CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 10.09.2026 9.9
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026 9.4
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 09.09.2026 9.3
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 09.09.2026 9
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 09.09.2026 9.6
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 09.09.2026 9.3
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026 9.2
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 09.09.2026 9.3
CVE-2026-67401 10.09.2026 9.9
CVE-2026-67403 09.09.2026 9
CVE-2026-68484 09.09.2026 9
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-80172 09.09.2026 9.8
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026 9.1
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026 10
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026 10
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module 09.09.2026 9.1
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist 09.09.2026 10
CVE-2026-21095 09.09.2026 9.2
CVE-2026-21096 09.09.2026 9.2
CVE-2026-21102 09.09.2026 9.3
CVE-2026-53939 OpenIDC/cjose uses all-zero Content Encryption Key for AES-CBC-HMAC JWE encryption 09.09.2026 9.1
CVE-2026-53581 ntp: write path traversal 09.09.2026 9
CVE-2026-85982 Stored Cross-Site Scripting (XSS) in Auth0 AD/LDAP Connector 08.09.2026 9
CVE-2026-84197 09.09.2026 9.2
CVE-2026-19232 Adobe Experience Manager | Incorrect Authorization (CWE-863) 10.09.2026 9.9
CVE-2026-86464 09.09.2026 9.9
CVE-2026-48273 ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95) 09.09.2026 9.9
CVE-2026-75746 ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) 09.09.2026 9.1
CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 09.09.2026 9.9
CVE-2026-28659 09.09.2026 10
CVE-2026-49883 10.09.2026 10
CVE-2026-82004 Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) 08.09.2026 10
CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-76200 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-76201 Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) 09.09.2026 9.3
CVE-2026-65669 Microsoft SQL Server Elevation of Privilege Vulnerability 09.09.2026 9.6
CVE-2026-68839 Windows USB Mass Storage Class Driver Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69276 Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 09.09.2026 9.3
CVE-2026-69408 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69431 Telnet Client Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69463 Windows NTFS Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69491 Microsoft DirectMusic Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69493 Windows Event Logging Service Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69496 Windows Compressed Folder Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69525 Remote Desktop Services Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69579 Windows Message Queuing Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69586 Microsoft Windows PDF Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69590 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69595 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 09.09.2026 9.1
CVE-2026-69715 Windows Direct Show Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69730 Windows DNS Server Remote Code Execution Vulnerability 10.09.2026 9.8
CVE-2026-69768 Windows RNDIS Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69769 Windows HTTP Print Provider Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69819 RPC Runtime Library Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69824 Microsoft Standard XPS Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69829 Windows Shell Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69845 Windows DHCP Server Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-69854 Spring Cloud Azure Elevation of Privilege Vulnerability 09.09.2026 9
CVE-2026-69910 Windows Hyper-V Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-70296 Windows Imaging Component Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-72983 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-73009 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-73010 Microsoft Failover Cluster Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-73025 Windows iSCSI Security Feature Bypass Vulnerability 09.09.2026 9.8
CVE-2026-77493 Windows Graphics Component Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-78445 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-78509 Microsoft Office Outlook Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-78510 Microsoft Word Remote Code Execution Vulnerability 09.09.2026 9.8
CVE-2026-81376 Visual Studio Code Security Feature Bypass Vulnerability 09.09.2026 9.6
CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability 09.09.2026 9.9
CVE-2026-82533 DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing 08.09.2026 9.4
CVE-2026-82067 Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup 08.09.2026 9.2
CVE-2026-86729 WWBN AVideo Unrestricted Authentication Attempts via get_api_preauthorize 08.09.2026 9.1
CVE-2026-86738 Snipe-IT before 8.7.0 CSS Injection via Custom CSS 08.09.2026 9.3
CVE-2026-12647 09.09.2026 9.9
CVE-2026-12645 09.09.2026 9.9
CVE-2026-12646 09.09.2026 9.9
CVE-2026-12650 09.09.2026 9.9
CVE-2026-12744 09.09.2026 9.8
CVE-2026-12745 09.09.2026 9.8
CVE-2026-61516 Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint 08.09.2026 9.3
CVE-2026-73309 XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint 09.09.2026 9.1
CVE-2026-73311 XenForo < 2.3.13 OAuth2 Authorization Code Reuse 09.09.2026 9.1
CVE-2026-73312 XenForo < 2.3.13 Refresh Token Replay via Expired Access Token 09.09.2026 9.1
CVE-2026-77089 Command Center API Authentication Bypass 09.09.2026 9.3
CVE-2026-78234 Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users 08.09.2026 9.9
CVE-2026-62645 08.09.2026 9.3
CVE-2026-62646 08.09.2026 9.1
CVE-2026-62647 08.09.2026 9.3
CVE-2026-67367 09.09.2026 9.2
CVE-2026-71376 OS Command Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71377 Command Argument Injection Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-71374 Deserialization of Untrusted Data Vulnerability in Cosminexus Component Container 08.09.2026 9.8
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write 08.09.2026 9.4
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow 08.09.2026 9.4
CVE-2026-44756 Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing 08.09.2026 10
CVE-2026-58240 Missing Authentication check in SAP NetWeaver (Message Server) 09.09.2026 9.8
CVE-2026-66768 Improper Access Control in SAP NetWeaver (SAP GUI for Java) 09.09.2026 9
CVE-2026-76969 Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) 08.09.2026 9.4
CVE-2026-86543 knowns before 0.30.0 Unauthenticated Management API Exposure 07.09.2026 9.3
CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 09.09.2026 10
CVE-2026-86478 09.09.2026 9.8
CVE-2026-86480 09.09.2026 9.8
CVE-2026-18922 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property 08.09.2026 9.8
CVE-2026-7861 Code Injection in Next4Biz's CSM (Customer Service Management) 09.09.2026 9.8
CVE-2026-80238 08.09.2026 9.3
CVE-2026-86426 LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion 08.09.2026 9.2
CVE-2026-61410 09.09.2026 9.4
CVE-2026-6223 OTP Bypass in Bahçelievler Muncipality's BiHayat App 08.09.2026 9.4
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci 08.09.2026 9.8
CVE-2026-86299 Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection 07.09.2026 9.4
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one 09.09.2026 9.2
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow 08.09.2026 10
CVE-2026-79697 Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection 08.09.2026 9.4
CVE-2026-79698 Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection 07.09.2026 9.4
CVE-2026-16876 08.09.2026 9.3
CVE-2026-86259 OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation 08.09.2026 9
CVE-2026-86167 Tenda HG10 Boa formgponConf os command injection 08.09.2026 9.4
CVE-2026-86165 Tenda HG10 formURL buffer overflow 08.09.2026 9.3
CVE-2026-16310 MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter 07.09.2026 9.8
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier 07.09.2026 9.8
CVE-2026-86218 pre-authentication remote code execution 09.09.2026 10
CVE-2026-86153 Tenda CP3 Redirect.cpp SetRedirectEnable privileges management 08.09.2026 9.4
CVE-2026-86152 Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection 06.09.2026 10
CVE-2026-86151 Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection 05.09.2026 9.4
CVE-2026-86149 Tenda CP3 NetCheckPing.cpp os command injection 08.09.2026 9.4
CVE-2026-86148 Tenda CP3 Kylin system.c SystemAsh os command injection 08.09.2026 9.4
CVE-2026-67276 SSH user impersonation possible in Mikrotik RouterOS 09.09.2026 9.2
CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 09.09.2026 9.2
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php 05.09.2026 9.3
CVE-2026-86190 WWBN AVideo Broken Access Control via videoViewsInfo hash Parameter 08.09.2026 9.3
CVE-2026-86184 Lara Dashboard before 1.3.0 Missing Authentication in screenshot-login Route 05.09.2026 9.3
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields 07.09.2026 9.8
CVE-2026-86117 Coolify through 4.3.17 OAuth Account Takeover via Unverified Email Matching 05.09.2026 9.2
CVE-2026-86119 Webstudio through 0.296.0 SSRF via /cgi proxy routes 05.09.2026 9.2
