| CVE-2026-18905 |
IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation |
04.09.2026 |
7.7 |
| CVE-2026-75169 |
|
04.09.2026 |
|
| CVE-2026-75170 |
|
04.09.2026 |
|
| CVE-2026-75171 |
|
04.09.2026 |
|
| CVE-2026-80824 |
usb: usbfs: fix use-after-free of usb_device in usbdev_release() |
04.09.2026 |
|
| CVE-2026-80825 |
wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb |
04.09.2026 |
|
| CVE-2026-80826 |
USB: c67x00: fix use-after-free in c67x00_add_iso_urb() |
04.09.2026 |
|
| CVE-2026-80827 |
USB: serial: option: fix slab OOB read in interrupt URB callback |
04.09.2026 |
|
| CVE-2026-80828 |
ALSA: usb-audio: Complete cleanup after system-resume errors |
04.09.2026 |
|
| CVE-2026-80829 |
ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() |
04.09.2026 |
|
| CVE-2026-80830 |
usb: core: Add lock to usb_wakeup_notification() |
04.09.2026 |
|
| CVE-2026-80831 |
crypto: mxs-dcp - fix source scatterlist length access |
04.09.2026 |
|
| CVE-2026-80832 |
crypto: qce - fix CCM AAD buffer underallocation |
04.09.2026 |
|
| CVE-2026-80833 |
crypto: sun8i-ss - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80834 |
crypto: sun8i-ce - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80835 |
crypto: qcom-rng - Remove crypto_rng interface |
04.09.2026 |
|
| CVE-2026-80836 |
crypto: virtio - bound the akcipher result length |
04.09.2026 |
|
| CVE-2026-80837 |
netfilter: nf_tables: don't queue packet path object notifications |
04.09.2026 |
|
| CVE-2026-80838 |
vxlan: keep the last remote linked during FDB flush |
04.09.2026 |
|
| CVE-2026-80839 |
batman-adv: reject unrepresentable multicast TVLV offsets |
04.09.2026 |
|
| CVE-2026-80840 |
ipv6: seg6: clear IPv4 control block on IPIP decapsulation |
04.09.2026 |
|
| CVE-2026-80841 |
net/packet: defer vmalloc TX_RING free until skbs finish |
04.09.2026 |
|
| CVE-2026-80842 |
net: bridge: mcast: fix use-after-free of a master VLAN's multicast context |
04.09.2026 |
|
| CVE-2026-80843 |
xfrm: fix xfrm_state_construct() auth-trunc leak |
04.09.2026 |
|
| CVE-2026-80844 |
xfrm: ah6: validate routing header segments_left |
04.09.2026 |
|
| CVE-2026-80845 |
xfrm: avoid lock inversion in nat keepalive work |
04.09.2026 |
|
| CVE-2026-80846 |
xfrm: drop ESP-in-TCP packets with no ingress device |
04.09.2026 |
|
| CVE-2026-80847 |
tcp: clamp route advmss to TCP_MIN_MSS |
04.09.2026 |
|
| CVE-2026-80848 |
xfrm: espintcp: fix UAF during close |
04.09.2026 |
|
| CVE-2026-80849 |
net/tcp-ao: fix use-after-free of current_key on reconnect to another peer |
04.09.2026 |
|
| CVE-2026-80850 |
tcp: fix AO info use-after-free in tcp_ao_connect_init() |
04.09.2026 |
|
| CVE-2026-80851 |
gtp: serialize PDP context updates |
04.09.2026 |
|
| CVE-2026-80852 |
tls: device: fix out-of-bounds write in tls_append_frag() |
04.09.2026 |
|
| CVE-2026-80853 |
KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts |
04.09.2026 |
|
| CVE-2026-80854 |
usb: gadget: f_tcm: keep port count until LUN teardown completes |
04.09.2026 |
|
| CVE-2026-80855 |
fuse: fix invalidate lock leak on open O_TRUNC DAX failure |
04.09.2026 |
|
| CVE-2026-80856 |
fuse: fix invalidate lock leak on setattr writeback failure |
04.09.2026 |
|
| CVE-2026-80857 |
fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free |
04.09.2026 |
|
| CVE-2026-80858 |
fuse: publish io-uring queues with release semantics |
04.09.2026 |
|
| CVE-2026-80859 |
fuse: fix missing barrier when checking io-uring readiness |
04.09.2026 |
|
| CVE-2026-80860 |
fuse: fix race between interrupt and resend |
04.09.2026 |
|
| CVE-2026-80861 |
usb: xhci: bail out of setup if the controller is inaccessible |
04.09.2026 |
|
| CVE-2026-80862 |
nvme-tcp: fix usage of page_frag_cache |
