CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026 9.4
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026 9.2
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026 10
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 26.09.2026 9.5
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 26.09.2026 9.3
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 26.09.2026 9.2
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 26.09.2026 9.2
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 26.09.2026 9.2
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026 9.4
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026 9.4
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 26.09.2026 9.4
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026 9.3
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026 9
CVE-2026-100382 Unauthenticated remote code execution through wikitext in ExternalData 25.09.2026 10
CVE-2026-100389 GestSup before 3.2.61 Remote Code Execution via IMAP Attachment 25.09.2026 9.2
CVE-2026-100390 Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 25.09.2026 9.1
CVE-2026-48482 GLPI: RCE via Form import 25.09.2026 9.4
CVE-2026-84458 Zammad: Account takeover via unverified email matching during SSO auto-link 25.09.2026 9.1
CVE-2026-97063 X-SpringBoot through 6.0 Authentication Bypass via Login Code 25.09.2026 9.3
CVE-2026-97064 X-SpringBoot through 6.0 Authentication Bypass via Static Master Code 25.09.2026 9.3
CVE-2026-42322 Piwigo: Authenticated RCE via File Upload in Logo Upload Feature 25.09.2026 9.1
CVE-2026-92161 FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 25.09.2026 9.8
CVE-2026-62262 Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` 25.09.2026 9.1
CVE-2026-39353 InvoicePlane: Remote Code Execution via Writable Templates Directory 25.09.2026 9.1
CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-93643 Zimbra Collaboration Suite OnlyOffice Integration Path Traversal Leading to Remote Code Execution via Unauthenticated /downloadas Request 26.09.2026 9.8
CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 26.09.2026 9.3
CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25.09.2026 9.3
CVE-2026-100075 RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters 25.09.2026 9.8
CVE-2026-95832 Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell 25.09.2026 9.3
CVE-2026-14281 Automation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' Parameter 25.09.2026 9.8
CVE-2026-89055 Customer Reviews for WooCommerce <= 5.120.0 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'items[][media]' Parameter 25.09.2026 9.1
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter 25.09.2026 9.1
CVE-2026-81630 Botslab G980H Dashcams Insufficient Verification of Data Authenticity 25.09.2026 9.2
CVE-2026-93289 OS command injection in Eufy Omni C20, Omni X10 Pro 24.09.2026 9
CVE-2026-93291 Improper certificate validation in Eufy Omni C20 24.09.2026 9.3
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform 25.09.2026 9.3
CVE-2026-13249 Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040 24.09.2026 9.8
CVE-2026-61741 http4s-scala-xml has an XML External Entity (XXE) processing issue 24.09.2026 9.3
CVE-2026-61604 ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass 24.09.2026 9.3
CVE-2026-61732 Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context 24.09.2026 10
CVE-2026-61742 DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution 24.09.2026 9.3
CVE-2026-79766 Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email 24.09.2026 9.1
CVE-2026-97413 RDMA/rtrs-srv: Fix integer underflow in process_read and process_write 25.09.2026 9.8
CVE-2026-93425 Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root 24.09.2026 9.9
CVE-2026-93228 svcrdma: Reject Write/Reply chunks with segcount 0 25.09.2026 9.1
CVE-2026-93207 SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry 25.09.2026 9.8
CVE-2026-81549 DataStage on Cloud Pak for Data has several vulnerabilities 24.09.2026 9.6
CVE-2026-90481 24.09.2026 9.2
CVE-2026-97404 24.09.2026 9.2
CVE-2026-97359 HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection 24.09.2026 10
CVE-2026-97360 HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine 24.09.2026 10
CVE-2026-91187 Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy 24.09.2026 9.3
CVE-2026-19072 Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal 25.09.2026 9.9
CVE-2026-12227 Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter 24.09.2026 9.8
CVE-2026-78312 Path Traversal in DIAEnergie 24.09.2026 9.1
CVE-2026-78308 Authentication Bypass in DIAEnergie 24.09.2026 9.8
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write 24.09.2026 9.3
CVE-2026-97055 SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret 24.09.2026 9.2