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control 08.09.2026 9.3
CVE-2026-86123 SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints 08.09.2026 9.4
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server 05.09.2026 9.3
CVE-2024-11080 Post Grid and Gutenberg Blocks – ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection 07.09.2026 9.8
CVE-2026-13447 MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery 07.09.2026 9.8
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log 07.09.2026 9.8
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize 08.09.2026 9.4
CVE-2026-52766 YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action 09.09.2026 9.1
CVE-2026-75925 IXON VPN Client CRLF Injection 07.09.2026 9.4
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server 08.09.2026 9.2
CVE-2026-75430 04.09.2026 9.8
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed 04.09.2026 9.8
CVE-2026-19274 IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image 04.09.2026 9.6
CVE-2026-75431 04.09.2026 9.1
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi 04.09.2026 9.3
CVE-2026-85620 Postgres MCP Pro 0.3.0 Restricted-Mode Bypass via FROM-Clause Function 04.09.2026 9.2
CVE-2026-85625 sift 17.1.3 Prototype Pollution Remote Code Execution via $where 04.09.2026 9.2
CVE-2026-85660 cli-mcp-server 0.2.5 Command Allowlist Bypass via Shell Substitution 04.09.2026 9.2
CVE-2026-85661 excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode 04.09.2026 9.3
CVE-2026-85663 Aim 3.29.1 Remote Code Execution via Unauthenticated Method Dispatch 04.09.2026 9.3
CVE-2026-85667 xiaobei through 5.5.2 Unauthenticated Webhook Message Injection 08.09.2026 9.3
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension 08.09.2026 9.3
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer 04.09.2026 9.3
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction 08.09.2026 9.2
CVE-2026-85695 FastChat Unauthenticated Worker Registration SSRF and Model Spoofing 04.09.2026 9.3
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename 04.09.2026 9.3
CVE-2026-85595 Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth 05.09.2026 9.3
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass 05.09.2026 9.3
CVE-2026-85614 OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker 04.09.2026 9.2
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes 04.09.2026 9.8
CVE-2026-85184 @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target 04.09.2026 9.1
CVE-2026-15354 ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter 04.09.2026 9.8
CVE-2026-62928 04.09.2026 9.3
CVE-2026-69657 04.09.2026 9.3
CVE-2026-70403 04.09.2026 9.3
CVE-2026-85085 04.09.2026 9.6
CVE-2026-11613 Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter 07.09.2026 9.8
CVE-2026-85506 09.09.2026 9.8
CVE-2026-85507 04.09.2026 9.8
CVE-2026-85508 04.09.2026 9.8
CVE-2026-85509 04.09.2026 9.8
CVE-2026-85504 04.09.2026 9.8
CVE-2026-85146 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-85148 Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials 04.09.2026 9.3
CVE-2026-75754 04.09.2026 10
CVE-2026-67402 04.09.2026 9.2
CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability 09.09.2026 9.1
CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability 09.09.2026 10
CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability 09.09.2026 9.3
CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability 09.09.2026 10
CVE-2026-85424 MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_CLEAR 05.09.2026 9.3
CVE-2026-85425 MOOS-IvP through 24.8.1 iSay Command Injection via SAY_MOOS 04.09.2026 9.3
CVE-2026-85426 MOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client Names 04.09.2026 9.3
CVE-2026-85427 MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILE 04.09.2026 9.2
CVE-2026-85428 MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write 03.09.2026 9.3
CVE-2026-85433 MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration 03.09.2026 9.3
CVE-2026-85434 MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping 05.09.2026 9.3
CVE-2026-85435 MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment 04.09.2026 9.3
CVE-2026-85437 MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders 04.09.2026 9.3
CVE-2026-85438 MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts 03.09.2026 9.3
CVE-2026-85440 MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length 04.09.2026 9.3
CVE-2026-85224 D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection 04.09.2026 9.4
CVE-2026-85223 D-Link DNS-340L CGI dropbox.cgi os command injection 04.09.2026 9.4
CVE-2026-85222 D-Link DNS-340L Add-On Center addon_center.cgi os command injection 04.09.2026 9.4
