CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 25.09.2026 9.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 25.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 25.09.2026 9.1
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 25.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 25.09.2026 9.3
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026 9.3
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 25.09.2026 9.1
CVE-2026-81630 Botslab G980H Dashcams Insufficient Verification of Data Authenticity 24.09.2026 9.2
CVE-2026-93289 OS command injection in Eufy Omni C20, Omni X10 Pro 24.09.2026 9
CVE-2026-93291 Improper certificate validation in Eufy Omni C20 24.09.2026 9.3
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13249 Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040 24.09.2026 9.8
CVE-2026-61741 http4s-scala-xml has an XML External Entity (XXE) processing issue 24.09.2026 9.3
CVE-2026-61604 ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass 24.09.2026 9.3
CVE-2026-61732 Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context 24.09.2026 10
CVE-2026-61742 DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution 24.09.2026 9.3
CVE-2026-79766 Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email 24.09.2026 9.1
CVE-2026-97413 RDMA/rtrs-srv: Fix integer underflow in process_read and process_write 25.09.2026 9.8
CVE-2026-93425 Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root 24.09.2026 9.9
CVE-2026-93228 svcrdma: Reject Write/Reply chunks with segcount 0 25.09.2026 9.1
CVE-2026-93207 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry 25.09.2026 9.8
CVE-2026-81549 DataStage on Cloud Pak for Data has several vulnerabilities 24.09.2026 9.6
CVE-2026-90481 24.09.2026 9.2
CVE-2026-97404 24.09.2026 9.2
CVE-2026-97359 HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection 24.09.2026 10
CVE-2026-97360 HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine 24.09.2026 10
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy 24.09.2026 9.3
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal 25.09.2026 9.9
CVE-2026-12227 Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter 24.09.2026 9.8
CVE-2026-78312 Path Traversal in DIAEnergie 24.09.2026 9.1
CVE-2026-78308 Authentication Bypass in DIAEnergie 24.09.2026 9.8
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write 24.09.2026 9.3
CVE-2026-97055 SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret 24.09.2026 9.2
CVE-2026-18467 Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter 24.09.2026 9.8
CVE-2026-89078 Double Free in GitLab 25.09.2026 9.9
CVE-2026-93577 Integer Overflow or Wraparound in GitLab 25.09.2026 9.9
CVE-2026-93352 Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload 24.09.2026 9.3
CVE-2026-6928 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67231 RabbitMQ: Trust-store whitelist by Issuer+Serial only 23.09.2026 9.1
CVE-2026-6721 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-6730 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch 23.09.2026 9.2
CVE-2026-87898 23.09.2026 9.4
CVE-2026-87899 24.09.2026 9.4
CVE-2026-87900 23.09.2026 9.4
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups 24.09.2026 9.1
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) 24.09.2026 9.9
CVE-2026-77602 OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites) 23.09.2026 9.9
CVE-2026-96770 s2s-proxy accepts untrusted client certificates 23.09.2026 9.3
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match 24.09.2026 9.9
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod 24.09.2026 9.9
CVE-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack 23.09.2026 9.2
CVE-2026-95601 WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability 23.09.2026 9.3
CVE-2026-85724 Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass 24.09.2026 9.6
CVE-2026-95848 Moquette fails open when configured authentication or authorization classes cannot load 23.09.2026 9.3
CVE-2026-96754 orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path 23.09.2026 9.3
CVE-2026-96755 orval @orval/effect 8.14.0 through 8.28.1 Code Injection 23.09.2026 9.3
CVE-2026-96756 orval before 8.30.0 Code Injection via Factory Generation 23.09.2026 9.2
CVE-2026-96757 orval before 8.29.0 Code Injection via unescaped OpenAPI media-type 23.09.2026 9.3
CVE-2026-96758 orval @orval/core before 8.28.0 Code Injection via Form-Data 23.09.2026 9.3
CVE-2026-96759 orval before 8.29.0 Code Injection via operationId 23.09.2026 9.3
CVE-2026-18872 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.3
CVE-2026-59167 SunEditor: Critical XSS vulnerability - sanitizer bypass 24.09.2026 10
CVE-2026-96560 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel 24.09.2026 9.3
CVE-2026-86708 Sensitive data exposure 24.09.2026 10
CVE-2026-19599 Remote Code Execution vulnerability 24.09.2026 9.9
CVE-2026-96257 Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow 23.09.2026 10
CVE-2026-18162 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18163 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18169 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.9
CVE-2026-19202 Token Cache Reuse in mcp-toolbox-sdk-python 23.09.2026 9.1
CVE-2026-17645 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1
CVE-2026-16346 DataStage on Cloud Pak for Data has several vulnerabilities 23.09.2026 9.9
CVE-2026-17472 Multiple Vulnerabilities in IBM Concert Software 24.09.2026 9.6
CVE-2026-17635 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1
CVE-2026-77987 GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery 23.09.2026 9.3
CVE-2026-87121 Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application 22.09.2026 9.3
CVE-2026-28324 SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability 22.09.2026 9.8
CVE-2026-47116 LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH 23.09.2026 9.2
CVE-2026-76708 Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE) 23.09.2026 9.8
CVE-2026-76709 Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE) 23.09.2026 9.8
CVE-2026-57149 plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection 22.09.2026 9.9
CVE-2026-91130 Home Assistant: XSS in Statistics Graph Card 22.09.2026 9.3
CVE-2026-75682 Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 23.09.2026 9.9
CVE-2026-75684 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 22.09.2026 9.3
CVE-2026-75686 Adobe Connect | Improper Input Validation (CWE-20) 23.09.2026 9.3
CVE-2026-75689 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 22.09.2026 9.3
CVE-2026-75697 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 22.09.2026 9.3
CVE-2026-75698 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) 23.09.2026 9.3
CVE-2026-75745 Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863) 22.09.2026 10
CVE-2026-81995 Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20) 23.09.2026 9.1
CVE-2026-82000 Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918) 23.09.2026 9.6
CVE-2026-77254 MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials 22.09.2026 9.1
CVE-2026-43641 Softaculous Virtualizor OS Command Injection via Billing Module Handler 23.09.2026 9.3
CVE-2026-43642 Softaculous Virtualizor PHP Object Injection via Billing Module Handler 22.09.2026 9.2
CVE-2026-18461 Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. 22.09.2026 9.2