CVE-2026-18467 Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter 24.09.2026 9.8
CVE-2026-89078 Double Free in GitLab 25.09.2026 9.9
CVE-2026-93577 Integer Overflow or Wraparound in GitLab 25.09.2026 9.9
CVE-2026-93352 Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload 26.09.2026 9.3
CVE-2026-6928 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67231 RabbitMQ: Trust-store whitelist by Issuer+Serial only 23.09.2026 9.1
CVE-2026-6721 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-6730 Multiple Vulnerabilities in IBM Concert Software 25.09.2026 9.8
CVE-2026-67404 RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch 23.09.2026 9.2
CVE-2026-87898 23.09.2026 9.4
CVE-2026-87899 24.09.2026 9.4
CVE-2026-87900 23.09.2026 9.4
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups 24.09.2026 9.1
CVE-2026-84719 Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) 25.09.2026 9.9
CVE-2026-77602 OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites) 23.09.2026 9.9
CVE-2026-96770 s2s-proxy accepts untrusted client certificates 23.09.2026 9.3
CVE-2026-84474 Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match 24.09.2026 9.9
CVE-2026-84502 Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod 24.09.2026 9.9
CVE-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack 23.09.2026 9.2
CVE-2026-95601 WordPress Product Filter by WBW plugin <= 3.1.7 - SQL Injection vulnerability 23.09.2026 9.3
CVE-2026-85724 Moquette pattern ACL wildcard injection allows cross-tenant authorization bypass 24.09.2026 9.6
CVE-2026-95848 Moquette fails open when configured authentication or authorization classes cannot load 23.09.2026 9.3
CVE-2026-96754 orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path 23.09.2026 9.3
CVE-2026-96755 orval @orval/effect 8.14.0 through 8.28.1 Code Injection 23.09.2026 9.3
CVE-2026-96756 orval before 8.30.0 Code Injection via Factory Generation 23.09.2026 9.2
CVE-2026-96757 orval before 8.29.0 Code Injection via unescaped OpenAPI media-type 23.09.2026 9.3
CVE-2026-96758 orval @orval/core before 8.28.0 Code Injection via Form-Data 23.09.2026 9.3
CVE-2026-96759 orval before 8.29.0 Code Injection via operationId 23.09.2026 9.3
CVE-2026-18872 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.3
CVE-2026-59167 SunEditor: Critical XSS vulnerability - sanitizer bypass 24.09.2026 10
CVE-2026-96560 LightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control Channel 24.09.2026 9.3
CVE-2026-86708 Sensitive data exposure 24.09.2026 10
CVE-2026-19599 Remote Code Execution vulnerability 24.09.2026 9.9
CVE-2026-96257 Fast FAC1203R Gigabit Edition Device Discovery Service copy_msg_element stack-based overflow 23.09.2026 10
CVE-2026-18162 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18163 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.8
CVE-2026-18169 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.9
CVE-2026-19202 Token Cache Reuse in mcp-toolbox-sdk-python 23.09.2026 9.1
CVE-2026-17645 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1
CVE-2026-16346 DataStage on Cloud Pak for Data has several vulnerabilities 23.09.2026 9.9
CVE-2026-17472 Multiple Vulnerabilities in IBM Concert Software 24.09.2026 9.6
CVE-2026-17635 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities 23.09.2026 9.1
CVE-2026-77987 GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery 23.09.2026 9.3
CVE-2026-87121 Out-of-bounds write in lwIP TCP/IP Stack MQTT Client Application 22.09.2026 9.3
CVE-2026-28324 SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability 22.09.2026 9.8
CVE-2026-47116 LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH 23.09.2026 9.2
CVE-2026-76708 Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE) 23.09.2026 9.8
CVE-2026-76709 Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE) 23.09.2026 9.8
CVE-2026-57149 plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection 22.09.2026 9.9
CVE-2026-91130 Home Assistant: XSS in Statistics Graph Card 22.09.2026 9.3
CVE-2026-75682 Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 23.09.2026 9.9
CVE-2026-75684 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 22.09.2026 9.3
CVE-2026-75686 Adobe Connect | Improper Input Validation (CWE-20) 23.09.2026 9.3
CVE-2026-75689 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 26.09.2026 9.3
CVE-2026-75697 Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79) 22.09.2026 9.3
CVE-2026-75698 Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79) 23.09.2026 9.3
CVE-2026-75745 Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863) 26.09.2026 10
CVE-2026-81995 Adobe Experience Manager Forms JEE | Improper Input Validation (CWE-20) 23.09.2026 9.1
CVE-2026-82000 Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918) 23.09.2026 9.6