04.09.2026 |
|
| CVE-2026-80863 |
RDMA/rxe: Fix OOB in free_rd_atomic_resources() |
04.09.2026 |
|
| CVE-2026-80864 |
RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp |
04.09.2026 |
|
| CVE-2026-19274 |
IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image |
04.09.2026 |
9.6 |
| CVE-2026-19283 |
IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image |
04.09.2026 |
7.7 |
| CVE-2026-19299 |
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components |
04.09.2026 |
6.5 |
| CVE-2026-19300 |
Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows |
04.09.2026 |
7.5 |
| CVE-2026-75166 |
|
04.09.2026 |
|
| CVE-2026-75167 |
|
04.09.2026 |
|
| CVE-2026-75168 |
|
04.09.2026 |
|
| CVE-2026-75431 |
|
04.09.2026 |
9.1 |
| CVE-2026-19302 |
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components |
04.09.2026 |
6.5 |
| CVE-2026-75163 |
|
04.09.2026 |
|
| CVE-2026-75164 |
|
04.09.2026 |
|
| CVE-2026-75165 |
|
04.09.2026 |
|
| CVE-2026-75160 |
|
04.09.2026 |
|
| CVE-2026-75161 |
|
04.09.2026 |
|
| CVE-2026-75162 |
|
04.09.2026 |
|
| CVE-2026-75429 |
|
04.09.2026 |
|
| CVE-2026-82911 |
CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes |
04.09.2026 |
|
| CVE-2022-35497 |
|
04.09.2026 |
|
| CVE-2022-35499 |
|
04.09.2026 |
|
| CVE-2026-19304 |
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components |
04.09.2026 |
7.7 |
| CVE-2026-19305 |
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components |
04.09.2026 |
8.6 |
| CVE-2026-44402 |
Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi |
04.09.2026 |
|
| CVE-2026-80821 |
nvmet: pci-epf: put CQ ref on create_cq mapping failure |
04.09.2026 |
|
| CVE-2026-80822 |
mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() |
04.09.2026 |
|
| CVE-2026-80823 |
nfc: st21nfca: validate ATR_REQ length against the received frame |
04.09.2026 |
|
| CVE-2026-19306 |
Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components |
04.09.2026 |
7.7 |
| CVE-2026-19645 |
Multiple vulnerabilities in IBM MQ Agent images |
04.09.2026 |
6.5 |
| CVE-2026-19649 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
6.2 |
| CVE-2026-5522 |
QRadar contains hard-coded credentials |
04.09.2026 |
6.7 |
| CVE-2026-77822 |
IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpoint |
04.09.2026 |
8.2 |
| CVE-2026-78543 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
5.3 |
| CVE-2026-78658 |
IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability |
04.09.2026 |
6.5 |
| CVE-2026-79418 |
|
04.09.2026 |
|
| CVE-2026-79419 |
|
04.09.2026 |
|
| CVE-2026-80758 |
futex: Avoid private hash use-after-free on final put |
04.09.2026 |
|
| CVE-2026-80759 |
Bluetooth: hci_aml: validate firmware segment lengths |
04.09.2026 |
|
| CVE-2026-80760 |
Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 |
04.09.2026 |
|
| CVE-2026-80761 |
Bluetooth: ISO: zero the sockaddr before returning it in getname |
04.09.2026 |
|
| CVE-2026-80762 |
Bluetooth: hci_sync: Fix accept list UAF during suspend |
04.09.2026 |
|
| CVE-2026-80763 |
Bluetooth: hci_event: validate LE Set CIG Parameters response |
04.09.2026 |
|
| CVE-2026-80764 |
Bluetooth: hci_event: fix LE list UAF on reset |
04.09.2026 |
|
| CVE-2026-80765 |
HID: hyperv: validate initial device info bounds |
04.09.2026 |
|
| CVE-2026-80766 |
HID: uclogic: fix use-after-free of inrange_timer on remove |
04.09.2026 |
|
| CVE-2026-80767 |
HID: sensor: custom: Fix use-after-free in enable_sensor |
04.09.2026 |
|
| CVE-2026-80768 |
HID: ft260: fix stack-use-after-return write in I2C read race |
04.09.2026 |
|
| CVE-2026-80769 |
HID: rapoo: fix missing hid_is_usb() check |
04.09.2026 |
|
| CVE-2026-80770 |
HID: nintendo: stop device IO before hid_hw_stop on probe failure |
