| CVE-2026-93958 |
D-Link R95 DHMAPI ssi system os command injection |
20.09.2026 |
9.4 |
| CVE-2026-94083 |
|
20.09.2026 |
9.4 |
| CVE-2026-94084 |
|
20.09.2026 |
9.4 |
| CVE-2026-93985 |
OpenPanel js-runtime JavaScript Template Sandbox Escape RCE |
19.09.2026 |
9.4 |
| CVE-2026-93742 |
Totolink A3002MU formWsc command injection |
19.09.2026 |
9.4 |
| CVE-2026-93741 |
Totolink A3002MU formWlWds buffer overflow |
19.09.2026 |
10 |
| CVE-2026-84434 |
Gravity Forms <= 3.1.0.4 - Unauthenticated Arbitrary File Upload via Hidden File Upload Field |
19.09.2026 |
9.8 |
| CVE-2026-89274 |
WP Recipe Maker <= 10.8.1 - Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content |
19.09.2026 |
9.1 |
| CVE-2026-92229 |
Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter |
19.09.2026 |
9.1 |
| CVE-2026-75885 |
Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint |
18.09.2026 |
9.3 |
| CVE-2026-93740 |
Totolink A3002MU formWlEncrypt buffer overflow |
18.09.2026 |
10 |
| CVE-2026-93739 |
Totolink A3002MU formWlAc buffer overflow |
18.09.2026 |
9.4 |
| CVE-2026-93738 |
Totolink A3002MU formSchedule buffer overflow |
18.09.2026 |
9.4 |
| CVE-2026-58264 |
FluidSynth: Heap-based buffer overrun |
18.09.2026 |
9.8 |
| CVE-2026-63647 |
CordysCRM SSE Notification Stream Hijack via `/sse/subscribe` |
18.09.2026 |
9.3 |
| CVE-2026-93868 |
Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
18.09.2026 |
9.2 |
| CVE-2026-84073 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.1 |
| CVE-2026-84075 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-84078 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-84082 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-61781 |
pg_partman has privilege escalation through SQL injection in create_partition_time() |
18.09.2026 |
9.9 |
| CVE-2026-84064 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-82967 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-84031 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9 |
| CVE-2026-81657 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-82340 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-82832 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.6 |
| CVE-2026-75878 |
IBM Sterling File Gateway is Vulnerable to Authentication Bypass |
19.09.2026 |
9.1 |
| CVE-2026-80441 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.8 |
| CVE-2026-80442 |
IBM Guardium Data Protection is affected by multiple vulnerabilities. |
19.09.2026 |
9.9 |
| CVE-2026-93839 |
LightLLM through 1.2.0 Missing Authentication in PD Master /pd_register WebSocket Endpoint |
18.09.2026 |
9.3 |
| CVE-2023-54399 |
Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree |
18.09.2026 |
9.3 |
| CVE-2026-59163 |
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass |
18.09.2026 |
9.1 |
| CVE-2026-61550 |
Icinga 2: Improper access control for JSON-RPC update certificate messages |
18.09.2026 |
9.8 |
| CVE-2025-66455 |
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py |
18.09.2026 |
9.8 |
| CVE-2026-92701 |
Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbinding attacks for Intel TDX verifier path |
18.09.2026 |
9.1 |
| CVE-2026-92702 |
Cocos AI: Intra-handshake attested TLS implementation can accept Evidence with nil, empty, or omitted reportData in the AMD SEV-SNP path |
18.09.2026 |
9.1 |
| CVE-2026-93762 |
Data deletion and attribute disclosure via field-name method injection in in-memory queries |
18.09.2026 |
9.2 |
| CVE-2026-77240 |
WACRM: Database-layer authorization bypasses |
18.09.2026 |
9.9 |
| CVE-2026-81321 |
CareCam CM2507 Cleartext Storage of Sensitive Information |
19.09.2026 |
9.3 |
| CVE-2026-85497 |
CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
18.09.2026 |
9.3 |
| CVE-2026-10858 |
IBM MQ for HPE NonStop is vulnerable to a denial of service attack |
19.09.2026 |
9.9 |
| CVE-2026-61682 |
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace |
18.09.2026 |
9.9 |
| CVE-2026-10747 |
IBM MQ Appliance is affected by a heap buffer overflow vulnerability in protocol message processing |
19.09.2026 |
10 |
| CVE-2026-84383 |
libheif: Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items |
18.09.2026 |
9.8 |
| CVE-2025-15399 |
Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool and IBM LKS Administration Agent |
19.09.2026 |
10 |
| CVE-2025-53837 |
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue |
18.09.2026 |
9.9 |
| CVE-2026-93659 |
Concrete CMS Community Store before 2.7.8 Stored XSS |
18.09.2026 |
9.3 |
| CVE-2023-5778 |
Missing Length Check |
18.09.2026 |
9.2 |
| CVE-2026-93603 |
vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function |
18.09.2026 |
10 |