CVE-2026-85061 MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip 04.09.2026 10
CVE-2026-85391 Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml 03.09.2026 9.3
CVE-2026-85394 python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret 03.09.2026 9.3
CVE-2026-82526 R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint 04.09.2026 9.3
CVE-2026-58400 GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter 04.09.2026 9.1
CVE-2026-84238 WordPress YITH Request a Quote for WooCommerce Premium plugin < 4.46.0 - Broken Access Control vulnerability 07.09.2026 9.8
CVE-2026-84753 WordPress Mail Mint plugin <= 1.31.0 - PHP Object Injection vulnerability 05.09.2026 9.8
CVE-2026-84768 WordPress VikAppointments Services Booking Calendar plugin <= 1.2.20 - SQL Injection vulnerability 03.09.2026 9.3
CVE-2026-84813 WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability 04.09.2026 9.3
CVE-2026-84814 WordPress Bricksforge plugin <= 3.1.8.8 - Privilege Escalation vulnerability 03.09.2026 9.8
CVE-2026-84834 WordPress JobSearch plugin <= 3.2.0 - PHP Object Injection vulnerability 07.09.2026 9.8
CVE-2026-85181 CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum 03.09.2026 9.3
CVE-2026-85183 Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS 03.09.2026 9.3
CVE-2026-85216 MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials 03.09.2026 9.5
CVE-2026-85109 Tenda HG10 Boa Web Server formLogin buffer overflow 03.09.2026 9.3
CVE-2026-82180 03.09.2026 9.5
CVE-2026-78080 Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 03.09.2026 9.3
CVE-2026-78069 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 03.09.2026 9.5
CVE-2026-85154 WWBN AVideo Authentication Bypass via Non-Expiring video_id_hash 05.09.2026 9.3
CVE-2026-76178 Multiple vulnerabilities in Ocsreports for OCS Inventory NG 03.09.2026 9.2

Latest Updates

CVE Title Updated Score
CVE-2026-7188 SQLi in Armiya Information Technologies' Access Control System 10.09.2026 9.8
CVE-2026-80351 Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod 10.09.2026
CVE-2026-80352 Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects 10.09.2026
CVE-2026-80354 Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace 10.09.2026
CVE-2026-88763 Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service 10.09.2026
CVE-2026-88770 Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-force-locked accounts 10.09.2026
CVE-2026-87804 10.09.2026
CVE-2026-0302 Checkov by Prisma Cloud: OS Command Injection Vulnerability 10.09.2026
CVE-2026-0303 Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File 10.09.2026
CVE-2026-0304 Cortex XDR Broker VM: Privilege Escalation Vulnerability 10.09.2026
CVE-2026-19436 Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation via Discounted Purchase 10.09.2026
CVE-2026-19439 Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Customer PII Disclosure via wps_uwgc_report_details 10.09.2026
CVE-2026-19840 Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions 10.09.2026
CVE-2026-77770 miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Email Link Validator 10.09.2026
CVE-2026-77771 miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout 10.09.2026
CVE-2026-78361 zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Option Deletion 10.09.2026
CVE-2026-81431 Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id 10.09.2026
CVE-2026-81635 10.09.2026
CVE-2026-82582 10.09.2026
CVE-2026-82925 Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature 10.09.2026
CVE-2026-0305 Prisma Access Agent: Information Disclosure Vulnerability on Linux 10.09.2026
CVE-2026-0306 Prisma Access Agent: EndPoint DLP Bypass Vulnerability on Windows 10.09.2026
CVE-2026-0307 GlobalProtect App: Local Privilege Escalation Vulnerabilities 10.09.2026
CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface 10.09.2026
CVE-2026-0309 PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration 10.09.2026
CVE-2026-85645 Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting 10.09.2026 6.1
CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing 10.09.2026
CVE-2026-82079 Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack 10.09.2026
CVE-2026-84939 Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks 10.09.2026
CVE-2026-49362 Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation 10.09.2026
CVE-2026-49363 Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription 10.09.2026
CVE-2026-49364 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers 10.09.2026
CVE-2026-57822 Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service 10.09.2026
CVE-2026-57967 Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment 10.09.2026
CVE-2026-67593 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion 10.09.2026