CVE-2026-77254 MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials 22.09.2026 9.1
CVE-2026-43641 Softaculous Virtualizor OS Command Injection via Billing Module Handler 23.09.2026 9.3
CVE-2026-43642 Softaculous Virtualizor PHP Object Injection via Billing Module Handler 25.09.2026 9.2
CVE-2026-18461 Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. 22.09.2026 9.2
CVE-2026-77244 [mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token 23.09.2026 10
CVE-2026-7866 Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. 23.09.2026 9.3
CVE-2026-73369 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 23.09.2026 10
CVE-2026-75699 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-75703 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-75721 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 25.09.2026 10
CVE-2026-75723 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 22.09.2026 10
CVE-2026-75728 Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) 23.09.2026 9.1
CVE-2026-82008 Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20) 22.09.2026 9.9
CVE-2026-82009 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 25.09.2026 9.1
CVE-2026-82010 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 22.09.2026 9.9
CVE-2026-82011 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 23.09.2026 9.1
CVE-2026-82013 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 22.09.2026 9.9
CVE-2026-82443 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 22.09.2026 9.6
CVE-2026-83660 Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918) 25.09.2026 9.9
CVE-2026-84412 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 10
CVE-2026-89275 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 23.09.2026 10
CVE-2026-89276 Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94) 22.09.2026 9.9
CVE-2026-85734 LightRAG: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks 22.09.2026 9.1
CVE-2026-86059 Dokploy: Git Provider Credential Exposure via Unprotected .one Endpoints and application.one 22.09.2026 9.6
CVE-2026-94456 Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys 22.09.2026 9.1
CVE-2026-63374 AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing 22.09.2026 9.3
CVE-2026-77621 Vector: Arbitrary file write in the file sink via templated path (path traversal). 25.09.2026 9.3
CVE-2026-80143 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read 24.09.2026 9.4
CVE-2026-80144 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write 24.09.2026 9.4
CVE-2026-80145 Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password 24.09.2026 9.4
CVE-2026-80146 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read 25.09.2026 9.4
CVE-2026-80147 Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write 24.09.2026 9.4
CVE-2026-80151 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download 26.09.2026 9.4
CVE-2026-80152 Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule 26.09.2026 9.4
CVE-2026-80155 Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path Truncation 24.09.2026 10
CVE-2026-80156 Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass 24.09.2026 9.4
CVE-2026-95654 Databasement before 1.7.14 Authorization Bypass via Stale Invitation Token 22.09.2026 9.1
CVE-2026-65113 22.09.2026 9.8
CVE-2026-84388 22.09.2026 9.1
CVE-2026-94127 BIG-IP APM OAuth vulnerability 23.09.2026 9.3
CVE-2026-12718 SQLi in Karel Electronics' KarelIPS 22.09.2026 9.8
CVE-2026-95675 D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface 22.09.2026 9.3
CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server 23.09.2026 9.8
CVE-2026-74849 Remote code execution vulnerability 23.09.2026 9.8
CVE-2026-25254 Improper authorization in Qualcomm Software Center 22.09.2026 9.8
CVE-2026-93556 Direct references to unsafe objects (IDOR) in Tankuam Places by Kompini 22.09.2026 9.3
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension 22.09.2026 9.3
CVE-2026-93952 Security Advisory 0183 23.09.2026 9.5
CVE-2026-13355 Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb_frontend_field_object_id' Parameter 22.09.2026 9.8
CVE-2026-19658 Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]' Parameter 22.09.2026 9.8
CVE-2026-94493 Gigatech PDV5701 WebSocket Service index.html missing authentication 24.09.2026 10
CVE-2026-94425 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management 22.09.2026 9.3
CVE-2026-46649 Joplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected Endpoint 21.09.2026 9.1
CVE-2026-77521 MaxKB: Prompt-injectable agent can lead to command execution 22.09.2026 10
CVE-2026-94424 Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow 22.09.2026 9.3
CVE-2026-79916 MaxKB AWS Bedrock model credential injection leads to remote code execution 22.09.2026 9.1