| CVE-2026-93605 |
vm2 NodeVM before 3.12.1 Remote Code Execution via child_process |
18.09.2026 |
10 |
| CVE-2026-93606 |
vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species |
18.09.2026 |
10 |
| CVE-2026-28197 |
Privilege Escalation via Argument Injection in NetBackup Flex OS Shell |
18.09.2026 |
9.4 |
| CVE-2026-28198 |
Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell |
18.09.2026 |
9.4 |
| CVE-2026-13639 |
|
18.09.2026 |
9.8 |
| CVE-2026-13684 |
|
18.09.2026 |
9.8 |
| CVE-2026-67100 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
9.8 |
| CVE-2026-67101 |
HCL BigFix Service Management is affected by multiple security vulnerabilities. |
18.09.2026 |
9.3 |
| CVE-2026-93467 |
HGiga|OAKlouds - Insecure Deserialization |
18.09.2026 |
9.3 |
| CVE-2026-62874 |
Azure Billing Elevation of Privilege Vulnerability |
19.09.2026 |
10 |
| CVE-2026-69843 |
Microsoft Fabric Elevation of Privilege Vulnerability |
19.09.2026 |
10 |
| CVE-2026-85878 |
Azure Database for PostgreSQL Elevation of Privilege Vulnerability |
19.09.2026 |
9.9 |
| CVE-2026-69399 |
Azure Arc Elevation of Privilege Vulnerability |
18.09.2026 |
10 |
| CVE-2026-69865 |
Microsoft Container Registry Elevation of Privilege Vulnerability |
18.09.2026 |
10 |
| CVE-2026-70009 |
Azure Arc Elevation of Privilege Vulnerability |
19.09.2026 |
9.3 |
| CVE-2026-70200 |
Azure Logic Apps Elevation of Privilege Vulnerability |
19.09.2026 |
10 |
| CVE-2026-77903 |
Microsoft Dataverse Elevation of Privilege Vulnerability |
19.09.2026 |
9 |
| CVE-2026-83944 |
Azure Logic Apps Elevation of Privilege Vulnerability |
19.09.2026 |
10 |
| CVE-2026-85885 |
Microsoft 365 Copilot Elevation of Privilege Vulnerability |
19.09.2026 |
9.9 |
| CVE-2026-85889 |
Azure AI Foundry Elevation of Privilege Vulnerability |
19.09.2026 |
10 |
| CVE-2026-87701 |
Azure Cosmos DB Elevation of Privilege Vulnerability |
19.09.2026 |
9.6 |
| CVE-2026-54734 |
Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction |
18.09.2026 |
10 |
| CVE-2026-76949 |
Remember-me sign-in guard reads a session key that is never written in ash_authentication, allowing session replacement |
18.09.2026 |
9.1 |
| CVE-2026-54670 |
WeGIA: Unauthenticated Auth Bypass + Local File Inclusion |
17.09.2026 |
9.1 |
| CVE-2026-54767 |
WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php |
18.09.2026 |
9.1 |
| CVE-2026-93393 |
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream |
18.09.2026 |
9.2 |
| CVE-2026-45140 |
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution |
18.09.2026 |
9.8 |
| CVE-2026-45143 |
Chamilo LMS: Student-to-admin stored XSS in private messages via v-html |
17.09.2026 |
9 |
| CVE-2026-54237 |
Wavelog: Unauthenticated Remote Code Execution |
18.09.2026 |
9.3 |
| CVE-2026-54460 |
OpenReception: Unauthenticated WebAuthn passkey injection via `POST /api/auth/passkeys` leads to account takeover |
17.09.2026 |
9.8 |
| CVE-2026-54501 |
Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviors |
17.09.2026 |
9.4 |
| CVE-2026-54752 |
NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request |
17.09.2026 |
9.6 |
| CVE-2026-54618 |
Obsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the user |
17.09.2026 |
9.4 |
| CVE-2026-54626 |
SAIL: Heap out-of-bounds write in SAIL TGA decoder (indexed-RLE bpp/stride mismatch) |
17.09.2026 |
9.8 |
| CVE-2026-54627 |
SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth) |
18.09.2026 |
9.8 |
| CVE-2026-92943 |
Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python |
17.09.2026 |
9.2 |
| CVE-2026-54617 |
GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler |
18.09.2026 |
9.8 |
| CVE-2026-47252 |
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) |
17.09.2026 |
9 |
| CVE-2026-54053 |
Many Notes: Path Traversal via ZIP import allows arbitrary file write and stored XSS in other users' vaults |
17.09.2026 |
9.6 |
| CVE-2026-90104 |
NFSv4.1: zero referring call lists before decoding |
18.09.2026 |
9.8 |
| CVE-2026-90110 |
inetpeer: randomize RB-tree node comparison using SipHash |
18.09.2026 |
9.4 |
| CVE-2026-90151 |
NFSv4: remove callback IDR entry on client allocation failure |
18.09.2026 |
9.8 |
| CVE-2026-90173 |
smb: smbdirect: free completion queues with ib_free_cq() |
18.09.2026 |
9.8 |
| CVE-2026-90230 |
nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() |
18.09.2026 |
9.1 |
| CVE-2026-90235 |
sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE |
18.09.2026 |
9.8 |
| CVE-2026-90413 |
IB/isert: reject login PDUs declaring more data than was received |
18.09.2026 |
9.1 |
| CVE-2026-90414 |
IB/isert: reject PDUs declaring more data than was received |
18.09.2026 |
9.1 |
| CVE-2026-92489 |
xfrm: Fix skb double-free in xfrm_dev_direct_output() |
18.09.2026 |
9.8 |
| CVE-2026-86863 |
pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode |
17.09.2026 |
9.3 |
| CVE-2026-76834 |
b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key |
18.09.2026 |
9.2 |
| CVE-2026-91039 |
dynamic_oidc identities are not namespaced by connection in ash_authentication, allowing cross-connection account takeover |
17.09.2026 |
9.1 |
| CVE-2026-79752 |
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection |
17.09.2026 |
9.2 |
| CVE-2026-63472 |
Vendure: External-authentication account takeover: external login linked to a pre-existing account by email without verification |
17.09.2026 |
9.1 |
| CVE-2026-88952 |
OAuth2 sign-in attached to an existing account without an email comparison in AshAuthentication |
17.09.2026 |
9.1 |
| CVE-2026-92934 |
vm2 before 3.11.8 Sandbox Escape RCE via AggregateError |
17.09.2026 |
9.5 |
| CVE-2026-92935 |
vm2 NodeVM Remote Code Execution via Array-Shaped Require |
17.09.2026 |
9.5 |
| CVE-2026-92937 |
vm2 3.11.6 Remote Code Execution via Promise call/apply |
18.09.2026 |
10 |
| CVE-2026-92938 |
vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite |
19.09.2026 |
9.4 |
| CVE-2026-92939 |
vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine |
17.09.2026 |
9.4 |
| CVE-2026-92940 |
vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent |
17.09.2026 |
10 |
| CVE-2026-92941 |
vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation |
17.09.2026 |
10 |
| CVE-2026-92944 |
vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector |
19.09.2026 |
9.3 |
| CVE-2026-92946 |
vm2 before 3.11.7 Remote Code Execution via require.external |
17.09.2026 |
10 |
| CVE-2026-92947 |
vm2 before 3.11.7 Memory Disclosure via Buffer Pool |
17.09.2026 |
10 |
| CVE-2026-92948 |
vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test |
18.09.2026 |
9.4 |
| CVE-2026-92950 |
vm2 before 3.11.7 Sandbox Escape via CLI require |
17.09.2026 |
9.3 |
| CVE-2026-92951 |
vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver |
17.09.2026 |
9.4 |
| CVE-2026-92953 |
vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray |
18.09.2026 |
9.3 |
| CVE-2026-92954 |
vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise |
17.09.2026 |
9.2 |
| CVE-2026-92955 |
vm2 before 3.11.8 Sandbox Escape via NodeVM |
17.09.2026 |
10 |
| CVE-2026-92956 |
vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming |
17.09.2026 |
10 |
| CVE-2026-92957 |
vm2 before 3.11.7 Authentication Bypass via node: Prefix |
17.09.2026 |
9.4 |
| CVE-2026-92960 |
vm2 before 3.11.6 Process-wide State Exposure via os and dns |
17.09.2026 |
10 |
| CVE-2026-62101 |
WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability |
17.09.2026 |
9.8 |
| CVE-2026-62104 |
WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability |
19.09.2026 |
10 |
| CVE-2026-62108 |
WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability |
17.09.2026 |
9.8 |
| CVE-2026-82761 |
Magic link single-use tokens replayable via TOCTOU race in AshAuthentication |
17.09.2026 |
9.1 |
| CVE-2026-85500 |
`require_confirmed_with` is not enforced on the action and fails open on an unreadable attribute in AshAuthentication |
17.09.2026 |
9.1 |
| CVE-2026-86533 |
Revoked session accepted because the session jti is never checked in AshAuthentication and AshAuthentication Phoenix |
17.09.2026 |
9.1 |
| CVE-2026-90822 |
|
17.09.2026 |
9.8 |
| CVE-2026-90823 |
|
17.09.2026 |
9.8 |
| CVE-2026-92860 |
rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation |
19.09.2026 |
9.4 |
| CVE-2026-92913 |
AVideo Weak PRNG Activation Code Authentication Bypass |
17.09.2026 |
9.1 |
| CVE-2026-15688 |
Password Authentication Bypass Vulnerability in GX Works3 and Motion Control Setting |
17.09.2026 |
9.2 |
| CVE-2026-87796 |
Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload |
19.09.2026 |
9.8 |
| CVE-2026-61594 |
djust has an authorization bypass on the WebSocket/SSE mount path |
17.09.2026 |
9.1 |
| CVE-2026-92576 |
HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool |
17.09.2026 |
9.2 |
| CVE-2026-92578 |
WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash |
17.09.2026 |
9.2 |
| CVE-2026-75513 |
Marten: SQL injection in Marten's LINQ provider via unescaped string literals |
19.09.2026 |
9.1 |
| CVE-2026-92749 |
SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret |
17.09.2026 |
9.2 |
| CVE-2026-92785 |
Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes |
17.09.2026 |
9.2 |
| CVE-2026-92787 |
Feast through 0.66.0 Authentication Bypass via Unverified Token |
19.09.2026 |
9.3 |
| CVE-2026-92805 |
