CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 29.09.2026 9.3
CVE-2026-22094 Weak root password in EVbee DC 80 29.09.2026 9.3
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026 9.3
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026 9.3
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026 9
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026 9.3
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026 9.3
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 29.09.2026 9.2
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026 10
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026 9.4
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 28.09.2026 9.3
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 28.09.2026 9.4
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 28.09.2026 9.4
CVE-2026-101262 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026 9.4
CVE-2026-101261 Ziroom ZHOME A0101 firstSetup_wifi command injection 28.09.2026 9.4
CVE-2026-101260 Ziroom ZHOME A0101 firstLogin command injection 28.09.2026 9.4
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection 28.09.2026 9.1
CVE-2026-101187 Ziroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injection 28.09.2026 9.4
CVE-2026-102268 PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard 29.09.2026 9.1
CVE-2026-100752 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 28.09.2026 9.3
CVE-2026-101108 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 28.09.2026 9.3
CVE-2026-101110 Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 28.09.2026 9.3
CVE-2026-49994 Bluehood: Missing authentication on Bluehood API routes when web auth is enabled 28.09.2026 9.1
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access 28.09.2026 9.3
CVE-2026-101894 @xhmikosr/decompress: Path traversal via symlink chain 28.09.2026 9.1
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution 28.09.2026 9.3
CVE-2026-101081 D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow 28.09.2026 9.4
CVE-2026-88804 Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher 28.09.2026 9.6
CVE-2026-12342 SailPoint IdentityIQ Improper Form Validation Vulnerability 29.09.2026 9.6
CVE-2026-101076 Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection 28.09.2026 10
CVE-2026-101077 Netcore NR289-GE boa_temp process_request missing authentication 28.09.2026 10
CVE-2026-101075 Netcore NR289-GE Location Time location_time.cgi system os command injection 28.09.2026 10
CVE-2026-101074 Netcore NR289-GE Authentication boa password-check stack-based overflow 28.09.2026 9.3
CVE-2026-90924 Default Admin Credentials in Innotim Software's Logsign SIEM 28.09.2026 9.8
CVE-2026-101072 Netcore NR289-GE CGI ap_ip.cgi system os command injection 28.09.2026 10
CVE-2026-73640 Time-based SQL Injection in Dayforce Payroll 28.09.2026 9.3
CVE-2026-73642 Path Traversal in Dayforce Payroll 28.09.2026 9.2
CVE-2026-85185 Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root 28.09.2026 9.6
CVE-2026-85526 Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD 29.09.2026 9.9
CVE-2026-87799 Arbitrary file write on LXD host via symlink in migration stream 29.09.2026 9.9
CVE-2026-81867 Deserialization of Untrusted Data in Application Integration allows Remote Code Execution 28.09.2026 9.4
CVE-2026-101039 FAST FAC1900R devdiscover Service copy_msg_element stack-based overflow 28.09.2026 10
CVE-2026-101038 FAST FAC1200R MmtAtePrase stack-based overflow 28.09.2026 9.4
CVE-2026-19759 Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution 28.09.2026 9.4
CVE-2026-101037 FAST FAC1200R devdiscover Service parse_advertisement_frame stack-based overflow 28.09.2026 9.4
CVE-2026-82384 Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint 29.09.2026 9.8
CVE-2026-82377 Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers 29.09.2026 9.9
CVE-2026-82378 Apache Roller: OAuth authorization endpoint trusts request-supplied identity 29.09.2026 9
CVE-2026-101008 aaPanel BaoTa File Merge files.py merge_split_file command injection 28.09.2026 9.4
CVE-2026-101009 aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection 28.09.2026 9.3
CVE-2026-101007 aaPanel BaoTa Database Backup database.py InputSql os command injection 28.09.2026 9.3
CVE-2026-101002 Netcore NBR200V2 Tools Ping network_tools system os command injection 28.09.2026 9.4
