88 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-53710 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sa | CRITICAL | 10.0 | 56%ile | NVD | 2026-09-15 |
| CVE-2026-62104 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | CRITICAL | 10.0 | 47%ile | NVD | 2026-09-17 |
| CVE-2026-92937 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for G | CRITICAL | 10.0 | 55%ile | NVD | 2026-09-17 |
| CVE-2026-93603 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge | CRITICAL | 10.0 | — | NVD | 2026-09-18 |
| CVE-2026-78159 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including | CRITICAL | 9.8 | 54%ile | NVD | 2026-09-12 |
| CVE-2026-57131 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router. | CRITICAL | 9.8 | 60%ile | NVD | 2026-09-14 |
| CVE-2026-62379 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice P | CRITICAL | 9.8 | 50%ile | NVD | 2026-09-15 |
| CVE-2026-57141 | PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-m | CRITICAL | 9.8 | 43%ile | NVD | 2026-09-15 |
| CVE-2026-90999 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled tele | CRITICAL | 9.8 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-51990 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary | CRITICAL | 9.8 | 61%ile | NVD | 2026-09-16 |
| CVE-2026-45140 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a | CRITICAL | 9.8 | 61%ile | NVD | 2026-09-17 |
| CVE-2026-75031 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick qu | CRITICAL | 9.8 | — | NVD | 2026-09-18 |
| CVE-2026-82340 | IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled refl | CRITICAL | 9.8 | — | NVD | 2026-09-18 |
| CVE-2026-73453 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary c | CRITICAL | 9.5 | 53%ile | NVD | 2026-09-16 |
| CVE-2026-85192 | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension fo | CRITICAL | 9.4 | 41%ile | NVD | 2026-09-14 |
| CVE-2026-89082 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, | CRITICAL | 9.3 | 42%ile | NVD | 2026-09-16 |
| CVE-2026-89083 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, | CRITICAL | 9.3 | 42%ile | NVD | 2026-09-16 |
| CVE-2026-54237 | Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instal | CRITICAL | 9.3 | 45%ile | NVD | 2026-09-17 |
| CVE-2026-73456 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) | CRITICAL | 9.2 | 53%ile | NVD | 2026-09-16 |
| CVE-2026-84738 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import f | CRITICAL | 9.1 | 13%ile | NVD | 2026-09-18 |
| CVE-2026-88795 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, | CRITICAL | 9.0 | 40%ile | NVD | 2026-09-17 |
| CVE-2026-47252 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access | CRITICAL | 9.0 | 38%ile | NVD | 2026-09-17 |
| CVE-2026-16428 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra | HIGH | 8.8 | 44%ile | NVD | 2026-09-14 |
| CVE-2026-19780 | Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi | HIGH | 8.8 | 60%ile | NVD | 2026-09-15 |
| CVE-2026-92125 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annot | HIGH | 8.8 | 43%ile | NVD | 2026-09-16 |
| CVE-2026-84858 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Byp | HIGH | 8.8 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-15815 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug | HIGH | 8.8 | 57%ile | NVD | 2026-09-17 |
| CVE-2026-54612 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until | HIGH | 8.8 | 41%ile | NVD | 2026-09-17 |
| CVE-2026-33625 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 conta | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-93759 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the d | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-14380 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile | HIGH | 8.8 | 43%ile | Microsoft | 2026-07-14 |
| CVE-2026-68489 | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authentic | HIGH | 8.7 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-73464 | On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted requ | HIGH | 8.7 | 41%ile | NVD | 2026-09-16 |
| CVE-2026-92593 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirec | HIGH | 8.7 | 36%ile | NVD | 2026-09-16 |
| CVE-2026-73166 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the | HIGH | 8.6 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-73170 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the | HIGH | 8.6 | 43%ile | NVD | 2026-09-16 |
| CVE-2026-90553 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores t | HIGH | 8.5 | 11%ile | NVD | 2026-09-12 |
| CVE-2026-91719 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via | HIGH | 8.1 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-83408 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppo | HIGH | 8.1 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-92127 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item | HIGH | 8.0 | 40%ile | NVD | 2026-09-16 |
| CVE-2026-63325 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/r | HIGH | 7.8 | 11%ile | NVD | 2026-09-16 |
| CVE-2026-86320 | A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. | HIGH | 7.8 | 13%ile | NVD | 2026-09-17 |
| CVE-2026-55895 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-92784 | @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source co | HIGH | 7.7 | 38%ile | NVD | 2026-09-16 |