CVE-2026-94571 22.09.2026 9.4
CVE-2026-94572 24.09.2026 9.4
CVE-2026-58491 Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter 22.09.2026 9.3
CVE-2026-94403 ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference 22.09.2026 9.3
CVE-2026-79920 Ajenti: Privilege escalation to root via unauthenticated/unauthorized plugin install task 21.09.2026 9.9
CVE-2026-61674 Fluent Bit: Remote stack buffer overflow in Fluent Bit `out_forward` Secure-Forward `PONG` handler 21.09.2026 9.2
CVE-2026-85751 Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forwarded-By` trust 21.09.2026 9.8
CVE-2026-94301 Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2.0.30 / 2.1.14) ZDRES-232 22.09.2026 9.8
CVE-2025-12999 22.09.2026 9.1
CVE-2026-94146 BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where 22.09.2026 9.3
CVE-2026-94142 BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94128 BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94129 BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where 21.09.2026 9.3
CVE-2026-94101 Netcore NBR200V2 routerd vlan_load_form_uci buffer overflow 21.09.2026 9.4
CVE-2026-94098 Netcore NBR200V2 Firmware Upgrade CGI Endpoint upgrade command injection 21.09.2026 9.4
CVE-2026-94099 Netcore NBR200V2 Backup Restore restore.cgi command injection 22.09.2026 9.4
CVE-2026-94100 Netcore NBR200V2 WAN VLAN Reconfiguration routerd wan_config_set_vlan buffer overflow 21.09.2026 9.4
CVE-2026-94097 Netcore NBR200V2 CGI Diagnostic Endpoint network_tools command injection 24.09.2026 10
CVE-2026-94096 Netcore NBR200V2 LAN IP Configuration network_tools command injection 21.09.2026 9.4
CVE-2026-94095 Netcore NBR200V2 Traceroute Diagnostic Feature network_tools command injection 21.09.2026 9.4
CVE-2026-94089 D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow 22.09.2026 10
CVE-2026-88857 Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 22.09.2026 9.4
CVE-2026-88854 Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 22.09.2026 9.3
CVE-2026-88856 Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 22.09.2026 9.4
CVE-2026-90817 21.09.2026 9.8
CVE-2026-94003 Comfast CF-N1-S Web Management mbox-config get_css_path_from_uri stack-based overflow 24.09.2026 10
CVE-2026-94107 NivoCart through 2.4.0 Predictable Administrator Password Reset Token 21.09.2026 9.2
CVE-2026-93958 D-Link R95 DHMAPI ssi system os command injection 21.09.2026 9.4
CVE-2026-94083 22.09.2026 9.4
CVE-2026-94084 22.09.2026 9.4

Latest Updates

CVE Title Updated Score
CVE-2026-97160 Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026
CVE-2026-97161 Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026
CVE-2026-97162 Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026
CVE-2026-97163 Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 26.09.2026
CVE-2026-94131 Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 26.09.2026
CVE-2026-94132 Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 26.09.2026
CVE-2026-94130 Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 26.09.2026
CVE-2026-100626 capgo through 12.128.2 IDOR via PUT /app icon endpoint 26.09.2026
CVE-2026-100600 ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API 26.09.2026
CVE-2026-100601 ClawHub SSRF via Unchecked DNS Resolution in Profile Image 26.09.2026
CVE-2026-100602 ClawHub Changelog Preview Information Disclosure via Authorization Bypass 26.09.2026
CVE-2026-100603 ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports 26.09.2026
CVE-2026-100604 ClawHub Authentication Bypass via Former Publisher Skill Control 26.09.2026
CVE-2026-100605 Flowise through 3.1.4 Missing Authorization via Chat Message Routes 26.09.2026
CVE-2026-100606 Flowise through 3.1.4 Authentication Bypass via SSO Email Match 26.09.2026
CVE-2026-100607 Flowise through 3.1.4 Authentication Bypass via Email-Only SSO 26.09.2026
CVE-2026-100608 Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard 26.09.2026
CVE-2026-100609 Flowise through 3.1.4 Insecure Direct Object Reference via Credential 26.09.2026
CVE-2026-100610 Flowise through 3.1.4 Missing Authorization via upsert-history 26.09.2026
CVE-2026-100611 Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list 26.09.2026
CVE-2026-100612 Capgo SSO Provider ID Authentication Bypass via Incomplete Migration 26.09.2026
CVE-2026-100613 capgo.app Authorization Bypass via Stale Channel Permission Overrides 26.09.2026
CVE-2026-100614 Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker 26.09.2026
CVE-2026-100615 Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation 26.09.2026
CVE-2026-100616 capgo.app Authentication Bypass via PostgREST customer_id Mutation 26.09.2026
CVE-2026-100617 Cap-go capgo.app Authorization Bypass via channel_permission_overrides 26.09.2026