CVE-2026-101001 Netcore NBR200V2 Web Management network_tools eval os command injection 28.09.2026 10
CVE-2026-101000 Netcore NBR100V2 ACL unauthenticated.json uci.apply authorization 28.09.2026 10
CVE-2026-100896 TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection 28.09.2026 9.4
CVE-2026-100886 Seetong T8108/T8108P/T8116/T8232 Debug Service improper authentication 28.09.2026 10
CVE-2026-101065 Obot Quickstart Docker Deployment Unauthenticated Admin Access 27.09.2026 9.3
CVE-2026-101084 obot before v0.21.1 Authorization Bypass via /mcp-connect 27.09.2026 9.3
CVE-2026-101090 Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri 28.09.2026 9.3
CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands 29.09.2026 9.5
CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 28.09.2026 9.5
CVE-2026-88773 HTTP Request Smuggling 29.09.2026 9.3
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 28.09.2026 9.8
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 28.09.2026 9.5
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 27.09.2026 9.1
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 28.09.2026 9.4
CVE-2026-82901 Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field 26.09.2026 9.8
CVE-2026-85984 miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter 26.09.2026 9.8
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.4
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.2
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 10
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 29.09.2026 9.5
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 27.09.2026 9.3
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 28.09.2026 9.2
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 28.09.2026 9.2
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 28.09.2026 9.2
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026 9.4
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026 9.4
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 28.09.2026 9.4
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026 9.3
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026 9
CVE-2026-100382 Unauthenticated remote code execution through wikitext in ExternalData 26.09.2026 10
CVE-2026-100389 GestSup before 3.2.61 Remote Code Execution via IMAP Attachment 25.09.2026 9.2
CVE-2026-100390 Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 25.09.2026 9.1
CVE-2026-48482 GLPI: RCE via Form import 25.09.2026 9.4
CVE-2026-84458 Zammad: Account takeover via unverified email matching during SSO auto-link 25.09.2026 9.1
CVE-2026-97063 X-SpringBoot through 6.0 Authentication Bypass via Login Code 25.09.2026 9.3
CVE-2026-97064 X-SpringBoot through 6.0 Authentication Bypass via Static Master Code 25.09.2026 9.3
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 28.09.2026 9.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 25.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 25.09.2026 9.1
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 26.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 28.09.2026 9.3
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026 9.3
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 26.09.2026 9.1
CVE-2026-81630 Botslab G980H Dashcams Insufficient Verification of Data Authenticity 25.09.2026 9.2
CVE-2026-93289 OS command injection in Eufy Omni C20, Omni X10 Pro 24.09.2026 9
CVE-2026-93291 Improper certificate validation in Eufy Omni C20 24.09.2026 9.3
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13249 Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040 24.09.2026 9.8
CVE-2026-61741 http4s-scala-xml has an XML External Entity (XXE) processing issue 29.09.2026 9.3
CVE-2026-61604 ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass 24.09.2026 9.3
CVE-2026-61732 Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context 24.09.2026 10
CVE-2026-61742 DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution 24.09.2026 9.3
CVE-2026-79766 Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email 29.09.2026 9.1
CVE-2026-97413 RDMA/rtrs-srv: Fix integer underflow in process_read and process_write 25.09.2026 9.8
CVE-2026-93425 Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root 24.09.2026 9.9
CVE-2026-93228 svcrdma: Reject Write/Reply chunks with segcount 0 25.09.2026 9.1
CVE-2026-93207 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry 25.09.2026 9.8
