145 CVEs — updated 2026-09-19 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-59971 | MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2 | CRITICAL | 10.0 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-71133 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 10.0 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83020 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 10.0 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-83021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported v | CRITICAL | 10.0 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-83059 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 10.0 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83099 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 10.0 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-92808 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An un | CRITICAL | 10.0 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-85889 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o | CRITICAL | 10.0 | 41%ile | NVD | 2026-09-17 |
| CVE-2026-84075 | IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentic | CRITICAL | 9.9 | — | NVD | 2026-09-18 |
| CVE-2026-84078 | IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An | CRITICAL | 9.9 | — | NVD | 2026-09-18 |
| CVE-2026-90898 | Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that pro | CRITICAL | 9.8 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-57123 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_se | CRITICAL | 9.8 | 40%ile | NVD | 2026-09-14 |
| CVE-2026-57125 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST | CRITICAL | 9.8 | 35%ile | NVD | 2026-09-14 |
| CVE-2026-57124 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect | CRITICAL | 9.8 | 49%ile | NVD | 2026-09-14 |
| CVE-2026-57127 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddlewar | CRITICAL | 9.8 | 58%ile | NVD | 2026-09-14 |
| CVE-2026-57131 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router. | CRITICAL | 9.8 | 60%ile | NVD | 2026-09-14 |
| CVE-2026-59178 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the d | CRITICAL | 9.8 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-57139 | PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/serve | CRITICAL | 9.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-70748 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t | CRITICAL | 9.8 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-70756 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-70757 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t | CRITICAL | 9.8 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-70913 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions | CRITICAL | 9.8 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-73940 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-73947 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.8 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-73950 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-73953 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-73956 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-73961 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-73963 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-82994 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-82995 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83000 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83035 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83036 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83037 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83042 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83054 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-83060 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83061 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83062 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83066 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83094 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83095 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83098 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-83100 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83108 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-83151 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-83232 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explore | CRITICAL | 9.8 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83261 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supporte | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-83269 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-83283 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-83327 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83339 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83355 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Me | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-83452 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Interna | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-83462 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-87184 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.8 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-87188 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-20326 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | CRITICAL | 9.8 | 33%ile | NVD | 2026-09-16 |
| CVE-2026-54460 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1 | CRITICAL | 9.8 | 47%ile | NVD | 2026-09-17 |
| CVE-2026-82967 | IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attack | CRITICAL | 9.8 | — | NVD | 2026-09-18 |
| CVE-2026-57140 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the | CRITICAL | 9.4 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-54618 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza | CRITICAL | 9.4 | 34%ile | NVD | 2026-09-17 |
| CVE-2026-92717 | Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated call | CRITICAL | 9.3 | 30%ile | NVD | 2026-09-16 |
| CVE-2026-92720 | Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated a | CRITICAL | 9.3 | 40%ile | NVD | 2026-09-16 |
| CVE-2026-92805 | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in Conf | CRITICAL | 9.3 | 28%ile | NVD | 2026-09-16 |
| CVE-2026-63647 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t | CRITICAL | 9.3 | — | NVD | 2026-09-18 |
| CVE-2026-93839 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allow | CRITICAL | 9.3 | — | NVD | 2026-09-18 |
| CVE-2026-73944 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-73952 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83104 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-83154 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | CRITICAL | 9.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83201 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | CRITICAL | 9.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83202 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | CRITICAL | 9.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-87128 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | CRITICAL | 9.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-87129 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | CRITICAL | 9.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87170 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-87173 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-87175 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87176 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-87217 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-87223 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-61594 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | CRITICAL | 9.1 | 36%ile | NVD | 2026-09-16 |