04.09.2026 |
|
| CVE-2026-80771 |
HID: nintendo: register input device after capabilities are set |
04.09.2026 |
|
| CVE-2026-80772 |
HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() |
04.09.2026 |
|
| CVE-2026-80773 |
HID: huawei: fix missing hid_is_usb() check |
04.09.2026 |
|
| CVE-2026-80774 |
HID: asus: fix missing hid_is_usb() check |
04.09.2026 |
|
| CVE-2026-80775 |
futex: Fix race on the initial mm->futex.phash.ref allocation |
04.09.2026 |
|
| CVE-2026-80776 |
futex: Fix race in futex_pivot_pending() during private hash resize |
04.09.2026 |
|
| CVE-2026-80777 |
futex/pi: Plug private futex exec() race |
04.09.2026 |
|
| CVE-2026-80778 |
futex/pi: Reject cross-mm private futex owners |
04.09.2026 |
|
| CVE-2026-80779 |
net/ionic: avoid OOB TX partner lookup for hwstamp RXQ |
04.09.2026 |
|
| CVE-2026-80780 |
HID: pidff: fix OOB write when hid->inputs is empty |
04.09.2026 |
|
| CVE-2026-80781 |
HID: core: fix OOB read of field->usage in hid_set_field() |
04.09.2026 |
|
| CVE-2026-80782 |
HID: magicmouse: do not keep a stale msc->input if no input is claimed |
04.09.2026 |
|
| CVE-2026-80783 |
HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() |
04.09.2026 |
|
| CVE-2026-80784 |
mptcp: pm: fix memory leak from alloc-during-teardown race |
04.09.2026 |
|
| CVE-2026-80785 |
fbdev: serialize mode sysfs access with lock_fb_info() |
04.09.2026 |
|
| CVE-2026-80786 |
fbdev: Wrap user-invoked calls to fb_set_var() in helper |
04.09.2026 |
|
| CVE-2026-80787 |
nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() |
04.09.2026 |
|
| CVE-2026-80788 |
nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations |
04.09.2026 |
|
| CVE-2026-80789 |
nvmet-tcp: bound SGL data length before allocating command buffers |
04.09.2026 |
|
| CVE-2026-80790 |
nvmet-fc: fix invalid free in LS IOD error path |
04.09.2026 |
|
| CVE-2026-80791 |
nvmet-auth: zero the AUTH_RECEIVE response buffer |
04.09.2026 |
|
| CVE-2026-80792 |
ipv6: fix use-after-free in ip6_finish_output2() |
04.09.2026 |
|
| CVE-2026-80793 |
ipv4: reject undersized MTUs in ip_do_fragment() |
04.09.2026 |
|
| CVE-2026-80794 |
nfc: nci: fix uninit-value in the RF discover/activated NTF handlers |
04.09.2026 |
|
| CVE-2026-80795 |
nfc: nci: fix out-of-bounds write in nci_target_auto_activated() |
04.09.2026 |
|
| CVE-2026-80796 |
nfc: nci: add data_len bound checks to activation parameter extractors |
04.09.2026 |
|
| CVE-2026-80797 |
nfc: pn533: purge fragmented skbs during cleanup |
04.09.2026 |
|
| CVE-2026-80798 |
nfc: llcp: reject PDUs shorter than the LLCP header |
04.09.2026 |
|
| CVE-2026-80799 |
nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers |
04.09.2026 |
|
| CVE-2026-80800 |
nfc: llcp: bound the connect_sn TLV walk to the skb |
04.09.2026 |
|
| CVE-2026-80801 |
nfc: microread: validate target discovery payload lengths |
04.09.2026 |
|
| CVE-2026-80802 |
nfc: fdp: bound the device-reported read length and fix an skb leak |
04.09.2026 |
|
| CVE-2026-80803 |
nfc: digital: clamp SENSF_RES length to the destination buffer |
04.09.2026 |
|
| CVE-2026-80804 |
xfs: restore nofs context unconditionally in xfs_trans_roll |
04.09.2026 |
|
| CVE-2026-80805 |
xfs: validate attr entry pointer before field access |
04.09.2026 |
|
| CVE-2026-80806 |
ext4: don't enable DAX on new encrypted files |
04.09.2026 |
|
| CVE-2026-80807 |
nilfs2: reject invalid block index in GC ioctl |
04.09.2026 |
|
| CVE-2026-80808 |
ext4: stop retrying saturated xattr cache entries |
04.09.2026 |
|
| CVE-2026-80809 |
ocfs2: fix missing metadata reservation for large xattrs |
04.09.2026 |
|
| CVE-2026-80810 |
io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() |