CVE-2026-81549 DataStage on Cloud Pak for Data has several vulnerabilities 24.09.2026 9.6
CVE-2026-90481 24.09.2026 9.2
CVE-2026-97404 26.09.2026 9.2
CVE-2026-97359 HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection 29.09.2026 10
CVE-2026-97360 HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine 24.09.2026 10
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy 24.09.2026 9.3
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal 25.09.2026 9.9
CVE-2026-12227 Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter 24.09.2026 9.8
CVE-2026-78312 Path Traversal in DIAEnergie 24.09.2026 9.1
CVE-2026-78308 Authentication Bypass in DIAEnergie 24.09.2026 9.8
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write 24.09.2026 9.3
CVE-2026-97055 SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret 24.09.2026 9.2
CVE-2026-18467 Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter 24.09.2026 9.8
CVE-2026-89078 Double Free in GitLab 25.09.2026 9.9
CVE-2026-93577 Integer Overflow or Wraparound in GitLab 25.09.2026 9.9
CVE-2026-93352 Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload 26.09.2026 9.3
CVE-2026-6928 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67231 RabbitMQ: Trust-store whitelist by Issuer+Serial only 29.09.2026 9.1
CVE-2026-6721 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-6730 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch 29.09.2026 9.2
CVE-2026-87898 23.09.2026 9.4
CVE-2026-87899 24.09.2026 9.4
CVE-2026-87900 23.09.2026 9.4
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups 24.09.2026 9.1
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) 25.09.2026 9.9
CVE-2026-77602 OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites) 29.09.2026 9.9
CVE-2026-96770 s2s-proxy accepts untrusted client certificates 23.09.2026 9.3
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match 24.09.2026 9.9
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod 24.09.2026 9.9
CVE-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack 23.09.2026 9.2
CVE-2026-95601 WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability 23.09.2026 9.3
CVE-2026-85724 Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass 24.09.2026 9.6
CVE-2026-95848 Moquette fails open when configured authentication or authorization classes cannot load 23.09.2026 9.3
CVE-2026-96754 orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path 29.09.2026 9.3
CVE-2026-96755 orval @orval/effect 8.14.0 through 8.28.1 Code Injection 23.09.2026 9.3
CVE-2026-96756 orval before 8.30.0 Code Injection via Factory Generation 23.09.2026 9.2
CVE-2026-96757 orval before 8.29.0 Code Injection via unescaped OpenAPI media-type 23.09.2026 9.3
CVE-2026-96758 orval @orval/core before 8.28.0 Code Injection via Form-Data 23.09.2026 9.3
CVE-2026-96759 orval before 8.29.0 Code Injection via operationId 29.09.2026 9.3
CVE-2026-18872 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.3
CVE-2026-59167 SunEditor: Critical XSS vulnerability - sanitizer bypass 24.09.2026 10
CVE-2026-96560 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel 24.09.2026 9.3
CVE-2026-86708 Sensitive data exposure 24.09.2026 10
CVE-2026-19599 Remote Code Execution vulnerability 24.09.2026 9.9
CVE-2026-96257 Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow 23.09.2026 10
CVE-2026-18162 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18163 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18169 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.9
CVE-2026-19202 Token Cache Reuse in mcp-toolbox-sdk-python 23.09.2026 9.1
CVE-2026-17645 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1

Latest Updates

CVE Title Updated Score
CVE-2026-100289 29.09.2026
CVE-2026-77177 29.09.2026
CVE-2026-100287 29.09.2026
CVE-2026-100288 29.09.2026
CVE-2026-102630 UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwarded-Host 29.09.2026
CVE-2026-19743 Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients 29.09.2026 7.8
CVE-2026-92368 Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution 29.09.2026 7.8
CVE-2026-92369 Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation 29.09.2026 7.3
CVE-2026-92370 Remote Session Access Control Bypass Leading to Remote Code Execution 29.09.2026 8.8
CVE-2026-92371 Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording 29.09.2026 7
CVE-2026-100286 29.09.2026
CVE-2026-102601 Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter 29.09.2026 3.5
CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing 29.09.2026
CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted 29.09.2026
CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC 29.09.2026
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves 29.09.2026
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS 29.09.2026
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V 29.09.2026
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake 29.09.2026
CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams 29.09.2026
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling 29.09.2026
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS 29.09.2026
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation 29.09.2026
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset 29.09.2026
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use 29.09.2026
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog 29.09.2026
CVE-2026-93332 29.09.2026
CVE-2026-97687 urllib3: HTTPS proxy TLS configuration may be ignored or overridden 29.09.2026
CVE-2026-97688 urllib3: Chunked Deflate streaming can enter an infinite loop 29.09.2026
CVE-2026-97689 urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory 29.09.2026
CVE-2023-54400 Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname 29.09.2026
CVE-2026-100308 GluonTS arbitrary command execution during model deserialization 29.09.2026 7.8
CVE-2026-102598 Werkzeug safe_join() allows Windows special device names 29.09.2026
CVE-2026-102600 Socket.IO: Prototype Pollution via Unsafe Client Session Lookup 29.09.2026 7.5
CVE-2026-93330 29.09.2026
CVE-2015-20122 Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp 29.09.2026
CVE-2026-49243 Webmin: Reflected XSS in the Configuration module 29.09.2026
CVE-2026-63209 Integer Overflow or Wraparound and Out-of-bounds Write in compress 29.09.2026 7.5
CVE-2026-68911 Nicotine+: Decompression of peer messages can exhaust available memory 29.09.2026
CVE-2026-86035 Weblate: Mercurial argument injection via repository filenames allows authenticated command execution 29.09.2026 8.5
CVE-2026-102491 mahonelau kykms SqlInjectionUtil QueryGenerator.java QueryGenerator.doMultiFieldsOrder sql injection 29.09.2026
CVE-2026-102566 CTranslate2 before 4.8.1 Heap Buffer Overflow via model.bin 29.09.2026
CVE-2026-102567 CTranslate2 before 4.8.1 Out-of-Bounds Read via Model Deserialization 29.09.2026
CVE-2026-102568 Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py 29.09.2026
CVE-2026-102569 ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter 29.09.2026
CVE-2026-102570 ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter 29.09.2026
CVE-2026-22094 Weak root password in EVbee DC 80 29.09.2026
CVE-2026-22101 Sensitive information leak through hidden menu 29.09.2026
CVE-2025-33207 29.09.2026 6.8
CVE-2026-102371 wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments 29.09.2026
CVE-2026-65102 29.09.2026 7.8
CVE-2026-97395 Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials 29.09.2026
CVE-2026-86450 Sensitive Data Exposure in Parla Auto's DetaWix Mobile Web Portal 29.09.2026 7.5
CVE-2026-102360 lib0 `readUint8Array` performs an unbounded read past the end of the decoder’s view, disclosing adjacent process memory 29.09.2026 8.6
CVE-2026-102521 lib0 `readFromDataView` out-of-bounds read 29.09.2026 8.6
CVE-2026-4034 TIBCO Administrator Injection Vulnerability 29.09.2026
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and batch-move endpoints 29.09.2026
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute Workflows and Tamper with Workflow Definitions 29.09.2026
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to Information Disclosure 29.09.2026
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths 29.09.2026
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized Workflow Execution 29.09.2026
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin 29.09.2026
CVE-2026-100756 Incorrect boundary conditions in the Audio/Video: Playback component 29.09.2026
CVE-2026-100757 Use-after-free in the Widget component 29.09.2026
CVE-2026-100758 Sandbox escape in the DOM: Navigation component 29.09.2026
CVE-2026-100759 Uninitialized memory in the Storage: Quota Manager component 29.09.2026
CVE-2026-100760 Sandbox escape in the Security: Process Sandboxing component 29.09.2026