CVE-2026-100618 Capgo App Icon Update Privilege Escalation via Service-Role Worker 26.09.2026
CVE-2026-100619 Capgo OTA Manifest Poisoning via app_versions.manifest Bypass 26.09.2026
CVE-2026-100620 Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service Account 26.09.2026
CVE-2026-100621 capgo.app Content-Lock Bypass via r2-direct Bundle Mutation 26.09.2026
CVE-2026-100622 capgo.app through 12.129.0 Cache Restoration of Deleted Bundles 26.09.2026
CVE-2026-100623 Capgo Authentication Bypass via Direct PostgREST org_users Table Write 26.09.2026
CVE-2026-100624 Capgo.app before 12.264.5 Upload Expiry Bypass via build upload 26.09.2026
CVE-2026-100625 Capgo Build Upload Proxy Authorization Bypass via TUS Resource 26.09.2026
CVE-2026-100627 Capgo bundle promotion API channel RBAC deny override bypass 26.09.2026
CVE-2026-100628 capgo.app before 12.128.12 Authentication Bypass via apikey 26.09.2026
CVE-2026-100629 Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH 26.09.2026
CVE-2026-100630 AVideo Stored XSS via HTML Entity Bypass in trailer1 Field 26.09.2026
CVE-2026-100631 Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection 26.09.2026
CVE-2026-100632 Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery 26.09.2026
CVE-2026-100633 SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations 26.09.2026
CVE-2026-100634 SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows 26.09.2026
CVE-2026-100635 SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie 26.09.2026
CVE-2026-100636 SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder 26.09.2026
CVE-2026-100637 SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID 26.09.2026
CVE-2026-100638 SiYuan before v3.8.4 Path Traversal via setNotebookIcon 26.09.2026
CVE-2026-100639 SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL 26.09.2026
CVE-2026-100640 SiYuan before v3.8.4 Clipboard Data Disclosure via IPC 26.09.2026
CVE-2026-100641 SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content 26.09.2026
CVE-2026-100642 SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth 26.09.2026
CVE-2026-100643 SiYuan before v3.8.4 Stored XSS via Attribute View textarea 26.09.2026
CVE-2026-100644 SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath 26.09.2026
CVE-2026-100645 SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban 26.09.2026
CVE-2026-100646 SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header 26.09.2026
CVE-2026-100647 vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt 26.09.2026
CVE-2026-100648 vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding 26.09.2026
CVE-2026-100649 vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass 26.09.2026
CVE-2026-100650 vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization 26.09.2026
CVE-2026-100651 vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass 26.09.2026
CVE-2026-100652 vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids 26.09.2026
CVE-2026-100653 vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation 26.09.2026
CVE-2026-100654 vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids 26.09.2026
CVE-2026-100655 Netty before 4.1.138.Final Denial of Service via SpdySessionHandler 26.09.2026
CVE-2026-100656 Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining 26.09.2026
CVE-2026-100657 Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder 26.09.2026
CVE-2026-100658 Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler 26.09.2026
CVE-2026-100659 Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass 26.09.2026
CVE-2026-100660 Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention 26.09.2026
CVE-2026-100661 Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation 26.09.2026
CVE-2026-100662 Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS 26.09.2026
CVE-2026-100663 Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 26.09.2026
CVE-2026-100664 Netty 4.2.2 through 4.2.15 HTTP/1 Host Header Authority Confusion 26.09.2026
CVE-2026-100665 Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass 26.09.2026
CVE-2026-100666 Netty 4.2.0 through 4.2.17 Response Desynchronization via HttpServerCodec 26.09.2026
CVE-2026-100667 grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass 26.09.2026
CVE-2026-100668 Grav before 2.0.25 Sandbox Escape via array Filter 26.09.2026
CVE-2026-100669 Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass 26.09.2026
CVE-2026-100670 Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass 26.09.2026
CVE-2026-100671 Grav before 2.0.25 Session Cookie Theft via Twig Sandbox 26.09.2026
CVE-2026-100672 grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure 26.09.2026
CVE-2026-100673 Grav Data Manager before 1.4.5 Stored XSS via item-detail view 26.09.2026
