9 |
| CVE-2026-50553 |
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) |
04.09.2026 |
|
| CVE-2026-80903 |
drm/xe/oa: Fix sync entry leak on OA config emit failure |
04.09.2026 |
|
| CVE-2026-80904 |
net/tls: Fail tls_sw_splice_read() after a failed async decrypt |
04.09.2026 |
|
| CVE-2026-80905 |
net: tap: fix wrong transport_header when sending VLAN-tagged frame |
04.09.2026 |
|
| CVE-2026-80906 |
net: packet: fix wrong transport_header when sending VLAN-tagged frame |
04.09.2026 |
|
| CVE-2026-80907 |
drm/amdgpu: Fix UVD dpb min size calculation for H264 |
04.09.2026 |
|
| CVE-2026-80908 |
drm/amdgpu: Reject UVD message with dimensions above 4096 |
04.09.2026 |
|
| CVE-2026-80909 |
drm/amdgpu: Reject UVD message with invalid number of h265 refs |
04.09.2026 |
|
| CVE-2026-80910 |
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses |
04.09.2026 |
|
| CVE-2026-80911 |
ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() |
04.09.2026 |
|
| CVE-2026-80912 |
selinux: reject an unclaimed class value in security_get_classes() |
04.09.2026 |
|
| CVE-2026-80913 |
selinux: require every boolean value to be defined |
04.09.2026 |
|
| CVE-2021-44320 |
|
04.09.2026 |
|
| CVE-2026-18540 |
undici vulnerable to downstream response splitting via retry interceptor |
04.09.2026 |
3.7 |
| CVE-2026-18745 |
|
04.09.2026 |
|
| CVE-2026-19534 |
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
04.09.2026 |
7.5 |
| CVE-2026-57159 |
PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance |
04.09.2026 |
|
| CVE-2026-57160 |
PJSIP: SIP message header buffer overflow |
04.09.2026 |
|
| CVE-2026-57161 |
PJSIP: Stack overflow handling Service-Route headers in a registration response |
04.09.2026 |
|
| CVE-2026-57162 |
PJSIP: Stack overflow parsing SDP a=crypto attributes |
04.09.2026 |
|
| CVE-2026-57163 |
PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend |
04.09.2026 |
|
| CVE-2026-57164 |
PJSIP: Heap overflow in the HTTP client |
04.09.2026 |
|
| CVE-2026-57165 |
PJSIP: Pre-authentication overflow in the telnet CLI history |
04.09.2026 |
|
| CVE-2026-57166 |
PJSIP: Pre-authentication overflow in the telnet CLI error |
04.09.2026 |
|
| CVE-2026-80887 |
drm/vmwgfx: use check_add_overflow for shader size+offset bound |
04.09.2026 |
|
| CVE-2026-80888 |
drm/vmwgfx: drop dma_buf reference on foreign-fd prime import |
04.09.2026 |
|
| CVE-2026-80889 |
can: isotp: fix timer drain order, wakeup handling and tx_gen ordering |
04.09.2026 |
|
| CVE-2026-80890 |
sctp: reject stale cookies with mismatched verification tags |
04.09.2026 |
|
| CVE-2026-80891 |
KVM: s390: pci: Validate AIBV and AISB before pinning guest pages |
04.09.2026 |
|
| CVE-2026-80892 |
erofs: cap LZMA stream pool size |
04.09.2026 |
|
| CVE-2026-80893 |
mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() |
04.09.2026 |
|
| CVE-2026-80894 |
iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace |
04.09.2026 |
|
| CVE-2026-80895 |
mshv: Order pt_vp_array publish against irqfd assertion path |
04.09.2026 |
|
| CVE-2026-80896 |
mshv: Fix race in mshv_irqfd_deassign |
04.09.2026 |
|
| CVE-2026-80897 |
netfs: release readahead folios on iterator preparation failure |
04.09.2026 |
|
| CVE-2026-80898 |
netfs: clear PG_private_2 on copy-to-cache append failure |
04.09.2026 |
|
| CVE-2026-80899 |
erofs: remove fscache backend entirely |
04.09.2026 |
|
| CVE-2026-80900 |
ASoC: SDCA: Make UMP message size check more robust |
04.09.2026 |
|
| CVE-2026-80901 |
ipvs: fix the checksum validations |
04.09.2026 |
|
| CVE-2026-80902 |
dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA |
04.09.2026 |
|
| CVE-2026-84890 |
undici vulnerable to Denial of Service via unbounded decompression of compressed responses |
04.09.2026 |
5.9 |
| CVE-2026-85654 |
Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server |
04.09.2026 |
|
| CVE-2026-84933 |
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches |
04.09.2026 |
6.5 |
| CVE-2026-31020 |
|
04.09.2026 |
|
| CVE-2026-80885 |
afs: Fix uncancelled rxrpc OOB message handler |
04.09.2026 |
|
| CVE-2026-80886 |
serial: msm: Disable DMA for kernel console UART |
04.09.2026 |
|
| CVE-2026-84947 |
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor |
04.09.2026 |
3.7 |
| CVE-2026-13297 |
Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access |
04.09.2026 |
|
| CVE-2026-14350 |
Vulnerabilities exists in IBM Cloud Pak for Data System |