CVE-2026-77244 [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token 23.09.2026 10
CVE-2026-7866 Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. 23.09.2026 9.3
CVE-2026-73369 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 23.09.2026 10
CVE-2026-75699 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-75703 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-75721 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-75723 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 22.09.2026 10
CVE-2026-75728 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 23.09.2026 9.1
CVE-2026-82008 Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20) 22.09.2026 9.9
CVE-2026-82009 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 22.09.2026 9.1
CVE-2026-82010 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 22.09.2026 9.9
CVE-2026-82011 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 23.09.2026 9.1
CVE-2026-82013 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 22.09.2026 9.9
CVE-2026-82443 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 22.09.2026 9.6
CVE-2026-83660 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 22.09.2026 9.9
CVE-2026-84412 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-89275 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 23.09.2026 10
CVE-2026-89276 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 9.9
CVE-2026-85734 LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks 22.09.2026 9.1
CVE-2026-86059 Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one 22.09.2026 9.6
CVE-2026-94456 Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys 22.09.2026 9.1
CVE-2026-63374 AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing 22.09.2026 9.3
CVE-2026-77621 Vector: Arbitrary file write in the file sink via templated path (path traversal). 22.09.2026 9.3
CVE-2026-80143 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read 24.09.2026 9.4
CVE-2026-80144 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write 24.09.2026 9.4
CVE-2026-80145 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password 24.09.2026 9.4
CVE-2026-80146 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read 24.09.2026 9.4
CVE-2026-80147 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write 24.09.2026 9.4
CVE-2026-80151 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download 24.09.2026 9.4
CVE-2026-80152 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule 24.09.2026 9.4
CVE-2026-80155 Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation 24.09.2026 10
CVE-2026-80156 Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass 24.09.2026 9.4
CVE-2026-95654 Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token 22.09.2026 9.1
CVE-2026-65113 22.09.2026 9.8
CVE-2026-84388 22.09.2026 9.1
CVE-2026-94127 BIG-IP APM OAuth vulnerability 23.09.2026 9.3
CVE-2026-12718 SQLi in Karel Electronics' KarelIPS 22.09.2026 9.8
CVE-2026-95675 D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface 22.09.2026 9.3
CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server 23.09.2026 9.8
CVE-2026-74849 Remote code execution vulnerability 23.09.2026 9.8
CVE-2026-25254 Improper authorization in Qualcomm Software Center 22.09.2026 9.8
CVE-2026-93556 Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini 22.09.2026 9.3
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension 22.09.2026 9.3
CVE-2026-93952 Security Advisory 0183 23.09.2026 9.5
CVE-2026-13355 Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter 22.09.2026 9.8
CVE-2026-19658 Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter 22.09.2026 9.8
CVE-2026-94493 Gigatech PDV5701 WebSocket Service index.html missing authentication 24.09.2026 10
CVE-2026-94425 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management 22.09.2026 9.3
CVE-2026-46649 Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint 21.09.2026 9.1
CVE-2026-77521 MaxKB: Prompt-injectable agent can lead to command execution 22.09.2026 10
CVE-2026-94424 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow 22.09.2026 9.3
CVE-2026-79916 MaxKB AWS Bedrock model credential injection leads to remote code execution 22.09.2026 9.1
CVE-2026-94571 22.09.2026 9.4
CVE-2026-94572 24.09.2026 9.4
CVE-2026-58491 Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter 22.09.2026 9.3
CVE-2026-94403 ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference 22.09.2026 9.3
CVE-2026-79920 Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task 21.09.2026 9.9
CVE-2026-61674 Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handler 21.09.2026 9.2
CVE-2026-85751 Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust 21.09.2026 9.8
CVE-2026-94301 Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 22.09.2026 9.8
CVE-2025-12999 22.09.2026 9.1
CVE-2026-94146 BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where 22.09.2026 9.3
CVE-2026-94142 BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94128 BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94129 BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94101 Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow 21.09.2026 9.4
CVE-2026-94098 Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection 21.09.2026 9.4
CVE-2026-94099 Netcore NBR200V2 Backup Restore restore.cgi command injection 22.09.2026 9.4
CVE-2026-94100 Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow 21.09.2026 9.4
CVE-2026-94097 Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection 24.09.2026 10
CVE-2026-94096 Netcore NBR200V2 LAN IP Configuration network_tools command injection 21.09.2026 9.4
CVE-2026-94095 Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection 21.09.2026 9.4
CVE-2026-94089 D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow 22.09.2026 10
CVE-2026-88857 Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 22.09.2026 9.4
CVE-2026-88854 Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 22.09.2026 9.3
CVE-2026-88856 Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 22.09.2026 9.4
CVE-2026-90817 21.09.2026 9.8
CVE-2026-94003 Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based overflow 24.09.2026 10
CVE-2026-94107 NivoCart through 2.4.0 Predictable Administrator Password Reset Token 21.09.2026 9.2
CVE-2026-93958 D-Link R95 DHMAPI ssi system os command injection 21.09.2026 9.4
CVE-2026-94083 22.09.2026 9.4
CVE-2026-94084 22.09.2026 9.4
CVE-2026-93985 OpenPanel js-runtime JavaScript Template Sandbox Escape RCE 21.09.2026 9.4
CVE-2026-93742 Totolink A3002MU formWsc command injection 21.09.2026 9.4
CVE-2026-93741 Totolink A3002MU formWlWds buffer overflow 22.09.2026 10
CVE-2026-84434 Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field 19.09.2026 9.8
CVE-2026-89274 WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content 19.09.2026 9.1
CVE-2026-92229 Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter 19.09.2026 9.1
CVE-2026-75885 Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint 21.09.2026 9.3
CVE-2026-93740 Totolink A3002MU formWlEncrypt buffer overflow 21.09.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-67236 RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST /login 25.09.2026
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 25.09.2026 9.1
CVE-2026-42324 Piwigo: Second-Order SQL Injection 25.09.2026 7.2
