| CVE-2026-86167 |
Tenda HG10 Boa formgponConf os command injection |
06.09.2026 |
9.4 |
| CVE-2026-86165 |
Tenda HG10 formURL buffer overflow |
06.09.2026 |
9.3 |
| CVE-2026-16310 |
MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter |
06.09.2026 |
9.8 |
| CVE-2026-75816 |
Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier |
06.09.2026 |
9.8 |
| CVE-2026-86218 |
pre-authentication remote code execution |
06.09.2026 |
10 |
| CVE-2026-86153 |
Tenda CP3 Redirect.cpp SetRedirectEnable privileges management |
06.09.2026 |
9.4 |
| CVE-2026-86152 |
Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection |
06.09.2026 |
10 |
| CVE-2026-86151 |
Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection |
05.09.2026 |
9.4 |
| CVE-2026-86149 |
Tenda CP3 NetCheckPing.cpp os command injection |
05.09.2026 |
9.4 |
| CVE-2026-86148 |
Tenda CP3 Kylin system.c SystemAsh os command injection |
05.09.2026 |
9.4 |
| CVE-2026-67276 |
SSH user impersonation possible in Mikrotik RouterOS |
05.09.2026 |
9.2 |
| CVE-2026-86060 |
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS |
05.09.2026 |
9.2 |
| CVE-2026-86189 |
WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php |
05.09.2026 |
9.3 |
| CVE-2026-86190 |
WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter |
05.09.2026 |
9.3 |
| CVE-2026-86184 |
Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route |
05.09.2026 |
9.3 |
| CVE-2026-10196 |
Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields |
05.09.2026 |
9.8 |
| CVE-2026-86117 |
Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching |
05.09.2026 |
9.2 |
| CVE-2026-86119 |
Webstudio through 0.296.0 SSRF via /cgi proxy routes |
05.09.2026 |
9.2 |
| CVE-2026-86121 |
Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control |
05.09.2026 |
9.3 |
| CVE-2026-86123 |
SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints |
05.09.2026 |
9.4 |
| CVE-2026-86124 |
AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server |
05.09.2026 |
9.3 |
| CVE-2024-11080 |
Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection |
05.09.2026 |
9.8 |
| CVE-2026-13447 |
MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery |
05.09.2026 |
9.8 |
| CVE-2026-83627 |
Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log |
05.09.2026 |
9.8 |
| CVE-2026-52777 |
YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize |
04.09.2026 |
9.4 |
| CVE-2026-52766 |
YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action |
04.09.2026 |
9.1 |
| CVE-2026-75925 |
IXON VPN Client CRLF Injection |
04.09.2026 |
9.4 |
| CVE-2026-9317 |
Nango < 0.71.6 Missing Authentication RCE via runner tRPC server |
05.09.2026 |
9.2 |
| CVE-2026-75430 |
|
04.09.2026 |
9.8 |
| CVE-2026-18658 |
IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed |
04.09.2026 |
9.8 |
| CVE-2026-19274 |
IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image |
04.09.2026 |
9.6 |
| CVE-2026-75431 |
|
04.09.2026 |
9.1 |
| CVE-2026-44402 |
Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi |
04.09.2026 |
9.3 |
| CVE-2026-85620 |
Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function |
04.09.2026 |
9.2 |
| CVE-2026-85625 |
sift 17.1.3 Prototype Pollution Remote Code Execution via $where |
04.09.2026 |
9.2 |
| CVE-2026-85660 |
cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution |
04.09.2026 |
9.2 |
| CVE-2026-85661 |
excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode |
04.09.2026 |
9.3 |
| CVE-2026-85663 |
Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch |
04.09.2026 |
9.3 |
| CVE-2026-85667 |
xiaobei through 5.5.2 Unauthenticated Webhook Message Injection |
04.09.2026 |
9.3 |
| CVE-2026-85672 |
zerox 1.1.20 OS Command Injection via Document URL File Extension |
04.09.2026 |
9.3 |
| CVE-2026-85688 |
TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer |
04.09.2026 |
9.3 |
| CVE-2026-85694 |
LaVague 0.2.35 Remote Code Execution via eval extraction |
04.09.2026 |
9.2 |
| CVE-2026-85695 |
FastChat Unauthenticated Worker Registration SSRF and Model Spoofing |
04.09.2026 |
9.3 |
| CVE-2026-85696 |
SadTalker OS Command Injection via Audio Filename |
04.09.2026 |
9.3 |
| CVE-2026-85595 |
Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth |
05.09.2026 |
9.3 |
| CVE-2026-85602 |
Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass |
05.09.2026 |
9.3 |
| CVE-2026-85614 |
OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker |
04.09.2026 |
9.2 |
| CVE-2026-82923 |
AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes |
04.09.2026 |
9.8 |
| CVE-2026-85184 |
@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target |
04.09.2026 |
9.1 |
| CVE-2026-15354 |
ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter |
04.09.2026 |
9.8 |
| CVE-2026-62928 |
|
04.09.2026 |
9.3 |
| CVE-2026-69657 |
|
04.09.2026 |
9.3 |
| CVE-2026-70403 |
|
04.09.2026 |
9.3 |
| CVE-2026-85085 |
|
04.09.2026 |
9.6 |
| CVE-2026-11613 |
Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter |
04.09.2026 |
9.8 |
| CVE-2026-85506 |
|
04.09.2026 |
9.8 |
| CVE-2026-85507 |
|
04.09.2026 |
9.8 |
| CVE-2026-85508 |
|
04.09.2026 |
9.8 |
| CVE-2026-85509 |
|
04.09.2026 |
9.8 |
| CVE-2026-85504 |
|
04.09.2026 |
9.8 |
| CVE-2026-85146 |
Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
04.09.2026 |
9.3 |
| CVE-2026-85148 |
Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials |
04.09.2026 |
9.3 |
| CVE-2026-75754 |
|
04.09.2026 |
10 |
| CVE-2026-67402 |
|
04.09.2026 |
9.2 |
| CVE-2026-62916 |
Microsoft Entra ID Elevation of Privilege Vulnerability |
05.09.2026 |
9.1 |
| CVE-2026-70352 |
Azure AI Language Elevation of Privilege Vulnerability |
05.09.2026 |
10 |
| CVE-2026-80098 |
Copilot Studio Elevation of Privilege Vulnerability |
05.09.2026 |
9.3 |
| CVE-2026-83711 |
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability |
05.09.2026 |
10 |
| CVE-2026-85424 |
MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR |
05.09.2026 |
9.3 |
| CVE-2026-85425 |
MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS |
04.09.2026 |
9.3 |
| CVE-2026-85426 |
MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names |
04.09.2026 |
9.3 |
| CVE-2026-85427 |
MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE |
04.09.2026 |
9.2 |
| CVE-2026-85428 |
MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write |
03.09.2026 |
9.3 |
| CVE-2026-85433 |
MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration |
03.09.2026 |
9.3 |
| CVE-2026-85434 |
MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping |
05.09.2026 |
9.3 |
| CVE-2026-85435 |
MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment |
04.09.2026 |
9.3 |
| CVE-2026-85437 |
MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders |
04.09.2026 |
9.3 |
| CVE-2026-85438 |
MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts |
03.09.2026 |
9.3 |
| CVE-2026-85440 |
MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length |
04.09.2026 |
9.3 |
| CVE-2026-85224 |
D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection |
04.09.2026 |
9.4 |
| CVE-2026-85223 |
D-Link DNS-340L CGI dropbox.cgi os command injection |
04.09.2026 |
9.4 |
| CVE-2026-85222 |
D-Link DNS-340L Add-On Center addon_center.cgi os command injection |
04.09.2026 |
9.4 |
| CVE-2026-85061 |
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip |
04.09.2026 |
10 |
| CVE-2026-85391 |
Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml |
03.09.2026 |
9.3 |
| CVE-2026-85394 |
python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret |
03.09.2026 |
9.3 |
| CVE-2026-82526 |
R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint |
04.09.2026 |
9.3 |
| CVE-2026-58400 |
GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter |
04.09.2026 |
9.1 |
| CVE-2026-84238 |
WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability |
03.09.2026 |
9.8 |
| CVE-2026-84753 |
WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability |
05.09.2026 |
9.8 |
| CVE-2026-84768 |
WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability |
03.09.2026 |
9.3 |
| CVE-2026-84813 |
WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability |
04.09.2026 |
9.3 |
| CVE-2026-84814 |
WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability |
03.09.2026 |
9.8 |
| CVE-2026-84834 |
WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability |
03.09.2026 |
9.8 |
| CVE-2026-85181 |
CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum |
03.09.2026 |
9.3 |
| CVE-2026-85183 |
Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS |
03.09.2026 |
9.3 |
| CVE-2026-85216 |
MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
03.09.2026 |
9.5 |
| CVE-2026-85109 |
Tenda HG10 Boa Web Server formLogin buffer overflow |
03.09.2026 |
9.3 |
| CVE-2026-82180 |
|
03.09.2026 |
9.5 |
| CVE-2026-78080 |
Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 |
03.09.2026 |
9.3 |
| CVE-2026-78069 |
Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 |
03.09.2026 |
9.5 |
| CVE-2026-85154 |
WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash |
05.09.2026 |
9.3 |
| CVE-2026-76178 |
Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
03.09.2026 |
9.2 |
| CVE-2026-76174 |
Multiple vulnerabilities in Ocsreports for OCS Inventory NG |
03.09.2026 |
9.4 |
| CVE-2026-80726 |
KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page |
04.09.2026 |
9.3 |
| CVE-2026-85031 |
TOTOLINK CP450 cstecgi.cgi buffer overflow |
03.09.2026 |
9.4 |
| CVE-2026-19117 |
Delinea Secret Server FIDO2 credential registration authentication bypass vulnerability |
02.09.2026 |
9.8 |
| CVE-2026-53670 |
PREVAIL: Non-singleton typeset in add() skips offset update, allowing OOB access to pass eBPF verification |
02.09.2026 |
9.3 |
| CVE-2026-53671 |
PREVAIL: Context-write no-op in do_mem_store allows unsafe eBPF programs to pass verification |
05.09.2026 |
9.3 |
| CVE-2026-66786 |
Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets |
05.09.2026 |
9.1 |
| CVE-2026-53649 |
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE |
04.09.2026 |
9.6 |
| CVE-2026-20212 |
Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability |
03.09.2026 |
9.8 |
| CVE-2026-20274 |
Cisco IOS XR Software Security Hardening Release: September 2026 |
04.09.2026 |
9.8 |
| CVE-2026-20279 |
Cisco IOS XR Software Security Hardening Release: September 2026 |
04.09.2026 |
9.8 |
| CVE-2026-53611 |
Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation |
02.09.2026 |
9.8 |
| CVE-2026-78689 |
NGINX ngx_http_js_module vulnerablility |
03.09.2026 |
9.2 |
| CVE-2026-82955 |
|
02.09.2026 |
9 |
| CVE-2025-9314 |
Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload |
02.09.2026 |
9.8 |
| CVE-2026-4357 |
Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload |
02.09.2026 |
10 |
| CVE-2026-77009 |
WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console |
02.09.2026 |
9.9 |
| CVE-2026-81294 |
WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability |
02.09.2026 |
9.8 |
| CVE-2026-81286 |
WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability |
04.09.2026 |
9.3 |
| CVE-2026-84795 |
Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance |
02.09.2026 |
9.2 |
| CVE-2026-78657 |
SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field |
02.09.2026 |
9.8 |
| CVE-2026-9055 |
Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' |
02.09.2026 |
9.8 |
| CVE-2026-84695 |
BookStack before 26.05.4 Stored XSS via Drawing Upload |
02.09.2026 |
9.3 |
| CVE-2026-84696 |