UVdesk Community Skeleton through 1.1.8 Missing Authentication on the Installation Wizard |
19.09.2026 |
9.3 |
| CVE-2026-20284 |
Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability |
18.09.2026 |
9.1 |
| CVE-2026-20332 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Access Control Vulnerabilities |
18.09.2026 |
9.9 |
| CVE-2026-76460 |
Cisco Identity Services Engine Authentication Bypass Vulnerability |
17.09.2026 |
10 |
| CVE-2026-20130 |
Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities |
18.09.2026 |
10 |
| CVE-2026-20176 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20192 |
Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities |
18.09.2026 |
10 |
| CVE-2026-20194 |
Cisco Identity Services Engine Hardening Release - Incorrect Resource Transfer Vulnerabilities |
18.09.2026 |
9.1 |
| CVE-2026-20211 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20237 |
Cisco Identity Services Engine Hardening Release - Input Validation Vulnerabilities |
18.09.2026 |
9.1 |
| CVE-2026-20242 |
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability |
18.09.2026 |
9.8 |
| CVE-2026-20322 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access Control |
18.09.2026 |
9.9 |
| CVE-2026-20324 |
Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerability |
18.09.2026 |
9.9 |
| CVE-2026-20325 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command |
18.09.2026 |
9.9 |
| CVE-2026-20326 |
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authentication for Critical Function |
18.09.2026 |
9.8 |
| CVE-2026-20329 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities |
18.09.2026 |
9.9 |
| CVE-2026-20330 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Improper Neutralization Vulnerabilities |
18.09.2026 |
9.9 |
| CVE-2026-20341 |
Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Execution Vulnerability |
18.09.2026 |
9.1 |
| CVE-2026-76423 |
Cisco ISE API Authentication Bypass Vulnerability |
17.09.2026 |
10 |
| CVE-2026-92808 |
Server-Side Request Forgery in Altium Enterprise Server UnifiedLogin Service Allows Unauthenticated System Compromise |
17.09.2026 |
10 |
| CVE-2026-89083 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
17.09.2026 |
9.3 |
| CVE-2026-89082 |
HP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File Write |
17.09.2026 |
9.3 |
| CVE-2026-73456 |
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. |
17.09.2026 |
9.2 |
| CVE-2026-91104 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
9.3 |
| CVE-2026-91106 |
HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities |
17.09.2026 |
9.3 |
| CVE-2026-92717 |
Covenant through 0.6 Missing Authentication on the CovenantHub SignalR Hub |
16.09.2026 |
9.3 |
| CVE-2026-92720 |
Kubero through 3.1.1 Unauthenticated Notifications API Access |
17.09.2026 |
9.3 |
| CVE-2026-20234 |
Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vulnerabilities |
17.09.2026 |
9.9 |
| CVE-2026-20305 |
Cisco Identity Services Engine Command Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20306 |
Cisco Identity Services Engine Command Injection Vulnerability |
17.09.2026 |
9.1 |
| CVE-2026-20307 |
Cisco Identity Services Engine Remote Code Execution Vulnerability |
17.09.2026 |
9.9 |
| CVE-2026-20331 |
Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Protection Mechanism Failure Vulnerabilities |
18.09.2026 |
9.6 |
| CVE-2026-76420 |
Cisco Secure Firewall Management Center Software Impersonated sftunnel Connection Vulnerability |
17.09.2026 |
9 |
| CVE-2026-92398 |
Ruijie RG-EW3000GX user_list_note admin os command injection |
16.09.2026 |
9.4 |
| CVE-2026-92397 |
Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection |
16.09.2026 |
9.4 |
| CVE-2025-59953 |
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy |
18.09.2026 |
9.8 |
| CVE-2026-70416 |
|
16.09.2026 |
10 |
| CVE-2026-77411 |
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr |
16.09.2026 |
9.5 |
| CVE-2026-77405 |
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser |
18.09.2026 |
9.4 |
| CVE-2026-92395 |
@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
17.09.2026 |
9.1 |
| CVE-2026-77408 |
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow |
16.09.2026 |
9.1 |
| CVE-2026-91843 |
Stack overflow in login process to the Security Management and Log Servers |
17.09.2026 |
9.8 |
| CVE-2026-73172 |
|
17.09.2026 |
9.3 |
| CVE-2026-40855 |
Command Injection in T-Mobile 5G Box IDU router via ping functionality |
16.09.2026 |
9.3 |
| CVE-2026-58146 |
Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
16.09.2026 |
9.4 |
| CVE-2026-58147 |
Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers |
16.09.2026 |
9.3 |