CVE-2026-44642 Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+) 25.09.2026 8.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 25.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 25.09.2026 9.1
CVE-2026-100230 25.09.2026 5.3
CVE-2026-33639 InvoicePlane permits DDL injection through tax_rate_decimal_places 25.09.2026 7.2
CVE-2026-42323 Piwigo: SQL Injection in Batch Manager 25.09.2026 7.2
CVE-2026-49850 InvoicePlane: Missing CSRF Protection on State-Changing delete Actions 25.09.2026 7.5
CVE-2026-50547 InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier 25.09.2026 7.5
CVE-2026-97469 PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink 25.09.2026 4.3
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-39372 InvoicePlane: Sensitive Information Disclosure via Unstripped EXIF Metadata in Attachments 25.09.2026 4.9
CVE-2026-54790 InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module 25.09.2026 6
CVE-2026-85274 InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection 25.09.2026 6.5
CVE-2026-85289 InvoicePlane: Missing CSRF Token Validation on Multiple Delete Endpoints 25.09.2026 6.5
CVE-2026-85290 InvoicePlane: Log Injection via Unsanitized User Input in Cron Key Error Logging 25.09.2026 5.3
CVE-2026-85291 InvoicePlane IDOR: Horizontal Privilege Escalation via Password Change Without Authorization Check 25.09.2026 6.5
CVE-2026-85292 InvoicePlane: Loose Type Comparison in Core Authentication Check (Defense-in-Depth) 25.09.2026 4.8
CVE-2026-85293 InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms 25.09.2026 4.8
CVE-2026-96874 Stored XSS in Cargo Drilldown tab names 25.09.2026
CVE-2026-97868 sheshbabu zen Note Editor NotesEditor.jsx dangerouslySetInnerHTML cross site scripting 25.09.2026
CVE-2026-97869 langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserialization 25.09.2026
CVE-2026-96812 Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE 25.09.2026
CVE-2026-97866 Zhonglun CloudPOS Automatic Update Program.cs channel accessible 25.09.2026
CVE-2026-60096 25.09.2026
CVE-2026-60097 25.09.2026
CVE-2026-60098 25.09.2026
CVE-2026-60099 25.09.2026
CVE-2026-60100 25.09.2026
CVE-2026-60101 25.09.2026
CVE-2026-93030 25.09.2026 6.5
CVE-2026-84862 IBM Guardium Data Protection is affected by multiple vulnerabilities. 25.09.2026 7.2
CVE-2026-84882 IBM Guardium Data Protection is affected by multiple vulnerabilities. 25.09.2026 7.5
CVE-2026-88389 25.09.2026
CVE-2026-93306 This Power System update is being released to address 25.09.2026 7.1
CVE-2026-84884 IBM Guardium Data Protection is affected by multiple vulnerabilities. 25.09.2026 7.5
CVE-2026-84893 IBM Guardium Data Protection is affected by multiple vulnerabilities. 25.09.2026 7.6
CVE-2026-85029 IBM Guardium Data Protection is affected by multiple vulnerabilities. 25.09.2026 7.5
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 25.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 25.09.2026 9.3
CVE-2026-100190 Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page 25.09.2026
CVE-2026-85542 IBM Guardium Data Protection is affected by multiple vulnerabilities. 25.09.2026 8.8
CVE-2026-85750 Piwigo arbitrary file read and remote code execution via insecure image processing 25.09.2026 7.2
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-97222 Gnumeric: gnumeric: heap use-after-free when opening a malformed workbook 25.09.2026
CVE-2026-100177 Ail Framework Crawler: Missing Cookiejar Authorization Check Allows Cross-Organization Cookiejar Attachment 25.09.2026
CVE-2026-100187 AIL Framework Onion Module: Non-Onion URL Accepted as Crawler Task Due to Bypassed Domain Validation 25.09.2026
CVE-2026-93834 Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape 25.09.2026
CVE-2026-100174 Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names 25.09.2026
CVE-2026-100176 Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip 25.09.2026
CVE-2026-80431 Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process 25.09.2026
CVE-2026-97865 Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization 25.09.2026
CVE-2026-100070 netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet 25.09.2026
CVE-2026-100071 net: hsr: free learned nodes on device setup failure 25.09.2026
CVE-2026-100072 ACPI: platform: Use acpi_bus_get_primary_device() 25.09.2026
CVE-2026-100073 ext4: fix transaction overflow during writeback 25.09.2026
CVE-2026-100074 bpf: Mark bpf_refcount field as unique 25.09.2026
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-100076 staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths 25.09.2026
CVE-2026-100077 drm/msm: Recover HW before retire hung submit 25.09.2026
CVE-2026-100078 wifi: iwlwifi: mei: pass correct argument to function 25.09.2026
CVE-2026-100079 usb: typec: ucsi: unregister debugfs entries on teardown 25.09.2026
CVE-2026-100172 Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attributes 25.09.2026
CVE-2026-80430 Improper link resolution in the kitty drag and drop protocol allows a client to create files outside the staging directory 25.09.2026
CVE-2026-97864 GibbonEdu Gibbon Unit Planner units_add_blockAjax.php makeBlock missing authentication 25.09.2026
CVE-2026-98160 staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() 25.09.2026
CVE-2026-98161 nvdimm: pmem: keep PREFLUSH before data writes 25.09.2026
CVE-2026-98162 smb/server: fix tree connection leak in smb2_tree_connect() 25.09.2026
CVE-2025-51457 25.09.2026
CVE-2026-79153 25.09.2026
CVE-2026-88421 25.09.2026
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026
CVE-2026-51772 25.09.2026
CVE-2026-51773 25.09.2026
CVE-2026-52622 25.09.2026 7.5
CVE-2026-78902 25.09.2026
CVE-2026-88420 25.09.2026
CVE-2026-97622 25.09.2026
CVE-2026-97875 DNS rebinding vulnerability in rojo serve HTTP API 25.09.2026 8.1
CVE-2026-98101 ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() 25.09.2026
CVE-2026-98102 ipv6: mcast: fix RCU list diversion in ip6_mc_del1_src() 25.09.2026
CVE-2026-98103 igmp: convert struct ip_sf_list to RCU 25.09.2026
CVE-2026-98104 net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted 25.09.2026
CVE-2026-98105 net: ethernet: oa_tc6: Improve the error recovery 25.09.2026
CVE-2026-98106 drm/pagemap: Prevent double migration of device pages 25.09.2026
CVE-2026-98107 Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect 25.09.2026
CVE-2026-98108 Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan 25.09.2026 7.5
CVE-2026-98109 Bluetooth: hci_core: Fix race condition during device registration 25.09.2026
CVE-2026-98110 Bluetooth: btintel: bound firmware ID by TLV length 25.09.2026
CVE-2026-98111 Bluetooth: btintel: validate version TLV value lengths 25.09.2026
CVE-2026-98112 ksmbd: fix listener task lifetime on netdev events 25.09.2026 7.8
CVE-2026-98113 ksmbd: rate limit unmapped SID errors 25.09.2026
CVE-2026-98114 ksmbd: propagate DACL parsing errors 25.09.2026
CVE-2026-98115 ksmbd: safely drain sessions during logoff 25.09.2026 8.8
CVE-2026-98116 ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF 25.09.2026 7.8
CVE-2026-98117 cachefiles: Fix potential UAF/KASAN warning 25.09.2026
CVE-2026-98118 netfs: Fix readahead synchronisation issues by loading all folios upfront 25.09.2026
CVE-2026-98119 netfs: break unbuffered write when netfs_alloc_subrequest() fails 25.09.2026
CVE-2026-98120 netfs: Fix subreq ref leak 25.09.2026