CVE-2026-100761 Privilege escalation due to use-after-free in the Graphics: WebGPU component 29.09.2026
CVE-2026-100762 Sandbox escape due to use-after-free in the DOM: Content Processes component 29.09.2026
CVE-2026-100763 Incorrect boundary conditions in the Graphics: WebGPU component 29.09.2026
CVE-2026-100764 Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component 29.09.2026
CVE-2026-100765 Use-after-free in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100766 Information disclosure in the Networking: JAR component 29.09.2026
CVE-2026-100767 Use-after-free in the Networking: Cache component 29.09.2026
CVE-2026-100768 Use-after-free in the Graphics: WebGPU component 29.09.2026
CVE-2026-100769 Use-after-free in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100770 Sandbox escape due to use-after-free in the DOM: Content Processes component 29.09.2026
CVE-2026-100771 Undefined behavior in the DOM: Streams component 29.09.2026
CVE-2026-100772 Use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100773 Use-after-free in the Storage: IndexedDB component 29.09.2026
CVE-2026-100774 Use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100775 Sandbox escape in the Graphics component 29.09.2026
CVE-2026-100776 Use-after-free in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100777 Use-after-free in the Graphics: Canvas2D component 29.09.2026
CVE-2026-100778 Sandbox escape due to use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100779 Use-after-free in the XSLT component 29.09.2026
CVE-2026-100780 Use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100781 Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component 29.09.2026
CVE-2026-100782 Privilege escalation due to incorrect boundary conditions in the Graphics component 29.09.2026
CVE-2026-100783 Uninitialized memory in the Audio/Video component 29.09.2026
CVE-2026-100784 Use-after-free in the Layout: Text and Fonts component 29.09.2026
CVE-2026-100785 Use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100786 Sandbox escape due to use-after-free in the Graphics component 29.09.2026
CVE-2026-100787 Sandbox escape in the XUL component 29.09.2026
CVE-2026-100788 Invalid pointer in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100789 Use-after-free in the Graphics: Canvas2D component 29.09.2026
CVE-2026-100790 Use-after-free in the XSLT component 29.09.2026
CVE-2026-100791 Use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100792 JIT miscompilation in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100793 JIT miscompilation in the JavaScript Engine component 29.09.2026
CVE-2026-100794 Sandbox escape due to incorrect boundary conditions in the Internationalization component 29.09.2026
CVE-2026-100795 Denial-of-service in the Networking component 29.09.2026
CVE-2026-100796 Use-after-free in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100797 Privilege escalation due to use-after-free in the Graphics: WebRender component 29.09.2026
CVE-2026-100798 Cryptography misuse in Storage: Quota Manager component 29.09.2026
CVE-2026-100799 Uninitialized memory in the Graphics: WebGPU component 29.09.2026
CVE-2026-100800 Sandbox escape due to use-after-free in the Disability Access APIs component 29.09.2026
CVE-2026-100801 Privilege escalation in the DLL Services component 29.09.2026
CVE-2026-100802 Uninitialized memory in the Graphics: WebGPU component 29.09.2026
CVE-2026-100803 Same-origin policy bypass in the WebExtensions component 29.09.2026
CVE-2026-100804 Sandbox escape due to use-after-free in the Preferences: Backend component 29.09.2026
CVE-2026-100805 Race condition, use-after-free in the Audio/Video component 29.09.2026
CVE-2026-100806 Uninitialized memory in the Graphics: WebGPU component 29.09.2026
CVE-2026-100807 Privilege escalation in the DOM: Service Workers component 29.09.2026
CVE-2026-100808 Mitigation bypass in the DOM: Service Workers component 29.09.2026
CVE-2026-100809 Same-origin policy bypass in the DevTools component 29.09.2026
CVE-2026-100810 Other issue in the DevTools component 29.09.2026
CVE-2026-100811 Sandbox escape due to use-after-free in the DOM: Core & HTML component 29.09.2026
CVE-2026-100812 Denial-of-service in the Graphics component 29.09.2026
CVE-2026-100813 Invalid pointer in the JavaScript Engine: JIT component 29.09.2026
CVE-2026-100814 Incorrect boundary conditions in the JavaScript Engine: JIT component 29.09.2026
