CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 27.09.2026 9.8
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 27.09.2026 9.5
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 27.09.2026 9.1
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 27.09.2026 9.4
CVE-2026-82901 Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Upload via Signature Form Field 26.09.2026 9.8
CVE-2026-85984 miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthenticated Authentication Bypass via 'mo_wp_login_intent' Parameter 26.09.2026 9.8
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.4
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 9.2
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 27.09.2026 10
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 27.09.2026 9.5
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 27.09.2026 9.3
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 26.09.2026 9.2
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 26.09.2026 9.2
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 26.09.2026 9.2
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026 9.4
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026 9.4
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 26.09.2026 9.4
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026 9.3
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026 9
CVE-2026-100382 Unauthenticated remote code execution through wikitext in ExternalData 26.09.2026 10
CVE-2026-100389 GestSup before 3.2.61 Remote Code Execution via IMAP Attachment 25.09.2026 9.2
CVE-2026-100390 Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 25.09.2026 9.1
CVE-2026-48482 GLPI: RCE via Form import 25.09.2026 9.4
CVE-2026-84458 Zammad: Account takeover via unverified email matching during SSO auto-link 25.09.2026 9.1
CVE-2026-97063 X-SpringBoot through 6.0 Authentication Bypass via Login Code 25.09.2026 9.3
CVE-2026-97064 X-SpringBoot through 6.0 Authentication Bypass via Static Master Code 25.09.2026 9.3
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 25.09.2026 9.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 25.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 25.09.2026 9.1
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 26.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 26.09.2026 9.3
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026 9.3
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 26.09.2026 9.1
CVE-2026-81630 Botslab G980H Dashcams Insufficient Verification of Data Authenticity 25.09.2026 9.2
CVE-2026-93289 OS command injection in Eufy Omni C20, Omni X10 Pro 24.09.2026 9
CVE-2026-93291 Improper certificate validation in Eufy Omni C20 24.09.2026 9.3
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13249 Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040 24.09.2026 9.8
CVE-2026-61741 http4s-scala-xml has an XML External Entity (XXE) processing issue 24.09.2026 9.3
CVE-2026-61604 ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass 24.09.2026 9.3
CVE-2026-61732 Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context 24.09.2026 10
CVE-2026-61742 DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution 24.09.2026 9.3
CVE-2026-79766 Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email 24.09.2026 9.1
CVE-2026-97413 RDMA/rtrs-srv: Fix integer underflow in process_read and process_write 25.09.2026 9.8
CVE-2026-93425 Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root 24.09.2026 9.9
CVE-2026-93228 svcrdma: Reject Write/Reply chunks with segcount 0 25.09.2026 9.1
CVE-2026-93207 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry 25.09.2026 9.8
CVE-2026-81549 DataStage on Cloud Pak for Data has several vulnerabilities 24.09.2026 9.6
CVE-2026-90481 24.09.2026 9.2
CVE-2026-97404 26.09.2026 9.2
CVE-2026-97359 HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection 24.09.2026 10
CVE-2026-97360 HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine 24.09.2026 10
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy 24.09.2026 9.3
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal 25.09.2026 9.9
CVE-2026-12227 Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter 24.09.2026 9.8
CVE-2026-78312 Path Traversal in DIAEnergie 24.09.2026 9.1
CVE-2026-78308 Authentication Bypass in DIAEnergie 24.09.2026 9.8
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write 24.09.2026 9.3
CVE-2026-97055 SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret 24.09.2026 9.2
CVE-2026-18467 Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter 24.09.2026 9.8
CVE-2026-89078 Double Free in GitLab 25.09.2026 9.9
CVE-2026-93577 Integer Overflow or Wraparound in GitLab 25.09.2026 9.9