CVE-2026-98121 watchdog: msc313e: Fix NULL pointer dereference in PM callbacks 25.09.2026
CVE-2026-98122 vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() 25.09.2026 7.8
CVE-2026-98123 sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration 25.09.2026
CVE-2026-98124 smb/client: invalidate fscache for fallocate range operations 25.09.2026
CVE-2026-98125 smb/client: fix stale page cache in insert/collapse range 25.09.2026
CVE-2026-98126 smb/client: validate new EOF for zero range 25.09.2026
CVE-2026-98127 smb/client: validate new EOF for insert range 25.09.2026
CVE-2026-98128 scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() 25.09.2026
CVE-2026-98129 scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() 25.09.2026
CVE-2026-98130 sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START 25.09.2026 8.1
CVE-2026-98131 net: stmmac: fix dma mapping leak in stmmac_tso_xmit() 25.09.2026
CVE-2026-98132 bpf: don't downgrade half-dead scalar zero spills to STACK_ZERO 25.09.2026
CVE-2026-98133 ntfs: leave HasEA flag untouched on setxattr failure 25.09.2026
CVE-2026-98134 bpf: check_cond_jmp_op(): properly infer if register is null 25.09.2026
CVE-2026-98135 ntfs: reject invalid sectors_per_cluster in the boot sector 25.09.2026
CVE-2026-98136 ntfs: bound $AttrDef table walk to the loaded table size 25.09.2026
CVE-2026-98137 ntfs: treat any nonzero dio zero-range return as an error 25.09.2026
CVE-2026-98138 ntfs: do not mark the volume clean in sync_fs when errors were recorded 25.09.2026
CVE-2026-98139 ntfs: only count successfully cleared runs when freeing clusters 25.09.2026
CVE-2026-98140 ntfs: fix kmap_local leak in write_mft_record_nolock() error paths 25.09.2026
CVE-2026-98141 ntfs: propagate reparse index insertion failure 25.09.2026
CVE-2026-98142 drm/cirrus-qemu: Validate BAR0 size during probe 25.09.2026
CVE-2026-98143 accel: ethosu: Don't read the U65 rounding mode as a storage mode 25.09.2026 7.8
CVE-2026-98144 accel/amdxdna: put the chained BO when its mapping fails 25.09.2026
CVE-2026-98145 accel/amdxdna: reject a command chain that carries no commands 25.09.2026
CVE-2026-98146 accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain 25.09.2026
CVE-2026-98147 printk: Don't WARN on kthread_run failure. 25.09.2026
CVE-2026-98148 drm/gud: validate GUD_ROTATION_0 is present in supported rotations 25.09.2026
CVE-2026-98149 bpf: Fix percpu map update indexing with sparse CPU IDs 25.09.2026
CVE-2026-98150 bpf: Fix BPF_F_CPU validation for sparse CPU IDs 25.09.2026 7
CVE-2026-98151 bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic 25.09.2026
CVE-2026-98152 nvmet-rdma: fix queue leak when connect backlog is exceeded 25.09.2026
CVE-2026-98153 nvme: fix racy access to FDP placement id array 25.09.2026
CVE-2026-98154 nvme-rdma: fix -EIO cleanup order in queue_rq 25.09.2026 7
CVE-2026-98155 accel/qaic: Address potential out-of-bounds read in resp_worker() 25.09.2026
CVE-2026-98156 drm/virtio: use the DMA API for resource backing on Xen 25.09.2026 7.8
CVE-2026-98157 EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation 25.09.2026
CVE-2026-98158 ppp_async: drop the errored frame instead of resetting its headroom 25.09.2026
CVE-2026-98159 wifi: mt76: mt7921: validate CLC firmware records 25.09.2026
CVE-2026-27867 CROSS-SITE SCRIPTING (XSS) VIA THE CMDCOOKIE PARAMETER REGESTA SMART HD-PLC OF TELDAT 25.09.2026
CVE-2026-97228 Rapid7 Bulk Export MCP — GraphQL Query Injection in Export Status Lookup 25.09.2026 2.7
CVE-2026-97522 mptcp: fix bad accounting in __mptcp_subflow_push_pending() 25.09.2026
CVE-2026-97523 mptcp: close race between scheduler and state change 25.09.2026 7.5
CVE-2026-97524 mptcp: avoid unneeded actions on subflow reset 25.09.2026 7.5
CVE-2026-97525 x86/mm/pat: Allocate split page tables as kernel page tables 25.09.2026 8.2
CVE-2026-97526 s390/pai: Support CPU hotplug for PMU PAI 25.09.2026
CVE-2026-97527 scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock 25.09.2026 8.8
CVE-2026-97528 scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error 25.09.2026 8.8
CVE-2026-97529 scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] 25.09.2026
CVE-2026-97530 scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature 25.09.2026
CVE-2026-97531 scsi: qla2xxx: Skip vport under deletion in report ID acquisition 25.09.2026 7.5
CVE-2026-97532 scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path 25.09.2026
CVE-2026-97533 x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF 25.09.2026
CVE-2026-97534 f2fs: accurately adjust free_sections during free_segment_range 25.09.2026
CVE-2026-97535 scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size 25.09.2026
CVE-2026-97536 scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown 25.09.2026 7.5
CVE-2026-97537 scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking 25.09.2026
CVE-2026-97538 hwmon: (asus_rog_ryujin) Validate HID report lengths 25.09.2026
CVE-2026-97539 usb: xusbatm: don't rely on id table pointer arithmetic 25.09.2026
CVE-2026-97540 net: usb: pegasus: don't rely on id table pointer arithmetic 25.09.2026
CVE-2026-97541 wifi: ath9k_htc: don't store usb_device_id 25.09.2026
CVE-2026-97542 xfs: bail out on bitmap errors in xrep_agfl_fill 25.09.2026
CVE-2026-97543 xfs: destroy seen inode bitmap when we fail to add a dirpath 25.09.2026
CVE-2026-97544 xfs: don't leak dqacct if rhashtable insertion fails 25.09.2026
CVE-2026-97545 xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails 25.09.2026
CVE-2026-97546 xfs: don't spin forever on zero-length dirents when salvaging them 25.09.2026
CVE-2026-97547 xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN 25.09.2026
CVE-2026-97548 xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions 25.09.2026 7.8
CVE-2026-97549 xfs: fix under-reservation of blocks when repairing sf directories 25.09.2026
CVE-2026-97550 xfs: fix unit conversions in per_binval computation 25.09.2026
CVE-2026-97551 xfs: initialise args->total for parent pointer updates 25.09.2026
CVE-2026-97552 xfs: initialise error in xfs_defer_finish_one() 25.09.2026
CVE-2026-97553 xfs: lock the healthmon when inserting unmount event 25.09.2026
CVE-2026-97554 smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() 25.09.2026
CVE-2026-97555 smb: client: fix heap overflow in DACL owner/group rewrite 25.09.2026 8.8
CVE-2026-97556 smb: client: avoid leaking refcount when cifs_sb_tlink() fails 25.09.2026
CVE-2026-97557 smb: client: avoid leaking refcount in cifs_queue_oplock_break() 25.09.2026 7.5
CVE-2026-97558 smb: client: fix cifsFileInfo reference leak in deferred close 25.09.2026
CVE-2026-97559 smb: client: fail DACL rewrite when the new DACL exceeds 64K 25.09.2026
CVE-2026-97560 smb: client: fix one-byte OOB read in smb2_parse_native_symlink() 25.09.2026
CVE-2026-97561 smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid 25.09.2026
CVE-2026-97562 smb: client: pin DFS superblock in iterator callback 25.09.2026 7.5
CVE-2026-97563 smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() 25.09.2026
CVE-2026-97564 smb: client: reject userspace cifs.idmap descriptions 25.09.2026
CVE-2026-97565 smb: client: reject short READ responses in CIFSSMBRead() 25.09.2026
CVE-2026-97566 mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0 25.09.2026
CVE-2026-97567 mptcp: prevent race between disconnect() and rtx 25.09.2026