04.09.2026 |
|
| CVE-2026-80811 |
io_uring/cmd: fix iovec leak when the async cmd is not recycled |
04.09.2026 |
|
| CVE-2026-80812 |
ALSA: dummy: Check card index validity at probe |
04.09.2026 |
|
| CVE-2026-80813 |
nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() |
04.09.2026 |
|
| CVE-2026-80814 |
rndis_host: add overflow check in rndis_rx_fixup() |
04.09.2026 |
|
| CVE-2026-80815 |
ALSA: scarlett2: Use a private URB for the notification endpoint |
04.09.2026 |
|
| CVE-2026-80816 |
ALSA: FCP: Use a private URB for the notification endpoint |
04.09.2026 |
|
| CVE-2026-80817 |
iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages |
04.09.2026 |
|
| CVE-2026-80818 |
iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown |
04.09.2026 |
|
| CVE-2026-80819 |
Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept |
04.09.2026 |
|
| CVE-2026-80820 |
xfs: don't livelock in scrub on a circular unlinked list |
04.09.2026 |
|
| CVE-2026-85730 |
smol-toml: Denial of Service via malformed TOML documents |
04.09.2026 |
|
| CVE-2026-6958 |
Acunetix 25.11.251107123 Local Privilege Escalation via wvsc.exe |
04.09.2026 |
|
| CVE-2026-81832 |
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs |
04.09.2026 |
7.7 |
| CVE-2026-81859 |
Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for August 2026. |
04.09.2026 |
6.2 |
| CVE-2026-82728 |
Unbounded HTTP/1 status-line and chunk-extension buffering in Mint causes memory-exhaustion DoS |
04.09.2026 |
|
| CVE-2026-82729 |
Quadratic chunk-size parsing in Mint.HTTP1.Parse allows CPU-exhaustion DoS |
04.09.2026 |
|
| CVE-2026-85605 |
Slink before 1.12.3 Missing Authorization on Image Comment Endpoints |
04.09.2026 |
|
| CVE-2026-85606 |
firecrawl-mcp-server 3.20.2 Arbitrary Local File Read via filePath |
04.09.2026 |
|
| CVE-2026-85607 |
Blinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC Router |
04.09.2026 |
|
| CVE-2026-85608 |
Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter |
04.09.2026 |
|
| CVE-2026-85618 |
ConvertX 0.17.0 Arbitrary File Read via LaTeX Input Directives |
04.09.2026 |
|
| CVE-2026-85619 |
AppFlowy-Cloud 0.9.64 Cross-Workspace Collab Access via HTTP API |
04.09.2026 |
|
| CVE-2026-85620 |
Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function |
04.09.2026 |
|
| CVE-2026-85621 |
LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu |
04.09.2026 |
|
| CVE-2026-85622 |
AppFlowy-Cloud through 0.9.64 Cross-Workspace Collab Read via WebSocket |
04.09.2026 |
|
| CVE-2026-85623 |
goose 1.37.0 Arbitrary Command Execution via Recipe Extensions |
04.09.2026 |
|
| CVE-2026-85624 |
Blinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceList |
04.09.2026 |
|
| CVE-2026-85625 |
sift 17.1.3 Prototype Pollution Remote Code Execution via $where |
04.09.2026 |
|
| CVE-2026-85626 |
git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters |
04.09.2026 |
|
| CVE-2026-85650 |
Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel |
04.09.2026 |
|
| CVE-2026-85651 |
Trigger.dev before 4.5.2 Unauthorized Environment Access via Run Replay |
04.09.2026 |
|
| CVE-2026-85660 |
cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution |
04.09.2026 |
|
| CVE-2026-85661 |
excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode |
04.09.2026 |
|
| CVE-2026-85662 |
Marqo 2.26.0 Server-Side Request Forgery via Media URLs |
04.09.2026 |
|
| CVE-2026-85663 |
Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch |
04.09.2026 |
|
| CVE-2026-85664 |
Chroma 1.5.9 Unbounded HNSW Index Parameters Memory Exhaustion |
04.09.2026 |
|
| CVE-2026-85665 |
Bruno 3.4.2 Arbitrary File Read via Unconfined Body File Path |
04.09.2026 |
|
| CVE-2026-85666 |
ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url |
04.09.2026 |
|
| CVE-2026-85667 |
xiaobei through 5.5.2 Unauthenticated Webhook Message Injection |
04.09.2026 |
|
| CVE-2026-85668 |
Xinference 3.3.0 Unauthenticated Arbitrary-Path File Read via /v1/models/llm/auto-register |
04.09.2026 |
|
| CVE-2026-85669 |
potpie through 2.0.0 Missing Ownership Check via code-changes sync |
04.09.2026 |
|
| CVE-2026-85670 |
tokenizers BpeBuilder Buffer Overflow via merge token |
04.09.2026 |
|
| CVE-2026-85671 |
QAnything 2.0.0 Unauthenticated Cross-User File Disclosure |
04.09.2026 |
|
| CVE-2026-85672 |
zerox 1.1.20 OS Command Injection via Document URL File Extension |
04.09.2026 |
|
| CVE-2026-85673 |
LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding |
04.09.2026 |
|
| CVE-2026-85674 |
aider 0.86.2 Remote Code Execution via .aider.conf.yml |
04.09.2026 |
|
| CVE-2026-85675 |
OWL DocumentProcessingToolkit Server-Side Request Forgery via URL Fetching |
04.09.2026 |
|
| CVE-2026-85676 |
Dub Open Redirect via Unrestricted redir_url Parameter |
04.09.2026 |
|
| CVE-2026-85684 |
marker through 2.0.0 Path Traversal via upload filename |
04.09.2026 |
|
| CVE-2026-85685 |
AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill |
04.09.2026 |
|
| CVE-2026-85686 |
ms-swift 4.5.2 Unauthenticated SSRF via Multimodal Media URLs |
04.09.2026 |
|
| CVE-2026-85687 |
surya 0.22.1 Unauthenticated Arbitrary File Read via screenshot server |
04.09.2026 |
|
| CVE-2026-85688 |
TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer |
04.09.2026 |
|
| CVE-2026-85689 |
llmware 0.4.6 SQL Injection via unescaped filter values |
04.09.2026 |
|
| CVE-2026-85690 |
Plandex 2.2.1 Path Traversal via ApplyFiles |
04.09.2026 |
|
| CVE-2026-85691 |
MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url |
04.09.2026 |
|
| CVE-2026-85692 |
Nightingale 9.1.1 SSRF Guard Bypass via IPv6 Encoding |
04.09.2026 |
|
| CVE-2026-85693 |
Chatbot UI Cross-User Private File Content Disclosure via Retrieval API |
04.09.2026 |
|
| CVE-2026-85694 |
LaVague 0.2.35 Remote Code Execution via eval extraction |
04.09.2026 |
|
| CVE-2026-85695 |
FastChat Unauthenticated Worker Registration SSRF and Model Spoofing |
04.09.2026 |
|
| CVE-2026-85696 |
SadTalker OS Command Injection via Audio Filename |
04.09.2026 |
|
| CVE-2026-85697 |
Documenso 2.17.0 PDF Route Ignores Document Visibility |
04.09.2026 |
|
| CVE-2026-85698 |
Turso through 0.8.0-pre.8 Out-of-Bounds Read Denial of Service |
04.09.2026 |
|
| CVE-2026-85699 |
jina-ai reader server-side request forgery via redirect validation bypass |
04.09.2026 |
|
| CVE-2026-85700 |
Onyx 4.6.6 Custom Tool Secret Header Disclosure via Tool Endpoints |
04.09.2026 |
|
| CVE-2026-14466 |
Possible XSS in the SNS web administration panel |
04.09.2026 |
4.3 |
| CVE-2026-8447 |
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust |
04.09.2026 |
6.1 |
| CVE-2026-9138 |
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components |
04.09.2026 |
6.5 |
| CVE-2026-9186 |
Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untrusted proxy header trust |
04.09.2026 |
6.5 |
| CVE-2026-19205 |
User Enumeration in GastroMenum's GastroMenum Web Panel |
04.09.2026 |
7.5 |
| CVE-2026-19727 |
HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System |
04.09.2026 |
6.1 |
| CVE-2026-19081 |
Missing Authorization Allows Unauthorized Access to Critical POS Functions in Gastromenum's Gastromenum Ticket and QR Menu System |
04.09.2026 |
4.3 |
| CVE-2026-19057 |
Stored XSS in Gastromenum's Gastromenum Ticket and QR Menu System |
04.09.2026 |
5.4 |
| CVE-2026-85522 |
valkey-io valkey Slot Migration cluster_migrateslots.c createSlotImportJob out-of-bounds |
04.09.2026 |
|