CVE-2026-100674 stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization 26.09.2026
CVE-2026-100675 stoatchat before 0.15.5 Denial of Service via mass mentions 26.09.2026
CVE-2026-100676 stoatchat before 0.15.5 Local Filesystem Read via SVG 26.09.2026
CVE-2026-100677 stoatchat before 0.15.5 Account Enumeration via Error Location 26.09.2026
CVE-2026-100678 stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting 26.09.2026
CVE-2026-100679 stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket 26.09.2026
CVE-2026-100680 Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import 26.09.2026
CVE-2026-100681 Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook 26.09.2026
CVE-2026-100682 Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink 26.09.2026
CVE-2026-100683 Budibase before 3.45.0 SQL Injection via column-rename DDL 26.09.2026
CVE-2026-100684 Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC 26.09.2026
CVE-2026-100685 Budibase before 3.45.0 Information Disclosure via Chat Links 26.09.2026
CVE-2026-100686 Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/global/groups/:groupId/apps 26.09.2026
CVE-2026-100687 Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast 26.09.2026
CVE-2026-100688 Budibase server before 3.45.0 Cross-Tenant Information Disclosure 26.09.2026
CVE-2026-100689 GitPython before 3.1.62 Path Traversal via gitmodules path 26.09.2026
CVE-2026-100690 Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks 26.09.2026
CVE-2026-100691 Hugo before 0.166.0 Stored XSS via lineAnchors code block option 26.09.2026
CVE-2026-100692 Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots 26.09.2026
CVE-2026-100693 Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass 26.09.2026
CVE-2026-100694 Hugo before 0.166.0 Cross-Site Scripting via text/org 26.09.2026
CVE-2026-100695 Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE 26.09.2026
CVE-2026-100696 Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver 26.09.2026
CVE-2026-100697 Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver 26.09.2026
CVE-2026-100698 Adminer before 6.0.2 Privileged-Port SSRF via host_port Regex 26.09.2026
CVE-2026-100699 Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment 26.09.2026
CVE-2026-100700 nodemailer before 10.0.6 Denial of Service via addressparser 26.09.2026
CVE-2026-100701 Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion 26.09.2026
CVE-2026-100702 Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays 26.09.2026
CVE-2026-100703 Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib 26.09.2026
CVE-2026-100704 Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass 26.09.2026
CVE-2026-100705 Kyverno before 1.19.1 SSRF via legacy apiCall service executor 26.09.2026
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath 26.09.2026
CVE-2026-100707 Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path 26.09.2026
CVE-2026-100708 Froxlor before 2.3.13 Private Key Disclosure via Certificates API 26.09.2026
CVE-2026-100709 Froxlor before 2.3.12 2FA Bypass via Namespace Confusion 26.09.2026
CVE-2026-100710 Froxlor before 2.3.12 DKIM Private Key Disclosure via API 26.09.2026
CVE-2026-100711 froxlor before 2.3.12 Authentication Bypass via Session Persistence 26.09.2026
CVE-2026-100712 froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF 26.09.2026
CVE-2026-100713 Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync 26.09.2026
CVE-2026-100714 Froxlor before 2.3.12 Command Injection via letsencryptchallengepath 26.09.2026
CVE-2026-100715 Froxlor before 2.3.12 Arbitrary File Deletion via Symlink 26.09.2026
CVE-2026-100716 Froxlor before 2.3.12 Privilege Escalation via Symlink 26.09.2026
CVE-2026-100717 froxlor before 2.3.12 CRLF Injection via validateUrl userinfo 26.09.2026
CVE-2026-100718 Froxlor before 2.3.12 Authentication Bypass via EmailSender.add 26.09.2026
CVE-2026-100719 Froxlor before 2.3.12 Credential Disclosure via DirProtections API 26.09.2026
CVE-2026-100720 Froxlor before 2.3.12 Stored XSS via SSL certificate issuer 26.09.2026
CVE-2026-100315 mathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injection 26.09.2026
CVE-2026-100314 mathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql injection 26.09.2026
CVE-2026-100313 mathurvishal CloudClassroom-PHP-Project updatequery.php cross site scripting 26.09.2026
CVE-2026-100312 mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection 26.09.2026
CVE-2026-98163 cgroup: Avoid iteration of dying tasks with zero refcount 26.09.2026
CVE-2026-100311 mathurvishal CloudClassroom-PHP-Project Faculty Video Management managevideos2.php cross site scripting 26.09.2026
CVE-2026-18143 Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler 26.09.2026 9.8