CVE-2026-93352 Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload 26.09.2026 9.3
CVE-2026-6928 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67231 RabbitMQ: Trust-store whitelist by Issuer+Serial only 23.09.2026 9.1
CVE-2026-6721 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-6730 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch 23.09.2026 9.2
CVE-2026-87898 23.09.2026 9.4
CVE-2026-87899 24.09.2026 9.4
CVE-2026-87900 23.09.2026 9.4
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups 24.09.2026 9.1
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) 25.09.2026 9.9
CVE-2026-77602 OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites) 23.09.2026 9.9
CVE-2026-96770 s2s-proxy accepts untrusted client certificates 23.09.2026 9.3
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match 24.09.2026 9.9
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod 24.09.2026 9.9
CVE-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack 23.09.2026 9.2
CVE-2026-95601 WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability 23.09.2026 9.3
CVE-2026-85724 Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass 24.09.2026 9.6
CVE-2026-95848 Moquette fails open when configured authentication or authorization classes cannot load 23.09.2026 9.3
CVE-2026-96754 orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path 23.09.2026 9.3
CVE-2026-96755 orval @orval/effect 8.14.0 through 8.28.1 Code Injection 23.09.2026 9.3
CVE-2026-96756 orval before 8.30.0 Code Injection via Factory Generation 23.09.2026 9.2
CVE-2026-96757 orval before 8.29.0 Code Injection via unescaped OpenAPI media-type 23.09.2026 9.3
CVE-2026-96758 orval @orval/core before 8.28.0 Code Injection via Form-Data 23.09.2026 9.3
CVE-2026-96759 orval before 8.29.0 Code Injection via operationId 23.09.2026 9.3
CVE-2026-18872 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.3
CVE-2026-59167 SunEditor: Critical XSS vulnerability - sanitizer bypass 24.09.2026 10
CVE-2026-96560 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel 24.09.2026 9.3
CVE-2026-86708 Sensitive data exposure 24.09.2026 10
CVE-2026-19599 Remote Code Execution vulnerability 24.09.2026 9.9
CVE-2026-96257 Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow 23.09.2026 10
CVE-2026-18162 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18163 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18169 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.9
CVE-2026-19202 Token Cache Reuse in mcp-toolbox-sdk-python 23.09.2026 9.1
CVE-2026-17645 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1
CVE-2026-16346 DataStage on Cloud Pak for Data has several vulnerabilities 23.09.2026 9.9
CVE-2026-17472 Multiple Vulnerabilities in IBM Concert Software 24.09.2026 9.6
CVE-2026-17635 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1
CVE-2026-77987 GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery 23.09.2026 9.3
CVE-2026-87121 Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application 22.09.2026 9.3
CVE-2026-28324 SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability 22.09.2026 9.8
CVE-2026-47116 LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH 23.09.2026 9.2
CVE-2026-76708 Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE) 23.09.2026 9.8
CVE-2026-76709 Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE) 23.09.2026 9.8
CVE-2026-57149 plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection 22.09.2026 9.9
CVE-2026-91130 Home Assistant: XSS in Statistics Graph Card 22.09.2026 9.3
CVE-2026-75682 Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 23.09.2026 9.9
CVE-2026-75684 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 26.09.2026 9.3
CVE-2026-75686 Adobe Connect | Improper Input Validation (CWE-20) 23.09.2026 9.3
CVE-2026-75689 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 26.09.2026 9.3
CVE-2026-75697 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 22.09.2026 9.3
CVE-2026-75698 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) 23.09.2026 9.3
CVE-2026-75745 Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863) 26.09.2026 10
CVE-2026-81995 Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20) 23.09.2026 9.1
CVE-2026-82000 Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918) 23.09.2026 9.6
CVE-2026-77254 MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials 22.09.2026 9.1
CVE-2026-43641 Softaculous Virtualizor OS Command Injection via Billing Module Handler 23.09.2026 9.3
CVE-2026-43642 Softaculous Virtualizor PHP Object Injection via Billing Module Handler 25.09.2026 9.2
CVE-2026-18461 Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. 22.09.2026 9.2
