28 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-57147 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public | CRITICAL | 9.8 | 54%ile | NVD | 2026-09-15 |
| CVE-2026-57148 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the p | CRITICAL | 9.8 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-37152 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. | CRITICAL | 9.8 | 40%ile | NVD | 2026-09-15 |
| CVE-2026-78225 | A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS | CRITICAL | 9.5 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-66890 | The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FT | CRITICAL | 9.4 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-81855 | A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wär | CRITICAL | 9.3 | 41%ile | NVD | 2026-09-15 |
| CVE-2026-92787 | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypas | CRITICAL | 9.3 | 31%ile | NVD | 2026-09-16 |
| CVE-2026-54767 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php | CRITICAL | 9.1 | 36%ile | NVD | 2026-09-17 |
| CVE-2026-28326 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. | HIGH | 8.8 | 45%ile | NVD | 2026-09-17 |
| CVE-2026-84034 | IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-90946 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSo | HIGH | 8.7 | 46%ile | NVD | 2026-09-14 |
| CVE-2026-68950 | The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providi | HIGH | 8.7 | 13%ile | NVD | 2026-09-15 |
| CVE-2026-86520 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active | HIGH | 8.7 | — | NVD | 2026-09-18 |
| CVE-2026-86689 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active | HIGH | 8.2 | — | NVD | 2026-09-18 |
| CVE-2026-16141 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force th | HIGH | 8.1 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-81440 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability | HIGH | 7.3 | 24%ile | NVD | 2026-09-17 |
| CVE-2026-90940 | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endp | MEDIUM | 6.9 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-77960 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active | MEDIUM | 6.9 | — | NVD | 2026-09-18 |
| CVE-2026-54147 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid | MEDIUM | 6.5 | — | NVD | 2026-09-18 |
| CVE-2026-63406 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemet | MEDIUM | 5.9 | — | NVD | 2026-09-18 |
| CVE-2026-90509 | A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspec | MEDIUM | 5.5 | 22%ile | NVD | 2026-09-13 |
| CVE-2026-92579 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without | MEDIUM | 5.3 | 5%ile | NVD | 2026-09-16 |
| CVE-2026-87965 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoi | MEDIUM | 4.8 | 4%ile | NVD | 2026-09-18 |
| CVE-2026-78427 | The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of | MEDIUM | 4.3 | 30%ile | NVD | 2026-09-17 |
| CVE-2026-79551 | Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. | UNKNOWN | — | 18%ile | NVD | 2026-09-15 |
| CVE-2026-89905 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Move arena register slot below TCC | UNKNOWN | — | 9%ile | NVD | 2026-09-16 |
| OSS-20260912-1 | Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey | UNKNOWN | — | — | OSS-Security | 2026-09-12 |
| FG-IR-26-129 | Hardcoded Encryption Key Used for VPN Saved Passwords | UNKNOWN | — | — | Fortinet | 2026-05-12 |