CVE-2026-100815 Use-after-free in the CSS Parsing and Computation component 29.09.2026
CVE-2026-100816 Site isolation issue in the DOM: Networking component 29.09.2026
CVE-2026-100817 Other issue in the JavaScript: WebAssembly component 29.09.2026
CVE-2026-100818 Sandbox escape due to use-after-free in the Widget: Gtk component 29.09.2026
CVE-2026-100819 Sandbox escape due to incorrect boundary conditions in the XPCOM component 29.09.2026
CVE-2026-100820 Privilege escalation in the Address Bar component 29.09.2026
CVE-2026-100821 Site isolation issue in the Panning and Zooming component 29.09.2026
CVE-2026-100822 Spoofing issue in the Networking: HTTP component 29.09.2026
CVE-2026-100823 Spoofing issue in the Downloads component in Firefox for Android 29.09.2026
CVE-2026-100824 Privilege escalation in the Places component 29.09.2026
CVE-2026-100825 Use-after-free in the JavaScript Engine: JIT component 29.09.2026
CVE-2026-100826 Denial-of-service in the Storage: StorageManager component 29.09.2026
CVE-2026-100828 Mitigation bypass in the Bookmarks & History component 29.09.2026
CVE-2026-100829 Mitigation bypass in the DOM: Security component 29.09.2026
CVE-2026-100830 Mitigation bypass in the DOM: Navigation component 29.09.2026
CVE-2026-100831 Use-after-free in the DOM: UI Events & Focus Handling component 29.09.2026
CVE-2026-100832 Use-after-free in the Graphics: Canvas2D component 29.09.2026
CVE-2026-76875 PyPy pyexpat ExternalEntityParserCreate Use-After-Free 29.09.2026
CVE-2026-96869 Information disclosure in the Networking component 29.09.2026
CVE-2026-101267 Revenue information leak 29.09.2026
CVE-2026-101268 Customer session fixation 29.09.2026
CVE-2026-101269 Incorrect session validation for API-uploaded files 29.09.2026
CVE-2026-101270 HTML injection 29.09.2026
CVE-2026-101271 OAuth credentials not disabled when application is disabled 29.09.2026
CVE-2026-102437 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in DeepSeek-Reasonix 29.09.2026 7.8
CVE-2026-73598 29.09.2026 7.8
CVE-2026-73599 29.09.2026 5.4
CVE-2026-76114 29.09.2026 5.9
CVE-2026-7192 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026
CVE-2026-7193 Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment 29.09.2026
CVE-2026-82973 Improper Neutralization of CRLF Sequences ('CRLF Injection') in docker-mailbox 29.09.2026 9.4
CVE-2026-98164 KVM: x86/mmu: Check write tracking in all address spaces 29.09.2026
CVE-2026-101266 Checkout validation bypass 29.09.2026
CVE-2026-73596 29.09.2026 3.8
CVE-2026-73597 29.09.2026 6.5
CVE-2026-102507 Sliver 1.7.7 Denial of Service via PE Parser Slice Bounds in Operator RPC 29.09.2026
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasources/unauth-datasource 29.09.2026
CVE-2026-87748 Privilege Escalation via Account Takeover in Interprobe's Qorela DC 29.09.2026 8.8
CVE-2026-102495 Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes 29.09.2026
CVE-2026-102496 Apache XMLSchema: Denial of service through deeply nested schema structures 29.09.2026
CVE-2026-102497 Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker 29.09.2026
CVE-2026-41875 Cross-Site Request Forgery in admin panel of Quick.Cart 29.09.2026
CVE-2026-73595 29.09.2026 4.7
CVE-2026-73593 29.09.2026 3
CVE-2026-73594 29.09.2026 6.4
CVE-2026-85520 Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module 29.09.2026
CVE-2026-95520 Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages 29.09.2026
CVE-2026-95509 Out-of-bounds read vulnerability in string formatting impacts Qt for MCUs 29.09.2026
CVE-2026-15390 Out-of-bounds write in Das U-Boot 29.09.2026
CVE-2026-19547 Local Privilege Escalation in Ghostscript for Windows 29.09.2026
CVE-2026-76719 HPE OneView - Cross-site scripting vulnerability 29.09.2026 8.2
CVE-2026-76720 HPE OneView - URL Redirect vulnerability 29.09.2026 4.3
CVE-2026-81862 Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs 29.09.2026
CVE-2026-81930 Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain 29.09.2026
CVE-2026-86843 Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag 29.09.2026
CVE-2026-76718 HPE OneView - Cross-site scripting vulnerability 29.09.2026 8.2
CVE-2026-81914 Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names 29.09.2026
CVE-2026-11796 29.09.2026
CVE-2026-7395 29.09.2026
CVE-2026-10518 Incorrect Authorization in GitLab 29.09.2026 4.3