Phison PS3111-S11 Controller Firmware Missing Authentication on Vendor Unique Commands |
02.09.2026 |
9.3 |
| CVE-2026-84699 |
Team Password Manager before 14.184.308 Authentication Bypass in Password Reset |
02.09.2026 |
9.3 |
| CVE-2026-84479 |
WWBN AVideo Authentication Bypass via User-Agent Header |
02.09.2026 |
9.3 |
| CVE-2026-84480 |
WWBN AVideo Password Recovery Token Expiration Bypass |
02.09.2026 |
9.3 |
| CVE-2023-54391 |
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter |
03.09.2026 |
9.3 |
| CVE-2026-75604 |
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers |
04.09.2026 |
9 |
| CVE-2026-84372 |
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections |
02.09.2026 |
9.8 |
| CVE-2026-73749 |
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX |
03.09.2026 |
9.8 |
| CVE-2026-76657 |
Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access |
01.09.2026 |
10 |
| CVE-2026-76658 |
Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon |
01.09.2026 |
10 |
| CVE-2026-19766 |
Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer |
02.09.2026 |
9.6 |
| CVE-2026-73700 |
Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management Interface |
02.09.2026 |
9 |
| CVE-2026-73701 |
Unauthenticated Remote Code Execution in HPE Networking Fabric Composer |
02.09.2026 |
9 |
| CVE-2026-79687 |
|
02.09.2026 |
9 |
| CVE-2026-18931 |
Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software |
01.09.2026 |
9.1 |
| CVE-2026-78012 |
Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack |
04.09.2026 |
9.3 |
| CVE-2026-18210 |
SQL Injection in TRtek Technological Products's Store |
01.09.2026 |
9.8 |
| CVE-2026-9621 |
RSLinx Classic® - Multiple Vulnerabilities |
01.09.2026 |
9.2 |
| CVE-2026-18808 |
Unauthenticated Remote Code Execution via Code Injection in Klemsan's KIO |
01.09.2026 |
9.8 |
| CVE-2026-18765 |
SQL Injection in Teracity Sotware's Teracity E-OSB Platform |
01.09.2026 |
9.8 |
| CVE-2026-84149 |
Information Disclosure Vulnerability in Manacle Technologies ERP System |
01.09.2026 |
9.2 |
| CVE-2026-84147 |
Remote Code Execution Vulnerability in Manacle Technologies ERP System |
01.09.2026 |
10 |
| CVE-2026-84148 |
Insecure Direct Object Reference Vulnerability in Manacle Technologies ERP System |
01.09.2026 |
9.2 |
| CVE-2023-54356 |
Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites |
04.09.2026 |
9.3 |
| CVE-2026-84189 |
LibreNMS before 26.7.0 Stored XSS via Oxidized API |
04.09.2026 |
9.2 |
| CVE-2026-84200 |
Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions |
02.09.2026 |
9.4 |
| CVE-2026-18550 |
Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter |
02.09.2026 |
9.8 |
| CVE-2026-4813 |
Code injection in the Lutece Core |
01.09.2026 |
9.4 |
| CVE-2026-78319 |
TOCTOU Vulnerability in file exchange |
01.09.2026 |
9.3 |
| CVE-2026-83772 |
Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection |
01.09.2026 |
9.4 |
| CVE-2026-67394 |
|
01.09.2026 |
9 |
| CVE-2026-75865 |
WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint |
01.09.2026 |
9.8 |
| CVE-2026-83524 |
RedPort Optimizer wXa-223 System Clock datetime.php exec command injection |
01.09.2026 |
9.4 |
| CVE-2026-82971 |
QVidium Opera11 CGI Script net_tr.cgi command injection |
01.09.2026 |
10 |
| CVE-2026-82954 |
Dokploy Settings application.ts writeTraefikConfigInPath path traversal |
02.09.2026 |
9.4 |
| CVE-2026-81779 |
WordPress Newspapers X theme 1.0.46-1.0.48 - Backdoor vulnerability |
01.09.2026 |
10 |
| CVE-2026-81293 |
WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability |
01.09.2026 |
9.3 |
| CVE-2026-81756 |
WordPress Smart Marketing SMS and Newsletters Forms plugin <= 5.1.24 - SQL Injection vulnerability |
02.09.2026 |
9.3 |
| CVE-2026-81763 |
WordPress Throws SPAM Away plugin <= 3.8.2 - SQL Injection vulnerability |