CVE-2026-75880 Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service 10.09.2026
CVE-2026-14873 Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password Reset 10.09.2026 8
CVE-2026-15019 Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment 10.09.2026 7.5
CVE-2026-15796 Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting 10.09.2026 6.4
CVE-2026-15820 Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module 'attributes' Setting 10.09.2026 6.4
CVE-2026-15823 Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter 10.09.2026 4.3
CVE-2026-18386 WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter 10.09.2026 4.9
CVE-2026-18594 Advanced Contact form 7 DB <= 2.1.3 - Missing Authorization to Authenticated (Custom+) Unauthorized Data Import via 'import_cf7_id' 10.09.2026 4.3
CVE-2026-4657 Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field 10.09.2026 6.4
CVE-2026-76562 Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter 10.09.2026 7.2
CVE-2026-19583 Velociraptor Required Permissions bypass by using client monitoring queries 10.09.2026 9.9
CVE-2026-19584 Velociraptor VQL injection during notebook restore from backup 10.09.2026 7.7
CVE-2026-87870 Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters 10.09.2026 6.4
CVE-2026-84062 10.09.2026
CVE-2026-84063 10.09.2026
CVE-2026-18351 Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter 10.09.2026 9.8
CVE-2026-87933 DaveGamble cJSON cJSON_Utils.c cJSONUtils_MergePatch use after free 10.09.2026
CVE-2026-87931 Behavioral Technology Group Pavlok Behavioral Conditioning Wearable Apple Notification Center Service Event buffer overflow 10.09.2026
CVE-2026-87926 Rizwan17 inventory-management-system Login Page index.php cross site scripting 09.09.2026
CVE-2026-87925 Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql injection 09.09.2026
CVE-2026-87924 Rizwan17 inventory-management-system Invoice Generation invoice_bill.php missing authentication 09.09.2026
CVE-2026-15460 Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path 09.09.2026 5.4
CVE-2026-87923 Rizwan17 inventory-management-system List DBOperation.php cross site scripting 09.09.2026
CVE-2026-71809 09.09.2026
CVE-2026-87922 Rizwan17 inventory-management-system AJAX Backend process.php DBOperation.addCategory missing authentication 09.09.2026
CVE-2026-88001 Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets 09.09.2026 5
CVE-2026-88002 Open WebUI: Any authenticated user can hang the server via a cyclic chat message history 09.09.2026 6.5
CVE-2026-88069 Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis 09.09.2026
CVE-2026-71805 09.09.2026
CVE-2026-75308 09.09.2026
CVE-2026-87921 Rizwan17 inventory-management-system manage.php update_record sql injection 09.09.2026
CVE-2026-87997 Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions 09.09.2026 4.3
CVE-2026-87998 Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion 09.09.2026 7.1
CVE-2026-87999 Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch 09.09.2026 7.1
CVE-2026-88000 Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree 09.09.2026 6.5
CVE-2026-71807 09.09.2026
CVE-2026-75307 09.09.2026
CVE-2026-87016 Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite 09.09.2026 8.1
CVE-2026-87017 Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends 09.09.2026 4.3
CVE-2026-87994 Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint 09.09.2026 4.3
CVE-2026-87995 Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin 09.09.2026 8.7
CVE-2026-87996 Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader 09.09.2026 7.7
CVE-2026-15913 Path Traversal in Fortra's GoAnywhere MFT Endpoint 09.09.2026 7.7
CVE-2026-87013 Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle 09.09.2026 4.3
CVE-2026-87014 Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes 09.09.2026 6.5
CVE-2026-87015 Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication 09.09.2026 6.8
CVE-2026-87011 Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout 09.09.2026 7.5
CVE-2026-87012 Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value 09.09.2026 4.3
CVE-2026-53956 Rattler vulnerable to package cache path traversal via conda package build string 09.09.2026 5.4
CVE-2026-79387 09.09.2026
CVE-2026-71802 09.09.2026
CVE-2026-71803 09.09.2026
CVE-2026-71808 09.09.2026
CVE-2026-79516 09.09.2026 4
CVE-2026-36433 09.09.2026
CVE-2026-50165 alf.io has Improper Access Control for Organization Owners that Exposes System Secrets 09.09.2026
CVE-2026-71801 09.09.2026
CVE-2026-79515 09.09.2026 4.3
CVE-2026-79513 09.09.2026 6.5
CVE-2026-79514 09.09.2026 6.5
CVE-2026-79522 09.09.2026 6.5
CVE-2026-61915 09.09.2026 4.2
CVE-2026-71616 09.09.2026
CVE-2026-61910 09.09.2026 3.5
CVE-2026-61911 09.09.2026 4.3