CVE-2026-97568 mptcp: syncookies: remember the request backup flag 25.09.2026
CVE-2026-97569 bnxt_en: Prevent queue stop with deferred completions 25.09.2026
CVE-2026-97570 bnxt_en: Bound SW TPA IDs to prevent crashes 25.09.2026 8.1
CVE-2026-97571 bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc() 25.09.2026
CVE-2026-97572 bnxt_en: Propagate RX ring init failures in bnxt_init_nic() 25.09.2026
CVE-2026-97573 bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() 25.09.2026 8.1
CVE-2026-97574 bnxt_en: Don't free the live ring's TPA state on queue restart failure 25.09.2026
CVE-2026-97575 media: v4l2-ctrls: validate AV1 tile counts 25.09.2026 7.8
CVE-2026-97576 media: v4l2-ctrls: validate HEVC tile counts 25.09.2026 7.8
CVE-2026-97577 media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity 25.09.2026 7.8
CVE-2026-97578 media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer 25.09.2026 7.8
CVE-2026-97579 media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity 25.09.2026 7.8
CVE-2026-97580 media: rkvdec: bound HEVC tile loops and PPS id to the array capacity 25.09.2026 7.8
CVE-2026-97581 media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity 25.09.2026
CVE-2026-97582 hwmon: (gpio-fan) Fix use-after-free in alarm work 25.09.2026
CVE-2026-97583 afs: Clear stale peer app data after address list changes 25.09.2026 7.5
CVE-2026-97584 afs: Fix incorrect free in candidate cleanup in afs_lookup_server() 25.09.2026 7.8
CVE-2026-97585 afs: Fix double-unmap of directory block 25.09.2026
CVE-2026-97586 afs: Fix missing kunmap in afs_dir_search_bucket() 25.09.2026
CVE-2026-97587 perf: RISC-V: store available counter mask as bitmap 25.09.2026
CVE-2026-97588 s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly 25.09.2026
CVE-2026-97589 s390/crypto: Fix wrong return code to engine in asynch callbacks 25.09.2026 7
CVE-2026-97590 s390/crypto: Fix missing scrub of temp buffers with PAES algorithm 25.09.2026
CVE-2026-97591 s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine 25.09.2026
CVE-2026-97592 s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm 25.09.2026
CVE-2026-97593 iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX 25.09.2026
CVE-2026-97594 landlock: Fix use-after-free of the source's parent directory 25.09.2026 7.8
CVE-2026-97595 mac802154: fix use-after-free of sdata via queued RX frames 25.09.2026 7.5
CVE-2026-97596 ipvs: reject invalid states in connection template sync records 25.09.2026
CVE-2026-97597 ipv6: flowlabel: cap duplicate leases per socket 25.09.2026
CVE-2026-97598 ipv4: fib: bound automatic table ID allocation 25.09.2026
CVE-2026-97599 ieee802154: hwsim: serialize pib updates to fix double-free 25.09.2026
CVE-2026-97600 ieee802154: cc2520: fix FIFOP work use-after-free 25.09.2026
CVE-2026-97601 ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink 25.09.2026
CVE-2026-97602 inet: frags: invalidate queues before flushing them 25.09.2026 7.8
CVE-2026-97603 idpf: disable DIM work before freeing q_vectors 25.09.2026
CVE-2026-97604 fbdev: vfb: defer cleanup until the last reference 25.09.2026
CVE-2026-97605 erofs: preserve LZMA decoders on resize failure 25.09.2026
CVE-2026-97606 fs: autofs: fix memory leak in autofs_fill_super() 25.09.2026
CVE-2026-97607 vdpa: ifcvf: Put device on unsupported feature error 25.09.2026
CVE-2026-97608 netfilter: nf_log: unregister loggers before per-net teardown 25.09.2026 7
CVE-2026-97609 netfilter: cttimeout: prevent UAF during module unload 25.09.2026 7
CVE-2026-97610 netfs: Fix uninitialized return value in netfs_unbuffered_write() 25.09.2026
CVE-2026-97611 net: openvswitch: fix use-after-free of the flow table mask array 25.09.2026 7.8
CVE-2026-97612 net: mpls: clear inner_protocol when the last label is popped 25.09.2026 7.8
CVE-2026-97613 net: mana: Reserve extra CQ slot for the fence completion CQE 25.09.2026
CVE-2026-97614 net: dsa: tag_brcm: legacy FCS: request needed tailroom 25.09.2026
CVE-2026-97615 net: bridge: use option bits for CFM/MRP frame handlers 25.09.2026
CVE-2026-97616 net/sched: act_api: release all action references on NEWACTION failure 25.09.2026
CVE-2026-97617 ring-buffer: Check resize_disabled before publishing the new subbuf order 25.09.2026
CVE-2026-97618 io_uring/net: don't overconsume buffers when using MSG_TRUNC 25.09.2026
CVE-2026-97619 io_uring/rw: end write accounting from ->ki_complete 25.09.2026
CVE-2026-97620 drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches 25.09.2026
CVE-2026-97621 drm/rockchip: analogix_dp: fix unchecked bound endpoint name length 25.09.2026
CVE-2026-97899 drm/i915: Fix memory leak in query_perf_config_list() 25.09.2026
CVE-2026-97900 drm/drm_exec: fix up contended obj when num_objects is 0 25.09.2026
CVE-2026-97901 genetlink: pin family module during policy dump 25.09.2026
CVE-2026-97902 fs: don't return -EINVAL for successful nested thaw 25.09.2026
CVE-2026-97903 exit: hold a reference to thread_pid across proc_flush_pid 25.09.2026 7.8
CVE-2026-97904 cpufreq: initialize policy rwsem before sysfs publication 25.09.2026
CVE-2026-97905 cpufreq: zero-initialize policy cpumask before sysfs publication 25.09.2026
CVE-2026-97906 bootconfig: Fix integer overflow in initrd size check 25.09.2026
CVE-2026-97907 Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 25.09.2026
CVE-2026-97908 Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev 25.09.2026
CVE-2026-97909 ASoC: sti: initialize IRQ lock before requesting IRQ 25.09.2026
CVE-2026-97910 ASoC: sprd: validate compress buffer sizes against fixed allocations 25.09.2026 7.8
CVE-2026-97911 accel: ethosu: Ensure SRAM region size matches job 25.09.2026 7.8
CVE-2026-97912 accel: ethosu: Ensure SRAM size is 0 on mapping failure 25.09.2026
CVE-2026-97913 accel: ethosu: Ensure cmd stream ends with a stop op 25.09.2026
CVE-2026-97914 accel: ethosu: Fix ethosu_job_open() return value 25.09.2026
CVE-2026-97915 accel/ivpu: Limit firmware log name prints to field size 25.09.2026
CVE-2026-97916 accel/ivpu: Validate firmware log buffer metadata 25.09.2026
CVE-2026-97917 accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr 25.09.2026
CVE-2026-97918 tracing: Undo the registration when enabling the histogram trigger fails 25.09.2026
CVE-2026-97919 tracing: Take the reference before publishing the named histogram trigger 25.09.2026
CVE-2026-97920 tracing: Keep the entry count when the histogram stats allocation fails 25.09.2026
CVE-2026-97921 tracing: Free histogram the field rejected for a bad modifier 25.09.2026
CVE-2026-97922 tracing: Free histogram var refs regardless of how often they are referenced 25.09.2026
CVE-2026-97923 tracing: Free histogram the var ref when its initialization fails 25.09.2026
CVE-2026-97924 tracing/user_events: Don't destroy fields when event removal fails 25.09.2026
CVE-2026-97925 tick/broadcast: Plug clockevents replacement race 25.09.2026
CVE-2026-97926 ufs: validate cylinder group metadata before caching it 25.09.2026 7
CVE-2026-97927 ufs: create the root dentry after loading cylinder metadata 25.09.2026
CVE-2026-97928 drm/amdgpu: skip the VMID 0 flush for VRAM 25.09.2026
CVE-2026-97929 ALSA: usbusx2y: validate URB actual_length in interrupt callback 25.09.2026
CVE-2026-97930 ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf 25.09.2026
CVE-2026-97931 ALSA: us122l: Prevent write upgrades for read mappings 25.09.2026 7