| CVE-2026-76550 | The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing expo | HIGH | 7.2 | 54%ile | NVD | 2026-09-16 |
| CVE-2026-76551 | The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported | HIGH | 7.2 | 54%ile | NVD | 2026-09-16 |
| CVE-2026-61552 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes atta | HIGH | 7.2 | — | NVD | 2026-09-18 |
| CVE-2026-77147 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequa | MEDIUM | 6.5 | 21%ile | NVD | 2026-09-14 |
| CVE-2026-77281 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depe | MEDIUM | 6.5 | 30%ile | NVD | 2026-09-17 |
| CVE-2026-90527 | A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admi | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-13 |
| CVE-2026-90571 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functio | MEDIUM | 5.3 | 20%ile | NVD | 2026-09-13 |
| CVE-2026-90583 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected | MEDIUM | 5.3 | 21%ile | NVD | 2026-09-13 |
| CVE-2026-90848 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component St | MEDIUM | 5.3 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90528 | A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality o | MEDIUM | 5.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90529 | A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of | MEDIUM | 5.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90563 | A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the fil | MEDIUM | 5.1 | 11%ile | NVD | 2026-09-13 |
| CVE-2026-90564 | A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatM | MEDIUM | 5.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90567 | A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function | MEDIUM | 5.1 | 26%ile | NVD | 2026-09-13 |
| CVE-2026-90568 | A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSor | MEDIUM | 5.1 | 24%ile | NVD | 2026-09-13 |
| CVE-2026-90602 | A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is t | MEDIUM | 5.1 | 27%ile | NVD | 2026-09-13 |
| CVE-2026-92214 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/c | MEDIUM | 5.1 | 18%ile | NVD | 2026-09-16 |
| CVE-2026-93505 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media- | MEDIUM | 5.1 | — | NVD | 2026-09-18 |
| CVE-2026-90569 | A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopic | MEDIUM | 4.8 | 28%ile | NVD | 2026-09-13 |
| CVE-2026-90570 | A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function Adm | MEDIUM | 4.8 | 28%ile | NVD | 2026-09-13 |
| CVE-2026-57583 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin | LOW | 3.3 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-90488 | A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of | LOW | 2.1 | 14%ile | NVD | 2026-09-13 |
| CVE-2026-90491 | A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the fil | LOW | 2.1 | 16%ile | NVD | 2026-09-13 |
| CVE-2026-90581 | A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpd | LOW | 2.1 | 16%ile | NVD | 2026-09-13 |
| CVE-2026-90615 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unkn | LOW | 2.1 | 20%ile | NVD | 2026-09-14 |
| CVE-2026-90795 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function o | LOW | 2.1 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-91854 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the fil | LOW | 2.1 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-90489 | A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobi | LOW | 2.0 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90497 | A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the functio | LOW | 2.0 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90502 | A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/ | LOW | 2.0 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90604 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90694 | A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90695 | A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknow | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90696 | A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90709 | A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the fi | LOW | 2.0 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-90835 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the | LOW | 2.0 | 10%ile | NVD | 2026-09-14 |
| CVE-2026-90845 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the | LOW | 2.0 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-92381 | A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/ | LOW | 2.0 | 24%ile | NVD | 2026-09-16 |
| CVE-2026-92418 | A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff | LOW | 2.0 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-90850 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown function | LOW | 1.9 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-92385 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown fun | LOW | 1.9 | 29%ile | NVD | 2026-09-16 |
| CVE-2026-79249 | Chromium: CVE-2026-79249 Code injection in Bisection | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-47162 | Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name | UNKNOWN | — | 18%ile | Microsoft | 2026-06-09 |
| CVE-2026-47167 | Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |