| CVE-2026-58196 |
ToolHive: SSRF in remote MCP server authentication discovery (host-side, bypasses container isolation) |
15.09.2026 |
4.7 |
| CVE-2026-59965 |
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission |
15.09.2026 |
7.1 |
| CVE-2026-88621 |
|
15.09.2026 |
|
| CVE-2026-54450 |
ToolHive: SSRF guard misses IPv6 NAT64 ranges (64:ff9b::/96, 64:ff9b:1::/48), allowing metadata/internal access behind a NAT64 gateway |
15.09.2026 |
|
| CVE-2026-55770 |
OpenBao: LDAPi ldaputil (wrong escape func) |
15.09.2026 |
6.8 |
| CVE-2026-55774 |
OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808 |
15.09.2026 |
|
| CVE-2026-55776 |
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types |
15.09.2026 |
6.5 |
| CVE-2026-55887 |
MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway |
15.09.2026 |
|
| CVE-2026-59157 |
webhookd: Unrestricted HTTP Header to Shell Variable Injection |
15.09.2026 |
6.5 |
| CVE-2026-44163 |
fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry` |
15.09.2026 |
5.3 |
| CVE-2026-54724 |
Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmation endpoint |
15.09.2026 |
6.1 |
| CVE-2026-55591 |
Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints |
15.09.2026 |
5.8 |
| CVE-2026-55630 |
Kiwi TCMS: Stored XSS via javascript: URI in extra_link field (TestPlan & TestCase) |
15.09.2026 |
0 |
| CVE-2026-55775 |
OpenBao's System Backend allows Unauthorized Management of the containing Namespace |
15.09.2026 |
|
| CVE-2026-55864 |
GeoNetwork: Unauthenticaded Server-Side Request Forgery in SLD Tool |
15.09.2026 |
|
| CVE-2026-77866 |
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts |
15.09.2026 |
|
| CVE-2026-77972 |
safeurl validated address is not bound to the request, allowing DNS rebinding |
15.09.2026 |
|
| CVE-2026-19407 |
GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK |
15.09.2026 |
|
| CVE-2026-37152 |
|
15.09.2026 |
|
| CVE-2026-44282 |
Election question titles allow stored script execution |
15.09.2026 |
4.8 |
| CVE-2026-55211 |
surfio IRAP header size fields cause out-of-bounds reads |
15.09.2026 |
|
| CVE-2026-55636 |
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected |
15.09.2026 |
5.7 |
| CVE-2026-87792 |
Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme |
15.09.2026 |
|
| CVE-2026-87793 |
Reflected XSS in WordPress theme design-scuole-wordpress-theme |
15.09.2026 |
|
| CVE-2026-88620 |
|
15.09.2026 |
|
| CVE-2026-89307 |
HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme |
15.09.2026 |
|
| CVE-2026-91849 |
WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload |
15.09.2026 |
|
| CVE-2023-54397 |
Tornado before 6.3.3 HTTP Request Smuggling via Content-Length |
15.09.2026 |
|
| CVE-2024-14029 |
Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding |
15.09.2026 |
|
| CVE-2024-58384 |
Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient |
15.09.2026 |
|
| CVE-2026-47215 |
Singularity: Incorrect path matching for 'limit container paths' directive |
15.09.2026 |
4.8 |
| CVE-2026-50024 |
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via a malicious .git server |
15.09.2026 |
5.3 |
| CVE-2026-54076 |
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221) |
15.09.2026 |
8.1 |
| CVE-2026-54077 |
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users |
15.09.2026 |
7.1 |
| CVE-2026-55701 |
OpenTelemetry githubreceiver silently ignores configured required_headers authentication |
15.09.2026 |
|
| CVE-2026-55828 |
qbee transport: Symlink-chain path traversal in tar extraction (one level outside destination) |
15.09.2026 |
|
| CVE-2026-59973 |
mcp-from-openapi: Bypass of OpenAPI external $ref SSRF fix in latest FrontMCP and mcp-from-openapi |
15.09.2026 |
8.5 |
| CVE-2026-65831 |
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read |
15.09.2026 |
7.7 |
| CVE-2026-85013 |
Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters |
15.09.2026 |
|
| CVE-2026-87791 |
Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme |
15.09.2026 |
|
| CVE-2026-88619 |
|
15.09.2026 |
|
| CVE-2026-91848 |
WuzhiCMS index.php getDataOfJson sql injection |
15.09.2026 |
|
| CVE-2026-91929 |
Flowise before 3.1.4 Cross-Tenant Authorization Bypass |
15.09.2026 |
7.1 |
| CVE-2026-91930 |
Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover |
15.09.2026 |
7.5 |
| CVE-2026-91931 |
Flowise before 3.1.4 Remote Code Execution via Custom MCP npx |
15.09.2026 |
8.5 |
| CVE-2026-91932 |
Flowise before 3.1.4 Remote Code Execution via cwd Parameter |
15.09.2026 |
8.5 |
| CVE-2026-91933 |
Flowise before 3.1.4 Authorization Bypass via openai-realtime |
15.09.2026 |
7.1 |
| CVE-2026-91934 |
Flowise before 3.1.4 Remote Code Execution via SQL Database Chain |
15.09.2026 |
8.8 |
| CVE-2026-91935 |
Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes |
15.09.2026 |
8.3 |
| CVE-2026-91936 |
Flowise before 3.1.4 Script Injection via Docker Workflows |
15.09.2026 |
6.8 |
| CVE-2026-91937 |
Flowise before 3.1.4 NoSQL Injection via sessionId |
15.09.2026 |
7.5 |
| CVE-2026-91938 |
Flowise before 3.1.4 Server-Side Request Forgery via document loaders |
15.09.2026 |
7.1 |
| CVE-2026-91940 |
crawl4ai before 0.9.3 Arbitrary File Write via PDFContentScrapingStrategy |
15.09.2026 |
|
| CVE-2026-91941 |
Crawl4AI before 0.9.3 Denial of Service via PDFContentScrapingStrategy |
15.09.2026 |
|
| CVE-2026-91942 |
crawl4ai before 0.9.3 Cross-Site Scripting via innerHTML |
15.09.2026 |
|
| CVE-2026-91943 |
Crawl4AI before 0.9.3 SSRF via PDFContentScrapingStrategy |
15.09.2026 |
|
| CVE-2026-91944 |
crawl4ai before 0.9.3 DOM-based XSS via Playground UI |
15.09.2026 |
|
| CVE-2026-91945 |
FreeRDP before 3.31.0 Out-of-bounds Read via Smartcard ATR |
15.09.2026 |
|
| CVE-2026-91946 |
FreeRDP before 3.31.0 Information Disclosure via RDPGFX ResetGraphics |
15.09.2026 |
|
| CVE-2026-91947 |
FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC |
15.09.2026 |
|
| CVE-2026-91948 |
FreeRDP before 3.31.0 Out-of-bounds Write via SHOW_PROTOCOL |
15.09.2026 |
|
| CVE-2026-91949 |
FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass |
15.09.2026 |
|
| CVE-2026-91950 |
FreeRDP before 3.31.0 Out-of-Bounds Read via UINT32 Wraparound |
15.09.2026 |
|
| CVE-2026-91951 |
FreeRDP 3.14.0 through 3.30.0 Out-of-bounds Write via urbdrc |
15.09.2026 |
|
| CVE-2026-91952 |
FreeRDP before 3.31.0 Denial of Service via pool_decode_rect |
15.09.2026 |
|
| CVE-2026-91953 |
FreeRDP before 3.31.0 Heap Buffer Overflow via LB_LOAD_BALANCE_INFO |
15.09.2026 |
|
| CVE-2026-91954 |
FreeRDP before 3.31.0 NULL Pointer Dereference via NSCodec |
15.09.2026 |
|
| CVE-2026-91955 |
FreeRDP before 3.31.0 Denial of Service via Desktop Dimensions |
15.09.2026 |
|
| CVE-2026-91956 |
FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC |
15.09.2026 |
|
| CVE-2026-91957 |
FreeRDP before 3.31.0 Use-After-Free via smartcard worker |
15.09.2026 |
|
| CVE-2026-91958 |
FreeRDP 3.11.0 through 3.30.0 Heap Buffer Overflow via Monitor Index |
15.09.2026 |
|
| CVE-2026-91959 |
FreeRDP before 3.31.0 Buffer Over-read via RTS Gateway |
15.09.2026 |
6.5 |
| CVE-2026-91960 |
FreeRDP before 3.31.0 Integer Overflow Double Free |
15.09.2026 |
6.5 |
| CVE-2026-91961 |
FreeRDP before 3.31.0 Denial of Service via URBDRC |
15.09.2026 |
|
| CVE-2026-91962 |
FreeRDP before 3.31.0 Integer Overflow via audin Apple backends |
15.09.2026 |
|
| CVE-2026-91963 |
FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc |
15.09.2026 |
|
| CVE-2026-91964 |
FreeRDP 2.0.0 through 3.30.0 Heap Buffer Overflow via RoutingToken |
15.09.2026 |
|
| CVE-2026-91965 |
WWBN AVideo through 29.0 Broken Access Control via Live Endpoints |
15.09.2026 |
|
| CVE-2026-91966 |
AVideo through 29.0 Unauthenticated SSRF via Host Header |
15.09.2026 |
|
| CVE-2026-91967 |
AVideo through 29.0 Blind SSRF via getHeaderContentTypeFromURL |
15.09.2026 |
|
| CVE-2026-91968 |
vikunja before 2.6.0 Denial of Service via unbounded filter recursion |
15.09.2026 |
6.5 |
| CVE-2026-91969 |
vikunja before 2.6.0 Resource Exhaustion via CSV Migration |
15.09.2026 |
6.5 |
| CVE-2026-91970 |
Vikunja before 2.6.0 Resource Exhaustion via Planka Migration |
15.09.2026 |
6.5 |
| CVE-2026-91971 |
Vikunja before 2.6.0 Denial of Service via Avatar Upload |
15.09.2026 |
|
| CVE-2026-91972 |
Vikunja before 2.6.0 Authentication Bypass via Unthrottled API |
15.09.2026 |
|
| CVE-2026-91973 |
Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth |
15.09.2026 |
|
| CVE-2026-91979 |
Vikunja before 2.6.0 Denial of Service via Decompression Bomb |
15.09.2026 |
6.5 |
| CVE-2026-91980 |
vikunja before 2.6.0 Team Enumeration via Project Share |
15.09.2026 |
4.3 |
| CVE-2026-91981 |
Vikunja before 2.6.0 User Enumeration via v2 API |
15.09.2026 |
4.3 |
| CVE-2026-91982 |
Vikunja before 2.6.0 TOTP Secret Disclosure via API |
15.09.2026 |
4.3 |
| CVE-2026-91983 |
Vikunja before 2.6.0 API Token Scope Bypass via expand Parameter |
15.09.2026 |
|
| CVE-2026-91984 |
Vikunja before 2.6.0 Broken Object-Level Authorization via task-position |
15.09.2026 |
|
| CVE-2026-91985 |
Vikunja before 2.6.0 Privilege Escalation via Link Share Hash |
15.09.2026 |
|
| CVE-2026-91986 |
gitoxide gix-transport before 0.59.2 CR/LF/NUL Injection |
15.09.2026 |
|
| CVE-2026-91987 |
atomic-agents-stack before 1.1.0 Cost Guardrail Bypass via Unknown Model |
15.09.2026 |
|
| CVE-2026-91988 |
atomic-agents-stack before 1.1.0 Remote Code Execution via HTTP MCP |
15.09.2026 |
|
| CVE-2026-91989 |
atomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.py |
15.09.2026 |
|
| CVE-2026-91990 |
Tornado before 6.5.8 Memory Amplification DoS via multipart |
15.09.2026 |
|
| CVE-2026-91991 |
Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs |
15.09.2026 |
|
| CVE-2026-91992 |
Tornado before 6.5.7 Credential Leak via Handle Reuse |
15.09.2026 |
|
| CVE-2026-55178 |
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data |
15.09.2026 |
7.5 |
| CVE-2026-88618 |
|
15.09.2026 |
|
| CVE-2026-91842 |
OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserialization |
15.09.2026 |
|
| CVE-2026-50166 |
Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured |
15.09.2026 |
|
| CVE-2026-52724 |
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured |
15.09.2026 |
|
| CVE-2026-61549 |
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend |
15.09.2026 |
|
| CVE-2026-63696 |
|
15.09.2026 |
9.1 |
| CVE-2026-47780 |
free5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistence |
15.09.2026 |
|
| CVE-2026-55158 |
Conflibot: Command injection via crafted pull request branch names under pull_request_target |