| CVE-2026-89846 |
scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read |
16.09.2026 |
9.1 |
| CVE-2026-89847 |
scsi: qla2xxx: Avoid double completion in async IOCB timeout |
16.09.2026 |
9.8 |
| CVE-2026-89857 |
scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject |
16.09.2026 |
9.8 |
| CVE-2026-89914 |
KVM: arm64: Sign-extend VA for range-based TLBI invalidation |
16.09.2026 |
9.3 |
| CVE-2026-89915 |
KVM: arm64: Remove VM-wide VNCR mapping counter |
16.09.2026 |
9.3 |
| CVE-2026-89916 |
KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry |
16.09.2026 |
9.3 |
| CVE-2026-89918 |
KVM: arm64: Correctly handle end of VA space TLBI invalidation |
16.09.2026 |
9.3 |
| CVE-2026-89930 |
KVM: nVMX: Service local TLB flushes on failed nested VM-Enter |
16.09.2026 |
9.3 |
| CVE-2026-89969 |
nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU |
16.09.2026 |
9.8 |
| CVE-2026-89970 |
nvmet-auth: Synchronize timeout work during SQ teardown |
16.09.2026 |
9.8 |
| CVE-2026-89972 |
nvme: add missing SRCU grace period in error path |
16.09.2026 |
9.8 |
| CVE-2026-89990 |
ceph: lock mutex in ceph_mds_check_access() |
16.09.2026 |
9.8 |
| CVE-2026-90011 |
scsi: target: iscsi: Reserve a terminator byte for the login payload |
16.09.2026 |
9.1 |
| CVE-2026-90012 |
spi: Fix DMA mapping ownership on partial map failure |
16.09.2026 |
9.8 |
| CVE-2026-90036 |
NFSD: Prevent client use-after-free during blocked-lock reaping |
16.09.2026 |
9.8 |
| CVE-2026-90037 |
NFSD: Prevent client use-after-free during close_lru reaping |
16.09.2026 |
9.8 |
| CVE-2026-90038 |
NFSD: Prevent client use-after-free during export state revocation |
16.09.2026 |
9.8 |
| CVE-2026-90042 |
ceph: properly decrypt filenames in vmalloc() buffers |
16.09.2026 |
9.8 |
| CVE-2026-90048 |
fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() |
16.09.2026 |
9.8 |
| CVE-2026-90049 |
net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() |
16.09.2026 |
9.3 |
| CVE-2026-73453 |
Security Advisory 0174 |
17.09.2026 |
9.5 |
| CVE-2026-89778 |
isofs: fix out-of-bounds page array access on empty zisofs block |
16.09.2026 |
9.8 |
| CVE-2026-89779 |
fs/ntfs3: validate ef->size covers the record's name and value |
16.09.2026 |
9.1 |
| CVE-2026-89783 |
xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full |
16.09.2026 |
9.8 |
| CVE-2026-89786 |
ext4: fix out-of-bounds read in ext4_read_inline_dir() |
16.09.2026 |
9.1 |
| CVE-2026-89788 |
ksmbd: fix tree connection use-after-free in smb2_tree_connect() |
16.09.2026 |
9.8 |
| CVE-2026-81642 |
Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY |
16.09.2026 |
9.1 |
| CVE-2026-89775 |
KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation |
16.09.2026 |
9.3 |
| CVE-2026-73461 |
Security Advisory 0163 |
17.09.2026 |
9.4 |
| CVE-2026-27546 |
Authentication Bypass in _account_log |
16.09.2026 |
9.8 |
| CVE-2026-27565 |
Remote code execution via uploading a malicious IODD file |
16.09.2026 |
9.8 |
| CVE-2026-73447 |
Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request |
17.09.2026 |
9.4 |
| CVE-2026-12793 |
JetFormBuilder <= 3.6.2 - Unauthenticated Privilege Escalation via '_jet_engine_booking_form_id' Parameter |
17.09.2026 |
9.8 |
| CVE-2026-14349 |
TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary User Email Modification via 'admin_addcustomer' AJAX Action |
16.09.2026 |
9.8 |
| CVE-2026-15638 |
Cryptographic Padding Oracle |
16.09.2026 |
9.1 |
| CVE-2026-15639 |
Reflected Cross-Site Scripting |
16.09.2026 |
9.3 |
| CVE-2026-15640 |
Authentication Bypass via SAML Response Manipulation |
16.09.2026 |
9.5 |
| CVE-2026-73807 |
mySCADA myPRO Manager Missing Authorization |
16.09.2026 |
9.3 |
| CVE-2026-78225 |
Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key |
16.09.2026 |
9.5 |
| CVE-2026-81855 |
Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key |
16.09.2026 |
9.3 |
| CVE-2026-61560 |
@zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover |
16.09.2026 |
9.8 |
| CVE-2026-61559 |
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery |
17.09.2026 |
9.6 |
| CVE-2026-61568 |
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport |
16.09.2026 |
9.6 |
| CVE-2026-68491 |
|
16.09.2026 |
9.4 |
| CVE-2026-91939 |
Cotonti 1.0.0 Comments Plugin PHP Object Injection via ci Parameter |
16.09.2026 |
9.3 |
| CVE-2026-66887 |
Missing Authorization in Digital Watchdog VMAX DVR and NVR Product Lineups |
16.09.2026 |
9.4 |
| CVE-2026-54337 |
Fireshare has Unauthenticated Argument Injection to Arbitrary File Write/Overwrite |
16.09.2026 |
9.8 |
| CVE-2026-66890 |
Use of Hard-coded Credentials in Digital Watchdog VMAX DVR and NVR Product Lineups |
16.09.2026 |