| CVE-2026-52691 |
Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module |
04.09.2026 |
|
| CVE-2026-77818 |
Reflected HTML Injection via Form Hijacking in Yordam Informatics's Library Automation System |
04.09.2026 |
6.1 |
| CVE-2026-12483 |
LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler |
04.09.2026 |
7.5 |
| CVE-2026-85517 |
code-projects Vehicle Management System SQL Database Backup File vehicle_management.sql information disclosure |
04.09.2026 |
|
| CVE-2026-85516 |
code-projects Vehicle Management System busprofile.php sql injection |
04.09.2026 |
|
| CVE-2026-85649 |
|
04.09.2026 |
7.9 |
| CVE-2026-85514 |
StackStorm st2 API Key auth.py privileges management |
04.09.2026 |
|
| CVE-2026-74235 |
GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler |
04.09.2026 |
|
| CVE-2026-74236 |
GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Diagnostic File Deletion Handler |
04.09.2026 |
|
| CVE-2026-74237 |
GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client |
04.09.2026 |
|
| CVE-2026-82309 |
Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries |
04.09.2026 |
|
| CVE-2026-85513 |
StackStorm st2 NoOp RBAC backend actionexecutions.py privileges management |
04.09.2026 |
|
| CVE-2026-18198 |
SQL Injection in TAC Information's GoldenHorn |
04.09.2026 |
8.8 |
| CVE-2026-19051 |
Plaintext Storage of User Credentials in Menulux Software's Menulux Portal |
04.09.2026 |
7.1 |
| CVE-2026-19080 |
Username Enumeration in Menulux Software's Menulux Portal |
04.09.2026 |
7.5 |
| CVE-2026-19043 |
Authorization Bypass Critical POS Management Functions in Menulux Software's Menulux Portal |
04.09.2026 |
4.3 |
| CVE-2026-18957 |
Stored XSS in Menulux Software's Menulux Portal |
04.09.2026 |
5.4 |
| CVE-2026-85577 |
AVideo userLogin.php Reflected XSS via error parameter |
04.09.2026 |
|
| CVE-2026-85578 |
SiYuan through 3.8.1 Authorization Bypass via getFile |
04.09.2026 |
|
| CVE-2026-85579 |
SiYuan before v3.8.2 Information Disclosure via undoState |
04.09.2026 |
|
| CVE-2026-85580 |
SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
04.09.2026 |
|
| CVE-2026-85581 |
SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
04.09.2026 |
|
| CVE-2026-85582 |
SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
04.09.2026 |
|
| CVE-2026-85583 |
SiYuan before v3.8.2 Path Traversal via symlink in file API |
04.09.2026 |
|
| CVE-2026-85584 |
SiYuan before v3.8.2 Denial of Service via Auth Throttle |
04.09.2026 |
|
| CVE-2026-85585 |
SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
04.09.2026 |
|
| CVE-2026-85586 |
phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter |
04.09.2026 |
|
| CVE-2026-85587 |
phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages |
04.09.2026 |
|
| CVE-2026-85588 |
phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export |
04.09.2026 |
|
| CVE-2026-85589 |
phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API |
04.09.2026 |
|
| CVE-2026-85590 |
phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable |
04.09.2026 |
|
| CVE-2026-85591 |
phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change |
04.09.2026 |
|
| CVE-2026-85592 |
phpMyFAQ before 4.1.8 Authorization Bypass via question/create |
04.09.2026 |
|
| CVE-2026-85593 |
phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode |
04.09.2026 |
|
| CVE-2026-85594 |
Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware |
04.09.2026 |
|
| CVE-2026-85595 |
Traefik before v2.11.55 Authentication Bypass via digestAuth |
04.09.2026 |
|
| CVE-2026-85596 |
Traefik v3.7 Authentication Bypass via TLS Option Conflict |
04.09.2026 |
|
| CVE-2026-85597 |
Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict |
04.09.2026 |