CVE-2026-97932 tracing: Don't dereference trace_event_file in deferred trigger free 25.09.2026
CVE-2026-97933 tracing: Take trace_array reference when opening a tracer options file 25.09.2026
CVE-2026-97934 tracing: Fix memory corruption from a "STACKTRACE" histogram key 25.09.2026
CVE-2026-97935 tracing: Set the trace clock before registering the histogram trigger 25.09.2026
CVE-2026-97936 tracing: Fix memory corruption from the histogram stacktrace modifier 25.09.2026
CVE-2026-97937 ftrace: fork: Initialize function graph state before copy_exec_state() 25.09.2026 7.8
CVE-2026-97938 reboot: fix cad_pid use-after-free race 25.09.2026
CVE-2026-97939 ipmr: account multicast table and route memory 25.09.2026
CVE-2026-97940 ipv6: fix fib6 walker UAF on seq stop 25.09.2026 7.8
CVE-2026-97941 mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race 25.09.2026 7.8
CVE-2026-97942 x86/alternatives: Exclude text poking against change_page_attr() 25.09.2026
CVE-2026-97943 x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF 25.09.2026
CVE-2026-97944 x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash() 25.09.2026
CVE-2026-97945 x86/mm: Fix user-space data loss with MADV_FREE and THP 25.09.2026
CVE-2026-97946 x86/amd_node: Fix PCI device reference counting in amd_smn_init() 25.09.2026
CVE-2026-97947 x86/amd_node: Fix potential NULL pointer dereference 25.09.2026
CVE-2026-97948 powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver 25.09.2026
CVE-2026-97949 configfs: unhash the dentry before dropping the item in rmdir 25.09.2026
CVE-2026-97950 configfs: pin the symlink target's dirent instead of chasing ->ci_dentry 25.09.2026
CVE-2026-97951 scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands 25.09.2026
CVE-2026-97952 sunvdc: unmap LDC cookies when the descriptor send fails 25.09.2026
CVE-2026-97953 net: stmmac: fix TX descriptor availability check for TSO traffic 25.09.2026 7
CVE-2026-97954 net/rds: fix tcp stream corruption with large pages 25.09.2026
CVE-2026-97955 net: mana: restore the XDP program pointer when pre-allocation fails 25.09.2026
CVE-2026-97956 net: net_failover: Fix the deadlock in net_failover_slave_name_change() 25.09.2026
CVE-2026-97957 net: hinic: fix mailbox segment buffer overflow 25.09.2026 8.8
CVE-2026-97958 net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain(). 25.09.2026
CVE-2026-97959 net/sched: cls_route: free emptied bucket on filter move 25.09.2026
CVE-2026-97960 perf/x86/intel: Prevent drain_pebs() reentry 25.09.2026
CVE-2026-97961 perf/core: Allow list_del during perf_event_overflow() 25.09.2026
CVE-2026-97962 net/mlx5e: Move representor vnic reporter to eswitch devlink port 25.09.2026
CVE-2026-97963 net: stmmac: initialize ptp_lock at probe time 25.09.2026
CVE-2026-97964 ppp_synctty: ensure a writeable skb header 25.09.2026
CVE-2026-97965 vxlan: initialize _md in vxlan_xmit_one() 25.09.2026
CVE-2026-97966 octeontx2-pf: reset HTB scheduler topology before freeing queues 25.09.2026
CVE-2026-97967 hwmon: (corsair-cpro) Remove debugfs entries when probe fails 25.09.2026
CVE-2026-97968 hwmon: (corsair-cpro) Create debugfs entries after hwmon registration 25.09.2026
CVE-2026-97969 watchdog: msc313e: Fix clock leak and spurious timer in settimeout() 25.09.2026
CVE-2026-97970 watchdog: msc313e: Avoid division by zero 25.09.2026
CVE-2026-97971 nstree: check listing permission before taking a namespace reference 25.09.2026 7.8
CVE-2026-97972 net: macb: put the "mdio" child node reference on success 25.09.2026
CVE-2026-97973 net: macb: destroy the phylink instance on the probe error path 25.09.2026
CVE-2026-97974 ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() 25.09.2026
CVE-2026-97975 Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() 25.09.2026
CVE-2026-97976 Bluetooth: btintel_pcie: validate packet_len before skb_put_data 25.09.2026
CVE-2026-97977 Bluetooth: btusb: Fix UAF of btusb_data by rx_work 25.09.2026
CVE-2026-97978 eth: ice: don't dereference pointers from TP_printk() 25.09.2026
CVE-2026-97979 ice: add missing xa_destroy for sched_node_ids 25.09.2026
CVE-2026-97980 s390/debug: Fix NULL pointer dereference in debug_set_level() 25.09.2026
CVE-2026-97981 net: ethernet: cortina: Count dropped frames as NAPI work 25.09.2026
CVE-2026-97982 net: ethernet: cortina: Fix budget accounting 25.09.2026
CVE-2026-97983 vduse: return compat ioctl results directly 25.09.2026
CVE-2026-97984 net: ipv6: Fix UDP length overflow with PMTU discover and big MTU 25.09.2026
CVE-2026-97985 af_unix: Update last skb marker in manage_oob(). 25.09.2026
CVE-2026-97986 virtio_input: stop callbacks before unregistering input device 25.09.2026
CVE-2026-97987 virtio_input: reset device if input_register_device() fails 25.09.2026
CVE-2026-97988 vhost: invalidate vring access on IOTLB transitions 25.09.2026
CVE-2026-97989 vduse: validate virtqueue alignment 25.09.2026
CVE-2026-97990 vdpa_sim_net: check TX pull result before RX copy 25.09.2026 7.5
CVE-2026-97991 vdpa_sim_blk: reject out-of-range sector starts 25.09.2026 7.8
CVE-2026-97992 vhost-vdpa: protect config_ctx from being freed under the config callback 25.09.2026
CVE-2026-97993 vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx 25.09.2026
CVE-2026-97994 vhost/vdpa: reject VRING_NUM larger than device max 25.09.2026
CVE-2026-97995 virtio_console: do not free control-out buffers on remove 25.09.2026
CVE-2026-97996 virtio: fix use-after-free in unregister_virtio_device() 25.09.2026
CVE-2026-97997 virtio_ring: fix stale descriptor flags after a failed packed add 25.09.2026
CVE-2026-97998 netfilter: nfnetlink_log: cope with concurrent instance destruction 25.09.2026
CVE-2026-98000 hwmon: Fix potential UAF in pec_store 25.09.2026
CVE-2026-98001 hwmon: (ltc4282) Make sure clk_init_data is fully initialized 25.09.2026
CVE-2026-98002 iommu/amd: Fix ineffective error check in nested domain allocation 25.09.2026 7.8
CVE-2026-98003 iommu/amd: Do not reallocate GA log buffers on resume 25.09.2026
CVE-2026-98004 iommu/riscv: Serialize command queue publishing 25.09.2026
CVE-2026-98005 erofs: delimit inode_share cache key components 25.09.2026
CVE-2026-98006 ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev 25.09.2026
CVE-2026-98007 bpf: Reject non-scalar bpf_loop iteration counts 25.09.2026
CVE-2026-98008 net: macb: fix NULL pointer dereference on unbind with fixed-link 25.09.2026
CVE-2026-98009 net/sched: ets: clamp quantum in parse and fallback paths 25.09.2026
CVE-2026-98010 net/sched: drr: clamp quantum in change class 25.09.2026
CVE-2026-98011 net/sched: hhf: clamp quantum in change and init paths 25.09.2026
CVE-2026-98012 net/sched: sfq: clamp quantum in change path 25.09.2026
CVE-2026-98013 net/sched: fq_pie: clamp quantum in change path 25.09.2026
CVE-2026-98014 net/mlx5: E-Switch, prevent mc_list repopulation during vport disable 25.09.2026
CVE-2026-98015 net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put 25.09.2026
CVE-2026-98016 net/mlx5e: Fix use-after-free race in sample_restore_put() 25.09.2026
CVE-2026-98017 net/sched: defer qdisc freeing after failed creation 25.09.2026 7.8
CVE-2026-98018 net: mctp: i3c: serialize probe with bus removal 25.09.2026
CVE-2026-98019 bpf: mark a NULL call argument precise 25.09.2026
CVE-2026-98020 pds_core: fix cmd_regs access racing BAR unmap on reset 25.09.2026
CVE-2026-98021 net: reject oversized tx_queue_len at netlink parse time 25.09.2026
CVE-2026-98022 net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations 25.09.2026
CVE-2026-98023 vxlan: reject dynamic fdb entries that reference a nexthop id 25.09.2026 7.8
CVE-2026-98024 s390/ism: folio_put() after error 25.09.2026
CVE-2026-98025 net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow 25.09.2026
CVE-2026-98026 net: bridge: mcast: properly convert mglist to rcu 25.09.2026
CVE-2026-98027 net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size 25.09.2026 7
CVE-2026-98028 eth: nfp: drop the replaced rule from the list when reprogramming fails 25.09.2026
CVE-2026-98029 eth: nfp: bound the ntuple rule dump by the caller's buffer size 25.09.2026 7
CVE-2026-98030 net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size 25.09.2026 7
CVE-2026-98031 nexthop: Initialize extack in remove_nh_grp_entry() 25.09.2026
CVE-2026-98032 tracing: Fix subbuf resize races with trace_pipe_raw readers 25.09.2026
CVE-2026-98033 bpf: Preserve inner map identity in callback frames 25.09.2026
CVE-2026-98034 bpf: Mark NULL kptr stores precise 25.09.2026
CVE-2026-98035 bpf: Cancel special fields when recycling rhtab elements 25.09.2026
CVE-2026-98036 bpf: Preserve special fields in recycled rhtab elements 25.09.2026
CVE-2026-98037 bpf: Reject untrusted allocated-object pointers 25.09.2026
CVE-2026-98038 bpf: Keep refcount_acquire nullable for borrowed RCU kptrs 25.09.2026
CVE-2026-98039 bpf: Require MEM_PERCPU for percpu kptr stores 25.09.2026
CVE-2026-98040 bpf: Mark the zero register precise for a register-form NULL check 25.09.2026
CVE-2026-98041 bpf: Don't predict JMP32 pointer vs zero comparisons 25.09.2026 7
CVE-2026-98042 bpf: Don't resurrect a scalar id dropped by collect_linked_regs() 25.09.2026
CVE-2026-98043 bpf: Don't infer non-NULL from a pointer with an unbounded offset 25.09.2026
CVE-2026-98044 bpf: Reject legacy packet loads from callbacks 25.09.2026
CVE-2026-98045 bpf: Mark faultable stack helpers as sleepable 25.09.2026
CVE-2026-98046 bpf: Mark bpf_btf_find_by_name_kind() as sleepable 25.09.2026
CVE-2026-98047 bpf: Check ancestor frames for rbtree callbacks 25.09.2026
CVE-2026-98048 bpf: don't rewrite bpf_fastcall patterns entered by a jump 25.09.2026
CVE-2026-98049 bpf: zero extend the result of an arena 32-bit cmpxchg 25.09.2026
CVE-2026-98050 mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context 25.09.2026 7.5
CVE-2026-98051 net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times 25.09.2026
CVE-2026-98052 net: bcmasp: clear txcb->last before writing each descriptor 25.09.2026 7.8
CVE-2026-98053 ASoC: Intel: avs: Refactor and fix init_config access 25.09.2026
CVE-2026-98054 ASoC: Intel: avs: Fix unbalanced module reference count 25.09.2026
CVE-2026-98055 ASoC: Intel: avs: Clean up the bus when fetching ML caps fails 25.09.2026
CVE-2026-98056 nvme: remove stale namespaces by NSID range during scan 25.09.2026 7.5
CVE-2026-98057 ring-buffer: Add checking nr_subbufs to persistent ring buffer validation 25.09.2026
CVE-2026-98058 bpf: Mark syscall helpers as sleepable 25.09.2026
CVE-2026-98059 bpf: Mark sched_process_wait argument as nullable 25.09.2026
CVE-2026-98060 bpf: Reject resilient lock operations in rbtree callbacks 25.09.2026
CVE-2026-98061 bpf: Reject tail calls directly from callback frames 25.09.2026
CVE-2026-98062 bpf: Mark signal tracepoint siginfo arguments as scalar 25.09.2026
CVE-2026-98063 bpf: Fix NULL-ptr-deref in btf_var_show() 25.09.2026
CVE-2026-98064 bpf: Fix NULL-ptr-deref when showing a void BTF type 25.09.2026
CVE-2026-98065 bpf: Reject key-less BTF for hash maps 25.09.2026
CVE-2026-98066 ALSA: caiaq: Fix potential double-free at error path 25.09.2026
CVE-2026-98067 erofs: disable LZ4 rolling decompression for now 25.09.2026
CVE-2026-98068 net/rds: don't let rds_conn_shutdown() consume a concurrent drop 25.09.2026
CVE-2026-98069 net/rds: acquire the fastpath locks in rds_conn_shutdown() 25.09.2026 8.1
CVE-2026-98070 net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() 25.09.2026 8.1
CVE-2026-98071 net/rds: clear cp_flags bits individually in rds_conn_path_reset() 25.09.2026
CVE-2026-98072 net/rds: use wq_has_sleeper() in release_in_xmit() 25.09.2026
CVE-2026-98073 net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(). 25.09.2026 7.8
CVE-2026-98074 bonding: do not clear curr_active_slave prematurely when releasing all slaves 25.09.2026
CVE-2026-98075 bpf: reject BPF_PSEUDO_FUNC reference to the main program 25.09.2026
CVE-2026-98076 tracing/probes: Fix use-after-free on field name/type of events with multiple probes 25.09.2026
CVE-2026-98077 netfilter: nf_conntrack_sip: fix OOB read in sip_skip_whitespace() 25.09.2026
CVE-2026-98078 ipvs: fix reversed sequence option serialization 25.09.2026
CVE-2026-98079 btrfs: zstd: fix lost wakeup when waiting for a workspace 25.09.2026
CVE-2026-98080 btrfs: do not force reloc root creation during qgroup_account_snapshot() 25.09.2026
CVE-2026-98081 btrfs: zoned: finish active block group cleanup if call_zone_finish() fails 25.09.2026
CVE-2026-98082 btrfs: fix the possible bioc_list memory leak during error 25.09.2026
CVE-2026-98083 btrfs: fix transaction use-after-free in raid stripe insertion 25.09.2026 7
CVE-2026-98084 bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks 25.09.2026
CVE-2026-98085 bpf: backtrack_insn(): Handle ld_{abs,ind} subprog exit edge 25.09.2026
CVE-2026-98086 ALSA: ump: do not touch legacy_rmidi before it exists 25.09.2026
CVE-2026-98087 sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate 25.09.2026
CVE-2026-98088 scsi: mpt3sas: Avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() 25.09.2026
CVE-2026-98089 bonding: alb: fix uninitialized transport header access in alb_determine_nd() 25.09.2026
CVE-2026-98090 btrfs: restore active device pointers after failed sprout 25.09.2026
CVE-2026-98091 btrfs: detach failed sprout device from transaction update list 25.09.2026
CVE-2026-98092 ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() 25.09.2026
CVE-2026-98093 ASoC: fsl_micfil: balance mclk enable/disable 25.09.2026
CVE-2026-98094 staging: fbtft: make dirty_lock IRQ-safe 25.09.2026
CVE-2026-98095 af_packet: Don't cast tpacket_hdr.tp_len to int in tpacket_parse_header(). 25.09.2026
CVE-2026-98096 ipv6: sr: restore network header before routing and forwarding 25.09.2026 7.4
CVE-2026-98097 tipc: Dont send random pad bytes in RESET/ACTIVATE messages 25.09.2026
CVE-2026-98098 tipc: fix NULL deref in tipc_named_node_up() on empty publication list 25.09.2026
CVE-2026-98099 ipv6: mcast: use rcu_assign_pointer() for __rcu list updates 25.09.2026
CVE-2026-97898 Broken authorization in Akia keyless entry lets an authenticated guest unlock other rooms 25.09.2026
CVE-2026-92106 lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS 25.09.2026
CVE-2026-6082 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-6083 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-6084 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-6085 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-6086 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-6087 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-6088 Stored Cross-Site Scripting in StockAgile by Novadigits technologies 25.09.2026
CVE-2026-80514 wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass 25.09.2026 5.3
CVE-2026-86837 Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass 25.09.2026 5.3
CVE-2026-88848 MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass 25.09.2026 4.2
CVE-2026-92550 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder 25.09.2026
CVE-2026-92560 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder 25.09.2026
CVE-2026-92564 Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing 25.09.2026
CVE-2026-92573 Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering 25.09.2026
CVE-2026-97863 misp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute Values 25.09.2026
CVE-2026-12037 Asset CleanUp: Page Speed Booster <= 1.4.0.5 - Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter 25.09.2026 5.5
CVE-2026-13179 WP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter 25.09.2026 6.4
CVE-2026-13456 WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter 25.09.2026 7.5
CVE-2026-17577 SSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' Parameter 25.09.2026 6.1
CVE-2026-17602 SSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' Parameter 25.09.2026 4.9
CVE-2026-19804 s2Member <= 260814 - Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return 25.09.2026 8.8
CVE-2026-84280 Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter 25.09.2026 7.2
CVE-2026-88996 WPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST Parameter 25.09.2026 6.1
CVE-2026-89406 Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters 25.09.2026 7.5
CVE-2026-89426 Knit Pay <= 9.6.1.0 - Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field 25.09.2026 8.8
CVE-2026-92608 Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 25.09.2026
CVE-2026-92609 Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication 25.09.2026
CVE-2026-92713 Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter 25.09.2026 8.1
CVE-2026-93654 Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter 25.09.2026 7.2
CVE-2026-93656 User Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Field 25.09.2026 6.4
CVE-2026-93747 wpForo Forum <= 3.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'telegram' Profile Field 25.09.2026 6.4
CVE-2026-93901 Optima Express IDX <= 8.7.5 - Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment 25.09.2026 7.3
CVE-2026-94573 Repeater Fields for Elementor Forms <= 2.2.7 - Unauthenticated Stored Cross-Site Scripting via Repeater Field Value 25.09.2026 7.2
CVE-2026-95864 Themify Builder <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter 25.09.2026 7.2
CVE-2026-95866 User Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar Field 25.09.2026 7.2
CVE-2026-96448 Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation 25.09.2026
CVE-2026-96568 Restaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter 25.09.2026 7.2
CVE-2026-96752 Zero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration 25.09.2026 7.2
CVE-2026-93477 Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash 25.09.2026
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-19775 OpenStation <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via AI Copilot Search Endpoint 25.09.2026 4.3
CVE-2026-83591 AMP for WP <= 1.1.16 - Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation 25.09.2026 7.2
CVE-2026-84279 Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'output_format' Parameter via Pro Export Print Job 25.09.2026 7.2
CVE-2026-84281 Fancy Product Designer <= 6.5.2 - Unauthenticated Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta 25.09.2026 7.2
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-92212 JetFormBuilder <= 3.6.5.3 - Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field 25.09.2026 6.1
CVE-2026-92746 Gutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute 25.09.2026 6.4
CVE-2026-92799 Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data 25.09.2026 5.3
CVE-2026-92829 Blog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers 25.09.2026 4.3
CVE-2026-93303 HT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume 25.09.2026 7.2
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 25.09.2026 9.1
CVE-2026-93897 GeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') 25.09.2026 6.4
CVE-2026-93899 Better Messages <= 3.0.4 - Authenticated (Subscriber+) SQL Injection via 'group_id' Message Meta Parameter 25.09.2026 6.5
CVE-2026-94376 Better Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via User Display Name 25.09.2026 6.4
CVE-2026-96039 BA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting via first_name Parameter 25.09.2026 7.2
CVE-2026-96766 GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' Parameter 25.09.2026 6.4
CVE-2026-62062 WordPress Elementor Website Builder plugin <= 4.3.1 - Cross Site Request Forgery (CSRF) vulnerability 25.09.2026 8.8
CVE-2026-75553 25.09.2026
CVE-2026-78393 Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links 25.09.2026
CVE-2026-78394 Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter 25.09.2026
CVE-2026-78397 Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation 25.09.2026
CVE-2026-97846 Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding 25.09.2026
CVE-2026-97721 Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorization 25.09.2026
CVE-2026-97818 25.09.2026 8.6
CVE-2026-97737 25.09.2026 7.4
CVE-2026-97764 25.09.2026 3.7
CVE-2026-97736 25.09.2026 5.4
CVE-2026-97735 25.09.2026 8
CVE-2025-14814 CSS & JavaScript Toolbox <= 12.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via cjtoolbox Shortcode 25.09.2026 6.4
CVE-2026-97732 25.09.2026 5.1
CVE-2026-97731 25.09.2026 7.1
CVE-2026-97730 25.09.2026 8.5
CVE-2026-97650 ningzichun student-management-system addLog.php echo cross site scripting 25.09.2026
CVE-2026-97724 25.09.2026
CVE-2026-97723 25.09.2026 5.4
CVE-2026-97649 ningzichun student-management-system example_lite.sql default credentials 25.09.2026
CVE-2026-95811 Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it 25.09.2026
CVE-2026-97647 ningzichun student-management-system editLog.php authorization 25.09.2026
CVE-2026-97648 ningzichun student-management-system cross-site request forgery 25.09.2026
CVE-2026-53493 Containerd has image-pull DoS via crafted OCI index graph amplification 25.09.2026
CVE-2026-85417 Incomplete property masking in the SANnav logging subsystem 25.09.2026
CVE-2026-92288 Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party 25.09.2026
CVE-2026-92289 Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret 25.09.2026
CVE-2026-97646 ningzichun student-management-system getStudent.php authorization 25.09.2026
CVE-2026-85082 Maple Media Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames 24.09.2026
CVE-2026-84283 FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass the PIN gate 24.09.2026
CVE-2026-97387 24.09.2026
CVE-2026-97230 IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL 24.09.2026
CVE-2026-87720 Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suffixes in Gerrit Code Review 24.09.2026
CVE-2026-87721 Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review 24.09.2026
CVE-2026-87722 Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review 24.09.2026
CVE-2026-85491 Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone 25.09.2026
CVE-2026-97636 Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key 24.09.2026