CVE-2026-11871 Team Showcase Supreme <= 9.2 - Unauthenticated Sensitive Data Disclosure via wpm_6310_team_member_details 26.09.2026
CVE-2026-16591 WP Directory Kit < 1.5.8 - Listing Admin+ Stored XSS via Category and Location Title and Icon Fields 26.09.2026
CVE-2026-19708 File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure 26.09.2026
CVE-2026-84095 WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import 26.09.2026
CVE-2026-84096 WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Form Fields 26.09.2026
CVE-2026-84097 WP Review Slider Pro < 12.7.12 - Subscriber+ SQLi via Stored Template Filter 26.09.2026
CVE-2026-85081 Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass 26.09.2026
CVE-2026-89237 Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' Parameters 26.09.2026
CVE-2026-92411 WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name 26.09.2026
CVE-2026-96524 MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF 26.09.2026
CVE-2026-96525 MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Missing Ownership Check 26.09.2026
CVE-2026-96526 MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workflows/run REST Route 26.09.2026
CVE-2026-96531 Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block 26.09.2026
CVE-2026-96532 Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update 26.09.2026
CVE-2026-96533 Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL 26.09.2026
CVE-2026-15273 Automatic.css 4.0.0 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI 26.09.2026 6.4
CVE-2026-100525 OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass 26.09.2026
CVE-2026-100526 Vulnerability in discord 26.09.2026
CVE-2026-100527 OpenClaw before 2026.8.2 Denial of Service via Browser Relay 26.09.2026
CVE-2026-100528 OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint 26.09.2026
CVE-2026-100529 OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer 26.09.2026
CVE-2026-100530 OpenClaw before 2026.8.1 Exec Approval Directory Binding 26.09.2026
CVE-2026-100531 openclaw Slack before 2026.8.1 Authorization Bypass 26.09.2026
CVE-2026-100532 openclaw WhatsApp before 2026.8.1 Authentication Bypass 26.09.2026
CVE-2026-100533 OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback 26.09.2026
CVE-2026-100534 OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass 26.09.2026
CVE-2026-100535 OpenClaw before 2026.8.1 Privilege Escalation via Session Memory 26.09.2026
CVE-2026-100536 OpenClaw before 2026.8.1 Path Traversal via Structured Attachments 26.09.2026
CVE-2026-100537 OpenClaw before 2026.8.1 Authentication Bypass via Active Memory 26.09.2026
CVE-2026-100538 OpenClaw before 2026.8.1 Local File Read via Outbound Attachments 26.09.2026
CVE-2026-100539 OpenClaw before 2026.8.1 Memory Access Control Bypass 26.09.2026
CVE-2026-100540 OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account 26.09.2026
CVE-2026-100541 OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding 26.09.2026
CVE-2026-100542 OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2 26.09.2026
CVE-2026-100543 OpenClaw before 2026.8.1 Information Disclosure via Configuration Hash 26.09.2026
CVE-2026-100544 openclaw voice-call before 2026.8.1 Authorization Bypass 26.09.2026
CVE-2026-100545 OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation 26.09.2026
CVE-2026-100546 OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript 26.09.2026
CVE-2026-100547 OpenClaw before 2026.8.1 Authentication Bypass via File URL 26.09.2026
CVE-2026-100548 OpenClaw before 2026.8.1 Credential Exposure via Embedding Fallback 26.09.2026
CVE-2026-100549 OpenClaw before 2026.8.1 Path Traversal via QQBot voice filenames 26.09.2026
CVE-2026-100550 OpenClaw before 2026.8.1 Authentication Bypass via Access Group 26.09.2026
CVE-2026-100551 OpenClaw iOS Control UI TLS Pin Enforcement Bypass 26.09.2026
CVE-2026-100552 OpenClaw before 2026.8.1 Policy Bypass via Native Tools 26.09.2026
CVE-2026-100553 OpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpin 26.09.2026
CVE-2026-100554 OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass 26.09.2026
CVE-2026-100555 OpenClaw before 2026.8.1 DNS Rebinding via attachment delivery 26.09.2026
CVE-2026-100556 OpenClaw before 2026.8.1 Authentication Bypass via Session Reset 26.09.2026
CVE-2026-100557 OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch 26.09.2026
CVE-2026-100558 OpenClaw before 2026.8.1 Resource Exhaustion via WebSocket Upgrade 26.09.2026
CVE-2026-100559 OpenClaw before 2026.8.1 Command Injection via Escaped Newlines 26.09.2026
CVE-2026-100560 OpenClaw before 2026.8.1 Reusable Exec Approvals Authorization Bypass 26.09.2026
CVE-2026-100561 OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper 26.09.2026
CVE-2026-100562 OpenClaw before 2026.8.1 Authorization Bypass via sessions.create 26.09.2026