CVE-2026-4523 Missing Authorization in GitLab 29.09.2026 3.7
CVE-2026-84739 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab 29.09.2026 8.7
CVE-2026-8067 29.09.2026 6.5
CVE-2026-8937 Missing Authorization in GitLab 29.09.2026 4.3
CVE-2026-95386 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark 29.09.2026 5.5
CVE-2026-95387 Heap-based Buffer Overflow in Wireshark 29.09.2026 8.1
CVE-2026-95388 Heap-based Buffer Overflow in Wireshark 29.09.2026 5.5
CVE-2026-95389 Heap-based Buffer Overflow in Wireshark 29.09.2026 8.1
CVE-2026-95390 NULL Pointer Dereference in Wireshark 29.09.2026 5.5
CVE-2026-95391 Use After Free in Wireshark 29.09.2026 5.5
CVE-2026-95392 Buffer Over-read in Wireshark 29.09.2026 5.5
CVE-2026-95393 Heap-based Buffer Overflow in Wireshark 29.09.2026 4.7
CVE-2026-95394 Unchecked Input for Loop Condition in Wireshark 29.09.2026 4.7
CVE-2026-95395 Missing Release of Memory after Effective Lifetime in Wireshark 29.09.2026 5.5
CVE-2026-96415 Stack-based Buffer Overflow in Wireshark 29.09.2026 5.5
CVE-2026-96416 Heap-based Buffer Overflow in Wireshark 29.09.2026 5.5
CVE-2026-96417 Heap-based Buffer Overflow in Wireshark 29.09.2026 5.5
CVE-2026-96418 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark 29.09.2026 5.5
CVE-2026-96419 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark 29.09.2026 5.5
CVE-2026-96420 Buffer Over-read in Wireshark 29.09.2026 4.7
CVE-2026-96421 Improperly Controlled Sequential Memory Allocation in Wireshark 29.09.2026 5.5
CVE-2026-96422 Reachable Assertion in Wireshark 29.09.2026 5.5
CVE-2026-96423 Heap-based Buffer Overflow in Wireshark 29.09.2026 5.5
CVE-2026-102473 Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled 29.09.2026
CVE-2026-102474 Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservation 29.09.2026
CVE-2026-8065 29.09.2026 9.1
CVE-2026-8066 29.09.2026 9.1
CVE-2026-92142 Apache Karaf: Authorization bypass in JMX MBean lifecycle operations 29.09.2026
CVE-2026-96440 Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) 29.09.2026
CVE-2026-91012 Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation 29.09.2026
CVE-2026-91048 Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create 29.09.2026
CVE-2026-91085 Apache Karaf: config:install missing ACL entry allows privilege escalation to admin 29.09.2026
CVE-2026-96429 Flowring Agentflow 4.0 - SQL Injection 29.09.2026
CVE-2026-96430 Flowring Agentflow 4.0 - Exposed Dangerous Method or Function 29.09.2026
CVE-2026-96431 Flowring Agentflow 4.0 - Unrestricted Upload of File with Dangerous Type 29.09.2026
CVE-2026-96428 Flowring Agentflow 4.0 - SQL Injection 29.09.2026
CVE-2026-101169 29.09.2026
CVE-2026-84154 Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x 29.09.2026 9.9
CVE-2026-86157 Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere 29.09.2026 5.6
CVE-2026-86158 Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere 29.09.2026 7.7
CVE-2026-102292 coolbeans1212 MateisHomePage-Website users.php cross site scripting 29.09.2026
CVE-2026-102293 realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServiceImpl.add improper authorization 29.09.2026
CVE-2026-102290 CodeCanyon Rocket LMS Student Profile Image Upload cross site scripting 29.09.2026
CVE-2026-102264 mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting 29.09.2026
CVE-2026-102261 owen2345 Camaleon CMS Media Crop media_controller.rb crop authorization 29.09.2026
CVE-2026-102263 mwasikz robo-cafe-rms manage-food.php unrestricted upload 29.09.2026
CVE-2026-102249 REBUILD file-editor-save authorization 29.09.2026
CVE-2026-102414 pbkdf2 rehashes long passwords on every iteration, enabling denial of service 29.09.2026
CVE-2026-102422 shell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` token 29.09.2026 8.1
CVE-2026-97029 Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group 29.09.2026
CVE-2026-102248 Rebuild Login Endpoint login improper authentication 29.09.2026
CVE-2026-97024 Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc 29.09.2026
CVE-2026-102245 MODSetter SurfSense circleback Endpoint circleback_webhook_route.py missing authentication 29.09.2026
CVE-2026-102247 FastAdmin Database Management database.php unnecessary privileges 29.09.2026
CVE-2026-102244 MODSetter SurfSense Document Export Feature editor_routes.py server-side request forgery 29.09.2026
CVE-2026-102241 Netcore NAP930 Backup/Restore backup_common.sh hard-coded key 29.09.2026