15.09.2026 |
9.1 |
| CVE-2026-55617 |
Hydro: Insufficient session expiration when recreating sessions |
15.09.2026 |
|
| CVE-2026-63695 |
|
15.09.2026 |
9.8 |
| CVE-2026-79303 |
|
15.09.2026 |
|
| CVE-2026-79551 |
|
15.09.2026 |
|
| CVE-2026-91836 |
OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factors |
15.09.2026 |
|
| CVE-2026-48737 |
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs |
15.09.2026 |
4.9 |
| CVE-2026-48987 |
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager |
15.09.2026 |
6.5 |
| CVE-2026-49446 |
Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel in Cosmos-Server |
15.09.2026 |
6.1 |
| CVE-2026-53957 |
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint |
15.09.2026 |
7.7 |
| CVE-2026-53966 |
XWiki Platform: Privilege escalation from edit to script right through Live Data editing |
15.09.2026 |
|
| CVE-2026-54254 |
Cyberdrop-DL: Pixeldrain API key shared with unverified thirdparty sites |
15.09.2026 |
|
| CVE-2026-55650 |
Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure |
15.09.2026 |
4.4 |
| CVE-2026-79425 |
|
15.09.2026 |
|
| CVE-2026-88617 |
|
15.09.2026 |
|
| CVE-2026-25825 |
|
15.09.2026 |
|
| CVE-2026-25826 |
|
15.09.2026 |
|
| CVE-2026-39919 |
Ghostscript < 10.08.0 Heap Buffer Overflow via JPEG 2000 Output Adapter |
15.09.2026 |
|
| CVE-2026-54167 |
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header |
15.09.2026 |
8.2 |
| CVE-2026-54168 |
Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution |
15.09.2026 |
6.5 |
| CVE-2026-57586 |
CodeRAG: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution |
15.09.2026 |
8.6 |
| CVE-2026-88616 |
|
15.09.2026 |
|
| CVE-2026-90439 |
NGINX ngx_http_v3_module vulnerability |
15.09.2026 |
6.5 |
| CVE-2026-25827 |
|
15.09.2026 |
|
| CVE-2026-46495 |
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI |
15.09.2026 |
|
| CVE-2026-48722 |
Nextflow: Incorrect default permissions in the nextflow auth login command |
15.09.2026 |
5.5 |
| CVE-2026-49254 |
Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth |
15.09.2026 |
|
| CVE-2026-54637 |
Dragonfly scheduler v1 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile |
15.09.2026 |
|
| CVE-2026-59971 |
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure) |
15.09.2026 |
10 |
| CVE-2026-89025 |
Hirschmann HiOS Switch Platform DoS via Malformed HTTP Request |
15.09.2026 |
|
| CVE-2026-90650 |
MotoPress Hotel Booking <= 6.2.4 - Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id' |
15.09.2026 |
7.2 |
| CVE-2026-91835 |
OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflict |
15.09.2026 |
|
| CVE-2026-92082 |
Payara Server is vulnerable to brute-force login attacks due to the absence of a limit on failed login attempts |
15.09.2026 |
|
| CVE-2026-16140 |
OpenBMC IPMI Privilege Escalation via Retargeted RAKP 1 |
15.09.2026 |
8.8 |
| CVE-2026-16141 |
OpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge Value |
15.09.2026 |
8.1 |
| CVE-2026-77179 |
Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback |
15.09.2026 |
|
| CVE-2026-14805 |
Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX |
15.09.2026 |
8.8 |
| CVE-2026-15609 |
Bridge - Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute |
15.09.2026 |
6.4 |
| CVE-2026-92074 |
Mitigation bypass in the Popup Blocker component |
15.09.2026 |
|
| CVE-2026-92075 |
Mitigation bypass in the Networking component |
15.09.2026 |
|
| CVE-2026-92076 |
Incorrect boundary conditions in the Networking component |