CVE-2026-77244 [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token 23.09.2026 10
CVE-2026-7866 Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. 23.09.2026 9.3
CVE-2026-73369 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 23.09.2026 10
CVE-2026-75699 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 26.09.2026 10
CVE-2026-75703 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-75721 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 25.09.2026 10
CVE-2026-75723 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 22.09.2026 10
CVE-2026-75728 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 23.09.2026 9.1
CVE-2026-82008 Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20) 22.09.2026 9.9
CVE-2026-82009 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 25.09.2026 9.1
CVE-2026-82010 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 22.09.2026 9.9
CVE-2026-82011 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 23.09.2026 9.1
CVE-2026-82013 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 26.09.2026 9.9
CVE-2026-82443 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 22.09.2026 9.6
CVE-2026-83660 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 25.09.2026 9.9
CVE-2026-84412 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-89275 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 23.09.2026 10
CVE-2026-89276 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 26.09.2026 9.9
CVE-2026-85734 LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks 22.09.2026 9.1
CVE-2026-86059 Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one 22.09.2026 9.6
CVE-2026-94456 Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys 22.09.2026 9.1
CVE-2026-63374 AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing 22.09.2026 9.3
CVE-2026-77621 Vector: Arbitrary file write in the file sink via templated path (path traversal). 25.09.2026 9.3
CVE-2026-80143 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read 24.09.2026 9.4
CVE-2026-80144 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write 24.09.2026 9.4
CVE-2026-80145 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password 24.09.2026 9.4
CVE-2026-80146 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read 25.09.2026 9.4
CVE-2026-80147 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write 24.09.2026 9.4
CVE-2026-80151 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download 26.09.2026 9.4
CVE-2026-80152 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule 26.09.2026 9.4
CVE-2026-80155 Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation 24.09.2026 10
CVE-2026-80156 Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass 24.09.2026 9.4
CVE-2026-95654 Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token 22.09.2026 9.1
CVE-2026-65113 22.09.2026 9.8
CVE-2026-84388 26.09.2026 9.1
CVE-2026-94127 BIG-IP APM OAuth vulnerability 23.09.2026 9.3
CVE-2026-12718 SQLi in Karel Electronics' KarelIPS 22.09.2026 9.8
CVE-2026-95675 D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface 22.09.2026 9.3
CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server 23.09.2026 9.8
CVE-2026-74849 Remote code execution vulnerability 23.09.2026 9.8
CVE-2026-25254 Improper authorization in Qualcomm Software Center 22.09.2026 9.8
CVE-2026-93556 Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini 22.09.2026 9.3
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension 22.09.2026 9.3
CVE-2026-93952 Security Advisory 0183 23.09.2026 9.5
CVE-2026-13355 Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter 22.09.2026 9.8
CVE-2026-19658 Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter 22.09.2026 9.8
CVE-2026-94493 Gigatech PDV5701 WebSocket Service index.html missing authentication 24.09.2026 10
CVE-2026-94425 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management 22.09.2026 9.3
CVE-2026-46649 Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint 21.09.2026 9.1
CVE-2026-77521 MaxKB: Prompt-injectable agent can lead to command execution 22.09.2026 10
CVE-2026-94424 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow 22.09.2026 9.3
CVE-2026-79916 MaxKB AWS Bedrock model credential injection leads to remote code execution 22.09.2026 9.1
CVE-2026-94571 22.09.2026 9.4
CVE-2026-94572 24.09.2026 9.4
CVE-2026-58491 Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter 22.09.2026 9.3
CVE-2026-94403 ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference 22.09.2026 9.3
CVE-2026-79920 Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task 21.09.2026 9.9
CVE-2026-61674 Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handler 21.09.2026 9.2
CVE-2026-85751 Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust 21.09.2026 9.8