01.09.2026 |
9.3 |
| CVE-2026-81780 |
WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability |
01.09.2026 |
10 |
| CVE-2026-82226 |
WordPress Tickera plugin <= 3.6.0.2 - PHP Object Injection vulnerability |
01.09.2026 |
9.8 |
| CVE-2026-82908 |
MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow |
01.09.2026 |
9.3 |
| CVE-2026-53552 |
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers |
01.09.2026 |
9.6 |
| CVE-2026-79748 |
MCPHub: Authenticated non-admin user achieves RCE via POST /api/servers (missing authorization on stdio command/args) |
31.08.2026 |
9.9 |
| CVE-2026-82807 |
ieungSoft Ultra RAMDisk Pro Kernel Driver URDSCSI.sys privileges management |
01.09.2026 |
9.3 |
| CVE-2026-73819 |
Ebyte NA111-M Weak Authentication |
01.09.2026 |
9.3 |
| CVE-2026-76133 |
Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm |
01.09.2026 |
9.3 |
| CVE-2026-66047 |
ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE |
02.09.2026 |
9.2 |
| CVE-2026-82970 |
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability |
31.08.2026 |
10 |
| CVE-2026-59111 |
Command Injection vulnerability in eObčanka-Identifikace |
31.08.2026 |
9.3 |
| CVE-2026-82694 |
Tenda AC1206 Web UI ate R7WebsSecurityHandler missing authentication |
31.08.2026 |
10 |
| CVE-2026-82695 |
Tenda AC18 Telnet telnet missing authentication |
31.08.2026 |
10 |
| CVE-2026-82692 |
D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82693 |
Tenda AC1206 Web UI telnet TendaTelnet missing authentication |
31.08.2026 |
10 |
| CVE-2026-82691 |
D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection |
02.09.2026 |
9.4 |
| CVE-2026-82690 |
D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82689 |
D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection |
31.08.2026 |
9.4 |
| CVE-2026-82688 |
D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection |
01.09.2026 |
9.4 |
| CVE-2026-82876 |
Phison PS3111-S11 Controller Firmware Signature Verification Bypass |
02.09.2026 |
9.3 |
| CVE-2026-49003 |
Unauthenticated RCE Vulnerability in ZTE ZXDU68 S202 V5.0 Product |
31.08.2026 |
9.6 |
| CVE-2026-82854 |
Nodemailer before 8.0.3 SMTP Command Injection via envelope.size |
31.08.2026 |
9.3 |
| CVE-2026-82855 |
@hulumi/policies before 1.3.2 Evidence Validation Bypass |
31.08.2026 |
9.3 |
| CVE-2026-82856 |
@hulumi/policies before 1.3.2 OIDC Trust Policy Bypass |
02.09.2026 |
9.3 |
| CVE-2026-82857 |
hulumi before v1.3.2 Privilege Escalation via IAM Policy |
01.09.2026 |
9.3 |
| CVE-2026-82858 |
@hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance |
31.08.2026 |
9.3 |
| CVE-2026-82859 |
hulumi before v1.3.2 SCP Template Tag-on-Create Bypass |
31.08.2026 |
9.3 |
| CVE-2026-82860 |
@hulumi/policies before 1.3.2 Admin Policy Bypass |
31.08.2026 |
9.3 |
| CVE-2026-19410 |
Google Cloud Build Comment Control Bypass via Webhook Suppression |
31.08.2026 |
9.4 |
| CVE-2026-82628 |
Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management |
31.08.2026 |
9.3 |
| CVE-2026-58574 |
|
31.08.2026 |
9.8 |
| CVE-2026-82616 |
TOTOLINK NR1800X cstecgi.cgi setUploadSetting stack-based overflow |
01.09.2026 |
9.4 |
| CVE-2026-82593 |
D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow |
01.09.2026 |
9.4 |
| CVE-2026-82592 |
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow |
31.08.2026 |
9.4 |
| CVE-2026-82645 |
AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token |
31.08.2026 |
9.2 |
| CVE-2026-82653 |
SiYuan before v3.8.1 Stored XSS via confirmDialog |
02.09.2026 |
9.3 |
| CVE-2026-82654 |
SiYuan before v3.8.1 Stored XSS via block name |
01.09.2026 |
9.3 |
| CVE-2026-82542 |
Tenda HG10 Boa Web Server formIPv6Routing buffer overflow |
01.09.2026 |
10 |
| CVE-2026-82539 |
TOTOLINK A720R MAC Filtering cstecgi.cgi setMacFilterRules memory corruption |
01.09.2026 |
9.4 |