04.09.2026 |
5.3 |
| CVE-2026-80865 |
bpf: Add missing access_ok call to copy_user_syms |
04.09.2026 |
|
| CVE-2026-80866 |
tipc: avoid busy looping in tipc_exit_net() |
04.09.2026 |
|
| CVE-2026-80867 |
alpha/PCI: Add security_locked_down() check to pci_mmap_resource() |
04.09.2026 |
|
| CVE-2026-80868 |
ntfs3: Allocate iomap inline_data using alloc_page |
04.09.2026 |
|
| CVE-2026-80869 |
ntfs: bound the attribute-list entry in ntfs_read_inode_mount() |
04.09.2026 |
|
| CVE-2026-80870 |
drm/amdkfd: Validate CRIU-restored IDs before idr_alloc |
04.09.2026 |
|
| CVE-2026-80871 |
crypto: xilinx-trng - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80872 |
ALSA: hda/tas2781: Cancel async firmware request at unbind |
04.09.2026 |
|
| CVE-2026-80873 |
KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions |
04.09.2026 |
|
| CVE-2026-80874 |
arm64: dts: renesas: ironhide: Describe inline ECC carveouts |
04.09.2026 |
|
| CVE-2026-80875 |
ipvs: use parsed transport offset in TCP state lookup |
04.09.2026 |
|
| CVE-2026-80876 |
ring-buffer: Fix event length with forced 8-byte alignment |
04.09.2026 |
|
| CVE-2026-80877 |
afs: Fix vllist leak |
04.09.2026 |
|
| CVE-2026-80878 |
afs: Fix leak of ungot volume |
04.09.2026 |
|
| CVE-2026-80879 |
ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write |
04.09.2026 |
|
| CVE-2026-80880 |
IB/mlx5: Properly support implicit ODP rereg_mr |
04.09.2026 |
|
| CVE-2026-80881 |
ocfs2: fix buffer head management in ocfs2_read_blocks() |
04.09.2026 |
|
| CVE-2026-80882 |
crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm |
04.09.2026 |
|
| CVE-2026-80883 |
drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered |
04.09.2026 |
|
| CVE-2026-80884 |
ntb: Store original DMA address for future release |
04.09.2026 |
|
| CVE-2026-84961 |
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool |
04.09.2026 |
7.4 |
| CVE-2026-14470 |
Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components |
04.09.2026 |
6.5 |
| CVE-2026-16180 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.7 |
| CVE-2026-16660 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] |
04.09.2026 |
5.3 |
| CVE-2026-16689 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
6.2 |
| CVE-2026-16693 |
IBM i is Affected By Cryptographic Algorithm Weakness in DCM [] |
04.09.2026 |
4.4 |
| CVE-2026-16826 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
5.3 |
| CVE-2026-16892 |
IBM i is Affected By An Improper Authentication Vulnerability in Network Authentication Service [] |
04.09.2026 |
5.4 |
| CVE-2026-16941 |
IBM i is Affected By An Incorrect Authorization Vulnerability [] |
04.09.2026 |
4.3 |
| CVE-2026-17057 |
IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] |
04.09.2026 |
6.5 |
| CVE-2026-17207 |
IBM i is Affected By Denial of Service Vulnerabilities in NFS [, ] |
04.09.2026 |
6.5 |
| CVE-2026-17255 |
IBM i is Affected By Denial of Service Vulnerability [] |
04.09.2026 |
4.3 |
| CVE-2026-17259 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
4.3 |
| CVE-2026-17270 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
4.3 |
| CVE-2026-85008 |
undici vulnerable to caching and replay of unsafe HTTP method responses |
04.09.2026 |
3.7 |
| CVE-2026-17273 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
6.5 |
| CVE-2026-17274 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
5.4 |
| CVE-2026-17440 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.5 |
| CVE-2026-17442 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.1 |
| CVE-2026-17443 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.3 |
| CVE-2026-17444 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.3 |
| CVE-2026-17469 |
IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ] |
04.09.2026 |
5.3 |
| CVE-2026-17470 |
IBM i is Affected By Denial of Service Vulnerabilities in Line Printer Daemon [, ] |
04.09.2026 |
5.3 |
| CVE-2026-17483 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] |
04.09.2026 |
4.3 |
| CVE-2026-17499 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
4.4 |
| CVE-2026-17621 |
Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components |
04.09.2026 |
5.4 |
| CVE-2026-17622 |
Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components |
04.09.2026 |
6.5 |
| CVE-2026-17627 |
Langflow is affected by improper authorization due to missing access control on the voice-mode WebSocket endpoint |