CVE-2026-94301 Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 22.09.2026 9.8
CVE-2025-12999 22.09.2026 9.1
CVE-2026-94146 BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where 22.09.2026 9.3
CVE-2026-94142 BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94128 BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94129 BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94101 Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow 21.09.2026 9.4
CVE-2026-94098 Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection 21.09.2026 9.4
CVE-2026-94099 Netcore NBR200V2 Backup Restore restore.cgi command injection 22.09.2026 9.4
CVE-2026-94100 Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow 21.09.2026 9.4
CVE-2026-94097 Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection 24.09.2026 10
CVE-2026-94096 Netcore NBR200V2 LAN IP Configuration network_tools command injection 21.09.2026 9.4
CVE-2026-94095 Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection 21.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-101041 Vulnerability-Lookup - Race Condition in Account Recovery Token Consumption Allows Password Takeover 27.09.2026
CVE-2026-101032 navi through 2.24.0 OS Command Injection via Cheatsheet Variables 27.09.2026
CVE-2026-101033 KitchenOwl through 0.7.10 IDOR via unchecked category ID 27.09.2026
CVE-2026-100866 onefetch through 2.28.1 Terminal Escape Sequence Injection 27.09.2026
CVE-2026-100867 spaceship-prompt through 4.22.5 Terminal Escape Sequence Injection 27.09.2026
CVE-2026-100868 Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge 27.09.2026
CVE-2026-100869 Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API 27.09.2026
CVE-2026-100870 Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning via Host Header 27.09.2026
CVE-2026-100871 Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API Authentication 27.09.2026
CVE-2026-100872 Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite 27.09.2026
CVE-2026-100747 Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 27.09.2026
CVE-2026-100748 Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 27.09.2026
CVE-2026-97164 Joomla Extension - svenbluege.de - Path Traversal in Clear Cache task in Event Gallery extension < 6.5.0 27.09.2026
CVE-2026-100749 Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 27.09.2026
CVE-2026-97165 Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 27.09.2026
CVE-2026-15442 Heap use-after-free on read during bidirectional (D)TLS shutdown 27.09.2026
CVE-2026-89102 OCSP stapling v2 multi accepts non-CA chain certificates as issuers 27.09.2026
CVE-2026-89133 NameConstraints not enforced across unconstrained intermediate CA 27.09.2026
CVE-2026-89134 Subject CN name-constraint check bypassed when non-DNS SAN present 27.09.2026
CVE-2026-89135 Failed X509_verify_cert leaves unverified CA in shared CertManager 27.09.2026
CVE-2026-89136 Client accepts unsolicited RawPublicKey server certificate type 27.09.2026
CVE-2026-93302 Trusted peer certificate match ignores public key, allowing forged CA clones 27.09.2026
CVE-2026-93304 (D)TLS 1.2 client accepts early ChangeCipherSpec before ClientKeyExchange 27.09.2026
CVE-2026-94417 CRL check skipped when OCSP enabled and certificate has no OCSP URL 27.09.2026
CVE-2026-94418 Signature failure masked by date error under WOLFSSL_SMALL_CERT_VERIFY 27.09.2026
CVE-2026-94419 Client session cache reference poisoning allows resumption with wrong server 27.09.2026
CVE-2026-100741 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in hMailServer 27.09.2026 9.8
CVE-2026-81655 Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields 27.09.2026
CVE-2026-82841 UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migration Notice 27.09.2026
CVE-2026-84069 WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php 27.09.2026
CVE-2026-85002 EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes 27.09.2026
CVE-2026-86609 Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription 27.09.2026
CVE-2026-86839 Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOR 27.09.2026
CVE-2026-86841 Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options 27.09.2026
CVE-2026-89000 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run 27.09.2026
CVE-2026-89001 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings 27.09.2026
CVE-2026-89003 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview 27.09.2026
CVE-2026-89006 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import 27.09.2026
CVE-2026-92436 Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via IDOR 27.09.2026
CVE-2026-92995 Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file 27.09.2026