9.4 |
| CVE-2026-70748 |
|
15.09.2026 |
9.8 |
| CVE-2026-70756 |
|
15.09.2026 |
9.8 |
| CVE-2026-70757 |
|
15.09.2026 |
9.8 |
| CVE-2026-70913 |
|
15.09.2026 |
9.8 |
| CVE-2026-71133 |
|
17.09.2026 |
10 |
| CVE-2026-71163 |
|
16.09.2026 |
9.9 |
| CVE-2026-73940 |
|
15.09.2026 |
9.8 |
| CVE-2026-73944 |
|
15.09.2026 |
9.1 |
| CVE-2026-73945 |
|
16.09.2026 |
9.9 |
| CVE-2026-73946 |
|
16.09.2026 |
9.1 |
| CVE-2026-73947 |
|
15.09.2026 |
9.8 |
| CVE-2026-73948 |
|
16.09.2026 |
9.9 |
| CVE-2026-73950 |
|
15.09.2026 |
9.8 |
| CVE-2026-73952 |
|
15.09.2026 |
9.1 |
| CVE-2026-73953 |
|
15.09.2026 |
9.8 |
| CVE-2026-73956 |
|
15.09.2026 |
9.8 |
| CVE-2026-73957 |
|
16.09.2026 |
9.3 |
| CVE-2026-73961 |
|
15.09.2026 |
9.8 |
| CVE-2026-73962 |
|
16.09.2026 |
9.6 |
| CVE-2026-73963 |
|
15.09.2026 |
9.8 |
| CVE-2026-82994 |
|
15.09.2026 |
9.8 |
| CVE-2026-82995 |
|
15.09.2026 |
9.8 |
| CVE-2026-82997 |
|
16.09.2026 |
9.9 |
| CVE-2026-82998 |
|
16.09.2026 |
9.9 |
| CVE-2026-82999 |
|
16.09.2026 |
9.9 |
| CVE-2026-83000 |
|
15.09.2026 |
9.8 |
| CVE-2026-83001 |
|
16.09.2026 |
9.1 |
| CVE-2026-83006 |
|
16.09.2026 |
9.1 |
| CVE-2026-83020 |
|
17.09.2026 |
10 |
| CVE-2026-83021 |
|
17.09.2026 |
10 |
| CVE-2026-83027 |
|
16.09.2026 |
9.3 |
| CVE-2026-83029 |
|
16.09.2026 |
9.6 |
| CVE-2026-83031 |
|
16.09.2026 |
9.9 |
| CVE-2026-83035 |
|
15.09.2026 |
9.8 |
| CVE-2026-83036 |
|
15.09.2026 |
9.8 |
| CVE-2026-83037 |
|
15.09.2026 |
9.8 |
| CVE-2026-83038 |
|
16.09.2026 |
9.9 |
| CVE-2026-83039 |
|
16.09.2026 |
9.9 |
| CVE-2026-83040 |
|
16.09.2026 |
9.6 |
| CVE-2026-83042 |
|
15.09.2026 |
9.8 |
| CVE-2026-83043 |
|
16.09.2026 |
9.6 |
| CVE-2026-83054 |
|
15.09.2026 |
9.8 |
| CVE-2026-83055 |
|
17.09.2026 |
9.9 |
| CVE-2026-83056 |
|
17.09.2026 |
9.9 |
| CVE-2026-83057 |
|
17.09.2026 |
9.9 |
| CVE-2026-83058 |
|
17.09.2026 |
9.9 |
| CVE-2026-83059 |
|
17.09.2026 |
10 |
| CVE-2026-83060 |
|
15.09.2026 |
9.8 |
| CVE-2026-83061 |
|
15.09.2026 |
9.8 |
| CVE-2026-83062 |
|
15.09.2026 |
9.8 |
| CVE-2026-83064 |
|
17.09.2026 |
9.1 |
| CVE-2026-83066 |
|
15.09.2026 |
9.8 |
| CVE-2026-83094 |
|
15.09.2026 |
9.8 |
| CVE-2026-83095 |
|
15.09.2026 |
9.8 |
| CVE-2026-83098 |
|
15.09.2026 |
9.8 |
| CVE-2026-83099 |
|
15.09.2026 |
10 |
| CVE-2026-83100 |
|
15.09.2026 |
9.8 |
| CVE-2026-83103 |
|
17.09.2026 |
9.1 |
| CVE-2026-83104 |
|
15.09.2026 |
9.1 |
| CVE-2026-83105 |
|
17.09.2026 |
9 |
| CVE-2026-83107 |
|
17.09.2026 |
9.1 |
| CVE-2026-83108 |
|
15.09.2026 |
9.8 |
| CVE-2026-83149 |
|
15.09.2026 |
9.1 |
| CVE-2026-83151 |
|
15.09.2026 |
9.8 |
| CVE-2026-83154 |
|
15.09.2026 |
9.1 |
| CVE-2026-83196 |
|
17.09.2026 |
9.1 |
| CVE-2026-83197 |
|
15.09.2026 |
9.1 |
| CVE-2026-83201 |
|
15.09.2026 |
9.1 |
| CVE-2026-83202 |
|
15.09.2026 |
9.1 |
| CVE-2026-83229 |
|
17.09.2026 |
9.1 |
| CVE-2026-83232 |
|
15.09.2026 |
9.8 |
| CVE-2026-83260 |
|
17.09.2026 |
9.1 |
| CVE-2026-83261 |
|
15.09.2026 |
9.8 |
| CVE-2026-83268 |
|
17.09.2026 |
9.1 |
| CVE-2026-83269 |
|
15.09.2026 |
9.8 |
| CVE-2026-83282 |
|
17.09.2026 |
9.9 |
| CVE-2026-83283 |
|
15.09.2026 |
9.8 |
| CVE-2026-83327 |
|
15.09.2026 |
9.8 |
| CVE-2026-83339 |
|
15.09.2026 |
9.8 |
| CVE-2026-83355 |
|
15.09.2026 |
9.8 |
| CVE-2026-83452 |
|
15.09.2026 |
9.8 |
| CVE-2026-83462 |
|
15.09.2026 |
9.8 |
| CVE-2026-87128 |
|
15.09.2026 |
9.1 |
| CVE-2026-87129 |
|
15.09.2026 |
9.1 |
| CVE-2026-87170 |
|
15.09.2026 |
9.1 |
| CVE-2026-87172 |
|
17.09.2026 |
9.9 |
| CVE-2026-87173 |
|
15.09.2026 |
9.1 |
| CVE-2026-87175 |
|
15.09.2026 |
9.1 |
| CVE-2026-87176 |
|
15.09.2026 |
9.1 |
| CVE-2026-87184 |
|
15.09.2026 |
9.8 |
| CVE-2026-87186 |
|
17.09.2026 |
9.6 |
| CVE-2026-87188 |
|
15.09.2026 |
9.8 |
| CVE-2026-87189 |
|
17.09.2026 |
9.1 |
| CVE-2026-87214 |
|
17.09.2026 |
9.1 |
| CVE-2026-87217 |
|
15.09.2026 |
9.1 |
| CVE-2026-87223 |
|
18.09.2026 |
9.1 |
| CVE-2026-87230 |
|
18.09.2026 |
10 |
| CVE-2026-89040 |
Tencent Mass Service Engine in Cluster (MSEC) path traversal |
15.09.2026 |
9.3 |
| CVE-2026-73458 |
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou |
15.09.2026 |
9.2 |
| CVE-2026-76669 |
Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator |
15.09.2026 |
9.9 |
| CVE-2026-76670 |
Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator |
15.09.2026 |
9.9 |
| CVE-2026-76672 |
Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator |
20.09.2026 |
9.9 |
| CVE-2026-76673 |
Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator |
15.09.2026 |
9.8 |
| CVE-2026-76674 |
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways |
15.09.2026 |
9.8 |
| CVE-2026-76675 |
Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways |
15.09.2026 |
9.1 |