15.09.2026 |
|
| CVE-2026-92077 |
Denial-of-service in the SVG component |
15.09.2026 |
|
| CVE-2026-92078 |
Denial-of-service in the Security component |
15.09.2026 |
|
| CVE-2026-92079 |
Mitigation bypass in the Widget: Win32 component |
15.09.2026 |
|
| CVE-2026-92005 |
Use-after-free in the Audio/Video: Web Codecs component |
15.09.2026 |
|
| CVE-2026-92006 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92007 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92008 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92009 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92010 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92011 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92012 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92013 |
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92014 |
Privilege escalation due to incorrect boundary conditions in the Graphics component |
15.09.2026 |
|
| CVE-2026-92015 |
Privilege escalation in the WebExtensions component |
15.09.2026 |
|
| CVE-2026-92016 |
Use-after-free in the Disability Access APIs component |
15.09.2026 |
|
| CVE-2026-92017 |
Privilege escalation in the DOM: Service Workers component |
15.09.2026 |
|
| CVE-2026-92018 |
Sandbox escape in the DOM: Core & HTML component |
15.09.2026 |
|
| CVE-2026-92019 |
Mitigation bypass in the Remote Settings Client component |
15.09.2026 |
|
| CVE-2026-92020 |
Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component |
15.09.2026 |
|
| CVE-2026-92021 |
Use-after-free in the JavaScript Engine: JIT component |
15.09.2026 |
|
| CVE-2026-92022 |
Use-after-free in the DOM: HTML Parser component |
15.09.2026 |
|
| CVE-2026-92023 |
Use-after-free in the XML component |
15.09.2026 |
|
| CVE-2026-92024 |
Use-after-free in the SVG component |
15.09.2026 |
|
| CVE-2026-92025 |
Use-after-free in the DOM: Navigation component |
15.09.2026 |
|
| CVE-2026-92026 |
Use-after-free in the Networking component |
15.09.2026 |
|
| CVE-2026-92027 |
Use-after-free in the DOM: Streams component |
15.09.2026 |
|
| CVE-2026-92028 |
Use-after-free in the DOM: Core & HTML component |
15.09.2026 |
|
| CVE-2026-92029 |
Use-after-free in the SVG component |
15.09.2026 |
|
| CVE-2026-92030 |
Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component |
15.09.2026 |
|
| CVE-2026-92031 |
Information disclosure in the Graphics: ImageLib component |
15.09.2026 |
|
| CVE-2026-92032 |
Sandbox escape due to invalid pointer in the Graphics component |
15.09.2026 |
|
| CVE-2026-92033 |
Privilege escalation in Firefox for Android |
15.09.2026 |
|
| CVE-2026-92034 |
Site isolation issue in the Graphics component |
15.09.2026 |
|
| CVE-2026-92035 |
Sandbox escape due to incorrect boundary conditions in the Graphics component |
15.09.2026 |
|
| CVE-2026-92036 |
Incorrect boundary conditions in the Networking: HTTP component |
15.09.2026 |
|
| CVE-2026-92037 |
Incorrect boundary conditions in the DOM: Animation component |
15.09.2026 |
|
| CVE-2026-92038 |
Mitigation bypass in the Remote Settings Client component |
15.09.2026 |
|
| CVE-2026-92039 |
Mitigation bypass in the DOM: Notifications component |
15.09.2026 |
|
| CVE-2026-92040 |
Use-after-free in the JavaScript: WebAssembly component |
15.09.2026 |
|
| CVE-2026-92041 |
Mitigation bypass in the DOM: Networking component |
15.09.2026 |
|
| CVE-2026-92042 |
Race condition in the DOM: Content Processes component |
15.09.2026 |
|
| CVE-2026-92043 |
Privilege escalation due to incorrect boundary conditions in the Audio/Video component |