CVE-2026-71613 09.09.2026
CVE-2026-71614 09.09.2026
CVE-2026-61909 09.09.2026 3.5
CVE-2026-71612 09.09.2026
CVE-2026-61908 09.09.2026 3.1
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server 09.09.2026 9.6
CVE-2026-38998 09.09.2026
CVE-2026-73769 Authenticated Remote Code Execution in CPPM Web Interface 09.09.2026 7.2
CVE-2026-73786 Unauthenticated Network-Based Denial of Service in CPPM systems 09.09.2026 7.5
CVE-2026-73787 Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface 09.09.2026 7.2
CVE-2026-73788 Privilege Escalation in ClearPass OnGuard Agent 09.09.2026 6.5
CVE-2026-73789 Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interface 09.09.2026 5.3
CVE-2026-79324 09.09.2026
CVE-2026-61907 09.09.2026 4.3
CVE-2026-79322 09.09.2026
CVE-2026-79323 09.09.2026
CVE-2026-54694 NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover 09.09.2026 9.6
CVE-2025-51619 09.09.2026
CVE-2026-39020 09.09.2026 5.5
CVE-2026-52482 09.09.2026
CVE-2026-87927 MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher 09.09.2026
CVE-2026-87928 MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page 09.09.2026
CVE-2026-87929 MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key 09.09.2026
CVE-2026-87930 MaxSite CMS through 109.6 PHP Object Injection via ci_session 09.09.2026
CVE-2026-18147 Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url 09.09.2026
CVE-2026-19233 09.09.2026
CVE-2026-40635 09.09.2026 5.4
CVE-2026-46460 09.09.2026 3.5
CVE-2026-77120 09.09.2026
CVE-2026-85788 Incomplete list of disallowed inputs in awslabs mysql-mcp-server 09.09.2026 5.5
CVE-2026-23855 09.09.2026 7.2
CVE-2026-24442 09.09.2026
CVE-2026-26350 09.09.2026
CVE-2026-28523 09.09.2026
CVE-2026-34412 09.09.2026
CVE-2026-43635 09.09.2026
CVE-2026-43645 09.09.2026
CVE-2026-47156 MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator 09.09.2026
CVE-2026-49947 09.09.2026
CVE-2026-56125 09.09.2026
CVE-2026-70425 09.09.2026 6.7
CVE-2026-80914 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready 10.09.2026 8.8
CVE-2026-80915 drm/xe: Fix DPT allocation paths. 09.09.2026
CVE-2026-80916 kcov: fix data corruption and race conditions on PREEMPT_RT 09.09.2026
CVE-2026-80917 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems 09.09.2026
CVE-2026-80918 HID: core: fix number/pointer type confusion on long items 09.09.2026
CVE-2026-80919 drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format 09.09.2026
CVE-2026-80920 io_uring: defer eventfd signaling when queued from a wakeup handler 09.09.2026
CVE-2026-80921 KVM: s390: vsie: zero stale crypto bits 10.09.2026 8.8
CVE-2026-80922 crypto: qcom-rng - Allow zero as a random number 09.09.2026
CVE-2026-80923 xhci: dbgtty: Fix unregister on tty_register_driver() failure 09.09.2026
CVE-2026-80924 crypto: krb5 - use kfree_sensitive() for derived key buffers 10.09.2026 7.5
CVE-2026-80925 vlan: fix skb_under_panic and races when toggling HW VLAN offload 09.09.2026
CVE-2026-87853 Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation 09.09.2026
CVE-2026-87872 Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure 09.09.2026
CVE-2026-87874 Community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the ansible controller 09.09.2026
CVE-2026-87875 Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound 09.09.2026
CVE-2026-87876 Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) 09.09.2026
CVE-2026-8044 09.09.2026
CVE-2026-79947 09.09.2026 5.5
CVE-2026-67401 10.09.2026
CVE-2026-67403 09.09.2026
CVE-2026-68484 09.09.2026
CVE-2026-22590 Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage 09.09.2026 9.1
CVE-2026-22591 Fast DDS DDSSQLFilter Recursive Parser Stack Exhaustion (Remote DoS) 09.09.2026 7.5
CVE-2026-77974 Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function 09.09.2026
CVE-2026-78484 09.09.2026 5.5
CVE-2026-78493 09.09.2026 5.5
CVE-2026-79735 09.09.2026 4.4
CVE-2026-79945 09.09.2026 5.5
CVE-2026-81330 Softish C6 Ear Camera and EarVision Android Application Cleartext transmission of sensitive information 09.09.2026
CVE-2026-81640 Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials 09.09.2026
CVE-2026-82563 Softish C6 Ear Camera and EarVision Android Application Authentication bypass by spoofing 09.09.2026
CVE-2026-79693 09.09.2026 3.4
CVE-2026-79689 09.09.2026 5.3
CVE-2026-79741 09.09.2026 5.3
CVE-2026-79942 09.09.2026 3.4
CVE-2026-79944 09.09.2026 3.4
CVE-2026-79946 09.09.2026 5.3
CVE-2026-79690 09.09.2026 3.7
CVE-2026-79941 09.09.2026 5.3
CVE-2026-83530 Uncontrolled Memory Allocation in cel-go 09.09.2026
CVE-2026-26212 Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE 09.09.2026
CVE-2026-79736 09.09.2026 3.7
CVE-2026-79729 09.09.2026 3.7
CVE-2026-78482 09.09.2026 5.5
CVE-2026-79732 09.09.2026 3.7