| CVE-2026-69204 |
Http4s: Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling) |
15.09.2026 |
9.2 |
| CVE-2026-19773 |
libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability |
16.09.2026 |
9.8 |
| CVE-2026-45579 |
DIRAC: RCE in RequestManager due to eval on untrusted input |
15.09.2026 |
9.9 |
| CVE-2026-53459 |
Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints |
17.09.2026 |
9.3 |
| CVE-2026-61667 |
DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval |
15.09.2026 |
9.9 |
| CVE-2026-12351 |
IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection |
16.09.2026 |
9.8 |
| CVE-2023-54398 |
Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet |
15.09.2026 |
9.3 |
| CVE-2024-58385 |
Yonyou U8 CRM SQL Injection via fillbacksettingedit.php |
15.09.2026 |
9.3 |
| CVE-2026-46488 |
motionEye: Authentication possible via password hash |
17.09.2026 |
9.1 |
| CVE-2026-53710 |
MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server |
15.09.2026 |
10 |
| CVE-2026-89026 |
Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate |
17.09.2026 |
9.3 |
| CVE-2026-89022 |
BookStack < 26.05.5 Authentication Bypass via Social Login Provider Confusion |
15.09.2026 |
9.1 |
| CVE-2026-77866 |
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts |
15.09.2026 |
9 |
| CVE-2026-77972 |
safeurl validated address is not bound to the request, allowing DNS rebinding |
15.09.2026 |
9 |
| CVE-2026-55211 |
surfio IRAP header size fields cause out-of-bounds reads |
17.09.2026 |
9.8 |
| CVE-2023-54397 |
Tornado before 6.3.3 HTTP Request Smuggling via Content-Length |
17.09.2026 |
9 |
| CVE-2024-14029 |
Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding |
15.09.2026 |
9 |
| CVE-2026-91931 |
Flowise before 3.1.4 Remote Code Execution via Custom MCP npx |
17.09.2026 |
9 |
| CVE-2026-91932 |
Flowise before 3.1.4 Remote Code Execution via cwd Parameter |
15.09.2026 |
9 |
| CVE-2026-91949 |
FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass |
17.09.2026 |
9.2 |
| CVE-2026-91988 |
atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP |
15.09.2026 |
9.2 |
| CVE-2026-61549 |
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend |
16.09.2026 |
9 |
| CVE-2026-63696 |
|
16.09.2026 |
9.1 |
| CVE-2026-55158 |
Conflibot: Command injection via crafted pull request branch names under pull_request_target |
17.09.2026 |
9.1 |
| CVE-2026-63695 |
|
16.09.2026 |
9.8 |
| CVE-2026-39919 |
Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter |
20.09.2026 |
9.3 |
| CVE-2026-46495 |
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI |
15.09.2026 |
9.2 |
| CVE-2026-59971 |
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) |
15.09.2026 |
10 |
| CVE-2026-77179 |
Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback |
15.09.2026 |
9.4 |
| CVE-2026-89308 |
Arbitrary command execution in TrxTimeATTENDANCE |
15.09.2026 |
9.3 |
| CVE-2026-91995 |
pig before 4.1.0 Unverified Password Change via /register/password |
18.09.2026 |
9.3 |
| CVE-2026-91998 |
Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp |
17.09.2026 |
9.4 |
| CVE-2026-52824 |
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
16.09.2026 |
9.1 |
| CVE-2026-57147 |
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery |
17.09.2026 |
9.8 |
| CVE-2026-57139 |
PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
17.09.2026 |
9.8 |
| CVE-2026-57140 |
PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
15.09.2026 |
9.4 |
| CVE-2026-57148 |
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) |
16.09.2026 |
9.8 |
| CVE-2026-57138 |
PraisonAI codeMode sandbox escape via Function constructor |
17.09.2026 |
9.9 |
| CVE-2026-57141 |
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
15.09.2026 |
9.8 |
| CVE-2026-48717 |
OpenAM OAuth Authorization Bypass via PKCE Challenge |
15.09.2026 |
9.1 |
| CVE-2026-45051 |
OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage |
15.09.2026 |
9.2 |
| CVE-2026-46619 |
OpenAM Authentication Bypass via MSISDN LDAP Injection |
15.09.2026 |
9.3 |
| CVE-2026-62263 |
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass |
15.09.2026 |
9.2 |
| CVE-2026-45052 |
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints |
16.09.2026 |
9.3 |
| CVE-2026-62379 |
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback |
15.09.2026 |
9.8 |
| CVE-2026-90711 |
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
15.09.2026 |
9.1 |
| CVE-2026-91003 |
D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow |
15.09.2026 |
9.4 |
| CVE-2026-91001 |
D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow |
15.09.2026 |
9.4 |
| CVE-2026-90847 |
EFM ipTIME C200E System Setup iux_set.cgi os command injection |