15.09.2026 |
|
| CVE-2026-92044 |
Information disclosure in the Networking: HTTP component |
15.09.2026 |
|
| CVE-2026-92045 |
Sandbox escape due to incorrect boundary conditions in the WebRTC component |
15.09.2026 |
|
| CVE-2026-92046 |
Use-after-free in the Graphics component |
15.09.2026 |
|
| CVE-2026-92047 |
Privilege escalation in the Crash Reporting component |
15.09.2026 |
|
| CVE-2026-92048 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component |
15.09.2026 |
|
| CVE-2026-92049 |
Use-after-free in the Widget: Win32 component |
15.09.2026 |
|
| CVE-2026-92050 |
Sandbox escape due to race condition in the XPConnect component |
15.09.2026 |
|
| CVE-2026-92051 |
Spoofing issue due to invalid pointer in the Graphics component |
15.09.2026 |
|
| CVE-2026-92052 |
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92053 |
Privilege escalation in the Graphics: CanvasWebGL component |
15.09.2026 |
|
| CVE-2026-92054 |
Privilege escalation in the Memory component |
15.09.2026 |
|
| CVE-2026-92055 |
Privilege escalation in the DevTools component |
15.09.2026 |
|
| CVE-2026-92056 |
Use-after-free in the Graphics: Text component |
15.09.2026 |
|
| CVE-2026-92057 |
Mitigation bypass in the Enterprise Policies component |
15.09.2026 |
|
| CVE-2026-92058 |
Use-after-free in the Graphics component |
15.09.2026 |
|
| CVE-2026-92059 |
Incorrect boundary conditions in the DOM: Editor component |
15.09.2026 |
|
| CVE-2026-92060 |
Use-after-free in the Internationalization component |
15.09.2026 |
|
| CVE-2026-92061 |
Incorrect boundary conditions in the Security: Process Sandboxing component |
15.09.2026 |
|
| CVE-2026-92062 |
Privilege escalation in the Session Restore component |
15.09.2026 |
|
| CVE-2026-92063 |
Denial-of-service in the Audio/Video component |
15.09.2026 |
|
| CVE-2026-92064 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component |
15.09.2026 |
|
| CVE-2026-92065 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component |
15.09.2026 |
|
| CVE-2026-92066 |
Sandbox escape in the Profile Backup component |
15.09.2026 |
|
| CVE-2026-92067 |
Use-after-free in the Widget: Gtk component |
15.09.2026 |
|
| CVE-2026-92068 |
Site isolation issue in the Reader Mode component |
15.09.2026 |
|
| CVE-2026-92069 |
Spoofing issue in the DOM: Navigation component |
15.09.2026 |
|
| CVE-2026-92070 |
Information disclosure in the Networking component |
15.09.2026 |
|
| CVE-2026-92071 |
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component |
15.09.2026 |
|
| CVE-2026-92072 |
Incorrect boundary conditions in the Safe Browsing component |
15.09.2026 |
|
| CVE-2026-92073 |
Privilege escalation in the Enterprise Policies component |
15.09.2026 |
|
| CVE-2026-91926 |
Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair entries in ntlm challenge |
15.09.2026 |
|
| CVE-2026-89308 |
Arbitrary command execution in TrxTimeATTENDANCE |
15.09.2026 |
|
| CVE-2026-92003 |
MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion |
15.09.2026 |
|
| CVE-2026-91993 |
Jpom through 2.11.12 Workspace Isolation Bypass via /build/branch-list |
15.09.2026 |
|
| CVE-2026-91994 |
Semaphore UI through 2.19.12 Missing Authorization on GET and HEAD Requests |
15.09.2026 |
|
| CVE-2026-91995 |
pig before 4.1.0 Unverified Password Change via /register/password |
15.09.2026 |
|
| CVE-2026-91996 |
lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint |
15.09.2026 |
|
| CVE-2026-91997 |
evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass |
15.09.2026 |
|
| CVE-2026-91998 |
Casdoor through 4.4.0 Cross-Organization User Administration via /api/mcp |
15.09.2026 |
|
| CVE-2026-92002 |
MISP: Authentication failure logging suppressed during Redis unavailability |
15.09.2026 |
|
| CVE-2026-91786 |
Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size |
15.09.2026 |
|
| CVE-2026-91922 |
Steedos Platform through 3.0.15-beta.47 Reflected XSS via page render |
15.09.2026 |
|
| CVE-2026-91923 |
KubeSphere through 4.1.3 SSRF via git credential verification endpoint |
15.09.2026 |
|
| CVE-2026-91924 |
pgweb through 0.17.0 Missing Authorization on Direct Connect Endpoint |
15.09.2026 |
|
| CVE-2026-91925 |
Polyaxon through 2.16.4 Server-Side Template Injection via Unsandboxed Jinja2 Engine |
15.09.2026 |
|
| CVE-2026-1758 |
Session Fixation |
15.09.2026 |
8.3 |
| CVE-2026-1759 |
|
15.09.2026 |
6.5 |
| CVE-2026-80489 |
EUC_JISX0213 decoding may hang on crafted input |
15.09.2026 |
5.9 |
| CVE-2026-52822 |
Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation |
15.09.2026 |
|
| CVE-2026-52827 |
Kimai: Two-factor authentication bypass on the Kimai API |
15.09.2026 |
|
| CVE-2026-52828 |
Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
15.09.2026 |
|
| CVE-2026-77117 |
SHIFT_JISX0213 decoding may hang on crafted input |
15.09.2026 |
5.9 |
| CVE-2026-52819 |
Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' timesheet records without being teamlead of the target |
15.09.2026 |
|
| CVE-2026-52820 |
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass |
15.09.2026 |
|
| CVE-2026-52821 |
Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creation Under Unauthorized Projects |
15.09.2026 |
|
| CVE-2026-52823 |
Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes |
15.09.2026 |
|
| CVE-2026-52824 |
Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
15.09.2026 |
|
| CVE-2026-52825 |
Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allows Expansion of Team Scope Beyond Authorized Visibility |
15.09.2026 |
|
| CVE-2026-52826 |
Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation |
15.09.2026 |
|
| CVE-2026-57147 |
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery |
15.09.2026 |
9.8 |
| CVE-2026-86818 |
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization |
15.09.2026 |
4.8 |
| CVE-2026-57133 |
PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
15.09.2026 |
8.8 |
| CVE-2026-57134 |
PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation |
15.09.2026 |
8.2 |
| CVE-2026-57135 |
PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients |
15.09.2026 |
7.6 |
| CVE-2026-57139 |
PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
15.09.2026 |
9.8 |
| CVE-2026-57140 |
PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
15.09.2026 |
9.4 |
| CVE-2026-57148 |
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) |
15.09.2026 |
9.8 |
| CVE-2026-86472 |
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets |
15.09.2026 |
4.8 |
| CVE-2026-57112 |
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools |
15.09.2026 |
8.3 |
| CVE-2026-57136 |
PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
15.09.2026 |
8.8 |
| CVE-2026-57137 |
PraisonAI AgentLoop onToolCall approval runs after tool execution |
15.09.2026 |
8.8 |
| CVE-2026-57138 |
PraisonAI codeMode sandbox escape via Function constructor |
15.09.2026 |
9.9 |
| CVE-2026-57141 |
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
15.09.2026 |
9.8 |
| CVE-2026-41573 |