CVE-2026-87822 t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.fromBytes 09.09.2026
CVE-2026-87823 zstd-jni 1.1.1 through 1.5.7-13 Out-of-Bounds Read via Direct ByteBuffer Frame-Size Methods 09.09.2026
CVE-2026-87824 zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirect 09.09.2026
CVE-2026-87825 zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompression Dictionaries 09.09.2026
CVE-2026-87877 zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After close() 09.09.2026
CVE-2026-79617 Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter 09.09.2026 7.1
CVE-2026-82530 IP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP Header 09.09.2026
CVE-2026-78483 09.09.2026 5.9
CVE-2026-79731 09.09.2026 4.4
CVE-2026-64857 tirreno has Session Fixation in Login Authentication 09.09.2026
CVE-2026-79950 09.09.2026 7.5
CVE-2026-86198 PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket 09.09.2026
CVE-2026-86199 PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login 09.09.2026
CVE-2026-86200 PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT 09.09.2026
CVE-2026-86201 PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData 09.09.2026
CVE-2026-86202 PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket 09.09.2026
CVE-2026-86203 PocketMine-MP before 5.39.2 Item Duplication via Despawn State 09.09.2026
CVE-2026-86204 PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket 09.09.2026
CVE-2026-86739 Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence 09.09.2026
CVE-2026-86740 Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains 09.09.2026
CVE-2026-86741 Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA 09.09.2026
CVE-2026-86742 Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report 09.09.2026
CVE-2026-86743 Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report 09.09.2026
CVE-2026-86744 snipe-it before 8.7.0 Race Condition in Asset Checkout 09.09.2026
CVE-2026-86745 Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export 09.09.2026
CVE-2026-86746 Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay 09.09.2026
CVE-2026-86747 snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User 09.09.2026
CVE-2026-86748 Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive 09.09.2026
CVE-2026-86749 snipe-it before 8.7.0 Data Loss via Failed Image Write 09.09.2026
CVE-2026-86750 snipe-it before 8.7.0 Authorization Bypass via API User Create/Update 09.09.2026
CVE-2026-86751 Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown 09.09.2026
CVE-2026-86752 snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints 09.09.2026
CVE-2026-86753 snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint 09.09.2026
CVE-2026-86754 Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients 09.09.2026
CVE-2026-86755 Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth 09.09.2026
CVE-2026-86756 Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState 09.09.2026
CVE-2026-86757 Snipe-IT before 8.7.0 Information Disclosure via Custom Fields 09.09.2026
CVE-2026-86758 Snipe-IT before 8.7.0 License Key Exposure via CSV Export 09.09.2026
CVE-2026-86759 Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer 09.09.2026
CVE-2026-86760 snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag 09.09.2026
CVE-2026-86761 snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints 09.09.2026
CVE-2026-86762 Snipe-IT before 8.7.0 Authentication Bypass via API Middleware 09.09.2026
CVE-2026-86763 snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer 09.09.2026
CVE-2026-86764 Snipe-IT 8.6.4 before 8.7.0 Permission Bypass via assigned components 09.09.2026
CVE-2026-86765 Snipe-IT 8.6.3 Authorization Bypass via Asset Update Endpoint 09.09.2026
CVE-2026-86766 Snipe-IT 8.6.3 Race Condition via Consumable Checkout 09.09.2026
CVE-2026-86767 Snipe-IT before 8.7.0 Cross-Company Read via requested-assets 09.09.2026
CVE-2026-86768 Snipe-IT before 8.7.0 Improper Input Validation via API Checkout 09.09.2026
CVE-2026-86769 Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout 09.09.2026
CVE-2026-86770 Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation 09.09.2026
CVE-2026-86771 Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num 09.09.2026
CVE-2026-86772 Snipe-IT 8.6.3 Stored XSS via Department Names 09.09.2026
CVE-2026-86773 Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints 09.09.2026
CVE-2026-86774 Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy 09.09.2026
CVE-2026-86775 knowns before 0.30.0 Path Traversal via Document API 09.09.2026
CVE-2023-54355 PocketMine-MP 5.2.0 Server Crash via Incorrect EC Curve 09.09.2026
CVE-2023-54390 PocketMine-MP before 5.3.1 Denial of Service via LoginPacket 09.09.2026
CVE-2023-54392 PocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacket 09.09.2026
CVE-2023-54393 PocketMine-MP before 4.20.5 Denial of Service via LoginPacket 09.09.2026
CVE-2023-54394 PocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTransactionPacket 09.09.2026
CVE-2023-54395 PocketMine-MP before 4.12.5 Denial of Service via ModalFormResponsePacket 09.09.2026
CVE-2023-54396 PocketMine-MP before 4.8.1 Server Crash via Banner NBT 09.09.2026
CVE-2024-58380 PocketMine-MP before 5.11.2 Denial of Service via BookEditPacket 09.09.2026
CVE-2024-58381 PocketMine-MP before 5.11.1 Denial of Service via LoginPacket 09.09.2026
CVE-2024-58382 league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity 09.09.2026
CVE-2025-71417 PocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponsePacket 09.09.2026
CVE-2025-71418 PocketMine-MP before 5.25.2 Denial of Service via explode 09.09.2026
CVE-2026-56711 VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Overflow in Picture Allocation 09.09.2026
CVE-2026-73324 VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminated RealRTSP Response Line 09.09.2026
CVE-2026-79738 09.09.2026 7.5
CVE-2026-79740 09.09.2026 7.5
CVE-2026-86099 Chainlit through 2.12.0 Path Traversal via socket.io sessionId 09.09.2026
CVE-2026-78486 09.09.2026 4.4
CVE-2026-79952 09.09.2026 5.3
CVE-2026-79964 09.09.2026 5.3
CVE-2026-79971 09.09.2026 5.3
CVE-2026-79962 09.09.2026 5.3
CVE-2026-79968 09.09.2026 5.6
CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 10.09.2026 9.8
CVE-2026-85103 Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding 10.09.2026 9.8
CVE-2026-79965 09.09.2026 5.3
CVE-2026-15140 09.09.2026
CVE-2026-79638 09.09.2026 5.3
CVE-2026-79966 CWE-532: Insertion of Sensitive Information into Log File 09.09.2026 3.3
CVE-2026-79969 09.09.2026 5.3
CVE-2026-80169 09.09.2026 3.3
CVE-2026-79694 09.09.2026 5.5
CVE-2026-79728 09.09.2026 6.5
CVE-2026-79961 09.09.2026 5.3
CVE-2026-78481 09.09.2026 6.5
CVE-2026-79730 09.09.2026 5.6
CVE-2026-79972 09.09.2026 7.2
CVE-2026-79970 09.09.2026 5.6
CVE-2026-80172 09.09.2026 9.8
CVE-2026-79692 09.09.2026 7.3
CVE-2026-78490 09.09.2026 7.5
CVE-2026-79695 09.09.2026 7.3
CVE-2026-78485 09.09.2026 7.3
CVE-2026-87806 Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password 09.09.2026
CVE-2026-87807 siyuan before v3.8.2 SQL Injection via fullTextSearchBlock 09.09.2026
CVE-2026-87808 SiYuan before v3.8.2 Read-Only Boundary Bypass via fullTextSearchBlock 09.09.2026
CVE-2026-87809 Siyuan before v3.8.2 Information Disclosure via Export Preview 09.09.2026
CVE-2026-87810 Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock 09.09.2026
CVE-2026-87811 SiYuan before v3.8.2 Stored XSS via notebook template paths 09.09.2026
CVE-2026-87812 SiYuan before v3.8.2 Stored XSS via Bazaar iconURL 09.09.2026
CVE-2026-87813 SiYuan before v3.8.2 Stored XSS via unescaped asset filenames 09.09.2026
CVE-2026-87814 SiYuan before v3.8.2 Stored XSS via Asset Preview 09.09.2026
CVE-2026-87815 SiYuan before v3.8.2 Path Traversal via removeRiffDeck 09.09.2026
CVE-2026-87816 PasswordPusher before 2.11.1 Race Condition View Limit Bypass 09.09.2026
CVE-2026-87817 GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation 09.09.2026
CVE-2026-87818 GitPython 3.1.59 Local File Content Oracle via --no-index 09.09.2026
CVE-2026-87819 GitPython before 3.1.60 Denial of Service via ReDoS 09.09.2026
CVE-2026-87820 CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner 09.09.2026
CVE-2026-87821 Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch 09.09.2026 7.1
CVE-2026-74761 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId 09.09.2026
CVE-2026-78489 09.09.2026 5.9
CVE-2026-78492 09.09.2026 7.4
CVE-2026-79637 09.09.2026 7.7
CVE-2026-79963 09.09.2026 7.4
CVE-2026-80171 09.09.2026 4.7
CVE-2026-79635 09.09.2026 7.3
CVE-2026-87827 KGUARD DVR unauthenticated remote command execution vulnerability 09.09.2026
CVE-2026-41869 Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API) 09.09.2026
CVE-2026-41870 Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API) 09.09.2026
CVE-2026-41871 Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API) 09.09.2026
CVE-2026-73334 Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation 09.09.2026
CVE-2026-54048 Apache Impala: Avro Schema URL Server-Side Request Forgery 09.09.2026
CVE-2026-56207 Apache Impala: SAML authentication bypass via forged bearer token 09.09.2026
CVE-2026-57866 Apache Impala: Secrets Exfiltration via SSRF 09.09.2026
CVE-2026-65181 Apache Impala: RCE via External Data Source Class Loading 09.09.2026
CVE-2026-79641 09.09.2026 7.5
CVE-2026-79727 09.09.2026 3.3
CVE-2026-80174 09.09.2026 5.3
CVE-2026-80239 09.09.2026 2.4
CVE-2026-85978 Unauthenticated Remote Code Execution in Akana API Platform 09.09.2026