04.09.2026 |
4.9 |
| CVE-2026-38961 |
|
04.09.2026 |
|
| CVE-2026-78849 |
|
04.09.2026 |
|
| CVE-2026-85014 |
undici vulnerable to Denial of Service via WebSocketStream unclean close |
04.09.2026 |
5.9 |
| CVE-2026-85152 |
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors |
04.09.2026 |
7.4 |
| CVE-2026-17631 |
Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components |
04.09.2026 |
5 |
| CVE-2026-18073 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
4.4 |
| CVE-2026-18076 |
IBM i is Affected By Multiple Vulnerabilities in Debug Server |
04.09.2026 |
4.3 |
| CVE-2026-18078 |
IBM i is Affected By Denial of Service Vulnerability in Save Restore [] |
04.09.2026 |
4.3 |
| CVE-2026-18175 |
IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] |
04.09.2026 |
8.1 |
| CVE-2026-18221 |
IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ] |
04.09.2026 |
8.1 |
| CVE-2026-18341 |
IBM i is Affected By Buffer Overflow Vulnerability [] |
04.09.2026 |
6.3 |
| CVE-2026-18486 |
IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution |
04.09.2026 |
8.8 |
| CVE-2026-18489 |
IBM ContextForge Translate is affected by cross-client credential context confusion |
04.09.2026 |
7.4 |
| CVE-2026-75430 |
|
04.09.2026 |
9.8 |
| CVE-2026-78745 |
|
04.09.2026 |
|
| CVE-2026-85024 |
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression |
04.09.2026 |
5.9 |
| CVE-2026-18567 |
IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ] |
04.09.2026 |
4.4 |
| CVE-2026-18658 |
IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed |
04.09.2026 |
9.8 |
| CVE-2026-18858 |
IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH [] |
04.09.2026 |
3.3 |
| CVE-2026-18887 |
IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE [] |
04.09.2026 |
6.5 |
| CVE-2026-19298 |
Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint |
04.09.2026 |
8.8 |
| CVE-2026-19301 |
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components |
04.09.2026 |
5 |
| CVE-2026-19303 |
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components |
04.09.2026 |
8.1 |
| CVE-2026-78970 |
|
04.09.2026 |
|
| CVE-2026-18905 |
IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation |
04.09.2026 |
7.7 |
| CVE-2026-75169 |
|
04.09.2026 |
|
| CVE-2026-75170 |
|
04.09.2026 |
|
| CVE-2026-75171 |
|
04.09.2026 |
|
| CVE-2026-80824 |
usb: usbfs: fix use-after-free of usb_device in usbdev_release() |
04.09.2026 |
|
| CVE-2026-80825 |
wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb |
04.09.2026 |
|
| CVE-2026-80826 |
USB: c67x00: fix use-after-free in c67x00_add_iso_urb() |
04.09.2026 |
|
| CVE-2026-80827 |
USB: serial: option: fix slab OOB read in interrupt URB callback |
04.09.2026 |
|
| CVE-2026-80828 |
ALSA: usb-audio: Complete cleanup after system-resume errors |
04.09.2026 |
|
| CVE-2026-80829 |
ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() |
04.09.2026 |
|
| CVE-2026-80830 |
usb: core: Add lock to usb_wakeup_notification() |
04.09.2026 |
|
| CVE-2026-80831 |
crypto: mxs-dcp - fix source scatterlist length access |
04.09.2026 |
|
| CVE-2026-80832 |
crypto: qce - fix CCM AAD buffer underallocation |
04.09.2026 |
|
| CVE-2026-80833 |
crypto: sun8i-ss - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80834 |
crypto: sun8i-ce - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80835 |
crypto: qcom-rng - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80836 |
crypto: virtio - bound the akcipher result length |
04.09.2026 |
|
| CVE-2026-80837 |
netfilter: nf_tables: don't queue packet path object notifications |
04.09.2026 |
|
| CVE-2026-80838 |
vxlan: keep the last remote linked during FDB flush |
04.09.2026 |
|
| CVE-2026-80839 |
batman-adv: reject unrepresentable multicast TVLV offsets |
04.09.2026 |
|
| CVE-2026-80840 |
ipv6: seg6: clear IPv4 control block on IPIP decapsulation |
04.09.2026 |
|
| CVE-2026-80841 |
net/packet: defer vmalloc TX_RING free until skbs finish |
04.09.2026 |
|
| CVE-2026-80842 |
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context |
04.09.2026 |
|
| CVE-2026-80843 |
xfrm: fix xfrm_state_construct() auth-trunc leak |
04.09.2026 |
|
| CVE-2026-80844 |
xfrm: ah6: validate routing header segments_left |
04.09.2026 |
|
| CVE-2026-80845 |
xfrm: avoid lock inversion in nat keepalive work |
04.09.2026 |
|
| CVE-2026-80846 |
xfrm: drop ESP-in-TCP packets with no ingress device |
04.09.2026 |
|
| CVE-2026-80847 |
tcp: clamp route advmss to TCP_MIN_MSS |
04.09.2026 |
|
| CVE-2026-80848 |
xfrm: espintcp: fix UAF during close |
04.09.2026 |
|
| CVE-2026-80849 |
net/tcp-ao: fix use-after-free of current_key on reconnect to another peer |
04.09.2026 |
|
| CVE-2026-80850 |
tcp: fix AO info use-after-free in tcp_ao_connect_init() |
04.09.2026 |
|
| CVE-2026-80851 |
gtp: serialize PDP context updates |
04.09.2026 |
|
| CVE-2026-80852 |
tls: device: fix out-of-bounds write in tls_append_frag() |
04.09.2026 |
|
| CVE-2026-80853 |
KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts |
04.09.2026 |
|
| CVE-2026-80854 |
usb: gadget: f_tcm: keep port count until LUN teardown completes |
04.09.2026 |
|
| CVE-2026-80855 |
fuse: fix invalidate lock leak on open O_TRUNC DAX failure |
04.09.2026 |
|
| CVE-2026-80856 |
fuse: fix invalidate lock leak on setattr writeback failure |
04.09.2026 |
|
| CVE-2026-80857 |
fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free |
04.09.2026 |
|
| CVE-2026-80858 |
fuse: publish io-uring queues with release semantics |
04.09.2026 |
|
| CVE-2026-80859 |
fuse: fix missing barrier when checking io-uring readiness |
04.09.2026 |
|
| CVE-2026-80860 |
fuse: fix race between interrupt and resend |
04.09.2026 |
|
| CVE-2026-80861 |
usb: xhci: bail out of setup if the controller is inaccessible |
04.09.2026 |
|
| CVE-2026-80862 |
nvme-tcp: fix usage of page_frag_cache |
04.09.2026 |
|
| CVE-2026-80863 |
RDMA/rxe: Fix OOB in free_rd_atomic_resources() |
04.09.2026 |
|
| CVE-2026-80864 |
RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp |
04.09.2026 |
|
| CVE-2026-19274 |
IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image |
04.09.2026 |
9.6 |
| CVE-2026-19283 |
IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image |
04.09.2026 |
7.7 |
| CVE-2026-19299 |
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components |
04.09.2026 |
6.5 |
| CVE-2026-19300 |
Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows |
04.09.2026 |
7.5 |
| CVE-2026-75166 |
|
04.09.2026 |
|
| CVE-2026-75167 |
|
04.09.2026 |
|
| CVE-2026-75168 |
|
04.09.2026 |
|
| CVE-2026-75431 |
|
04.09.2026 |
9.1 |
| CVE-2026-19302 |
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components |
04.09.2026 |
6.5 |
| CVE-2026-75163 |
|
04.09.2026 |
|
| CVE-2026-75164 |
|
04.09.2026 |
|
| CVE-2026-75165 |
|
04.09.2026 |
|
| CVE-2026-75160 |
|
04.09.2026 |
|
| CVE-2026-75161 |
|
04.09.2026 |
|
| CVE-2026-75162 |
|
04.09.2026 |
|
| CVE-2026-75429 |
|
04.09.2026 |
|
| CVE-2026-82911 |
CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes |
04.09.2026 |
|
| CVE-2022-35497 |
|
04.09.2026 |
|
| CVE-2022-35499 |
|
04.09.2026 |
|
| CVE-2026-19304 |
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components |
04.09.2026 |
7.7 |
| CVE-2026-19305 |
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components |
04.09.2026 |
8.6 |
| CVE-2026-44402 |
Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi |
04.09.2026 |
|
| CVE-2026-80821 |
nvmet: pci-epf: put CQ ref on create_cq mapping failure |
04.09.2026 |
|
| CVE-2026-80822 |
mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() |
04.09.2026 |
|
| CVE-2026-80823 |
nfc: st21nfca: validate ATR_REQ length against the received frame |
04.09.2026 |
|
| CVE-2026-19306 |
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components |
04.09.2026 |
7.7 |
| CVE-2026-19645 |
Multiple vulnerabilities in IBM MQ Agent images |
04.09.2026 |
6.5 |
| CVE-2026-19649 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
6.2 |
| CVE-2026-5522 |
QRadar contains hard-coded credentials |
04.09.2026 |
6.7 |
| CVE-2026-77822 |
IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpoint |
04.09.2026 |
8.2 |
| CVE-2026-78543 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.3 |
| CVE-2026-78658 |
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability |
04.09.2026 |
6.5 |
| CVE-2026-79418 |
|
04.09.2026 |
|
| CVE-2026-79419 |
|
05.09.2026 |
|
| CVE-2026-80758 |
futex: Avoid private hash use-after-free on final put |
04.09.2026 |
|
| CVE-2026-80759 |
Bluetooth: hci_aml: validate firmware segment lengths |
04.09.2026 |
|
| CVE-2026-80760 |
Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 |
04.09.2026 |
|
| CVE-2026-80761 |
Bluetooth: ISO: zero the sockaddr before returning it in getname |
04.09.2026 |
|
| CVE-2026-80762 |
Bluetooth: hci_sync: Fix accept list UAF during suspend |
04.09.2026 |
|
| CVE-2026-80763 |
Bluetooth: hci_event: validate LE Set CIG Parameters response |
04.09.2026 |
|
| CVE-2026-80764 |
Bluetooth: hci_event: fix LE list UAF on reset |
04.09.2026 |
|
| CVE-2026-80765 |
HID: hyperv: validate initial device info bounds |
04.09.2026 |
|
| CVE-2026-80766 |
HID: uclogic: fix use-after-free of inrange_timer on remove |
04.09.2026 |
|
| CVE-2026-80767 |
HID: sensor: custom: Fix use-after-free in enable_sensor |
04.09.2026 |
|
| CVE-2026-80768 |
HID: ft260: fix stack-use-after-return write in I2C read race |
04.09.2026 |
|
| CVE-2026-80769 |
HID: rapoo: fix missing hid_is_usb() check |
04.09.2026 |
|
| CVE-2026-80770 |
HID: nintendo: stop device IO before hid_hw_stop on probe failure |
04.09.2026 |
|
| CVE-2026-80771 |
HID: nintendo: register input device after capabilities are set |
04.09.2026 |
|
| CVE-2026-80772 |
HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() |
04.09.2026 |
|
| CVE-2026-80773 |
HID: huawei: fix missing hid_is_usb() check |
04.09.2026 |
|
| CVE-2026-80774 |
HID: asus: fix missing hid_is_usb() check |
04.09.2026 |
|
| CVE-2026-80775 |
futex: Fix race on the initial mm->futex.phash.ref allocation |
04.09.2026 |
|
| CVE-2026-80776 |
futex: Fix race in futex_pivot_pending() during private hash resize |
04.09.2026 |
|
| CVE-2026-80777 |
futex/pi: Plug private futex exec() race |
04.09.2026 |
|
| CVE-2026-80778 |
futex/pi: Reject cross-mm private futex owners |
04.09.2026 |
|
| CVE-2026-80779 |
net/ionic: avoid OOB TX partner lookup for hwstamp RXQ |
04.09.2026 |
|
| CVE-2026-80780 |
HID: pidff: fix OOB write when hid->inputs is empty |
04.09.2026 |
|
| CVE-2026-80781 |
HID: core: fix OOB read of field->usage in hid_set_field() |
04.09.2026 |
|
| CVE-2026-80782 |
HID: magicmouse: do not keep a stale msc->input if no input is claimed |
04.09.2026 |
|
| CVE-2026-80783 |
HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() |
04.09.2026 |
|
| CVE-2026-80784 |
mptcp: pm: fix memory leak from alloc-during-teardown race |
04.09.2026 |
|
| CVE-2026-80785 |
fbdev: serialize mode sysfs access with lock_fb_info() |
04.09.2026 |
|
| CVE-2026-80786 |
fbdev: Wrap user-invoked calls to fb_set_var() in helper |
04.09.2026 |
|
| CVE-2026-80787 |
nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() |
04.09.2026 |
|
| CVE-2026-80788 |
nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations |
04.09.2026 |
|
| CVE-2026-80789 |
nvmet-tcp: bound SGL data length before allocating command buffers |
04.09.2026 |
|
| CVE-2026-80790 |
nvmet-fc: fix invalid free in LS IOD error path |
04.09.2026 |
|
| CVE-2026-80791 |
nvmet-auth: zero the AUTH_RECEIVE response buffer |
04.09.2026 |
|
| CVE-2026-80792 |
ipv6: fix use-after-free in ip6_finish_output2() |
04.09.2026 |
|
| CVE-2026-80793 |
ipv4: reject undersized MTUs in ip_do_fragment() |
04.09.2026 |
|
| CVE-2026-80794 |
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers |
04.09.2026 |
|
| CVE-2026-80795 |
nfc: nci: fix out-of-bounds write in nci_target_auto_activated() |
04.09.2026 |
|
| CVE-2026-80796 |
nfc: nci: add data_len bound checks to activation parameter extractors |
04.09.2026 |
|
| CVE-2026-80797 |
nfc: pn533: purge fragmented skbs during cleanup |
04.09.2026 |
|
| CVE-2026-80798 |
nfc: llcp: reject PDUs shorter than the LLCP header |
04.09.2026 |
|
| CVE-2026-80799 |
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers |
04.09.2026 |
|
| CVE-2026-80800 |
nfc: llcp: bound the connect_sn TLV walk to the skb |
04.09.2026 |
|
| CVE-2026-80801 |
nfc: microread: validate target discovery payload lengths |
04.09.2026 |
|
| CVE-2026-80802 |
nfc: fdp: bound the device-reported read length and fix an skb leak |
04.09.2026 |
|
| CVE-2026-80803 |
nfc: digital: clamp SENSF_RES length to the destination buffer |
04.09.2026 |
|
| CVE-2026-80804 |
xfs: restore nofs context unconditionally in xfs_trans_roll |
04.09.2026 |
|
| CVE-2026-80805 |
xfs: validate attr entry pointer before field access |
04.09.2026 |
|
| CVE-2026-80806 |
ext4: don't enable DAX on new encrypted files |
04.09.2026 |
|
| CVE-2026-80807 |
nilfs2: reject invalid block index in GC ioctl |
04.09.2026 |
|
| CVE-2026-80808 |
ext4: stop retrying saturated xattr cache entries |
04.09.2026 |
|
| CVE-2026-80809 |
ocfs2: fix missing metadata reservation for large xattrs |
04.09.2026 |
|
| CVE-2026-80810 |
io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() |
04.09.2026 |
|
| CVE-2026-80811 |
io_uring/cmd: fix iovec leak when the async cmd is not recycled |
04.09.2026 |
|
| CVE-2026-80812 |
ALSA: dummy: Check card index validity at probe |
04.09.2026 |
|
| CVE-2026-80813 |
nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() |
04.09.2026 |
|
| CVE-2026-80814 |
rndis_host: add overflow check in rndis_rx_fixup() |
04.09.2026 |
|
| CVE-2026-80815 |
ALSA: scarlett2: Use a private URB for the notification endpoint |
04.09.2026 |
|
| CVE-2026-80816 |
ALSA: FCP: Use a private URB for the notification endpoint |
04.09.2026 |
|
| CVE-2026-80817 |
iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages |
04.09.2026 |
|
| CVE-2026-80818 |
iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown |
04.09.2026 |
|
| CVE-2026-80819 |
Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept |
04.09.2026 |
|
| CVE-2026-80820 |
xfs: don't livelock in scrub on a circular unlinked list |
04.09.2026 |
|
| CVE-2026-85730 |
smol-toml: Denial of Service via malformed TOML documents |
04.09.2026 |
|
| CVE-2026-6958 |
Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe |
04.09.2026 |
|
| CVE-2026-81832 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
7.7 |
| CVE-2026-81859 |
Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026. |
04.09.2026 |
6.2 |
| CVE-2026-82728 |
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS |
04.09.2026 |
|
| CVE-2026-82729 |
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS |
04.09.2026 |
|
| CVE-2026-85605 |
Slink before 1.12.3 Missing Authorization on Image Comment Endpoints |
04.09.2026 |
|
| CVE-2026-85606 |
firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath |
04.09.2026 |
|
| CVE-2026-85607 |
Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router |
04.09.2026 |
|
| CVE-2026-85608 |
Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter |
04.09.2026 |
|
| CVE-2026-85618 |
ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives |
04.09.2026 |
|
| CVE-2026-85619 |
AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API |
04.09.2026 |
|
| CVE-2026-85620 |
Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function |
04.09.2026 |
|
| CVE-2026-85621 |
LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu |
04.09.2026 |
|
| CVE-2026-85622 |
AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket |
04.09.2026 |
|
| CVE-2026-85623 |
goose 1.37.0 Arbitrary Command Execution via Recipe Extensions |
04.09.2026 |
|
| CVE-2026-85624 |
Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList |
04.09.2026 |
|
| CVE-2026-85625 |
sift 17.1.3 Prototype Pollution Remote Code Execution via $where |
04.09.2026 |
|
| CVE-2026-85626 |
git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters |
04.09.2026 |
|
| CVE-2026-85650 |
Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel |
04.09.2026 |
|
| CVE-2026-85651 |
Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay |
04.09.2026 |
|
| CVE-2026-85660 |
cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution |
04.09.2026 |
|
| CVE-2026-85661 |
excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode |
04.09.2026 |
|
| CVE-2026-85662 |
Marqo 2.26.0 Server-Side Request Forgery via Media URLs |
04.09.2026 |
|
| CVE-2026-85663 |
Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch |
04.09.2026 |
|
| CVE-2026-85664 |
Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion |
04.09.2026 |
|
| CVE-2026-85665 |
Bruno 3.4.2 Arbitrary File Read via Unconfined Body File Path |
04.09.2026 |
|
| CVE-2026-85666 |
ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url |
04.09.2026 |
|
| CVE-2026-85667 |
xiaobei through 5.5.2 Unauthenticated Webhook Message Injection |
04.09.2026 |
|
| CVE-2026-85668 |
Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register |
04.09.2026 |
|
| CVE-2026-85669 |
potpie through 2.0.0 Missing Ownership Check via code-changes sync |
04.09.2026 |
|
| CVE-2026-85670 |
tokenizers BpeBuilder Buffer Overflow via merge token |
04.09.2026 |
|
| CVE-2026-85671 |
QAnything 2.0.0 Unauthenticated Cross-User File Disclosure |
04.09.2026 |
|
| CVE-2026-85672 |
zerox 1.1.20 OS Command Injection via Document URL File Extension |
04.09.2026 |
|
| CVE-2026-85673 |
LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding |
04.09.2026 |
|
| CVE-2026-85674 |
aider 0.86.2 Remote Code Execution via .aider.conf.yml |
04.09.2026 |
|
| CVE-2026-85675 |
OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching |
04.09.2026 |
|
| CVE-2026-85676 |
Dub Open Redirect via Unrestricted redir_url Parameter |
04.09.2026 |
|
| CVE-2026-85684 |
marker through 2.0.0 Path Traversal via upload filename |
04.09.2026 |
|
| CVE-2026-85685 |
AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill |
04.09.2026 |
|
| CVE-2026-85686 |
ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs |
04.09.2026 |
|
| CVE-2026-85687 |
surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server |
04.09.2026 |
|
| CVE-2026-85688 |
TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer |
04.09.2026 |
|
| CVE-2026-85689 |
llmware 0.4.6 SQL Injection via unescaped filter values |
04.09.2026 |
|
| CVE-2026-85690 |
Plandex 2.2.1 Path Traversal via ApplyFiles |
04.09.2026 |
|
| CVE-2026-85691 |
MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url |
04.09.2026 |
|
| CVE-2026-85692 |
Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding |
04.09.2026 |
|
| CVE-2026-85693 |
Chatbot UI Cross-User Private File Content Disclosure via Retrieval API |
04.09.2026 |
|
| CVE-2026-85694 |
LaVague 0.2.35 Remote Code Execution via eval extraction |
04.09.2026 |
|
| CVE-2026-85695 |
FastChat Unauthenticated Worker Registration SSRF and Model Spoofing |
04.09.2026 |
|
| CVE-2026-85696 |
SadTalker OS Command Injection via Audio Filename |
04.09.2026 |
|
| CVE-2026-85697 |
Documenso 2.17.0 PDF Route Ignores Document Visibility |
04.09.2026 |
|
| CVE-2026-85698 |
Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service |
04.09.2026 |
|
| CVE-2026-85699 |
jina-ai reader server-side request forgery via redirect validation bypass |
04.09.2026 |
|
| CVE-2026-85700 |
Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints |
04.09.2026 |
|
| CVE-2026-14466 |
Possible XSS in the SNS web administration panel |
04.09.2026 |
4.3 |
| CVE-2026-8447 |
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust |
04.09.2026 |
6.1 |
| CVE-2026-9138 |
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components |
04.09.2026 |
6.5 |
| CVE-2026-9186 |
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust |
04.09.2026 |
6.5 |
| CVE-2026-19205 |
User Enumeration in GastroMenum's GastroMenum Web Panel |
04.09.2026 |
7.5 |
| CVE-2026-19727 |
HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System |
04.09.2026 |
6.1 |
| CVE-2026-19081 |
Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System |
04.09.2026 |
4.3 |
| CVE-2026-19057 |
Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System |
04.09.2026 |
5.4 |
| CVE-2026-85522 |
valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds |
04.09.2026 |
|
| CVE-2026-52691 |
Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module |
04.09.2026 |
|
| CVE-2026-77818 |
Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System |
04.09.2026 |
6.1 |
| CVE-2026-12483 |
LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler |
04.09.2026 |
7.5 |
| CVE-2026-85517 |
code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql information disclosure |
04.09.2026 |
|
| CVE-2026-85516 |
code-projects Vehicle Management System busprofile.php sql injection |
04.09.2026 |
|
| CVE-2026-85649 |
|
04.09.2026 |
7.9 |
| CVE-2026-85514 |
StackStorm st2 API Key auth.py privileges management |
04.09.2026 |
|
| CVE-2026-74235 |
GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler |
04.09.2026 |
|
| CVE-2026-74236 |
GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler |
04.09.2026 |
|
| CVE-2026-74237 |
GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client |
04.09.2026 |
|
| CVE-2026-82309 |
Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries |
04.09.2026 |
|
| CVE-2026-85513 |
StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management |
04.09.2026 |
|
| CVE-2026-18198 |
SQL Injection in TAC Information's GoldenHorn |
04.09.2026 |
8.8 |
| CVE-2026-19051 |
Plaintext Storage of User Credentials in Menulux Software's Menulux Portal |
04.09.2026 |
7.1 |
| CVE-2026-19080 |
Username Enumeration in Menulux Software's Menulux Portal |
04.09.2026 |
7.5 |
| CVE-2026-19043 |
Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Portal |
04.09.2026 |
4.3 |
| CVE-2026-18957 |
Stored XSS in Menulux Software's Menulux Portal |
04.09.2026 |
5.4 |
| CVE-2026-85577 |
AVideo userLogin.php Reflected XSS via error parameter |
04.09.2026 |
|
| CVE-2026-85578 |
SiYuan through 3.8.1 Authorization Bypass via getFile |
04.09.2026 |
|
| CVE-2026-85579 |
SiYuan before v3.8.2 Information Disclosure via undoState |
04.09.2026 |
|
| CVE-2026-85580 |
SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
04.09.2026 |
|
| CVE-2026-85581 |
SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
04.09.2026 |
|
| CVE-2026-85582 |
SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
04.09.2026 |
|
| CVE-2026-85583 |
SiYuan before v3.8.2 Path Traversal via symlink in file API |
04.09.2026 |
|
| CVE-2026-85584 |
SiYuan before v3.8.2 Denial of Service via Auth Throttle |
04.09.2026 |
|
| CVE-2026-85585 |
SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
04.09.2026 |
|
| CVE-2026-85586 |
phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter |
04.09.2026 |
|
| CVE-2026-85587 |
phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages |
04.09.2026 |
|
| CVE-2026-85588 |
phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export |
04.09.2026 |
|
| CVE-2026-85589 |
phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API |
04.09.2026 |
|
| CVE-2026-85590 |
phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable |
04.09.2026 |
|
| CVE-2026-85591 |
phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change |
04.09.2026 |
|
| CVE-2026-85592 |
phpMyFAQ before 4.1.8 Authorization Bypass via question/create |
04.09.2026 |
|
| CVE-2026-85593 |
phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode |
04.09.2026 |
|
| CVE-2026-85594 |
Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware |
04.09.2026 |
|
| CVE-2026-85595 |
Traefik before v2.11.55 Authentication Bypass via digestAuth |
04.09.2026 |
|
| CVE-2026-85596 |
Traefik v3.7 Authentication Bypass via TLS Option Conflict |
04.09.2026 |
|
| CVE-2026-85597 |
Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict |
04.09.2026 |
|
| CVE-2026-85598 |
Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages |
04.09.2026 |
|
| CVE-2026-85599 |
Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters |
04.09.2026 |
|
| CVE-2026-85600 |
Grav Admin before 2.0.21 Stored XSS via username |
04.09.2026 |
|
| CVE-2026-85601 |
Grav Admin before 2.0.20 Cross-Site Scripting via marked.js |
04.09.2026 |
|
| CVE-2026-85602 |
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass |
04.09.2026 |
|
| CVE-2026-85603 |
Grav Admin Plugin Path Traversal via Save As Language Code |
04.09.2026 |
|
| CVE-2026-85604 |
Grav before 2.0.19 Remote Code Execution via sort filter |
04.09.2026 |
|
| CVE-2026-85609 |
Openpanel before 2.3.0 SSRF via Site Checker Endpoint |
04.09.2026 |
|
| CVE-2026-85610 |
OpenPanel before 2.3.0 Remote Code Execution via chart formulas |
04.09.2026 |
|
| CVE-2026-85611 |
OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures |
04.09.2026 |
|
| CVE-2026-85612 |
OpenPanel before 2.3.0 SSRF via favicon and og endpoints |
04.09.2026 |
|
| CVE-2026-85613 |
OpenPanel Unauthenticated XSS via SVG Favicon Proxy |
04.09.2026 |
|
| CVE-2026-85614 |
OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker |
04.09.2026 |
|
| CVE-2026-85615 |
Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts |
04.09.2026 |
|
| CVE-2026-85616 |
Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance |
04.09.2026 |
|
| CVE-2026-85617 |
snipe-it before 8.6.3 Authorization Bypass via Bulk Delete |
04.09.2026 |
|
| CVE-2026-27347 |
WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability |
04.09.2026 |
5.3 |
| CVE-2026-84428 |
fastify vulnerable to header validation bypass via incomplete schema case normalization |
04.09.2026 |
7.5 |
| CVE-2026-4644 |
Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover |
04.09.2026 |
|
| CVE-2026-79707 |
Arbitrary File Read in Google Agent Development Kit (ADK) |
04.09.2026 |
|
| CVE-2026-84045 |
E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart |
04.09.2026 |
5.3 |
| CVE-2026-85512 |
SourceCodester Class and Exam Timetabling System session.php authorization |
04.09.2026 |
|
| CVE-2026-85534 |
Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read |
04.09.2026 |
|
| CVE-2026-82923 |
AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes |
04.09.2026 |
9.8 |
| CVE-2026-84043 |
ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypass |
04.09.2026 |
5.3 |
| CVE-2026-84044 |
Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPN |
04.09.2026 |
5.3 |
| CVE-2026-84469 |
fastify vulnerable to request validation bypass via skipped boolean false schemas |
04.09.2026 |
7.5 |