CVE-2026-102243 MODSetter SurfSense MCP Connector Integration test command injection 29.09.2026
CVE-2026-97685 LimeSurvey Community Edition 7.3.0 - Cross-survey object authorization bypass in REST survey patch operations 29.09.2026
CVE-2026-101878 Bitwarden Server 2025.6.0 < 2025.6.0 Authentication Bypass via SSO Identifier Truncation 29.09.2026
CVE-2026-102240 Netcore NAP930 Network Tools CGI network_tools eval os command injection 29.09.2026
CVE-2026-101859 RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection 29.09.2026
CVE-2026-101860 RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management 29.09.2026
CVE-2026-96326 HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenticated Stored Cross-Site Scripting via Rich Text Editor Field 29.09.2026 7.2
CVE-2026-101354 FAST FAC1203R MmtAtePrase _tWlanTask stack-based overflow 29.09.2026
CVE-2026-101858 RaspAP raspap-webgui SSID Processing WiFiManager.php writeWpaSupplicant os command injection 29.09.2026
CVE-2026-101278 Trusted Domain Project OpenDMARC PSL Wildcard opendmarc_tld.c : opendmarc_get_tld origin validation 29.09.2026
CVE-2026-101279 Trusted Domain Project OpenDMARC opendmarc_policy.c integer overflow 29.09.2026
CVE-2026-101280 Trusted Domain Project OpenDMARC Multi-Record Set opendmarc_policy_query_dmarc authentication spoofing 29.09.2026
CVE-2026-101281 Trusted Domain Project OpenDMARC SPF Macro opendmarc_spf.c opendmarc_sp2_find_mailfrom_domain improper authentication 29.09.2026
CVE-2026-102372 GestSup before 3.2.62 Stored XSS via Email Body in LOGIN IMAP Connector 29.09.2026
CVE-2026-102373 GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter 29.09.2026
CVE-2026-102374 GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IMAP Connector 29.09.2026
CVE-2026-101277 Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source 28.09.2026
CVE-2026-102361 mall4j through 4.0 Missing Authentication in Password Update Endpoint 28.09.2026
CVE-2026-102362 mall4j through 4.0 Missing Authentication in Product Review Deletion 29.09.2026
CVE-2026-102363 mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number 28.09.2026
CVE-2026-102364 mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API 28.09.2026
CVE-2026-102365 mall4j through 4.0 Missing Authorization in Admin User Address Endpoints 28.09.2026
CVE-2026-102366 mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints 29.09.2026
CVE-2026-102367 mall4j through 4.0 Insufficient Session Expiration via Token Refresh 28.09.2026
CVE-2026-101265 Intelbras TIP 125i Básico sensitive information in source 29.09.2026
CVE-2026-18417 Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asynchronous error 28.09.2026 6.5
CVE-2026-18746 NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted 28.09.2026 5.9
CVE-2026-18747 Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read 28.09.2026 6.8
CVE-2026-101263 Ziroom ZHOME A0101 set_online_client command injection 28.09.2026
CVE-2026-101264 Ziroom ZHOME A0101 set_passwd command injection 28.09.2026
CVE-2026-101262 Ziroom ZHOME A0101 set_online_client command injection 29.09.2026
CVE-2026-101261 Ziroom ZHOME A0101 firstSetup_wifi command injection 28.09.2026
CVE-2026-101260 Ziroom ZHOME A0101 firstLogin command injection 28.09.2026
CVE-2026-102332 Dozzle before 11.1.2 Path Traversal via Log ZIP Download 28.09.2026
CVE-2026-102333 httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL 29.09.2026
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 Missing Brute-Force Protection 28.09.2026
CVE-2026-102335 Nginx Proxy Manager through 2.16.0 Improper Authorization via advanced_config 28.09.2026
CVE-2024-58386 ZoneMinder 1.37.x Path Traversal via files view 28.09.2026
CVE-2026-101091 SiYuan before v3.8.4 SQL Injection via Block Query Embed 28.09.2026
CVE-2026-101092 SiYuan before v3.8.4 Information Disclosure via getCurrentAttrViewImages 28.09.2026
CVE-2026-101093 Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion 29.09.2026
CVE-2026-101205 FastStone Image Viewer PCX Decoder out-of-bounds 29.09.2026
CVE-2026-102296 ZoneMinder before 1.38.4 Buffer Overflow via HTTP Camera Response 28.09.2026
CVE-2026-102297 ZoneMinder before 1.38.4 Incorrect Authorization in frames API index 28.09.2026
CVE-2026-101204 FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds 28.09.2026
CVE-2024-42002 Unsafe use of eval() method in ros2 topic hz tool 28.09.2026