| CVE-2026-54670 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont | CRITICAL | 9.1 | 45%ile | NVD | 2026-09-17 |
| CVE-2026-54767 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php | CRITICAL | 9.1 | 36%ile | NVD | 2026-09-17 |
| CVE-2026-90938 | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/p | HIGH | 8.8 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-90944 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenti | HIGH | 8.8 | 52%ile | NVD | 2026-09-14 |
| CVE-2026-59160 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts it | HIGH | 8.8 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-73173 | Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver m | HIGH | 8.8 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-92729 | SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the H | HIGH | 8.8 | 44%ile | NVD | 2026-09-16 |
| CVE-2026-86801 | The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress an | HIGH | 8.8 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-92972 | SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefi | HIGH | 8.8 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-54504 | MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13 | HIGH | 8.8 | 50%ile | NVD | 2026-09-17 |
| CVE-2026-58197 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-82787 | Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an | HIGH | 8.7 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-91996 | lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attacker | HIGH | 8.7 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-68070 | The affected products are missing authentication for a critical function, which could allow an attacker to run as root a | HIGH | 8.7 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-88263 | XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve t | HIGH | 8.7 | 45%ile | NVD | 2026-09-16 |
| CVE-2026-86106 | An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions with | HIGH | 8.7 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-79954 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv | HIGH | 8.7 | 26%ile | NVD | 2026-09-18 |
| CVE-2026-88259 | CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenti | HIGH | 8.7 | — | NVD | 2026-09-18 |
| CVE-2026-18111 | Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image | HIGH | 8.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-57112 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, Tool | HIGH | 8.3 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-90896 | Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checko | HIGH | 8.2 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-81475 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio | HIGH | 8.1 | 52%ile | NVD | 2026-09-17 |
| CVE-2026-54446 | NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensi | HIGH | 8.1 | 40%ile | NVD | 2026-09-17 |
| CVE-2026-81238 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulne | HIGH | 7.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-88065 | `tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions | HIGH | 7.5 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-92625 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/r | HIGH | 7.5 | 43%ile | NVD | 2026-09-16 |
| CVE-2026-20343 | A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to downl | HIGH | 7.5 | 38%ile | NVD | 2026-09-16 |
| CVE-2026-53714 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | HIGH | 7.4 | 21%ile | NVD | 2026-09-14 |
| CVE-2026-87195 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-61590 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 7.4 | 27%ile | NVD | 2026-09-16 |
| CVE-2026-68953 | The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclos | HIGH | 7.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-40856 | WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cg | HIGH | 7.1 | 25%ile | NVD | 2026-09-16 |
| CVE-2026-89034 | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low En | HIGH | 7.1 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-90539 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in t | MEDIUM | 6.9 | 16%ile | NVD | 2026-09-12 |
| CVE-2026-90543 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a mis | MEDIUM | 6.9 | 28%ile | NVD | 2026-09-12 |
| CVE-2026-90513 | A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue | MEDIUM | 6.9 | 38%ile | NVD | 2026-09-13 |
| CVE-2026-82784 | Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | MEDIUM | 6.9 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-89027 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downg | MEDIUM | 6.9 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-93559 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This aff | MEDIUM | 6.9 | — | NVD | 2026-09-18 |
| CVE-2026-55837 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_ | MEDIUM | 6.8 | 12%ile | NVD | 2026-09-14 |
| CVE-2026-54246 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves clu | MEDIUM | 5.7 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-90504 | A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted e | MEDIUM | 5.5 | 49%ile | NVD | 2026-09-13 |
| CVE-2026-90524 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d30995 | MEDIUM | 5.5 | 51%ile | NVD | 2026-09-13 |
| CVE-2026-90579 | A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http | MEDIUM | 5.5 | 33%ile | NVD | 2026-09-13 |
| CVE-2026-90620 | A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted elemen | MEDIUM | 5.5 | 33%ile | NVD | 2026-09-14 |
| CVE-2026-91002 | A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of t | MEDIUM | 5.5 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-12910 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 5.4 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-76439 | A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE | MEDIUM | 5.3 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-76444 | A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to | MEDIUM | 5.3 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-76447 | A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-16 |
| CVE-2026-71568 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requir | MEDIUM | 5.3 | 6%ile | NVD | 2026-09-17 |
| CVE-2026-11539 | IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX conne | MEDIUM | 5.3 | — | NVD | 2026-09-18 |
| CVE-2026-77339 | Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listen | MEDIUM | 5.1 | — | NVD | 2026-09-18 |
| CVE-2026-76902 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior t | MEDIUM | 5.0 | — | NVD | 2026-09-18 |
| CVE-2026-50604 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The | MEDIUM | 4.9 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-57128 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praison | MEDIUM | 4.3 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-12763 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context | MEDIUM | 4.2 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-81441 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio | MEDIUM | 4.0 | 7%ile | NVD | 2026-09-17 |
| CVE-2026-49254 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/ro | LOW | 2.9 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-85478 | A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical | LOW | 2.4 | — | NVD | 2026-09-18 |
| CVE-2026-84400 | CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote d | LOW | 2.3 | — | NVD | 2026-09-18 |
| CVE-2026-50608 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. | LOW | 1.2 | 4%ile | NVD | 2026-09-17 |