|
| CVE-2026-85598 |
Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages |
04.09.2026 |
|
| CVE-2026-85599 |
Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters |
04.09.2026 |
|
| CVE-2026-85600 |
Grav Admin before 2.0.21 Stored XSS via username |
04.09.2026 |
|
| CVE-2026-85601 |
Grav Admin before 2.0.20 Cross-Site Scripting via marked.js |
04.09.2026 |
|
| CVE-2026-85602 |
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass |
04.09.2026 |
|
| CVE-2026-85603 |
Grav Admin Plugin Path Traversal via Save As Language Code |
04.09.2026 |
|
| CVE-2026-85604 |
Grav before 2.0.19 Remote Code Execution via sort filter |
04.09.2026 |
|
| CVE-2026-85609 |
Openpanel before 2.3.0 SSRF via Site Checker Endpoint |
04.09.2026 |
|
| CVE-2026-85610 |
OpenPanel before 2.3.0 Remote Code Execution via chart formulas |
04.09.2026 |
|
| CVE-2026-85611 |
OpenPanel before 2.3.0 Cross-Tenant BOLA via report procedures |
04.09.2026 |
|
| CVE-2026-85612 |
OpenPanel before 2.3.0 SSRF via favicon and og endpoints |
04.09.2026 |
|
| CVE-2026-85613 |
OpenPanel Unauthenticated XSS via SVG Favicon Proxy |
04.09.2026 |
|
| CVE-2026-85614 |
OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker |
04.09.2026 |
|
| CVE-2026-85615 |
Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts |
04.09.2026 |
|
| CVE-2026-85616 |
Snipe-IT before 8.6.2 Authorization Bypass via Checkout-Acceptance |
04.09.2026 |
|
| CVE-2026-85617 |
snipe-it before 8.6.3 Authorization Bypass via Bulk Delete |
04.09.2026 |
|
| CVE-2026-27347 |
WordPress JetPopup plugin <= 2.0.20.2 - Broken Access Control vulnerability |
04.09.2026 |
5.3 |
| CVE-2026-84428 |
fastify vulnerable to header validation bypass via incomplete schema case normalization |
04.09.2026 |
7.5 |
| CVE-2026-4644 |
Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover |
04.09.2026 |
|
| CVE-2026-79707 |
Arbitrary File Read in Google Agent Development Kit (ADK) |
04.09.2026 |
|
| CVE-2026-84045 |
E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation via mptbm_add_to_cart |
04.09.2026 |
5.3 |
| CVE-2026-85512 |
SourceCodester Class and Exam Timetabling System session.php authorization |
04.09.2026 |
|
| CVE-2026-85534 |
Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read |
04.09.2026 |
|
| CVE-2026-82923 |
AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes |
04.09.2026 |
9.8 |
| CVE-2026-84043 |
ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypass |
04.09.2026 |
5.3 |
| CVE-2026-84044 |
Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPN |
04.09.2026 |
5.3 |
| CVE-2026-84469 |
fastify vulnerable to request validation bypass via skipped boolean false schemas |
04.09.2026 |
7.5 |
| CVE-2026-76169 |
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers |
04.09.2026 |
7.5 |
| CVE-2026-13148 |
Memory leak in scan method |
04.09.2026 |
|
| CVE-2026-81666 |
Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems |
04.09.2026 |
|
| CVE-2026-84504 |
fastify vulnerable to request body replacement via an async validation result collision |
04.09.2026 |
8.1 |
| CVE-2026-85540 |
Interinfo|DreamMaker - SQL Injection |
04.09.2026 |
|
| CVE-2026-85541 |
Interinfo|DreamMaker - Reflected Cross-site Scripting |
04.09.2026 |
|
| CVE-2026-85547 |
Cross-Site Request Forgery via Attacker-Controlled REST Detection in MISP |
04.09.2026 |
|
| CVE-2026-85546 |
MISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET Requests |
04.09.2026 |
|
| CVE-2026-27086 |
WordPress WoodMart theme < 8.3.8 - Cross Site Scripting (XSS) vulnerability |
04.09.2026 |
6.5 |
| CVE-2026-85184 |
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target |
04.09.2026 |
9.1 |
| CVE-2026-81302 |
|
04.09.2026 |
|
| CVE-2026-81665 |
Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly |
04.09.2026 |
|
| CVE-2026-85538 |
MISP Attribute Deletion Authorization Bypass Allows Users Without Modify Permissions to Delete Attributes |
04.09.2026 |
|
| CVE-2026-85533 |
MISP Sharing Group Authorization Bypass via Omitted Distribution Parameter |
04.09.2026 |
|
| CVE-2026-27432 |
WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR) vulnerability |
04.09.2026 |
5.4 |
| CVE-2026-85528 |
Snowflake JDBC Driver auto-configuration account validation permits credential redirection |
04.09.2026 |
5.3 |
| CVE-2026-15937 |
Agent receiver certificate confusion allows authentication with a certificate issued for another endpoint |
04.09.2026 |
|
| CVE-2026-32480 |
WordPress WCFM Membership plugin <= 2.11.11 - Broken Access Control vulnerability |
04.09.2026 |
5.3 |
| CVE-2026-57777 |
WordPress WooCommerce plugin < 11.0 - SQL Injection vulnerability |
04.09.2026 |
7.6 |
| CVE-2026-85311 |
WordPress MarketKing plugin <= 2.1.60 - Broken Access Control vulnerability |
04.09.2026 |
5.3 |
| CVE-2026-85525 |
Improper OCSP response validation in Snowflake drivers |
04.09.2026 |
7.4 |
| CVE-2026-85197 |
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload |
04.09.2026 |
|
| CVE-2026-6217 |
Information Disclosure in Pik Online Software's Portal |
04.09.2026 |
6.3 |
| CVE-2026-80190 |
Apache Allura: Stored XSS via code repositories |
04.09.2026 |
|
| CVE-2026-85229 |
Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057) |
04.09.2026 |
|
| CVE-2026-71216 |
Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP |
04.09.2026 |
|
| CVE-2026-80181 |
Apache Allura: Server-side request forgery |
04.09.2026 |
|
| CVE-2026-81270 |
Apache Allura: Information exposure via search |
04.09.2026 |
|
| CVE-2026-15354 |
ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter |
04.09.2026 |
9.8 |
| CVE-2026-62928 |
|
04.09.2026 |
|
| CVE-2026-66840 |
|
04.09.2026 |
|
| CVE-2026-69657 |
|
04.09.2026 |
|
| CVE-2026-70403 |
|
04.09.2026 |
|
| CVE-2026-80180 |
Apache Allura: Stored XSS via markdown HTML processing |
04.09.2026 |
|
| CVE-2025-15691 |
WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms |
04.09.2026 |
|
| CVE-2026-16281 |
Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR |
04.09.2026 |
|
| CVE-2026-17517 |
Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status Filter |
04.09.2026 |
|
| CVE-2026-19224 |
Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite |
04.09.2026 |
|
| CVE-2026-74853 |
Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback |
04.09.2026 |
|
| CVE-2026-79630 |
WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substitution |
04.09.2026 |
|
| CVE-2026-79631 |
WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Log Files |
04.09.2026 |
|
| CVE-2026-79632 |
WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submission |
04.09.2026 |
|
| CVE-2026-80438 |
Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Information Disclosure via Abilities REST API |
04.09.2026 |
|
| CVE-2026-81347 |
Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion via Custom Directory Path Traversal |
04.09.2026 |
|
| CVE-2026-82186 |
WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter |
04.09.2026 |
|
| CVE-2026-82193 |
WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via Path Traversal |
04.09.2026 |
|
| CVE-2026-82194 |
WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal |
04.09.2026 |
|
| CVE-2026-84066 |
Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload |
04.09.2026 |
|
| CVE-2026-84146 |
Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick View |
04.09.2026 |
|
| CVE-2026-85085 |
|
04.09.2026 |
9.6 |
| CVE-2026-85094 |
|
04.09.2026 |
8.8 |