CVE-2026-96895 WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes 27.09.2026
CVE-2026-96896 Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request 27.09.2026
CVE-2026-96897 Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache 27.09.2026
CVE-2026-96899 Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script 27.09.2026
CVE-2026-97227 NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion 27.09.2026
CVE-2026-97319 PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block 27.09.2026
CVE-2026-100746 coollabsio Coolify GitHub App Setup redirect missing authentication 27.09.2026
CVE-2026-100745 Edimax BR-6428nC Wireless Wizard formWizSurvey stack-based overflow 27.09.2026
CVE-2025-71422 Contrast before 1.12.1 Insecure LUKS2 Persistent Storage 27.09.2026
CVE-2025-71423 Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure 27.09.2026
CVE-2025-71424 Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount 27.09.2026
CVE-2025-71425 Contrast before 1.8.1 Information Disclosure via Logging 27.09.2026
CVE-2025-71426 Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery 27.09.2026
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver 27.09.2026
CVE-2026-100722 vm2 before 3.12.2 Host Process Termination via Construct Trap 27.09.2026
CVE-2026-100723 vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool 27.09.2026
CVE-2026-100724 http4k before 6.49.0.0 Host Header Routing Bypass via reverseProxy 27.09.2026
CVE-2026-100725 http4k before 6.48.0.0 Cookie Scoping Bypass via BasicCookieStorage 27.09.2026
CVE-2026-100833 Contrast before 1.23.1 Image Substitution via Policy Generation 27.09.2026
CVE-2026-100834 http4k before 6.48.0.0 Digest Authentication Replay Protection Bypass 27.09.2026
CVE-2026-100835 Contrast before 1.16.0 Remote Attestation Relay Attack 27.09.2026
CVE-2026-100836 Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer 27.09.2026
CVE-2026-100837 Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching 27.09.2026
CVE-2026-100838 Contrast before 1.19.1 CopyFile Policy Symlink Subversion 27.09.2026
CVE-2026-100839 Contrast before 1.18.0 AML Injection Remote Code Execution 27.09.2026
CVE-2026-100840 MONAI through 1.6.0 Remote Code Execution via bundle configuration 27.09.2026
CVE-2026-100841 MONAI 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache 27.09.2026
CVE-2026-100842 MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains 27.09.2026
CVE-2026-100843 MONAI before 1.6.0 Remote Code Execution via algo_from_pickle 27.09.2026
CVE-2026-100844 MONAI before 1.6.0 OS Command Injection via dataset_name_or_id 27.09.2026
CVE-2026-100845 MONAI before 1.6.0 Remote Code Execution via NumpyReader 27.09.2026
CVE-2026-100846 MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization 27.09.2026
CVE-2026-100847 AzuraCast before 0.23.8 DQL Injection via sortOrder 27.09.2026
CVE-2026-100848 AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL 27.09.2026
CVE-2026-100849 AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs 27.09.2026
CVE-2026-100850 AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist 27.09.2026
CVE-2026-100851 AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile 27.09.2026
CVE-2026-100852 AzuraCast through 0.23.x Command Injection via Streamer Username 27.09.2026
CVE-2026-100853 AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass 27.09.2026
CVE-2026-100854 AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API 27.09.2026
CVE-2026-100855 AzuraCast before 0.23.6 Missing Permission Check via /play 27.09.2026
CVE-2026-100856 AzuraCast before 0.23.6 Code Injection via Remote Relay Password 27.09.2026
CVE-2026-100857 AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation 27.09.2026
CVE-2026-100858 heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes 27.09.2026
CVE-2026-100859 Heym before 0.0.106 Credential Exfiltration via URL Override 27.09.2026
CVE-2026-100860 heym before 0.0.105 Authentication Bypass via Redis Node 27.09.2026
CVE-2026-100861 heym before 0.0.105 SSRF via credential-controlled base URLs 27.09.2026
CVE-2026-100862 heym before 0.0.91 Multiple Secrets Plaintext Storage 27.09.2026
CVE-2026-100863 Heym before 0.0.91 SSRF via image fetching and IPv6 validation 27.09.2026
CVE-2026-100864 heym before 0.0.91 Remote Code Execution via Expression Engine 27.09.2026
CVE-2026-100865 Heym before 0.0.53 Multiple RCE and Authentication Bypass Vulnerabilities 27.09.2026
CVE-2026-100744 coollabsio Coolify Route-Level Middleware CanUpdateResource.php authorization 27.09.2026
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write 27.09.2026
CVE-2026-100739 mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection 26.09.2026