CVE-2026-100563 OpenClaw before 2026.8.1 CSV Formula Injection via Session Labels 26.09.2026
CVE-2026-100564 OpenClaw before 2026.8.1 CSV Formula Injection via Attendance Export 26.09.2026
CVE-2026-100566 OpenClaw LINE before 2026.8.1 Access Control Inheritance 26.09.2026
CVE-2026-100567 OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname 26.09.2026
CVE-2026-100568 OpenClaw before 2026.8.1 Unauthorized Command Job Access 26.09.2026
CVE-2026-100569 OpenClaw before 2026.8.1 Credential Exposure via Endpoint Override 26.09.2026
CVE-2026-100570 OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS 26.09.2026
CVE-2026-100571 OpenClaw before 2026.8.1 SMS Webhook Rate Limit Bypass 26.09.2026
CVE-2026-100572 OpenClaw before 2026.8.1 Denial of Service via Rate Limit 26.09.2026
CVE-2026-100573 OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback 26.09.2026
CVE-2026-100574 OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS 26.09.2026
CVE-2026-100575 OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM 26.09.2026
CVE-2026-100576 OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates 26.09.2026
CVE-2026-100577 OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset 26.09.2026
CVE-2026-100578 OpenClaw before 2026.7.1 Authorization Bypass via chat.send 26.09.2026
CVE-2026-100579 OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester 26.09.2026
CVE-2026-100580 OpenClaw before 2026.7.1 Remote Code Execution via cron tool 26.09.2026
CVE-2026-100581 OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension 26.09.2026
CVE-2026-100582 OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass 26.09.2026
CVE-2026-100583 OpenClaw Discord before 2026.7.1 Authorization Bypass 26.09.2026
CVE-2026-100584 OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows 26.09.2026
CVE-2026-100585 OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel 26.09.2026
CVE-2026-100586 OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind 26.09.2026
CVE-2026-100587 OpenClaw before 2026.7.1 Authorization Bypass via Codex Install 26.09.2026
CVE-2026-100588 OpenClaw before 2026.7.1 Authentication Bypass via node.invoke 26.09.2026
CVE-2026-100589 OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node 26.09.2026
CVE-2026-100590 OpenClaw before 2026.7.1 Authorization Bypass via voice set 26.09.2026
CVE-2026-100591 OpenClaw before 2026.7.1 Authentication Bypass via Active Memory 26.09.2026
CVE-2026-100592 OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming 26.09.2026
CVE-2026-100593 OpenClaw before 2026.7.1 Authentication Bypass via activation 26.09.2026
CVE-2026-100594 OpenClaw before 2026.7.1 Authorization Bypass via trajectory export 26.09.2026
CVE-2026-100595 OpenClaw before 2026.7.1 Authorization Bypass via diagnostics 26.09.2026
CVE-2026-100596 OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration 26.09.2026
CVE-2026-100597 OpenClaw before 2026.7.1 Path Traversal via Filesystem Race 26.09.2026
CVE-2026-100598 OpenClaw before 2026.7.1 Approval Binding Logic Error 26.09.2026
CVE-2026-100599 OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome 26.09.2026
CVE-2026-100503 Ghidra through 12.1.4 Heap Use-After-Free in Decompiler 26.09.2026
CVE-2026-100504 Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128 26.09.2026
CVE-2026-100505 Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager 26.09.2026
CVE-2026-100520 Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint 26.09.2026
CVE-2026-100521 Cotonti through 1.0.0 Reflected XSS via search highlight parameter 26.09.2026
CVE-2026-100522 Cotonti through 1.0.0 Reflected XSS via message.php lng parameter 26.09.2026
CVE-2026-100523 Cotonti through 1.0.0 Open Redirect via message.php redirect parameter 26.09.2026
CVE-2026-100524 Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager 26.09.2026
CVE-2026-57449 Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token 25.09.2026
CVE-2026-86066 Horilla attendance approval endpoint is vulnerable to cross-site request forgery 25.09.2026
CVE-2026-96795 Horilla: Authenticated RCE in Horilla List-View Export 25.09.2026 8.8
CVE-2026-100418 Flame through 2.4.0 Information Exposure via GET /api/config 25.09.2026
CVE-2026-100419 gitoxide gix-fs before 0.23.0 Worktree Escape via Symlink 25.09.2026
CVE-2026-100501 Flame through 2.4.0 Brute-Force Attack via Login Endpoint 25.09.2026
CVE-2026-100502 Flame through 2.4.0 Admin Token Insufficient Session Expiration 25.09.2026
CVE-2026-63432 Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server Metadata 25.09.2026 6.5
CVE-2026-71483 Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View 25.09.2026
CVE-2026-63431 Horilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structures and Personal Loan Records (IDOR) 25.09.2026 6.5