OpenAM LDAP Injection via `_queryId` Parameter |
15.09.2026 |
|
| CVE-2026-47424 |
OpenAM Authenticated RCE via Groovy Sandbox Escape |
15.09.2026 |
|
| CVE-2026-47426 |
OpenAM OAuth Client Impersonation via JWKS Resolver Cache |
15.09.2026 |
|
| CVE-2026-48717 |
OpenAM OAuth Authorization Bypass via PKCE Challenge |
15.09.2026 |
|
| CVE-2025-13166 |
Username Enumeration via SMS OTP Flow in WSO2 Identity Server Allows User Account Discovery |
15.09.2026 |
3.7 |
| CVE-2025-5802 |
Username Enumeration via Self Registration Flow in Multiple WSO2 Products Allows User Account Discovery |
15.09.2026 |
5.3 |
| CVE-2026-19515 |
OS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command Execution |
15.09.2026 |
7 |
| CVE-2026-45048 |
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC |
15.09.2026 |
8.5 |
| CVE-2026-45051 |
OpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage |
15.09.2026 |
|
| CVE-2026-45794 |
OpenAM Unsafe Java Deserialization via SNS |
15.09.2026 |
|
| CVE-2026-46498 |
OpenAM Arbitrary OAuth Token Minting via Push Registration |
15.09.2026 |
|
| CVE-2026-46619 |
OpenAM Authentication Bypass via MSISDN LDAP Injection |
15.09.2026 |
|
| CVE-2026-46623 |
OpenAM Account Takeover via Unverified Password Change in OAuth2 Module |
15.09.2026 |
|
| CVE-2026-62263 |
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass |
15.09.2026 |
|
| CVE-2026-62280 |
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page |
15.09.2026 |
6.1 |
| CVE-2026-44202 |
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice` |
15.09.2026 |
|
| CVE-2026-44203 |
OpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl) |
15.09.2026 |
|
| CVE-2026-44793 |
OpenAM: Pre-authentication Reflected XSS in SAML2 Cluster Cookie-Hash-Redirect Path via `FSUtils.postToTarget` |
15.09.2026 |
|
| CVE-2026-45052 |
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints |
15.09.2026 |
|
| CVE-2026-53660 |
OpenAM Insecure SSO Cookie Initialization |
15.09.2026 |
|
| CVE-2026-62379 |
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback |
15.09.2026 |
9.8 |
| CVE-2026-91859 |
MISP Access Log Entry Overwritten by Error Controller's Second beforeFilter Pass |
15.09.2026 |
|
| CVE-2026-59341 |
Sealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpoints |
15.09.2026 |
4.2 |
| CVE-2026-91857 |
MISP: State-changing actions accessible via GET request enabling CSRF |
15.09.2026 |
|
| CVE-2026-91782 |
GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereference |
15.09.2026 |
|
| CVE-2026-76159 |
Duplicati for Windows - Incorrect Permission Assignment for Critical Resource |
15.09.2026 |
|
| CVE-2026-77853 |
|
15.09.2026 |
|
| CVE-2026-80217 |
|
15.09.2026 |
|
| CVE-2026-91781 |
GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference |
15.09.2026 |
|
| CVE-2026-91826 |
|
15.09.2026 |
4.4 |
| CVE-2026-91851 |
MISP Dashboard Template ACL Bypass Due to VARCHAR-to-Integer Type Coercion in Permission Flag Comparison |
15.09.2026 |
|
| CVE-2026-91780 |
GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference |
15.09.2026 |
|
| CVE-2026-91846 |
MISP Collection Element Add Missing Authorization on Referenced Object UUID |
15.09.2026 |
|
| CVE-2026-75092 |
Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins |
15.09.2026 |
|
| CVE-2026-87730 |
|
15.09.2026 |
|
| CVE-2026-91779 |
GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereference |
15.09.2026 |
|
| CVE-2026-91825 |
MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omitted During Edit |
15.09.2026 |
|