15.09.2026 |
9.4 |
| CVE-2026-12944 |
Incomplete Security Scanner Blocklist Enables Network-Based Code Execution |
16.09.2026 |
9.6 |
| CVE-2026-67399 |
|
15.09.2026 |
9.3 |
| CVE-2026-53713 |
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure |
16.09.2026 |
9.1 |
| CVE-2026-54333 |
UEFI Firmware Parser: Stack out-of-bounds write in tiano decompressor MakeTable |
15.09.2026 |
9.8 |
| CVE-2026-54334 |
UEFI Firmware Parser: Heap out-of-bounds write in tiano decompressor `ReadCLen` |
16.09.2026 |
9.8 |
| CVE-2026-50006 |
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode |
15.09.2026 |
9.1 |
| CVE-2026-55209 |
resdata insufficiently validates untrusted GRDECL files |
14.09.2026 |
9.8 |
| CVE-2026-16338 |
DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
14.09.2026 |
9.9 |
| CVE-2026-59178 |
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade |
14.09.2026 |
9.8 |
| CVE-2026-90942 |
Casdoor through 4.4.0 Private Key Exposure via Certificate Endpoints |
14.09.2026 |
9.3 |
| CVE-2026-90945 |
Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret |
16.09.2026 |
9.3 |
| CVE-2026-57578 |
DotVVM: Missing authorization in AuthorizeActionFilter |
14.09.2026 |
9.2 |
| CVE-2026-20353 |
Cisco Secure Email Gateway Security Hardening Release |
15.09.2026 |
9.8 |
| CVE-2026-76440 |
Cisco Secure Email Gateway Security Hardening Release |
15.09.2026 |
9.8 |
| CVE-2026-76441 |
Cisco Secure Email Gateway Security Hardening Release |
15.09.2026 |
9.8 |
| CVE-2026-76443 |
Cisco Secure Email Gateway Security Hardening Release |
15.09.2026 |
9.8 |
| CVE-2026-76461 |
Cisco Secure Email Gateway SQL Injection Vulnerability |
18.09.2026 |
9.8 |
| CVE-2026-61534 |
Yayson: Prototype pollution in the Store/LegacyStore deserialization |
14.09.2026 |
9.1 |
| CVE-2026-90943 |
parallax filament-comments through 3.0.0 Stored XSS via Comment Body |
14.09.2026 |
9.3 |
| CVE-2026-57124 |
PraisonAI UI MCP connect endpoint allows unauthenticated local command execution |
14.09.2026 |
9.8 |
| CVE-2026-57127 |
praisonai: recipe serve auth middleware silently disables itself when no secret is set |
14.09.2026 |
9.8 |
| CVE-2026-57131 |
praisonai: Jobs API exposes agent-execution endpoints with no authentication |
14.09.2026 |
9.8 |
| CVE-2026-57145 |
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation |
14.09.2026 |
9.1 |
| CVE-2026-57123 |
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in |
14.09.2026 |
9.8 |
| CVE-2026-57125 |
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass |
14.09.2026 |
9.8 |
| CVE-2026-82434 |
Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs |
14.09.2026 |
10 |
| CVE-2026-90961 |
MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials |
14.09.2026 |
9.3 |
| CVE-2026-90937 |
froxlor before 2.2.5 nginx/Apache Configuration Injection via subdomain redirect URL |
16.09.2026 |
9.4 |
| CVE-2026-12258 |
Inadequate access control in the Hiperdino REST API |
14.09.2026 |
9.2 |
| CVE-2026-90919 |
LightLLM through 1.2.0 Unauthenticated Remote Code Execution via Config Server Pickle Deserialization |
14.09.2026 |
9.3 |
| CVE-2026-21391 |
Improper Claim Validation in PingAM OIDC Provider |
14.09.2026 |
9.5 |
| CVE-2026-90898 |
Bifrost unauthenticated remote code execution via MCP stdio client registration |
14.09.2026 |
9.8 |
| CVE-2026-90703 |
D-Link DWR-M921 formDiskCreateShare system os command injection |
15.09.2026 |
9.4 |
| CVE-2026-90702 |
D-Link DWR-M921 formDiskFormat system os command injection |
15.09.2026 |
9.4 |
| CVE-2026-90699 |
D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection |
14.09.2026 |
9.4 |
| CVE-2026-90693 |
D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow |
15.09.2026 |
9.4 |
| CVE-2026-90692 |
D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow |
15.09.2026 |
9.4 |
| CVE-2026-85192 |
Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 |
14.09.2026 |
9.4 |
| CVE-2026-90680 |
D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow |
16.09.2026 |
9.4 |
| CVE-2026-90607 |
Totolink A3002MU boa formNewSchedule buffer overflow |
14.09.2026 |
9.4 |
| CVE-2026-90608 |
Totolink A3002MU boa formPortFw buffer overflow |
16.09.2026 |
9.4 |
| CVE-2026-90606 |
Totolink A3002MU boa formIpv6Setup buffer overflow |
15.09.2026 |
9.4 |
| CVE-2026-90605 |
Totolink A3002MU boa formFilter buffer overflow |
15.09.2026 |
9.4 |
| CVE-2026-81648 |
CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX Router |
14.09.2026 |
10 |
| CVE-2026-90561 |
Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG |
18.09.2026 |
9.3 |
| CVE-2026-90562 |
LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key |
16.09.2026 |
9.2 |